Installing the cert-manager Operator for Red Hat OpenShift
The cert-manager Operator for Red Hat OpenShift is not installed in OpenShift Container Platform by default. You can install the cert-manager Operator for Red Hat OpenShift by using the web console and command-line interface (CLI).
The cert-manager Operator for Red Hat OpenShift sets the features.operators.openshift.io/token-auth-aws, features.operators.openshift.io/token-auth-azure, and features.operators.openshift.io/token-auth-gcp annotations in the ClusterServiceVersion custom resource of the Operator. The OpenShift Container Platform web console requires the credential details when these annotations are set. Currently, the Operator does not use the values collected by the OpenShift web console and you can provide any value when asked for the input. For example, when installing on the managed OpenShift Container Platform cluster, the identity-provider-arn is asked and any value can be provided to proceed.
The cert-manager Operator for Red Hat OpenShift version 1.15 or later supports the AllNamespaces, SingleNamespace, and OwnNamespace installation modes. Earlier versions, such as 1.14, support only the SingleNamespace and OwnNamespace installation modes.
Install the cert-manager Operator for Red Hat OpenShift by using the web console
You can use the web console to install the cert-manager Operator for Red Hat OpenShift.
Prerequisites
- You have access to the cluster with
cluster-adminprivileges. - You have access to the OpenShift Container Platform web console.
Procedure
-
Log in to the OpenShift Container Platform web console.
-
Navigate to Ecosystem → Software Catalog.
-
Enter cert-manager Operator for Red Hat OpenShift into the filter box.
-
Select the cert-manager Operator for Red Hat OpenShift
-
Select the cert-manager Operator for Red Hat OpenShift version from Version drop-down list, and click Install.
noteSee supported cert-manager Operator for Red Hat OpenShift versions in the following "Additional resources" section.
-
On the Install Operator page:
-
Update the Update channel, if necessary. The channel defaults to stable-v1, which installs the latest stable release of the cert-manager Operator for Red Hat OpenShift.
-
Choose the Installed Namespace for the Operator. The default Operator namespace is
cert-manager-operator. If thecert-manager-operatornamespace does not exist, it is created for you.noteDuring the installation, the OpenShift Container Platform web console allows you to select between
AllNamespacesandSingleNamespaceinstallation modes. For installations with cert-manager Operator for Red Hat OpenShift version 1.15.0 or later, it is recommended to choose theAllNamespacesinstallation mode.SingleNamespaceandOwnNamespacesupport will remain for earlier versions but will be deprecated in future versions. -
Select an Update approval strategy.
- The Automatic strategy allows Operator Lifecycle Manager (OLM) to automatically update the Operator when a new version is available.
- The Manual strategy requires a user with appropriate credentials to approve the Operator update.
-
Click Install.
-
Verification
-
Navigate to Ecosystem → Installed Operators.
-
Verify that cert-manager Operator for Red Hat OpenShift is listed with a Status of Succeeded in the
cert-manager-operatornamespace. -
Verify that cert-manager pods are up and running by entering the following command:
$ oc get pods -n cert-managerExample outputNAME READY STATUS RESTARTS AGEcert-manager-bd7fbb9fc-wvbbt 1/1 Running 0 3m39scert-manager-cainjector-56cc5f9868-7g9z7 1/1 Running 0 4m5scert-manager-webhook-d4f79d7f7-9dg9w 1/1 Running 0 4m9sYou can use the cert-manager Operator for Red Hat OpenShift only after cert-manager pods are up and running.
Install the cert-manager Operator for Red Hat OpenShift by using the CLI
You can install the cert-manager Operator for Red Hat OpenShift by using the command-line interface (CLI).
Prerequisites
- You have access to the cluster with
cluster-adminprivileges.
Procedure
- Create a new project named
cert-manager-operatorby running the following command:$ oc new-project cert-manager-operator - Create an
OperatorGroupobject:-
Create a YAML file, for example,
operatorGroup.yaml, with the following content:apiVersion: operators.coreos.com/v1kind: OperatorGroupmetadata:name: openshift-cert-manager-operatornamespace: cert-manager-operatorspec:targetNamespaces:- "cert-manager-operator" -
For cert-manager Operator for Red Hat OpenShift v1.15.0 or later, create a YAML file with the following content:
apiVersion: operators.coreos.com/v1kind: OperatorGroupmetadata:name: openshift-cert-manager-operatornamespace: cert-manager-operatorspec:targetNamespaces: []spec: {}noteStarting from cert-manager Operator for Red Hat OpenShift version 1.15.0, it is recommended to install the Operator using the
AllNamespacesOLMinstallMode. Older versions can continue using theSingleNamespaceorOwnNamespaceOLMinstallMode. Support forSingleNamespaceandOwnNamespacewill be deprecated in future versions. -
Create the
OperatorGroupobject by running the following command:$ oc create -f operatorGroup.yaml
-
- Create a
Subscriptionobject:- Create a YAML file, for example,
subscription.yaml, that defines theSubscriptionobject:apiVersion: operators.coreos.com/v1alpha1kind: Subscriptionmetadata:name: openshift-cert-manager-operatornamespace: cert-manager-operatorspec:channel: stable-v1name: openshift-cert-manager-operatorsource: redhat-operatorssourceNamespace: openshift-marketplaceinstallPlanApproval: Automatic - Create the
Subscriptionobject by running the following command:$ oc create -f subscription.yaml
- Create a YAML file, for example,
Verification
-
Verify that the OLM subscription is created by running the following command:
$ oc get subscription -n cert-manager-operatorExample outputNAME PACKAGE SOURCE CHANNELopenshift-cert-manager-operator openshift-cert-manager-operator redhat-operators stable-v1 -
Verify whether the Operator is successfully installed by running the following command:
$ oc get csv -n cert-manager-operatorExample outputNAME DISPLAY VERSION REPLACES PHASEcert-manager-operator.v1.13.0 cert-manager Operator for Red Hat OpenShift 1.13.0 cert-manager-operator.v1.12.1 Succeeded -
Verify that the status cert-manager Operator for Red Hat OpenShift is
Runningby running the following command:$ oc get pods -n cert-manager-operatorExample outputNAME READY STATUS RESTARTS AGEcert-manager-operator-controller-manager-695b4d46cb-r4hld 2/2 Running 0 7m4s -
Verify that the status of cert-manager pods is
Runningby running the following command:$ oc get pods -n cert-managerExample outputNAME READY STATUS RESTARTS AGEcert-manager-58b7f649c4-dp6l4 1/1 Running 0 7m1scert-manager-cainjector-5565b8f897-gx25h 1/1 Running 0 7m37scert-manager-webhook-9bc98cbdd-f972x 1/1 Running 0 7m40s
Additional resources