Configuring Operator Lifecycle Manager features
Cluster administrators can enable or disable Operator Lifecycle Manager (OLM) cluster features by editing the OLMConfig custom resource (CR) named cluster in OpenShift Container Platform.
Disabling copied CSVs
To reduce memory, etcd, and network usage on large OpenShift Container Platform clusters, you can disable copied cluster service versions (CSVs) for Operators installed in AllNamespaces mode through the cluster OLMConfig.
When an Operator is installed by Operator Lifecycle Manager (OLM), a simplified copy of its cluster service version (CSV) is created by default in every namespace that the Operator is configured to watch. These CSVs are known as copied CSVs and communicate to users which controllers are actively reconciling resource events in a given namespace.
When an Operator is configured to use the AllNamespaces install mode, versus targeting a single or specified set of namespaces, a copied CSV for the Operator is created in every namespace on the cluster. On especially large clusters, with namespaces and installed Operators potentially in the hundreds or thousands, copied CSVs consume an untenable amount of resources, such as OLM’s memory usage, cluster etcd limits, and networking.
If you disable copied CSVs, an Operator installed in AllNamespaces mode has their CSV copied only to the openshift namespace, instead of every namespace on the cluster. In disabled copied CSVs mode, the behavior differs between the web console and CLI:
-
In the web console, the default behavior is modified to show copied CSVs from the
openshiftnamespace in every namespace, even though the CSVs are not actually copied to every namespace. This allows regular users to still be able to view the details of these Operators in their namespaces and create related custom resources (CRs). -
In the OpenShift CLI (
oc), regular users can view Operators installed directly in their namespaces by using theoc get csvscommand, but the copied CSVs from theopenshiftnamespace are not visible in their namespaces. Operators affected by this limitation are still available and continue to reconcile events in the user’s namespace. To view a full list of installed global Operators, similar to the web console behavior, all authenticated users can run the following command:$ oc get csvs -n openshift
Procedure
-
Edit the
OLMConfigobject namedclusterand set thespec.features.disableCopiedCSVsfield totrue:$ oc apply -f - <<EOFapiVersion: operators.coreos.com/v1kind: OLMConfigmetadata:name: clusterspec:features:disableCopiedCSVs: true (1)EOF- Disabled copied CSVs for
AllNamespacesinstall mode Operators
- Disabled copied CSVs for
Verification
-
When copied CSVs are disabled, OLM captures this information in an event in the Operator’s namespace:
$ oc get eventsExample outputLAST SEEN TYPE REASON OBJECT MESSAGE85s Warning DisabledCopiedCSVs clusterserviceversion/my-csv.v1.0.0 CSV copying disabled for operators/my-csv.v1.0.0When the
spec.features.disableCopiedCSVsfield is missing or set tofalse, OLM recreates the copied CSVs for all Operators installed with theAllNamespacesmode and deletes the previously mentioned events.
Additional resources