Enabling create-only mode for the Zero Trust Workload Identity Manager {#zero-trust-manager-reconciliation_{context}}
To pause Operator reconciliation, enable create-only mode by setting an environment variable in the subscription object. By setting this value, you can perform manual configurations or debug the operator without the controller overwriting your changes.
The following scenarios are examples of when the create-only mode might be of use:
Manual Customization Required: You need to customize operator-managed resources (ConfigMaps, Deployments, DaemonSets, etc.) with specific configurations that differ from the operator’s defaults
Day 2 Operations: After initial deployment, you want to prevent the operator from overwriting their manual changes during subsequent reconciliation cycles
Configuration Drift Prevention: You want to maintain control over certain resource configurations while still benefiting from the operator’s lifecycle management
Pausing Operator reconciliation
Pause reconciliation of the operands by enabling create-only mode. This setting prevents the Operator from automatically reverting your manual changes to the desired state. You can enable this mode by updating the Operator’s subscription object.
When create-only mode is disabled, the Operator overwrites the resources if any conflicts exist.
Prerequisites
- You have installed Zero Trust Workload Identity Manager on your machine.
- You have installed the SPIRE Servers, Agents, SPIFFE Container Storage Interface (CSI), and an OpenID Connect (OIDC) Discovery Provider and are in running status.
Procedure
- To pause reconciling the operands resources managed by the Operator, add the environment variable
CREATE_ONLY_MODE:truein the subscription object by running the following command:$ oc -n $OPERATOR_NAMESPACE patch subscription openshift-zero-trust-workload-identity-manager --type='merge' -p '{"spec":{"config":{"env":[{"name":"CREATE_ONLY_MODE","value":"true"}]}}}'
Verification
-
Check the status of the
SpireServerresource to confirm that thecreate-onlymode is active. Thestatusmust betrueand thereasonmust beCreateOnlyModeEnabled.$ oc get SpireServer cluster -o yamlThe following is an example that confirms that the 'create-only' mode is active.
status:conditions:- lastTransitionTime: "2025-12-23T11:36:58Z"message: All components are readyreason: Readystatus: "True"type: Ready- lastTransitionTime: "2025-12-23T11:36:58Z"message: All operand CRs are readyreason: Readystatus: "True"type: OperandsAvailable- lastTransitionTime: "2025-12-23T11:36:58Z"message: create-only mode enabledreason: CreateOnlyModeEnabledstatus: "True"type: CreateOnlyModewarningThe Operator updates the upgradeable condition to
falsein theoperatorConditionresource. You might not be able to upgrade the Operator when increate-onlymode.
Resuming Operator reconciliation
To resume Operator reconciliation after manual configuration or debugging, disable the create-only mode. This allows the controller to resume managing resources and applying the desired state. You can disable this mode by setting the environment variable in the subscription object.
Prerequisites
- You have enabled
create-onlymode on the Zero Trust Workload Identity Manager. - You have completed your manual configuration or debugging tasks.
Procedure
- To restart reconciling the Operator-managed resources, add the environment variable
CREATE_ONLY_MODE:falsein the subscription object by running the following command:$ oc -n $OPERATOR_NAMESPACE patch subscription openshift-zero-trust-workload-identity-manager --type='merge' -p '{"spec":{"config":{"env":[{"name":"CREATE_ONLY_MODE","value":"false"}]}}}'
Verification
-
Check the status of the
SpireServerresource to confirm thatcreate-onlymode is disabled by running the following command:$ oc get SpireServer cluster -o yamlExample outputstatus:conditions:- lastTransitionTime: "2025-12-23T11:40:00Z"message: create-only mode disabledreason: CreateOnlyModeDisabledstatus: "False"type: CreateOnlyMode