Overriding the active deadline for run-once pods¶
You can use the Run Once Duration Override Operator to set a maximum active deadline for run-once pods in your cluster.
By enabling the run-once duration override on a namespace, all future run-once pods created or updated in that namespace have their activeDeadlineSeconds field set to the value specified by the Run Once Duration Override Operator.
Note
If both the run-once pod and the Run Once Duration Override Operator have their activeDeadlineSeconds value set, the lower of the two values is used.
Install the Run Once Duration Override Operator¶
Install the Run Once Duration Override Operator by using the web console to create the required namespace, install the Operator from the software catalog, and create a RunOnceDurationOverride instance.
Prerequisites
- You have access to the cluster with
cluster-adminprivileges. - You have access to the OpenShift Container Platform web console.
Procedure
-
Log in to the OpenShift Container Platform web console.
-
Create the required namespace for the Run Once Duration Override Operator.
- Navigate to Administration → Namespaces and click Create Namespace.
- Enter
openshift-run-once-duration-override-operatorin the Name field and click Create.
-
Install the Run Once Duration Override Operator.
-
Navigate to Ecosystem → Software Catalog.
-
Enter Run Once Duration Override Operator into the filter box.
-
Select the Run Once Duration Override Operator and click Install.
-
On the Install Operator page:
-
The Update channel is set to stable, which installs the latest stable release of the Run Once Duration Override Operator.
-
Select A specific namespace on the cluster.
-
Choose openshift-run-once-duration-override-operator from the dropdown menu under Installed namespace.
-
Select an Update approval strategy.
- The Automatic strategy allows Operator Lifecycle Manager (OLM) to automatically update the Operator when a new version is available.
- The Manual strategy requires a user with appropriate credentials to approve the Operator update.
-
Click Install.
-
-
-
Create a
RunOnceDurationOverrideinstance.-
From the Ecosystem → Installed Operators page, click Run Once Duration Override Operator.
-
Select the Run Once Duration Override tab and click Create RunOnceDurationOverride.
-
Edit the settings as necessary.
Under the
runOnceDurationOverridesection, you can update thespec.activeDeadlineSecondsvalue, if required. The predefined value is3600seconds, or 1 hour. -
Click Create.
-
Verification
-
Log in to the OpenShift CLI.
-
Verify all pods are created and running properly.
Enable the run-once duration override on a namespace¶
Enable the run-once duration override on a namespace by adding the runoncedurationoverrides.admission.runoncedurationoverride.openshift.io/enabled=true label to the namespace.
Prerequisites
- The Run Once Duration Override Operator is installed.
Procedure
-
Log in to the OpenShift CLI.
-
Add the label to enable the run-once duration override to your namespace:
$ oc label namespace <namespace> \ runoncedurationoverrides.admission.runoncedurationoverride.openshift.io/enabled=trueReplace <namespace> with the namespace to enable the run-once duration override on.
After you enable the run-once duration override on this namespace, future run-once pods that are created in this namespace will have their
activeDeadlineSecondsfield set to the override value from the Run Once Duration Override Operator. Existing pods in this namespace will also have theiractiveDeadlineSecondsvalue set when they are updated next.
Verification
-
Create a test run-once pod in the namespace that you enabled the run-once duration override on:
apiVersion: v1 kind: Pod metadata: name: example namespace: namespace spec: restartPolicy: Never securityContext: runAsNonRoot: true seccompProfile: type: RuntimeDefault containers: - name: busybox securityContext: allowPrivilegeEscalation: false capabilities: drop: [ALL] image: busybox:1.25 command: - /bin/sh - -ec - | while sleep 5; do date; donewhere:
metadata.namespace- Specifies your namespace.
spec.restartPolicy- Specifies the restart policy. The
restartPolicymust beNeverorOnFailureto be a run-once pod.
-
Verify that the pod has its
activeDeadlineSecondsfield set:
Update the run-once active deadline override value¶
Update the activeDeadlineSeconds field in the RunOnceDurationOverride resource to customize the override value that the operator applies to run-once pods.
Prerequisites
- You have access to the cluster with
cluster-adminprivileges. - You have installed the Run Once Duration Override Operator.
Procedure
-
Log in to the OpenShift CLI.
-
Edit the
RunOnceDurationOverrideresource: -
Update the
activeDeadlineSecondsfield:apiVersion: operator.openshift.io/v1 kind: RunOnceDurationOverride metadata: # ... spec: runOnceDurationOverride: spec: activeDeadlineSeconds: 1800 # ...where:
spec.runOnceDurationOverride.spec.activeDeadlineSeconds- Specifies the desired time limit value, in seconds.
-
Save the file to apply the changes.
Any future run-once pods created in namespaces where the run-once duration override is enabled will have their
activeDeadlineSecondsfield set to this new value. Existing run-once pods in these namespaces will receive this new value when they are updated.