Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
27 commits
Select commit Hold shift + click to select a range
4c9336d
feat(orchestrator-infra): add OLM v1 ClusterExtension install path
Fortune-Ndlovu Sep 16, 2026
120070a
fix(orchestrator-infra): resolve OLM v1 install failures on cluster
Fortune-Ndlovu Sep 16, 2026
b48f58a
fix(orchestrator-infra): defer Knative CRs on OLM v1 install path
Fortune-Ndlovu Sep 16, 2026
8759870
chore(orchestrator-infra): align docs/schema and drop NOTES.txt changes
Fortune-Ndlovu Sep 16, 2026
121d33d
docs(orchestrator-infra): simplify OLM installation README text
Fortune-Ndlovu Sep 16, 2026
d4b66d6
fix(orchestrator-infra): address Qodo review findings for OLM v1 path
Fortune-Ndlovu Sep 16, 2026
c83f8ec
fix(orchestrator-infra): fix CRD hooks for chart-testing upgrade path
Fortune-Ndlovu Sep 16, 2026
21d1301
fix(orchestrator-infra): restore Knative CRDs under crds/ unchanged
Fortune-Ndlovu Sep 16, 2026
5b84aec
fix(orchestrator-infra): use OLM API name in helm test
Fortune-Ndlovu Sep 17, 2026
dbb6b4c
fix(orchestrator-infra): address Qodo review items 1, 4, and 5 (#543)
Fortune-Ndlovu Sep 17, 2026
098f5e3
fix(orchestrator-infra): fix CI pre-commit and CRD upgrade path
Fortune-Ndlovu Sep 17, 2026
64d9c5a
fix(orchestrator-infra): provision Knative CRs via post-install hooks
Fortune-Ndlovu Sep 17, 2026
ffaacd3
fix(orchestrator-infra): run Knative provisioning on post-upgrade
Fortune-Ndlovu Sep 17, 2026
de929fc
fix(orchestrator-infra): add memory limits to Knative hook jobs
Fortune-Ndlovu Sep 17, 2026
60e6711
chore(orchestrator-infra): regenerate README with helm-docs
Fortune-Ndlovu Sep 17, 2026
b35f83c
refactor(orchestrator-infra): simplify OLM v1 path to ClusterExtensio…
Fortune-Ndlovu Sep 17, 2026
73d522f
Merge branch 'main' into feat/RHIDP-14789-orchestrator-infra-olm-v1
Fortune-Ndlovu Sep 21, 2026
b882606
fix(orchestrator-infra): remove auto olmVersion to support ArgoCD
Fortune-Ndlovu Sep 22, 2026
d38b528
Merge branch 'main' into feat/RHIDP-14789-orchestrator-infra-olm-v1
Fortune-Ndlovu Sep 22, 2026
687e864
fix(orchestrator-infra): remove all lookup and Capabilities.APIVersio…
Fortune-Ndlovu Sep 22, 2026
7187acc
fix(orchestrator-infra): add Helm ownership metadata to namespaces fo…
Fortune-Ndlovu Sep 22, 2026
dc0ac55
fix(orchestrator-infra): prevent duplicate namespace creation
Fortune-Ndlovu Sep 22, 2026
cf4487a
fix(orchestrator-infra): remove Helm ownership metadata from namespaces
Fortune-Ndlovu Sep 22, 2026
34288c8
fix(orchestrator-infra): address PR review feedback
Fortune-Ndlovu Sep 22, 2026
c9d6a0b
docs: update references from files/ to crds/ directory
Fortune-Ndlovu Sep 22, 2026
8d4abd2
fix(orchestrator-infra): add createNamespace flag to avoid adoption e…
Fortune-Ndlovu Sep 22, 2026
c596528
docs: regenerate README with helm-docs
Fortune-Ndlovu Sep 22, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 2 additions & 3 deletions .github/actions/test-charts/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -190,9 +190,8 @@ runs:
env:
SONATAFLOW_OPERATOR_VERSION: "10.1.0"
run: |
for crdDir in charts/orchestrator-infra/crds/*; do
kubectl create -f "${crdDir}"
done
kubectl create -f charts/orchestrator-infra/crds/knative-eventing/knative-eventing-crd.yaml
kubectl create -f charts/orchestrator-infra/crds/knative-serving/knative-serving-crd.yaml
kubectl create -f "https://github.com/apache/incubator-kie-tools/releases/download/${SONATAFLOW_OPERATOR_VERSION}/apache-kie-${SONATAFLOW_OPERATOR_VERSION}-incubating-sonataflow-operator.yaml"

- name: Set up external services and test resources for rhdh
Expand Down
2 changes: 1 addition & 1 deletion charts/orchestrator-infra/Chart.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -14,4 +14,4 @@ maintainers:
type: application
sources:
- https://github.com/redhat-developer/rhdh-chart
version: 0.6.1
version: 0.7.0
24 changes: 20 additions & 4 deletions charts/orchestrator-infra/README.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@

# Orchestrator Infra Chart for OpenShift

![Version: 0.6.1](https://img.shields.io/badge/Version-0.6.1-informational?style=flat-square)
![Version: 0.7.0](https://img.shields.io/badge/Version-0.7.0-informational?style=flat-square)
![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square)

Helm chart to deploy the Orchestrator solution's required infrastructure suite on OpenShift, including OpenShift Serverless Operator and OpenShift Serverless Logic Operator, both required to configure Red Hat Developer Hub to use the Orchestrator.
Expand All @@ -25,7 +25,7 @@ Kubernetes: `>= 1.25.0-0`
```console
helm repo add redhat-developer https://redhat-developer.github.io/rhdh-chart

helm install my-orchestrator-infra redhat-developer/redhat-developer-hub-orchestrator-infra --version 0.6.1
helm install my-orchestrator-infra redhat-developer/redhat-developer-hub-orchestrator-infra --version 0.7.0
```

> **Tip**: List all releases using `helm list`
Expand Down Expand Up @@ -83,6 +83,10 @@ The command removes all the Kubernetes components associated with the chart and

| Key | Description | Type | Default |
|-----|-------------|------|---------|
| olm.catalog.selector | ClusterCatalog selector for OLM v1 ClusterExtension resources | object | `{"matchLabels":{"olm.operatorframework.io/metadata.name":"openshift-redhat-operators"}}` |
| olmVersion | OLM API version to use for operator installation (`v0` or `v1`) | string | `"v0"` |
| serverlessLogicOperator.clusterExtension.serviceAccount.name | service account used by OLM v1 to install the operator | string | `"serverless-logic-operator-installer"` |
| serverlessLogicOperator.createNamespace | whether to create the operator namespace (set to false if namespace already exists) | bool | `true` |
| serverlessLogicOperator.enabled | whether the operator should be deployed by the chart | bool | `true` |
| serverlessLogicOperator.subscription.namespace | namespace where the operator should be deployed | string | `"openshift-serverless-logic"` |
| serverlessLogicOperator.subscription.spec.channel | channel of an operator package to subscribe to | string | `"stable"` |
Expand All @@ -91,6 +95,8 @@ The command removes all the Kubernetes components associated with the chart and
| serverlessLogicOperator.subscription.spec.source | name of the catalog source | string | `"redhat-operators"` |
| serverlessLogicOperator.subscription.spec.sourceNamespace | | string | `"openshift-marketplace"` |
| serverlessLogicOperator.subscription.spec.startingCSV | The initial version of the operator, must match CRDs installed by the chart | string | `"logic-operator.v1.38.0"` |
| serverlessOperator.clusterExtension.serviceAccount.name | service account used by OLM v1 to install the operator | string | `"serverless-operator-installer"` |
| serverlessOperator.createNamespace | whether to create the operator namespace (set to false if namespace already exists) | bool | `true` |
| serverlessOperator.enabled | whether the operator should be deployed by the chart | bool | `true` |
| serverlessOperator.subscription.namespace | namespace where the operator should be deployed | string | `"openshift-serverless"` |
| serverlessOperator.subscription.spec.channel | channel of an operator package to subscribe to | string | `"stable"` |
Expand All @@ -101,6 +107,18 @@ The command removes all the Kubernetes components associated with the chart and
| tests.enabled | Whether to create the test pod used for testing the Release using `helm test`. | bool | `true` |
| tests.image | Test pod image | string | `"bitnami/kubectl:latest"` |

### OLM v0 and OLM v1 operator installation

The chart defaults to `olmVersion: v0`.

- `v0`: creates `Subscription` resources
- `v1`: creates `ClusterExtension` resources with an installer ServiceAccount and ClusterRoleBinding

```bash
helm install my-orchestrator-infra ./charts/orchestrator-infra --set olmVersion=v0
helm install my-orchestrator-infra ./charts/orchestrator-infra --set olmVersion=v1
```

### Installing Knative Eventing and Knative Serving CRDs

The orchestrator-infra chart requires several CRDs for Knative Eventing and Knative Serving. These CRDs will be applied prior to installing the chart, ensuring that Knative CRs can be created as part of the chart's deployment process. This approach eliminates the need to wait for the OpenShift Serverless Operator's subscription to install them beforehand.
Expand All @@ -116,5 +134,3 @@ podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1b

podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1beta1_knativeserving_crd.yaml > crds/knative-serving/knative-serving-crd.yaml
```

After running these commands, you may need to re-add the `helm.sh/hook` annotations.
16 changes: 13 additions & 3 deletions charts/orchestrator-infra/README.md.gotmpl
Original file line number Diff line number Diff line change
Expand Up @@ -76,12 +76,24 @@ The command removes all the Kubernetes components associated with the chart and

{{ template "chart.valuesSection" . }}

### OLM v0 and OLM v1 operator installation

The chart defaults to `olmVersion: v0`.

- `v0`: creates `Subscription` resources
- `v1`: creates `ClusterExtension` resources with an installer ServiceAccount and ClusterRoleBinding

```bash
helm install my-orchestrator-infra ./charts/orchestrator-infra --set olmVersion=v0
helm install my-orchestrator-infra ./charts/orchestrator-infra --set olmVersion=v1
```

### Installing Knative Eventing and Knative Serving CRDs

The orchestrator-infra chart requires several CRDs for Knative Eventing and Knative Serving. These CRDs will be applied prior to installing the chart, ensuring that Knative CRs can be created as part of the chart's deployment process. This approach eliminates the need to wait for the OpenShift Serverless Operator's subscription to install them beforehand.

The KnativeEventing and KnativeServing CRDs are required for this chart to run. These CRDs need to be present under the `crds/` directory before running `helm install`.
After installing the openshift-serverless subscription, more Knative CRDs will be installed on the cluster.
After installing the openshift-serverless subscription, more Knative CRDs will be installed on the cluster.

The versions of the CRDs present in the chart and the ones in the subscription must match. In order to verify the correct CRD, use this following command to extract the CRD:

Expand All @@ -91,5 +103,3 @@ podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1b

podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1beta1_knativeserving_crd.yaml > crds/knative-serving/knative-serving-crd.yaml
```

After running these commands, you may need to re-add the `helm.sh/hook` annotations.
2 changes: 2 additions & 0 deletions charts/orchestrator-infra/ci/upstream-olm-values.yaml

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Since we can have both OLM v0 and v1 running in the same cluster, I think it might be worth adding a separate CI values file testing with olmVersion: v1. But that can be addressed in a followup issue/PR.

Original file line number Diff line number Diff line change
@@ -1,11 +1,13 @@
serverlessLogicOperator:
enabled: true
createNamespace: false
subscription:
namespace: operators
spec:
sourceNamespace: olm

serverlessOperator:
createNamespace: false
subscription:
namespace: operators
spec:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -16,10 +16,6 @@ apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
name: knativeeventings.operator.knative.dev
annotations:
"helm.sh/hook": pre-delete
"helm.sh/hook-weight": "-10"
"helm.sh/hook-delete-policy": before-hook-creation
labels:
app.kubernetes.io/version: devel
app.kubernetes.io/name: knative-operator
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -16,10 +16,6 @@ apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
name: knativeservings.operator.knative.dev
annotations:
"helm.sh/hook": pre-delete
"helm.sh/hook-weight": "-10"
"helm.sh/hook-delete-policy": before-hook-creation
labels:
app.kubernetes.io/version: devel
app.kubernetes.io/name: knative-operator
Expand Down
7 changes: 0 additions & 7 deletions charts/orchestrator-infra/templates/NOTES.txt
Original file line number Diff line number Diff line change
Expand Up @@ -4,18 +4,11 @@ Helm Release {{ .Release.Name }} installed in namespace {{ .Release.Namespace }}
{{- $yes := "YES" }}
{{- $no := "NO " }}
{{- $serverlessOperatorInstalled := $no }}
{{- $knativeServingInstalled := $no }}
{{- $knativeEventingInstalled := $no }}
{{- $serverlessLogicOperatorInstalled := $no }}
{{- $sonataFlowPlatformInstalled := $no }}
{{- $timeout := "--timeout=5m" }}

{{- if .Values.serverlessOperator.enabled }}
{{- $unmanagedSubscriptionExists := include "unmanaged-resource-exists" (list "operators.coreos.com/v1alpha1" "Subscription" .Values.serverlessOperator.subscription.namespace "serverless-operator" .Release.Name .Capabilities.APIVersions ) }}
{{- if eq $unmanagedSubscriptionExists "false" }}
{{- $serverlessOperatorInstalled = $yes }}
{{- end }}
{{- end }}

{{- if .Values.serverlessLogicOperator.enabled }}
{{- $serverlessLogicOperatorInstalled = $yes }}
Expand Down
42 changes: 9 additions & 33 deletions charts/orchestrator-infra/templates/_helpers.tpl
Original file line number Diff line number Diff line change
@@ -1,37 +1,13 @@
{{/* Helper functions */}}

{{- define "unmanaged-resource-exists" -}}
{{- $api := index . 0 -}}
{{- $kind := index . 1 -}}
{{- $namespace := index . 2 -}}
{{- $name := index . 3 -}}
{{- $releaseName := index . 4 -}}
{{- $apiCapabilities := index . 5 -}}
{{- $unmanagedSubscriptionExists := "true" -}}
{{- if $apiCapabilities.Has (printf "%s/%s" $api $kind) }}
{{- $existingOperator := lookup $api $kind $namespace $name -}}
{{- if empty $existingOperator -}}
{{- "false" -}}
{{- else -}}
{{- $isManagedResource := include "is-managed-resource" (list $existingOperator $releaseName) -}}
{{- if eq $isManagedResource "true" -}}
{{- "false" -}}
{{- else -}}
{{- "true" -}}
{{- end -}}
{{- end -}}
{{- else -}}
{{- "false" -}}
{{- end -}}
{{- define "olm-version" -}}
{{- $requested := default "v0" .Values.olmVersion -}}
{{- $requested -}}
{{- end -}}

{{- define "is-managed-resource" -}}
{{- $resource := index . 0 -}}
{{- $releaseName := index . 1 -}}
{{- $resourceReleaseName := dig "metadata" "annotations" (dict "meta.helm.sh/release-name" "NA") $resource -}}
{{- if eq (get $resourceReleaseName "meta.helm.sh/release-name") $releaseName -}}
{{- "true" -}}
{{- else -}}
{{- "false" -}}
{{- end -}}
{{- end -}}
{{- define "csv-version" -}}
{{- $csv := index . 0 -}}
{{- $packageName := index . 1 -}}
{{- $version := trimPrefix (printf "%s." $packageName) $csv -}}
{{- trimPrefix "v" $version -}}
{{- end -}}
Original file line number Diff line number Diff line change
@@ -0,0 +1,55 @@
{{- $packageName := .Values.serverlessLogicOperator.subscription.spec.name -}}
{{- $namespace := .Values.serverlessLogicOperator.subscription.namespace -}}
{{- $serviceAccountName := .Values.serverlessLogicOperator.clusterExtension.serviceAccount.name -}}
{{- if and (eq (include "olm-version" .) "v1") .Values.serverlessLogicOperator.enabled }}
apiVersion: v1
kind: ServiceAccount
metadata:
name: {{ $serviceAccountName }}
namespace: {{ $namespace }}
annotations:
meta.helm.sh/release-name: {{ .Release.Name }}
meta.helm.sh/release-namespace: {{ .Release.Namespace }}
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: {{ $packageName }}-installer-binding
annotations:
meta.helm.sh/release-name: {{ .Release.Name }}
meta.helm.sh/release-namespace: {{ .Release.Namespace }}
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: cluster-admin
subjects:
- kind: ServiceAccount
name: {{ $serviceAccountName }}
namespace: {{ $namespace }}
---
apiVersion: olm.operatorframework.io/v1
kind: ClusterExtension
metadata:
name: {{ $packageName }}
annotations:
meta.helm.sh/release-name: {{ .Release.Name }}
meta.helm.sh/release-namespace: {{ .Release.Namespace }}
spec:
install:
preflight:
crdUpgradeSafety:
enforcement: None
namespace: {{ $namespace }}
serviceAccount:
name: {{ $serviceAccountName }}
source:
sourceType: Catalog
catalog:
packageName: {{ $packageName }}
channels:
- {{ .Values.serverlessLogicOperator.subscription.spec.channel }}
version: {{ include "csv-version" (list .Values.serverlessLogicOperator.subscription.spec.startingCSV $packageName) | quote }}
selector:
{{- toYaml .Values.olm.catalog.selector | nindent 8 }}
upgradeConstraintPolicy: CatalogProvided
{{- end }}
Original file line number Diff line number Diff line change
@@ -1,8 +1,9 @@
{{- $unmanagedNamespaceExists := include "unmanaged-resource-exists" (list "v1" "Namespace" "" .Values.serverlessLogicOperator.subscription.namespace .Release.Name .Capabilities.APIVersions) }}
{{- if and (eq $unmanagedNamespaceExists "false") .Values.serverlessLogicOperator.enabled }}
{{- if and .Values.serverlessLogicOperator.enabled .Values.serverlessLogicOperator.createNamespace (ne .Values.serverlessLogicOperator.subscription.namespace .Values.serverlessOperator.subscription.namespace) }}
---
apiVersion: v1
kind: Namespace
metadata:
name: {{ .Values.serverlessLogicOperator.subscription.namespace }}
annotations:
"helm.sh/resource-policy": keep
{{- end }}
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
{{- if .Values.serverlessLogicOperator.enabled }}
{{- if and .Values.serverlessLogicOperator.enabled (eq (include "olm-version" .) "v0") }}
apiVersion: operators.coreos.com/v1
kind: OperatorGroup
metadata:
Expand Down
Original file line number Diff line number Diff line change
@@ -1,10 +1,11 @@
{{- $unmanagedSubscriptionExists := include "unmanaged-resource-exists" (list "operators.coreos.com/v1alpha1" "Subscription" .Values.serverlessLogicOperator.subscription.namespace .Values.serverlessLogicOperator.subscription.spec.name .Release.Name .Capabilities.APIVersions ) }}
{{- if and (eq $unmanagedSubscriptionExists "false") .Values.serverlessLogicOperator.enabled }}
{{- $packageName := .Values.serverlessLogicOperator.subscription.spec.name -}}
{{- $subscriptionNamespace := .Values.serverlessLogicOperator.subscription.namespace -}}
{{- if and (eq (include "olm-version" .) "v0") .Values.serverlessLogicOperator.enabled }}
apiVersion: operators.coreos.com/v1alpha1
kind: Subscription
metadata:
name: {{ .Values.serverlessLogicOperator.subscription.spec.name }}
namespace: {{ .Values.serverlessLogicOperator.subscription.namespace }}
name: {{ $packageName }}
namespace: {{ $subscriptionNamespace }}
spec:
{{- toYaml .Values.serverlessLogicOperator.subscription.spec | nindent 2 }}
{{- end }}
Original file line number Diff line number Diff line change
@@ -0,0 +1,54 @@
{{- $packageName := .Values.serverlessOperator.subscription.spec.name -}}
{{- $namespace := .Values.serverlessOperator.subscription.namespace -}}
{{- $serviceAccountName := .Values.serverlessOperator.clusterExtension.serviceAccount.name -}}
{{- if and (eq (include "olm-version" .) "v1") .Values.serverlessOperator.enabled }}
apiVersion: v1
kind: ServiceAccount
metadata:
name: {{ $serviceAccountName }}
namespace: {{ $namespace }}
annotations:
meta.helm.sh/release-name: {{ .Release.Name }}
meta.helm.sh/release-namespace: {{ .Release.Namespace }}
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: {{ $packageName }}-installer-binding
annotations:
meta.helm.sh/release-name: {{ .Release.Name }}
meta.helm.sh/release-namespace: {{ .Release.Namespace }}
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: cluster-admin
subjects:
- kind: ServiceAccount
name: {{ $serviceAccountName }}
namespace: {{ $namespace }}
---
apiVersion: olm.operatorframework.io/v1
kind: ClusterExtension
metadata:
name: {{ $packageName }}
annotations:
meta.helm.sh/release-name: {{ .Release.Name }}
meta.helm.sh/release-namespace: {{ .Release.Namespace }}
spec:
install:
preflight:
crdUpgradeSafety:
enforcement: None
namespace: {{ $namespace }}
serviceAccount:
name: {{ $serviceAccountName }}
source:
sourceType: Catalog
catalog:
packageName: {{ $packageName }}
channels:
- {{ .Values.serverlessOperator.subscription.spec.channel }}
selector:
{{- toYaml .Values.olm.catalog.selector | nindent 8 }}
upgradeConstraintPolicy: CatalogProvided
{{- end }}
Loading
Loading