OpenShift
The OpenShift install path is experimental. It currently requires running sandbox pods under the privileged SCC and installing the gateway with TLS disabled. Use only for evaluation on a private network.
OpenShift’s Security Context Constraints reject the chart’s default pod security settings. Installing on OpenShift requires precreating the namespace, granting the privileged SCC to the sandbox service account, and overriding a few chart values so the cluster admission controller can assign UIDs and FS groups itself.
OpenShell installs sandbox nftables rules as individual commands. On OpenShift nodes where optional conntrack or packet log expressions are unavailable, those optional rules can fail without rolling back the required proxy bypass reject rules.
Prerequisites
- OpenShift 4.x cluster with
occonfigured - Helm 3.x
- Agent Sandbox controller and CRDs installed
Install
Create the namespace
Pre-create the namespace so the SCC binding can be applied before the chart installs:
Connect to the gateway
The gateway is now running over plaintext HTTP. Connect with oc port-forward:
Register the gateway with the CLI:
Production: expose externally with a real certificate
The steps above run the gateway over plaintext HTTP for quick evaluation. For a real deployment, cert-manager can issue the gateway’s server certificate from a real Issuer or ClusterIssuer (for example, an ACME issuer), and an OpenShift Route with TLS passthrough exposes it externally while the gateway keeps terminating its own TLS and mTLS.
Install cert-manager and configure a working ClusterIssuer first — see
Managing Certificates for the
certManager.serverIssuerRef details. Configure an OIDC provider as described
in Access Control — remote gateways authenticate
CLI users via OIDC, not mTLS, so the gateway must know the OIDC issuer URL.
Install the chart with:
Register the gateway with the CLI over OIDC. Remote gateways authenticate CLI users via OIDC, not mTLS — see Access Control:
Next Steps
- For more on certificate provisioning modes, refer to Managing Certificates.
- To expose the gateway externally through the Kubernetes Gateway API instead of a Route, refer to Ingress.
- To configure OIDC authentication, refer to Access Control.