Moving Avi from Blue to Green Without Ever Writing Back to Blue

Building GSLB is not the same job as moving the virtual services that already exist. The first job proves a name can fail over. The second job has a source of truth, a blue controller full of applications, and a green pair that should come to match it without anyone retyping a pool.

The Challenge

A virtual service is the visible object. Behind it is everything it uses. Copy the virtual service and forget a profile, and green looks installed until the first request. Copy everything, including the source site’s cloud, VRF, and Service Engine group, and green is now pretending to be blue. The new site has its own cloud, its own VRF, its own SE group, and its own VIP network. Those are the environment. They are not configuration to clone.

What Converge Does

The tool is customer-agnostic. One environment file holds the site keys. Converge makes the green controllers match that file: every virtual service from blue, with everything it uses, placed on that site’s own cloud, VRF, SE group, and VIP network. Environment references that are not those three have to be mapped explicitly. Shipped product objects are resolved by name on the target and never created.

GSLB is part of the same converge, not a later project. The leader gets a subdomain per zone, DNS services authoritative for them, and one GSLB service per blue VIP. Each site’s services are live or staged according to the environment file. The output that matters is a flip list: every DNS name, its GSLB target, and whether it is ready.

No client reaches green until its DNS name is flipped to the GSLB name. The flips are made from that list, on the Windows DNS side, name by name, when the application owner is ready. Not when the controller UI looks finished.

The Rules the Code Enforces

Converge is a dry run unless you pass --commit. A second run after a commit reports unchanged. Objects come back as add, update, unchanged, frozen, kept, or blocked.

Blue stays the source of truth until one of an application’s names is flipped. After that, green owns it. Converge will not update it from blue, will not rearrange its GSLB members, and will not take it offline. Nothing is ever written to blue. The client refuses a write there, and it refuses a target that turns out to be blue’s cluster.

Converge never deletes. Purge deletes what converge created, and nothing else: not an object that was already on green, not an object a flipped application uses. A live service is taken out of service only with an explicit allow-offline flag. Private keys are read from blue and posted to green in the same pass. They are not written to disk or to a journal.

There is an offline self-test that needs no credentials, and an example config that prints the keys commented out. Use those before the first converge against a real controller. The GSLB build order is the other half of this. That post is how the DNS virtual services get proved. This one is how the applications arrive, and how they stop arriving once a name has flipped.

The Results

Green matched the source virtual services, placed on that site’s own cloud, VRF, SE group, and VIP network. Shipped product objects were resolved by name and not created. GSLB came along in the same converge, and the output that mattered was the flip list. A second run after a commit reported unchanged. After a name flipped, that application stopped being updated from blue.

Lessons Learned

Copying the source site’s cloud and SE group makes green pretend to be blue. Those three references are the environment. They are not configuration to clone. A dry run has to be the default, because the first converge against a real controller is where a missed profile shows up. Private keys do not belong in a journal.

Getting Started

Run the offline check first. It needs no controller. The environment file is yours. The sample keys are site_a and site_b. Point the hosts at your controllers, for example avi-blue.essential.coach.

python3 avi_migrate.py selftest
python3 avi_migrate.py --example-config > env.essential.yaml
python3 avi_migrate.py converge --config env.essential.yaml
python3 avi_migrate.py converge --config env.essential.yaml --commit

Clone avi-blue-green. Run the offline self-test before you point it at a controller. Rename site_a and site_b to your site keys. Converge does not write unless you pass --commit. Flip DNS names from the list the tool prints, one at a time, when the application owner is ready. Do not flip them because the controller UI looks finished.

Conclusion

Blue stays the source of truth until a name flips. After that, green owns the application, and the tool will not drag it back. Nothing is ever written to blue.

The converge tool and the offline self-test are in the repository. The sample environment calls the sites site_a and site_b. Rename those keys. Converge does not write unless you pass --commit.


Repository: github.com/noahfarshad/avi-blue-green

Related Stories:

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top