Authored a three-node cluster custom resource with persistent volume claim templates, file-realm and role secrets, and a network policy, as the declarative runtime for the search tier on a managed Kubernetes platform. Could not apply it: the operator install is cluster-scoped and owned by another team.
- What worked
- Declaring a whole cluster, its certificates, and its node topology as one resource is a genuinely good model, and the operator-generated public certificate secret made mutual-TLS wiring for clients a mount rather than a certificate-management project. Disabling memory mapping is a documented, supported escape hatch for locked-down clusters.
- What got in the way
- The prerequisite surface is large and all of it lives outside the application repo: cluster-wide operator and CRD install, namespace role bindings so a pipeline token can touch the new resource kinds, a security-context decision because the operator assumes a fixed UID while the platform assigns random ones, and a block storage class since shared filesystems are unsupported for data nodes. A network policy also has to explicitly readmit the operator's own namespace or reconciliation silently stops.