Using Operator Lifecycle Manager in disconnected environments
For OpenShift Container Platform clusters in disconnected environments, Operator Lifecycle Manager (OLM) by default cannot access the Red Hat-provided software catalog sources hosted on remote registries because those remote sources require full internet connectivity.
However, as a cluster administrator you can still enable your cluster to use OLM in a disconnected environment if you have a workstation that has full internet access. The workstation, which requires full internet access to pull the remote software catalog content, is used to prepare local mirrors of the remote sources, and push the content to a mirror registry.
The mirror registry can be located on a bastion host, which requires connectivity to both your workstation and the disconnected cluster, or a completely disconnected, or airgapped, host, which requires removable media to physically move the mirrored content to the disconnected environment.
This guide describes the following process that is required to enable OLM in disconnected environments:
- Disable the default remote software catalog sources for OLM.
- Use a workstation with full internet access to create and push local mirrors of the software catalog content to a mirror registry.
- Configure OLM to install and manage Operators from local sources on the mirror registry instead of the default remote sources.
After enabling OLM in a disconnected environment, you can continue to use your unrestricted workstation to keep your local software catalog sources updated as newer versions of Operators are released.
While OLM can manage Operators from local sources, the ability for a given Operator to run successfully in a disconnected environment still depends on the Operator itself meeting the following criteria:
- List any related images, or other container images that the Operator might require to perform their functions, in the
relatedImagesparameter of itsClusterServiceVersion(CSV) object. - Reference all specified images by a digest (SHA) and not by a tag.
You can search software on the Red Hat Ecosystem Catalog for a list of Red Hat Operators that support running in disconnected mode by filtering with the following selections:
- Type
- Containerized application
- Deployment method
- Operator
- Infrastructure features
- Disconnected For more information, see "Red Hat Ecosystem Catalog".
Additional resources
Prerequisites
You must meet several prerequisites before using OLM in a disconnected environment.
The following prerequisites must be met:
- You are logged in to your OpenShift Container Platform cluster as a user with
cluster-adminprivileges. - If you are using OLM in a disconnected environment on IBM Z(R), you must have at least 12 GB allocated to the directory where you place your registry.
Disabling the default software catalog sources
To use only trusted or locally available Operator catalogs, disable the default software catalog sources that OpenShift Container Platform configures during installation. In a restricted network environment, you must disable the default catalogs as a cluster administrator. You can then configure the OperatorHub custom resource definition (CRD) to use local catalog sources for the software catalog.
Procedure
-
Disable the sources for the default catalogs by adding
disableAllDefaultSources: trueto theOperatorHubobject:$ oc patch OperatorHub cluster --type json \-p '[{"op": "add", "path": "/spec/disableAllDefaultSources", "value": true}]'tipOr, you can use the web console to manage catalog sources. From the Administration → Cluster Settings → Configuration → OperatorHub page, click the Sources tab, where you can create, update, delete, disable, and enable individual sources.
Mirroring an Operator catalog
For instructions about mirroring Operator catalogs for use with disconnected clusters, see "Mirroring Operator catalogs for use with disconnected clusters".
As of OpenShift Container Platform 4.11, the default Red Hat-provided Operator catalog releases in the file-based catalog format. The default Red Hat-provided Operator catalogs for OpenShift Container Platform 4.6 through 4.10 released in the deprecated SQLite database format.
The opm subcommands, flags, and functionality related to the SQLite database format are also deprecated and will be removed in a future release. The features are still supported and must be used for catalogs that use the deprecated SQLite database format.
Many of the opm subcommands and flags for working with the SQLite database format, such as opm index prune, do not work with the file-based catalog format. For more information about working with file-based catalogs, see "Operator Framework packaging format", "Managing custom catalogs", and "Mirroring images for a disconnected installation by using the oc-mirror plugin v2".
Additional resources
- Mirroring Operator catalogs for use with disconnected clusters
- Operator Framework packaging format
- Managing custom catalogs
- Mirroring images for a disconnected installation by using the oc-mirror plugin v2
Adding a catalog source to a cluster
To make Operators from a custom index image available for installation, create a catalog source that adds the catalog content to your cluster.
Cluster administrators
can create a CatalogSource object that references an index image. The software catalog uses catalog sources to populate the user interface.
Alternatively, you can use the web console to manage catalog sources. From the Administration → Cluster Settings → Configuration → OperatorHub page, click the Sources tab, where you can create, update, delete, disable, and enable individual sources.
Prerequisites
- You built and pushed an index image to a registry.
- You have access to the cluster as a user with the
cluster-adminrole.
Procedure
- Create a
CatalogSourceobject that references your index image. If you used theoc adm catalog mirrorcommand to mirror your catalog to a target registry, you can use the generatedcatalogSource.yamlfile in your manifests directory as a starting point.-
Modify the following to your specifications and save it as a
catalogSource.yamlfile:apiVersion: operators.coreos.com/v1alpha1kind: CatalogSourcemetadata:name: my-operator-catalognamespace: openshift-marketplacespec:sourceType: grpcgrpcPodConfig:securityContextConfig: <security_mode>image: <registry>/<namespace>/redhat-operator-index:v4.22displayName: My Operator Catalogpublisher: <publisher_name>updateStrategy:registryPoll:interval: 30mwhere:
metadata.nameSpecifies the value for the
metadata.nameparameter. If you mirrored content to local files before uploading to a registry, remove any backslash (/) characters from themetadata.namefield to avoid an "invalid resource name" error when you create the object.metadata.namespaceSpecifies the value for the
metadata.namespaceparameter. If you want the catalog source to be available globally to users in all namespaces, specify theopenshift-marketplacenamespace. Otherwise, you can specify a different namespace for the catalog to be scoped and available only for that namespace.spec.grpcPodConfig.securityContextConfigSpecifies the value of
legacyorrestricted. If the field is not set, the default value islegacy. In a future OpenShift Container Platform release, it is planned that the default value will berestricted.noteIf your catalog cannot run with
restrictedpermissions, it is recommended that you manually set this field tolegacy.spec.imageSpecifies your index image. If you specify a tag after the image name, for example
:v4.22, the catalog source pod uses an image pull policy ofAlways, meaning the pod always pulls the image before starting the container. If you specify a digest, for example@sha256:<id>, the image pull policy isIfNotPresent, meaning the pod pulls the image only if it does not already exist on the node.spec.publisherSpecifies your name or an organization name publishing the catalog.
spec.updateStrategy.registryPollSpecifies the value for the
spec.updateStrategy.registryPollparameter. The catalog sources can automatically check for new versions to keep up to date. -
Use the file to create the
CatalogSourceobject:$ oc apply -f catalogSource.yaml
-
- Verify the following resources are created successfully.
-
Check the pods:
$ oc get pods -n openshift-marketplaceThe following is example output:
NAME READY STATUS RESTARTS AGEmy-operator-catalog-6njx6 1/1 Running 0 28smarketplace-operator-d9f549946-96sgr 1/1 Running 0 26h -
Check the catalog source:
$ oc get catalogsource -n openshift-marketplaceThe following is example output:
NAME DISPLAY TYPE PUBLISHER AGEmy-operator-catalog My Operator Catalog grpc 5s -
Check the package manifest:
$ oc get packagemanifest -n openshift-marketplaceThe following is example output:
NAME CATALOG AGEjaeger-product My Operator Catalog 93sYou can now install the Operators from the Software Catalog page on your OpenShift Container Platform web console.
-
Additional resources