Note: This Operator is in the early stages of implementation and keeps changing.
The NodeObservability Operator allows you to deploy and manage NodeObservability Agent on the worker nodes. The NodeObservability agent is deployed through DaemonSets on the selected nodes.
Afterward, the profiling requests can be created to trigger different types of profiling. The profiling data will be accessible in the root filesystem of the NodeObservability Agent.
- Deploying the NodeObservability Operator
- Verifying the installation of NodeObservability Operator
- Creating the NodeObservability CR
The node-observability-operator once installed will create a daemonset on all or only labeled nodes, once the cluster-admin creates and deploys a CRD for nodeobservability. After ensuring all agent pods are running on the desired nodes the cluster-admin can then create a node-observability-run CRD, this will then call the API end points of all agents and trigger either a profiling or scripting execution, the profiling data/ scripting artifacts will be stored in the agent container using hostPath for later retrieval
NodeObservability Operator can be deployed using one of the following procedures.
You can install the NodeObservability Operator by building and pushing the Operator image into a registry.
- To build and push the Operator image into a registry, run the following commands:
# set the envar CONTAINER_ENGINE to the preffered container manager tool (default is podman) export IMG=${REGISTRY}/${REPOSITORY}/node-observability-operator:${VERSION} make container-build container-push
- To deploy the NodeObservability Operator, run the following command:
To specify the custom image for the NodeObservability Agent, patch the deployment of the operator with the following command:
make deployoc set env deployment/node-observability-operator --containers=manager RELATED_IMAGE_AGENT=${MY_IMAGE_AGENT} -n node-observability-operator
- The previous step deploys the conversion webhook, which requires the TLS verification on the webhook server's side. The
manifests deployed through the
make deploycommand do not contain a valid certificate and key. You must provision a valid certificate and key through other tools.
If you run on OpenShift, you can use a convenience script,hack/add-serving-cert.shto enable the service serving certificate feature.
Run thehack/add-serving-cert.shscript with the following inputs:Note: you may need to wait for the retry of the volume mount in the operator's PODhack/add-serving-cert.sh --crd "nodeobservabilities.nodeobservability.olm.openshift.io nodeobservabilitymachineconfigs.nodeobservability.olm.openshift.io" \ --service node-observability-operator-webhook-service --secret webhook-server-cert --namespace node-observability-operator
Note: It is recommended to use podman as a container engine.
NodeObservability Operator can be installed by building and pushing the custom OLM bundle index image.
-
Build and push the Operator image to the registry:
export IMG=${REGISTRY}/${REPOSITORY}/node-observability-operator:${VERSION} make container-build container-push
-
Build and push the bundle image to the registry:
export BUNDLE_IMG=${REGISTRY}/${REPOSITORY}/node-observability-operator-bundle:${VERSION} make bundle-build bundle-push
-
Build and push the index image to the registry:
export INDEX_IMG=${REGISTRY}/${REPOSITORY}/node-observability-operator-bundle-index:${VERSION} make index-image-build index-image-push
-
(Optional) If the image is private, then link the registry secret to the pod of the
node-observability-operatorcreated in theopenshift-marketplacenamespace:a. Create a secret with authentication details of your image registry (you have to be logged into the registry):
oc -n openshift-marketplace create secret generic nodeobs-olm-secret --type=kubernetes.io/dockercfg --from-file=.dockercfg=${XDG_RUNTIME_DIR}/containers/auth.jsonb. Link the secret to the
defaultservice account:oc -n openshift-marketplace secrets link default nodeobs-olm-secret --for=pull
-
Create the
CatalogSourceobject:cat <<EOF | oc apply -f - apiVersion: operators.coreos.com/v1alpha1 kind: CatalogSource metadata: name: node-observability-operator namespace: openshift-marketplace spec: sourceType: grpc image: ${INDEX_IMG} EOF -
Install the operator from the command line client or from the webUI:
From the CLI
-
Create the Operator namespace:
oc create namespace node-observability-operator
-
Create the
OperatorGroupobject to scope the Operator tonode-observability-operatornamespace:cat <<EOF | oc apply -f - apiVersion: operators.coreos.com/v1 kind: OperatorGroup metadata: name: node-observability-operator namespace: node-observability-operator EOF -
Create the
Subscriptionobject:cat <<EOF | oc apply -f - apiVersion: operators.coreos.com/v1alpha1 kind: Subscription metadata: name: node-observability-operator namespace: node-observability-operator spec: channel: alpha name: node-observability-operator source: node-observability-operator sourceNamespace: openshift-marketplace EOFIf you want to specify the agent image of your choice, use the following subscription:
cat <<EOF | oc apply -f - apiVersion: operators.coreos.com/v1alpha1 kind: Subscription metadata: name: node-observability-operator namespace: node-observability-operator spec: channel: alpha name: node-observability-operator source: node-observability-operator sourceNamespace: openshift-marketplace env: config: env: - name: RELATED_IMAGE_AGENT value: ${MY_IMAGE_AGENT} EOF
From the webUI
- Log in to the OpenShift Container Platform web console.
- Navigate to Operators → OperatorHub.
- Type Node Observability Operator into the filter box and select it.
- Click Install.
- On the Install Operator page, select a specific namespace on the cluster. Select node-observability-operator from the drop-down menu.
- Once finished, the Node Observability Operator will be listed in the Installed Operators section of the web console.
Run the following commands to verify that the Node Observability Operator has been installed:
oc -n node-observability-operator get subscription -o yaml
oc -n node-observability-operator get installplan -o yaml
oc -n node-observability-operator get deployment/node-observability-operatorRun the following command to create an instance of NodeObservability:
oc apply -f config/samples/nodeobservability_v1alpha2_nodeobservability-all.yaml