---
title: Install or Upgrade Manufacturing Connect
slug: install-or-upgrade-manufacturing-connect
docTags: 
createdAt: 2022-03-30T21:31:35.000Z
---



You can install the Manufacturing Connect in the Google Cloud Platform (GCP).

:::hint{type="info"}
**Note:** For information on upgrading Manufacturing Connect (MC), see [Upgrade Manufacturing Connect](docId\:yHwg58LEB5Hm4g507YeG0) below.
:::

This process includes the following procedures:

1. Pre-installation Tasks
2. Prepare GCP Project
3. Deploy The Manufacturing Connect through the Google Cloud Marketplace
4. Post-installation Tasks
5. Set Up Google Authentication (optional)

# Before You Begin

- For Google Cloud Platform (GCP): Ensure you have access to a project (with respective project ID) for the Manufacturing Connect instance.
- For Google Cloud Platform (GCP): Ensure you have a **zone&#xA0;**&#x61;nd a respective **region** for the Manufacturing Connect instance to use.
- (Optional) Install Google Manufacturing Data Engine (MDE) to simplify some of the following incoming installation steps.

# Step 1: Pre-deployment Tasks

You can create the necessary GCP infrastructure and deploy the Manufacturing Connect dependencies step-by-step.

## Step 1a: Access the Google Cloud Shell

You will first need to access the Google Cloud Shell to configure the environment.&#x20;

**To access the Google Cloud Shell:**

1. [Access Google Cloud Shell](https://cloud.google.com/shell/docs/launching-cloud-shell) or install `gcloud-cli` using the instructions within [Install the gcloud CLI](https://cloud.google.com/sdk/docs/install)
2. Launch Google Cloud Shell or a local command-line terminal `gcloud-cli` to execute the following incoming commands. **Note**: When asked for any type of permissions, always click **Enable**.

Refer to the following commands to set up the environment.

## Step 1b: Define Initial Environment Variables&#x20;

Use the following commands to define the initial environment variables.&#x20;

```linux
export GCP_PROJECT_ID='your-gcp-project-id'
```

```linux
export REGION='us-central1'
```

```linux
export ZONE='us-central1-c'
```

```linux
export NETWORK_NAME="sfp-private-network"
```

```linux
export SUBNET_NAME="sfp-subnet"
```



```linux
export GKECLUSTER="mc-cluster"
```

## Step 1c: Enable GCP Services

Use the following command to enable GCP services.&#x20;

```linux
gcloud services enable --project=${GCP_PROJECT_ID} container.googleapis.com
```

## Step 1d: (Optional) Install Network

When Manufacturing Data Engine (MDE) is not installed, a network can be instead installed by entering the following command.&#x20;

:::hint{type="info"}
**Note:** Installing Manufacturing Data Engine (MDE) automatically sets up a network.
:::

```linux
gcloud compute networks create "$NETWORK_NAME" --project="$GCP_PROJECT_ID" \
							--description="MDE private network" \
							--subnet-mode=custom \
							--mtu=1460 \
						--bgp-routing-mode=regional
```

```linux
gcloud compute networks subnets create "$SUBNET_NAME" --project="$GCP_PROJECT_ID" \
							--range=10.154.0.0/20 \
							--network="$NETWORK_NAME" \
							--region="$REGION" \
						--enable-private-ip-google-access
```

## Step 1e: Create GKE Cluster

To create a GKE cluster, enter one of the two GKE Cluster Deployment methods:

:::hint{type="warning"}
**Important:** 

- Manufacturing Connect's services are deployed into a Kubernetes cluster. The cluster must be created before deploying the Manufacturing Connect from the Google Cloud Marketplace. `UBUNTU_CONTAINERD` is the only supported image type for GKE nodes. The Manufacturing Connect can be either deployed into a public or private GKE cluster.
- The cluster network where Manufacturing Connect(MC) and Google Manufacturing Data Engine (MDE) are located should be the same to ensure communication between the two.&#x20;
:::

### Public GKE Cluster Deployment &#x20;

To deploy Manufacturing Connect to a public GKE Cluster, enter the following command.&#x20;

:::CodeblockTabs
Linux

```linux
gcloud beta container --project "${GCP_PROJECT_ID}" clusters create $GKECLUSTER --zone "${ZONE}" \
							--no-enable-basic-auth --release-channel "regular" --machine-type "e2-standard-2" --image-type "UBUNTU_CONTAINERD" \
							--disk-type "pd-standard" --disk-size "100" --metadata disable-legacy-endpoints=true \
							--scopes "https://www.googleapis.com/auth/devstorage.read_only","https://www.googleapis.com/auth/logging.write","https://www.googleapis.com/auth/monitoring","https://www.googleapis.com/auth/servicecontrol","https://www.googleapis.com/auth/service.management.readonly","https://www.googleapis.com/auth/trace.append" \
							--max-pods-per-node "110" --num-nodes "3" --logging=SYSTEM,WORKLOAD --monitoring=SYSTEM \
							--enable-ip-alias  --no-enable-intra-node-visibility --default-max-pods-per-node "110" \
							--no-enable-master-authorized-networks --addons HorizontalPodAutoscaling,HttpLoadBalancing,GcePersistentDiskCsiDriver \
							--enable-autoupgrade --enable-autorepair --max-surge-upgrade 1 --max-unavailable-upgrade 0 \
							--maintenance-window-start "2022-05-21T02:00:00Z" --maintenance-window-end "2022-05-22T02:00:00Z" \
							--maintenance-window-recurrence "FREQ=WEEKLY;BYDAY=MO,TU,WE,TH,FR,SA,SU" \
							--workload-pool "${GCP_PROJECT_ID}.svc.id.goog" --enable-shielded-nodes --node-locations "${ZONE}" \
						--network "${NETWORK_NAME}" --subnetwork "${SUBNET_NAME}" --labels "goog-packaged-solution=mfg-mde"
```
:::

### Private GKE Cluster Deployment

To deploy Manufacturing Connect to a private GKE Cluster, enter the following command. Modify Kubernetes control nodes CIDR `--master-ipv4-cidr 10.155.1.0/28` for your network setup.

```linux
gcloud beta container clusters create $GKECLUSTER --project "$GCP_PROJECT_ID" --zone "$ZONE" \
            --no-enable-basic-auth --release-channel "regular" --machine-type "e2-standard-2" --image-type "UBUNTU_CONTAINERD" \
            --disk-type "pd-standard" --disk-size "100" --metadata disable-legacy-endpoints=true \
            --scopes "https://www.googleapis.com/auth/devstorage.read_only","https://www.googleapis.com/auth/logging.write","https://www.googleapis.com/auth/monitoring","https://www.googleapis.com/auth/servicecontrol","https://www.googleapis.com/auth/service.management.readonly","https://www.googleapis.com/auth/trace.append" \
            --max-pods-per-node "110" --num-nodes "3" --logging=SYSTEM,WORKLOAD --monitoring=SYSTEM \
            --enable-ip-alias  --no-enable-intra-node-visibility --default-max-pods-per-node "110" \
            --enable-master-authorized-networks --addons HorizontalPodAutoscaling,HttpLoadBalancing,GcePersistentDiskCsiDriver \
            --enable-autoupgrade --enable-autorepair --max-surge-upgrade 1 --max-unavailable-upgrade 0 \
            --maintenance-window-start "2022-11-21T02:00:00Z" --maintenance-window-end "2022-11-22T02:00:00Z" \
            --maintenance-window-recurrence "FREQ=WEEKLY;BYDAY=MO,TU,WE,TH,FR,SA,SU" \
            --workload-pool "$GCP_PROJECT_ID.svc.id.goog" --enable-shielded-nodes --node-locations "$ZONE" \
            --network "$NETWORK_NAME" --subnetwork "$SUBNET_NAME" --labels "goog-packaged-solution=mfg-mde" \
            --enable-private-nodes --enable-private-endpoint --master-ipv4-cidr 10.155.1.0/28
```

# Step 2: Prepare GCP Project

Follow this guide: [Managing billing for Cloud Marketplace products](https://cloud.google.com/marketplace/docs/manage-billing#before_you_begin)

# Step 3: Deploy Manufacturing Connect through the Google Cloud Marketplace

**To purchase the Manufacturing Connect for a billing account:**

1. Using a Google Cloud Provider Billing Admin role, open [Manufacturing Connect from the Google Marketplace page](https://console.cloud.google.com/kubernetes/application\(cameo\:product/litmus-public/intelligent-manufacturing-connect\)).
2. Click **PURCHASE.**
3. Click the **MANAGE ACCOUNTS** button.
4. Link the service account that was created in the previous step: **Prepare GCP project**.
   - It is advisable to create the service account in the same project where Manufacturing Connect will be deployed.
   - Deleting the service account will disrupt GCP Marketplace Billing and may remove the product license.

**To deploy the Manufacturing Connect to a particular GCP project:**

After you've created a Kubernetes cluster, you can deploy the **Manufacturing Connect** from the [Google Cloud Marketplace.](https://console.cloud.google.com/kubernetes/application\(cameo\:product/litmus-public/intelligent-manufacturing-connect\))

1. Log into the Google Cloud Marketplace.
2. Click the **Configure** button.
3. In dropdown list **Reporting service account**, select the service account name that was created in the previous step: **Prepare GCP Project**.
   - If the Manufacturing Connect is deployed to a private GKE cluster, then select the **Internal Load Balancer** option.

Refer to the following table to learn more about GCP parameters.&#x20;

| **Parameter**                                     | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Existing Kubernetes Cluster**                   | Select the name of the GKE Cluster that was deployed in *Step 1: Pre-installation Tasks*. You can also select **Or Create New Cluster** to specify a different GKE cluster, if needed.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| **Namespace**                                     | This is the namespace where the Manufacturing Connect will be deployed to. You cannot have two identical namespaces in the same Google Kubernetes Engine (GKE) cluster.<br />Create a new namespace. See [Kubernetes Namespaces](https://kubernetes.io/docs/concepts/overview/working-with-objects/namespaces/) for more details.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| **App instance name**                             | This is the application name of the Manufacturing Connect instance. In most situations, it can be left as the default value `intelligent-manufacturing-con-1`. However, if you have multiple Manufacturing Connect instances or multiple applications in your GKE cluster, changing this value will help you uniquely identify each instance.<br />While you could have identical names, this is not recommended to prevent confusion.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| **Use Internal TCP/UDP Load Balancer**            | If the Manufacturing Connect will be deployed to a private GKE cluster, Select **Yes.&#x20;**&#x53;elect **No** otherwise.<br />When **Yes** is selected, then **Frontend Load Balancer static IP address&#x20;**&#x61;nd **Remote Access Load Balancer static IP Address&#x20;**&#x77;ill only be accessible within the Virtual Private Cloud (VPC) network where the private GKE cluster is located. These two addresses will not be connected to the internet.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| **Frontend Load Balancer static IP address**      | This is the load balancer for TCP-based protocols such as HTTPS and MQTT. When specified, it will provide a consistent endpoint for Manufacturing Connect Edge to connect to. This eliminates the need for Manufacturing Connect Edge reactivation in the case of Manufacturing Connect redeployment. Both **Frontend Load Balancer static IP address&#x20;**&#x61;n&#x64;**&#x20;Remote Access Load Balancer static IP address** must be specified to eliminate the need for Manufacturing Connect Edge reactivation.<br />This value cannot be identical to **Remote Access Load Balancer static IP Address.**<br />When an IP address is not specified, Manufacturing Connect will automatically specify a dynamic IP address for this parameter instead. If Manufacturing Connect has to be redeployed, you can obtain the dynamic IP address and specify it as the new **Frontend Load Balancer static IP address**. Otherwise, any Manufacturing Connect Edge connected to the redeployed Manufacturing Connect will have to be [reactivated](docId\:JalA8oA1dTK8BdVoENAwA).  |
| **Remote Access Load Balancer static IP Address** | This is the load balancer for UDP-based protocols. When specified, it will provide a consistent endpoint for Manufacturing Connect Edge to connect to. This eliminates the need for Manufacturing Connect Edge reactivation in the case of Manufacturing Connect redeployment. Both **Frontend Load Balancer static IP address&#x20;**&#x61;n&#x64;**&#x20; Remote Access Load Balancer static IP address** must be specified to eliminate the need for Manufacturing Connect Edge reactivation.<br />This value cannot be identical to **Frontend Load Balancer static IP address.**<br />When an IP address is not specified, Manufacturing Connect will automatically specify a dynamic IP address for this parameter instead. If Manufacturing Connect has to be redeployed, you can obtain the dynamic IP address and specify it as the new **Remote Access Load Balancer static IP Address**. Otherwise, any Manufacturing Connect Edge connected to the redeployed Manufacturing Connect will have to be [reactivated](docId\:JalA8oA1dTK8BdVoENAwA).                        |
| **RemoteAccess network for Edge devices**         | This is the network range used for communication between Manufacturing Connect and Manufacturing Connect Edge. By default, this range is `192.168.127.0/24`.<br />If your internal network uses this same range, then there is a potential for conflict. You may not be able to access a Manufacturing Connect Edge remotely from Manufacturing Connect.  Likewise, if you have third-party software (for example, an MQTT server) located in this IP range, your Manufacturing Connect Edge will not be able to access the software (in this case, fail to connect to the MQTT server).<br />Specify a different range to avoid IP address conflict.                                                                                                                                                                                                                                                                                                                                                                                                                               |
| **MDE integration topic**                         | By default, this is `input-messages`. When you deploy MDE (and the Pub/Sub topic was changed), change this value to the equivalent MDE deployment Pub/Sub topic.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| **Create new service account**                    | Select the service account name that was created in *Step 2: Prepare GCP Project*.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |

After the project is successfully deployed, you will receive an IP address on where the Manufacturing Connect is located.

:::hint{type="info"}
**Note**: After Manufacturing Connect is deployed, it will automatically attempt to [Activate the License Server](docId\:BdTZOr5AZx0Yafvh9JtcP) and receive a site license from the license server. This site license will be later used to activate Manufacturing Connect edge instances that use the site-license. If the Manufacturing Connect is located on a private network, then you must [Activate the License Server](docId\:BdTZOr5AZx0Yafvh9JtcP) manually.
:::

# Step 4: Post-deployment Tasks

Refer to the following post-deployment tasks.&#x20;

## Verify Site License Installation

1. Log in to Manufacturing Connect Admin Console. See the *Access the Admin Console* section of [Access to Manufacturing Connect](docId\:my_EU8guLSwCsytRr5zIV) for details.
2. From the Navigation panel, select **License Server**.   The *License Server Management* pane appears.&#x20;
3. From *Core license list*, verify there is a license. If no license exists, you must [Activate the License Server](docId\:BdTZOr5AZx0Yafvh9JtcP).&#x20;

::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/WmTZwQxhx00YU4tWFPffi_image.png" size="80" width="1710" height="251" position="flex-start" caption="MC Admin Console : License Server:Core license installed" darkWidth="1710" darkHeight="251" showCaption="true" indent="2"}

## Change Initial Credentials (Mandatory)

1. Open [GKE applications list](https://console.cloud.google.com/kubernetes/application) in your GCP project.
2. Click the Kubernetes application which was just installed.
3. Click the **Show Info** Panel.
4. From the **Show Info** Panel, follow instructions to get the application URLs and initial credentials.
5. Change the MC Admin password.
6. Change the MC Keycloak Admin password.

## Upload GCP Credentials (Mandatory)

1. Open the MC Admin Console.
2. Click **Settings/Cloud Settings**.&#x20;
   See [Cloud Settings](docId:5qmRCk-SoDaAvKPtB58KN) for more details.
3. Follow instructions for **Generate Key** in the *Cloud Credentials* section.

## Set GCS Bucket (Optional)

1. Open MC Admin Console.
2. Click **Settings/Cloud Settings**.
3. Select **Google Cloud Storage** in *Storage&#x20;*&#x73;ettings.
4. To create a bucket, follow instructions for **Create bucket.**
5. Set bucket name.
6. Click **Save**.

## Associate a Domain Name with MC Instance

This is mandatory only if Google Authorization is needed for the MC instance.

1. Associate MC external IP address with a domain name.
2. Open the MC Admin Console.
3. Open **Settings/Entrypoints**.
4. Set the new domain name.
5. Click **Save**.

# Step 5: Setup Google Authentication (optional)

If Google Authentication is desired for the Manufacturing Connect instance, a domain name must be associated with the Manufacturing Connect instance.

## OAuth Consent Screen

1. Open the [APIs & Services OAuth consent](https://console.cloud.google.com/apis/credentials/consent) screen.
2. Select **External&#x20;**&#x74;ype.

:::hint{type="info"}
**Note:** In testing mode, **External** allows add up to 100 Google accounts from any organization. **Internal** type allows only users within the current organization.
:::

&#x20;    3\. On the next screen set mandatory attributes.

- App Name
- User support email
- Add authorized domain

:::hint{type="info"}
**Example:** If for Manufacturing Connect we use domain name `test.mc.domain.com`, then use `domain.com` as an authorized domain.
:::

- Developer contact information

## Create OAuth 2.0 Credentials

1. Open the [APIs & Services OAuth credentials](https://console.cloud.google.com/apis/credentials) screen.
2. Create OAuth client ID with the following field-value pairs.
   - **Application type**: Web application
   - **Authorized redirect url**: `https://<your-domain>/auth/realms/standalone/broker/google/endpoint`

## Set up Manufacturing Connect Keycloak

1. Open the Keycloak Admin console.
2. Click **Identity Providers**.
3. Select **Google** from the list
4. Set **Client ID** and **Secret ID** values from the previous step: **Create OAuth 2.0 credentials**.
5. Set First Login Flow to **google-login**.
6. Click **Save**.

## Grant Permissions to Your Email Accounts

1. Open the MC Admin Console.
2. Click **Users**.
3. Add a new user (set up your Google email or another email account.).
4. Enable the user.
5. Grant Admin role if required.

***

# Upgrade Manufacturing Connect

Refer to the following steps to upgrade Manufacturing Connect (MC).&#x20;

See the [Manufacturing Connect installation guide](https://github.com/litmusautomation/mc-gcp-marketplace#upgrading-manufactring-connect) from GitHub to learn more.&#x20;

## Step 1: Retrieve the Git Repository

```linux
git clone https://github.com/litmusautomation/mc-gcp-marketplace.git
```

## Step 2: Enter the Retrieved Repository

```linux
cd mc-gcp-marketplace
```

## Step 3: Run Upgrade Script

```linux
./upgrade-mc.sh $GCP_PROJECT_ID $ZONE $GKECLUSTER $NAMESPACE $TARGET_VERSION
```

**Specify the following parameters:**

- `$GCP_PROJECT_ID` is the Google Cloud Platform (GCP) project ID.
- `$ZONE` is the Zone where GKE cluster is deployed.
- `$GKECLUSTER` is the GKE cluster name.
- `$NAMESPACE` is the Kubernetes namespace where Manufacturing Connect is deployed.
- `$TARGET_VERSION` is the required Manufacturing Connect target version, for example `2.31.1-150`.

The following table shows `$TARGET_VERSION` values that you use for specific Long-Term Supported (LTS) releases.

| **LTS&#x20;** | **$Target\_Version Value** |
| ------------- | -------------------------- |
| 2.31.5        | 2.31.5-150                 |
| 2.31.4        | 2.31.4-150                 |
| 2.31.2        | 2.31.2-150                 |
| 2.26.4        | 2.26.3-150                 |

