For the latest version, please use Virtual Appliance 1.0.3!

Export bundle archives

Use a connected workstation to export a release or update bundle for browser upload to Management. For a fresh air-gapped installation, export the release bundle only. If Management can reach the registry, follow Connected installation to retrieve the release directly.

Management image preparation is covered in Prepare the Management container image. Appliance boot images and checksums are on Download appliance boot media.

Check the Docker version requirements before running the commands below.

Choose the bundle

Image repository Purpose and tag

repo.mtg.de/releases/ers/vapp/release-bundle

Full installation and recovery content. The tag is the appliance release to install or recover.

repo.mtg.de/releases/ers/vapp/update-bundle

One supported update transition. The tag has the form SOURCE-to-TARGET. Both versions must match a transition published by MTG.

An update bundle is available only for a published source-to-target transition; do not assume that an update exists for every pair of releases. See Files and Bundles.

Sign in to the MTG repository

Enter the MTG repository username. Docker then prompts for the MTG-provided password or token. Continue only after login succeeds.

The export examples use docker image save --platform. Both the Docker CLI and engine must meet the version requirements above.

read -r -p 'MTG repository username: ' MTG_REPOSITORY_USER
docker login repo.mtg.de --username "$MTG_REPOSITORY_USER"

Pull the bundle

Replace the placeholder tags with those supplied for your release. Pull only the images required for your task.

Management runs the bundle’s Operations code on its own CPU architecture. Select the same platform as the destination Management engine, even though the appliance nodes use AMD64. Use linux/arm64 when the destination engine is ARM64 and MTG supplies that variant.

MANAGEMENT_PLATFORM='linux/amd64'
RELEASE_TAG='REPLACE_WITH_APPLIANCE_RELEASE'
UPDATE_TAG='REPLACE_WITH_SOURCE-to-TARGET'

RELEASE_IMAGE="repo.mtg.de/releases/ers/vapp/release-bundle:${RELEASE_TAG}"
UPDATE_IMAGE="repo.mtg.de/releases/ers/vapp/update-bundle:${UPDATE_TAG}"
docker pull --platform "$MANAGEMENT_PLATFORM" "$RELEASE_IMAGE"
# Only when MTG has published the required update transition:
docker pull --platform "$MANAGEMENT_PLATFORM" "$UPDATE_IMAGE"

A successful pull puts the image in Docker’s local image store. It does not install an update or import a bundle into Management.

Save bundles for browser upload

Browser uploads of release and update bundles require an OCI image archive with its full tagged image reference. Export the complete bundle image; do not use container filesystem export or extract only the inner content file.

Use Docker’s containerd image store to save the bundle directly as an OCI-compatible archive. It must be enabled in the engine used for the pull and save. Export one tagged bundle image for the destination Management platform:

docker image save --platform "$MANAGEMENT_PLATFORM" --output release.oci.tar "$RELEASE_IMAGE"

# Only for a published update that you pulled above:
docker image save --platform "$MANAGEMENT_PLATFORM" --output update.oci.tar "$UPDATE_IMAGE"

Upload the saved file directly to Management. No conversion tool is required. The classic Docker image store produces a different archive layout; changing the filename to .oci.tar does not change that format.

The archives must retain the full repo.mtg.de/…​:tag reference. Upload the resulting release or update archive through Settings > Bundles > Add bundle > Computer > Release or update. Wait until Management reports the bundle as available and check its target version and, for updates, its source version. See Manage bundles and registries.

Verify downloads and sign out

Repository credentials are separate from the mtg-admin account used to sign in to Management. A successful local CLI login does not populate Settings > Registries. Configure that connection separately if Management will retrieve bundles itself.

Keep certificate verification enabled when logging in and pulling. For a company proxy or private CA, configure trust in the container engine. Record the image reference and digest reported by the pull with your deployment records. Verify transferred files against their recorded SHA-256 checksums before loading or uploading them.

After completing downloads, remove the local registry login when it is no longer needed:

docker logout repo.mtg.de

For CLI details, see Docker image save.

Appliance boot media

See Download appliance boot media for the public download links and checksums.