Open tahonen opened 4 years ago
oc patch daemonset twistlock-defender-ds --type=merge -p '{"spec":{"template":{"spec":{"tolerations":[{"effect":"NoSchedule","key":"node-role.kubernetes.io/master","operator":"Exists"}]}}}}'
Thanks! I've made a dew changes in https://github.com/twistlock/docs/pull/160 that should take care of this.
By default defender daemonset doesn't have any node selector. You assume that it will be deployed to every node in the cluster. OpenShift 4+ uses Taints to prevent workload to be scheduled to masters.
To deploy defender to masters you need to add matching Toleration to daemonset.
This is documentation issue, if not implemented to installer script/templates.