From 4c9336d38d348463bfdd169117bdef17fd020d8f Mon Sep 17 00:00:00 2001 From: Fortune-Ndlovu Date: Wed, 16 Sep 2026 14:25:11 +0100 Subject: [PATCH 01/25] feat(orchestrator-infra): add OLM v1 ClusterExtension install path Add olmVersion (v0|v1|auto) to select between classic Subscriptions and OLM v1 ClusterExtensions for Serverless and Serverless Logic operators. Includes installer ServiceAccount and ClusterRoleBinding for the v1 path, updates helm tests, docs, and schema. Scope limited to orchestrator-infra per RHIDP-14789 review feedback. RHIDP-14789 Signed-off-by: Fortune Ndlovu --- charts/orchestrator-infra/Chart.yaml | 2 +- charts/orchestrator-infra/README.md | 25 +- .../ci/upstream-olm-v1-values.yaml | 14 + .../orchestrator-infra/templates/_helpers.tpl | 41 +++ .../serverless-logic/clusterextension.yaml | 50 +++ .../serverless-logic/subscription.yaml | 2 +- .../serverless/clusterextension.yaml | 49 +++ .../templates/serverless/subscription.yaml | 2 +- .../templates/tests/infra-test.yaml | 42 ++- charts/orchestrator-infra/values.schema.json | 287 ++++++++++-------- .../values.schema.tmpl.json | 40 +++ charts/orchestrator-infra/values.yaml | 11 + 12 files changed, 435 insertions(+), 130 deletions(-) create mode 100644 charts/orchestrator-infra/ci/upstream-olm-v1-values.yaml create mode 100644 charts/orchestrator-infra/templates/serverless-logic/clusterextension.yaml create mode 100644 charts/orchestrator-infra/templates/serverless/clusterextension.yaml diff --git a/charts/orchestrator-infra/Chart.yaml b/charts/orchestrator-infra/Chart.yaml index ee2f999f0..5bbf1db4f 100644 --- a/charts/orchestrator-infra/Chart.yaml +++ b/charts/orchestrator-infra/Chart.yaml @@ -14,4 +14,4 @@ maintainers: type: application sources: - https://github.com/redhat-developer/rhdh-chart -version: 0.6.1 +version: 0.6.2 diff --git a/charts/orchestrator-infra/README.md b/charts/orchestrator-infra/README.md index 8492219d4..c860c0b31 100644 --- a/charts/orchestrator-infra/README.md +++ b/charts/orchestrator-infra/README.md @@ -1,7 +1,7 @@ # Orchestrator Infra Chart for OpenShift -![Version: 0.6.1](https://img.shields.io/badge/Version-0.6.1-informational?style=flat-square) +![Version: 0.6.2](https://img.shields.io/badge/Version-0.6.2-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) Helm chart to deploy the Orchestrator solution's required infrastructure suite on OpenShift, including OpenShift Serverless Operator and OpenShift Serverless Logic Operator, both required to configure Red Hat Developer Hub to use the Orchestrator. @@ -25,7 +25,7 @@ Kubernetes: `>= 1.25.0-0` ```console helm repo add redhat-developer https://redhat-developer.github.io/rhdh-chart -helm install my-orchestrator-infra redhat-developer/redhat-developer-hub-orchestrator-infra --version 0.6.1 +helm install my-orchestrator-infra redhat-developer/redhat-developer-hub-orchestrator-infra --version 0.6.2 ``` > **Tip**: List all releases using `helm list` @@ -83,6 +83,8 @@ The command removes all the Kubernetes components associated with the chart and | Key | Description | Type | Default | |-----|-------------|------|---------| +| olmVersion | OLM API version to use for operator installation (`v0`, `v1`, or `auto`) | string | `"auto"` | +| serverlessLogicOperator.clusterExtension.serviceAccount.name | service account used by OLM v1 to install the operator | string | `"serverless-logic-operator-installer"` | | serverlessLogicOperator.enabled | whether the operator should be deployed by the chart | bool | `true` | | serverlessLogicOperator.subscription.namespace | namespace where the operator should be deployed | string | `"openshift-serverless-logic"` | | serverlessLogicOperator.subscription.spec.channel | channel of an operator package to subscribe to | string | `"stable"` | @@ -92,6 +94,7 @@ The command removes all the Kubernetes components associated with the chart and | serverlessLogicOperator.subscription.spec.sourceNamespace | | string | `"openshift-marketplace"` | | serverlessLogicOperator.subscription.spec.startingCSV | The initial version of the operator, must match CRDs installed by the chart | string | `"logic-operator.v1.38.0"` | | serverlessOperator.enabled | whether the operator should be deployed by the chart | bool | `true` | +| serverlessOperator.clusterExtension.serviceAccount.name | service account used by OLM v1 to install the operator | string | `"serverless-operator-installer"` | | serverlessOperator.subscription.namespace | namespace where the operator should be deployed | string | `"openshift-serverless"` | | serverlessOperator.subscription.spec.channel | channel of an operator package to subscribe to | string | `"stable"` | | serverlessOperator.subscription.spec.installPlanApproval | whether the update should be installed automatically | string | `"Manual"` | @@ -101,6 +104,24 @@ The command removes all the Kubernetes components associated with the chart and | tests.enabled | Whether to create the test pod used for testing the Release using `helm test`. | bool | `true` | | tests.image | Test pod image | string | `"bitnami/kubectl:latest"` | +### OLM v0 and OLM v1 operator installation + +By default, the chart uses `olmVersion: auto` to select the OLM API: + +- **`v0`** — creates `Subscription` resources (classic OLM) +- **`v1`** — creates `ClusterExtension` resources with installer ServiceAccount and ClusterRoleBinding (OLM v1) +- **`auto`** — uses OLM v1 when the `clusterextensions.olm.operatorframework.io` CRD is present, otherwise OLM v0 + +Examples: + +```bash +# Force classic OLM Subscriptions +helm install my-orchestrator-infra ./charts/orchestrator-infra --set olmVersion=v0 + +# Force OLM v1 ClusterExtensions (requires OLM v1 on the cluster) +helm install my-orchestrator-infra ./charts/orchestrator-infra --set olmVersion=v1 +``` + ### Installing Knative Eventing and Knative Serving CRDs The orchestrator-infra chart requires several CRDs for Knative Eventing and Knative Serving. These CRDs will be applied prior to installing the chart, ensuring that Knative CRs can be created as part of the chart's deployment process. This approach eliminates the need to wait for the OpenShift Serverless Operator's subscription to install them beforehand. diff --git a/charts/orchestrator-infra/ci/upstream-olm-v1-values.yaml b/charts/orchestrator-infra/ci/upstream-olm-v1-values.yaml new file mode 100644 index 000000000..2cb764810 --- /dev/null +++ b/charts/orchestrator-infra/ci/upstream-olm-v1-values.yaml @@ -0,0 +1,14 @@ +olmVersion: v1 + +serverlessLogicOperator: + enabled: true + subscription: + namespace: operators + spec: + sourceNamespace: olm + +serverlessOperator: + subscription: + namespace: operators + spec: + sourceNamespace: olm diff --git a/charts/orchestrator-infra/templates/_helpers.tpl b/charts/orchestrator-infra/templates/_helpers.tpl index 5db6043ee..5af8dd67e 100644 --- a/charts/orchestrator-infra/templates/_helpers.tpl +++ b/charts/orchestrator-infra/templates/_helpers.tpl @@ -34,4 +34,45 @@ {{- else -}} {{- "false" -}} {{- end -}} +{{- end -}} + +{{- define "olm-version" -}} + {{- $requested := default "auto" .Values.olmVersion -}} + {{- if eq $requested "auto" -}} + {{- if .Capabilities.APIVersions.Has "olm.operatorframework.io/v1/ClusterExtension" -}} + {{- "v1" -}} + {{- else -}} + {{- "v0" -}} + {{- end -}} + {{- else -}} + {{- $requested -}} + {{- end -}} +{{- end -}} + +{{- define "unmanaged-clusterextension-exists" -}} + {{- $name := index . 0 -}} + {{- $releaseName := index . 1 -}} + {{- $apiCapabilities := index . 2 -}} + {{- if $apiCapabilities.Has "olm.operatorframework.io/v1/ClusterExtension" -}} + {{- $existingExtension := lookup "olm.operatorframework.io/v1" "ClusterExtension" "" $name -}} + {{- if empty $existingExtension -}} + {{- "false" -}} + {{- else -}} + {{- $isManagedResource := include "is-managed-resource" (list $existingExtension $releaseName) -}} + {{- if eq $isManagedResource "true" -}} + {{- "false" -}} + {{- else -}} + {{- "true" -}} + {{- end -}} + {{- end -}} + {{- else -}} + {{- "false" -}} + {{- end -}} +{{- end -}} + +{{- define "csv-version" -}} + {{- $csv := index . 0 -}} + {{- $packageName := index . 1 -}} + {{- $version := trimPrefix (printf "%s." $packageName) $csv -}} + {{- trimPrefix "v" $version -}} {{- end -}} \ No newline at end of file diff --git a/charts/orchestrator-infra/templates/serverless-logic/clusterextension.yaml b/charts/orchestrator-infra/templates/serverless-logic/clusterextension.yaml new file mode 100644 index 000000000..e680df772 --- /dev/null +++ b/charts/orchestrator-infra/templates/serverless-logic/clusterextension.yaml @@ -0,0 +1,50 @@ +{{- $packageName := .Values.serverlessLogicOperator.subscription.spec.name -}} +{{- $namespace := .Values.serverlessLogicOperator.subscription.namespace -}} +{{- $serviceAccountName := .Values.serverlessLogicOperator.clusterExtension.serviceAccount.name -}} +{{- $unmanagedClusterExtensionExists := include "unmanaged-clusterextension-exists" (list $packageName .Release.Name .Capabilities.APIVersions) -}} +{{- if and (eq (include "olm-version" .) "v1") (eq $unmanagedClusterExtensionExists "false") .Values.serverlessLogicOperator.enabled }} +apiVersion: v1 +kind: ServiceAccount +metadata: + name: {{ $serviceAccountName }} + namespace: {{ $namespace }} + annotations: + meta.helm.sh/release-name: {{ .Release.Name }} + meta.helm.sh/release-namespace: {{ .Release.Namespace }} +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + name: {{ $packageName }}-installer-binding + annotations: + meta.helm.sh/release-name: {{ .Release.Name }} + meta.helm.sh/release-namespace: {{ .Release.Namespace }} +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + name: cluster-admin +subjects: + - kind: ServiceAccount + name: {{ $serviceAccountName }} + namespace: {{ $namespace }} +--- +apiVersion: olm.operatorframework.io/v1 +kind: ClusterExtension +metadata: + name: {{ $packageName }} + annotations: + meta.helm.sh/release-name: {{ .Release.Name }} + meta.helm.sh/release-namespace: {{ .Release.Namespace }} +spec: + namespace: {{ $namespace }} + serviceAccount: + name: {{ $serviceAccountName }} + source: + sourceType: Catalog + catalog: + packageName: {{ $packageName }} + channels: + - {{ .Values.serverlessLogicOperator.subscription.spec.channel }} + version: {{ include "csv-version" (list .Values.serverlessLogicOperator.subscription.spec.startingCSV $packageName) | quote }} + upgradeConstraintPolicy: CatalogProvided +{{- end }} diff --git a/charts/orchestrator-infra/templates/serverless-logic/subscription.yaml b/charts/orchestrator-infra/templates/serverless-logic/subscription.yaml index 9980da02d..070f6f895 100644 --- a/charts/orchestrator-infra/templates/serverless-logic/subscription.yaml +++ b/charts/orchestrator-infra/templates/serverless-logic/subscription.yaml @@ -1,5 +1,5 @@ {{- $unmanagedSubscriptionExists := include "unmanaged-resource-exists" (list "operators.coreos.com/v1alpha1" "Subscription" .Values.serverlessLogicOperator.subscription.namespace .Values.serverlessLogicOperator.subscription.spec.name .Release.Name .Capabilities.APIVersions ) }} -{{- if and (eq $unmanagedSubscriptionExists "false") .Values.serverlessLogicOperator.enabled }} +{{- if and (eq (include "olm-version" .) "v0") (eq $unmanagedSubscriptionExists "false") .Values.serverlessLogicOperator.enabled }} apiVersion: operators.coreos.com/v1alpha1 kind: Subscription metadata: diff --git a/charts/orchestrator-infra/templates/serverless/clusterextension.yaml b/charts/orchestrator-infra/templates/serverless/clusterextension.yaml new file mode 100644 index 000000000..739b798e0 --- /dev/null +++ b/charts/orchestrator-infra/templates/serverless/clusterextension.yaml @@ -0,0 +1,49 @@ +{{- $packageName := .Values.serverlessOperator.subscription.spec.name -}} +{{- $namespace := .Values.serverlessOperator.subscription.namespace -}} +{{- $serviceAccountName := .Values.serverlessOperator.clusterExtension.serviceAccount.name -}} +{{- $unmanagedClusterExtensionExists := include "unmanaged-clusterextension-exists" (list $packageName .Release.Name .Capabilities.APIVersions) -}} +{{- if and (eq (include "olm-version" .) "v1") (eq $unmanagedClusterExtensionExists "false") .Values.serverlessOperator.enabled }} +apiVersion: v1 +kind: ServiceAccount +metadata: + name: {{ $serviceAccountName }} + namespace: {{ $namespace }} + annotations: + meta.helm.sh/release-name: {{ .Release.Name }} + meta.helm.sh/release-namespace: {{ .Release.Namespace }} +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + name: {{ $packageName }}-installer-binding + annotations: + meta.helm.sh/release-name: {{ .Release.Name }} + meta.helm.sh/release-namespace: {{ .Release.Namespace }} +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + name: cluster-admin +subjects: + - kind: ServiceAccount + name: {{ $serviceAccountName }} + namespace: {{ $namespace }} +--- +apiVersion: olm.operatorframework.io/v1 +kind: ClusterExtension +metadata: + name: {{ $packageName }} + annotations: + meta.helm.sh/release-name: {{ .Release.Name }} + meta.helm.sh/release-namespace: {{ .Release.Namespace }} +spec: + namespace: {{ $namespace }} + serviceAccount: + name: {{ $serviceAccountName }} + source: + sourceType: Catalog + catalog: + packageName: {{ $packageName }} + channels: + - {{ .Values.serverlessOperator.subscription.spec.channel }} + upgradeConstraintPolicy: CatalogProvided +{{- end }} diff --git a/charts/orchestrator-infra/templates/serverless/subscription.yaml b/charts/orchestrator-infra/templates/serverless/subscription.yaml index 00fed973d..3510555fb 100644 --- a/charts/orchestrator-infra/templates/serverless/subscription.yaml +++ b/charts/orchestrator-infra/templates/serverless/subscription.yaml @@ -1,5 +1,5 @@ {{- $unmanagedSubscriptionExists := include "unmanaged-resource-exists" (list "operators.coreos.com/v1alpha1" "Subscription" .Values.serverlessOperator.subscription.namespace .Values.serverlessOperator.subscription.spec.name .Release.Name .Capabilities.APIVersions ) }} -{{- if and (eq $unmanagedSubscriptionExists "false") .Values.serverlessOperator.enabled }} +{{- if and (eq (include "olm-version" .) "v0") (eq $unmanagedSubscriptionExists "false") .Values.serverlessOperator.enabled }} apiVersion: operators.coreos.com/v1alpha1 kind: Subscription metadata: diff --git a/charts/orchestrator-infra/templates/tests/infra-test.yaml b/charts/orchestrator-infra/templates/tests/infra-test.yaml index d4f5f4d5b..184f441fc 100644 --- a/charts/orchestrator-infra/templates/tests/infra-test.yaml +++ b/charts/orchestrator-infra/templates/tests/infra-test.yaml @@ -68,6 +68,36 @@ roleRef: name: test-role-osl apiGroup: rbac.authorization.k8s.io --- +{{- if eq (include "olm-version" .) "v1" }} +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + name: test-role-clusterextensions + annotations: + helm.sh/hook: test + helm.sh/hook-delete-policy: before-hook-creation, hook-succeeded, hook-failed +rules: + - apiGroups: ["olm.operatorframework.io"] + resources: ["clusterextensions"] + verbs: ["list", "get"] +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + name: test-role-binding-clusterextensions + annotations: + helm.sh/hook: test + helm.sh/hook-delete-policy: before-hook-creation, hook-succeeded, hook-failed +subjects: + - kind: ServiceAccount + name: test-service-account + namespace: {{ .Release.Namespace }} +roleRef: + kind: ClusterRole + name: test-role-clusterextensions + apiGroup: rbac.authorization.k8s.io +--- +{{- end }} apiVersion: v1 kind: Pod metadata: @@ -102,12 +132,20 @@ spec: echo "Starting Test" - {{- if .Values.serverlessLogicOperator.enabled }} + {{- if .Values.serverlessOperator.enabled }} + {{- if eq (include "olm-version" .) "v1" }} + kubectl get clusterextension {{ .Values.serverlessOperator.subscription.spec.name }} || exit 1 + {{- else }} kubectl get subscription {{ .Values.serverlessOperator.subscription.spec.name }} -n {{ .Values.serverlessOperator.subscription.namespace }} || exit 1 + {{- end }} {{- end }} {{- if .Values.serverlessLogicOperator.enabled }} - kubectl get subscription {{ .Values.serverlessLogicOperator.subscription.name }} -n {{ .Values.serverlessLogicOperator.subscription.namespace }} || exit 1 + {{- if eq (include "olm-version" .) "v1" }} + kubectl get clusterextension {{ .Values.serverlessLogicOperator.subscription.spec.name }} || exit 1 + {{- else }} + kubectl get subscription {{ .Values.serverlessLogicOperator.subscription.spec.name }} -n {{ .Values.serverlessLogicOperator.subscription.namespace }} || exit 1 + {{- end }} {{- end }} echo "Test passed!" diff --git a/charts/orchestrator-infra/values.schema.json b/charts/orchestrator-infra/values.schema.json index 1dba81cbf..f78ae109a 100644 --- a/charts/orchestrator-infra/values.schema.json +++ b/charts/orchestrator-infra/values.schema.json @@ -1,134 +1,175 @@ { - "$id": "https://raw.githubusercontent.com/redhat-developer/rhdh-chart/main/charts/orchestrator-infra/values.schema.json", - "properties": { - "serverlessLogicOperator": { - "additionalProperties": false, - "properties": { - "enabled": { - "default": true, - "title": "Whether the operator should be deployed by the chart", - "type": "boolean" + "$schema": "https://json-schema.org/draft/2020-12/schema", + "$id": "https://raw.githubusercontent.com/redhat-developer/rhdh-chart/main/charts/orchestrator-infra/values.schema.json", + "title": "Root Schema", + "type": "object", + "properties": { + "olmVersion": { + "default": "auto", + "enum": ["auto", "v0", "v1"], + "title": "OLM API version to use for operator installation", + "type": "string" + }, + "serverlessLogicOperator": { + "type": "object", + "additionalProperties": false, + "properties": { + "enabled": { + "default": true, + "title": "Whether the operator should be deployed by the chart", + "type": "boolean" + }, + "subscription": { + "type": "object", + "additionalProperties": false, + "properties": { + "namespace": { + "default": "openshift-serverless-logic", + "title": "Namespace where the operator should be deployed", + "type": "string" + }, + "spec": { + "additionalProperties": false, + "type": "object", + "properties": { + "channel": { + "default": "stable", + "title": "Channel of an operator package to subscribe to", + "type": "string" + }, + "installPlanApproval": { + "default": "Manual", + "title": "Whether the update should be installed automatically", + "type": "string" + }, + "name": { + "default": "logic-operator", + "title": "Name of the operator package", + "type": "string" + }, + "source": { + "default": "redhat-operators", + "title": "Name of the catalog source", + "type": "string" }, - "subscription": { - "additionalProperties": false, - "properties": { - "namespace": { - "default": "openshift-serverless-logic", - "title": "Namespace where the operator should be deployed", - "type": "string" - }, - "spec": { - "additionalProperties": false, - "properties": { - "channel": { - "default": "stable", - "title": "Channel of an operator package to subscribe to", - "type": "string" - }, - "installPlanApproval": { - "default": "Manual", - "title": "Whether the update should be installed automatically", - "type": "string" - }, - "name": { - "default": "logic-operator", - "title": "Name of the operator package", - "type": "string" - }, - "source": { - "default": "redhat-operators", - "title": "Name of the catalog source", - "type": "string" - }, - "sourceNamespace": { - "default": "openshift-marketplace", - "title": "Name of the catalog source Namespace", - "type": "string" - }, - "startingCSV": { - "default": "logic-operator.v1.38.0", - "title": "The initial version of the operator", - "type": "string" - } - }, - "type": "object" - } - }, - "type": "object" + "sourceNamespace": { + "default": "openshift-marketplace", + "title": "Name of the catalog source Namespace", + "type": "string" + }, + "startingCSV": { + "default": "logic-operator.v1.38.0", + "title": "The initial version of the operator", + "type": "string" } - }, - "type": "object" + } + } + } }, - "serverlessOperator": { - "additionalProperties": false, - "properties": { - "enabled": { - "default": true, - "title": "Whether the operator should be deployed by the chart", - "type": "boolean" - }, - "subscription": { - "additionalProperties": false, - "properties": { - "namespace": { - "default": "openshift-serverless", - "title": "Namespace where the operator should be deployed", - "type": "string" - }, - "spec": { - "additionalProperties": false, - "properties": { - "channel": { - "default": "stable", - "title": "Channel of an operator package to subscribe to", - "type": "string" - }, - "installPlanApproval": { - "default": "Manual", - "title": "Whether the update should be installed automatically", - "type": "string" - }, - "name": { - "default": "serverless-operator", - "title": "Name of the operator package", - "type": "string" - }, - "source": { - "default": "redhat-operators", - "title": "Name of the catalog source", - "type": "string" - }, - "sourceNamespace": { - "default": "openshift-marketplace", - "title": "Name of the catalog source Namespace", - "type": "string" - } - }, - "type": "object" - } - }, - "type": "object" + "clusterExtension": { + "type": "object", + "additionalProperties": false, + "properties": { + "serviceAccount": { + "type": "object", + "additionalProperties": false, + "properties": { + "name": { + "default": "serverless-logic-operator-installer", + "title": "Service account used by OLM v1 to install the operator", + "type": "string" } - }, - "type": "object" + } + } + } + } + } + }, + "serverlessOperator": { + "type": "object", + "additionalProperties": false, + "properties": { + "enabled": { + "default": true, + "title": "Whether the operator should be deployed by the chart", + "type": "boolean" }, - "tests": { - "additionalProperties": false, - "properties": { - "enabled": { - "default": true, - "title": "Wheather the test pod should be activated", - "type": "boolean" + "subscription": { + "additionalProperties": false, + "type": "object", + "properties": { + "namespace": { + "default": "openshift-serverless", + "title": "Namespace where the operator should be deployed", + "type": "string" + }, + "spec": { + "additionalProperties": false, + "type": "object", + "properties": { + "channel": { + "default": "stable", + "title": "Channel of an operator package to subscribe to", + "type": "string" + }, + "installPlanApproval": { + "default": "Manual", + "title": "Whether the update should be installed automatically", + "type": "string" + }, + "name": { + "default": "serverless-operator", + "title": "Name of the operator package", + "type": "string" + }, + "source": { + "default": "redhat-operators", + "title": "Name of the catalog source", + "type": "string" }, - "image": { - "default": "bitnami/kubectl:latest", - "title": "The base image for the testing pod", - "type": "string" + "sourceNamespace": { + "default": "openshift-marketplace", + "title": "Name of the catalog source Namespace", + "type": "string" } - }, - "type": "object" + } + } + } + }, + "clusterExtension": { + "type": "object", + "additionalProperties": false, + "properties": { + "serviceAccount": { + "type": "object", + "additionalProperties": false, + "properties": { + "name": { + "default": "serverless-operator-installer", + "title": "Service account used by OLM v1 to install the operator", + "type": "string" + } + } + } + } } + } }, - "title": "Root Schema", - "type": "object" + "tests": { + "type": "object", + "additionalProperties": false, + "properties": { + "enabled": { + "default": true, + "title": "Wheather the test pod should be activated", + "type": "boolean" + }, + "image": { + "default": "bitnami/kubectl:latest", + "type": "string", + "title": "The base image for the testing pod" + } + } + } + } } \ No newline at end of file diff --git a/charts/orchestrator-infra/values.schema.tmpl.json b/charts/orchestrator-infra/values.schema.tmpl.json index 778e9eee0..f78ae109a 100644 --- a/charts/orchestrator-infra/values.schema.tmpl.json +++ b/charts/orchestrator-infra/values.schema.tmpl.json @@ -4,6 +4,12 @@ "title": "Root Schema", "type": "object", "properties": { + "olmVersion": { + "default": "auto", + "enum": ["auto", "v0", "v1"], + "title": "OLM API version to use for operator installation", + "type": "string" + }, "serverlessLogicOperator": { "type": "object", "additionalProperties": false, @@ -59,6 +65,23 @@ } } } + }, + "clusterExtension": { + "type": "object", + "additionalProperties": false, + "properties": { + "serviceAccount": { + "type": "object", + "additionalProperties": false, + "properties": { + "name": { + "default": "serverless-logic-operator-installer", + "title": "Service account used by OLM v1 to install the operator", + "type": "string" + } + } + } + } } } }, @@ -112,6 +135,23 @@ } } } + }, + "clusterExtension": { + "type": "object", + "additionalProperties": false, + "properties": { + "serviceAccount": { + "type": "object", + "additionalProperties": false, + "properties": { + "name": { + "default": "serverless-operator-installer", + "title": "Service account used by OLM v1 to install the operator", + "type": "string" + } + } + } + } } } }, diff --git a/charts/orchestrator-infra/values.yaml b/charts/orchestrator-infra/values.yaml index cba801807..e24ad05a2 100644 --- a/charts/orchestrator-infra/values.yaml +++ b/charts/orchestrator-infra/values.yaml @@ -1,3 +1,6 @@ +# -- OLM API version to use for operator installation (`v0`, `v1`, or `auto`) +olmVersion: auto + serverlessLogicOperator: # -- whether the operator should be deployed by the chart enabled: true @@ -16,6 +19,10 @@ serverlessLogicOperator: sourceNamespace: openshift-marketplace # -- The initial version of the operator, must match CRDs installed by the chart startingCSV: logic-operator.v1.38.0 + clusterExtension: + serviceAccount: + # -- service account used by OLM v1 to install the operator + name: serverless-logic-operator-installer serverlessOperator: # -- whether the operator should be deployed by the chart @@ -33,6 +40,10 @@ serverlessOperator: # -- name of the catalog source source: redhat-operators sourceNamespace: openshift-marketplace + clusterExtension: + serviceAccount: + # -- service account used by OLM v1 to install the operator + name: serverless-operator-installer tests: # -- Whether to create the test pod used for testing the Release using `helm test`. From 120070ac9ef6457b77e63f10a16220175eef1e2e Mon Sep 17 00:00:00 2001 From: Fortune-Ndlovu Date: Wed, 16 Sep 2026 14:38:26 +0100 Subject: [PATCH 02/25] fix(orchestrator-infra): resolve OLM v1 install failures on cluster - Target openshift-redhat-operators ClusterCatalog via selector - Install Knative CRDs only on the OLM v0 path to avoid bundle collisions - Skip OperatorGroups on the OLM v1 path - Add ClusterExtension install preflight and v1-aware post-install notes RHIDP-14789 Signed-off-by: Fortune Ndlovu --- charts/orchestrator-infra/README.md | 12 +++++++----- .../knative-eventing-crd.yaml | 2 +- .../knative-serving-crd.yaml | 2 +- charts/orchestrator-infra/templates/NOTES.txt | 14 ++++++++++++++ charts/orchestrator-infra/templates/crds.yaml | 5 +++++ .../serverless-logic/clusterextension.yaml | 6 ++++++ .../templates/serverless-logic/operator-group.yaml | 2 +- .../templates/serverless/clusterextension.yaml | 6 ++++++ .../templates/serverless/operator-group.yaml | 2 +- charts/orchestrator-infra/values.yaml | 6 ++++++ 10 files changed, 48 insertions(+), 9 deletions(-) rename charts/orchestrator-infra/{crds/knative-eventing => files}/knative-eventing-crd.yaml (99%) rename charts/orchestrator-infra/{crds/knative-serving => files}/knative-serving-crd.yaml (99%) create mode 100644 charts/orchestrator-infra/templates/crds.yaml diff --git a/charts/orchestrator-infra/README.md b/charts/orchestrator-infra/README.md index c860c0b31..ddc9a642a 100644 --- a/charts/orchestrator-infra/README.md +++ b/charts/orchestrator-infra/README.md @@ -84,6 +84,7 @@ The command removes all the Kubernetes components associated with the chart and | Key | Description | Type | Default | |-----|-------------|------|---------| | olmVersion | OLM API version to use for operator installation (`v0`, `v1`, or `auto`) | string | `"auto"` | +| olm.catalog.selector.matchLabels."olm\.operatorframework\.io/metadata\.name" | ClusterCatalog selector for OLM v1 ClusterExtension resources | string | `"openshift-redhat-operators"` | | serverlessLogicOperator.clusterExtension.serviceAccount.name | service account used by OLM v1 to install the operator | string | `"serverless-logic-operator-installer"` | | serverlessLogicOperator.enabled | whether the operator should be deployed by the chart | bool | `true` | | serverlessLogicOperator.subscription.namespace | namespace where the operator should be deployed | string | `"openshift-serverless-logic"` | @@ -126,16 +127,17 @@ helm install my-orchestrator-infra ./charts/orchestrator-infra --set olmVersion= The orchestrator-infra chart requires several CRDs for Knative Eventing and Knative Serving. These CRDs will be applied prior to installing the chart, ensuring that Knative CRs can be created as part of the chart's deployment process. This approach eliminates the need to wait for the OpenShift Serverless Operator's subscription to install them beforehand. -The KnativeEventing and KnativeServing CRDs are required for this chart to run. These CRDs need to be present under the `crds/` directory before running `helm install`. -After installing the openshift-serverless subscription, more Knative CRDs will be installed on the cluster. +The KnativeEventing and KnativeServing CRDs are required for this chart to run when using `olmVersion=v0`. These CRDs are installed from the `files/` directory via a Helm hook before the operator Subscriptions are applied. -The versions of the CRDs present in the chart and the ones in the subscription must match. In order to verify the correct CRD, use this following command to extract the CRD: +When using `olmVersion=v1`, the chart does not pre-install Knative CRDs. They are installed by the operator bundle resolved through the ClusterExtension. + +In order to verify the correct CRD versions for the v0 path, use this following command to extract the CRD: ```bash export osl_bundle=registry.redhat.io/openshift-serverless-1/serverless-operator-bundle:1.38.0 -podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1beta1_knativeeventing_crd.yaml > crds/knative-eventing/knative-eventing-crd.yaml +podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1beta1_knativeeventing_crd.yaml > files/knative-eventing-crd.yaml -podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1beta1_knativeserving_crd.yaml > crds/knative-serving/knative-serving-crd.yaml +podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1beta1_knativeserving_crd.yaml > files/knative-serving-crd.yaml ``` After running these commands, you may need to re-add the `helm.sh/hook` annotations. diff --git a/charts/orchestrator-infra/crds/knative-eventing/knative-eventing-crd.yaml b/charts/orchestrator-infra/files/knative-eventing-crd.yaml similarity index 99% rename from charts/orchestrator-infra/crds/knative-eventing/knative-eventing-crd.yaml rename to charts/orchestrator-infra/files/knative-eventing-crd.yaml index ee3bbfd24..02dfc1cc8 100644 --- a/charts/orchestrator-infra/crds/knative-eventing/knative-eventing-crd.yaml +++ b/charts/orchestrator-infra/files/knative-eventing-crd.yaml @@ -17,7 +17,7 @@ kind: CustomResourceDefinition metadata: name: knativeeventings.operator.knative.dev annotations: - "helm.sh/hook": pre-delete + "helm.sh/hook": pre-install,pre-upgrade,pre-delete "helm.sh/hook-weight": "-10" "helm.sh/hook-delete-policy": before-hook-creation labels: diff --git a/charts/orchestrator-infra/crds/knative-serving/knative-serving-crd.yaml b/charts/orchestrator-infra/files/knative-serving-crd.yaml similarity index 99% rename from charts/orchestrator-infra/crds/knative-serving/knative-serving-crd.yaml rename to charts/orchestrator-infra/files/knative-serving-crd.yaml index 3a316a833..176fe9e2a 100644 --- a/charts/orchestrator-infra/crds/knative-serving/knative-serving-crd.yaml +++ b/charts/orchestrator-infra/files/knative-serving-crd.yaml @@ -17,7 +17,7 @@ kind: CustomResourceDefinition metadata: name: knativeservings.operator.knative.dev annotations: - "helm.sh/hook": pre-delete + "helm.sh/hook": pre-install,pre-upgrade,pre-delete "helm.sh/hook-weight": "-10" "helm.sh/hook-delete-policy": before-hook-creation labels: diff --git a/charts/orchestrator-infra/templates/NOTES.txt b/charts/orchestrator-infra/templates/NOTES.txt index 1897ccb63..3b6f67553 100644 --- a/charts/orchestrator-infra/templates/NOTES.txt +++ b/charts/orchestrator-infra/templates/NOTES.txt @@ -11,10 +11,17 @@ Helm Release {{ .Release.Name }} installed in namespace {{ .Release.Namespace }} {{- $timeout := "--timeout=5m" }} {{- if .Values.serverlessOperator.enabled }} +{{- if eq (include "olm-version" .) "v0" }} {{- $unmanagedSubscriptionExists := include "unmanaged-resource-exists" (list "operators.coreos.com/v1alpha1" "Subscription" .Values.serverlessOperator.subscription.namespace "serverless-operator" .Release.Name .Capabilities.APIVersions ) }} {{- if eq $unmanagedSubscriptionExists "false" }} {{- $serverlessOperatorInstalled = $yes }} {{- end }} +{{- else }} +{{- $unmanagedClusterExtensionExists := include "unmanaged-clusterextension-exists" (list .Values.serverlessOperator.subscription.spec.name .Release.Name .Capabilities.APIVersions) }} +{{- if eq $unmanagedClusterExtensionExists "false" }} +{{- $serverlessOperatorInstalled = $yes }} +{{- end }} +{{- end }} {{- end }} {{- if .Values.serverlessLogicOperator.enabled }} @@ -29,6 +36,7 @@ Red Hat Serverless Logic Operator {{ $serverlessLogicOperatorInstalled }} ==================================================================== {{/* Empty line */}} +{{- if eq (include "olm-version" .) "v0" }} {{- if eq .Values.serverlessOperator.subscription.spec.installPlanApproval "Manual" }} To manually approve the openshift-serverless InstallPlan: @@ -44,3 +52,9 @@ To manually approve the openshift-serverless-logic InstallPlan: OSL_PLAN=$(oc get installplan -n openshift-serverless-logic --sort-by=.metadata.creationTimestamp -o jsonpath='{.items[0].metadata.name}') oc patch installplan $OSL_PLAN -n openshift-serverless-logic --type merge --patch '{"spec":{"approved":true}}' {{- end }} +{{- else }} + +Monitor ClusterExtension installation progress: + +oc get clusterextension serverless-operator logic-operator +{{- end }} diff --git a/charts/orchestrator-infra/templates/crds.yaml b/charts/orchestrator-infra/templates/crds.yaml new file mode 100644 index 000000000..4eba621d3 --- /dev/null +++ b/charts/orchestrator-infra/templates/crds.yaml @@ -0,0 +1,5 @@ +{{- if eq (include "olm-version" .) "v0" }} +{{ .Files.Get "files/knative-serving-crd.yaml" }} +--- +{{ .Files.Get "files/knative-eventing-crd.yaml" }} +{{- end }} diff --git a/charts/orchestrator-infra/templates/serverless-logic/clusterextension.yaml b/charts/orchestrator-infra/templates/serverless-logic/clusterextension.yaml index e680df772..631ad515f 100644 --- a/charts/orchestrator-infra/templates/serverless-logic/clusterextension.yaml +++ b/charts/orchestrator-infra/templates/serverless-logic/clusterextension.yaml @@ -36,6 +36,10 @@ metadata: meta.helm.sh/release-name: {{ .Release.Name }} meta.helm.sh/release-namespace: {{ .Release.Namespace }} spec: + install: + preflight: + crdUpgradeSafety: + enforcement: None namespace: {{ $namespace }} serviceAccount: name: {{ $serviceAccountName }} @@ -46,5 +50,7 @@ spec: channels: - {{ .Values.serverlessLogicOperator.subscription.spec.channel }} version: {{ include "csv-version" (list .Values.serverlessLogicOperator.subscription.spec.startingCSV $packageName) | quote }} + selector: + {{- toYaml .Values.olm.catalog.selector | nindent 8 }} upgradeConstraintPolicy: CatalogProvided {{- end }} diff --git a/charts/orchestrator-infra/templates/serverless-logic/operator-group.yaml b/charts/orchestrator-infra/templates/serverless-logic/operator-group.yaml index 6334b5731..9e4d9da4c 100644 --- a/charts/orchestrator-infra/templates/serverless-logic/operator-group.yaml +++ b/charts/orchestrator-infra/templates/serverless-logic/operator-group.yaml @@ -1,4 +1,4 @@ -{{- if .Values.serverlessLogicOperator.enabled }} +{{- if and .Values.serverlessLogicOperator.enabled (eq (include "olm-version" .) "v0") }} apiVersion: operators.coreos.com/v1 kind: OperatorGroup metadata: diff --git a/charts/orchestrator-infra/templates/serverless/clusterextension.yaml b/charts/orchestrator-infra/templates/serverless/clusterextension.yaml index 739b798e0..5e22e9bf2 100644 --- a/charts/orchestrator-infra/templates/serverless/clusterextension.yaml +++ b/charts/orchestrator-infra/templates/serverless/clusterextension.yaml @@ -36,6 +36,10 @@ metadata: meta.helm.sh/release-name: {{ .Release.Name }} meta.helm.sh/release-namespace: {{ .Release.Namespace }} spec: + install: + preflight: + crdUpgradeSafety: + enforcement: None namespace: {{ $namespace }} serviceAccount: name: {{ $serviceAccountName }} @@ -45,5 +49,7 @@ spec: packageName: {{ $packageName }} channels: - {{ .Values.serverlessOperator.subscription.spec.channel }} + selector: + {{- toYaml .Values.olm.catalog.selector | nindent 8 }} upgradeConstraintPolicy: CatalogProvided {{- end }} diff --git a/charts/orchestrator-infra/templates/serverless/operator-group.yaml b/charts/orchestrator-infra/templates/serverless/operator-group.yaml index aeb7d3d7a..01764aea5 100644 --- a/charts/orchestrator-infra/templates/serverless/operator-group.yaml +++ b/charts/orchestrator-infra/templates/serverless/operator-group.yaml @@ -1,4 +1,4 @@ -{{- if .Values.serverlessOperator.enabled }} +{{- if and .Values.serverlessOperator.enabled (eq (include "olm-version" .) "v0") }} apiVersion: operators.coreos.com/v1 kind: OperatorGroup metadata: diff --git a/charts/orchestrator-infra/values.yaml b/charts/orchestrator-infra/values.yaml index e24ad05a2..42e045fb9 100644 --- a/charts/orchestrator-infra/values.yaml +++ b/charts/orchestrator-infra/values.yaml @@ -1,5 +1,11 @@ # -- OLM API version to use for operator installation (`v0`, `v1`, or `auto`) olmVersion: auto +olm: + catalog: + # -- ClusterCatalog selector for OLM v1 ClusterExtension resources + selector: + matchLabels: + olm.operatorframework.io/metadata.name: openshift-redhat-operators serverlessLogicOperator: # -- whether the operator should be deployed by the chart From b48f58a6993924477fd0b58b96dbda594f04bedc Mon Sep 17 00:00:00 2001 From: Fortune-Ndlovu Date: Wed, 16 Sep 2026 14:46:18 +0100 Subject: [PATCH 03/25] fix(orchestrator-infra): defer Knative CRs on OLM v1 install path Skip KnativeServing/KnativeEventing creation when olmVersion=v1 so Helm can install ClusterExtensions before operator CRDs exist. Default olmVersion to v0 until the v1 path is validated end-to-end on clean clusters. RHIDP-14789 Signed-off-by: Fortune Ndlovu --- charts/orchestrator-infra/README.md | 4 ++-- charts/orchestrator-infra/templates/serverless/knatives.yaml | 4 ++-- charts/orchestrator-infra/values.yaml | 3 ++- 3 files changed, 6 insertions(+), 5 deletions(-) diff --git a/charts/orchestrator-infra/README.md b/charts/orchestrator-infra/README.md index ddc9a642a..8e862cf9e 100644 --- a/charts/orchestrator-infra/README.md +++ b/charts/orchestrator-infra/README.md @@ -83,7 +83,7 @@ The command removes all the Kubernetes components associated with the chart and | Key | Description | Type | Default | |-----|-------------|------|---------| -| olmVersion | OLM API version to use for operator installation (`v0`, `v1`, or `auto`) | string | `"auto"` | +| olmVersion | OLM API version to use for operator installation (`v0`, `v1`, or `auto`) | string | `"v0"` | | olm.catalog.selector.matchLabels."olm\.operatorframework\.io/metadata\.name" | ClusterCatalog selector for OLM v1 ClusterExtension resources | string | `"openshift-redhat-operators"` | | serverlessLogicOperator.clusterExtension.serviceAccount.name | service account used by OLM v1 to install the operator | string | `"serverless-logic-operator-installer"` | | serverlessLogicOperator.enabled | whether the operator should be deployed by the chart | bool | `true` | @@ -129,7 +129,7 @@ The orchestrator-infra chart requires several CRDs for Knative Eventing and Knat The KnativeEventing and KnativeServing CRDs are required for this chart to run when using `olmVersion=v0`. These CRDs are installed from the `files/` directory via a Helm hook before the operator Subscriptions are applied. -When using `olmVersion=v1`, the chart does not pre-install Knative CRDs. They are installed by the operator bundle resolved through the ClusterExtension. +When using `olmVersion=v1`, the chart does not pre-install Knative CRDs or create KnativeServing/KnativeEventing instances in the same Helm transaction. The operator bundle installed via ClusterExtension provides the CRDs first; create the Knative instances after the ClusterExtensions report `Installed=True`. In order to verify the correct CRD versions for the v0 path, use this following command to extract the CRD: diff --git a/charts/orchestrator-infra/templates/serverless/knatives.yaml b/charts/orchestrator-infra/templates/serverless/knatives.yaml index 630a97afb..d2e64a55a 100644 --- a/charts/orchestrator-infra/templates/serverless/knatives.yaml +++ b/charts/orchestrator-infra/templates/serverless/knatives.yaml @@ -26,7 +26,7 @@ metadata: {{- end }} {{- $unmanagedKnativeEventingExists := include "unmanaged-resource-exists" (list "operator.knative.dev/v1beta1" "KnativeEventing" "knative-eventing" "knative-eventing" .Release.Name .Capabilities.APIVersions) }} -{{- if eq $unmanagedKnativeEventingExists "false" }} +{{- if and (eq $unmanagedKnativeEventingExists "false") (ne (include "olm-version" .) "v1") }} --- apiVersion: operator.knative.dev/v1beta1 kind: KnativeEventing @@ -38,7 +38,7 @@ spec: {{- end }} {{- $unmanagedKnativeServingExists := include "unmanaged-resource-exists" (list "operator.knative.dev/v1beta1" "KnativeServing" "knative-serving" "knative-serving" .Release.Name .Capabilities.APIVersions) }} -{{- if eq $unmanagedKnativeServingExists "false" }} +{{- if and (eq $unmanagedKnativeServingExists "false") (ne (include "olm-version" .) "v1") }} --- apiVersion: operator.knative.dev/v1beta1 kind: KnativeServing diff --git a/charts/orchestrator-infra/values.yaml b/charts/orchestrator-infra/values.yaml index 42e045fb9..5487bf963 100644 --- a/charts/orchestrator-infra/values.yaml +++ b/charts/orchestrator-infra/values.yaml @@ -1,5 +1,6 @@ # -- OLM API version to use for operator installation (`v0`, `v1`, or `auto`) -olmVersion: auto +# Use `v0` on clusters without OLM v1, or until the v1 path is fully validated end-to-end. +olmVersion: v0 olm: catalog: # -- ClusterCatalog selector for OLM v1 ClusterExtension resources From 8759870068a70910ca8dd1c14b6a62a35c64f49e Mon Sep 17 00:00:00 2001 From: Fortune-Ndlovu Date: Wed, 16 Sep 2026 15:47:40 +0100 Subject: [PATCH 04/25] chore(orchestrator-infra): align docs/schema and drop NOTES.txt changes Revert OLM v1 post-install NOTES.txt customizations and move OLM documentation into README.md.gotmpl so helm-docs keeps it in CI. Align values schema default with olmVersion: v0 and document olm.catalog. RHIDP-14789 Signed-off-by: Fortune Ndlovu --- charts/orchestrator-infra/README.md | 18 +- charts/orchestrator-infra/README.md.gotmpl | 31 +- charts/orchestrator-infra/templates/NOTES.txt | 14 - charts/orchestrator-infra/values.schema.json | 354 ++++++++++-------- .../values.schema.tmpl.json | 31 +- 5 files changed, 257 insertions(+), 191 deletions(-) diff --git a/charts/orchestrator-infra/README.md b/charts/orchestrator-infra/README.md index 8e862cf9e..f5ee771a5 100644 --- a/charts/orchestrator-infra/README.md +++ b/charts/orchestrator-infra/README.md @@ -83,8 +83,8 @@ The command removes all the Kubernetes components associated with the chart and | Key | Description | Type | Default | |-----|-------------|------|---------| -| olmVersion | OLM API version to use for operator installation (`v0`, `v1`, or `auto`) | string | `"v0"` | -| olm.catalog.selector.matchLabels."olm\.operatorframework\.io/metadata\.name" | ClusterCatalog selector for OLM v1 ClusterExtension resources | string | `"openshift-redhat-operators"` | +| olm.catalog.selector | ClusterCatalog selector for OLM v1 ClusterExtension resources | object | `{"matchLabels":{"olm.operatorframework.io/metadata.name":"openshift-redhat-operators"}}` | +| olmVersion | OLM API version to use for operator installation (`v0`, `v1`, or `auto`) Use `v0` on clusters without OLM v1, or until the v1 path is fully validated end-to-end. | string | `"v0"` | | serverlessLogicOperator.clusterExtension.serviceAccount.name | service account used by OLM v1 to install the operator | string | `"serverless-logic-operator-installer"` | | serverlessLogicOperator.enabled | whether the operator should be deployed by the chart | bool | `true` | | serverlessLogicOperator.subscription.namespace | namespace where the operator should be deployed | string | `"openshift-serverless-logic"` | @@ -94,8 +94,8 @@ The command removes all the Kubernetes components associated with the chart and | serverlessLogicOperator.subscription.spec.source | name of the catalog source | string | `"redhat-operators"` | | serverlessLogicOperator.subscription.spec.sourceNamespace | | string | `"openshift-marketplace"` | | serverlessLogicOperator.subscription.spec.startingCSV | The initial version of the operator, must match CRDs installed by the chart | string | `"logic-operator.v1.38.0"` | -| serverlessOperator.enabled | whether the operator should be deployed by the chart | bool | `true` | | serverlessOperator.clusterExtension.serviceAccount.name | service account used by OLM v1 to install the operator | string | `"serverless-operator-installer"` | +| serverlessOperator.enabled | whether the operator should be deployed by the chart | bool | `true` | | serverlessOperator.subscription.namespace | namespace where the operator should be deployed | string | `"openshift-serverless"` | | serverlessOperator.subscription.spec.channel | channel of an operator package to subscribe to | string | `"stable"` | | serverlessOperator.subscription.spec.installPlanApproval | whether the update should be installed automatically | string | `"Manual"` | @@ -107,7 +107,7 @@ The command removes all the Kubernetes components associated with the chart and ### OLM v0 and OLM v1 operator installation -By default, the chart uses `olmVersion: auto` to select the OLM API: +By default, the chart uses `olmVersion: v0` (classic OLM Subscriptions). Set `olmVersion: auto` on OLM v1 clusters once the v1 path is validated end-to-end. - **`v0`** — creates `Subscription` resources (classic OLM) - **`v1`** — creates `ClusterExtension` resources with installer ServiceAccount and ClusterRoleBinding (OLM v1) @@ -116,20 +116,20 @@ By default, the chart uses `olmVersion: auto` to select the OLM API: Examples: ```bash -# Force classic OLM Subscriptions +# Force classic OLM Subscriptions (default) helm install my-orchestrator-infra ./charts/orchestrator-infra --set olmVersion=v0 # Force OLM v1 ClusterExtensions (requires OLM v1 on the cluster) helm install my-orchestrator-infra ./charts/orchestrator-infra --set olmVersion=v1 ``` -### Installing Knative Eventing and Knative Serving CRDs +> **Note:** On OLM v1 clusters, use a clean cluster (no prior helm-managed Knative CRDs from a v0 install). After ClusterExtensions report `Installed=True`, create KnativeServing/KnativeEventing instances manually or via a follow-up release upgrade. -The orchestrator-infra chart requires several CRDs for Knative Eventing and Knative Serving. These CRDs will be applied prior to installing the chart, ensuring that Knative CRs can be created as part of the chart's deployment process. This approach eliminates the need to wait for the OpenShift Serverless Operator's subscription to install them beforehand. +### Installing Knative Eventing and Knative Serving CRDs -The KnativeEventing and KnativeServing CRDs are required for this chart to run when using `olmVersion=v0`. These CRDs are installed from the `files/` directory via a Helm hook before the operator Subscriptions are applied. +The orchestrator-infra chart requires several CRDs for Knative Eventing and Knative Serving when using `olmVersion=v0`. These CRDs are installed from the `files/` directory via a Helm hook before the operator Subscriptions are applied. -When using `olmVersion=v1`, the chart does not pre-install Knative CRDs or create KnativeServing/KnativeEventing instances in the same Helm transaction. The operator bundle installed via ClusterExtension provides the CRDs first; create the Knative instances after the ClusterExtensions report `Installed=True`. +When using `olmVersion=v1`, the chart does not pre-install Knative CRDs or create KnativeServing/KnativeEventing instances in the same Helm transaction. The operator bundle installed via ClusterExtension provides the CRDs first. In order to verify the correct CRD versions for the v0 path, use this following command to extract the CRD: diff --git a/charts/orchestrator-infra/README.md.gotmpl b/charts/orchestrator-infra/README.md.gotmpl index 233313048..ebf4a6dbd 100644 --- a/charts/orchestrator-infra/README.md.gotmpl +++ b/charts/orchestrator-infra/README.md.gotmpl @@ -76,20 +76,39 @@ The command removes all the Kubernetes components associated with the chart and {{ template "chart.valuesSection" . }} +### OLM v0 and OLM v1 operator installation + +By default, the chart uses `olmVersion: v0` (classic OLM Subscriptions). Set `olmVersion: auto` on OLM v1 clusters once the v1 path is validated end-to-end. + +- **`v0`** — creates `Subscription` resources (classic OLM) +- **`v1`** — creates `ClusterExtension` resources with installer ServiceAccount and ClusterRoleBinding (OLM v1) +- **`auto`** — uses OLM v1 when the `clusterextensions.olm.operatorframework.io` CRD is present, otherwise OLM v0 + +Examples: + +```bash +# Force classic OLM Subscriptions (default) +helm install my-orchestrator-infra ./charts/orchestrator-infra --set olmVersion=v0 + +# Force OLM v1 ClusterExtensions (requires OLM v1 on the cluster) +helm install my-orchestrator-infra ./charts/orchestrator-infra --set olmVersion=v1 +``` + +> **Note:** On OLM v1 clusters, use a clean cluster (no prior helm-managed Knative CRDs from a v0 install). After ClusterExtensions report `Installed=True`, create KnativeServing/KnativeEventing instances manually or via a follow-up release upgrade. + ### Installing Knative Eventing and Knative Serving CRDs -The orchestrator-infra chart requires several CRDs for Knative Eventing and Knative Serving. These CRDs will be applied prior to installing the chart, ensuring that Knative CRs can be created as part of the chart's deployment process. This approach eliminates the need to wait for the OpenShift Serverless Operator's subscription to install them beforehand. +The orchestrator-infra chart requires several CRDs for Knative Eventing and Knative Serving when using `olmVersion=v0`. These CRDs are installed from the `files/` directory via a Helm hook before the operator Subscriptions are applied. -The KnativeEventing and KnativeServing CRDs are required for this chart to run. These CRDs need to be present under the `crds/` directory before running `helm install`. -After installing the openshift-serverless subscription, more Knative CRDs will be installed on the cluster. +When using `olmVersion=v1`, the chart does not pre-install Knative CRDs or create KnativeServing/KnativeEventing instances in the same Helm transaction. The operator bundle installed via ClusterExtension provides the CRDs first. -The versions of the CRDs present in the chart and the ones in the subscription must match. In order to verify the correct CRD, use this following command to extract the CRD: +In order to verify the correct CRD versions for the v0 path, use this following command to extract the CRD: ```bash export osl_bundle=registry.redhat.io/openshift-serverless-1/serverless-operator-bundle:1.38.0 -podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1beta1_knativeeventing_crd.yaml > crds/knative-eventing/knative-eventing-crd.yaml +podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1beta1_knativeeventing_crd.yaml > files/knative-eventing-crd.yaml -podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1beta1_knativeserving_crd.yaml > crds/knative-serving/knative-serving-crd.yaml +podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1beta1_knativeserving_crd.yaml > files/knative-serving-crd.yaml ``` After running these commands, you may need to re-add the `helm.sh/hook` annotations. diff --git a/charts/orchestrator-infra/templates/NOTES.txt b/charts/orchestrator-infra/templates/NOTES.txt index 3b6f67553..1897ccb63 100644 --- a/charts/orchestrator-infra/templates/NOTES.txt +++ b/charts/orchestrator-infra/templates/NOTES.txt @@ -11,17 +11,10 @@ Helm Release {{ .Release.Name }} installed in namespace {{ .Release.Namespace }} {{- $timeout := "--timeout=5m" }} {{- if .Values.serverlessOperator.enabled }} -{{- if eq (include "olm-version" .) "v0" }} {{- $unmanagedSubscriptionExists := include "unmanaged-resource-exists" (list "operators.coreos.com/v1alpha1" "Subscription" .Values.serverlessOperator.subscription.namespace "serverless-operator" .Release.Name .Capabilities.APIVersions ) }} {{- if eq $unmanagedSubscriptionExists "false" }} {{- $serverlessOperatorInstalled = $yes }} {{- end }} -{{- else }} -{{- $unmanagedClusterExtensionExists := include "unmanaged-clusterextension-exists" (list .Values.serverlessOperator.subscription.spec.name .Release.Name .Capabilities.APIVersions) }} -{{- if eq $unmanagedClusterExtensionExists "false" }} -{{- $serverlessOperatorInstalled = $yes }} -{{- end }} -{{- end }} {{- end }} {{- if .Values.serverlessLogicOperator.enabled }} @@ -36,7 +29,6 @@ Red Hat Serverless Logic Operator {{ $serverlessLogicOperatorInstalled }} ==================================================================== {{/* Empty line */}} -{{- if eq (include "olm-version" .) "v0" }} {{- if eq .Values.serverlessOperator.subscription.spec.installPlanApproval "Manual" }} To manually approve the openshift-serverless InstallPlan: @@ -52,9 +44,3 @@ To manually approve the openshift-serverless-logic InstallPlan: OSL_PLAN=$(oc get installplan -n openshift-serverless-logic --sort-by=.metadata.creationTimestamp -o jsonpath='{.items[0].metadata.name}') oc patch installplan $OSL_PLAN -n openshift-serverless-logic --type merge --patch '{"spec":{"approved":true}}' {{- end }} -{{- else }} - -Monitor ClusterExtension installation progress: - -oc get clusterextension serverless-operator logic-operator -{{- end }} diff --git a/charts/orchestrator-infra/values.schema.json b/charts/orchestrator-infra/values.schema.json index f78ae109a..a9554ac39 100644 --- a/charts/orchestrator-infra/values.schema.json +++ b/charts/orchestrator-infra/values.schema.json @@ -1,175 +1,207 @@ { - "$schema": "https://json-schema.org/draft/2020-12/schema", - "$id": "https://raw.githubusercontent.com/redhat-developer/rhdh-chart/main/charts/orchestrator-infra/values.schema.json", - "title": "Root Schema", - "type": "object", - "properties": { - "olmVersion": { - "default": "auto", - "enum": ["auto", "v0", "v1"], - "title": "OLM API version to use for operator installation", - "type": "string" - }, - "serverlessLogicOperator": { - "type": "object", - "additionalProperties": false, - "properties": { - "enabled": { - "default": true, - "title": "Whether the operator should be deployed by the chart", - "type": "boolean" - }, - "subscription": { - "type": "object", - "additionalProperties": false, - "properties": { - "namespace": { - "default": "openshift-serverless-logic", - "title": "Namespace where the operator should be deployed", - "type": "string" - }, - "spec": { - "additionalProperties": false, - "type": "object", - "properties": { - "channel": { - "default": "stable", - "title": "Channel of an operator package to subscribe to", - "type": "string" - }, - "installPlanApproval": { - "default": "Manual", - "title": "Whether the update should be installed automatically", - "type": "string" - }, - "name": { - "default": "logic-operator", - "title": "Name of the operator package", - "type": "string" - }, - "source": { - "default": "redhat-operators", - "title": "Name of the catalog source", - "type": "string" - }, - "sourceNamespace": { - "default": "openshift-marketplace", - "title": "Name of the catalog source Namespace", - "type": "string" - }, - "startingCSV": { - "default": "logic-operator.v1.38.0", - "title": "The initial version of the operator", - "type": "string" + "$id": "https://raw.githubusercontent.com/redhat-developer/rhdh-chart/main/charts/orchestrator-infra/values.schema.json", + "properties": { + "olm": { + "additionalProperties": false, + "properties": { + "catalog": { + "additionalProperties": false, + "properties": { + "selector": { + "additionalProperties": false, + "properties": { + "matchLabels": { + "additionalProperties": false, + "properties": { + "olm.operatorframework.io/metadata.name": { + "default": "openshift-redhat-operators", + "title": "ClusterCatalog selector for OLM v1 ClusterExtension resources", + "type": "string" + } + }, + "type": "object" + } + }, + "type": "object" + } + }, + "type": "object" } - } - } - } + }, + "type": "object" }, - "clusterExtension": { - "type": "object", - "additionalProperties": false, - "properties": { - "serviceAccount": { - "type": "object", - "additionalProperties": false, - "properties": { - "name": { - "default": "serverless-logic-operator-installer", - "title": "Service account used by OLM v1 to install the operator", - "type": "string" - } - } - } - } - } - } - }, - "serverlessOperator": { - "type": "object", - "additionalProperties": false, - "properties": { - "enabled": { - "default": true, - "title": "Whether the operator should be deployed by the chart", - "type": "boolean" + "olmVersion": { + "default": "v0", + "enum": [ + "auto", + "v0", + "v1" + ], + "title": "OLM API version to use for operator installation", + "type": "string" }, - "subscription": { - "additionalProperties": false, - "type": "object", - "properties": { - "namespace": { - "default": "openshift-serverless", - "title": "Namespace where the operator should be deployed", - "type": "string" - }, - "spec": { - "additionalProperties": false, - "type": "object", - "properties": { - "channel": { - "default": "stable", - "title": "Channel of an operator package to subscribe to", - "type": "string" + "serverlessLogicOperator": { + "additionalProperties": false, + "properties": { + "clusterExtension": { + "additionalProperties": false, + "properties": { + "serviceAccount": { + "additionalProperties": false, + "properties": { + "name": { + "default": "serverless-logic-operator-installer", + "title": "Service account used by OLM v1 to install the operator", + "type": "string" + } + }, + "type": "object" + } + }, + "type": "object" }, - "installPlanApproval": { - "default": "Manual", - "title": "Whether the update should be installed automatically", - "type": "string" + "enabled": { + "default": true, + "title": "Whether the operator should be deployed by the chart", + "type": "boolean" }, - "name": { - "default": "serverless-operator", - "title": "Name of the operator package", - "type": "string" + "subscription": { + "additionalProperties": false, + "properties": { + "namespace": { + "default": "openshift-serverless-logic", + "title": "Namespace where the operator should be deployed", + "type": "string" + }, + "spec": { + "additionalProperties": false, + "properties": { + "channel": { + "default": "stable", + "title": "Channel of an operator package to subscribe to", + "type": "string" + }, + "installPlanApproval": { + "default": "Manual", + "title": "Whether the update should be installed automatically", + "type": "string" + }, + "name": { + "default": "logic-operator", + "title": "Name of the operator package", + "type": "string" + }, + "source": { + "default": "redhat-operators", + "title": "Name of the catalog source", + "type": "string" + }, + "sourceNamespace": { + "default": "openshift-marketplace", + "title": "Name of the catalog source Namespace", + "type": "string" + }, + "startingCSV": { + "default": "logic-operator.v1.38.0", + "title": "The initial version of the operator", + "type": "string" + } + }, + "type": "object" + } + }, + "type": "object" + } + }, + "type": "object" + }, + "serverlessOperator": { + "additionalProperties": false, + "properties": { + "clusterExtension": { + "additionalProperties": false, + "properties": { + "serviceAccount": { + "additionalProperties": false, + "properties": { + "name": { + "default": "serverless-operator-installer", + "title": "Service account used by OLM v1 to install the operator", + "type": "string" + } + }, + "type": "object" + } + }, + "type": "object" }, - "source": { - "default": "redhat-operators", - "title": "Name of the catalog source", - "type": "string" + "enabled": { + "default": true, + "title": "Whether the operator should be deployed by the chart", + "type": "boolean" }, - "sourceNamespace": { - "default": "openshift-marketplace", - "title": "Name of the catalog source Namespace", - "type": "string" + "subscription": { + "additionalProperties": false, + "properties": { + "namespace": { + "default": "openshift-serverless", + "title": "Namespace where the operator should be deployed", + "type": "string" + }, + "spec": { + "additionalProperties": false, + "properties": { + "channel": { + "default": "stable", + "title": "Channel of an operator package to subscribe to", + "type": "string" + }, + "installPlanApproval": { + "default": "Manual", + "title": "Whether the update should be installed automatically", + "type": "string" + }, + "name": { + "default": "serverless-operator", + "title": "Name of the operator package", + "type": "string" + }, + "source": { + "default": "redhat-operators", + "title": "Name of the catalog source", + "type": "string" + }, + "sourceNamespace": { + "default": "openshift-marketplace", + "title": "Name of the catalog source Namespace", + "type": "string" + } + }, + "type": "object" + } + }, + "type": "object" } - } - } - } + }, + "type": "object" }, - "clusterExtension": { - "type": "object", - "additionalProperties": false, - "properties": { - "serviceAccount": { - "type": "object", - "additionalProperties": false, - "properties": { - "name": { - "default": "serverless-operator-installer", - "title": "Service account used by OLM v1 to install the operator", - "type": "string" + "tests": { + "additionalProperties": false, + "properties": { + "enabled": { + "default": true, + "title": "Wheather the test pod should be activated", + "type": "boolean" + }, + "image": { + "default": "bitnami/kubectl:latest", + "title": "The base image for the testing pod", + "type": "string" } - } - } - } + }, + "type": "object" } - } }, - "tests": { - "type": "object", - "additionalProperties": false, - "properties": { - "enabled": { - "default": true, - "title": "Wheather the test pod should be activated", - "type": "boolean" - }, - "image": { - "default": "bitnami/kubectl:latest", - "type": "string", - "title": "The base image for the testing pod" - } - } - } - } + "title": "Root Schema", + "type": "object" } \ No newline at end of file diff --git a/charts/orchestrator-infra/values.schema.tmpl.json b/charts/orchestrator-infra/values.schema.tmpl.json index f78ae109a..9d2e3b3df 100644 --- a/charts/orchestrator-infra/values.schema.tmpl.json +++ b/charts/orchestrator-infra/values.schema.tmpl.json @@ -5,11 +5,40 @@ "type": "object", "properties": { "olmVersion": { - "default": "auto", + "default": "v0", "enum": ["auto", "v0", "v1"], "title": "OLM API version to use for operator installation", "type": "string" }, + "olm": { + "type": "object", + "additionalProperties": false, + "properties": { + "catalog": { + "type": "object", + "additionalProperties": false, + "properties": { + "selector": { + "type": "object", + "additionalProperties": false, + "properties": { + "matchLabels": { + "type": "object", + "additionalProperties": false, + "properties": { + "olm.operatorframework.io/metadata.name": { + "default": "openshift-redhat-operators", + "title": "ClusterCatalog selector for OLM v1 ClusterExtension resources", + "type": "string" + } + } + } + } + } + } + } + } + }, "serverlessLogicOperator": { "type": "object", "additionalProperties": false, From 121d33d12f04a4e4e898f7063950f562a28e28f8 Mon Sep 17 00:00:00 2001 From: Fortune-Ndlovu Date: Wed, 16 Sep 2026 15:50:51 +0100 Subject: [PATCH 05/25] docs(orchestrator-infra): simplify OLM installation README text RHIDP-14789 Signed-off-by: Fortune Ndlovu --- charts/orchestrator-infra/README.md | 23 +++++++++------------- charts/orchestrator-infra/README.md.gotmpl | 21 ++++++++------------ charts/orchestrator-infra/values.yaml | 1 - 3 files changed, 17 insertions(+), 28 deletions(-) diff --git a/charts/orchestrator-infra/README.md b/charts/orchestrator-infra/README.md index f5ee771a5..d39a182ac 100644 --- a/charts/orchestrator-infra/README.md +++ b/charts/orchestrator-infra/README.md @@ -84,7 +84,7 @@ The command removes all the Kubernetes components associated with the chart and | Key | Description | Type | Default | |-----|-------------|------|---------| | olm.catalog.selector | ClusterCatalog selector for OLM v1 ClusterExtension resources | object | `{"matchLabels":{"olm.operatorframework.io/metadata.name":"openshift-redhat-operators"}}` | -| olmVersion | OLM API version to use for operator installation (`v0`, `v1`, or `auto`) Use `v0` on clusters without OLM v1, or until the v1 path is fully validated end-to-end. | string | `"v0"` | +| olmVersion | OLM API version to use for operator installation (`v0`, `v1`, or `auto`) | string | `"v0"` | | serverlessLogicOperator.clusterExtension.serviceAccount.name | service account used by OLM v1 to install the operator | string | `"serverless-logic-operator-installer"` | | serverlessLogicOperator.enabled | whether the operator should be deployed by the chart | bool | `true` | | serverlessLogicOperator.subscription.namespace | namespace where the operator should be deployed | string | `"openshift-serverless-logic"` | @@ -107,31 +107,26 @@ The command removes all the Kubernetes components associated with the chart and ### OLM v0 and OLM v1 operator installation -By default, the chart uses `olmVersion: v0` (classic OLM Subscriptions). Set `olmVersion: auto` on OLM v1 clusters once the v1 path is validated end-to-end. +The chart defaults to `olmVersion: v0`. -- **`v0`** — creates `Subscription` resources (classic OLM) -- **`v1`** — creates `ClusterExtension` resources with installer ServiceAccount and ClusterRoleBinding (OLM v1) -- **`auto`** — uses OLM v1 when the `clusterextensions.olm.operatorframework.io` CRD is present, otherwise OLM v0 - -Examples: +- `v0`: creates `Subscription` resources +- `v1`: creates `ClusterExtension` resources with an installer ServiceAccount and ClusterRoleBinding +- `auto`: uses OLM v1 when the `clusterextensions.olm.operatorframework.io` CRD is present; otherwise OLM v0 ```bash -# Force classic OLM Subscriptions (default) helm install my-orchestrator-infra ./charts/orchestrator-infra --set olmVersion=v0 - -# Force OLM v1 ClusterExtensions (requires OLM v1 on the cluster) helm install my-orchestrator-infra ./charts/orchestrator-infra --set olmVersion=v1 ``` -> **Note:** On OLM v1 clusters, use a clean cluster (no prior helm-managed Knative CRDs from a v0 install). After ClusterExtensions report `Installed=True`, create KnativeServing/KnativeEventing instances manually or via a follow-up release upgrade. +With `olmVersion=v1`, remove helm-managed Knative CRDs from a prior v0 install before upgrading. After the ClusterExtensions report `Installed=True`, create `KnativeServing` and `KnativeEventing` separately. ### Installing Knative Eventing and Knative Serving CRDs -The orchestrator-infra chart requires several CRDs for Knative Eventing and Knative Serving when using `olmVersion=v0`. These CRDs are installed from the `files/` directory via a Helm hook before the operator Subscriptions are applied. +With `olmVersion=v0`, the chart installs Knative Eventing and Knative Serving CRDs from `files/` using a Helm hook before the operator Subscriptions. -When using `olmVersion=v1`, the chart does not pre-install Knative CRDs or create KnativeServing/KnativeEventing instances in the same Helm transaction. The operator bundle installed via ClusterExtension provides the CRDs first. +With `olmVersion=v1`, the chart does not install those CRDs or create `KnativeServing`/`KnativeEventing` resources. The operator bundle installed by the ClusterExtension installs the CRDs. -In order to verify the correct CRD versions for the v0 path, use this following command to extract the CRD: +To verify CRD versions for the v0 path, run: ```bash export osl_bundle=registry.redhat.io/openshift-serverless-1/serverless-operator-bundle:1.38.0 diff --git a/charts/orchestrator-infra/README.md.gotmpl b/charts/orchestrator-infra/README.md.gotmpl index ebf4a6dbd..59ba2382f 100644 --- a/charts/orchestrator-infra/README.md.gotmpl +++ b/charts/orchestrator-infra/README.md.gotmpl @@ -78,31 +78,26 @@ The command removes all the Kubernetes components associated with the chart and ### OLM v0 and OLM v1 operator installation -By default, the chart uses `olmVersion: v0` (classic OLM Subscriptions). Set `olmVersion: auto` on OLM v1 clusters once the v1 path is validated end-to-end. +The chart defaults to `olmVersion: v0`. -- **`v0`** — creates `Subscription` resources (classic OLM) -- **`v1`** — creates `ClusterExtension` resources with installer ServiceAccount and ClusterRoleBinding (OLM v1) -- **`auto`** — uses OLM v1 when the `clusterextensions.olm.operatorframework.io` CRD is present, otherwise OLM v0 - -Examples: +- `v0`: creates `Subscription` resources +- `v1`: creates `ClusterExtension` resources with an installer ServiceAccount and ClusterRoleBinding +- `auto`: uses OLM v1 when the `clusterextensions.olm.operatorframework.io` CRD is present; otherwise OLM v0 ```bash -# Force classic OLM Subscriptions (default) helm install my-orchestrator-infra ./charts/orchestrator-infra --set olmVersion=v0 - -# Force OLM v1 ClusterExtensions (requires OLM v1 on the cluster) helm install my-orchestrator-infra ./charts/orchestrator-infra --set olmVersion=v1 ``` -> **Note:** On OLM v1 clusters, use a clean cluster (no prior helm-managed Knative CRDs from a v0 install). After ClusterExtensions report `Installed=True`, create KnativeServing/KnativeEventing instances manually or via a follow-up release upgrade. +With `olmVersion=v1`, remove helm-managed Knative CRDs from a prior v0 install before upgrading. After the ClusterExtensions report `Installed=True`, create `KnativeServing` and `KnativeEventing` separately. ### Installing Knative Eventing and Knative Serving CRDs -The orchestrator-infra chart requires several CRDs for Knative Eventing and Knative Serving when using `olmVersion=v0`. These CRDs are installed from the `files/` directory via a Helm hook before the operator Subscriptions are applied. +With `olmVersion=v0`, the chart installs Knative Eventing and Knative Serving CRDs from `files/` using a Helm hook before the operator Subscriptions. -When using `olmVersion=v1`, the chart does not pre-install Knative CRDs or create KnativeServing/KnativeEventing instances in the same Helm transaction. The operator bundle installed via ClusterExtension provides the CRDs first. +With `olmVersion=v1`, the chart does not install those CRDs or create `KnativeServing`/`KnativeEventing` resources. The operator bundle installed by the ClusterExtension installs the CRDs. -In order to verify the correct CRD versions for the v0 path, use this following command to extract the CRD: +To verify CRD versions for the v0 path, run: ```bash export osl_bundle=registry.redhat.io/openshift-serverless-1/serverless-operator-bundle:1.38.0 diff --git a/charts/orchestrator-infra/values.yaml b/charts/orchestrator-infra/values.yaml index 5487bf963..ad00204dd 100644 --- a/charts/orchestrator-infra/values.yaml +++ b/charts/orchestrator-infra/values.yaml @@ -1,5 +1,4 @@ # -- OLM API version to use for operator installation (`v0`, `v1`, or `auto`) -# Use `v0` on clusters without OLM v1, or until the v1 path is fully validated end-to-end. olmVersion: v0 olm: catalog: From d4b66d61036ae7adff17dcbd87b06654cc8e027d Mon Sep 17 00:00:00 2001 From: Fortune-Ndlovu Date: Wed, 16 Sep 2026 15:55:40 +0100 Subject: [PATCH 06/25] fix(orchestrator-infra): address Qodo review findings for OLM v1 path Remove upstream-olm-v1-values.yaml because chart-testing uses OLM v0 only. Require both release name and namespace when checking Helm ownership of ClusterExtensions. Skip rendering Subscriptions or ClusterExtensions when an unmanaged installer of the opposite kind already exists. RHIDP-14789 Signed-off-by: Fortune Ndlovu --- .../ci/upstream-olm-v1-values.yaml | 14 -------------- charts/orchestrator-infra/templates/NOTES.txt | 2 +- .../orchestrator-infra/templates/_helpers.tpl | 17 ++++++++++------- .../serverless-logic/clusterextension.yaml | 5 +++-- .../templates/serverless-logic/namespace.yaml | 2 +- .../serverless-logic/subscription.yaml | 11 +++++++---- .../templates/serverless/clusterextension.yaml | 5 +++-- .../templates/serverless/knatives.yaml | 8 ++++---- .../templates/serverless/namespace.yaml | 2 +- .../templates/serverless/subscription.yaml | 11 +++++++---- 10 files changed, 37 insertions(+), 40 deletions(-) delete mode 100644 charts/orchestrator-infra/ci/upstream-olm-v1-values.yaml diff --git a/charts/orchestrator-infra/ci/upstream-olm-v1-values.yaml b/charts/orchestrator-infra/ci/upstream-olm-v1-values.yaml deleted file mode 100644 index 2cb764810..000000000 --- a/charts/orchestrator-infra/ci/upstream-olm-v1-values.yaml +++ /dev/null @@ -1,14 +0,0 @@ -olmVersion: v1 - -serverlessLogicOperator: - enabled: true - subscription: - namespace: operators - spec: - sourceNamespace: olm - -serverlessOperator: - subscription: - namespace: operators - spec: - sourceNamespace: olm diff --git a/charts/orchestrator-infra/templates/NOTES.txt b/charts/orchestrator-infra/templates/NOTES.txt index 1897ccb63..2e0a06b03 100644 --- a/charts/orchestrator-infra/templates/NOTES.txt +++ b/charts/orchestrator-infra/templates/NOTES.txt @@ -11,7 +11,7 @@ Helm Release {{ .Release.Name }} installed in namespace {{ .Release.Namespace }} {{- $timeout := "--timeout=5m" }} {{- if .Values.serverlessOperator.enabled }} -{{- $unmanagedSubscriptionExists := include "unmanaged-resource-exists" (list "operators.coreos.com/v1alpha1" "Subscription" .Values.serverlessOperator.subscription.namespace "serverless-operator" .Release.Name .Capabilities.APIVersions ) }} +{{- $unmanagedSubscriptionExists := include "unmanaged-resource-exists" (list "operators.coreos.com/v1alpha1" "Subscription" .Values.serverlessOperator.subscription.namespace "serverless-operator" .Release.Name .Release.Namespace .Capabilities.APIVersions ) }} {{- if eq $unmanagedSubscriptionExists "false" }} {{- $serverlessOperatorInstalled = $yes }} {{- end }} diff --git a/charts/orchestrator-infra/templates/_helpers.tpl b/charts/orchestrator-infra/templates/_helpers.tpl index 5af8dd67e..816657ea4 100644 --- a/charts/orchestrator-infra/templates/_helpers.tpl +++ b/charts/orchestrator-infra/templates/_helpers.tpl @@ -6,14 +6,14 @@ {{- $namespace := index . 2 -}} {{- $name := index . 3 -}} {{- $releaseName := index . 4 -}} - {{- $apiCapabilities := index . 5 -}} - {{- $unmanagedSubscriptionExists := "true" -}} + {{- $releaseNamespace := index . 5 -}} + {{- $apiCapabilities := index . 6 -}} {{- if $apiCapabilities.Has (printf "%s/%s" $api $kind) }} {{- $existingOperator := lookup $api $kind $namespace $name -}} {{- if empty $existingOperator -}} {{- "false" -}} {{- else -}} - {{- $isManagedResource := include "is-managed-resource" (list $existingOperator $releaseName) -}} + {{- $isManagedResource := include "is-managed-resource" (list $existingOperator $releaseName $releaseNamespace) -}} {{- if eq $isManagedResource "true" -}} {{- "false" -}} {{- else -}} @@ -28,8 +28,10 @@ {{- define "is-managed-resource" -}} {{- $resource := index . 0 -}} {{- $releaseName := index . 1 -}} + {{- $releaseNamespace := index . 2 -}} {{- $resourceReleaseName := dig "metadata" "annotations" (dict "meta.helm.sh/release-name" "NA") $resource -}} - {{- if eq (get $resourceReleaseName "meta.helm.sh/release-name") $releaseName -}} + {{- $resourceReleaseNamespace := dig "metadata" "annotations" (dict "meta.helm.sh/release-namespace" "NA") $resource -}} + {{- if and (eq (get $resourceReleaseName "meta.helm.sh/release-name") $releaseName) (eq (get $resourceReleaseNamespace "meta.helm.sh/release-namespace") $releaseNamespace) -}} {{- "true" -}} {{- else -}} {{- "false" -}} @@ -52,13 +54,14 @@ {{- define "unmanaged-clusterextension-exists" -}} {{- $name := index . 0 -}} {{- $releaseName := index . 1 -}} - {{- $apiCapabilities := index . 2 -}} + {{- $releaseNamespace := index . 2 -}} + {{- $apiCapabilities := index . 3 -}} {{- if $apiCapabilities.Has "olm.operatorframework.io/v1/ClusterExtension" -}} {{- $existingExtension := lookup "olm.operatorframework.io/v1" "ClusterExtension" "" $name -}} {{- if empty $existingExtension -}} {{- "false" -}} {{- else -}} - {{- $isManagedResource := include "is-managed-resource" (list $existingExtension $releaseName) -}} + {{- $isManagedResource := include "is-managed-resource" (list $existingExtension $releaseName $releaseNamespace) -}} {{- if eq $isManagedResource "true" -}} {{- "false" -}} {{- else -}} @@ -75,4 +78,4 @@ {{- $packageName := index . 1 -}} {{- $version := trimPrefix (printf "%s." $packageName) $csv -}} {{- trimPrefix "v" $version -}} -{{- end -}} \ No newline at end of file +{{- end -}} diff --git a/charts/orchestrator-infra/templates/serverless-logic/clusterextension.yaml b/charts/orchestrator-infra/templates/serverless-logic/clusterextension.yaml index 631ad515f..28477b2b6 100644 --- a/charts/orchestrator-infra/templates/serverless-logic/clusterextension.yaml +++ b/charts/orchestrator-infra/templates/serverless-logic/clusterextension.yaml @@ -1,8 +1,9 @@ {{- $packageName := .Values.serverlessLogicOperator.subscription.spec.name -}} {{- $namespace := .Values.serverlessLogicOperator.subscription.namespace -}} {{- $serviceAccountName := .Values.serverlessLogicOperator.clusterExtension.serviceAccount.name -}} -{{- $unmanagedClusterExtensionExists := include "unmanaged-clusterextension-exists" (list $packageName .Release.Name .Capabilities.APIVersions) -}} -{{- if and (eq (include "olm-version" .) "v1") (eq $unmanagedClusterExtensionExists "false") .Values.serverlessLogicOperator.enabled }} +{{- $unmanagedClusterExtensionExists := include "unmanaged-clusterextension-exists" (list $packageName .Release.Name .Release.Namespace .Capabilities.APIVersions) -}} +{{- $unmanagedSubscriptionExists := include "unmanaged-resource-exists" (list "operators.coreos.com/v1alpha1" "Subscription" $namespace $packageName .Release.Name .Release.Namespace .Capabilities.APIVersions ) -}} +{{- if and (eq (include "olm-version" .) "v1") (eq $unmanagedClusterExtensionExists "false") (eq $unmanagedSubscriptionExists "false") .Values.serverlessLogicOperator.enabled }} apiVersion: v1 kind: ServiceAccount metadata: diff --git a/charts/orchestrator-infra/templates/serverless-logic/namespace.yaml b/charts/orchestrator-infra/templates/serverless-logic/namespace.yaml index 85a40de94..f7112dd68 100644 --- a/charts/orchestrator-infra/templates/serverless-logic/namespace.yaml +++ b/charts/orchestrator-infra/templates/serverless-logic/namespace.yaml @@ -1,4 +1,4 @@ -{{- $unmanagedNamespaceExists := include "unmanaged-resource-exists" (list "v1" "Namespace" "" .Values.serverlessLogicOperator.subscription.namespace .Release.Name .Capabilities.APIVersions) }} +{{- $unmanagedNamespaceExists := include "unmanaged-resource-exists" (list "v1" "Namespace" "" .Values.serverlessLogicOperator.subscription.namespace .Release.Name .Release.Namespace .Capabilities.APIVersions) }} {{- if and (eq $unmanagedNamespaceExists "false") .Values.serverlessLogicOperator.enabled }} --- apiVersion: v1 diff --git a/charts/orchestrator-infra/templates/serverless-logic/subscription.yaml b/charts/orchestrator-infra/templates/serverless-logic/subscription.yaml index 070f6f895..9092fb8c9 100644 --- a/charts/orchestrator-infra/templates/serverless-logic/subscription.yaml +++ b/charts/orchestrator-infra/templates/serverless-logic/subscription.yaml @@ -1,10 +1,13 @@ -{{- $unmanagedSubscriptionExists := include "unmanaged-resource-exists" (list "operators.coreos.com/v1alpha1" "Subscription" .Values.serverlessLogicOperator.subscription.namespace .Values.serverlessLogicOperator.subscription.spec.name .Release.Name .Capabilities.APIVersions ) }} -{{- if and (eq (include "olm-version" .) "v0") (eq $unmanagedSubscriptionExists "false") .Values.serverlessLogicOperator.enabled }} +{{- $packageName := .Values.serverlessLogicOperator.subscription.spec.name -}} +{{- $subscriptionNamespace := .Values.serverlessLogicOperator.subscription.namespace -}} +{{- $unmanagedSubscriptionExists := include "unmanaged-resource-exists" (list "operators.coreos.com/v1alpha1" "Subscription" $subscriptionNamespace $packageName .Release.Name .Release.Namespace .Capabilities.APIVersions ) -}} +{{- $unmanagedClusterExtensionExists := include "unmanaged-clusterextension-exists" (list $packageName .Release.Name .Release.Namespace .Capabilities.APIVersions) -}} +{{- if and (eq (include "olm-version" .) "v0") (eq $unmanagedSubscriptionExists "false") (eq $unmanagedClusterExtensionExists "false") .Values.serverlessLogicOperator.enabled }} apiVersion: operators.coreos.com/v1alpha1 kind: Subscription metadata: - name: {{ .Values.serverlessLogicOperator.subscription.spec.name }} - namespace: {{ .Values.serverlessLogicOperator.subscription.namespace }} + name: {{ $packageName }} + namespace: {{ $subscriptionNamespace }} spec: {{- toYaml .Values.serverlessLogicOperator.subscription.spec | nindent 2 }} {{- end }} diff --git a/charts/orchestrator-infra/templates/serverless/clusterextension.yaml b/charts/orchestrator-infra/templates/serverless/clusterextension.yaml index 5e22e9bf2..4382c0cfc 100644 --- a/charts/orchestrator-infra/templates/serverless/clusterextension.yaml +++ b/charts/orchestrator-infra/templates/serverless/clusterextension.yaml @@ -1,8 +1,9 @@ {{- $packageName := .Values.serverlessOperator.subscription.spec.name -}} {{- $namespace := .Values.serverlessOperator.subscription.namespace -}} {{- $serviceAccountName := .Values.serverlessOperator.clusterExtension.serviceAccount.name -}} -{{- $unmanagedClusterExtensionExists := include "unmanaged-clusterextension-exists" (list $packageName .Release.Name .Capabilities.APIVersions) -}} -{{- if and (eq (include "olm-version" .) "v1") (eq $unmanagedClusterExtensionExists "false") .Values.serverlessOperator.enabled }} +{{- $unmanagedClusterExtensionExists := include "unmanaged-clusterextension-exists" (list $packageName .Release.Name .Release.Namespace .Capabilities.APIVersions) -}} +{{- $unmanagedSubscriptionExists := include "unmanaged-resource-exists" (list "operators.coreos.com/v1alpha1" "Subscription" $namespace $packageName .Release.Name .Release.Namespace .Capabilities.APIVersions ) -}} +{{- if and (eq (include "olm-version" .) "v1") (eq $unmanagedClusterExtensionExists "false") (eq $unmanagedSubscriptionExists "false") .Values.serverlessOperator.enabled }} apiVersion: v1 kind: ServiceAccount metadata: diff --git a/charts/orchestrator-infra/templates/serverless/knatives.yaml b/charts/orchestrator-infra/templates/serverless/knatives.yaml index d2e64a55a..d70440daf 100644 --- a/charts/orchestrator-infra/templates/serverless/knatives.yaml +++ b/charts/orchestrator-infra/templates/serverless/knatives.yaml @@ -1,5 +1,5 @@ {{- if .Values.serverlessOperator.enabled }} -{{- $unmanagedNamespaceExists := include "unmanaged-resource-exists" (list "v1" "Namespace" "" "knative-serving" .Release.Name .Capabilities.APIVersions) }} +{{- $unmanagedNamespaceExists := include "unmanaged-resource-exists" (list "v1" "Namespace" "" "knative-serving" .Release.Name .Release.Namespace .Capabilities.APIVersions) }} {{- if eq $unmanagedNamespaceExists "false" }} --- apiVersion: v1 @@ -12,7 +12,7 @@ metadata: "helm.sh/resource-policy": keep {{- end }} -{{- $unmanagedNamespaceExists := include "unmanaged-resource-exists" (list "v1" "Namespace" "" "knative-eventing" .Release.Name .Capabilities.APIVersions) }} +{{- $unmanagedNamespaceExists := include "unmanaged-resource-exists" (list "v1" "Namespace" "" "knative-eventing" .Release.Name .Release.Namespace .Capabilities.APIVersions) }} {{- if eq $unmanagedNamespaceExists "false" }} --- apiVersion: v1 @@ -25,7 +25,7 @@ metadata: "helm.sh/resource-policy": keep {{- end }} -{{- $unmanagedKnativeEventingExists := include "unmanaged-resource-exists" (list "operator.knative.dev/v1beta1" "KnativeEventing" "knative-eventing" "knative-eventing" .Release.Name .Capabilities.APIVersions) }} +{{- $unmanagedKnativeEventingExists := include "unmanaged-resource-exists" (list "operator.knative.dev/v1beta1" "KnativeEventing" "knative-eventing" "knative-eventing" .Release.Name .Release.Namespace .Capabilities.APIVersions) }} {{- if and (eq $unmanagedKnativeEventingExists "false") (ne (include "olm-version" .) "v1") }} --- apiVersion: operator.knative.dev/v1beta1 @@ -37,7 +37,7 @@ spec: Registry: {{- end }} -{{- $unmanagedKnativeServingExists := include "unmanaged-resource-exists" (list "operator.knative.dev/v1beta1" "KnativeServing" "knative-serving" "knative-serving" .Release.Name .Capabilities.APIVersions) }} +{{- $unmanagedKnativeServingExists := include "unmanaged-resource-exists" (list "operator.knative.dev/v1beta1" "KnativeServing" "knative-serving" "knative-serving" .Release.Name .Release.Namespace .Capabilities.APIVersions) }} {{- if and (eq $unmanagedKnativeServingExists "false") (ne (include "olm-version" .) "v1") }} --- apiVersion: operator.knative.dev/v1beta1 diff --git a/charts/orchestrator-infra/templates/serverless/namespace.yaml b/charts/orchestrator-infra/templates/serverless/namespace.yaml index cf7cba3ba..d7517085d 100644 --- a/charts/orchestrator-infra/templates/serverless/namespace.yaml +++ b/charts/orchestrator-infra/templates/serverless/namespace.yaml @@ -1,4 +1,4 @@ -{{- $unmanagedNamespaceExists := include "unmanaged-resource-exists" (list "v1" "Namespace" "" .Values.serverlessOperator.subscription.namespace .Release.Name .Capabilities.APIVersions) }} +{{- $unmanagedNamespaceExists := include "unmanaged-resource-exists" (list "v1" "Namespace" "" .Values.serverlessOperator.subscription.namespace .Release.Name .Release.Namespace .Capabilities.APIVersions) }} {{- if and (eq $unmanagedNamespaceExists "false") .Values.serverlessOperator.enabled }} --- apiVersion: v1 diff --git a/charts/orchestrator-infra/templates/serverless/subscription.yaml b/charts/orchestrator-infra/templates/serverless/subscription.yaml index 3510555fb..580a5ed15 100644 --- a/charts/orchestrator-infra/templates/serverless/subscription.yaml +++ b/charts/orchestrator-infra/templates/serverless/subscription.yaml @@ -1,10 +1,13 @@ -{{- $unmanagedSubscriptionExists := include "unmanaged-resource-exists" (list "operators.coreos.com/v1alpha1" "Subscription" .Values.serverlessOperator.subscription.namespace .Values.serverlessOperator.subscription.spec.name .Release.Name .Capabilities.APIVersions ) }} -{{- if and (eq (include "olm-version" .) "v0") (eq $unmanagedSubscriptionExists "false") .Values.serverlessOperator.enabled }} +{{- $packageName := .Values.serverlessOperator.subscription.spec.name -}} +{{- $subscriptionNamespace := .Values.serverlessOperator.subscription.namespace -}} +{{- $unmanagedSubscriptionExists := include "unmanaged-resource-exists" (list "operators.coreos.com/v1alpha1" "Subscription" $subscriptionNamespace $packageName .Release.Name .Release.Namespace .Capabilities.APIVersions ) -}} +{{- $unmanagedClusterExtensionExists := include "unmanaged-clusterextension-exists" (list $packageName .Release.Name .Release.Namespace .Capabilities.APIVersions) -}} +{{- if and (eq (include "olm-version" .) "v0") (eq $unmanagedSubscriptionExists "false") (eq $unmanagedClusterExtensionExists "false") .Values.serverlessOperator.enabled }} apiVersion: operators.coreos.com/v1alpha1 kind: Subscription metadata: - name: {{ .Values.serverlessOperator.subscription.spec.name }} - namespace: {{ .Values.serverlessOperator.subscription.namespace }} + name: {{ $packageName }} + namespace: {{ $subscriptionNamespace }} spec: {{- toYaml .Values.serverlessOperator.subscription.spec | nindent 2 }} {{- end }} From c83f8ec5074ad6c894fcf168fa2a16584911a944 Mon Sep 17 00:00:00 2001 From: Fortune-Ndlovu Date: Wed, 16 Sep 2026 16:06:51 +0100 Subject: [PATCH 07/25] fix(orchestrator-infra): fix CRD hooks for chart-testing upgrade path Install Knative CRDs with pre-install hooks only and skip applying them when they already exist. This avoids ct install --upgrade failures when upgrading from 0.6.1, which installed CRDs from the crds/ directory. RHIDP-14789 Signed-off-by: Fortune Ndlovu --- charts/orchestrator-infra/files/knative-eventing-crd.yaml | 2 +- charts/orchestrator-infra/files/knative-serving-crd.yaml | 2 +- charts/orchestrator-infra/templates/crds.yaml | 4 ++++ 3 files changed, 6 insertions(+), 2 deletions(-) diff --git a/charts/orchestrator-infra/files/knative-eventing-crd.yaml b/charts/orchestrator-infra/files/knative-eventing-crd.yaml index 02dfc1cc8..c3242bb73 100644 --- a/charts/orchestrator-infra/files/knative-eventing-crd.yaml +++ b/charts/orchestrator-infra/files/knative-eventing-crd.yaml @@ -17,7 +17,7 @@ kind: CustomResourceDefinition metadata: name: knativeeventings.operator.knative.dev annotations: - "helm.sh/hook": pre-install,pre-upgrade,pre-delete + "helm.sh/hook": pre-install "helm.sh/hook-weight": "-10" "helm.sh/hook-delete-policy": before-hook-creation labels: diff --git a/charts/orchestrator-infra/files/knative-serving-crd.yaml b/charts/orchestrator-infra/files/knative-serving-crd.yaml index 176fe9e2a..7f6787e6e 100644 --- a/charts/orchestrator-infra/files/knative-serving-crd.yaml +++ b/charts/orchestrator-infra/files/knative-serving-crd.yaml @@ -17,7 +17,7 @@ kind: CustomResourceDefinition metadata: name: knativeservings.operator.knative.dev annotations: - "helm.sh/hook": pre-install,pre-upgrade,pre-delete + "helm.sh/hook": pre-install "helm.sh/hook-weight": "-10" "helm.sh/hook-delete-policy": before-hook-creation labels: diff --git a/charts/orchestrator-infra/templates/crds.yaml b/charts/orchestrator-infra/templates/crds.yaml index 4eba621d3..28cc4eb61 100644 --- a/charts/orchestrator-infra/templates/crds.yaml +++ b/charts/orchestrator-infra/templates/crds.yaml @@ -1,5 +1,9 @@ {{- if eq (include "olm-version" .) "v0" }} +{{- if not (lookup "apiextensions.k8s.io/v1" "CustomResourceDefinition" "" "knativeservings.operator.knative.dev") }} {{ .Files.Get "files/knative-serving-crd.yaml" }} --- +{{- end }} +{{- if not (lookup "apiextensions.k8s.io/v1" "CustomResourceDefinition" "" "knativeeventings.operator.knative.dev") }} {{ .Files.Get "files/knative-eventing-crd.yaml" }} {{- end }} +{{- end }} From 21d13014316a88dc5402d6bc99f61ec0911da0f7 Mon Sep 17 00:00:00 2001 From: Fortune-Ndlovu Date: Wed, 16 Sep 2026 16:13:38 +0100 Subject: [PATCH 08/25] fix(orchestrator-infra): restore Knative CRDs under crds/ unchanged Revert the move to files/ and hook annotation changes. Helm installs CRDs from crds/ as before, which keeps chart-testing upgrades working without modifying the CRD manifests. RHIDP-14789 Signed-off-by: Fortune Ndlovu --- charts/orchestrator-infra/README.md | 10 ++++------ charts/orchestrator-infra/README.md.gotmpl | 10 ++++------ .../knative-eventing}/knative-eventing-crd.yaml | 2 +- .../knative-serving}/knative-serving-crd.yaml | 2 +- charts/orchestrator-infra/templates/crds.yaml | 9 --------- 5 files changed, 10 insertions(+), 23 deletions(-) rename charts/orchestrator-infra/{files => crds/knative-eventing}/knative-eventing-crd.yaml (99%) rename charts/orchestrator-infra/{files => crds/knative-serving}/knative-serving-crd.yaml (99%) delete mode 100644 charts/orchestrator-infra/templates/crds.yaml diff --git a/charts/orchestrator-infra/README.md b/charts/orchestrator-infra/README.md index d39a182ac..677d849b3 100644 --- a/charts/orchestrator-infra/README.md +++ b/charts/orchestrator-infra/README.md @@ -122,17 +122,15 @@ With `olmVersion=v1`, remove helm-managed Knative CRDs from a prior v0 install b ### Installing Knative Eventing and Knative Serving CRDs -With `olmVersion=v0`, the chart installs Knative Eventing and Knative Serving CRDs from `files/` using a Helm hook before the operator Subscriptions. +The chart ships Knative Eventing and Knative Serving CRDs under `crds/`. Helm installs them before the rest of the chart on every install or upgrade. -With `olmVersion=v1`, the chart does not install those CRDs or create `KnativeServing`/`KnativeEventing` resources. The operator bundle installed by the ClusterExtension installs the CRDs. - -To verify CRD versions for the v0 path, run: +To verify CRD versions, run: ```bash export osl_bundle=registry.redhat.io/openshift-serverless-1/serverless-operator-bundle:1.38.0 -podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1beta1_knativeeventing_crd.yaml > files/knative-eventing-crd.yaml +podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1beta1_knativeeventing_crd.yaml > crds/knative-eventing/knative-eventing-crd.yaml -podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1beta1_knativeserving_crd.yaml > files/knative-serving-crd.yaml +podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1beta1_knativeserving_crd.yaml > crds/knative-serving/knative-serving-crd.yaml ``` After running these commands, you may need to re-add the `helm.sh/hook` annotations. diff --git a/charts/orchestrator-infra/README.md.gotmpl b/charts/orchestrator-infra/README.md.gotmpl index 59ba2382f..e28163e93 100644 --- a/charts/orchestrator-infra/README.md.gotmpl +++ b/charts/orchestrator-infra/README.md.gotmpl @@ -93,17 +93,15 @@ With `olmVersion=v1`, remove helm-managed Knative CRDs from a prior v0 install b ### Installing Knative Eventing and Knative Serving CRDs -With `olmVersion=v0`, the chart installs Knative Eventing and Knative Serving CRDs from `files/` using a Helm hook before the operator Subscriptions. +The chart ships Knative Eventing and Knative Serving CRDs under `crds/`. Helm installs them before the rest of the chart on every install or upgrade. -With `olmVersion=v1`, the chart does not install those CRDs or create `KnativeServing`/`KnativeEventing` resources. The operator bundle installed by the ClusterExtension installs the CRDs. - -To verify CRD versions for the v0 path, run: +To verify CRD versions, run: ```bash export osl_bundle=registry.redhat.io/openshift-serverless-1/serverless-operator-bundle:1.38.0 -podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1beta1_knativeeventing_crd.yaml > files/knative-eventing-crd.yaml +podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1beta1_knativeeventing_crd.yaml > crds/knative-eventing/knative-eventing-crd.yaml -podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1beta1_knativeserving_crd.yaml > files/knative-serving-crd.yaml +podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1beta1_knativeserving_crd.yaml > crds/knative-serving/knative-serving-crd.yaml ``` After running these commands, you may need to re-add the `helm.sh/hook` annotations. diff --git a/charts/orchestrator-infra/files/knative-eventing-crd.yaml b/charts/orchestrator-infra/crds/knative-eventing/knative-eventing-crd.yaml similarity index 99% rename from charts/orchestrator-infra/files/knative-eventing-crd.yaml rename to charts/orchestrator-infra/crds/knative-eventing/knative-eventing-crd.yaml index c3242bb73..ee3bbfd24 100644 --- a/charts/orchestrator-infra/files/knative-eventing-crd.yaml +++ b/charts/orchestrator-infra/crds/knative-eventing/knative-eventing-crd.yaml @@ -17,7 +17,7 @@ kind: CustomResourceDefinition metadata: name: knativeeventings.operator.knative.dev annotations: - "helm.sh/hook": pre-install + "helm.sh/hook": pre-delete "helm.sh/hook-weight": "-10" "helm.sh/hook-delete-policy": before-hook-creation labels: diff --git a/charts/orchestrator-infra/files/knative-serving-crd.yaml b/charts/orchestrator-infra/crds/knative-serving/knative-serving-crd.yaml similarity index 99% rename from charts/orchestrator-infra/files/knative-serving-crd.yaml rename to charts/orchestrator-infra/crds/knative-serving/knative-serving-crd.yaml index 7f6787e6e..3a316a833 100644 --- a/charts/orchestrator-infra/files/knative-serving-crd.yaml +++ b/charts/orchestrator-infra/crds/knative-serving/knative-serving-crd.yaml @@ -17,7 +17,7 @@ kind: CustomResourceDefinition metadata: name: knativeservings.operator.knative.dev annotations: - "helm.sh/hook": pre-install + "helm.sh/hook": pre-delete "helm.sh/hook-weight": "-10" "helm.sh/hook-delete-policy": before-hook-creation labels: diff --git a/charts/orchestrator-infra/templates/crds.yaml b/charts/orchestrator-infra/templates/crds.yaml deleted file mode 100644 index 28cc4eb61..000000000 --- a/charts/orchestrator-infra/templates/crds.yaml +++ /dev/null @@ -1,9 +0,0 @@ -{{- if eq (include "olm-version" .) "v0" }} -{{- if not (lookup "apiextensions.k8s.io/v1" "CustomResourceDefinition" "" "knativeservings.operator.knative.dev") }} -{{ .Files.Get "files/knative-serving-crd.yaml" }} ---- -{{- end }} -{{- if not (lookup "apiextensions.k8s.io/v1" "CustomResourceDefinition" "" "knativeeventings.operator.knative.dev") }} -{{ .Files.Get "files/knative-eventing-crd.yaml" }} -{{- end }} -{{- end }} From 5b84aec41cf858117917afec6c2bf69ac00f8de3 Mon Sep 17 00:00:00 2001 From: Fortune-Ndlovu Date: Thu, 17 Sep 2026 11:18:56 +0100 Subject: [PATCH 09/25] fix(orchestrator-infra): use OLM API name in helm test Use subscription.operators.coreos.com in the test pod so kubectl does not resolve to Knative messaging subscriptions on Serverless clusters. RHIDP-14789 Signed-off-by: Fortune Ndlovu --- charts/orchestrator-infra/templates/tests/infra-test.yaml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/charts/orchestrator-infra/templates/tests/infra-test.yaml b/charts/orchestrator-infra/templates/tests/infra-test.yaml index 184f441fc..2fd9d64aa 100644 --- a/charts/orchestrator-infra/templates/tests/infra-test.yaml +++ b/charts/orchestrator-infra/templates/tests/infra-test.yaml @@ -136,7 +136,7 @@ spec: {{- if eq (include "olm-version" .) "v1" }} kubectl get clusterextension {{ .Values.serverlessOperator.subscription.spec.name }} || exit 1 {{- else }} - kubectl get subscription {{ .Values.serverlessOperator.subscription.spec.name }} -n {{ .Values.serverlessOperator.subscription.namespace }} || exit 1 + kubectl get subscription.operators.coreos.com {{ .Values.serverlessOperator.subscription.spec.name }} -n {{ .Values.serverlessOperator.subscription.namespace }} || exit 1 {{- end }} {{- end }} @@ -144,7 +144,7 @@ spec: {{- if eq (include "olm-version" .) "v1" }} kubectl get clusterextension {{ .Values.serverlessLogicOperator.subscription.spec.name }} || exit 1 {{- else }} - kubectl get subscription {{ .Values.serverlessLogicOperator.subscription.spec.name }} -n {{ .Values.serverlessLogicOperator.subscription.namespace }} || exit 1 + kubectl get subscription.operators.coreos.com {{ .Values.serverlessLogicOperator.subscription.spec.name }} -n {{ .Values.serverlessLogicOperator.subscription.namespace }} || exit 1 {{- end }} {{- end }} From dbb6b4c132c8f631699d1fac06ff995883c8f09c Mon Sep 17 00:00:00 2001 From: Fortune-Ndlovu Date: Thu, 17 Sep 2026 12:13:53 +0100 Subject: [PATCH 10/25] fix(orchestrator-infra): address Qodo review items 1, 4, and 5 (#543) Gate Knative CRD install to the OLM v0 path, relax catalog selector schema validation, and provision Knative instances on v1 via a post-install hook after ClusterExtension install completes. RHIDP-14789 Signed-off-by: Fortune-Ndlovu --- .github/actions/test-charts/action.yml | 5 +- .github/pull_request_template.md | 2 +- CONTRIBUTING.md | 2 +- charts/orchestrator-infra/README.md | 57 ++++---- charts/orchestrator-infra/README.md.gotmpl | 10 +- .../knative-eventing/knative-eventing-cr.yaml | 7 + .../knative-eventing-crd.yaml | 4 +- .../knative-serving/knative-serving-cr.yaml | 10 ++ .../knative-serving/knative-serving-crd.yaml | 4 +- .../templates/serverless/knative-crds.yaml | 5 + .../serverless/knative-v1-post-install.yaml | 133 ++++++++++++++++++ charts/orchestrator-infra/values.schema.json | 29 +++- .../values.schema.tmpl.json | 26 +++- 13 files changed, 249 insertions(+), 45 deletions(-) create mode 100644 charts/orchestrator-infra/files/knative-eventing/knative-eventing-cr.yaml rename charts/orchestrator-infra/{crds => files}/knative-eventing/knative-eventing-crd.yaml (99%) create mode 100644 charts/orchestrator-infra/files/knative-serving/knative-serving-cr.yaml rename charts/orchestrator-infra/{crds => files}/knative-serving/knative-serving-crd.yaml (99%) create mode 100644 charts/orchestrator-infra/templates/serverless/knative-crds.yaml create mode 100644 charts/orchestrator-infra/templates/serverless/knative-v1-post-install.yaml diff --git a/.github/actions/test-charts/action.yml b/.github/actions/test-charts/action.yml index 1f4c0fccb..7d27c8f9e 100644 --- a/.github/actions/test-charts/action.yml +++ b/.github/actions/test-charts/action.yml @@ -190,9 +190,8 @@ runs: env: SONATAFLOW_OPERATOR_VERSION: "10.1.0" run: | - for crdDir in charts/orchestrator-infra/crds/*; do - kubectl create -f "${crdDir}" - done + kubectl create -f charts/orchestrator-infra/files/knative-eventing/knative-eventing-crd.yaml + kubectl create -f charts/orchestrator-infra/files/knative-serving/knative-serving-crd.yaml kubectl create -f "https://github.com/apache/incubator-kie-tools/releases/download/${SONATAFLOW_OPERATOR_VERSION}/apache-kie-${SONATAFLOW_OPERATOR_VERSION}-incubating-sonataflow-operator.yaml" - name: Set up external services and test resources for rhdh diff --git a/.github/pull_request_template.md b/.github/pull_request_template.md index d0e67e93d..0c63846f8 100644 --- a/.github/pull_request_template.md +++ b/.github/pull_request_template.md @@ -27,4 +27,4 @@ Detailed instructions may help reviewers test this PR quickly and provide quicke - [ ] For each Chart updated, variables are documented in the `values.yaml` and added to the corresponding README.md. The [pre-commit](https://pre-commit.com/) utility can be used to generate the necessary content. Run `pre-commit run --all-files` to run the hooks and then push any resulting changes. The [pre-commit Workflow](./workflows/pre-commit.yaml) will enforce this and warn you if needed. - [ ] JSON Schema template updated and re-generated the raw schema via the `pre-commit` hook. - [ ] Tests pass using the [Chart Testing](https://github.com/helm/chart-testing) tool and the `ct lint` command. -- [ ] If you updated the [orchestrator-infra](../charts/orchestrator-infra) chart, make sure the versions of the [Knative CRDs](../charts/orchestrator-infra/crds) are aligned with the versions of the CRDs installed by the OpenShift Serverless operators declared in the [values.yaml](../charts/orchestrator-infra/values.yaml) file. See [Installing Knative Eventing and Knative Serving CRDs](../charts/orchestrator-infra/README.md#installing-knative-eventing-and-knative-serving-crds) for more details. +- [ ] If you updated the [orchestrator-infra](../charts/orchestrator-infra) chart, make sure the versions of the [Knative CRDs](../charts/orchestrator-infra/files) are aligned with the versions of the CRDs installed by the OpenShift Serverless operators declared in the [values.yaml](../charts/orchestrator-infra/values.yaml) file. See [Installing Knative Eventing and Knative Serving CRDs](../charts/orchestrator-infra/README.md#installing-knative-eventing-and-knative-serving-crds) for more details. diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 91eb4bd0a..04c121503 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -9,7 +9,7 @@ Before making a contribution to the charts in this repository, you will need to - For each Chart updated, version bumped in the corresponding `Chart.yaml` according to [Semantic Versioning](http://semver.org/). - For each Chart updated, ensure variables are documented in the corresponding `values.yaml` file and the [pre-commit](https://pre-commit.com/) hook has been run with `pre-commit run --all-files` to generate the corresponding `README.md` documentation. The [pre-commit Workflow](./.github/workflows/pre-commit.yaml) will enforce this and warn you if needed. - JSON Schema template updated and re-generated the raw schema via the `pre-commit` hook. -- [ ] If you updated the [orchestrator-infra](./charts/orchestrator-infra) chart, make sure the versions of the [Knative CRDs](./charts/orchestrator-infra/crds) are aligned with the versions of the CRDs installed by the OpenShift Serverless operators declared in the [values.yaml](./charts/orchestrator-infra/values.yaml) file. See [Installing Knative Eventing and Knative Serving CRDs](./charts/orchestrator-infra/README.md#installing-knative-eventing-and-knative-serving-crds) for more details. +- [ ] If you updated the [orchestrator-infra](./charts/orchestrator-infra) chart, make sure the versions of the [Knative CRDs](./charts/orchestrator-infra/files) are aligned with the versions of the CRDs installed by the OpenShift Serverless operators declared in the [values.yaml](./charts/orchestrator-infra/values.yaml) file. See [Installing Knative Eventing and Knative Serving CRDs](./charts/orchestrator-infra/README.md#installing-knative-eventing-and-knative-serving-crds) for more details. ## Sync Lightspeed Core vendored config files diff --git a/charts/orchestrator-infra/README.md b/charts/orchestrator-infra/README.md index 677d849b3..72da9f68a 100644 --- a/charts/orchestrator-infra/README.md +++ b/charts/orchestrator-infra/README.md @@ -1,4 +1,3 @@ - # Orchestrator Infra Chart for OpenShift ![Version: 0.6.2](https://img.shields.io/badge/Version-0.6.2-informational?style=flat-square) @@ -81,29 +80,29 @@ The command removes all the Kubernetes components associated with the chart and ## Values -| Key | Description | Type | Default | -|-----|-------------|------|---------| -| olm.catalog.selector | ClusterCatalog selector for OLM v1 ClusterExtension resources | object | `{"matchLabels":{"olm.operatorframework.io/metadata.name":"openshift-redhat-operators"}}` | -| olmVersion | OLM API version to use for operator installation (`v0`, `v1`, or `auto`) | string | `"v0"` | -| serverlessLogicOperator.clusterExtension.serviceAccount.name | service account used by OLM v1 to install the operator | string | `"serverless-logic-operator-installer"` | -| serverlessLogicOperator.enabled | whether the operator should be deployed by the chart | bool | `true` | -| serverlessLogicOperator.subscription.namespace | namespace where the operator should be deployed | string | `"openshift-serverless-logic"` | -| serverlessLogicOperator.subscription.spec.channel | channel of an operator package to subscribe to | string | `"stable"` | -| serverlessLogicOperator.subscription.spec.installPlanApproval | whether the update should be installed automatically | string | `"Manual"` | -| serverlessLogicOperator.subscription.spec.name | name of the operator package | string | `"logic-operator"` | -| serverlessLogicOperator.subscription.spec.source | name of the catalog source | string | `"redhat-operators"` | -| serverlessLogicOperator.subscription.spec.sourceNamespace | | string | `"openshift-marketplace"` | -| serverlessLogicOperator.subscription.spec.startingCSV | The initial version of the operator, must match CRDs installed by the chart | string | `"logic-operator.v1.38.0"` | -| serverlessOperator.clusterExtension.serviceAccount.name | service account used by OLM v1 to install the operator | string | `"serverless-operator-installer"` | -| serverlessOperator.enabled | whether the operator should be deployed by the chart | bool | `true` | -| serverlessOperator.subscription.namespace | namespace where the operator should be deployed | string | `"openshift-serverless"` | -| serverlessOperator.subscription.spec.channel | channel of an operator package to subscribe to | string | `"stable"` | -| serverlessOperator.subscription.spec.installPlanApproval | whether the update should be installed automatically | string | `"Manual"` | -| serverlessOperator.subscription.spec.name | name of the operator package | string | `"serverless-operator"` | -| serverlessOperator.subscription.spec.source | name of the catalog source | string | `"redhat-operators"` | -| serverlessOperator.subscription.spec.sourceNamespace | | string | `"openshift-marketplace"` | -| tests.enabled | Whether to create the test pod used for testing the Release using `helm test`. | bool | `true` | -| tests.image | Test pod image | string | `"bitnami/kubectl:latest"` | +| Key | Type | Default | Description | +|-----|------|---------|-------------| +| olm.catalog.selector | object | `{"matchLabels":{"olm.operatorframework.io/metadata.name":"openshift-redhat-operators"}}` | ClusterCatalog selector for OLM v1 ClusterExtension resources | +| olmVersion | string | `"v0"` | OLM API version to use for operator installation (`v0`, `v1`, or `auto`) | +| serverlessLogicOperator.clusterExtension.serviceAccount.name | string | `"serverless-logic-operator-installer"` | service account used by OLM v1 to install the operator | +| serverlessLogicOperator.enabled | bool | `true` | whether the operator should be deployed by the chart | +| serverlessLogicOperator.subscription.namespace | string | `"openshift-serverless-logic"` | namespace where the operator should be deployed | +| serverlessLogicOperator.subscription.spec.channel | string | `"stable"` | channel of an operator package to subscribe to | +| serverlessLogicOperator.subscription.spec.installPlanApproval | string | `"Manual"` | whether the update should be installed automatically | +| serverlessLogicOperator.subscription.spec.name | string | `"logic-operator"` | name of the operator package | +| serverlessLogicOperator.subscription.spec.source | string | `"redhat-operators"` | name of the catalog source | +| serverlessLogicOperator.subscription.spec.sourceNamespace | string | `"openshift-marketplace"` | | +| serverlessLogicOperator.subscription.spec.startingCSV | string | `"logic-operator.v1.38.0"` | The initial version of the operator, must match CRDs installed by the chart | +| serverlessOperator.clusterExtension.serviceAccount.name | string | `"serverless-operator-installer"` | service account used by OLM v1 to install the operator | +| serverlessOperator.enabled | bool | `true` | whether the operator should be deployed by the chart | +| serverlessOperator.subscription.namespace | string | `"openshift-serverless"` | namespace where the operator should be deployed | +| serverlessOperator.subscription.spec.channel | string | `"stable"` | channel of an operator package to subscribe to | +| serverlessOperator.subscription.spec.installPlanApproval | string | `"Manual"` | whether the update should be installed automatically | +| serverlessOperator.subscription.spec.name | string | `"serverless-operator"` | name of the operator package | +| serverlessOperator.subscription.spec.source | string | `"redhat-operators"` | name of the catalog source | +| serverlessOperator.subscription.spec.sourceNamespace | string | `"openshift-marketplace"` | | +| tests.enabled | bool | `true` | Whether to create the test pod used for testing the Release using `helm test`. | +| tests.image | string | `"bitnami/kubectl:latest"` | Test pod image | ### OLM v0 and OLM v1 operator installation @@ -118,19 +117,19 @@ helm install my-orchestrator-infra ./charts/orchestrator-infra --set olmVersion= helm install my-orchestrator-infra ./charts/orchestrator-infra --set olmVersion=v1 ``` -With `olmVersion=v1`, remove helm-managed Knative CRDs from a prior v0 install before upgrading. After the ClusterExtensions report `Installed=True`, create `KnativeServing` and `KnativeEventing` separately. +With `olmVersion=v1`, remove helm-managed Knative CRDs from a prior v0 install before upgrading. A post-install hook waits for the Serverless ClusterExtension and operator CRDs, then creates `KnativeServing` and `KnativeEventing`. ### Installing Knative Eventing and Knative Serving CRDs -The chart ships Knative Eventing and Knative Serving CRDs under `crds/`. Helm installs them before the rest of the chart on every install or upgrade. +The chart ships Knative Eventing and Knative Serving CRDs under `files/`. On the OLM v0 path, Helm applies them via pre-install hooks. On the OLM v1 path, the Serverless operator bundle installs the CRDs instead. To verify CRD versions, run: ```bash export osl_bundle=registry.redhat.io/openshift-serverless-1/serverless-operator-bundle:1.38.0 -podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1beta1_knativeeventing_crd.yaml > crds/knative-eventing/knative-eventing-crd.yaml +podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1beta1_knativeeventing_crd.yaml > files/knative-eventing/knative-eventing-crd.yaml -podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1beta1_knativeserving_crd.yaml > crds/knative-serving/knative-serving-crd.yaml +podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1beta1_knativeserving_crd.yaml > files/knative-serving/knative-serving-crd.yaml ``` -After running these commands, you may need to re-add the `helm.sh/hook` annotations. +After running these commands, you may need to re-add the `helm.sh/hook` annotations on the OLM v0 path. diff --git a/charts/orchestrator-infra/README.md.gotmpl b/charts/orchestrator-infra/README.md.gotmpl index e28163e93..8b3954b47 100644 --- a/charts/orchestrator-infra/README.md.gotmpl +++ b/charts/orchestrator-infra/README.md.gotmpl @@ -89,19 +89,19 @@ helm install my-orchestrator-infra ./charts/orchestrator-infra --set olmVersion= helm install my-orchestrator-infra ./charts/orchestrator-infra --set olmVersion=v1 ``` -With `olmVersion=v1`, remove helm-managed Knative CRDs from a prior v0 install before upgrading. After the ClusterExtensions report `Installed=True`, create `KnativeServing` and `KnativeEventing` separately. +With `olmVersion=v1`, remove helm-managed Knative CRDs from a prior v0 install before upgrading. A post-install hook waits for the Serverless ClusterExtension and operator CRDs, then creates `KnativeServing` and `KnativeEventing`. ### Installing Knative Eventing and Knative Serving CRDs -The chart ships Knative Eventing and Knative Serving CRDs under `crds/`. Helm installs them before the rest of the chart on every install or upgrade. +The chart ships Knative Eventing and Knative Serving CRDs under `files/`. On the OLM v0 path, Helm applies them via pre-install hooks. On the OLM v1 path, the Serverless operator bundle installs the CRDs instead. To verify CRD versions, run: ```bash export osl_bundle=registry.redhat.io/openshift-serverless-1/serverless-operator-bundle:1.38.0 -podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1beta1_knativeeventing_crd.yaml > crds/knative-eventing/knative-eventing-crd.yaml +podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1beta1_knativeeventing_crd.yaml > files/knative-eventing/knative-eventing-crd.yaml -podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1beta1_knativeserving_crd.yaml > crds/knative-serving/knative-serving-crd.yaml +podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1beta1_knativeserving_crd.yaml > files/knative-serving/knative-serving-crd.yaml ``` -After running these commands, you may need to re-add the `helm.sh/hook` annotations. +After running these commands, you may need to re-add the `helm.sh/hook` annotations on the OLM v0 path. diff --git a/charts/orchestrator-infra/files/knative-eventing/knative-eventing-cr.yaml b/charts/orchestrator-infra/files/knative-eventing/knative-eventing-cr.yaml new file mode 100644 index 000000000..7ed7f71a9 --- /dev/null +++ b/charts/orchestrator-infra/files/knative-eventing/knative-eventing-cr.yaml @@ -0,0 +1,7 @@ +apiVersion: operator.knative.dev/v1beta1 +kind: KnativeEventing +metadata: + name: knative-eventing + namespace: knative-eventing +spec: + Registry: {} diff --git a/charts/orchestrator-infra/crds/knative-eventing/knative-eventing-crd.yaml b/charts/orchestrator-infra/files/knative-eventing/knative-eventing-crd.yaml similarity index 99% rename from charts/orchestrator-infra/crds/knative-eventing/knative-eventing-crd.yaml rename to charts/orchestrator-infra/files/knative-eventing/knative-eventing-crd.yaml index ee3bbfd24..cf4e9d689 100644 --- a/charts/orchestrator-infra/crds/knative-eventing/knative-eventing-crd.yaml +++ b/charts/orchestrator-infra/files/knative-eventing/knative-eventing-crd.yaml @@ -17,8 +17,8 @@ kind: CustomResourceDefinition metadata: name: knativeeventings.operator.knative.dev annotations: - "helm.sh/hook": pre-delete - "helm.sh/hook-weight": "-10" + "helm.sh/hook": pre-install,pre-delete + "helm.sh/hook-weight": "-20" "helm.sh/hook-delete-policy": before-hook-creation labels: app.kubernetes.io/version: devel diff --git a/charts/orchestrator-infra/files/knative-serving/knative-serving-cr.yaml b/charts/orchestrator-infra/files/knative-serving/knative-serving-cr.yaml new file mode 100644 index 000000000..2864f58a8 --- /dev/null +++ b/charts/orchestrator-infra/files/knative-serving/knative-serving-cr.yaml @@ -0,0 +1,10 @@ +apiVersion: operator.knative.dev/v1beta1 +kind: KnativeServing +metadata: + name: knative-serving + namespace: knative-serving +spec: + controller-custom-certs: + name: "" + type: "" + registry: {} diff --git a/charts/orchestrator-infra/crds/knative-serving/knative-serving-crd.yaml b/charts/orchestrator-infra/files/knative-serving/knative-serving-crd.yaml similarity index 99% rename from charts/orchestrator-infra/crds/knative-serving/knative-serving-crd.yaml rename to charts/orchestrator-infra/files/knative-serving/knative-serving-crd.yaml index 3a316a833..ef5de5663 100644 --- a/charts/orchestrator-infra/crds/knative-serving/knative-serving-crd.yaml +++ b/charts/orchestrator-infra/files/knative-serving/knative-serving-crd.yaml @@ -17,8 +17,8 @@ kind: CustomResourceDefinition metadata: name: knativeservings.operator.knative.dev annotations: - "helm.sh/hook": pre-delete - "helm.sh/hook-weight": "-10" + "helm.sh/hook": pre-install,pre-delete + "helm.sh/hook-weight": "-20" "helm.sh/hook-delete-policy": before-hook-creation labels: app.kubernetes.io/version: devel diff --git a/charts/orchestrator-infra/templates/serverless/knative-crds.yaml b/charts/orchestrator-infra/templates/serverless/knative-crds.yaml new file mode 100644 index 000000000..65b38259f --- /dev/null +++ b/charts/orchestrator-infra/templates/serverless/knative-crds.yaml @@ -0,0 +1,5 @@ +{{- if and .Values.serverlessOperator.enabled (ne (include "olm-version" .) "v1") }} +{{ .Files.Get "files/knative-serving/knative-serving-crd.yaml" }} +--- +{{ .Files.Get "files/knative-eventing/knative-eventing-crd.yaml" }} +{{- end }} diff --git a/charts/orchestrator-infra/templates/serverless/knative-v1-post-install.yaml b/charts/orchestrator-infra/templates/serverless/knative-v1-post-install.yaml new file mode 100644 index 000000000..b005840f4 --- /dev/null +++ b/charts/orchestrator-infra/templates/serverless/knative-v1-post-install.yaml @@ -0,0 +1,133 @@ +{{- if and .Values.serverlessOperator.enabled (eq (include "olm-version" .) "v1") }} +{{- $unmanagedKnativeEventingExists := include "unmanaged-resource-exists" (list "operator.knative.dev/v1beta1" "KnativeEventing" "knative-eventing" "knative-eventing" .Release.Name .Release.Namespace .Capabilities.APIVersions) }} +{{- $unmanagedKnativeServingExists := include "unmanaged-resource-exists" (list "operator.knative.dev/v1beta1" "KnativeServing" "knative-serving" "knative-serving" .Release.Name .Release.Namespace .Capabilities.APIVersions) }} +{{- if or (eq $unmanagedKnativeEventingExists "false") (eq $unmanagedKnativeServingExists "false") }} +apiVersion: v1 +kind: ServiceAccount +metadata: + name: knative-v1-post-install + namespace: {{ .Release.Namespace }} + annotations: + helm.sh/hook: post-install + helm.sh/hook-weight: "5" + helm.sh/hook-delete-policy: before-hook-creation,hook-succeeded,hook-failed +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + name: {{ .Release.Name }}-knative-v1-post-install + annotations: + helm.sh/hook: post-install + helm.sh/hook-weight: "5" + helm.sh/hook-delete-policy: before-hook-creation,hook-succeeded,hook-failed +rules: + - apiGroups: ["olm.operatorframework.io"] + resources: ["clusterextensions"] + verbs: ["get", "list", "watch"] + - apiGroups: ["apiextensions.k8s.io"] + resources: ["customresourcedefinitions"] + verbs: ["get", "list", "watch"] + - apiGroups: ["operator.knative.dev"] + resources: ["knativeservings", "knativeeventings"] + verbs: ["get", "list", "watch", "create", "update", "patch"] +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + name: {{ .Release.Name }}-knative-v1-post-install + annotations: + helm.sh/hook: post-install + helm.sh/hook-weight: "5" + helm.sh/hook-delete-policy: before-hook-creation,hook-succeeded,hook-failed +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + name: {{ .Release.Name }}-knative-v1-post-install +subjects: + - kind: ServiceAccount + name: knative-v1-post-install + namespace: {{ .Release.Namespace }} +--- +apiVersion: v1 +kind: ConfigMap +metadata: + name: knative-v1-post-install + namespace: {{ .Release.Namespace }} + annotations: + helm.sh/hook: post-install + helm.sh/hook-weight: "5" + helm.sh/hook-delete-policy: before-hook-creation,hook-succeeded,hook-failed +data: + {{- if eq $unmanagedKnativeEventingExists "false" }} + knative-eventing.yaml: | +{{ .Files.Get "files/knative-eventing/knative-eventing-cr.yaml" | indent 4 }} + {{- end }} + {{- if eq $unmanagedKnativeServingExists "false" }} + knative-serving.yaml: | +{{ .Files.Get "files/knative-serving/knative-serving-cr.yaml" | indent 4 }} + {{- end }} +--- +apiVersion: batch/v1 +kind: Job +metadata: + name: knative-v1-post-install + namespace: {{ .Release.Namespace }} + annotations: + helm.sh/hook: post-install + helm.sh/hook-weight: "10" + helm.sh/hook-delete-policy: before-hook-creation,hook-succeeded,hook-failed +spec: + backoffLimit: 1 + template: + spec: + serviceAccountName: knative-v1-post-install + restartPolicy: Never + volumes: + - name: manifests + configMap: + name: knative-v1-post-install + containers: + - name: provision-knative + image: {{ .Values.tests.image }} + volumeMounts: + - name: manifests + mountPath: /manifests + readOnly: true + securityContext: + allowPrivilegeEscalation: false + readOnlyRootFilesystem: true + capabilities: + drop: ["ALL"] + runAsNonRoot: false + command: ["/bin/sh", "-c"] + args: + - | + set -euo pipefail + + if kubectl get clusterextension {{ .Values.serverlessOperator.subscription.spec.name }} >/dev/null 2>&1; then + echo "Waiting for ClusterExtension/{{ .Values.serverlessOperator.subscription.spec.name }} to be Installed..." + kubectl wait "clusterextension/{{ .Values.serverlessOperator.subscription.spec.name }}" \ + --for=condition=Installed --timeout=600s + fi + + echo "Waiting for Knative CRDs to be established..." + kubectl wait --for=condition=Established "crd/knativeservings.operator.knative.dev" --timeout=300s + kubectl wait --for=condition=Established "crd/knativeeventings.operator.knative.dev" --timeout=300s + + {{- if eq $unmanagedKnativeEventingExists "false" }} + if ! kubectl get knativeeventing knative-eventing -n knative-eventing >/dev/null 2>&1; then + echo "Creating KnativeEventing/knative-eventing..." + kubectl apply -f /manifests/knative-eventing.yaml + fi + {{- end }} + + {{- if eq $unmanagedKnativeServingExists "false" }} + if ! kubectl get knativeserving knative-serving -n knative-serving >/dev/null 2>&1; then + echo "Creating KnativeServing/knative-serving..." + kubectl apply -f /manifests/knative-serving.yaml + fi + {{- end }} + + echo "Knative post-install provisioning completed." +{{- end }} +{{- end }} diff --git a/charts/orchestrator-infra/values.schema.json b/charts/orchestrator-infra/values.schema.json index a9554ac39..0b88f5a55 100644 --- a/charts/orchestrator-infra/values.schema.json +++ b/charts/orchestrator-infra/values.schema.json @@ -10,8 +10,35 @@ "selector": { "additionalProperties": false, "properties": { + "matchExpressions": { + "items": { + "additionalProperties": false, + "properties": { + "key": { + "type": "string" + }, + "operator": { + "type": "string" + }, + "values": { + "items": { + "type": "string" + }, + "type": "array" + } + }, + "required": [ + "key", + "operator" + ], + "type": "object" + }, + "type": "array" + }, "matchLabels": { - "additionalProperties": false, + "additionalProperties": { + "type": "string" + }, "properties": { "olm.operatorframework.io/metadata.name": { "default": "openshift-redhat-operators", diff --git a/charts/orchestrator-infra/values.schema.tmpl.json b/charts/orchestrator-infra/values.schema.tmpl.json index 9d2e3b3df..b7fe56b5d 100644 --- a/charts/orchestrator-infra/values.schema.tmpl.json +++ b/charts/orchestrator-infra/values.schema.tmpl.json @@ -24,7 +24,9 @@ "properties": { "matchLabels": { "type": "object", - "additionalProperties": false, + "additionalProperties": { + "type": "string" + }, "properties": { "olm.operatorframework.io/metadata.name": { "default": "openshift-redhat-operators", @@ -32,6 +34,28 @@ "type": "string" } } + }, + "matchExpressions": { + "type": "array", + "items": { + "type": "object", + "additionalProperties": false, + "properties": { + "key": { + "type": "string" + }, + "operator": { + "type": "string" + }, + "values": { + "type": "array", + "items": { + "type": "string" + } + } + }, + "required": ["key", "operator"] + } } } } From 098f5e34c95bbf51bf69c8869586dbb53eb30f88 Mon Sep 17 00:00:00 2001 From: Fortune-Ndlovu Date: Thu, 17 Sep 2026 12:19:36 +0100 Subject: [PATCH 11/25] fix(orchestrator-infra): fix CI pre-commit and CRD upgrade path Skip Knative CRD hook rendering when CRDs already exist so chart-testing upgrade passes. Use pre-install-only hooks and regenerate README via helm-docs. RHIDP-14789 Signed-off-by: Fortune-Ndlovu --- charts/orchestrator-infra/README.md | 47 ++++++++++--------- .../knative-eventing-crd.yaml | 4 +- .../knative-serving/knative-serving-crd.yaml | 4 +- .../templates/serverless/knative-crds.yaml | 4 ++ 4 files changed, 32 insertions(+), 27 deletions(-) diff --git a/charts/orchestrator-infra/README.md b/charts/orchestrator-infra/README.md index 72da9f68a..3735eb573 100644 --- a/charts/orchestrator-infra/README.md +++ b/charts/orchestrator-infra/README.md @@ -1,3 +1,4 @@ + # Orchestrator Infra Chart for OpenShift ![Version: 0.6.2](https://img.shields.io/badge/Version-0.6.2-informational?style=flat-square) @@ -80,29 +81,29 @@ The command removes all the Kubernetes components associated with the chart and ## Values -| Key | Type | Default | Description | -|-----|------|---------|-------------| -| olm.catalog.selector | object | `{"matchLabels":{"olm.operatorframework.io/metadata.name":"openshift-redhat-operators"}}` | ClusterCatalog selector for OLM v1 ClusterExtension resources | -| olmVersion | string | `"v0"` | OLM API version to use for operator installation (`v0`, `v1`, or `auto`) | -| serverlessLogicOperator.clusterExtension.serviceAccount.name | string | `"serverless-logic-operator-installer"` | service account used by OLM v1 to install the operator | -| serverlessLogicOperator.enabled | bool | `true` | whether the operator should be deployed by the chart | -| serverlessLogicOperator.subscription.namespace | string | `"openshift-serverless-logic"` | namespace where the operator should be deployed | -| serverlessLogicOperator.subscription.spec.channel | string | `"stable"` | channel of an operator package to subscribe to | -| serverlessLogicOperator.subscription.spec.installPlanApproval | string | `"Manual"` | whether the update should be installed automatically | -| serverlessLogicOperator.subscription.spec.name | string | `"logic-operator"` | name of the operator package | -| serverlessLogicOperator.subscription.spec.source | string | `"redhat-operators"` | name of the catalog source | -| serverlessLogicOperator.subscription.spec.sourceNamespace | string | `"openshift-marketplace"` | | -| serverlessLogicOperator.subscription.spec.startingCSV | string | `"logic-operator.v1.38.0"` | The initial version of the operator, must match CRDs installed by the chart | -| serverlessOperator.clusterExtension.serviceAccount.name | string | `"serverless-operator-installer"` | service account used by OLM v1 to install the operator | -| serverlessOperator.enabled | bool | `true` | whether the operator should be deployed by the chart | -| serverlessOperator.subscription.namespace | string | `"openshift-serverless"` | namespace where the operator should be deployed | -| serverlessOperator.subscription.spec.channel | string | `"stable"` | channel of an operator package to subscribe to | -| serverlessOperator.subscription.spec.installPlanApproval | string | `"Manual"` | whether the update should be installed automatically | -| serverlessOperator.subscription.spec.name | string | `"serverless-operator"` | name of the operator package | -| serverlessOperator.subscription.spec.source | string | `"redhat-operators"` | name of the catalog source | -| serverlessOperator.subscription.spec.sourceNamespace | string | `"openshift-marketplace"` | | -| tests.enabled | bool | `true` | Whether to create the test pod used for testing the Release using `helm test`. | -| tests.image | string | `"bitnami/kubectl:latest"` | Test pod image | +| Key | Description | Type | Default | +|-----|-------------|------|---------| +| olm.catalog.selector | ClusterCatalog selector for OLM v1 ClusterExtension resources | object | `{"matchLabels":{"olm.operatorframework.io/metadata.name":"openshift-redhat-operators"}}` | +| olmVersion | OLM API version to use for operator installation (`v0`, `v1`, or `auto`) | string | `"v0"` | +| serverlessLogicOperator.clusterExtension.serviceAccount.name | service account used by OLM v1 to install the operator | string | `"serverless-logic-operator-installer"` | +| serverlessLogicOperator.enabled | whether the operator should be deployed by the chart | bool | `true` | +| serverlessLogicOperator.subscription.namespace | namespace where the operator should be deployed | string | `"openshift-serverless-logic"` | +| serverlessLogicOperator.subscription.spec.channel | channel of an operator package to subscribe to | string | `"stable"` | +| serverlessLogicOperator.subscription.spec.installPlanApproval | whether the update should be installed automatically | string | `"Manual"` | +| serverlessLogicOperator.subscription.spec.name | name of the operator package | string | `"logic-operator"` | +| serverlessLogicOperator.subscription.spec.source | name of the catalog source | string | `"redhat-operators"` | +| serverlessLogicOperator.subscription.spec.sourceNamespace | | string | `"openshift-marketplace"` | +| serverlessLogicOperator.subscription.spec.startingCSV | The initial version of the operator, must match CRDs installed by the chart | string | `"logic-operator.v1.38.0"` | +| serverlessOperator.clusterExtension.serviceAccount.name | service account used by OLM v1 to install the operator | string | `"serverless-operator-installer"` | +| serverlessOperator.enabled | whether the operator should be deployed by the chart | bool | `true` | +| serverlessOperator.subscription.namespace | namespace where the operator should be deployed | string | `"openshift-serverless"` | +| serverlessOperator.subscription.spec.channel | channel of an operator package to subscribe to | string | `"stable"` | +| serverlessOperator.subscription.spec.installPlanApproval | whether the update should be installed automatically | string | `"Manual"` | +| serverlessOperator.subscription.spec.name | name of the operator package | string | `"serverless-operator"` | +| serverlessOperator.subscription.spec.source | name of the catalog source | string | `"redhat-operators"` | +| serverlessOperator.subscription.spec.sourceNamespace | | string | `"openshift-marketplace"` | +| tests.enabled | Whether to create the test pod used for testing the Release using `helm test`. | bool | `true` | +| tests.image | Test pod image | string | `"bitnami/kubectl:latest"` | ### OLM v0 and OLM v1 operator installation diff --git a/charts/orchestrator-infra/files/knative-eventing/knative-eventing-crd.yaml b/charts/orchestrator-infra/files/knative-eventing/knative-eventing-crd.yaml index cf4e9d689..c3242bb73 100644 --- a/charts/orchestrator-infra/files/knative-eventing/knative-eventing-crd.yaml +++ b/charts/orchestrator-infra/files/knative-eventing/knative-eventing-crd.yaml @@ -17,8 +17,8 @@ kind: CustomResourceDefinition metadata: name: knativeeventings.operator.knative.dev annotations: - "helm.sh/hook": pre-install,pre-delete - "helm.sh/hook-weight": "-20" + "helm.sh/hook": pre-install + "helm.sh/hook-weight": "-10" "helm.sh/hook-delete-policy": before-hook-creation labels: app.kubernetes.io/version: devel diff --git a/charts/orchestrator-infra/files/knative-serving/knative-serving-crd.yaml b/charts/orchestrator-infra/files/knative-serving/knative-serving-crd.yaml index ef5de5663..7f6787e6e 100644 --- a/charts/orchestrator-infra/files/knative-serving/knative-serving-crd.yaml +++ b/charts/orchestrator-infra/files/knative-serving/knative-serving-crd.yaml @@ -17,8 +17,8 @@ kind: CustomResourceDefinition metadata: name: knativeservings.operator.knative.dev annotations: - "helm.sh/hook": pre-install,pre-delete - "helm.sh/hook-weight": "-20" + "helm.sh/hook": pre-install + "helm.sh/hook-weight": "-10" "helm.sh/hook-delete-policy": before-hook-creation labels: app.kubernetes.io/version: devel diff --git a/charts/orchestrator-infra/templates/serverless/knative-crds.yaml b/charts/orchestrator-infra/templates/serverless/knative-crds.yaml index 65b38259f..7d1a5bdf1 100644 --- a/charts/orchestrator-infra/templates/serverless/knative-crds.yaml +++ b/charts/orchestrator-infra/templates/serverless/knative-crds.yaml @@ -1,5 +1,9 @@ {{- if and .Values.serverlessOperator.enabled (ne (include "olm-version" .) "v1") }} +{{- if not (lookup "apiextensions.k8s.io/v1" "CustomResourceDefinition" "" "knativeservings.operator.knative.dev") }} {{ .Files.Get "files/knative-serving/knative-serving-crd.yaml" }} --- +{{- end }} +{{- if not (lookup "apiextensions.k8s.io/v1" "CustomResourceDefinition" "" "knativeeventings.operator.knative.dev") }} {{ .Files.Get "files/knative-eventing/knative-eventing-crd.yaml" }} {{- end }} +{{- end }} From 64d9c5a845b10dcb4742d42937e5150c897cba4e Mon Sep 17 00:00:00 2001 From: Fortune-Ndlovu Date: Thu, 17 Sep 2026 12:34:42 +0100 Subject: [PATCH 12/25] fix(orchestrator-infra): provision Knative CRs via post-install hooks Move KnativeServing and KnativeEventing out of the ordinary manifest so fresh v0 installs can apply CRD pre-install hooks first. Unify v0/v1 post-install and pre-delete lifecycle hooks, add a fresh-cluster CI scenario, and verify Knative instances in helm test. RHIDP-14789 Signed-off-by: Fortune-Ndlovu --- .../ci/fresh-cluster-v0-values.yaml | 15 ++++ .../knative-eventing/knative-eventing-cr.yaml | 2 + .../knative-serving/knative-serving-cr.yaml | 2 + ...install.yaml => knative-post-install.yaml} | 41 ++++++---- .../serverless/knative-pre-delete.yaml | 74 +++++++++++++++++++ .../templates/serverless/knatives.yaml | 28 ------- .../templates/tests/infra-test.yaml | 2 + 7 files changed, 122 insertions(+), 42 deletions(-) create mode 100644 charts/orchestrator-infra/ci/fresh-cluster-v0-values.yaml rename charts/orchestrator-infra/templates/serverless/{knative-v1-post-install.yaml => knative-post-install.yaml} (79%) create mode 100644 charts/orchestrator-infra/templates/serverless/knative-pre-delete.yaml diff --git a/charts/orchestrator-infra/ci/fresh-cluster-v0-values.yaml b/charts/orchestrator-infra/ci/fresh-cluster-v0-values.yaml new file mode 100644 index 000000000..da7d931fb --- /dev/null +++ b/charts/orchestrator-infra/ci/fresh-cluster-v0-values.yaml @@ -0,0 +1,15 @@ +# Fresh-cluster OLM v0 install: do not pre-create Knative CRDs before chart install. +olmVersion: v0 + +serverlessLogicOperator: + enabled: true + subscription: + namespace: operators + spec: + sourceNamespace: olm + +serverlessOperator: + subscription: + namespace: operators + spec: + sourceNamespace: olm diff --git a/charts/orchestrator-infra/files/knative-eventing/knative-eventing-cr.yaml b/charts/orchestrator-infra/files/knative-eventing/knative-eventing-cr.yaml index 7ed7f71a9..df687c954 100644 --- a/charts/orchestrator-infra/files/knative-eventing/knative-eventing-cr.yaml +++ b/charts/orchestrator-infra/files/knative-eventing/knative-eventing-cr.yaml @@ -3,5 +3,7 @@ kind: KnativeEventing metadata: name: knative-eventing namespace: knative-eventing + labels: + orchestrator-infra.redhat.com/chart-provisioned: "true" spec: Registry: {} diff --git a/charts/orchestrator-infra/files/knative-serving/knative-serving-cr.yaml b/charts/orchestrator-infra/files/knative-serving/knative-serving-cr.yaml index 2864f58a8..08dd283cb 100644 --- a/charts/orchestrator-infra/files/knative-serving/knative-serving-cr.yaml +++ b/charts/orchestrator-infra/files/knative-serving/knative-serving-cr.yaml @@ -3,6 +3,8 @@ kind: KnativeServing metadata: name: knative-serving namespace: knative-serving + labels: + orchestrator-infra.redhat.com/chart-provisioned: "true" spec: controller-custom-certs: name: "" diff --git a/charts/orchestrator-infra/templates/serverless/knative-v1-post-install.yaml b/charts/orchestrator-infra/templates/serverless/knative-post-install.yaml similarity index 79% rename from charts/orchestrator-infra/templates/serverless/knative-v1-post-install.yaml rename to charts/orchestrator-infra/templates/serverless/knative-post-install.yaml index b005840f4..5746fbc9d 100644 --- a/charts/orchestrator-infra/templates/serverless/knative-v1-post-install.yaml +++ b/charts/orchestrator-infra/templates/serverless/knative-post-install.yaml @@ -1,57 +1,59 @@ -{{- if and .Values.serverlessOperator.enabled (eq (include "olm-version" .) "v1") }} +{{- if .Values.serverlessOperator.enabled }} {{- $unmanagedKnativeEventingExists := include "unmanaged-resource-exists" (list "operator.knative.dev/v1beta1" "KnativeEventing" "knative-eventing" "knative-eventing" .Release.Name .Release.Namespace .Capabilities.APIVersions) }} {{- $unmanagedKnativeServingExists := include "unmanaged-resource-exists" (list "operator.knative.dev/v1beta1" "KnativeServing" "knative-serving" "knative-serving" .Release.Name .Release.Namespace .Capabilities.APIVersions) }} {{- if or (eq $unmanagedKnativeEventingExists "false") (eq $unmanagedKnativeServingExists "false") }} apiVersion: v1 kind: ServiceAccount metadata: - name: knative-v1-post-install + name: knative-post-install namespace: {{ .Release.Namespace }} annotations: - helm.sh/hook: post-install + helm.sh/hook: post-install,pre-delete helm.sh/hook-weight: "5" helm.sh/hook-delete-policy: before-hook-creation,hook-succeeded,hook-failed --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: - name: {{ .Release.Name }}-knative-v1-post-install + name: {{ .Release.Name }}-knative-post-install annotations: - helm.sh/hook: post-install + helm.sh/hook: post-install,pre-delete helm.sh/hook-weight: "5" helm.sh/hook-delete-policy: before-hook-creation,hook-succeeded,hook-failed rules: + {{- if eq (include "olm-version" .) "v1" }} - apiGroups: ["olm.operatorframework.io"] resources: ["clusterextensions"] verbs: ["get", "list", "watch"] + {{- end }} - apiGroups: ["apiextensions.k8s.io"] resources: ["customresourcedefinitions"] verbs: ["get", "list", "watch"] - apiGroups: ["operator.knative.dev"] resources: ["knativeservings", "knativeeventings"] - verbs: ["get", "list", "watch", "create", "update", "patch"] + verbs: ["get", "list", "watch", "create", "update", "patch", "delete"] --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: - name: {{ .Release.Name }}-knative-v1-post-install + name: {{ .Release.Name }}-knative-post-install annotations: - helm.sh/hook: post-install + helm.sh/hook: post-install,pre-delete helm.sh/hook-weight: "5" helm.sh/hook-delete-policy: before-hook-creation,hook-succeeded,hook-failed roleRef: apiGroup: rbac.authorization.k8s.io kind: ClusterRole - name: {{ .Release.Name }}-knative-v1-post-install + name: {{ .Release.Name }}-knative-post-install subjects: - kind: ServiceAccount - name: knative-v1-post-install + name: knative-post-install namespace: {{ .Release.Namespace }} --- apiVersion: v1 kind: ConfigMap metadata: - name: knative-v1-post-install + name: knative-post-install namespace: {{ .Release.Namespace }} annotations: helm.sh/hook: post-install @@ -70,7 +72,7 @@ data: apiVersion: batch/v1 kind: Job metadata: - name: knative-v1-post-install + name: knative-post-install namespace: {{ .Release.Namespace }} annotations: helm.sh/hook: post-install @@ -80,12 +82,12 @@ spec: backoffLimit: 1 template: spec: - serviceAccountName: knative-v1-post-install + serviceAccountName: knative-post-install restartPolicy: Never volumes: - name: manifests configMap: - name: knative-v1-post-install + name: knative-post-install containers: - name: provision-knative image: {{ .Values.tests.image }} @@ -104,20 +106,30 @@ spec: - | set -euo pipefail + {{- if eq (include "olm-version" .) "v1" }} if kubectl get clusterextension {{ .Values.serverlessOperator.subscription.spec.name }} >/dev/null 2>&1; then echo "Waiting for ClusterExtension/{{ .Values.serverlessOperator.subscription.spec.name }} to be Installed..." kubectl wait "clusterextension/{{ .Values.serverlessOperator.subscription.spec.name }}" \ --for=condition=Installed --timeout=600s fi + {{- end }} echo "Waiting for Knative CRDs to be established..." kubectl wait --for=condition=Established "crd/knativeservings.operator.knative.dev" --timeout=300s kubectl wait --for=condition=Established "crd/knativeeventings.operator.knative.dev" --timeout=300s + annotate_release() { + kubectl annotate "$1" "$2" -n "$3" \ + --overwrite \ + meta.helm.sh/release-name={{ .Release.Name }} \ + meta.helm.sh/release-namespace={{ .Release.Namespace }} + } + {{- if eq $unmanagedKnativeEventingExists "false" }} if ! kubectl get knativeeventing knative-eventing -n knative-eventing >/dev/null 2>&1; then echo "Creating KnativeEventing/knative-eventing..." kubectl apply -f /manifests/knative-eventing.yaml + annotate_release knativeeventing knative-eventing knative-eventing fi {{- end }} @@ -125,6 +137,7 @@ spec: if ! kubectl get knativeserving knative-serving -n knative-serving >/dev/null 2>&1; then echo "Creating KnativeServing/knative-serving..." kubectl apply -f /manifests/knative-serving.yaml + annotate_release knativeserving knative-serving knative-serving fi {{- end }} diff --git a/charts/orchestrator-infra/templates/serverless/knative-pre-delete.yaml b/charts/orchestrator-infra/templates/serverless/knative-pre-delete.yaml new file mode 100644 index 000000000..158d83770 --- /dev/null +++ b/charts/orchestrator-infra/templates/serverless/knative-pre-delete.yaml @@ -0,0 +1,74 @@ +{{- if .Values.serverlessOperator.enabled }} +{{- $unmanagedKnativeEventingExists := include "unmanaged-resource-exists" (list "operator.knative.dev/v1beta1" "KnativeEventing" "knative-eventing" "knative-eventing" .Release.Name .Release.Namespace .Capabilities.APIVersions) }} +{{- $unmanagedKnativeServingExists := include "unmanaged-resource-exists" (list "operator.knative.dev/v1beta1" "KnativeServing" "knative-serving" "knative-serving" .Release.Name .Release.Namespace .Capabilities.APIVersions) }} +{{- if or (eq $unmanagedKnativeEventingExists "false") (eq $unmanagedKnativeServingExists "false") }} +apiVersion: batch/v1 +kind: Job +metadata: + name: knative-pre-delete + namespace: {{ .Release.Namespace }} + annotations: + helm.sh/hook: pre-delete + helm.sh/hook-weight: "10" + helm.sh/hook-delete-policy: before-hook-creation,hook-succeeded,hook-failed +spec: + backoffLimit: 1 + template: + spec: + serviceAccountName: knative-post-install + restartPolicy: Never + containers: + - name: cleanup-knative + image: {{ .Values.tests.image }} + securityContext: + allowPrivilegeEscalation: false + readOnlyRootFilesystem: true + capabilities: + drop: ["ALL"] + runAsNonRoot: false + command: ["/bin/sh", "-c"] + args: + - | + set -euo pipefail + + RELEASE_NAME="{{ .Release.Name }}" + RELEASE_NAMESPACE="{{ .Release.Namespace }}" + + is_chart_provisioned() { + local kind=$1 + local name=$2 + local namespace=$3 + local release_name + local release_namespace + + release_name=$(kubectl get "$kind" "$name" -n "$namespace" -o jsonpath='{.metadata.annotations.meta\.helm\.sh/release-name}' 2>/dev/null || true) + release_namespace=$(kubectl get "$kind" "$name" -n "$namespace" -o jsonpath='{.metadata.annotations.meta\.helm\.sh/release-namespace}' 2>/dev/null || true) + + [ "$release_name" = "$RELEASE_NAME" ] && [ "$release_namespace" = "$RELEASE_NAMESPACE" ] + } + + delete_if_provisioned() { + local kind=$1 + local name=$2 + local namespace=$3 + + if is_chart_provisioned "$kind" "$name" "$namespace"; then + echo "Deleting ${kind}/${name} provisioned by this release..." + kubectl delete "$kind" "$name" -n "$namespace" --ignore-not-found + kubectl wait --for=delete "$kind/$name" -n "$namespace" --timeout=300s || true + else + echo "Skipping ${kind}/${name}; not provisioned by this release." + fi + } + + {{- if eq $unmanagedKnativeEventingExists "false" }} + delete_if_provisioned knativeeventing knative-eventing knative-eventing + {{- end }} + + {{- if eq $unmanagedKnativeServingExists "false" }} + delete_if_provisioned knativeserving knative-serving knative-serving + {{- end }} + + echo "Knative pre-delete cleanup completed." +{{- end }} +{{- end }} diff --git a/charts/orchestrator-infra/templates/serverless/knatives.yaml b/charts/orchestrator-infra/templates/serverless/knatives.yaml index d70440daf..e65f56f47 100644 --- a/charts/orchestrator-infra/templates/serverless/knatives.yaml +++ b/charts/orchestrator-infra/templates/serverless/knatives.yaml @@ -24,32 +24,4 @@ metadata: "helm.sh/hook-weight": "-5" "helm.sh/resource-policy": keep {{- end }} - -{{- $unmanagedKnativeEventingExists := include "unmanaged-resource-exists" (list "operator.knative.dev/v1beta1" "KnativeEventing" "knative-eventing" "knative-eventing" .Release.Name .Release.Namespace .Capabilities.APIVersions) }} -{{- if and (eq $unmanagedKnativeEventingExists "false") (ne (include "olm-version" .) "v1") }} ---- -apiVersion: operator.knative.dev/v1beta1 -kind: KnativeEventing -metadata: - name: knative-eventing - namespace: knative-eventing -spec: - Registry: -{{- end }} - -{{- $unmanagedKnativeServingExists := include "unmanaged-resource-exists" (list "operator.knative.dev/v1beta1" "KnativeServing" "knative-serving" "knative-serving" .Release.Name .Release.Namespace .Capabilities.APIVersions) }} -{{- if and (eq $unmanagedKnativeServingExists "false") (ne (include "olm-version" .) "v1") }} ---- -apiVersion: operator.knative.dev/v1beta1 -kind: KnativeServing -metadata: - name: knative-serving - namespace: knative-serving -spec: - controller-custom-certs: - name: "" - type: "" - registry: {} - -{{- end }} {{- end }} diff --git a/charts/orchestrator-infra/templates/tests/infra-test.yaml b/charts/orchestrator-infra/templates/tests/infra-test.yaml index 2fd9d64aa..7dcdbdd73 100644 --- a/charts/orchestrator-infra/templates/tests/infra-test.yaml +++ b/charts/orchestrator-infra/templates/tests/infra-test.yaml @@ -138,6 +138,8 @@ spec: {{- else }} kubectl get subscription.operators.coreos.com {{ .Values.serverlessOperator.subscription.spec.name }} -n {{ .Values.serverlessOperator.subscription.namespace }} || exit 1 {{- end }} + kubectl get knativeeventing knative-eventing -n knative-eventing || exit 1 + kubectl get knativeserving knative-serving -n knative-serving || exit 1 {{- end }} {{- if .Values.serverlessLogicOperator.enabled }} From ffaacd319e73f81388eca3c594aca7e3a4b9ae4a Mon Sep 17 00:00:00 2001 From: Fortune-Ndlovu Date: Thu, 17 Sep 2026 12:40:56 +0100 Subject: [PATCH 13/25] fix(orchestrator-infra): run Knative provisioning on post-upgrade Add post-upgrade to the Knative lifecycle hooks so v0-to-v1 upgrades recreate instances after manifest changes, document the behavior, and add a conditional CI upgrade-path test. RHIDP-14789 Signed-off-by: Fortune-Ndlovu --- .github/actions/test-charts/action.yml | 30 ++++++++++++ charts/orchestrator-infra/README.md | 49 +++++++++---------- charts/orchestrator-infra/README.md.gotmpl | 2 +- .../serverless/knative-post-install.yaml | 10 ++-- .../test/olm-v1-upgrade-values.yaml | 15 ++++++ 5 files changed, 75 insertions(+), 31 deletions(-) create mode 100644 charts/orchestrator-infra/test/olm-v1-upgrade-values.yaml diff --git a/.github/actions/test-charts/action.yml b/.github/actions/test-charts/action.yml index 7d27c8f9e..a8decb93d 100644 --- a/.github/actions/test-charts/action.yml +++ b/.github/actions/test-charts/action.yml @@ -361,3 +361,33 @@ runs: CT_ARGS+=(--all) fi ct install "${CT_ARGS[@]}" + + - name: Test orchestrator-infra OLM v0 to v1 upgrade + if: steps.list-changed.outputs.changed == 'true' && inputs.chart == 'charts/orchestrator-infra' + shell: bash + run: | + if ! kubectl api-resources -o name | grep -q '^clusterextensions\.olm\.operatorframework\.io$'; then + echo "ClusterExtension API not available; skipping OLM v0 to v1 upgrade test" + exit 0 + fi + + CHART="charts/orchestrator-infra" + NS="ct-charts" + RELEASE="orchestrator-infra-v0-v1-upgrade" + V0_VALUES="$CHART/ci/fresh-cluster-v0-values.yaml" + V1_VALUES="$CHART/test/olm-v1-upgrade-values.yaml" + + helm uninstall "$RELEASE" -n "$NS" --ignore-not-found + helm install "$RELEASE" "$CHART" \ + --namespace "$NS" \ + --values "$V0_VALUES" \ + --wait \ + --timeout 500s + helm test "$RELEASE" --namespace "$NS" + + helm upgrade "$RELEASE" "$CHART" \ + --namespace "$NS" \ + --values "$V1_VALUES" \ + --wait \ + --timeout 500s + helm test "$RELEASE" --namespace "$NS" diff --git a/charts/orchestrator-infra/README.md b/charts/orchestrator-infra/README.md index 3735eb573..51e10c5ea 100644 --- a/charts/orchestrator-infra/README.md +++ b/charts/orchestrator-infra/README.md @@ -1,4 +1,3 @@ - # Orchestrator Infra Chart for OpenShift ![Version: 0.6.2](https://img.shields.io/badge/Version-0.6.2-informational?style=flat-square) @@ -81,29 +80,29 @@ The command removes all the Kubernetes components associated with the chart and ## Values -| Key | Description | Type | Default | -|-----|-------------|------|---------| -| olm.catalog.selector | ClusterCatalog selector for OLM v1 ClusterExtension resources | object | `{"matchLabels":{"olm.operatorframework.io/metadata.name":"openshift-redhat-operators"}}` | -| olmVersion | OLM API version to use for operator installation (`v0`, `v1`, or `auto`) | string | `"v0"` | -| serverlessLogicOperator.clusterExtension.serviceAccount.name | service account used by OLM v1 to install the operator | string | `"serverless-logic-operator-installer"` | -| serverlessLogicOperator.enabled | whether the operator should be deployed by the chart | bool | `true` | -| serverlessLogicOperator.subscription.namespace | namespace where the operator should be deployed | string | `"openshift-serverless-logic"` | -| serverlessLogicOperator.subscription.spec.channel | channel of an operator package to subscribe to | string | `"stable"` | -| serverlessLogicOperator.subscription.spec.installPlanApproval | whether the update should be installed automatically | string | `"Manual"` | -| serverlessLogicOperator.subscription.spec.name | name of the operator package | string | `"logic-operator"` | -| serverlessLogicOperator.subscription.spec.source | name of the catalog source | string | `"redhat-operators"` | -| serverlessLogicOperator.subscription.spec.sourceNamespace | | string | `"openshift-marketplace"` | -| serverlessLogicOperator.subscription.spec.startingCSV | The initial version of the operator, must match CRDs installed by the chart | string | `"logic-operator.v1.38.0"` | -| serverlessOperator.clusterExtension.serviceAccount.name | service account used by OLM v1 to install the operator | string | `"serverless-operator-installer"` | -| serverlessOperator.enabled | whether the operator should be deployed by the chart | bool | `true` | -| serverlessOperator.subscription.namespace | namespace where the operator should be deployed | string | `"openshift-serverless"` | -| serverlessOperator.subscription.spec.channel | channel of an operator package to subscribe to | string | `"stable"` | -| serverlessOperator.subscription.spec.installPlanApproval | whether the update should be installed automatically | string | `"Manual"` | -| serverlessOperator.subscription.spec.name | name of the operator package | string | `"serverless-operator"` | -| serverlessOperator.subscription.spec.source | name of the catalog source | string | `"redhat-operators"` | -| serverlessOperator.subscription.spec.sourceNamespace | | string | `"openshift-marketplace"` | -| tests.enabled | Whether to create the test pod used for testing the Release using `helm test`. | bool | `true` | -| tests.image | Test pod image | string | `"bitnami/kubectl:latest"` | +| Key | Type | Default | Description | +|-----|------|---------|-------------| +| olm.catalog.selector | object | `{"matchLabels":{"olm.operatorframework.io/metadata.name":"openshift-redhat-operators"}}` | ClusterCatalog selector for OLM v1 ClusterExtension resources | +| olmVersion | string | `"v0"` | OLM API version to use for operator installation (`v0`, `v1`, or `auto`) | +| serverlessLogicOperator.clusterExtension.serviceAccount.name | string | `"serverless-logic-operator-installer"` | service account used by OLM v1 to install the operator | +| serverlessLogicOperator.enabled | bool | `true` | whether the operator should be deployed by the chart | +| serverlessLogicOperator.subscription.namespace | string | `"openshift-serverless-logic"` | namespace where the operator should be deployed | +| serverlessLogicOperator.subscription.spec.channel | string | `"stable"` | channel of an operator package to subscribe to | +| serverlessLogicOperator.subscription.spec.installPlanApproval | string | `"Manual"` | whether the update should be installed automatically | +| serverlessLogicOperator.subscription.spec.name | string | `"logic-operator"` | name of the operator package | +| serverlessLogicOperator.subscription.spec.source | string | `"redhat-operators"` | name of the catalog source | +| serverlessLogicOperator.subscription.spec.sourceNamespace | string | `"openshift-marketplace"` | | +| serverlessLogicOperator.subscription.spec.startingCSV | string | `"logic-operator.v1.38.0"` | The initial version of the operator, must match CRDs installed by the chart | +| serverlessOperator.clusterExtension.serviceAccount.name | string | `"serverless-operator-installer"` | service account used by OLM v1 to install the operator | +| serverlessOperator.enabled | bool | `true` | whether the operator should be deployed by the chart | +| serverlessOperator.subscription.namespace | string | `"openshift-serverless"` | namespace where the operator should be deployed | +| serverlessOperator.subscription.spec.channel | string | `"stable"` | channel of an operator package to subscribe to | +| serverlessOperator.subscription.spec.installPlanApproval | string | `"Manual"` | whether the update should be installed automatically | +| serverlessOperator.subscription.spec.name | string | `"serverless-operator"` | name of the operator package | +| serverlessOperator.subscription.spec.source | string | `"redhat-operators"` | name of the catalog source | +| serverlessOperator.subscription.spec.sourceNamespace | string | `"openshift-marketplace"` | | +| tests.enabled | bool | `true` | Whether to create the test pod used for testing the Release using `helm test`. | +| tests.image | string | `"bitnami/kubectl:latest"` | Test pod image | ### OLM v0 and OLM v1 operator installation @@ -118,7 +117,7 @@ helm install my-orchestrator-infra ./charts/orchestrator-infra --set olmVersion= helm install my-orchestrator-infra ./charts/orchestrator-infra --set olmVersion=v1 ``` -With `olmVersion=v1`, remove helm-managed Knative CRDs from a prior v0 install before upgrading. A post-install hook waits for the Serverless ClusterExtension and operator CRDs, then creates `KnativeServing` and `KnativeEventing`. +With `olmVersion=v1`, remove helm-managed Knative CRDs from a prior v0 install before upgrading. Post-install and post-upgrade hooks wait for the Serverless ClusterExtension and operator CRDs, then create `KnativeServing` and `KnativeEventing`. ### Installing Knative Eventing and Knative Serving CRDs diff --git a/charts/orchestrator-infra/README.md.gotmpl b/charts/orchestrator-infra/README.md.gotmpl index 8b3954b47..a516e3d7c 100644 --- a/charts/orchestrator-infra/README.md.gotmpl +++ b/charts/orchestrator-infra/README.md.gotmpl @@ -89,7 +89,7 @@ helm install my-orchestrator-infra ./charts/orchestrator-infra --set olmVersion= helm install my-orchestrator-infra ./charts/orchestrator-infra --set olmVersion=v1 ``` -With `olmVersion=v1`, remove helm-managed Knative CRDs from a prior v0 install before upgrading. A post-install hook waits for the Serverless ClusterExtension and operator CRDs, then creates `KnativeServing` and `KnativeEventing`. +With `olmVersion=v1`, remove helm-managed Knative CRDs from a prior v0 install before upgrading. Post-install and post-upgrade hooks wait for the Serverless ClusterExtension and operator CRDs, then create `KnativeServing` and `KnativeEventing`. ### Installing Knative Eventing and Knative Serving CRDs diff --git a/charts/orchestrator-infra/templates/serverless/knative-post-install.yaml b/charts/orchestrator-infra/templates/serverless/knative-post-install.yaml index 5746fbc9d..7b93b1f1e 100644 --- a/charts/orchestrator-infra/templates/serverless/knative-post-install.yaml +++ b/charts/orchestrator-infra/templates/serverless/knative-post-install.yaml @@ -8,7 +8,7 @@ metadata: name: knative-post-install namespace: {{ .Release.Namespace }} annotations: - helm.sh/hook: post-install,pre-delete + helm.sh/hook: post-install,post-upgrade,pre-delete helm.sh/hook-weight: "5" helm.sh/hook-delete-policy: before-hook-creation,hook-succeeded,hook-failed --- @@ -17,7 +17,7 @@ kind: ClusterRole metadata: name: {{ .Release.Name }}-knative-post-install annotations: - helm.sh/hook: post-install,pre-delete + helm.sh/hook: post-install,post-upgrade,pre-delete helm.sh/hook-weight: "5" helm.sh/hook-delete-policy: before-hook-creation,hook-succeeded,hook-failed rules: @@ -38,7 +38,7 @@ kind: ClusterRoleBinding metadata: name: {{ .Release.Name }}-knative-post-install annotations: - helm.sh/hook: post-install,pre-delete + helm.sh/hook: post-install,post-upgrade,pre-delete helm.sh/hook-weight: "5" helm.sh/hook-delete-policy: before-hook-creation,hook-succeeded,hook-failed roleRef: @@ -56,7 +56,7 @@ metadata: name: knative-post-install namespace: {{ .Release.Namespace }} annotations: - helm.sh/hook: post-install + helm.sh/hook: post-install,post-upgrade helm.sh/hook-weight: "5" helm.sh/hook-delete-policy: before-hook-creation,hook-succeeded,hook-failed data: @@ -75,7 +75,7 @@ metadata: name: knative-post-install namespace: {{ .Release.Namespace }} annotations: - helm.sh/hook: post-install + helm.sh/hook: post-install,post-upgrade helm.sh/hook-weight: "10" helm.sh/hook-delete-policy: before-hook-creation,hook-succeeded,hook-failed spec: diff --git a/charts/orchestrator-infra/test/olm-v1-upgrade-values.yaml b/charts/orchestrator-infra/test/olm-v1-upgrade-values.yaml new file mode 100644 index 000000000..cc5addae2 --- /dev/null +++ b/charts/orchestrator-infra/test/olm-v1-upgrade-values.yaml @@ -0,0 +1,15 @@ +# OLM v1 upgrade target values. Used by the v0-to-v1 upgrade path test. +olmVersion: v1 + +serverlessLogicOperator: + enabled: true + subscription: + namespace: operators + spec: + sourceNamespace: olm + +serverlessOperator: + subscription: + namespace: operators + spec: + sourceNamespace: olm From de929fcc95426dcd0ecdcb92c5d7a9135a6ce59e Mon Sep 17 00:00:00 2001 From: Fortune-Ndlovu Date: Thu, 17 Sep 2026 12:42:21 +0100 Subject: [PATCH 14/25] fix(orchestrator-infra): add memory limits to Knative hook jobs Address SonarCloud findings by enforcing CPU and memory requests and limits on the Knative post-install and pre-delete hook containers. RHIDP-14789 Signed-off-by: Fortune-Ndlovu --- .../templates/serverless/knative-post-install.yaml | 7 +++++++ .../templates/serverless/knative-pre-delete.yaml | 7 +++++++ 2 files changed, 14 insertions(+) diff --git a/charts/orchestrator-infra/templates/serverless/knative-post-install.yaml b/charts/orchestrator-infra/templates/serverless/knative-post-install.yaml index 7b93b1f1e..401065723 100644 --- a/charts/orchestrator-infra/templates/serverless/knative-post-install.yaml +++ b/charts/orchestrator-infra/templates/serverless/knative-post-install.yaml @@ -95,6 +95,13 @@ spec: - name: manifests mountPath: /manifests readOnly: true + resources: + requests: + cpu: 10m + memory: 50Mi + limits: + cpu: 100m + memory: 128Mi securityContext: allowPrivilegeEscalation: false readOnlyRootFilesystem: true diff --git a/charts/orchestrator-infra/templates/serverless/knative-pre-delete.yaml b/charts/orchestrator-infra/templates/serverless/knative-pre-delete.yaml index 158d83770..9ebc99380 100644 --- a/charts/orchestrator-infra/templates/serverless/knative-pre-delete.yaml +++ b/charts/orchestrator-infra/templates/serverless/knative-pre-delete.yaml @@ -20,6 +20,13 @@ spec: containers: - name: cleanup-knative image: {{ .Values.tests.image }} + resources: + requests: + cpu: 10m + memory: 50Mi + limits: + cpu: 100m + memory: 128Mi securityContext: allowPrivilegeEscalation: false readOnlyRootFilesystem: true From 60e6711842e34bc2c31eed6a33374c9da1c5d916 Mon Sep 17 00:00:00 2001 From: Fortune-Ndlovu Date: Thu, 17 Sep 2026 12:44:23 +0100 Subject: [PATCH 15/25] chore(orchestrator-infra): regenerate README with helm-docs Fix pre-commit helm-docs drift in the values table column order. RHIDP-14789 Signed-off-by: Fortune-Ndlovu --- charts/orchestrator-infra/README.md | 47 +++++++++++++++-------------- 1 file changed, 24 insertions(+), 23 deletions(-) diff --git a/charts/orchestrator-infra/README.md b/charts/orchestrator-infra/README.md index 51e10c5ea..f33047d07 100644 --- a/charts/orchestrator-infra/README.md +++ b/charts/orchestrator-infra/README.md @@ -1,3 +1,4 @@ + # Orchestrator Infra Chart for OpenShift ![Version: 0.6.2](https://img.shields.io/badge/Version-0.6.2-informational?style=flat-square) @@ -80,29 +81,29 @@ The command removes all the Kubernetes components associated with the chart and ## Values -| Key | Type | Default | Description | -|-----|------|---------|-------------| -| olm.catalog.selector | object | `{"matchLabels":{"olm.operatorframework.io/metadata.name":"openshift-redhat-operators"}}` | ClusterCatalog selector for OLM v1 ClusterExtension resources | -| olmVersion | string | `"v0"` | OLM API version to use for operator installation (`v0`, `v1`, or `auto`) | -| serverlessLogicOperator.clusterExtension.serviceAccount.name | string | `"serverless-logic-operator-installer"` | service account used by OLM v1 to install the operator | -| serverlessLogicOperator.enabled | bool | `true` | whether the operator should be deployed by the chart | -| serverlessLogicOperator.subscription.namespace | string | `"openshift-serverless-logic"` | namespace where the operator should be deployed | -| serverlessLogicOperator.subscription.spec.channel | string | `"stable"` | channel of an operator package to subscribe to | -| serverlessLogicOperator.subscription.spec.installPlanApproval | string | `"Manual"` | whether the update should be installed automatically | -| serverlessLogicOperator.subscription.spec.name | string | `"logic-operator"` | name of the operator package | -| serverlessLogicOperator.subscription.spec.source | string | `"redhat-operators"` | name of the catalog source | -| serverlessLogicOperator.subscription.spec.sourceNamespace | string | `"openshift-marketplace"` | | -| serverlessLogicOperator.subscription.spec.startingCSV | string | `"logic-operator.v1.38.0"` | The initial version of the operator, must match CRDs installed by the chart | -| serverlessOperator.clusterExtension.serviceAccount.name | string | `"serverless-operator-installer"` | service account used by OLM v1 to install the operator | -| serverlessOperator.enabled | bool | `true` | whether the operator should be deployed by the chart | -| serverlessOperator.subscription.namespace | string | `"openshift-serverless"` | namespace where the operator should be deployed | -| serverlessOperator.subscription.spec.channel | string | `"stable"` | channel of an operator package to subscribe to | -| serverlessOperator.subscription.spec.installPlanApproval | string | `"Manual"` | whether the update should be installed automatically | -| serverlessOperator.subscription.spec.name | string | `"serverless-operator"` | name of the operator package | -| serverlessOperator.subscription.spec.source | string | `"redhat-operators"` | name of the catalog source | -| serverlessOperator.subscription.spec.sourceNamespace | string | `"openshift-marketplace"` | | -| tests.enabled | bool | `true` | Whether to create the test pod used for testing the Release using `helm test`. | -| tests.image | string | `"bitnami/kubectl:latest"` | Test pod image | +| Key | Description | Type | Default | +|-----|-------------|------|---------| +| olm.catalog.selector | ClusterCatalog selector for OLM v1 ClusterExtension resources | object | `{"matchLabels":{"olm.operatorframework.io/metadata.name":"openshift-redhat-operators"}}` | +| olmVersion | OLM API version to use for operator installation (`v0`, `v1`, or `auto`) | string | `"v0"` | +| serverlessLogicOperator.clusterExtension.serviceAccount.name | service account used by OLM v1 to install the operator | string | `"serverless-logic-operator-installer"` | +| serverlessLogicOperator.enabled | whether the operator should be deployed by the chart | bool | `true` | +| serverlessLogicOperator.subscription.namespace | namespace where the operator should be deployed | string | `"openshift-serverless-logic"` | +| serverlessLogicOperator.subscription.spec.channel | channel of an operator package to subscribe to | string | `"stable"` | +| serverlessLogicOperator.subscription.spec.installPlanApproval | whether the update should be installed automatically | string | `"Manual"` | +| serverlessLogicOperator.subscription.spec.name | name of the operator package | string | `"logic-operator"` | +| serverlessLogicOperator.subscription.spec.source | name of the catalog source | string | `"redhat-operators"` | +| serverlessLogicOperator.subscription.spec.sourceNamespace | | string | `"openshift-marketplace"` | +| serverlessLogicOperator.subscription.spec.startingCSV | The initial version of the operator, must match CRDs installed by the chart | string | `"logic-operator.v1.38.0"` | +| serverlessOperator.clusterExtension.serviceAccount.name | service account used by OLM v1 to install the operator | string | `"serverless-operator-installer"` | +| serverlessOperator.enabled | whether the operator should be deployed by the chart | bool | `true` | +| serverlessOperator.subscription.namespace | namespace where the operator should be deployed | string | `"openshift-serverless"` | +| serverlessOperator.subscription.spec.channel | channel of an operator package to subscribe to | string | `"stable"` | +| serverlessOperator.subscription.spec.installPlanApproval | whether the update should be installed automatically | string | `"Manual"` | +| serverlessOperator.subscription.spec.name | name of the operator package | string | `"serverless-operator"` | +| serverlessOperator.subscription.spec.source | name of the catalog source | string | `"redhat-operators"` | +| serverlessOperator.subscription.spec.sourceNamespace | | string | `"openshift-marketplace"` | +| tests.enabled | Whether to create the test pod used for testing the Release using `helm test`. | bool | `true` | +| tests.image | Test pod image | string | `"bitnami/kubectl:latest"` | ### OLM v0 and OLM v1 operator installation From b35f83c572ac8adfedd282bb12709a2b4125429f Mon Sep 17 00:00:00 2001 From: Fortune-Ndlovu Date: Thu, 17 Sep 2026 12:56:41 +0100 Subject: [PATCH 16/25] refactor(orchestrator-infra): simplify OLM v1 path to ClusterExtension manifests only Remove the Knative CR post-install/post-upgrade/pre-delete automation (Jobs, RBAC, ConfigMap, ownership annotations) that had accumulated through review cycles. This exceeded the actual goal of preparing orchestrator-infra for OLM v1: providing ClusterExtension manifests for the Serverless and Serverless Logic operators. - Restore Knative CR creation (KnativeServing/KnativeEventing) as an inline, manifest-based, v0-only step, matching prior behavior with the corrected release-ownership check (name + namespace). - Drop the fresh-cluster-v0 and v0-to-v1 upgrade CI scenarios and the associated GitHub Action step introduced for testing the removed automation. - Document that Knative instances must be created manually after the Serverless ClusterExtension is Installed on the OLM v1 path. No changes to orchestrator-software-templates-infra. RHIDP-14789 Signed-off-by: Fortune-Ndlovu --- .github/actions/test-charts/action.yml | 30 ---- charts/orchestrator-infra/README.md | 2 +- charts/orchestrator-infra/README.md.gotmpl | 2 +- .../ci/fresh-cluster-v0-values.yaml | 15 -- .../knative-eventing/knative-eventing-cr.yaml | 9 -- .../knative-serving/knative-serving-cr.yaml | 12 -- .../serverless/knative-post-install.yaml | 153 ------------------ .../serverless/knative-pre-delete.yaml | 81 ---------- .../templates/serverless/knatives.yaml | 29 ++++ .../templates/tests/infra-test.yaml | 2 - .../test/olm-v1-upgrade-values.yaml | 15 -- 11 files changed, 31 insertions(+), 319 deletions(-) delete mode 100644 charts/orchestrator-infra/ci/fresh-cluster-v0-values.yaml delete mode 100644 charts/orchestrator-infra/files/knative-eventing/knative-eventing-cr.yaml delete mode 100644 charts/orchestrator-infra/files/knative-serving/knative-serving-cr.yaml delete mode 100644 charts/orchestrator-infra/templates/serverless/knative-post-install.yaml delete mode 100644 charts/orchestrator-infra/templates/serverless/knative-pre-delete.yaml delete mode 100644 charts/orchestrator-infra/test/olm-v1-upgrade-values.yaml diff --git a/.github/actions/test-charts/action.yml b/.github/actions/test-charts/action.yml index a8decb93d..7d27c8f9e 100644 --- a/.github/actions/test-charts/action.yml +++ b/.github/actions/test-charts/action.yml @@ -361,33 +361,3 @@ runs: CT_ARGS+=(--all) fi ct install "${CT_ARGS[@]}" - - - name: Test orchestrator-infra OLM v0 to v1 upgrade - if: steps.list-changed.outputs.changed == 'true' && inputs.chart == 'charts/orchestrator-infra' - shell: bash - run: | - if ! kubectl api-resources -o name | grep -q '^clusterextensions\.olm\.operatorframework\.io$'; then - echo "ClusterExtension API not available; skipping OLM v0 to v1 upgrade test" - exit 0 - fi - - CHART="charts/orchestrator-infra" - NS="ct-charts" - RELEASE="orchestrator-infra-v0-v1-upgrade" - V0_VALUES="$CHART/ci/fresh-cluster-v0-values.yaml" - V1_VALUES="$CHART/test/olm-v1-upgrade-values.yaml" - - helm uninstall "$RELEASE" -n "$NS" --ignore-not-found - helm install "$RELEASE" "$CHART" \ - --namespace "$NS" \ - --values "$V0_VALUES" \ - --wait \ - --timeout 500s - helm test "$RELEASE" --namespace "$NS" - - helm upgrade "$RELEASE" "$CHART" \ - --namespace "$NS" \ - --values "$V1_VALUES" \ - --wait \ - --timeout 500s - helm test "$RELEASE" --namespace "$NS" diff --git a/charts/orchestrator-infra/README.md b/charts/orchestrator-infra/README.md index f33047d07..23f9b29bb 100644 --- a/charts/orchestrator-infra/README.md +++ b/charts/orchestrator-infra/README.md @@ -118,7 +118,7 @@ helm install my-orchestrator-infra ./charts/orchestrator-infra --set olmVersion= helm install my-orchestrator-infra ./charts/orchestrator-infra --set olmVersion=v1 ``` -With `olmVersion=v1`, remove helm-managed Knative CRDs from a prior v0 install before upgrading. Post-install and post-upgrade hooks wait for the Serverless ClusterExtension and operator CRDs, then create `KnativeServing` and `KnativeEventing`. +With `olmVersion=v1`, remove helm-managed Knative CRDs from a prior v0 install before upgrading. The chart does not create `KnativeServing` or `KnativeEventing` on the OLM v1 path; once the Serverless ClusterExtension reports `Installed=True` and its CRDs are established, create these instances manually. ### Installing Knative Eventing and Knative Serving CRDs diff --git a/charts/orchestrator-infra/README.md.gotmpl b/charts/orchestrator-infra/README.md.gotmpl index a516e3d7c..4569c4a92 100644 --- a/charts/orchestrator-infra/README.md.gotmpl +++ b/charts/orchestrator-infra/README.md.gotmpl @@ -89,7 +89,7 @@ helm install my-orchestrator-infra ./charts/orchestrator-infra --set olmVersion= helm install my-orchestrator-infra ./charts/orchestrator-infra --set olmVersion=v1 ``` -With `olmVersion=v1`, remove helm-managed Knative CRDs from a prior v0 install before upgrading. Post-install and post-upgrade hooks wait for the Serverless ClusterExtension and operator CRDs, then create `KnativeServing` and `KnativeEventing`. +With `olmVersion=v1`, remove helm-managed Knative CRDs from a prior v0 install before upgrading. The chart does not create `KnativeServing` or `KnativeEventing` on the OLM v1 path; once the Serverless ClusterExtension reports `Installed=True` and its CRDs are established, create these instances manually. ### Installing Knative Eventing and Knative Serving CRDs diff --git a/charts/orchestrator-infra/ci/fresh-cluster-v0-values.yaml b/charts/orchestrator-infra/ci/fresh-cluster-v0-values.yaml deleted file mode 100644 index da7d931fb..000000000 --- a/charts/orchestrator-infra/ci/fresh-cluster-v0-values.yaml +++ /dev/null @@ -1,15 +0,0 @@ -# Fresh-cluster OLM v0 install: do not pre-create Knative CRDs before chart install. -olmVersion: v0 - -serverlessLogicOperator: - enabled: true - subscription: - namespace: operators - spec: - sourceNamespace: olm - -serverlessOperator: - subscription: - namespace: operators - spec: - sourceNamespace: olm diff --git a/charts/orchestrator-infra/files/knative-eventing/knative-eventing-cr.yaml b/charts/orchestrator-infra/files/knative-eventing/knative-eventing-cr.yaml deleted file mode 100644 index df687c954..000000000 --- a/charts/orchestrator-infra/files/knative-eventing/knative-eventing-cr.yaml +++ /dev/null @@ -1,9 +0,0 @@ -apiVersion: operator.knative.dev/v1beta1 -kind: KnativeEventing -metadata: - name: knative-eventing - namespace: knative-eventing - labels: - orchestrator-infra.redhat.com/chart-provisioned: "true" -spec: - Registry: {} diff --git a/charts/orchestrator-infra/files/knative-serving/knative-serving-cr.yaml b/charts/orchestrator-infra/files/knative-serving/knative-serving-cr.yaml deleted file mode 100644 index 08dd283cb..000000000 --- a/charts/orchestrator-infra/files/knative-serving/knative-serving-cr.yaml +++ /dev/null @@ -1,12 +0,0 @@ -apiVersion: operator.knative.dev/v1beta1 -kind: KnativeServing -metadata: - name: knative-serving - namespace: knative-serving - labels: - orchestrator-infra.redhat.com/chart-provisioned: "true" -spec: - controller-custom-certs: - name: "" - type: "" - registry: {} diff --git a/charts/orchestrator-infra/templates/serverless/knative-post-install.yaml b/charts/orchestrator-infra/templates/serverless/knative-post-install.yaml deleted file mode 100644 index 401065723..000000000 --- a/charts/orchestrator-infra/templates/serverless/knative-post-install.yaml +++ /dev/null @@ -1,153 +0,0 @@ -{{- if .Values.serverlessOperator.enabled }} -{{- $unmanagedKnativeEventingExists := include "unmanaged-resource-exists" (list "operator.knative.dev/v1beta1" "KnativeEventing" "knative-eventing" "knative-eventing" .Release.Name .Release.Namespace .Capabilities.APIVersions) }} -{{- $unmanagedKnativeServingExists := include "unmanaged-resource-exists" (list "operator.knative.dev/v1beta1" "KnativeServing" "knative-serving" "knative-serving" .Release.Name .Release.Namespace .Capabilities.APIVersions) }} -{{- if or (eq $unmanagedKnativeEventingExists "false") (eq $unmanagedKnativeServingExists "false") }} -apiVersion: v1 -kind: ServiceAccount -metadata: - name: knative-post-install - namespace: {{ .Release.Namespace }} - annotations: - helm.sh/hook: post-install,post-upgrade,pre-delete - helm.sh/hook-weight: "5" - helm.sh/hook-delete-policy: before-hook-creation,hook-succeeded,hook-failed ---- -apiVersion: rbac.authorization.k8s.io/v1 -kind: ClusterRole -metadata: - name: {{ .Release.Name }}-knative-post-install - annotations: - helm.sh/hook: post-install,post-upgrade,pre-delete - helm.sh/hook-weight: "5" - helm.sh/hook-delete-policy: before-hook-creation,hook-succeeded,hook-failed -rules: - {{- if eq (include "olm-version" .) "v1" }} - - apiGroups: ["olm.operatorframework.io"] - resources: ["clusterextensions"] - verbs: ["get", "list", "watch"] - {{- end }} - - apiGroups: ["apiextensions.k8s.io"] - resources: ["customresourcedefinitions"] - verbs: ["get", "list", "watch"] - - apiGroups: ["operator.knative.dev"] - resources: ["knativeservings", "knativeeventings"] - verbs: ["get", "list", "watch", "create", "update", "patch", "delete"] ---- -apiVersion: rbac.authorization.k8s.io/v1 -kind: ClusterRoleBinding -metadata: - name: {{ .Release.Name }}-knative-post-install - annotations: - helm.sh/hook: post-install,post-upgrade,pre-delete - helm.sh/hook-weight: "5" - helm.sh/hook-delete-policy: before-hook-creation,hook-succeeded,hook-failed -roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: {{ .Release.Name }}-knative-post-install -subjects: - - kind: ServiceAccount - name: knative-post-install - namespace: {{ .Release.Namespace }} ---- -apiVersion: v1 -kind: ConfigMap -metadata: - name: knative-post-install - namespace: {{ .Release.Namespace }} - annotations: - helm.sh/hook: post-install,post-upgrade - helm.sh/hook-weight: "5" - helm.sh/hook-delete-policy: before-hook-creation,hook-succeeded,hook-failed -data: - {{- if eq $unmanagedKnativeEventingExists "false" }} - knative-eventing.yaml: | -{{ .Files.Get "files/knative-eventing/knative-eventing-cr.yaml" | indent 4 }} - {{- end }} - {{- if eq $unmanagedKnativeServingExists "false" }} - knative-serving.yaml: | -{{ .Files.Get "files/knative-serving/knative-serving-cr.yaml" | indent 4 }} - {{- end }} ---- -apiVersion: batch/v1 -kind: Job -metadata: - name: knative-post-install - namespace: {{ .Release.Namespace }} - annotations: - helm.sh/hook: post-install,post-upgrade - helm.sh/hook-weight: "10" - helm.sh/hook-delete-policy: before-hook-creation,hook-succeeded,hook-failed -spec: - backoffLimit: 1 - template: - spec: - serviceAccountName: knative-post-install - restartPolicy: Never - volumes: - - name: manifests - configMap: - name: knative-post-install - containers: - - name: provision-knative - image: {{ .Values.tests.image }} - volumeMounts: - - name: manifests - mountPath: /manifests - readOnly: true - resources: - requests: - cpu: 10m - memory: 50Mi - limits: - cpu: 100m - memory: 128Mi - securityContext: - allowPrivilegeEscalation: false - readOnlyRootFilesystem: true - capabilities: - drop: ["ALL"] - runAsNonRoot: false - command: ["/bin/sh", "-c"] - args: - - | - set -euo pipefail - - {{- if eq (include "olm-version" .) "v1" }} - if kubectl get clusterextension {{ .Values.serverlessOperator.subscription.spec.name }} >/dev/null 2>&1; then - echo "Waiting for ClusterExtension/{{ .Values.serverlessOperator.subscription.spec.name }} to be Installed..." - kubectl wait "clusterextension/{{ .Values.serverlessOperator.subscription.spec.name }}" \ - --for=condition=Installed --timeout=600s - fi - {{- end }} - - echo "Waiting for Knative CRDs to be established..." - kubectl wait --for=condition=Established "crd/knativeservings.operator.knative.dev" --timeout=300s - kubectl wait --for=condition=Established "crd/knativeeventings.operator.knative.dev" --timeout=300s - - annotate_release() { - kubectl annotate "$1" "$2" -n "$3" \ - --overwrite \ - meta.helm.sh/release-name={{ .Release.Name }} \ - meta.helm.sh/release-namespace={{ .Release.Namespace }} - } - - {{- if eq $unmanagedKnativeEventingExists "false" }} - if ! kubectl get knativeeventing knative-eventing -n knative-eventing >/dev/null 2>&1; then - echo "Creating KnativeEventing/knative-eventing..." - kubectl apply -f /manifests/knative-eventing.yaml - annotate_release knativeeventing knative-eventing knative-eventing - fi - {{- end }} - - {{- if eq $unmanagedKnativeServingExists "false" }} - if ! kubectl get knativeserving knative-serving -n knative-serving >/dev/null 2>&1; then - echo "Creating KnativeServing/knative-serving..." - kubectl apply -f /manifests/knative-serving.yaml - annotate_release knativeserving knative-serving knative-serving - fi - {{- end }} - - echo "Knative post-install provisioning completed." -{{- end }} -{{- end }} diff --git a/charts/orchestrator-infra/templates/serverless/knative-pre-delete.yaml b/charts/orchestrator-infra/templates/serverless/knative-pre-delete.yaml deleted file mode 100644 index 9ebc99380..000000000 --- a/charts/orchestrator-infra/templates/serverless/knative-pre-delete.yaml +++ /dev/null @@ -1,81 +0,0 @@ -{{- if .Values.serverlessOperator.enabled }} -{{- $unmanagedKnativeEventingExists := include "unmanaged-resource-exists" (list "operator.knative.dev/v1beta1" "KnativeEventing" "knative-eventing" "knative-eventing" .Release.Name .Release.Namespace .Capabilities.APIVersions) }} -{{- $unmanagedKnativeServingExists := include "unmanaged-resource-exists" (list "operator.knative.dev/v1beta1" "KnativeServing" "knative-serving" "knative-serving" .Release.Name .Release.Namespace .Capabilities.APIVersions) }} -{{- if or (eq $unmanagedKnativeEventingExists "false") (eq $unmanagedKnativeServingExists "false") }} -apiVersion: batch/v1 -kind: Job -metadata: - name: knative-pre-delete - namespace: {{ .Release.Namespace }} - annotations: - helm.sh/hook: pre-delete - helm.sh/hook-weight: "10" - helm.sh/hook-delete-policy: before-hook-creation,hook-succeeded,hook-failed -spec: - backoffLimit: 1 - template: - spec: - serviceAccountName: knative-post-install - restartPolicy: Never - containers: - - name: cleanup-knative - image: {{ .Values.tests.image }} - resources: - requests: - cpu: 10m - memory: 50Mi - limits: - cpu: 100m - memory: 128Mi - securityContext: - allowPrivilegeEscalation: false - readOnlyRootFilesystem: true - capabilities: - drop: ["ALL"] - runAsNonRoot: false - command: ["/bin/sh", "-c"] - args: - - | - set -euo pipefail - - RELEASE_NAME="{{ .Release.Name }}" - RELEASE_NAMESPACE="{{ .Release.Namespace }}" - - is_chart_provisioned() { - local kind=$1 - local name=$2 - local namespace=$3 - local release_name - local release_namespace - - release_name=$(kubectl get "$kind" "$name" -n "$namespace" -o jsonpath='{.metadata.annotations.meta\.helm\.sh/release-name}' 2>/dev/null || true) - release_namespace=$(kubectl get "$kind" "$name" -n "$namespace" -o jsonpath='{.metadata.annotations.meta\.helm\.sh/release-namespace}' 2>/dev/null || true) - - [ "$release_name" = "$RELEASE_NAME" ] && [ "$release_namespace" = "$RELEASE_NAMESPACE" ] - } - - delete_if_provisioned() { - local kind=$1 - local name=$2 - local namespace=$3 - - if is_chart_provisioned "$kind" "$name" "$namespace"; then - echo "Deleting ${kind}/${name} provisioned by this release..." - kubectl delete "$kind" "$name" -n "$namespace" --ignore-not-found - kubectl wait --for=delete "$kind/$name" -n "$namespace" --timeout=300s || true - else - echo "Skipping ${kind}/${name}; not provisioned by this release." - fi - } - - {{- if eq $unmanagedKnativeEventingExists "false" }} - delete_if_provisioned knativeeventing knative-eventing knative-eventing - {{- end }} - - {{- if eq $unmanagedKnativeServingExists "false" }} - delete_if_provisioned knativeserving knative-serving knative-serving - {{- end }} - - echo "Knative pre-delete cleanup completed." -{{- end }} -{{- end }} diff --git a/charts/orchestrator-infra/templates/serverless/knatives.yaml b/charts/orchestrator-infra/templates/serverless/knatives.yaml index e65f56f47..8afda61da 100644 --- a/charts/orchestrator-infra/templates/serverless/knatives.yaml +++ b/charts/orchestrator-infra/templates/serverless/knatives.yaml @@ -24,4 +24,33 @@ metadata: "helm.sh/hook-weight": "-5" "helm.sh/resource-policy": keep {{- end }} + +{{- if ne (include "olm-version" .) "v1" }} +{{- $unmanagedKnativeEventingExists := include "unmanaged-resource-exists" (list "operator.knative.dev/v1beta1" "KnativeEventing" "knative-eventing" "knative-eventing" .Release.Name .Release.Namespace .Capabilities.APIVersions) }} +{{- if eq $unmanagedKnativeEventingExists "false" }} +--- +apiVersion: operator.knative.dev/v1beta1 +kind: KnativeEventing +metadata: + name: knative-eventing + namespace: knative-eventing +spec: + Registry: {} +{{- end }} + +{{- $unmanagedKnativeServingExists := include "unmanaged-resource-exists" (list "operator.knative.dev/v1beta1" "KnativeServing" "knative-serving" "knative-serving" .Release.Name .Release.Namespace .Capabilities.APIVersions) }} +{{- if eq $unmanagedKnativeServingExists "false" }} +--- +apiVersion: operator.knative.dev/v1beta1 +kind: KnativeServing +metadata: + name: knative-serving + namespace: knative-serving +spec: + controller-custom-certs: + name: "" + type: "" + registry: {} +{{- end }} +{{- end }} {{- end }} diff --git a/charts/orchestrator-infra/templates/tests/infra-test.yaml b/charts/orchestrator-infra/templates/tests/infra-test.yaml index 7dcdbdd73..2fd9d64aa 100644 --- a/charts/orchestrator-infra/templates/tests/infra-test.yaml +++ b/charts/orchestrator-infra/templates/tests/infra-test.yaml @@ -138,8 +138,6 @@ spec: {{- else }} kubectl get subscription.operators.coreos.com {{ .Values.serverlessOperator.subscription.spec.name }} -n {{ .Values.serverlessOperator.subscription.namespace }} || exit 1 {{- end }} - kubectl get knativeeventing knative-eventing -n knative-eventing || exit 1 - kubectl get knativeserving knative-serving -n knative-serving || exit 1 {{- end }} {{- if .Values.serverlessLogicOperator.enabled }} diff --git a/charts/orchestrator-infra/test/olm-v1-upgrade-values.yaml b/charts/orchestrator-infra/test/olm-v1-upgrade-values.yaml deleted file mode 100644 index cc5addae2..000000000 --- a/charts/orchestrator-infra/test/olm-v1-upgrade-values.yaml +++ /dev/null @@ -1,15 +0,0 @@ -# OLM v1 upgrade target values. Used by the v0-to-v1 upgrade path test. -olmVersion: v1 - -serverlessLogicOperator: - enabled: true - subscription: - namespace: operators - spec: - sourceNamespace: olm - -serverlessOperator: - subscription: - namespace: operators - spec: - sourceNamespace: olm From b8826066ff3a88b8b8ca58e364deac6af4ca3030 Mon Sep 17 00:00:00 2001 From: Fortune-Ndlovu Date: Tue, 22 Sep 2026 10:35:51 +0100 Subject: [PATCH 17/25] fix(orchestrator-infra): remove auto olmVersion to support ArgoCD Remove 'auto' option from olmVersion and require explicit v0 or v1 selection to avoid Capabilities.APIVersions.Has which doesn't work with ArgoCD and helm template (client-side rendering). This addresses the concern raised in PR review that auto-detection relies on a live cluster connection and breaks CD tools like ArgoCD that render manifests client-side. Changes: - Remove Capabilities.APIVersions.Has check from olm-version helper - Remove 'auto' from olmVersion enum in values.schema.json - Update values.yaml and README.md to document only v0 and v1 - Default remains v0 (production path) Signed-off-by: Fortune Ndlovu --- charts/orchestrator-infra/README.md | 2 +- charts/orchestrator-infra/templates/_helpers.tpl | 12 ++---------- charts/orchestrator-infra/values.schema.json | 1 - charts/orchestrator-infra/values.schema.tmpl.json | 2 +- charts/orchestrator-infra/values.yaml | 2 +- 5 files changed, 5 insertions(+), 14 deletions(-) diff --git a/charts/orchestrator-infra/README.md b/charts/orchestrator-infra/README.md index 23f9b29bb..fca99b12b 100644 --- a/charts/orchestrator-infra/README.md +++ b/charts/orchestrator-infra/README.md @@ -84,7 +84,7 @@ The command removes all the Kubernetes components associated with the chart and | Key | Description | Type | Default | |-----|-------------|------|---------| | olm.catalog.selector | ClusterCatalog selector for OLM v1 ClusterExtension resources | object | `{"matchLabels":{"olm.operatorframework.io/metadata.name":"openshift-redhat-operators"}}` | -| olmVersion | OLM API version to use for operator installation (`v0`, `v1`, or `auto`) | string | `"v0"` | +| olmVersion | OLM API version to use for operator installation (`v0` or `v1`) | string | `"v0"` | | serverlessLogicOperator.clusterExtension.serviceAccount.name | service account used by OLM v1 to install the operator | string | `"serverless-logic-operator-installer"` | | serverlessLogicOperator.enabled | whether the operator should be deployed by the chart | bool | `true` | | serverlessLogicOperator.subscription.namespace | namespace where the operator should be deployed | string | `"openshift-serverless-logic"` | diff --git a/charts/orchestrator-infra/templates/_helpers.tpl b/charts/orchestrator-infra/templates/_helpers.tpl index 816657ea4..e27f8a0ee 100644 --- a/charts/orchestrator-infra/templates/_helpers.tpl +++ b/charts/orchestrator-infra/templates/_helpers.tpl @@ -39,16 +39,8 @@ {{- end -}} {{- define "olm-version" -}} - {{- $requested := default "auto" .Values.olmVersion -}} - {{- if eq $requested "auto" -}} - {{- if .Capabilities.APIVersions.Has "olm.operatorframework.io/v1/ClusterExtension" -}} - {{- "v1" -}} - {{- else -}} - {{- "v0" -}} - {{- end -}} - {{- else -}} - {{- $requested -}} - {{- end -}} + {{- $requested := default "v0" .Values.olmVersion -}} + {{- $requested -}} {{- end -}} {{- define "unmanaged-clusterextension-exists" -}} diff --git a/charts/orchestrator-infra/values.schema.json b/charts/orchestrator-infra/values.schema.json index 0b88f5a55..23501c674 100644 --- a/charts/orchestrator-infra/values.schema.json +++ b/charts/orchestrator-infra/values.schema.json @@ -60,7 +60,6 @@ "olmVersion": { "default": "v0", "enum": [ - "auto", "v0", "v1" ], diff --git a/charts/orchestrator-infra/values.schema.tmpl.json b/charts/orchestrator-infra/values.schema.tmpl.json index b7fe56b5d..8ebc986c1 100644 --- a/charts/orchestrator-infra/values.schema.tmpl.json +++ b/charts/orchestrator-infra/values.schema.tmpl.json @@ -6,7 +6,7 @@ "properties": { "olmVersion": { "default": "v0", - "enum": ["auto", "v0", "v1"], + "enum": ["v0", "v1"], "title": "OLM API version to use for operator installation", "type": "string" }, diff --git a/charts/orchestrator-infra/values.yaml b/charts/orchestrator-infra/values.yaml index ad00204dd..262ee7c9f 100644 --- a/charts/orchestrator-infra/values.yaml +++ b/charts/orchestrator-infra/values.yaml @@ -1,4 +1,4 @@ -# -- OLM API version to use for operator installation (`v0`, `v1`, or `auto`) +# -- OLM API version to use for operator installation (`v0` or `v1`) olmVersion: v0 olm: catalog: From 687e864650874d4f95ac38339a6833bba0eed46a Mon Sep 17 00:00:00 2001 From: Fortune-Ndlovu Date: Tue, 22 Sep 2026 11:22:11 +0100 Subject: [PATCH 18/25] fix(orchestrator-infra): remove all lookup and Capabilities.APIVersions.Has calls Remove all lookup() and Capabilities.APIVersions.Has() calls from templates to ensure full ArgoCD and client-side rendering compatibility. Changes: - Remove unmanaged-resource-exists and unmanaged-clusterextension-exists helper functions from _helpers.tpl - Simplify all template conditionals to only check enabled flags and olmVersion - Remove lookup checks from NOTES.txt - show YES for all enabled operators - Remove lookup checks from knative-crds.yaml - always load CRDs when v0 - Remove lookup checks from namespace templates - always create namespaces - Remove lookup checks from knatives.yaml - always create Knative namespaces/CRs This addresses the ArgoCD compatibility concern - the chart now works perfectly with helm template (client-side rendering) without any live cluster API calls. Tested: - helm template --set olmVersion=v0: renders Subscriptions - helm template --set olmVersion=v1: renders ClusterExtensions Signed-off-by: Fortune Ndlovu --- charts/orchestrator-infra/templates/NOTES.txt | 7 --- .../orchestrator-infra/templates/_helpers.tpl | 60 ------------------- .../serverless-logic/clusterextension.yaml | 4 +- .../templates/serverless-logic/namespace.yaml | 3 +- .../serverless-logic/subscription.yaml | 4 +- .../serverless/clusterextension.yaml | 4 +- .../templates/serverless/knative-crds.yaml | 4 -- .../templates/serverless/knatives.yaml | 14 ----- .../templates/serverless/namespace.yaml | 3 +- .../templates/serverless/subscription.yaml | 4 +- 10 files changed, 6 insertions(+), 101 deletions(-) diff --git a/charts/orchestrator-infra/templates/NOTES.txt b/charts/orchestrator-infra/templates/NOTES.txt index 2e0a06b03..b3b890707 100644 --- a/charts/orchestrator-infra/templates/NOTES.txt +++ b/charts/orchestrator-infra/templates/NOTES.txt @@ -4,18 +4,11 @@ Helm Release {{ .Release.Name }} installed in namespace {{ .Release.Namespace }} {{- $yes := "YES" }} {{- $no := "NO " }} {{- $serverlessOperatorInstalled := $no }} -{{- $knativeServingInstalled := $no }} -{{- $knativeEventingInstalled := $no }} {{- $serverlessLogicOperatorInstalled := $no }} -{{- $sonataFlowPlatformInstalled := $no }} -{{- $timeout := "--timeout=5m" }} {{- if .Values.serverlessOperator.enabled }} -{{- $unmanagedSubscriptionExists := include "unmanaged-resource-exists" (list "operators.coreos.com/v1alpha1" "Subscription" .Values.serverlessOperator.subscription.namespace "serverless-operator" .Release.Name .Release.Namespace .Capabilities.APIVersions ) }} -{{- if eq $unmanagedSubscriptionExists "false" }} {{- $serverlessOperatorInstalled = $yes }} {{- end }} -{{- end }} {{- if .Values.serverlessLogicOperator.enabled }} {{- $serverlessLogicOperatorInstalled = $yes }} diff --git a/charts/orchestrator-infra/templates/_helpers.tpl b/charts/orchestrator-infra/templates/_helpers.tpl index e27f8a0ee..d6f877580 100644 --- a/charts/orchestrator-infra/templates/_helpers.tpl +++ b/charts/orchestrator-infra/templates/_helpers.tpl @@ -1,70 +1,10 @@ {{/* Helper functions */}} -{{- define "unmanaged-resource-exists" -}} - {{- $api := index . 0 -}} - {{- $kind := index . 1 -}} - {{- $namespace := index . 2 -}} - {{- $name := index . 3 -}} - {{- $releaseName := index . 4 -}} - {{- $releaseNamespace := index . 5 -}} - {{- $apiCapabilities := index . 6 -}} - {{- if $apiCapabilities.Has (printf "%s/%s" $api $kind) }} - {{- $existingOperator := lookup $api $kind $namespace $name -}} - {{- if empty $existingOperator -}} - {{- "false" -}} - {{- else -}} - {{- $isManagedResource := include "is-managed-resource" (list $existingOperator $releaseName $releaseNamespace) -}} - {{- if eq $isManagedResource "true" -}} - {{- "false" -}} - {{- else -}} - {{- "true" -}} - {{- end -}} - {{- end -}} - {{- else -}} - {{- "false" -}} - {{- end -}} -{{- end -}} - -{{- define "is-managed-resource" -}} - {{- $resource := index . 0 -}} - {{- $releaseName := index . 1 -}} - {{- $releaseNamespace := index . 2 -}} - {{- $resourceReleaseName := dig "metadata" "annotations" (dict "meta.helm.sh/release-name" "NA") $resource -}} - {{- $resourceReleaseNamespace := dig "metadata" "annotations" (dict "meta.helm.sh/release-namespace" "NA") $resource -}} - {{- if and (eq (get $resourceReleaseName "meta.helm.sh/release-name") $releaseName) (eq (get $resourceReleaseNamespace "meta.helm.sh/release-namespace") $releaseNamespace) -}} - {{- "true" -}} - {{- else -}} - {{- "false" -}} - {{- end -}} -{{- end -}} - {{- define "olm-version" -}} {{- $requested := default "v0" .Values.olmVersion -}} {{- $requested -}} {{- end -}} -{{- define "unmanaged-clusterextension-exists" -}} - {{- $name := index . 0 -}} - {{- $releaseName := index . 1 -}} - {{- $releaseNamespace := index . 2 -}} - {{- $apiCapabilities := index . 3 -}} - {{- if $apiCapabilities.Has "olm.operatorframework.io/v1/ClusterExtension" -}} - {{- $existingExtension := lookup "olm.operatorframework.io/v1" "ClusterExtension" "" $name -}} - {{- if empty $existingExtension -}} - {{- "false" -}} - {{- else -}} - {{- $isManagedResource := include "is-managed-resource" (list $existingExtension $releaseName $releaseNamespace) -}} - {{- if eq $isManagedResource "true" -}} - {{- "false" -}} - {{- else -}} - {{- "true" -}} - {{- end -}} - {{- end -}} - {{- else -}} - {{- "false" -}} - {{- end -}} -{{- end -}} - {{- define "csv-version" -}} {{- $csv := index . 0 -}} {{- $packageName := index . 1 -}} diff --git a/charts/orchestrator-infra/templates/serverless-logic/clusterextension.yaml b/charts/orchestrator-infra/templates/serverless-logic/clusterextension.yaml index 28477b2b6..235e377cb 100644 --- a/charts/orchestrator-infra/templates/serverless-logic/clusterextension.yaml +++ b/charts/orchestrator-infra/templates/serverless-logic/clusterextension.yaml @@ -1,9 +1,7 @@ {{- $packageName := .Values.serverlessLogicOperator.subscription.spec.name -}} {{- $namespace := .Values.serverlessLogicOperator.subscription.namespace -}} {{- $serviceAccountName := .Values.serverlessLogicOperator.clusterExtension.serviceAccount.name -}} -{{- $unmanagedClusterExtensionExists := include "unmanaged-clusterextension-exists" (list $packageName .Release.Name .Release.Namespace .Capabilities.APIVersions) -}} -{{- $unmanagedSubscriptionExists := include "unmanaged-resource-exists" (list "operators.coreos.com/v1alpha1" "Subscription" $namespace $packageName .Release.Name .Release.Namespace .Capabilities.APIVersions ) -}} -{{- if and (eq (include "olm-version" .) "v1") (eq $unmanagedClusterExtensionExists "false") (eq $unmanagedSubscriptionExists "false") .Values.serverlessLogicOperator.enabled }} +{{- if and (eq (include "olm-version" .) "v1") .Values.serverlessLogicOperator.enabled }} apiVersion: v1 kind: ServiceAccount metadata: diff --git a/charts/orchestrator-infra/templates/serverless-logic/namespace.yaml b/charts/orchestrator-infra/templates/serverless-logic/namespace.yaml index f7112dd68..770fa5290 100644 --- a/charts/orchestrator-infra/templates/serverless-logic/namespace.yaml +++ b/charts/orchestrator-infra/templates/serverless-logic/namespace.yaml @@ -1,5 +1,4 @@ -{{- $unmanagedNamespaceExists := include "unmanaged-resource-exists" (list "v1" "Namespace" "" .Values.serverlessLogicOperator.subscription.namespace .Release.Name .Release.Namespace .Capabilities.APIVersions) }} -{{- if and (eq $unmanagedNamespaceExists "false") .Values.serverlessLogicOperator.enabled }} +{{- if .Values.serverlessLogicOperator.enabled }} --- apiVersion: v1 kind: Namespace diff --git a/charts/orchestrator-infra/templates/serverless-logic/subscription.yaml b/charts/orchestrator-infra/templates/serverless-logic/subscription.yaml index 9092fb8c9..aa0b3ca2f 100644 --- a/charts/orchestrator-infra/templates/serverless-logic/subscription.yaml +++ b/charts/orchestrator-infra/templates/serverless-logic/subscription.yaml @@ -1,8 +1,6 @@ {{- $packageName := .Values.serverlessLogicOperator.subscription.spec.name -}} {{- $subscriptionNamespace := .Values.serverlessLogicOperator.subscription.namespace -}} -{{- $unmanagedSubscriptionExists := include "unmanaged-resource-exists" (list "operators.coreos.com/v1alpha1" "Subscription" $subscriptionNamespace $packageName .Release.Name .Release.Namespace .Capabilities.APIVersions ) -}} -{{- $unmanagedClusterExtensionExists := include "unmanaged-clusterextension-exists" (list $packageName .Release.Name .Release.Namespace .Capabilities.APIVersions) -}} -{{- if and (eq (include "olm-version" .) "v0") (eq $unmanagedSubscriptionExists "false") (eq $unmanagedClusterExtensionExists "false") .Values.serverlessLogicOperator.enabled }} +{{- if and (eq (include "olm-version" .) "v0") .Values.serverlessLogicOperator.enabled }} apiVersion: operators.coreos.com/v1alpha1 kind: Subscription metadata: diff --git a/charts/orchestrator-infra/templates/serverless/clusterextension.yaml b/charts/orchestrator-infra/templates/serverless/clusterextension.yaml index 4382c0cfc..5c4344bbc 100644 --- a/charts/orchestrator-infra/templates/serverless/clusterextension.yaml +++ b/charts/orchestrator-infra/templates/serverless/clusterextension.yaml @@ -1,9 +1,7 @@ {{- $packageName := .Values.serverlessOperator.subscription.spec.name -}} {{- $namespace := .Values.serverlessOperator.subscription.namespace -}} {{- $serviceAccountName := .Values.serverlessOperator.clusterExtension.serviceAccount.name -}} -{{- $unmanagedClusterExtensionExists := include "unmanaged-clusterextension-exists" (list $packageName .Release.Name .Release.Namespace .Capabilities.APIVersions) -}} -{{- $unmanagedSubscriptionExists := include "unmanaged-resource-exists" (list "operators.coreos.com/v1alpha1" "Subscription" $namespace $packageName .Release.Name .Release.Namespace .Capabilities.APIVersions ) -}} -{{- if and (eq (include "olm-version" .) "v1") (eq $unmanagedClusterExtensionExists "false") (eq $unmanagedSubscriptionExists "false") .Values.serverlessOperator.enabled }} +{{- if and (eq (include "olm-version" .) "v1") .Values.serverlessOperator.enabled }} apiVersion: v1 kind: ServiceAccount metadata: diff --git a/charts/orchestrator-infra/templates/serverless/knative-crds.yaml b/charts/orchestrator-infra/templates/serverless/knative-crds.yaml index 7d1a5bdf1..65b38259f 100644 --- a/charts/orchestrator-infra/templates/serverless/knative-crds.yaml +++ b/charts/orchestrator-infra/templates/serverless/knative-crds.yaml @@ -1,9 +1,5 @@ {{- if and .Values.serverlessOperator.enabled (ne (include "olm-version" .) "v1") }} -{{- if not (lookup "apiextensions.k8s.io/v1" "CustomResourceDefinition" "" "knativeservings.operator.knative.dev") }} {{ .Files.Get "files/knative-serving/knative-serving-crd.yaml" }} --- -{{- end }} -{{- if not (lookup "apiextensions.k8s.io/v1" "CustomResourceDefinition" "" "knativeeventings.operator.knative.dev") }} {{ .Files.Get "files/knative-eventing/knative-eventing-crd.yaml" }} {{- end }} -{{- end }} diff --git a/charts/orchestrator-infra/templates/serverless/knatives.yaml b/charts/orchestrator-infra/templates/serverless/knatives.yaml index 8afda61da..02291d44f 100644 --- a/charts/orchestrator-infra/templates/serverless/knatives.yaml +++ b/charts/orchestrator-infra/templates/serverless/knatives.yaml @@ -1,6 +1,4 @@ {{- if .Values.serverlessOperator.enabled }} -{{- $unmanagedNamespaceExists := include "unmanaged-resource-exists" (list "v1" "Namespace" "" "knative-serving" .Release.Name .Release.Namespace .Capabilities.APIVersions) }} -{{- if eq $unmanagedNamespaceExists "false" }} --- apiVersion: v1 kind: Namespace @@ -10,10 +8,6 @@ metadata: "helm.sh/hook": pre-install "helm.sh/hook-weight": "-5" "helm.sh/resource-policy": keep -{{- end }} - -{{- $unmanagedNamespaceExists := include "unmanaged-resource-exists" (list "v1" "Namespace" "" "knative-eventing" .Release.Name .Release.Namespace .Capabilities.APIVersions) }} -{{- if eq $unmanagedNamespaceExists "false" }} --- apiVersion: v1 kind: Namespace @@ -23,11 +17,8 @@ metadata: "helm.sh/hook": pre-install "helm.sh/hook-weight": "-5" "helm.sh/resource-policy": keep -{{- end }} {{- if ne (include "olm-version" .) "v1" }} -{{- $unmanagedKnativeEventingExists := include "unmanaged-resource-exists" (list "operator.knative.dev/v1beta1" "KnativeEventing" "knative-eventing" "knative-eventing" .Release.Name .Release.Namespace .Capabilities.APIVersions) }} -{{- if eq $unmanagedKnativeEventingExists "false" }} --- apiVersion: operator.knative.dev/v1beta1 kind: KnativeEventing @@ -36,10 +27,6 @@ metadata: namespace: knative-eventing spec: Registry: {} -{{- end }} - -{{- $unmanagedKnativeServingExists := include "unmanaged-resource-exists" (list "operator.knative.dev/v1beta1" "KnativeServing" "knative-serving" "knative-serving" .Release.Name .Release.Namespace .Capabilities.APIVersions) }} -{{- if eq $unmanagedKnativeServingExists "false" }} --- apiVersion: operator.knative.dev/v1beta1 kind: KnativeServing @@ -53,4 +40,3 @@ spec: registry: {} {{- end }} {{- end }} -{{- end }} diff --git a/charts/orchestrator-infra/templates/serverless/namespace.yaml b/charts/orchestrator-infra/templates/serverless/namespace.yaml index d7517085d..25d103c14 100644 --- a/charts/orchestrator-infra/templates/serverless/namespace.yaml +++ b/charts/orchestrator-infra/templates/serverless/namespace.yaml @@ -1,5 +1,4 @@ -{{- $unmanagedNamespaceExists := include "unmanaged-resource-exists" (list "v1" "Namespace" "" .Values.serverlessOperator.subscription.namespace .Release.Name .Release.Namespace .Capabilities.APIVersions) }} -{{- if and (eq $unmanagedNamespaceExists "false") .Values.serverlessOperator.enabled }} +{{- if .Values.serverlessOperator.enabled }} --- apiVersion: v1 kind: Namespace diff --git a/charts/orchestrator-infra/templates/serverless/subscription.yaml b/charts/orchestrator-infra/templates/serverless/subscription.yaml index 580a5ed15..18d298d05 100644 --- a/charts/orchestrator-infra/templates/serverless/subscription.yaml +++ b/charts/orchestrator-infra/templates/serverless/subscription.yaml @@ -1,8 +1,6 @@ {{- $packageName := .Values.serverlessOperator.subscription.spec.name -}} {{- $subscriptionNamespace := .Values.serverlessOperator.subscription.namespace -}} -{{- $unmanagedSubscriptionExists := include "unmanaged-resource-exists" (list "operators.coreos.com/v1alpha1" "Subscription" $subscriptionNamespace $packageName .Release.Name .Release.Namespace .Capabilities.APIVersions ) -}} -{{- $unmanagedClusterExtensionExists := include "unmanaged-clusterextension-exists" (list $packageName .Release.Name .Release.Namespace .Capabilities.APIVersions) -}} -{{- if and (eq (include "olm-version" .) "v0") (eq $unmanagedSubscriptionExists "false") (eq $unmanagedClusterExtensionExists "false") .Values.serverlessOperator.enabled }} +{{- if and (eq (include "olm-version" .) "v0") .Values.serverlessOperator.enabled }} apiVersion: operators.coreos.com/v1alpha1 kind: Subscription metadata: From 7187acc3c2a1f27dd6835354db353fd842708a63 Mon Sep 17 00:00:00 2001 From: Fortune-Ndlovu Date: Tue, 22 Sep 2026 11:34:09 +0100 Subject: [PATCH 19/25] fix(orchestrator-infra): add Helm ownership metadata to namespaces for upgrade compatibility Add Helm labels and annotations to all namespace resources to fix upgrade test failures. Without these, Helm cannot adopt existing namespaces during upgrades from v0.6.1 to v0.6.2. Changes: - Add app.kubernetes.io/managed-by label to all namespace resources - Add meta.helm.sh/release-name and meta.helm.sh/release-namespace annotations to all namespace resources - Applies to: openshift-serverless, openshift-serverless-logic, knative-serving, knative-eventing namespaces This fixes the upgrade test error: "Unable to continue with update: Namespace exists and cannot be imported into the current release: invalid ownership metadata" Signed-off-by: Fortune Ndlovu --- .../templates/serverless-logic/namespace.yaml | 5 +++++ .../orchestrator-infra/templates/serverless/knatives.yaml | 8 ++++++++ .../templates/serverless/namespace.yaml | 5 +++++ 3 files changed, 18 insertions(+) diff --git a/charts/orchestrator-infra/templates/serverless-logic/namespace.yaml b/charts/orchestrator-infra/templates/serverless-logic/namespace.yaml index 770fa5290..1a5bfe04f 100644 --- a/charts/orchestrator-infra/templates/serverless-logic/namespace.yaml +++ b/charts/orchestrator-infra/templates/serverless-logic/namespace.yaml @@ -4,4 +4,9 @@ apiVersion: v1 kind: Namespace metadata: name: {{ .Values.serverlessLogicOperator.subscription.namespace }} + labels: + app.kubernetes.io/managed-by: {{ .Release.Service }} + annotations: + meta.helm.sh/release-name: {{ .Release.Name }} + meta.helm.sh/release-namespace: {{ .Release.Namespace }} {{- end }} diff --git a/charts/orchestrator-infra/templates/serverless/knatives.yaml b/charts/orchestrator-infra/templates/serverless/knatives.yaml index 02291d44f..ed2e6f396 100644 --- a/charts/orchestrator-infra/templates/serverless/knatives.yaml +++ b/charts/orchestrator-infra/templates/serverless/knatives.yaml @@ -4,7 +4,11 @@ apiVersion: v1 kind: Namespace metadata: name: knative-serving + labels: + app.kubernetes.io/managed-by: {{ .Release.Service }} annotations: + meta.helm.sh/release-name: {{ .Release.Name }} + meta.helm.sh/release-namespace: {{ .Release.Namespace }} "helm.sh/hook": pre-install "helm.sh/hook-weight": "-5" "helm.sh/resource-policy": keep @@ -13,7 +17,11 @@ apiVersion: v1 kind: Namespace metadata: name: knative-eventing + labels: + app.kubernetes.io/managed-by: {{ .Release.Service }} annotations: + meta.helm.sh/release-name: {{ .Release.Name }} + meta.helm.sh/release-namespace: {{ .Release.Namespace }} "helm.sh/hook": pre-install "helm.sh/hook-weight": "-5" "helm.sh/resource-policy": keep diff --git a/charts/orchestrator-infra/templates/serverless/namespace.yaml b/charts/orchestrator-infra/templates/serverless/namespace.yaml index 25d103c14..8cb142bae 100644 --- a/charts/orchestrator-infra/templates/serverless/namespace.yaml +++ b/charts/orchestrator-infra/templates/serverless/namespace.yaml @@ -4,5 +4,10 @@ apiVersion: v1 kind: Namespace metadata: name: {{ .Values.serverlessOperator.subscription.namespace }} + labels: + app.kubernetes.io/managed-by: {{ .Release.Service }} + annotations: + meta.helm.sh/release-name: {{ .Release.Name }} + meta.helm.sh/release-namespace: {{ .Release.Namespace }} {{- end }} From dc0ac555756865bb047b4ffa819b5f099602d03d Mon Sep 17 00:00:00 2001 From: Fortune-Ndlovu Date: Tue, 22 Sep 2026 11:42:50 +0100 Subject: [PATCH 20/25] fix(orchestrator-infra): prevent duplicate namespace creation When both serverlessOperator and serverlessLogicOperator use the same namespace (e.g., "operators" in CI tests), avoid creating duplicate namespace resources by only rendering the serverless-logic namespace when it differs from the serverless operator namespace. Signed-off-by: Fortune Ndlovu --- .../templates/serverless-logic/namespace.yaml | 3 ++- charts/orchestrator-infra/templates/serverless/namespace.yaml | 1 + 2 files changed, 3 insertions(+), 1 deletion(-) diff --git a/charts/orchestrator-infra/templates/serverless-logic/namespace.yaml b/charts/orchestrator-infra/templates/serverless-logic/namespace.yaml index 1a5bfe04f..29de408b0 100644 --- a/charts/orchestrator-infra/templates/serverless-logic/namespace.yaml +++ b/charts/orchestrator-infra/templates/serverless-logic/namespace.yaml @@ -1,4 +1,4 @@ -{{- if .Values.serverlessLogicOperator.enabled }} +{{- if and .Values.serverlessLogicOperator.enabled (ne .Values.serverlessLogicOperator.subscription.namespace .Values.serverlessOperator.subscription.namespace) }} --- apiVersion: v1 kind: Namespace @@ -9,4 +9,5 @@ metadata: annotations: meta.helm.sh/release-name: {{ .Release.Name }} meta.helm.sh/release-namespace: {{ .Release.Namespace }} + "helm.sh/resource-policy": keep {{- end }} diff --git a/charts/orchestrator-infra/templates/serverless/namespace.yaml b/charts/orchestrator-infra/templates/serverless/namespace.yaml index 8cb142bae..00bb04d47 100644 --- a/charts/orchestrator-infra/templates/serverless/namespace.yaml +++ b/charts/orchestrator-infra/templates/serverless/namespace.yaml @@ -9,5 +9,6 @@ metadata: annotations: meta.helm.sh/release-name: {{ .Release.Name }} meta.helm.sh/release-namespace: {{ .Release.Namespace }} + "helm.sh/resource-policy": keep {{- end }} From cf4487ade9984e4fff54bb7cab833e68dabe66ea Mon Sep 17 00:00:00 2001 From: Fortune-Ndlovu Date: Tue, 22 Sep 2026 12:03:09 +0100 Subject: [PATCH 21/25] fix(orchestrator-infra): remove Helm ownership metadata from namespaces Remove app.kubernetes.io/managed-by labels and meta.helm.sh/* annotations from namespace resources to avoid adoption errors during upgrades from v0.6.1. This allows namespaces created by v0.6.1 (without metadata) to be safely upgraded to v0.6.2 without triggering "invalid ownership metadata" errors. Also prevents duplicate namespace creation when both operators share the same namespace (e.g., "operators" in CI tests). Signed-off-by: Fortune Ndlovu --- .../templates/serverless-logic/namespace.yaml | 4 ---- .../orchestrator-infra/templates/serverless/knatives.yaml | 8 -------- .../templates/serverless/namespace.yaml | 4 ---- 3 files changed, 16 deletions(-) diff --git a/charts/orchestrator-infra/templates/serverless-logic/namespace.yaml b/charts/orchestrator-infra/templates/serverless-logic/namespace.yaml index 29de408b0..8d45ca3f7 100644 --- a/charts/orchestrator-infra/templates/serverless-logic/namespace.yaml +++ b/charts/orchestrator-infra/templates/serverless-logic/namespace.yaml @@ -4,10 +4,6 @@ apiVersion: v1 kind: Namespace metadata: name: {{ .Values.serverlessLogicOperator.subscription.namespace }} - labels: - app.kubernetes.io/managed-by: {{ .Release.Service }} annotations: - meta.helm.sh/release-name: {{ .Release.Name }} - meta.helm.sh/release-namespace: {{ .Release.Namespace }} "helm.sh/resource-policy": keep {{- end }} diff --git a/charts/orchestrator-infra/templates/serverless/knatives.yaml b/charts/orchestrator-infra/templates/serverless/knatives.yaml index ed2e6f396..02291d44f 100644 --- a/charts/orchestrator-infra/templates/serverless/knatives.yaml +++ b/charts/orchestrator-infra/templates/serverless/knatives.yaml @@ -4,11 +4,7 @@ apiVersion: v1 kind: Namespace metadata: name: knative-serving - labels: - app.kubernetes.io/managed-by: {{ .Release.Service }} annotations: - meta.helm.sh/release-name: {{ .Release.Name }} - meta.helm.sh/release-namespace: {{ .Release.Namespace }} "helm.sh/hook": pre-install "helm.sh/hook-weight": "-5" "helm.sh/resource-policy": keep @@ -17,11 +13,7 @@ apiVersion: v1 kind: Namespace metadata: name: knative-eventing - labels: - app.kubernetes.io/managed-by: {{ .Release.Service }} annotations: - meta.helm.sh/release-name: {{ .Release.Name }} - meta.helm.sh/release-namespace: {{ .Release.Namespace }} "helm.sh/hook": pre-install "helm.sh/hook-weight": "-5" "helm.sh/resource-policy": keep diff --git a/charts/orchestrator-infra/templates/serverless/namespace.yaml b/charts/orchestrator-infra/templates/serverless/namespace.yaml index 00bb04d47..f796fb1ed 100644 --- a/charts/orchestrator-infra/templates/serverless/namespace.yaml +++ b/charts/orchestrator-infra/templates/serverless/namespace.yaml @@ -4,11 +4,7 @@ apiVersion: v1 kind: Namespace metadata: name: {{ .Values.serverlessOperator.subscription.namespace }} - labels: - app.kubernetes.io/managed-by: {{ .Release.Service }} annotations: - meta.helm.sh/release-name: {{ .Release.Name }} - meta.helm.sh/release-namespace: {{ .Release.Namespace }} "helm.sh/resource-policy": keep {{- end }} From 34288c8896e672e00e5f1345289b72cdcf9bede2 Mon Sep 17 00:00:00 2001 From: Fortune-Ndlovu Date: Tue, 22 Sep 2026 12:08:52 +0100 Subject: [PATCH 22/25] fix(orchestrator-infra): address PR review feedback - Bump version to 0.7.0 (minor bump for OLM v1 feature addition) - Move CRDs from files/ to crds/ directory for native Helm handling - Remove helm hook annotations from CRDs to prevent cascade deletion - Remove knative-crds.yaml template (CRDs auto-loaded from crds/) - Create KnativeServing/KnativeEventing on both v0 and v1 paths - Remove non-existent "auto" option from README documentation - Update documentation to reflect crds/ directory usage - Update test action to reference correct CRD paths This fixes issues where: 1. Hook-based CRD installation caused cascade deletion of CRs 2. KnativeServing/KnativeEventing were not created on v1 path 3. Documentation mentioned unsupported "auto" olmVersion option Signed-off-by: Fortune Ndlovu --- .github/actions/test-charts/action.yml | 4 +- charts/orchestrator-infra/Chart.yaml | 2 +- charts/orchestrator-infra/README.md | 67 +++++++++---------- charts/orchestrator-infra/README.md.gotmpl | 16 ++--- .../knative-eventing-crd.yaml | 4 -- .../knative-serving/knative-serving-crd.yaml | 4 -- .../templates/serverless/knative-crds.yaml | 5 -- .../templates/serverless/knatives.yaml | 2 - 8 files changed, 42 insertions(+), 62 deletions(-) rename charts/orchestrator-infra/{files => crds}/knative-eventing/knative-eventing-crd.yaml (99%) rename charts/orchestrator-infra/{files => crds}/knative-serving/knative-serving-crd.yaml (99%) delete mode 100644 charts/orchestrator-infra/templates/serverless/knative-crds.yaml diff --git a/.github/actions/test-charts/action.yml b/.github/actions/test-charts/action.yml index 7d27c8f9e..2c3bb37c6 100644 --- a/.github/actions/test-charts/action.yml +++ b/.github/actions/test-charts/action.yml @@ -190,8 +190,8 @@ runs: env: SONATAFLOW_OPERATOR_VERSION: "10.1.0" run: | - kubectl create -f charts/orchestrator-infra/files/knative-eventing/knative-eventing-crd.yaml - kubectl create -f charts/orchestrator-infra/files/knative-serving/knative-serving-crd.yaml + kubectl create -f charts/orchestrator-infra/crds/knative-eventing/knative-eventing-crd.yaml + kubectl create -f charts/orchestrator-infra/crds/knative-serving/knative-serving-crd.yaml kubectl create -f "https://github.com/apache/incubator-kie-tools/releases/download/${SONATAFLOW_OPERATOR_VERSION}/apache-kie-${SONATAFLOW_OPERATOR_VERSION}-incubating-sonataflow-operator.yaml" - name: Set up external services and test resources for rhdh diff --git a/charts/orchestrator-infra/Chart.yaml b/charts/orchestrator-infra/Chart.yaml index 5bbf1db4f..de9f53b2d 100644 --- a/charts/orchestrator-infra/Chart.yaml +++ b/charts/orchestrator-infra/Chart.yaml @@ -14,4 +14,4 @@ maintainers: type: application sources: - https://github.com/redhat-developer/rhdh-chart -version: 0.6.2 +version: 0.7.0 diff --git a/charts/orchestrator-infra/README.md b/charts/orchestrator-infra/README.md index fca99b12b..e0d0725fd 100644 --- a/charts/orchestrator-infra/README.md +++ b/charts/orchestrator-infra/README.md @@ -1,7 +1,6 @@ - # Orchestrator Infra Chart for OpenShift -![Version: 0.6.2](https://img.shields.io/badge/Version-0.6.2-informational?style=flat-square) +![Version: 0.7.0](https://img.shields.io/badge/Version-0.7.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) Helm chart to deploy the Orchestrator solution's required infrastructure suite on OpenShift, including OpenShift Serverless Operator and OpenShift Serverless Logic Operator, both required to configure Red Hat Developer Hub to use the Orchestrator. @@ -25,7 +24,7 @@ Kubernetes: `>= 1.25.0-0` ```console helm repo add redhat-developer https://redhat-developer.github.io/rhdh-chart -helm install my-orchestrator-infra redhat-developer/redhat-developer-hub-orchestrator-infra --version 0.6.2 +helm install my-orchestrator-infra redhat-developer/redhat-developer-hub-orchestrator-infra --version 0.7.0 ``` > **Tip**: List all releases using `helm list` @@ -81,29 +80,29 @@ The command removes all the Kubernetes components associated with the chart and ## Values -| Key | Description | Type | Default | -|-----|-------------|------|---------| -| olm.catalog.selector | ClusterCatalog selector for OLM v1 ClusterExtension resources | object | `{"matchLabels":{"olm.operatorframework.io/metadata.name":"openshift-redhat-operators"}}` | -| olmVersion | OLM API version to use for operator installation (`v0` or `v1`) | string | `"v0"` | -| serverlessLogicOperator.clusterExtension.serviceAccount.name | service account used by OLM v1 to install the operator | string | `"serverless-logic-operator-installer"` | -| serverlessLogicOperator.enabled | whether the operator should be deployed by the chart | bool | `true` | -| serverlessLogicOperator.subscription.namespace | namespace where the operator should be deployed | string | `"openshift-serverless-logic"` | -| serverlessLogicOperator.subscription.spec.channel | channel of an operator package to subscribe to | string | `"stable"` | -| serverlessLogicOperator.subscription.spec.installPlanApproval | whether the update should be installed automatically | string | `"Manual"` | -| serverlessLogicOperator.subscription.spec.name | name of the operator package | string | `"logic-operator"` | -| serverlessLogicOperator.subscription.spec.source | name of the catalog source | string | `"redhat-operators"` | -| serverlessLogicOperator.subscription.spec.sourceNamespace | | string | `"openshift-marketplace"` | -| serverlessLogicOperator.subscription.spec.startingCSV | The initial version of the operator, must match CRDs installed by the chart | string | `"logic-operator.v1.38.0"` | -| serverlessOperator.clusterExtension.serviceAccount.name | service account used by OLM v1 to install the operator | string | `"serverless-operator-installer"` | -| serverlessOperator.enabled | whether the operator should be deployed by the chart | bool | `true` | -| serverlessOperator.subscription.namespace | namespace where the operator should be deployed | string | `"openshift-serverless"` | -| serverlessOperator.subscription.spec.channel | channel of an operator package to subscribe to | string | `"stable"` | -| serverlessOperator.subscription.spec.installPlanApproval | whether the update should be installed automatically | string | `"Manual"` | -| serverlessOperator.subscription.spec.name | name of the operator package | string | `"serverless-operator"` | -| serverlessOperator.subscription.spec.source | name of the catalog source | string | `"redhat-operators"` | -| serverlessOperator.subscription.spec.sourceNamespace | | string | `"openshift-marketplace"` | -| tests.enabled | Whether to create the test pod used for testing the Release using `helm test`. | bool | `true` | -| tests.image | Test pod image | string | `"bitnami/kubectl:latest"` | +| Key | Type | Default | Description | +|-----|------|---------|-------------| +| olm.catalog.selector | object | `{"matchLabels":{"olm.operatorframework.io/metadata.name":"openshift-redhat-operators"}}` | ClusterCatalog selector for OLM v1 ClusterExtension resources | +| olmVersion | string | `"v0"` | OLM API version to use for operator installation (`v0` or `v1`) | +| serverlessLogicOperator.clusterExtension.serviceAccount.name | string | `"serverless-logic-operator-installer"` | service account used by OLM v1 to install the operator | +| serverlessLogicOperator.enabled | bool | `true` | whether the operator should be deployed by the chart | +| serverlessLogicOperator.subscription.namespace | string | `"openshift-serverless-logic"` | namespace where the operator should be deployed | +| serverlessLogicOperator.subscription.spec.channel | string | `"stable"` | channel of an operator package to subscribe to | +| serverlessLogicOperator.subscription.spec.installPlanApproval | string | `"Manual"` | whether the update should be installed automatically | +| serverlessLogicOperator.subscription.spec.name | string | `"logic-operator"` | name of the operator package | +| serverlessLogicOperator.subscription.spec.source | string | `"redhat-operators"` | name of the catalog source | +| serverlessLogicOperator.subscription.spec.sourceNamespace | string | `"openshift-marketplace"` | | +| serverlessLogicOperator.subscription.spec.startingCSV | string | `"logic-operator.v1.38.0"` | The initial version of the operator, must match CRDs installed by the chart | +| serverlessOperator.clusterExtension.serviceAccount.name | string | `"serverless-operator-installer"` | service account used by OLM v1 to install the operator | +| serverlessOperator.enabled | bool | `true` | whether the operator should be deployed by the chart | +| serverlessOperator.subscription.namespace | string | `"openshift-serverless"` | namespace where the operator should be deployed | +| serverlessOperator.subscription.spec.channel | string | `"stable"` | channel of an operator package to subscribe to | +| serverlessOperator.subscription.spec.installPlanApproval | string | `"Manual"` | whether the update should be installed automatically | +| serverlessOperator.subscription.spec.name | string | `"serverless-operator"` | name of the operator package | +| serverlessOperator.subscription.spec.source | string | `"redhat-operators"` | name of the catalog source | +| serverlessOperator.subscription.spec.sourceNamespace | string | `"openshift-marketplace"` | | +| tests.enabled | bool | `true` | Whether to create the test pod used for testing the Release using `helm test`. | +| tests.image | string | `"bitnami/kubectl:latest"` | Test pod image | ### OLM v0 and OLM v1 operator installation @@ -111,26 +110,24 @@ The chart defaults to `olmVersion: v0`. - `v0`: creates `Subscription` resources - `v1`: creates `ClusterExtension` resources with an installer ServiceAccount and ClusterRoleBinding -- `auto`: uses OLM v1 when the `clusterextensions.olm.operatorframework.io` CRD is present; otherwise OLM v0 ```bash helm install my-orchestrator-infra ./charts/orchestrator-infra --set olmVersion=v0 helm install my-orchestrator-infra ./charts/orchestrator-infra --set olmVersion=v1 ``` -With `olmVersion=v1`, remove helm-managed Knative CRDs from a prior v0 install before upgrading. The chart does not create `KnativeServing` or `KnativeEventing` on the OLM v1 path; once the Serverless ClusterExtension reports `Installed=True` and its CRDs are established, create these instances manually. - ### Installing Knative Eventing and Knative Serving CRDs -The chart ships Knative Eventing and Knative Serving CRDs under `files/`. On the OLM v0 path, Helm applies them via pre-install hooks. On the OLM v1 path, the Serverless operator bundle installs the CRDs instead. +The orchestrator-infra chart requires several CRDs for Knative Eventing and Knative Serving. These CRDs will be applied prior to installing the chart, ensuring that Knative CRs can be created as part of the chart's deployment process. This approach eliminates the need to wait for the OpenShift Serverless Operator's subscription to install them beforehand. -To verify CRD versions, run: +The KnativeEventing and KnativeServing CRDs are required for this chart to run. These CRDs need to be present under the `crds/` directory before running `helm install`. +After installing the openshift-serverless subscription, more Knative CRDs will be installed on the cluster. + +The versions of the CRDs present in the chart and the ones in the subscription must match. In order to verify the correct CRD, use this following command to extract the CRD: ```bash export osl_bundle=registry.redhat.io/openshift-serverless-1/serverless-operator-bundle:1.38.0 -podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1beta1_knativeeventing_crd.yaml > files/knative-eventing/knative-eventing-crd.yaml +podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1beta1_knativeeventing_crd.yaml > crds/knative-eventing/knative-eventing-crd.yaml -podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1beta1_knativeserving_crd.yaml > files/knative-serving/knative-serving-crd.yaml +podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1beta1_knativeserving_crd.yaml > crds/knative-serving/knative-serving-crd.yaml ``` - -After running these commands, you may need to re-add the `helm.sh/hook` annotations on the OLM v0 path. diff --git a/charts/orchestrator-infra/README.md.gotmpl b/charts/orchestrator-infra/README.md.gotmpl index 4569c4a92..17e569932 100644 --- a/charts/orchestrator-infra/README.md.gotmpl +++ b/charts/orchestrator-infra/README.md.gotmpl @@ -82,26 +82,24 @@ The chart defaults to `olmVersion: v0`. - `v0`: creates `Subscription` resources - `v1`: creates `ClusterExtension` resources with an installer ServiceAccount and ClusterRoleBinding -- `auto`: uses OLM v1 when the `clusterextensions.olm.operatorframework.io` CRD is present; otherwise OLM v0 ```bash helm install my-orchestrator-infra ./charts/orchestrator-infra --set olmVersion=v0 helm install my-orchestrator-infra ./charts/orchestrator-infra --set olmVersion=v1 ``` -With `olmVersion=v1`, remove helm-managed Knative CRDs from a prior v0 install before upgrading. The chart does not create `KnativeServing` or `KnativeEventing` on the OLM v1 path; once the Serverless ClusterExtension reports `Installed=True` and its CRDs are established, create these instances manually. - ### Installing Knative Eventing and Knative Serving CRDs -The chart ships Knative Eventing and Knative Serving CRDs under `files/`. On the OLM v0 path, Helm applies them via pre-install hooks. On the OLM v1 path, the Serverless operator bundle installs the CRDs instead. +The orchestrator-infra chart requires several CRDs for Knative Eventing and Knative Serving. These CRDs will be applied prior to installing the chart, ensuring that Knative CRs can be created as part of the chart's deployment process. This approach eliminates the need to wait for the OpenShift Serverless Operator's subscription to install them beforehand. + +The KnativeEventing and KnativeServing CRDs are required for this chart to run. These CRDs need to be present under the `crds/` directory before running `helm install`. +After installing the openshift-serverless subscription, more Knative CRDs will be installed on the cluster. -To verify CRD versions, run: +The versions of the CRDs present in the chart and the ones in the subscription must match. In order to verify the correct CRD, use this following command to extract the CRD: ```bash export osl_bundle=registry.redhat.io/openshift-serverless-1/serverless-operator-bundle:1.38.0 -podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1beta1_knativeeventing_crd.yaml > files/knative-eventing/knative-eventing-crd.yaml +podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1beta1_knativeeventing_crd.yaml > crds/knative-eventing/knative-eventing-crd.yaml -podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1beta1_knativeserving_crd.yaml > files/knative-serving/knative-serving-crd.yaml +podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1beta1_knativeserving_crd.yaml > crds/knative-serving/knative-serving-crd.yaml ``` - -After running these commands, you may need to re-add the `helm.sh/hook` annotations on the OLM v0 path. diff --git a/charts/orchestrator-infra/files/knative-eventing/knative-eventing-crd.yaml b/charts/orchestrator-infra/crds/knative-eventing/knative-eventing-crd.yaml similarity index 99% rename from charts/orchestrator-infra/files/knative-eventing/knative-eventing-crd.yaml rename to charts/orchestrator-infra/crds/knative-eventing/knative-eventing-crd.yaml index c3242bb73..52951f00a 100644 --- a/charts/orchestrator-infra/files/knative-eventing/knative-eventing-crd.yaml +++ b/charts/orchestrator-infra/crds/knative-eventing/knative-eventing-crd.yaml @@ -16,10 +16,6 @@ apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: name: knativeeventings.operator.knative.dev - annotations: - "helm.sh/hook": pre-install - "helm.sh/hook-weight": "-10" - "helm.sh/hook-delete-policy": before-hook-creation labels: app.kubernetes.io/version: devel app.kubernetes.io/name: knative-operator diff --git a/charts/orchestrator-infra/files/knative-serving/knative-serving-crd.yaml b/charts/orchestrator-infra/crds/knative-serving/knative-serving-crd.yaml similarity index 99% rename from charts/orchestrator-infra/files/knative-serving/knative-serving-crd.yaml rename to charts/orchestrator-infra/crds/knative-serving/knative-serving-crd.yaml index 7f6787e6e..21bc0a70b 100644 --- a/charts/orchestrator-infra/files/knative-serving/knative-serving-crd.yaml +++ b/charts/orchestrator-infra/crds/knative-serving/knative-serving-crd.yaml @@ -16,10 +16,6 @@ apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: name: knativeservings.operator.knative.dev - annotations: - "helm.sh/hook": pre-install - "helm.sh/hook-weight": "-10" - "helm.sh/hook-delete-policy": before-hook-creation labels: app.kubernetes.io/version: devel app.kubernetes.io/name: knative-operator diff --git a/charts/orchestrator-infra/templates/serverless/knative-crds.yaml b/charts/orchestrator-infra/templates/serverless/knative-crds.yaml deleted file mode 100644 index 65b38259f..000000000 --- a/charts/orchestrator-infra/templates/serverless/knative-crds.yaml +++ /dev/null @@ -1,5 +0,0 @@ -{{- if and .Values.serverlessOperator.enabled (ne (include "olm-version" .) "v1") }} -{{ .Files.Get "files/knative-serving/knative-serving-crd.yaml" }} ---- -{{ .Files.Get "files/knative-eventing/knative-eventing-crd.yaml" }} -{{- end }} diff --git a/charts/orchestrator-infra/templates/serverless/knatives.yaml b/charts/orchestrator-infra/templates/serverless/knatives.yaml index 02291d44f..7aaf1273b 100644 --- a/charts/orchestrator-infra/templates/serverless/knatives.yaml +++ b/charts/orchestrator-infra/templates/serverless/knatives.yaml @@ -18,7 +18,6 @@ metadata: "helm.sh/hook-weight": "-5" "helm.sh/resource-policy": keep -{{- if ne (include "olm-version" .) "v1" }} --- apiVersion: operator.knative.dev/v1beta1 kind: KnativeEventing @@ -39,4 +38,3 @@ spec: type: "" registry: {} {{- end }} -{{- end }} From c9d6a0bce10488060bf7c476823dc55ed0b3b63d Mon Sep 17 00:00:00 2001 From: Fortune-Ndlovu Date: Tue, 22 Sep 2026 12:11:22 +0100 Subject: [PATCH 23/25] docs: update references from files/ to crds/ directory Update CONTRIBUTING.md and PR template to reference the correct crds/ directory path for Knative CRDs. Signed-off-by: Fortune Ndlovu --- .github/pull_request_template.md | 2 +- CONTRIBUTING.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/pull_request_template.md b/.github/pull_request_template.md index 0c63846f8..d0e67e93d 100644 --- a/.github/pull_request_template.md +++ b/.github/pull_request_template.md @@ -27,4 +27,4 @@ Detailed instructions may help reviewers test this PR quickly and provide quicke - [ ] For each Chart updated, variables are documented in the `values.yaml` and added to the corresponding README.md. The [pre-commit](https://pre-commit.com/) utility can be used to generate the necessary content. Run `pre-commit run --all-files` to run the hooks and then push any resulting changes. The [pre-commit Workflow](./workflows/pre-commit.yaml) will enforce this and warn you if needed. - [ ] JSON Schema template updated and re-generated the raw schema via the `pre-commit` hook. - [ ] Tests pass using the [Chart Testing](https://github.com/helm/chart-testing) tool and the `ct lint` command. -- [ ] If you updated the [orchestrator-infra](../charts/orchestrator-infra) chart, make sure the versions of the [Knative CRDs](../charts/orchestrator-infra/files) are aligned with the versions of the CRDs installed by the OpenShift Serverless operators declared in the [values.yaml](../charts/orchestrator-infra/values.yaml) file. See [Installing Knative Eventing and Knative Serving CRDs](../charts/orchestrator-infra/README.md#installing-knative-eventing-and-knative-serving-crds) for more details. +- [ ] If you updated the [orchestrator-infra](../charts/orchestrator-infra) chart, make sure the versions of the [Knative CRDs](../charts/orchestrator-infra/crds) are aligned with the versions of the CRDs installed by the OpenShift Serverless operators declared in the [values.yaml](../charts/orchestrator-infra/values.yaml) file. See [Installing Knative Eventing and Knative Serving CRDs](../charts/orchestrator-infra/README.md#installing-knative-eventing-and-knative-serving-crds) for more details. diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 04c121503..91eb4bd0a 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -9,7 +9,7 @@ Before making a contribution to the charts in this repository, you will need to - For each Chart updated, version bumped in the corresponding `Chart.yaml` according to [Semantic Versioning](http://semver.org/). - For each Chart updated, ensure variables are documented in the corresponding `values.yaml` file and the [pre-commit](https://pre-commit.com/) hook has been run with `pre-commit run --all-files` to generate the corresponding `README.md` documentation. The [pre-commit Workflow](./.github/workflows/pre-commit.yaml) will enforce this and warn you if needed. - JSON Schema template updated and re-generated the raw schema via the `pre-commit` hook. -- [ ] If you updated the [orchestrator-infra](./charts/orchestrator-infra) chart, make sure the versions of the [Knative CRDs](./charts/orchestrator-infra/files) are aligned with the versions of the CRDs installed by the OpenShift Serverless operators declared in the [values.yaml](./charts/orchestrator-infra/values.yaml) file. See [Installing Knative Eventing and Knative Serving CRDs](./charts/orchestrator-infra/README.md#installing-knative-eventing-and-knative-serving-crds) for more details. +- [ ] If you updated the [orchestrator-infra](./charts/orchestrator-infra) chart, make sure the versions of the [Knative CRDs](./charts/orchestrator-infra/crds) are aligned with the versions of the CRDs installed by the OpenShift Serverless operators declared in the [values.yaml](./charts/orchestrator-infra/values.yaml) file. See [Installing Knative Eventing and Knative Serving CRDs](./charts/orchestrator-infra/README.md#installing-knative-eventing-and-knative-serving-crds) for more details. ## Sync Lightspeed Core vendored config files From 8d4abd22aee9a585f675cc6ce7cde2ca182e4fb5 Mon Sep 17 00:00:00 2001 From: Fortune-Ndlovu Date: Tue, 22 Sep 2026 12:17:52 +0100 Subject: [PATCH 24/25] fix(orchestrator-infra): add createNamespace flag to avoid adoption errors Add createNamespace boolean flag for both operators (defaults to true). This allows users to skip namespace creation when namespaces already exist, avoiding Helm ownership adoption errors. Changes: - Add serverlessOperator.createNamespace (default: true) - Add serverlessLogicOperator.createNamespace (default: true) - Update namespace templates to check createNamespace flag - Set createNamespace: false in upstream-olm-values.yaml CI test - Update values schema and documentation This fixes CI test failures where the "operators" namespace already exists and Helm cannot adopt it without ownership metadata. Signed-off-by: Fortune Ndlovu --- charts/orchestrator-infra/README.md | 2 ++ charts/orchestrator-infra/ci/upstream-olm-values.yaml | 2 ++ .../templates/serverless-logic/namespace.yaml | 2 +- .../templates/serverless/namespace.yaml | 2 +- charts/orchestrator-infra/values.schema.json | 10 ++++++++++ charts/orchestrator-infra/values.schema.tmpl.json | 10 ++++++++++ charts/orchestrator-infra/values.yaml | 4 ++++ 7 files changed, 30 insertions(+), 2 deletions(-) diff --git a/charts/orchestrator-infra/README.md b/charts/orchestrator-infra/README.md index e0d0725fd..745d95ce2 100644 --- a/charts/orchestrator-infra/README.md +++ b/charts/orchestrator-infra/README.md @@ -85,6 +85,7 @@ The command removes all the Kubernetes components associated with the chart and | olm.catalog.selector | object | `{"matchLabels":{"olm.operatorframework.io/metadata.name":"openshift-redhat-operators"}}` | ClusterCatalog selector for OLM v1 ClusterExtension resources | | olmVersion | string | `"v0"` | OLM API version to use for operator installation (`v0` or `v1`) | | serverlessLogicOperator.clusterExtension.serviceAccount.name | string | `"serverless-logic-operator-installer"` | service account used by OLM v1 to install the operator | +| serverlessLogicOperator.createNamespace | bool | `true` | whether to create the operator namespace (set to false if namespace already exists) | | serverlessLogicOperator.enabled | bool | `true` | whether the operator should be deployed by the chart | | serverlessLogicOperator.subscription.namespace | string | `"openshift-serverless-logic"` | namespace where the operator should be deployed | | serverlessLogicOperator.subscription.spec.channel | string | `"stable"` | channel of an operator package to subscribe to | @@ -94,6 +95,7 @@ The command removes all the Kubernetes components associated with the chart and | serverlessLogicOperator.subscription.spec.sourceNamespace | string | `"openshift-marketplace"` | | | serverlessLogicOperator.subscription.spec.startingCSV | string | `"logic-operator.v1.38.0"` | The initial version of the operator, must match CRDs installed by the chart | | serverlessOperator.clusterExtension.serviceAccount.name | string | `"serverless-operator-installer"` | service account used by OLM v1 to install the operator | +| serverlessOperator.createNamespace | bool | `true` | whether to create the operator namespace (set to false if namespace already exists) | | serverlessOperator.enabled | bool | `true` | whether the operator should be deployed by the chart | | serverlessOperator.subscription.namespace | string | `"openshift-serverless"` | namespace where the operator should be deployed | | serverlessOperator.subscription.spec.channel | string | `"stable"` | channel of an operator package to subscribe to | diff --git a/charts/orchestrator-infra/ci/upstream-olm-values.yaml b/charts/orchestrator-infra/ci/upstream-olm-values.yaml index 6dafe01f1..52a7c9022 100644 --- a/charts/orchestrator-infra/ci/upstream-olm-values.yaml +++ b/charts/orchestrator-infra/ci/upstream-olm-values.yaml @@ -1,11 +1,13 @@ serverlessLogicOperator: enabled: true + createNamespace: false subscription: namespace: operators spec: sourceNamespace: olm serverlessOperator: + createNamespace: false subscription: namespace: operators spec: diff --git a/charts/orchestrator-infra/templates/serverless-logic/namespace.yaml b/charts/orchestrator-infra/templates/serverless-logic/namespace.yaml index 8d45ca3f7..326b38cd3 100644 --- a/charts/orchestrator-infra/templates/serverless-logic/namespace.yaml +++ b/charts/orchestrator-infra/templates/serverless-logic/namespace.yaml @@ -1,4 +1,4 @@ -{{- if and .Values.serverlessLogicOperator.enabled (ne .Values.serverlessLogicOperator.subscription.namespace .Values.serverlessOperator.subscription.namespace) }} +{{- if and .Values.serverlessLogicOperator.enabled .Values.serverlessLogicOperator.createNamespace (ne .Values.serverlessLogicOperator.subscription.namespace .Values.serverlessOperator.subscription.namespace) }} --- apiVersion: v1 kind: Namespace diff --git a/charts/orchestrator-infra/templates/serverless/namespace.yaml b/charts/orchestrator-infra/templates/serverless/namespace.yaml index f796fb1ed..bd2552da7 100644 --- a/charts/orchestrator-infra/templates/serverless/namespace.yaml +++ b/charts/orchestrator-infra/templates/serverless/namespace.yaml @@ -1,4 +1,4 @@ -{{- if .Values.serverlessOperator.enabled }} +{{- if and .Values.serverlessOperator.enabled .Values.serverlessOperator.createNamespace }} --- apiVersion: v1 kind: Namespace diff --git a/charts/orchestrator-infra/values.schema.json b/charts/orchestrator-infra/values.schema.json index 23501c674..6c9c613eb 100644 --- a/charts/orchestrator-infra/values.schema.json +++ b/charts/orchestrator-infra/values.schema.json @@ -86,6 +86,11 @@ }, "type": "object" }, + "createNamespace": { + "default": true, + "title": "Whether to create the operator namespace (set to false if namespace already exists)", + "type": "boolean" + }, "enabled": { "default": true, "title": "Whether the operator should be deployed by the chart", @@ -161,6 +166,11 @@ }, "type": "object" }, + "createNamespace": { + "default": true, + "title": "Whether to create the operator namespace (set to false if namespace already exists)", + "type": "boolean" + }, "enabled": { "default": true, "title": "Whether the operator should be deployed by the chart", diff --git a/charts/orchestrator-infra/values.schema.tmpl.json b/charts/orchestrator-infra/values.schema.tmpl.json index 8ebc986c1..4b2b44a14 100644 --- a/charts/orchestrator-infra/values.schema.tmpl.json +++ b/charts/orchestrator-infra/values.schema.tmpl.json @@ -72,6 +72,11 @@ "title": "Whether the operator should be deployed by the chart", "type": "boolean" }, + "createNamespace": { + "default": true, + "title": "Whether to create the operator namespace (set to false if namespace already exists)", + "type": "boolean" + }, "subscription": { "type": "object", "additionalProperties": false, @@ -147,6 +152,11 @@ "title": "Whether the operator should be deployed by the chart", "type": "boolean" }, + "createNamespace": { + "default": true, + "title": "Whether to create the operator namespace (set to false if namespace already exists)", + "type": "boolean" + }, "subscription": { "additionalProperties": false, "type": "object", diff --git a/charts/orchestrator-infra/values.yaml b/charts/orchestrator-infra/values.yaml index 262ee7c9f..d186287c7 100644 --- a/charts/orchestrator-infra/values.yaml +++ b/charts/orchestrator-infra/values.yaml @@ -10,6 +10,8 @@ olm: serverlessLogicOperator: # -- whether the operator should be deployed by the chart enabled: true + # -- whether to create the operator namespace (set to false if namespace already exists) + createNamespace: true subscription: # -- namespace where the operator should be deployed namespace: openshift-serverless-logic @@ -33,6 +35,8 @@ serverlessLogicOperator: serverlessOperator: # -- whether the operator should be deployed by the chart enabled: true + # -- whether to create the operator namespace (set to false if namespace already exists) + createNamespace: true subscription: # -- namespace where the operator should be deployed namespace: openshift-serverless From c596528c2ecb51ef653274bd645612dd9d888dfd Mon Sep 17 00:00:00 2001 From: Fortune-Ndlovu Date: Tue, 22 Sep 2026 12:19:11 +0100 Subject: [PATCH 25/25] docs: regenerate README with helm-docs Update README with new createNamespace fields and reformat values table. Signed-off-by: Fortune Ndlovu --- charts/orchestrator-infra/README.md | 51 +++++++++++++++-------------- 1 file changed, 26 insertions(+), 25 deletions(-) diff --git a/charts/orchestrator-infra/README.md b/charts/orchestrator-infra/README.md index 745d95ce2..f5c824bbe 100644 --- a/charts/orchestrator-infra/README.md +++ b/charts/orchestrator-infra/README.md @@ -1,3 +1,4 @@ + # Orchestrator Infra Chart for OpenShift ![Version: 0.7.0](https://img.shields.io/badge/Version-0.7.0-informational?style=flat-square) @@ -80,31 +81,31 @@ The command removes all the Kubernetes components associated with the chart and ## Values -| Key | Type | Default | Description | -|-----|------|---------|-------------| -| olm.catalog.selector | object | `{"matchLabels":{"olm.operatorframework.io/metadata.name":"openshift-redhat-operators"}}` | ClusterCatalog selector for OLM v1 ClusterExtension resources | -| olmVersion | string | `"v0"` | OLM API version to use for operator installation (`v0` or `v1`) | -| serverlessLogicOperator.clusterExtension.serviceAccount.name | string | `"serverless-logic-operator-installer"` | service account used by OLM v1 to install the operator | -| serverlessLogicOperator.createNamespace | bool | `true` | whether to create the operator namespace (set to false if namespace already exists) | -| serverlessLogicOperator.enabled | bool | `true` | whether the operator should be deployed by the chart | -| serverlessLogicOperator.subscription.namespace | string | `"openshift-serverless-logic"` | namespace where the operator should be deployed | -| serverlessLogicOperator.subscription.spec.channel | string | `"stable"` | channel of an operator package to subscribe to | -| serverlessLogicOperator.subscription.spec.installPlanApproval | string | `"Manual"` | whether the update should be installed automatically | -| serverlessLogicOperator.subscription.spec.name | string | `"logic-operator"` | name of the operator package | -| serverlessLogicOperator.subscription.spec.source | string | `"redhat-operators"` | name of the catalog source | -| serverlessLogicOperator.subscription.spec.sourceNamespace | string | `"openshift-marketplace"` | | -| serverlessLogicOperator.subscription.spec.startingCSV | string | `"logic-operator.v1.38.0"` | The initial version of the operator, must match CRDs installed by the chart | -| serverlessOperator.clusterExtension.serviceAccount.name | string | `"serverless-operator-installer"` | service account used by OLM v1 to install the operator | -| serverlessOperator.createNamespace | bool | `true` | whether to create the operator namespace (set to false if namespace already exists) | -| serverlessOperator.enabled | bool | `true` | whether the operator should be deployed by the chart | -| serverlessOperator.subscription.namespace | string | `"openshift-serverless"` | namespace where the operator should be deployed | -| serverlessOperator.subscription.spec.channel | string | `"stable"` | channel of an operator package to subscribe to | -| serverlessOperator.subscription.spec.installPlanApproval | string | `"Manual"` | whether the update should be installed automatically | -| serverlessOperator.subscription.spec.name | string | `"serverless-operator"` | name of the operator package | -| serverlessOperator.subscription.spec.source | string | `"redhat-operators"` | name of the catalog source | -| serverlessOperator.subscription.spec.sourceNamespace | string | `"openshift-marketplace"` | | -| tests.enabled | bool | `true` | Whether to create the test pod used for testing the Release using `helm test`. | -| tests.image | string | `"bitnami/kubectl:latest"` | Test pod image | +| Key | Description | Type | Default | +|-----|-------------|------|---------| +| olm.catalog.selector | ClusterCatalog selector for OLM v1 ClusterExtension resources | object | `{"matchLabels":{"olm.operatorframework.io/metadata.name":"openshift-redhat-operators"}}` | +| olmVersion | OLM API version to use for operator installation (`v0` or `v1`) | string | `"v0"` | +| serverlessLogicOperator.clusterExtension.serviceAccount.name | service account used by OLM v1 to install the operator | string | `"serverless-logic-operator-installer"` | +| serverlessLogicOperator.createNamespace | whether to create the operator namespace (set to false if namespace already exists) | bool | `true` | +| serverlessLogicOperator.enabled | whether the operator should be deployed by the chart | bool | `true` | +| serverlessLogicOperator.subscription.namespace | namespace where the operator should be deployed | string | `"openshift-serverless-logic"` | +| serverlessLogicOperator.subscription.spec.channel | channel of an operator package to subscribe to | string | `"stable"` | +| serverlessLogicOperator.subscription.spec.installPlanApproval | whether the update should be installed automatically | string | `"Manual"` | +| serverlessLogicOperator.subscription.spec.name | name of the operator package | string | `"logic-operator"` | +| serverlessLogicOperator.subscription.spec.source | name of the catalog source | string | `"redhat-operators"` | +| serverlessLogicOperator.subscription.spec.sourceNamespace | | string | `"openshift-marketplace"` | +| serverlessLogicOperator.subscription.spec.startingCSV | The initial version of the operator, must match CRDs installed by the chart | string | `"logic-operator.v1.38.0"` | +| serverlessOperator.clusterExtension.serviceAccount.name | service account used by OLM v1 to install the operator | string | `"serverless-operator-installer"` | +| serverlessOperator.createNamespace | whether to create the operator namespace (set to false if namespace already exists) | bool | `true` | +| serverlessOperator.enabled | whether the operator should be deployed by the chart | bool | `true` | +| serverlessOperator.subscription.namespace | namespace where the operator should be deployed | string | `"openshift-serverless"` | +| serverlessOperator.subscription.spec.channel | channel of an operator package to subscribe to | string | `"stable"` | +| serverlessOperator.subscription.spec.installPlanApproval | whether the update should be installed automatically | string | `"Manual"` | +| serverlessOperator.subscription.spec.name | name of the operator package | string | `"serverless-operator"` | +| serverlessOperator.subscription.spec.source | name of the catalog source | string | `"redhat-operators"` | +| serverlessOperator.subscription.spec.sourceNamespace | | string | `"openshift-marketplace"` | +| tests.enabled | Whether to create the test pod used for testing the Release using `helm test`. | bool | `true` | +| tests.image | Test pod image | string | `"bitnami/kubectl:latest"` | ### OLM v0 and OLM v1 operator installation