如何在OpenShift/Kubernetes中升级容器?含OpenShift应用升级实操疑问
Great question! Your current approach of editing the YAML and running oc replace works, but there are definitely more efficient ways to handle application upgrades in OpenShift—including automated rollouts when a new image hits your registry. Let's break down the options:
Instead of modifying the YAML file and replacing the deployment, you can directly update the image reference using the oc set image command. This is faster and avoids having to edit and reapply the entire manifest:
oc set image deployment/ds-hub ds-hub=selenium/hub:3.7
This command targets the ds-hub container within the ds-hub deployment and updates its image to selenium/hub:3.7. OpenShift will automatically trigger a rolling update to replace the old pods with the new image.
To fully automate upgrades (so you don't have to run any commands or edit configs when a new image is pushed), you'll want to use ImageStreams and DeploymentConfigs (OpenShift's native alternative to Kubernetes Deployments, which has built-in image change triggers). Here's how to set this up:
Step 1: Create an ImageStream for Your Registry Image
An ImageStream acts as a pointer to your external registry (GitLab Registry or the official Selenium registry in your example) and monitors for new image versions.
For the official Selenium hub image, create this imagestream.yaml:
apiVersion: image.openshift.io/v1 kind: ImageStream metadata: name: selenium-hub spec: lookupPolicy: local: false tags: - from: kind: DockerImage name: selenium/hub name: "3.7" # Track the specific version, or use "latest" if you want to follow updates referencePolicy: type: Source
Apply it with:
oc create -f imagestream.yaml
If you're using a private GitLab Registry, first create an image pull secret to authenticate with GitLab:
oc create secret docker-registry gitlab-reg-secret \ --docker-server=registry.gitlab.com \ --docker-username=<your-gitlab-username> \ --docker-password=<your-gitlab-personal-access-token> \ --docker-email=<your-email>
Then link this secret to your project's default service account so pods can pull the private image:
oc secrets link default gitlab-reg-secret --for=pull
Step 2: Use a DeploymentConfig with Image Change Triggers
Convert your existing Deployment to a DeploymentConfig (or create a new one) and add an ImageChangeTrigger that watches the ImageStream. This trigger will automatically roll out new pods whenever the ImageStream detects a new image version.
Here's the updated DeploymentConfig for your Selenium Hub:
apiVersion: apps.openshift.io/v1 kind: DeploymentConfig metadata: annotations: kompose.cmd: kompose convert -f docker-compose-debug.yml kompose.version: 1.6.0 (e4adfef) labels: io.kompose.service: ds-hub name: ds-hub spec: replicas: 1 selector: io.kompose.service: ds-hub template: metadata: labels: io.kompose.service: ds-hub spec: containers: - env: - name: GRID_CLEAN_UP_CYCLE value: "10000" - name: GRID_MAX_SESSION value: "10" - name: GRID_TIMEOUT value: "150" image: selenium/hub:3.6 name: ds-hub ports: - containerPort: 4444 resources: {} stdin: true tty: true restartPolicy: Always triggers: # Auto-trigger when the ImageStream updates - type: ImageChange imageChangeParams: automatic: true containerNames: - ds-hub from: kind: ImageStreamTag name: selenium-hub:3.7 # Match the tag in your ImageStream lastTriggeredImage: "" # Trigger when the DeploymentConfig itself is edited - type: ConfigChange
Apply this with:
oc create -f deploymentconfig.yaml
Now, whenever the selenium-hub:3.7 image in your registry is updated (or if you switch to latest and a new latest image is pushed), OpenShift will automatically roll out new pods with the updated image.
If you prefer to stick with Kubernetes Deployments instead of DeploymentConfigs, you can set imagePullPolicy: Always on your container and use an external tool like Argo CD to monitor the registry for updates—but DeploymentConfigs are the native OpenShift way to handle this automation.
If you prefer using a graphical interface instead of the command line, here's how to do it:
Manual Upgrade via Console
- Log into the OpenShift Web Console and navigate to your project.
- Go to Workloads > Deployments (or DeploymentConfigs if you're using that) in the left menu.
- Click on your
ds-hubdeployment to open its details page. - Click the Actions dropdown at the top right and select Edit Deployment (or Edit DeploymentConfig).
- In the container section, find the Image field and change it from
selenium/hub:3.6toselenium/hub:3.7. - Click Save—OpenShift will immediately start a rolling update to replace the old pods.
Configure Automatic Triggers via Console
- On the
ds-hubDeploymentConfig details page, go to the Configuration tab. - Scroll down to the Triggers section and click Add Trigger.
- Select Image Change Trigger from the dropdown.
- Choose your
selenium-hubImageStream and the appropriate tag (e.g.,3.7), then check the Automatic box. - Click Save—now the deployment will auto-update whenever the image in the registry changes.
内容的提问来源于stack exchange,提问作者Slavik Muz

