# Difficulty installing ECK in a single namespace

**URL:** <https://discuss.elastic.co/t/difficulty-installing-eck-in-a-single-namespace/225891>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [March 31, 2020, 2:41pm UTC](https://discuss.elastic.co/t/difficulty-installing-eck-in-a-single-namespace/225891 "2020-03-31T14:41:28Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![data\_smith](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/data_smith/32/124122_2.png) [@data\_smith](https://discuss.elastic.co/u/data_smith)\
**Post date:** [March 31, 2020, 2:41pm UTC](https://discuss.elastic.co/t/difficulty-installing-eck-in-a-single-namespace/225891/1 "2020-03-31T14:41:28Z")

</div>

I ran the script:

```auto
     OPERATOR_NAME=myelastic-op OPERATOR_IMAGE=docker.elastic.co/eck/eck-operator:1.0.1 NAMESPACE=myns MANAGED_NAMESPACE=myns make generate-namespace | kubectl apply -f -

```

And it works up until I get this error in the pod:  
message: "unable to setup and fill webhook certificates", error="resource may not be empty"

Do I need to set something up beforehand?

---

<div class="post-metadata">

**Author:** ![data\_smith](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/data_smith/32/124122_2.png) [@data\_smith](https://discuss.elastic.co/u/data_smith)\
**Post date:** [March 31, 2020, 3:51pm UTC](https://discuss.elastic.co/t/difficulty-installing-eck-in-a-single-namespace/225891/2 "2020-03-31T15:51:11Z")

</div>

Also, I noticed the operator template for all-in-one had values for certs and services, whereas the operator template for namespace did not. Is the configuration ready for running ECK in a single namespace? We don't want to give users access other namespaces like is done with all-in-one so we would really like to get this working in a single namespace.

---

<div class="post-metadata">

**Author:** ![sebgl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sebgl/32/48702_2.png) [@sebgl](https://discuss.elastic.co/u/sebgl)\
**Post date:** [April 2, 2020, 1:19pm UTC](https://discuss.elastic.co/t/difficulty-installing-eck-in-a-single-namespace/225891/3 "2020-04-02T13:19:45Z")

</div>

@data_smith I think you should [download the official manifests](https://download.elastic.co/downloads/eck/1.0.1/all-in-one.yaml), and try to adapt them to your needs.  
The namespace sample we have in the github repository might be tricky to setup, however it gives you a pretty good idea of how you should adapt the all-in-one manifests.  
Basically, you mostly have to tweak the namespace of the `elastic-operator` StatefulSet in that yaml file, and also add the `--managed-namespaces=<your-namespace1>,<your-namespace2>` flag to the StatefulSet container args.

Let me know if that works for you.  
We want to improve this process with some extra tooling in the future, see [https://github.com/elastic/cloud-on-k8s/issues/2406](https://github.com/elastic/cloud-on-k8s/issues/2406).

---

<div class="post-metadata">

**Author:** ![pebrc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pebrc/32/101790_2.png) [@pebrc](https://discuss.elastic.co/u/pebrc)\
**Post date:** [April 2, 2020, 8:51pm UTC](https://discuss.elastic.co/t/difficulty-installing-eck-in-a-single-namespace/225891/4 "2020-04-02T20:51:05Z")

</div>

> [@data\_smith](#):
>
> message: "unable to setup and fill webhook certificates", error="resource may not be empty"

I believe this particular error indicates that ECK is running with the webhook role enabled which should not be the case when you running in single namespace mode.

I think I have a theory about what is the problem in your case though: I am assuming you checked out the ECK code locally to run this make target and that code contains already changes incompatible with the 1.0.1 image you are trying to run. Most notably we have removed the concept of operator roles and the corresponding `--operator-roles` parameter, which means the manifest you generated does not have the parameter and ECK defaults to all roles which includes the webhook role, causing your error.

You can:

- either checkout the code corresponding to the version of ECK you want to run (in your case 1.0.1) and re-generate the manifest again
- or you can manually edit the manifest you generated and add the missing roles flag. You want something like

```auto
 args: ["manager", "--namespaces", "myns", "--operator-roles", "namespace,global"]

```

---

<div class="post-metadata">

**Author:** ![data\_smith](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/data_smith/32/124122_2.png) [@data\_smith](https://discuss.elastic.co/u/data_smith)\
**Post date:** [April 3, 2020, 2:14pm UTC](https://discuss.elastic.co/t/difficulty-installing-eck-in-a-single-namespace/225891/5 "2020-04-03T14:14:03Z")

</div>

Thanks, I ended up doing that. Here's exactly what I ran:

> [@Can I disable the webhook?](https://discuss.elastic.co/t/can-i-disable-the-webhook/226113/2):
>
> It looks like you can add args: ['operator-roles','namespace,global'] in your stateful set config for the operator and that'll disable it

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 7:51am UTC](https://discuss.elastic.co/t/difficulty-installing-eck-in-a-single-namespace/225891/6 "2022-11-04T07:51:37Z")

</div>


