Skip to content

OSDOCS-19153 [NETOBSERV] 1.12 Technology Preview Network Observability Operator Day 0 - #111382

Open
gwynnemonahan wants to merge 5 commits into
openshift:mainfrom
gwynnemonahan:OSDOCS-19153
Open

OSDOCS-19153 [NETOBSERV] 1.12 Technology Preview Network Observability Operator Day 0#111382
gwynnemonahan wants to merge 5 commits into
openshift:mainfrom
gwynnemonahan:OSDOCS-19153

Conversation

@gwynnemonahan

@gwynnemonahan gwynnemonahan commented May 7, 2026

Copy link
Copy Markdown
Contributor

OSDOCS-19153 [NETOBSERV] 1.12 Technology Preview Network Observability Operator Day 0

NOTES

  • Do not merge until OCP 5 has been released.
  • Add to NetObserv 2.0 rel notes. Can come Technology Preview section in 1.12 rel notes.
  • Do not merge until CORENET-6714: Enable Network Observability on Day 0 cluster-network-operator#2925 has been merged.
  • This is a work-in-progress as the information architecture continues to be worked out.
  • Use of "Network Observability Operator Day 0" is a placeholder.
  • Headers/titles are likely to change prior to formal reviews.
  • Cluster Network Operator CR updates

Version(s):
5.0+

Issue:
https://redhat.atlassian.net/browse/OSDOCS-19153

Link to docs preview:

NETWORKING

NETWORK OBSERVABILITY OPERATOR

QE review:

  • QE has approved this change.

Additional information:

  • Check with Gwynne before merging.
  • 09/10/2026: Changes since initial PR was created. Unchecked "QE" approval box.
    • PR needs fresh Dev/QE reviews
  • Might make sense to close this and open a new one so its easier to review. However, keeping this PR, and its growing comments, keeps the history of changes in the same PR.
  • 05/07/2026: Initial PR created to work through information architecture between Networking and Observiability > Network Observability

@openshift-ci openshift-ci Bot added the size/L Denotes a PR that changes 100-499 lines, ignoring generated files. label May 7, 2026
@ocpdocs-previewbot

ocpdocs-previewbot commented May 7, 2026

Copy link
Copy Markdown

🤖 Thu Sep 10 16:39:29 - Prow CI generated the docs preview:
https://111382--ocpdocs-pr.netlify.app
Complete list of updated preview URLs: artifacts/updated_preview_urls.txt

Comment thread modules/network-observability-day-0-getting-started.adoc Outdated
@openshift-ci openshift-ci Bot added size/XL Denotes a PR that changes 500-999 lines, ignoring generated files. and removed size/L Denotes a PR that changes 100-499 lines, ignoring generated files. labels May 11, 2026
Comment thread modules/network-observability-enabling-feature-gate-existing-cluster.adoc Outdated
Comment thread modules/network-observability-enabling-feature-gate.adoc Outdated
Comment thread modules/nw-operator-cr.adoc Outdated
Comment thread modules/network-observability-day-0-do-not-install.adoc Outdated
Comment thread modules/network-observability-day-0-getting-started.adoc Outdated
Comment thread modules/network-observability-day-0-getting-started.adoc Outdated
Comment thread modules/network-observability-day-0-install-and-enable.adoc Outdated
Comment thread modules/network-observability-day-0-install-and-enable.adoc Outdated
Comment thread modules/network-observability-enabling.adoc Outdated
Comment thread modules/network-observability-enabling.adoc Outdated
Comment thread modules/network-observability-day-0-architecture.adoc Outdated
Comment thread modules/network-observability-day-0-getting-started.adoc Outdated
@gwynnemonahan

Copy link
Copy Markdown
Contributor Author

Rebased 05/26/2026 PM.

@gwynnemonahan
gwynnemonahan force-pushed the OSDOCS-19153 branch 2 times, most recently from 6e900dc to ff59d9b Compare May 29, 2026 17:47
@gwynnemonahan

Copy link
Copy Markdown
Contributor Author

Rebased 05/29/2026 to capture stub page from #111600

@gwynnemonahan

Copy link
Copy Markdown
Contributor Author

Rebased 07/20/2026 AM.

@gwynnemonahan

Copy link
Copy Markdown
Contributor Author

Rebased 07/28/2026 PM.

@gwynnemonahan

Copy link
Copy Markdown
Contributor Author

Rebased 08/05/2026 PM.

@gwynnemonahan

Copy link
Copy Markdown
Contributor Author

Rebased 08/12/2026 PM.

@gwynnemonahan

Copy link
Copy Markdown
Contributor Author

/retest

@gwynnemonahan

Copy link
Copy Markdown
Contributor Author

Rebased 08/18/2026 AM.

@gwynnemonahan

Copy link
Copy Markdown
Contributor Author

Rebased 09/03/2026 AM.

@openshift-ci openshift-ci Bot removed the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Sep 3, 2026
@gwynnemonahan

Copy link
Copy Markdown
Contributor Author

Rebase 09/03/2026 PM.

@gwynnemonahan

Copy link
Copy Markdown
Contributor Author

Rebased 09/10/2026 AM.

@openshift-ci openshift-ci Bot added size/XL Denotes a PR that changes 500-999 lines, ignoring generated files. and removed size/L Denotes a PR that changes 100-499 lines, ignoring generated files. labels Sep 10, 2026
@openshift-ci

openshift-ci Bot commented Sep 10, 2026

Copy link
Copy Markdown

@gwynnemonahan: all tests passed!

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

installationPolicy:
|Controls whether the Network Observability Operator is automatically installed during cluster creation. This field is available only when the `NetworkObservabilityInstall` feature gate is enabled.

When set to `InstallAndEnable`, the Cluster Network Operator installs the Network Observability Operator and creates a default FlowCollector during cluster creation. The CNO monitors the installation and reinstalls the operator if it is removed.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If you set to InstallAndEnable, it will also install on SNO clusters. That's the difference between explicitly setting this value and omitting the value.

It also does not reinstall. (Note: This was a more recent change.)


You can use Network observability to complete the following tasks:

* Monitor network traffic flows between pods, services, and external endpoints.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If you are referring to general Network Observability, then this is okay. This feature configures Network Observability with no Loki so there are no flows. Maybe just remove the word "flow"?


The following cluster types do not enable network observability by default:

* {sno-caps} clusters, due to resource constraints.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It will enable NetworkObservability if the installation policy is set to "InstallAndEnable".

The following cluster types do not enable network observability by default:

* {sno-caps} clusters, due to resource constraints.
* Clusters where you disabled network observability in the installation configuration.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

To be explicit, this occurs when the installation policy is set to "NoAction".

Network topology visualization:: Explore visual representations of network traffic flows between namespaces, workloads, and nodes.

Metrics and dashboards:: Access Prometheus metrics and Grafana dashboards that track network performance indicators including throughput, packet drops, and connection counts.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This might be the right place to say if you want flows and features that require flows, you need to configure a LokiStack.

The automatic network observability installation occurs during cluster creation and upgrade. The Cluster Network Operator (CNO) installs the Network Observability Operator and creates a default `FlowCollector` custom resource (CR), and then sets the `NetworkObservabilityDeployed` condition in the Network CR status.

After successful deployment with the default policy, the CNO does not monitor or manage the Network Observability Operator. If you delete the Network Observability Operator or the `FlowCollector` resource, they are not automatically reinstalled.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You could put an asterisk here and then let the user know there is a way to effectively "reset it back to the factory default" behavior. To do this, enter oc edit network.operator cluster --subresource=status and remove the status entry associated with 'type: NetworkObservabilityDeployed'. Now it looks like a brand new cluster.


After successful deployment with the default policy, the CNO does not monitor or manage the Network Observability Operator. If you delete the Network Observability Operator or the `FlowCollector` resource, they are not automatically reinstalled.

If you set `installationPolicy` to `InstallAndEnable` in your `install-config.yaml` file, the CNO continues to monitor the installation and reinstalls the Network Observability Operator if you remove it. The CNO does not manage the `FlowCollector` resource because it is managed by the Network Observability Operator.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It doesn't reinstall anymore. The previous statement "If you delete the Network Observability Operator or the FlowCollector resource, they are not automatically reinstalled." is the correct one.

For production deployments, Red Hat recommends using the standard `postinstallation` method to install the Network Observability Operator.
====

On {product-title} 4.22 clusters with the `NetworkObservabilityInstall` feature gate enabled, the Network Observability Operator and its dependencies are automatically installed and configured during cluster creation. This provides immediate access to network traffic monitoring capabilities through the {product-title} web console.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Change "4.22" to "5.0"

* *Agent type*: eBPF with DNS tracking enabled
* *Sampling rate*: 400 (collects 1 in every 400 flows)
* *Deployment model*: Service
* *Loki storage*: Disabled (flows are not persisted)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

"None" rather than "Disabled"

[id="deployment-lifecycle_{context}"]
== Deployment lifecycle

The automatic network observability installation occurs during cluster creation and upgrade. The Cluster Network Operator (CNO) installs the Network Observability Operator and creates a default `FlowCollector` custom resource (CR), and then sets the `NetworkObservabilityDeployed` condition in the Network CR status.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It only occurs in OCP 5+ when the cluster is created or in OCP 4.22 upgrade to 5.0. To be clear, it doesn't occur on every upgrade.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

branch/enterprise-4.22 branch/enterprise-5.0 size/XL Denotes a PR that changes 500-999 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants