OpenShift installation
Notes for installing on OpenShift
OpenShift installs follow the Helm or manifest path with these differences:
- Security context: the image runs as uid 1000 and works under the
restricted-v2SCC. If the project enforces arbitrary uids, setpodSecurityContext.runAsUserto a uid in the project's range and keepfsGroupequal to it; the application only needs a writable data volume. - Routes: disable the chart Ingress (
ingress.enabled: false) and create a Route to thetestingopsservice, TLS termination edge or reencrypt. The Route host must equalapp.publicUrl. - Image registry: create the pull secret and link it to the default service account:
oc secrets link default testingops-registry --for=pull. - Storage: use a StorageClass backed by ODF/Ceph or the cloud block storage;
hostPathclasses are not supported.
Everything else — secrets, values, first login, upgrade — is identical to the Helm guide.