// the find
tektoncd/operator
Kubernetes operator to manage installation, updation and uninstallation of tektoncd projects (pipeline, …)
The official operator for installing, upgrading, and removing the Tekton CI/CD stack (Pipelines, Triggers, Dashboard, Chains, Results, and several newer add-ons) on a Kubernetes or OpenShift cluster. It's for platform teams running Tekton at scale who don't want to hand-roll manifest management and upgrades across clusters.
It covers the whole Tekton ecosystem through one CRD-driven config (TektonConfig fans out to TektonPipeline, TektonTrigger, TektonChain, TektonResult, TektonPruner, etc.), so you declare intent once instead of juggling separate Helm installs per component. The installer-set pattern (TektonInstallerSet CRD) separates 'what manifests should exist' from reconciliation state, which makes upgrades and rollbacks less fragile than a naive apply-and-hope controller. It genuinely supports two different platforms (vanilla Kubernetes and OpenShift) as first-class targets with separate cmd/ entrypoints and kodata payloads rather than bolting OpenShift support on as an afterthought. CI is serious for a project this size: CodeQL, zizmor (workflow security linting), an e2e matrix, and a CII Best Practices badge that's actually earned.
The README tells you almost nothing about how the operator actually works — it's just a list of links, so you have to go spelunking in docs/TektonConfig.md and the controller source to understand the reconciliation model before you can debug anything. Kubernetes and OpenShift logic live in largely separate cmd/kubernetes and cmd/openshift trees with their own kodata directories, which means platform-specific bugs and drift are a real risk since the two paths aren't sharing much beyond Go packages. The CRD surface is large (14+ generated CRDs), so onboarding a contributor or even just tracing 'why didn't my TektonChain install' through TektonConfig -> TektonInstallerSet -> actual Chain resource takes real spelunking. It's also explicitly a Tekton-ecosystem-only operator — if you're managing a broader set of CI tooling, you're still stitching this together with other operators yourself.