From 8252066e7f1b4462600d8a08351686abf12c64cf Mon Sep 17 00:00:00 2001 From: Sebastian Bernauer Date: Wed, 5 Aug 2026 15:05:44 +0200 Subject: [PATCH] backport: Document olm-deployer and fix secret/listener-operator memory docs (#912) * Document olm-deployer and fix secret/listener-operator memory docs * Apply suggestions from code review Co-authored-by: Razvan-Daniel Mihai <84674+razvan@users.noreply.github.com> --------- Co-authored-by: Razvan-Daniel Mihai <84674+razvan@users.noreply.github.com> --- modules/ROOT/pages/kubernetes/openshift.adoc | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/modules/ROOT/pages/kubernetes/openshift.adoc b/modules/ROOT/pages/kubernetes/openshift.adoc index f5a726751..8d1c3b906 100644 --- a/modules/ROOT/pages/kubernetes/openshift.adoc +++ b/modules/ROOT/pages/kubernetes/openshift.adoc @@ -6,6 +6,10 @@ SDP operators are certified for the OpenShift platform and can be installed from IMPORTANT: OpenShift installations with FIPS mode enabled are not supported. This is because neither the SDP operators, nor the supported Apache products are FIPS-compliant. +IMPORTANT: The operators deployed with OLM might have higher memory requests (and limits) compared to our Helm charts, as we have seen typical production OpenShift clusters being larger than typical non-Openshift clusters. +The reason is that memory usage of some of our operators scales with the number of objects in your Kubernetes cluster. +However, you can fine-tune the operator memory requirements using a custom Subscription object as described below, so this note is only about the default resources! + == Customizing operator installations As described in the https://github.com/operator-framework/operator-lifecycle-manager/blob/master/doc/design/subscription-config.md[Openshift Subscription documentation{external-link-icon}^] you can configure the deployed operators. @@ -52,7 +56,12 @@ spec: value: kafka-namespace ---- -IMPORTANT: The described configuration mechanism currently does not work for secret and listener-operator due to restrictions on deploying DaemonSets. +=== secret and listener-operator + +The secret and listener operator are not deployed by OLM directly but rather by a helper tool called `olm-deployer`. This tool is needed to work around some OLM limitations that prevent it from directly installing these operators. +In this case, `olm-deployer` takes **it's own** resource requests and applies them to all containers on the `DaemonSets` of these operators.. + +This allows you to customize the resources of the DaemonSet in the same way as for the other operators - but doesn't allow individual resources for each container. == Security context constraints