I'm running into problems with install bundles for airgapped clusters

Hi,
I am encountering problems when attempting to update versions on airgapped kURL clusters if the new version needs to update by more than 1 Kubernetes version. I know that an installer bundle contains only one version of each add-on. I created additional bundles to update the Kubernetes version iteratively, but the problem I’m having is that only the kubeadm gets updated. The kubelet and kubectl don’t.

The first problem I had was that I took the instructions literally (I don’t actually know that being literal was the problem, but it seems likely.):

⚙  Downloading assets required for Kubernetes 1.30.7 to 1.33.4 upgrade
The following packages are not available locally, and are required:
kubernetes-1.31.14.tar.gz
kubernetes-1.32.12.tar.gz

You can download them with the following command:

curl -LO https://kurl.sh/bundle/version/v2026.02.24-0/c9f92c5/packages/kubernetes-1.31.14,kubernetes-1.32.12.tar.gz

So instead I created installation bundles that would only change the Kubernetes version, iteratively, and ran them. But I encountered messages that looked like this:

[upgrade] SUCCESS! A control plane node of your cluster was upgraded to "v1.33.4".

[upgrade] Now please proceed with upgrading the rest of the nodes by following the right order.
⚙  Install kubelet, kubectl and cni host packages
⚙  Installing host packages kubelet-1.33.4 kubectl-1.33.4
kURL kubernetes-1.33.4 Local Repo               414 kB/s | 3.9 kB     00:00
All matches were filtered out by exclude filtering for argument: kubelet-1.33.4
All matches were filtered out by exclude filtering for argument: kubectl-1.33.4
Error: Unable to find a match: kubelet-1.33.4 kubectl-1.33.4
An error occurred on line 3084

I was unable to just run the install command again because the pods in the kurl namespace (etcd and the two registry pods) were stuck in Pending.

What allowed me to proceed was to manually update the kubelet by this procedure:
Download the kubelet with a command like this (on a different machine)
curl -LO https://dl.k8s.io/v1.33.4/kubernetes-server-linux-amd64.tar.gz
then after pushing the tarball to the airgapped VM, I ran the following commands:

tar -xzf kubernetes-server-linux-amd64.tar.gz
cd kubernetes/server/bin
sudo systemctl stop kubelet
sudo mv /usr/bin/kubelet /usr/bin/kubelet-backup
sudo cp kubelet /usr/bin/
sudo systemctl daemon-reexec
sudo systemctl start kubelet
sudo systemctl enable kubelet
kubelet --version
kubectl uncordon <nodeName>
kubectl rollout restart sts -n knime
kubectl rollout restart deployments -n knime

That allowed me to proceed, but even so, I ended up with the versions of kubeadm, kubelet, and kubectl not matching (at least insofar as the client version of kubectl was still old).
So then I separately downloaded kubectl on a separate machine:
curl -LO "https://dl.k8s.io/release/v1.33.4/bin/linux/amd64/kubectl"
And then pushed that to the airgapped VM, and moved kubectl to /usr/bin (/usr/local/bin didn’t work).

So my question is how do I get this to work correctly, airgapped, on RHEL? (I don’t know that RHEL is any different from Ubuntu, but I don’t recall having this particular problem in the past.)

I was able to work through it, eventually, but this is not as clean as I would like for my customers.

@lepome I’m glad to hear you managed to get past the upgrade hurdle. Could you let me know what part in the upgrade flow you’d like to see reduced friction? You can paste commands from the latest successful upgrade steps you ran. Also, feel free to raise a support ticket in support.replicated.com if you would like to share more sensitive details.

The commands that allowed me to complete the update are those I provided. I would have preferred, however, if I could have skipped the parts where I got the error message and then iterative steps downloading kubelet for each version, and also the separate download and push of kubectl.

I would have preferred if the multiple versions of Kubernetes could be installed with a single download and push, and if that’s not possible, then with a single download and push for each version. Having to download kubelet and kubectl separately was not documented. (Note that this kind of process is necessary when Airgapped instances are updated from older versions because the default installer from the download portal is only the very latest one, so neither does it include multiple versions of Kubernetes, which must be iteratively updated, nor does it include the older versions of other packages.)

I’m also providing a link to my Box location where you can see a recording of the install that didn’t complete on its own, and .yaml files that I used to create intermediate steps in the update path. (KNIME tends to update in bursts.)

Here is a summary Claude wrote:

Hi Evans,

Thank you for following up. The friction is in the host-package step at the end of each Kubernetes-only installer bundle on airgapped RHEL. kubeadm upgrades successfully, but the kubelet and kubectl packages are not installed. Here is a recent example (1.33.4 to 1.34.11, on the way to 1.35.7):

[upgrade] SUCCESS! A control plane node of your cluster was upgraded to "v1.34.11".
Install kubelet, kubectl and cni host packages
Installing host packages kubelet-1.34.11 kubectl-1.34.11
kURL kubernetes-1.34.11 Local Repo   474 kB/s | 3.9 kB   00:00
All matches were filtered out by exclude filtering for argument: kubelet-1.34.11
All matches were filtered out by exclude filtering for argument: kubectl-1.34.11
Error: Unable to find a match: kubelet-1.34.11 kubectl-1.34.11
An error occurred on line 3085

The installer does not recover on a rerun, because the etcd and two registry pods in the kurl namespace are stuck in Pending.

This is what I ran to get past it. On a connected machine:

curl -LO https://dl.k8s.io/v1.34.11/kubernetes-server-linux-amd64.tar.gz
curl -LO "https://dl.k8s.io/release/v1.34.11/bin/linux/amd64/kubectl"

Then, after copying both files to the airgapped VM:

tar -xzf kubernetes-server-linux-amd64.tar.gz
cd kubernetes/server/bin
sudo systemctl stop kubelet
sudo mv /usr/bin/kubelet /usr/bin/kubelet-backup
sudo cp kubelet /usr/bin/
sudo systemctl daemon-reexec
sudo systemctl start kubelet
sudo systemctl enable kubelet
kubelet --version
kubectl uncordon <nodeName>
kubectl rollout restart sts -n knime
kubectl rollout restart deployments -n knime

For kubectl, I copied the downloaded binary to /usr/bin (/usr/local/bin did not work). I had to repeat this after every Kubernetes step of the update.

My questions:

  1. What causes the “filtered out by exclude filtering” message for kubelet and kubectl from the kURL local repo on RHEL?
  2. Is there a supported way to get kubelet and kubectl updated by the installer itself, so the manual steps are not needed?
  3. Is there a supported way to go directly across several Kubernetes minor versions in an airgapped install, without building one installer bundle per version?

Thanks,
Lisa

Also, in case it matters:
NAME=“Red Hat Enterprise Linux”
VERSION=“9.6 (Plow)”
ID=“rhel”
ID_LIKE=“fedora”
VERSION_ID=“9.6”
PLATFORM_ID=“platform:el9”
PRETTY_NAME=“Red Hat Enterprise Linux 9.6 (Plow)”
ANSI_COLOR=“0;31”
LOGO=“fedora-logo-icon”
CPE_NAME=“cpe:/o:redhat:enterprise_linux:9::baseos”
HOME_URL=“https://www.redhat.com/”
DOCUMENTATION_URL=“https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9”
BUG_REPORT_URL=“https://issues.redhat.com/”

REDHAT_BUGZILLA_PRODUCT=“Red Hat Enterprise Linux 9”
REDHAT_BUGZILLA_PRODUCT_VERSION=9.6
REDHAT_SUPPORT_PRODUCT=“Red Hat Enterprise Linux”
REDHAT_SUPPORT_PRODUCT_VERSION=“9.6”

NAME                               STATUS   ROLES                  AGE   VERSION   INTERNAL-IP   EXTERNAL-IP   OS-IMAGE                              KERNEL-VERSION                 CONTAINER-RUNTIME
i-0694d6fafa3d26701.ec2.internal   Ready    control-plane,master   96d   v1.35.7   10.0.1.215    <none>        Red Hat Enterprise Linux 9.6 (Plow)   5.14.0-570.62.1.el9_6.x86_64   containerd://1.7.29

Now I have a cleaner workaround: After downloading using the peculiar-looking command
curl -LO https://kurl.sh/bundle/version/v2026.02.24-0/c9f92c5/packages/kubernetes-1.31.14,kubernetes-1.32.12.tar.gz
I also used
curl -LO https://kurl.sh/bundle/version/v2026.01.13-0/2578085/packages/kubernetes-1.31.14.tar.gz
and
curl -LO https://kurl.sh/bundle/version/v2026.02.24-0/2578085/packages/kubernetes-1.32.12.tar.gz

then pushed all three files to the airgapped computer.

If I untar the installer and load images, it still fails, but if after that failure I untar the kubernetes package and load images, then the upgrade using the installer works.

tar -xvzf kubernetes-1.31.14.tar.gz
cat tasks.sh | sudo bash -s load-images
cat install.sh | sudo bash -s airgap installer-spec-file="./patch.yaml"