---
title: Overriding the active deadline for run-once pods
---

# Overriding the active deadline for run-once pods {#run-once-duration-override-install}

You can use the Run Once Duration Override Operator to set a maximum active deadline for run-once pods in your cluster.

By enabling the run-once duration override on a namespace, all future run-once pods created or updated in that namespace have their `activeDeadlineSeconds` field set to the value specified by the Run Once Duration Override Operator.

> [!NOTE]
> If both the run-once pod and the Run Once Duration Override Operator have their `activeDeadlineSeconds` value set, the lower of the two values is used.

## Installing the Run Once Duration Override Operator {#rodoo-install-operator_run-once-duration-override-install}

Install the Run Once Duration Override Operator by using the web console to create the required namespace, install the Operator from the software catalog, and create a `RunOnceDurationOverride` instance.

**Prerequisites**

- You have access to the cluster with `cluster-admin` privileges.
- You have access to the OpenShift Container Platform web console.

**Procedure**

1. Log in to the OpenShift Container Platform web console.
2. Create the required namespace for the Run Once Duration Override Operator.

   1. Navigate to **Administration** → **Namespaces** and click **Create Namespace**.
   2. Enter `openshift-run-once-duration-override-operator` in the **Name** field and click **Create**.
3. Install the Run Once Duration Override Operator.

   1. Navigate to **Ecosystem** → **Software Catalog**.
   2. Enter **Run Once Duration Override Operator** into the filter box.
   3. Select the **Run Once Duration Override Operator** and click **Install**.
   4. On the **Install Operator** page:

      1. The **Update channel** is set to **stable**, which installs the latest stable release of the Run Once Duration Override Operator.
      2. Select **A specific namespace on the cluster**.
      3. Choose **openshift-run-once-duration-override-operator** from the dropdown menu under **Installed namespace**.
      4. Select an **Update approval** strategy.

         - The **Automatic** strategy allows Operator Lifecycle Manager (OLM) to automatically update the Operator when a new version is available.
         - The **Manual** strategy requires a user with appropriate credentials to approve the Operator update.
      5. Click **Install**.
4. Create a `RunOnceDurationOverride` instance.

   1. From the **Ecosystem** → **Installed Operators** page, click **Run Once Duration Override Operator**.
   2. Select the **Run Once Duration Override** tab and click **Create RunOnceDurationOverride**.
   3. Edit the settings as necessary.

      Under the `runOnceDurationOverride` section, you can update the `spec.activeDeadlineSeconds` value, if required. The predefined value is `3600` seconds, or 1 hour.
   4. Click **Create**.

**Verification**

1. Log in to the OpenShift CLI.
2. Verify all pods are created and running properly.

   ```terminal
   $ oc get pods -n openshift-run-once-duration-override-operator
   ```

   ```terminal {title="Example output"}
   NAME                                                   READY   STATUS    RESTARTS   AGE
   run-once-duration-override-operator-7b88c676f6-lcxgc   1/1     Running   0          7m46s
   runoncedurationoverride-62blp                          1/1     Running   0          41s
   runoncedurationoverride-h8h8b                          1/1     Running   0          41s
   runoncedurationoverride-tdsqk                          1/1     Running   0          41s
   ```

## Enabling the run-once duration override on a namespace {#rodoo-enable-override_run-once-duration-override-install}

Enable the run-once duration override on a namespace by adding the `runoncedurationoverrides.admission.runoncedurationoverride.openshift.io/enabled=true` label to the namespace.

**Prerequisites**

- The Run Once Duration Override Operator is installed.

**Procedure**

1. Log in to the OpenShift CLI.
2. Add the label to enable the run-once duration override to your namespace:

   ```terminal
   $ oc label namespace <namespace> \
       runoncedurationoverrides.admission.runoncedurationoverride.openshift.io/enabled=true
   ```

   Replace <namespace> with the namespace to enable the run-once duration override on.

   After you enable the run-once duration override on this namespace, future run-once pods that are created in this namespace will have their `activeDeadlineSeconds` field set to the override value from the Run Once Duration Override Operator. Existing pods in this namespace will also have their `activeDeadlineSeconds` value set when they are updated next.

**Verification**

1. Create a test run-once pod in the namespace that you enabled the run-once duration override on:

   ```yaml
   apiVersion: v1
   kind: Pod
   metadata:
     name: example
     namespace: namespace
   spec:
     restartPolicy: Never
     securityContext:
       runAsNonRoot: true
       seccompProfile:
         type: RuntimeDefault
     containers:
       - name: busybox
         securityContext:
           allowPrivilegeEscalation: false
           capabilities:
             drop: [ALL]
         image: busybox:1.25
         command:
           - /bin/sh
           - -ec
           - |
             while sleep 5; do date; done
   ```

   where:

   `metadata.namespace`
   :   Specifies your namespace.

   `spec.restartPolicy`
   :   Specifies the restart policy. The `restartPolicy` must be `Never` or `OnFailure` to be a run-once pod.
2. Verify that the pod has its `activeDeadlineSeconds` field set:

   ```terminal
   $ oc get pods -n <namespace> -o yaml | grep activeDeadlineSeconds
   ```

   ```terminal {title="Example output"}
       activeDeadlineSeconds: 3600
   ```

## Updating the run-once active deadline override value {#rodoo-update-active-deadline-seconds_run-once-duration-override-install}

Update the `activeDeadlineSeconds` field in the `RunOnceDurationOverride` resource to customize the override value that the operator applies to run-once pods.

**Prerequisites**

- You have access to the cluster with `cluster-admin` privileges.
- You have installed the Run Once Duration Override Operator.

**Procedure**

1. Log in to the OpenShift CLI.
2. Edit the `RunOnceDurationOverride` resource:

   ```terminal
   $ oc edit runoncedurationoverride cluster
   ```
3. Update the `activeDeadlineSeconds` field:

   ```yaml
   apiVersion: operator.openshift.io/v1
   kind: RunOnceDurationOverride
   metadata:
   # ...
   spec:
     runOnceDurationOverride:
       spec:
         activeDeadlineSeconds: 1800
   # ...
   ```

   where:

   `spec.runOnceDurationOverride.spec.activeDeadlineSeconds`
   :   Specifies the desired time limit value, in seconds.
4. Save the file to apply the changes.

   Any future run-once pods created in namespaces where the run-once duration override is enabled will have their `activeDeadlineSeconds` field set to this new value. Existing run-once pods in these namespaces will receive this new value when they are updated.
