Allowed Pod disruptions
You can configure the allowed Pod disruptions as described in Allowed Pod disruptions.
What the operator creates depends on the workload kind of the role.
DaemonSet
No PodDisruptionBudget is created.
Setting podDisruptionBudget.enabled: true is rejected as a misconfiguration and the OpaCluster is not reconciled.
A configured maxUnavailable is ignored and the operator logs a warning.
kubectl drain skips DaemonSet Pods, a budget is never consulted during a node drain.
Moreover, PodDisruptionBudgets over DaemonSets can never be evaluated: DaemonSet does not implement the scale subresource.
Therefore the budget stays at disruptionsAllowed: 0 with a SyncFailed condition and refuses every direct eviction.
Because the role Service routes node-locally in this mode, products on a drained node cannot reach OPA on another node. Drain nodes together with the products that query OPA on them.
Deployment
The operator creates one PodDisruptionBudget per role, allowing one Pod to be unavailable at a time by default:
spec:
servers:
roleConfig:
podDisruptionBudget:
enabled: true (1)
maxUnavailable: 1 (2)
| 1 | Defaults to true for a Deployment. Set it to false to create no budget. |
| 2 | Defaults to 1. Raise it to allow more Pods to be unavailable at once. |
Keep maxUnavailable at 1 unless you have measured that OPA tolerates more.
Products query OPA on every request, budgets that drain too many Pods at once turn a node rotation into a platform-wide slowdown.
A budget only helps when there is another Pod to fall back to.
With replicas set to 1, the single Pod can still be evicted.
|