Upgrade Airlock IAM with Docker image

This article explains how to upgrade a single local Airlock IAM instance running as a Docker container. The required IAM Docker image is pulled directly from the (private image respository) Quay.io and used locally.

To upgrade a local IAM instance with Docker, perform these steps:

  1. Stop the currently running IAM instance in Docker. In our example, this is the auth instance, locally located in $CUSTOM_DIRECTORY/airlock-iam-docker/iam/instances/auth. It runs in the Docker container called airlock-iam.
    In the Docker CLI, run the following command:
  2.  
    Terminal box
    docker kill airlock-iam
    # airlock-iam is the container's name
  3. Now upgrade your IAM instance by running the following command in the Docker CLI. Be sure to
    • Run this command from the local directory $CUSTOM_DIRECTORY/airlock-iam-docker.
    • Use the correct IAM version in the expression quay.io/airlock/iam:<version to upgrade to>.
    • Use the instance name from your previous setup in the expression upgrade -i <instance name> (here, the instance name is auth).
  4.  
    Terminal box
    docker run --rm -v "$(pwd)/iam:/home/airlock/iam" quay.io/airlock/iam:<version to upgrade to> upgrade -i auth -a LICENSE_DATA
    
  5.  
    Notice

    Starting with IAM 8.5, the IAM license and analytics feature is mandatory. If it is not configured, configuration activation will fail. The IAM CLI is used to configure the analytics plugin, during the init, reset, and upgrade operations. When you run any of these operations, you must specify your preferred analytics mode. For more information, see License and usage analytics.

  6. You have now upgraded Airlock IAM with Docker.
  7. Start the upgraded IAM instance by running the command below. This command will do the following:
    • --env “TZ=Europe/Zurich”: Sets the timezone to Europe/Zurich.
    • --env “IAM_LOG_LEVEL=DEBUG”: Sets the log level to “debug”.
    • -v “$(pwd)/iam:/home/airlock/iam”: Mounts the IAM configuration directory. That is, it maps your local iam folder to the /home/airlock/iam directory inside the Docker container, and synchronizes any local change immediately with the container at /home/airlock/iam.
    • 8443:8443: Maps your local port https://localhost:8443 to the Docker container port 8443, and thus exposes the IAM web interface to your browser.
    • run -i auth: Starts the upgraded IAM instance auth.
  8.  
    Terminal box
    docker run --rm \
    --env "TZ=Europe/Zurich" \
    --env "IAM_LOG_LEVEL=DEBUG" \
    -v "$(pwd)/iam:/home/airlock/iam" \
    -p 8443:8443 \
    -d quay.io/airlock/iam:<upgraded version> \
    run -i auth
  9. To check that the upgraded IAM instance is really up, running, and ready for use, enter https://localhost:8443/auth-admin/ui/app/login in your browser. This will open the IAM Adminapp login page. Note that it may take some time before the application is available.
  10. The upgrade was successful, if you can log in to the Adminapp and continue working as usual.

Further information and links

Internal links