Skip to content

Openshift/OKD related changes to helm charts - #1118

Open
fruboes wants to merge 10 commits into
lsst:mainfrom
lsst-pl:2026.9.4-rc1-openshift
Open

fruboes wants to merge 10 commits into
lsst:mainfrom
lsst-pl:2026.9.4-rc1-openshift

Conversation

@fruboes

@fruboes fruboes commented Oct 2, 2026

Copy link
Copy Markdown

This PR contains changes necessary to use qserv helm chart in Openshift/OKD. Each change/addition is guarded with a {{ if .Values.openshift }} conditional, with the controlling value set to false in top level values.yaml file. Three main problems are covered:

  1. openshift/okd by default randomizes uid/gid with which container is executed and disallows hardcoded values, e.g. defined on Dockerfile level. To workaround this a service account is created along with SecurityContextConstraint allowing for specific gid/uid (1000) to be used. This service account is used for all types of pods (worker/czar/...) for which this is necessary
  2. openshift/okd does not allow for modifications of files/directories of underlying container image. This is handled by adding emptyDir volumes where necessary
  3. openshift/okd by default prohibits pod binding to ports <1024. This is handled by going with the port to higher value (e.g. 80 -> 8080) . Note: having Service with port <1024 (80 in our case) is OK.

Please let me know if this could be merged, i.e. if there is anything that needs to be changed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant