Skip to content

Install the operator

Run these commands from a clone of the celld operator repository after completing prerequisites. They install one operator per cluster. Use a registry that your EKS nodes can pull from.

  1. Clone, build and publish the operator image. The development :dev image is not a published release. Choose a unique tag and registry path. The Dockerfile cross-compiles its Go binaries for the target platform; this command publishes an image index for both common EKS node architectures. Inspect the published index and copy its top-level sha256:… digest for Helm.

    Terminal window
    git clone https://github.com/ewhauser/celld-operator.git
    cd celld-operator
    docker buildx build --platform linux/amd64,linux/arm64 \
    --build-arg VERSION=YOUR_TAG \
    --tag YOUR_REGISTRY/celld-operator:YOUR_TAG --push .
    docker buildx imagetools inspect YOUR_REGISTRY/celld-operator:YOUR_TAG

    Authenticate Docker to your registry before pushing, and check that the inspection lists the platforms used by your EKS nodes. If the registry is private, create an image pull Secret in celld-system and set chart imagePullSecrets for the manager. See the chart values. The runtime is a separately pinned compatible celld fork image; stock upstream releases lack the fork’s recovery behavior. See compatibility.

  2. Install or update the CRDs. Helm does not upgrade CRDs from a chart’s crds/ directory. Apply the repository copies on every operator upgrade.

    Terminal window
    kubectl --context YOUR_CONTEXT apply -f config/crd/
  3. Install the Helm chart. The fleetNamespaces value creates a Role and RoleBinding in each named namespace. fleets must already exist. The operator uses Kubernetes credentials only; configure AWS bucket access on the runtime ServiceAccount.

    Terminal window
    helm --kube-context YOUR_CONTEXT upgrade --install celld charts/celld-operator \
    --namespace celld-system --create-namespace \
    --set image.repository=YOUR_REGISTRY/celld-operator \
    --set image.digest=sha256:YOUR_PUBLISHED_DIGEST \
    --set 'fleetNamespaces={fleets}'

    Both profiles run celld directly; the launcherImage value is deprecated and ignored. The chart’s operator ServiceAccount is celld-celld-operator for this release name and needs no AWS association.

  4. Check the rollout and namespace permissions. A healthy installation has both requested operator replicas available and a RoleBinding in fleets whose subject is celld-celld-operator in celld-system.

    Terminal window
    kubectl --context YOUR_CONTEXT -n celld-system rollout status deployment/celld-celld-operator --timeout=180s
    kubectl --context YOUR_CONTEXT -n celld-system get pods
    kubectl --context YOUR_CONTEXT -n fleets get rolebinding celld-celld-operator-fleet -o yaml
  5. Attest NetworkPolicy enforcement. Once you have independently checked that your CNI enforces policies, enable fleet provisioning:

    Terminal window
    helm --kube-context YOUR_CONTEXT upgrade celld charts/celld-operator \
    --namespace celld-system --reuse-values --set networkPolicyEnforced=true
    kubectl --context YOUR_CONTEXT -n celld-system rollout status deployment/celld-celld-operator --timeout=180s

The plain-manifest path uses config/manager/operator.yaml and config/rbac/fleet-namespace.yaml. That RoleBinding refers to celld-system/celld-operator, the plain-manifest ServiceAccount. Do not apply it unchanged as a fallback for the Helm release: edit its subject to celld-system/celld-celld-operator, or add fleets to fleetNamespaces and let Helm render the binding.

For PersistentFleet, also prepare the CSI storage prerequisites. See chart values for other options. Never use --local-test on EKS; that flag is for the disposable MinIO integration harness.

Next: create your first fleet.

Experimental software for evaluation.Capabilities and limitations· Contribute