2021-11-30 12:31:54 -07:00
####################################################################################################
2019-03-13 23:15:14 -06:00
# Create the common resources that are necessary to start the operator and the ceph cluster.
# These resources *must* be created before the operator.yaml and cluster.yaml or their variants.
2021-11-30 12:31:54 -07:00
# The samples all assume that a single operator will manage a single cluster crd in the same
# "rook-ceph" namespace.
####################################################################################################
2019-03-13 23:15:14 -06:00
2019-03-16 08:41:09 -06:00
# Namespace where the operator and other rook resources are created
2019-03-13 23:15:14 -06:00
apiVersion : v1
kind : Namespace
metadata :
2020-12-09 13:21:15 -07:00
name : rook-ceph # namespace:cluster
2019-08-26 17:42:36 -04:00
---
2021-11-30 12:31:54 -07:00
kind : ClusterRole
2020-08-14 10:59:17 +02:00
apiVersion : rbac.authorization.k8s.io/v1
2019-04-16 11:32:51 -06:00
metadata :
2021-11-30 12:31:54 -07:00
name : cephfs-csi-nodeplugin
rules :
- apiGroups : [ "" ]
resources : [ "nodes" ]
verbs : [ "get" , "list" , "update" ]
- apiGroups : [ "" ]
resources : [ "namespaces" ]
verbs : [ "get" , "list" ]
- apiGroups : [ "" ]
resources : [ "persistentvolumes" ]
verbs : [ "get" , "list" , "watch" , "update" ]
- apiGroups : [ "storage.k8s.io" ]
resources : [ "volumeattachments" ]
verbs : [ "get" , "list" , "watch" , "update" ]
- apiGroups : [ "" ]
resources : [ "configmaps" ]
verbs : [ "get" , "list" ]
---
kind : ClusterRole
apiVersion : rbac.authorization.k8s.io/v1
metadata :
name : cephfs-external-provisioner-runner
rules :
- apiGroups : [ "" ]
resources : [ "secrets" ]
verbs : [ "get" , "list" ]
- apiGroups : [ "" ]
resources : [ "persistentvolumes" ]
verbs : [ "get" , "list" , "watch" , "create" , "delete" , "update" , "patch" ]
- apiGroups : [ "" ]
resources : [ "persistentvolumeclaims" ]
verbs : [ "get" , "list" , "watch" , "update" ]
- apiGroups : [ "storage.k8s.io" ]
resources : [ "storageclasses" ]
verbs : [ "get" , "list" , "watch" ]
- apiGroups : [ "" ]
resources : [ "events" ]
verbs : [ "list" , "watch" , "create" , "update" , "patch" ]
- apiGroups : [ "snapshot.storage.k8s.io" ]
resources : [ "volumesnapshots" ]
verbs : [ "get" , "list" , "watch" , "update" ]
- apiGroups : [ "snapshot.storage.k8s.io" ]
resources : [ "volumesnapshotcontents" ]
verbs : [ "create" , "get" , "list" , "watch" , "update" , "delete" ]
- apiGroups : [ "snapshot.storage.k8s.io" ]
resources : [ "volumesnapshotclasses" ]
verbs : [ "get" , "list" , "watch" ]
- apiGroups : [ "snapshot.storage.k8s.io" ]
resources : [ "volumesnapshotcontents/status" ]
verbs : [ "update" ]
- apiGroups : [ "snapshot.storage.k8s.io" ]
resources : [ "volumesnapshots/status" ]
verbs : [ "update" ]
- apiGroups : [ "storage.k8s.io" ]
resources : [ "volumeattachments" ]
verbs : [ "get" , "list" , "watch" , "update" , "patch" ]
- apiGroups : [ "storage.k8s.io" ]
resources : [ "volumeattachments/status" ]
verbs : [ "patch" ]
- apiGroups : [ "" ]
resources : [ "nodes" ]
verbs : [ "get" , "list" , "watch" ]
- apiGroups : [ "" ]
resources : [ "persistentvolumeclaims/status" ]
verbs : [ "update" , "patch" ]
---
apiVersion : rbac.authorization.k8s.io/v1
kind : ClusterRole
metadata :
name : "psp:rook"
rules :
- apiGroups :
- policy
resources :
- podsecuritypolicies
resourceNames :
- 00 -rook-privileged
verbs :
- use
---
kind : ClusterRole
apiVersion : rbac.authorization.k8s.io/v1
metadata :
name : rbd-csi-nodeplugin
rules :
- apiGroups : [ "" ]
resources : [ "secrets" ]
verbs : [ "get" , "list" ]
- apiGroups : [ "" ]
resources : [ "nodes" ]
verbs : [ "get" , "list" , "update" ]
- apiGroups : [ "" ]
resources : [ "namespaces" ]
verbs : [ "get" , "list" ]
- apiGroups : [ "" ]
resources : [ "persistentvolumes" ]
verbs : [ "get" , "list" , "watch" , "update" ]
- apiGroups : [ "storage.k8s.io" ]
resources : [ "volumeattachments" ]
verbs : [ "get" , "list" , "watch" , "update" ]
- apiGroups : [ "" ]
resources : [ "configmaps" ]
verbs : [ "get" , "list" ]
- apiGroups : [ "" ]
resources : [ "serviceaccounts" ]
verbs : [ "get" ]
---
kind : ClusterRole
apiVersion : rbac.authorization.k8s.io/v1
metadata :
name : rbd-external-provisioner-runner
rules :
- apiGroups : [ "" ]
resources : [ "secrets" ]
verbs : [ "get" , "list" , "watch" ]
- apiGroups : [ "" ]
resources : [ "persistentvolumes" ]
verbs : [ "get" , "list" , "watch" , "create" , "delete" , "update" , "patch" ]
- apiGroups : [ "" ]
resources : [ "persistentvolumeclaims" ]
verbs : [ "get" , "list" , "watch" , "update" ]
- apiGroups : [ "storage.k8s.io" ]
resources : [ "volumeattachments" ]
verbs : [ "get" , "list" , "watch" , "update" , "patch" ]
- apiGroups : [ "storage.k8s.io" ]
resources : [ "volumeattachments/status" ]
verbs : [ "patch" ]
- apiGroups : [ "" ]
resources : [ "nodes" ]
verbs : [ "get" , "list" , "watch" ]
- apiGroups : [ "storage.k8s.io" ]
resources : [ "storageclasses" ]
verbs : [ "get" , "list" , "watch" ]
- apiGroups : [ "" ]
resources : [ "events" ]
verbs : [ "list" , "watch" , "create" , "update" , "patch" ]
- apiGroups : [ "snapshot.storage.k8s.io" ]
resources : [ "volumesnapshots" ]
verbs : [ "get" , "list" , "watch" , "update" ]
- apiGroups : [ "snapshot.storage.k8s.io" ]
resources : [ "volumesnapshotcontents" ]
verbs : [ "create" , "get" , "list" , "watch" , "update" , "delete" ]
- apiGroups : [ "snapshot.storage.k8s.io" ]
resources : [ "volumesnapshotclasses" ]
verbs : [ "get" , "list" , "watch" ]
- apiGroups : [ "snapshot.storage.k8s.io" ]
resources : [ "volumesnapshotcontents/status" ]
verbs : [ "update" ]
- apiGroups : [ "snapshot.storage.k8s.io" ]
resources : [ "volumesnapshots/status" ]
verbs : [ "update" ]
- apiGroups : [ "" ]
resources : [ "persistentvolumeclaims/status" ]
verbs : [ "update" , "patch" ]
- apiGroups : [ "" ]
resources : [ "configmaps" ]
verbs : [ "get" ]
- apiGroups : [ "replication.storage.openshift.io" ]
resources : [ "volumereplications" , "volumereplicationclasses" ]
verbs : [ "create" , "delete" , "get" , "list" , "patch" , "update" , "watch" ]
- apiGroups : [ "replication.storage.openshift.io" ]
resources : [ "volumereplications/finalizers" ]
verbs : [ "update" ]
- apiGroups : [ "replication.storage.openshift.io" ]
resources : [ "volumereplications/status" ]
verbs : [ "get" , "patch" , "update" ]
- apiGroups : [ "replication.storage.openshift.io" ]
resources : [ "volumereplicationclasses/status" ]
verbs : [ "get" ]
- apiGroups : [ "" ]
resources : [ "serviceaccounts" ]
verbs : [ "get" ]
2019-08-26 17:42:36 -04:00
---
2020-07-29 16:54:38 -06:00
# The cluster role for managing all the cluster-specific resources in a namespace
2020-08-14 10:59:17 +02:00
apiVersion : rbac.authorization.k8s.io/v1
2019-04-12 21:39:08 +05:30
kind : ClusterRole
metadata :
2020-07-29 16:54:38 -06:00
name : rook-ceph-cluster-mgmt
2019-04-12 21:39:08 +05:30
labels :
operator : rook
storage-backend : ceph
2019-03-13 23:15:14 -06:00
rules :
2021-03-08 12:18:21 +05:30
- apiGroups :
- ""
- apps
- extensions
resources :
- secrets
- pods
- pods/log
- services
- configmaps
- deployments
- daemonsets
verbs :
- get
- list
- watch
- patch
- create
- update
- delete
2019-03-16 09:14:45 -06:00
---
2019-03-13 23:15:14 -06:00
# The cluster role for managing the Rook CRDs
2020-08-14 10:59:17 +02:00
apiVersion : rbac.authorization.k8s.io/v1
2021-09-21 15:59:58 -06:00
# Rook watches for its CRDs in all namespaces, so this should be a cluster-scoped role unless the
# operator config `ROOK_CURRENT_NAMESPACE_ONLY=true`.
2019-03-13 23:15:14 -06:00
kind : ClusterRole
metadata :
name : rook-ceph-global
labels :
operator : rook
storage-backend : ceph
rules :
2021-03-08 12:18:21 +05:30
- apiGroups :
- ""
resources :
# Pod access is needed for fencing
- pods
# Node access is needed for determining nodes where mons should run
- nodes
- nodes/proxy
- services
2021-09-21 15:59:58 -06:00
# Rook watches secrets which it uses to configure access to external resources.
# e.g., external Ceph cluster; TLS certificates for the admission controller or object store
- secrets
# Rook watches for changes to the rook-operator-config configmap
- configmaps
2021-03-08 12:18:21 +05:30
verbs :
- get
- list
- watch
- apiGroups :
- ""
resources :
- events
# PVs and PVCs are managed by the Rook provisioner
- persistentvolumes
- persistentvolumeclaims
- endpoints
verbs :
- get
- list
- watch
- patch
- create
- update
- delete
- apiGroups :
- storage.k8s.io
resources :
- storageclasses
verbs :
- get
- list
- watch
- apiGroups :
- batch
resources :
- jobs
- cronjobs
verbs :
- get
- list
- watch
- create
- update
- delete
- apiGroups :
- ceph.rook.io
resources :
- "*"
verbs :
- "*"
- apiGroups :
- rook.io
resources :
- "*"
verbs :
- "*"
- apiGroups :
- policy
- apps
- extensions
resources :
# This is for the clusterdisruption controller
- poddisruptionbudgets
# This is for both clusterdisruption and nodedrain controllers
- deployments
- replicasets
verbs :
- "*"
- apiGroups :
- healthchecking.openshift.io
resources :
- machinedisruptionbudgets
verbs :
- get
- list
- watch
- create
- update
- delete
- apiGroups :
- machine.openshift.io
resources :
- machines
verbs :
- get
- list
- watch
- create
- update
- delete
- apiGroups :
- storage.k8s.io
resources :
- csidrivers
verbs :
- create
- delete
- get
- update
- apiGroups :
- k8s.cni.cncf.io
resources :
- network-attachment-definitions
verbs :
- get
2019-03-13 23:15:14 -06:00
---
# Aspects of ceph-mgr that require cluster-wide access
kind : ClusterRole
2020-08-14 10:59:17 +02:00
apiVersion : rbac.authorization.k8s.io/v1
2019-03-13 23:15:14 -06:00
metadata :
name : rook-ceph-mgr-cluster
labels :
operator : rook
storage-backend : ceph
rules :
2021-03-08 12:18:21 +05:30
- apiGroups :
- ""
resources :
- configmaps
- nodes
- nodes/proxy
2021-07-20 16:15:31 -04:00
- persistentvolumes
2021-03-08 12:18:21 +05:30
verbs :
- get
- list
- watch
- apiGroups :
- ""
resources :
- events
verbs :
- create
- patch
- list
- get
- watch
2021-07-20 16:15:31 -04:00
- apiGroups :
- storage.k8s.io
resources :
- storageclasses
verbs :
- get
- list
- watch
2019-03-13 23:15:14 -06:00
---
2021-11-30 12:31:54 -07:00
# Aspects of ceph-mgr that require access to the system namespace
kind : ClusterRole
apiVersion : rbac.authorization.k8s.io/v1
metadata :
name : rook-ceph-mgr-system
rules :
- apiGroups :
- ""
resources :
- configmaps
verbs :
- get
- list
- watch
---
2021-09-21 15:59:58 -06:00
# Used for provisioning ObjectBuckets (OBs) in response to ObjectBucketClaims (OBCs).
# Note: Rook runs a copy of the lib-bucket-provisioner's OBC controller.
# OBCs can be created in any Kubernetes namespace, so this must be a cluster-scoped role.
2019-04-16 11:32:51 -06:00
kind : ClusterRole
2020-08-14 10:59:17 +02:00
apiVersion : rbac.authorization.k8s.io/v1
2019-04-16 11:32:51 -06:00
metadata :
name : rook-ceph-object-bucket
labels :
operator : rook
storage-backend : ceph
rules :
2021-09-21 15:59:58 -06:00
- apiGroups : [ "" ]
resources : [ "secrets" , "configmaps" ]
2021-03-08 12:18:21 +05:30
verbs :
2021-09-21 15:59:58 -06:00
# OBC controller creates secrets and configmaps containing information for users about how to
# connect to object buckets. It deletes them when an OBC is deleted.
2021-03-08 12:18:21 +05:30
- get
2021-09-21 15:59:58 -06:00
- create
- update
- delete
- apiGroups : [ "storage.k8s.io" ]
resources : [ "storageclasses" ]
verbs :
# OBC controller gets parameters from the OBC's storageclass
# Rook gets additional parameters from the OBC's storageclass
- get
- apiGroups : [ "objectbucket.io" ]
resources : [ "objectbucketclaims" ]
verbs :
# OBC controller needs to list/watch OBCs and get latest version of a reconciled OBC
2021-03-08 12:18:21 +05:30
- list
- watch
2021-09-21 15:59:58 -06:00
- get
# Ideally, update should not be needed, but the OBC controller updates the OBC with bucket
# information outside of the status subresource
- update
# OBC controller does not delete OBCs; users do this
- apiGroups : [ "objectbucket.io" ]
resources : [ "objectbuckets" ]
2021-03-08 12:18:21 +05:30
verbs :
2021-09-21 15:59:58 -06:00
# OBC controller needs to list/watch OBs and get latest version of a reconciled OB
- list
- watch
- get
# OBC controller creates an OB when an OBC's bucket has been provisioned by Ceph, updates them
# when an OBC is updated, and deletes them when the OBC is de-provisioned.
- create
- update
- delete
- apiGroups : [ "objectbucket.io" ]
resources : [ "objectbucketclaims/status" , "objectbuckets/status" ]
verbs :
# OBC controller updates OBC and OB statuses
- update
2019-08-26 17:42:36 -04:00
---
2021-11-30 12:31:54 -07:00
kind : ClusterRole
2020-08-14 10:59:17 +02:00
apiVersion : rbac.authorization.k8s.io/v1
2021-11-30 12:31:54 -07:00
metadata :
name : rook-ceph-osd
rules :
- apiGroups :
- ""
resources :
- nodes
verbs :
- get
- list
---
apiVersion : rbac.authorization.k8s.io/v1
kind : ClusterRole
2019-03-13 23:15:14 -06:00
metadata :
name : rook-ceph-system
labels :
operator : rook
storage-backend : ceph
2021-11-30 12:31:54 -07:00
rules :
# Most resources are represented by a string representation of their name, such as "pods", just as it appears in the URL for the relevant API endpoint.
# However, some Kubernetes APIs involve a "subresource", such as the logs for a pod. [...]
# To represent this in an RBAC role, use a slash to delimit the resource and subresource.
# https://kubernetes.io/docs/reference/access-authn-authz/rbac/#referring-to-resources
- apiGroups : [ "" ]
resources : [ "pods" , "pods/log" ]
verbs : [ "get" , "list" ]
- apiGroups : [ "" ]
resources : [ "pods/exec" ]
verbs : [ "create" ]
2021-07-06 23:27:15 +02:00
---
kind : ClusterRoleBinding
apiVersion : rbac.authorization.k8s.io/v1
metadata :
2021-11-30 12:31:54 -07:00
name : cephfs-csi-nodeplugin
2021-07-06 23:27:15 +02:00
subjects :
- kind : ServiceAccount
2021-11-30 12:31:54 -07:00
name : rook-csi-cephfs-plugin-sa
2021-07-06 23:27:15 +02:00
namespace : rook-ceph # namespace:operator
2021-11-30 12:31:54 -07:00
roleRef :
kind : ClusterRole
name : cephfs-csi-nodeplugin
apiGroup : rbac.authorization.k8s.io
---
kind : ClusterRoleBinding
apiVersion : rbac.authorization.k8s.io/v1
metadata :
name : cephfs-csi-provisioner-role
subjects :
- kind : ServiceAccount
name : rook-csi-cephfs-provisioner-sa
namespace : rook-ceph # namespace:operator
roleRef :
kind : ClusterRole
name : cephfs-external-provisioner-runner
apiGroup : rbac.authorization.k8s.io
---
kind : ClusterRoleBinding
apiVersion : rbac.authorization.k8s.io/v1
metadata :
name : rbd-csi-nodeplugin
subjects :
- kind : ServiceAccount
name : rook-csi-rbd-plugin-sa
namespace : rook-ceph # namespace:operator
roleRef :
kind : ClusterRole
name : rbd-csi-nodeplugin
apiGroup : rbac.authorization.k8s.io
---
kind : ClusterRoleBinding
apiVersion : rbac.authorization.k8s.io/v1
metadata :
name : rbd-csi-provisioner-role
subjects :
- kind : ServiceAccount
name : rook-csi-rbd-provisioner-sa
namespace : rook-ceph # namespace:operator
roleRef :
kind : ClusterRole
name : rbd-external-provisioner-runner
apiGroup : rbac.authorization.k8s.io
2019-03-13 23:15:14 -06:00
---
# Grant the rook system daemons cluster-wide access to manage the Rook CRDs, PVCs, and storage classes
kind : ClusterRoleBinding
2020-08-14 10:59:17 +02:00
apiVersion : rbac.authorization.k8s.io/v1
2019-03-13 23:15:14 -06:00
metadata :
name : rook-ceph-global
labels :
operator : rook
storage-backend : ceph
roleRef :
apiGroup : rbac.authorization.k8s.io
kind : ClusterRole
name : rook-ceph-global
subjects :
2021-03-08 12:18:21 +05:30
- kind : ServiceAccount
name : rook-ceph-system
namespace : rook-ceph # namespace:operator
2019-03-13 23:15:14 -06:00
---
# Allow the ceph mgr to access cluster-wide resources necessary for the mgr modules
kind : ClusterRoleBinding
2020-08-14 10:59:17 +02:00
apiVersion : rbac.authorization.k8s.io/v1
2019-03-13 23:15:14 -06:00
metadata :
name : rook-ceph-mgr-cluster
roleRef :
apiGroup : rbac.authorization.k8s.io
kind : ClusterRole
name : rook-ceph-mgr-cluster
subjects :
2021-03-08 12:18:21 +05:30
- kind : ServiceAccount
name : rook-ceph-mgr
namespace : rook-ceph # namespace:cluster
2021-11-30 12:31:54 -07:00
---
# Give Rook-Ceph Operator permissions to provision ObjectBuckets in response to ObjectBucketClaims.
kind : ClusterRoleBinding
apiVersion : rbac.authorization.k8s.io/v1
metadata :
name : rook-ceph-object-bucket
roleRef :
apiGroup : rbac.authorization.k8s.io
kind : ClusterRole
name : rook-ceph-object-bucket
subjects :
- kind : ServiceAccount
name : rook-ceph-system
namespace : rook-ceph # namespace:operator
2019-09-05 16:39:41 +05:30
---
2019-09-18 11:14:30 +02:00
# Allow the ceph osd to access cluster-wide resources necessary for determining their topology location
2019-09-05 16:39:41 +05:30
kind : ClusterRoleBinding
2020-08-14 10:59:17 +02:00
apiVersion : rbac.authorization.k8s.io/v1
2019-09-05 16:39:41 +05:30
metadata :
name : rook-ceph-osd
roleRef :
apiGroup : rbac.authorization.k8s.io
kind : ClusterRole
name : rook-ceph-osd
subjects :
2021-03-08 12:18:21 +05:30
- kind : ServiceAccount
name : rook-ceph-osd
namespace : rook-ceph # namespace:cluster
2019-08-26 17:42:36 -04:00
---
2021-11-30 12:31:54 -07:00
kind : ClusterRoleBinding
2020-08-14 10:59:17 +02:00
apiVersion : rbac.authorization.k8s.io/v1
2019-06-27 13:58:04 -06:00
metadata :
2021-11-30 12:31:54 -07:00
name : rook-ceph-system
labels :
operator : rook
storage-backend : ceph
2019-06-27 13:58:04 -06:00
roleRef :
apiGroup : rbac.authorization.k8s.io
2021-11-30 12:31:54 -07:00
kind : ClusterRole
name : rook-ceph-system
2019-06-27 13:58:04 -06:00
subjects :
2021-03-08 12:18:21 +05:30
- kind : ServiceAccount
2021-11-30 12:31:54 -07:00
name : rook-ceph-system
namespace : rook-ceph # namespace:operator
---
apiVersion : rbac.authorization.k8s.io/v1
kind : ClusterRoleBinding
metadata :
name : rook-ceph-system-psp
roleRef :
apiGroup : rbac.authorization.k8s.io
kind : ClusterRole
name : "psp:rook"
subjects :
- kind : ServiceAccount
name : rook-ceph-system
namespace : rook-ceph # namespace:operator
---
apiVersion : rbac.authorization.k8s.io/v1
kind : ClusterRoleBinding
metadata :
name : rook-csi-cephfs-plugin-sa-psp
roleRef :
apiGroup : rbac.authorization.k8s.io
kind : ClusterRole
name : "psp:rook"
subjects :
- kind : ServiceAccount
name : rook-csi-cephfs-plugin-sa
namespace : rook-ceph # namespace:operator
---
apiVersion : rbac.authorization.k8s.io/v1
kind : ClusterRoleBinding
metadata :
name : rook-csi-cephfs-provisioner-sa-psp
roleRef :
apiGroup : rbac.authorization.k8s.io
kind : ClusterRole
name : "psp:rook"
subjects :
- kind : ServiceAccount
name : rook-csi-cephfs-provisioner-sa
namespace : rook-ceph # namespace:operator
---
apiVersion : rbac.authorization.k8s.io/v1
kind : ClusterRoleBinding
metadata :
name : rook-csi-rbd-plugin-sa-psp
roleRef :
apiGroup : rbac.authorization.k8s.io
kind : ClusterRole
name : "psp:rook"
subjects :
- kind : ServiceAccount
name : rook-csi-rbd-plugin-sa
namespace : rook-ceph # namespace:operator
---
apiVersion : rbac.authorization.k8s.io/v1
kind : ClusterRoleBinding
metadata :
name : rook-csi-rbd-provisioner-sa-psp
roleRef :
apiGroup : rbac.authorization.k8s.io
kind : ClusterRole
name : "psp:rook"
subjects :
- kind : ServiceAccount
name : rook-csi-rbd-provisioner-sa
namespace : rook-ceph # namespace:operator
2019-08-26 17:42:36 -04:00
---
2019-05-28 17:20:08 -06:00
apiVersion : policy/v1beta1
kind : PodSecurityPolicy
metadata :
2020-04-24 10:13:25 -06:00
# Note: Kubernetes matches PSPs to deployments alphabetically. In some environments, this PSP may
# need to be renamed with a value that will match before others.
name : 00 -rook-privileged
2020-04-15 16:25:45 +05:30
annotations :
2021-03-08 12:18:21 +05:30
seccomp.security.alpha.kubernetes.io/allowedProfileNames : "runtime/default"
seccomp.security.alpha.kubernetes.io/defaultProfileName : "runtime/default"
2019-05-28 17:20:08 -06:00
spec :
privileged : true
allowedCapabilities :
# required by CSI
- SYS_ADMIN
fsGroup :
rule : RunAsAny
# runAsUser, supplementalGroups - Rook needs to run some pods as root
# Ceph pods could be run as the Ceph user, but that user isn't always known ahead of time
runAsUser :
rule : RunAsAny
supplementalGroups :
rule : RunAsAny
# seLinux - seLinux context is unknown ahead of time; set if this is well-known
seLinux :
rule : RunAsAny
volumes :
# recommended minimum set
- configMap
- downwardAPI
- emptyDir
- persistentVolumeClaim
- secret
- projected
# required for Rook
- hostPath
# allowedHostPaths can be set to Rook's known host volume mount points when they are fully-known
# allowedHostPaths:
2019-08-02 14:52:04 +02:00
# - pathPrefix: "/run/udev" # for OSD prep
# readOnly: false
# - pathPrefix: "/dev" # for OSD prep
# readOnly: false
# - pathPrefix: "/var/lib/rook" # or whatever the dataDirHostPath value is set to
# readOnly: false
2019-05-28 17:20:08 -06:00
# Ceph requires host IPC for setting up encrypted devices
hostIPC : true
# Ceph OSDs need to share the same PID namespace
hostPID : true
# hostNetwork can be set to 'false' if host networking isn't used
hostNetwork : true
hostPorts :
# Ceph messenger protocol v1
- min : 6789
max : 6790 # <- support old default port
# Ceph messenger protocol v2
- min : 3300
max : 3300
# Ceph RADOS ports for OSDs, MDSes
- min : 6800
max : 7300
# # Ceph dashboard port HTTP (not recommended)
# - min: 7000
# max: 7000
# Ceph dashboard port HTTPS
- min : 8443
max : 8443
# Ceph mgr Prometheus Metrics
- min : 9283
max : 9283
2019-08-26 17:42:36 -04:00
---
2019-08-22 16:27:14 -04:00
kind : Role
apiVersion : rbac.authorization.k8s.io/v1
metadata :
name : cephfs-external-provisioner-cfg
2020-12-09 13:21:15 -07:00
namespace : rook-ceph # namespace:operator
2019-08-22 16:27:14 -04:00
rules :
- apiGroups : [ "" ]
resources : [ "endpoints" ]
verbs : [ "get" , "watch" , "list" , "delete" , "update" , "create" ]
- apiGroups : [ "" ]
resources : [ "configmaps" ]
verbs : [ "get" , "list" , "create" , "delete" ]
2019-08-23 14:40:48 +05:30
- apiGroups : [ "coordination.k8s.io" ]
resources : [ "leases" ]
verbs : [ "get" , "watch" , "list" , "delete" , "update" , "create" ]
2019-08-22 16:27:14 -04:00
---
kind : Role
apiVersion : rbac.authorization.k8s.io/v1
metadata :
name : rbd-external-provisioner-cfg
2020-12-09 13:21:15 -07:00
namespace : rook-ceph # namespace:operator
2019-08-22 16:27:14 -04:00
rules :
- apiGroups : [ "" ]
resources : [ "endpoints" ]
verbs : [ "get" , "watch" , "list" , "delete" , "update" , "create" ]
- apiGroups : [ "" ]
resources : [ "configmaps" ]
2020-11-02 11:15:34 +05:30
verbs : [ "get" , "list" , "watch" , "create" , "delete" , "update" ]
2019-08-23 14:40:48 +05:30
- apiGroups : [ "coordination.k8s.io" ]
resources : [ "leases" ]
verbs : [ "get" , "watch" , "list" , "delete" , "update" , "create" ]
2019-08-22 16:27:14 -04:00
---
2021-11-30 12:31:54 -07:00
kind : Role
2019-08-22 16:27:14 -04:00
apiVersion : rbac.authorization.k8s.io/v1
metadata :
2021-11-30 12:31:54 -07:00
name : rook-ceph-cmd-reporter
namespace : rook-ceph # namespace:cluster
2019-08-01 16:31:50 -06:00
rules :
2021-11-30 12:31:54 -07:00
- apiGroups :
- ""
resources :
- pods
- configmaps
verbs :
- get
- list
- watch
- create
- update
- delete
---
# Aspects of ceph-mgr that operate within the cluster's namespace
kind : Role
apiVersion : rbac.authorization.k8s.io/v1
metadata :
name : rook-ceph-mgr
namespace : rook-ceph # namespace:cluster
rules :
- apiGroups :
- ""
resources :
- pods
- services
- pods/log
verbs :
- get
- list
- watch
- create
- update
- delete
- apiGroups :
- batch
resources :
- jobs
verbs :
- get
- list
- watch
- create
- update
- delete
- apiGroups :
- ceph.rook.io
resources :
- "*"
verbs :
- "*"
- apiGroups :
- apps
resources :
- deployments/scale
- deployments
verbs :
- patch
- delete
- apiGroups :
- ""
resources :
- persistentvolumeclaims
verbs :
- delete
---
kind : Role
apiVersion : rbac.authorization.k8s.io/v1
metadata :
name : rook-ceph-osd
namespace : rook-ceph # namespace:cluster
rules :
# this is needed for rook's "key-management" CLI to fetch the vault token from the secret when
# validating the connection details
2019-08-01 16:31:50 -06:00
- apiGroups : [ "" ]
resources : [ "secrets" ]
2021-11-30 12:31:54 -07:00
verbs : [ "get" ]
2019-08-01 16:31:50 -06:00
- apiGroups : [ "" ]
resources : [ "configmaps" ]
2021-11-30 12:31:54 -07:00
verbs : [ "get" , "list" , "watch" , "create" , "update" , "delete" ]
- apiGroups : [ "ceph.rook.io" ]
resources : [ "cephclusters" , "cephclusters/finalizers" ]
verbs : [ "get" , "list" , "create" , "update" , "delete" ]
2021-07-19 17:09:35 +02:00
---
# Aspects of ceph osd purge job that require access to the operator/cluster namespace
kind : Role
apiVersion : rbac.authorization.k8s.io/v1
metadata :
name : rook-ceph-purge-osd
2021-10-19 12:06:42 -06:00
namespace : rook-ceph # namespace:cluster
2021-07-19 17:09:35 +02:00
rules :
- apiGroups : [ "" ]
resources : [ "configmaps" ]
verbs : [ "get" ]
- apiGroups : [ "apps" ]
resources : [ "deployments" ]
verbs : [ "get" , "delete" ]
- apiGroups : [ "batch" ]
resources : [ "jobs" ]
verbs : [ "get" , "list" , "delete" ]
- apiGroups : [ "" ]
resources : [ "persistentvolumeclaims" ]
2021-09-23 18:36:46 +02:00
verbs : [ "get" , "update" , "delete" ]
2021-07-19 17:09:35 +02:00
---
2021-11-30 12:31:54 -07:00
# The role for the operator to manage resources in its own namespace
apiVersion : rbac.authorization.k8s.io/v1
kind : Role
metadata :
name : rook-ceph-system
namespace : rook-ceph # namespace:operator
labels :
operator : rook
storage-backend : ceph
rules :
- apiGroups :
- ""
resources :
- pods
- configmaps
- services
verbs :
- get
- list
- watch
- patch
- create
- update
- delete
- apiGroups :
- apps
- extensions
resources :
- daemonsets
- statefulsets
- deployments
verbs :
- get
- list
- watch
- create
- update
- delete
- apiGroups :
- batch
resources :
- cronjobs
verbs :
- delete
---
kind : RoleBinding
apiVersion : rbac.authorization.k8s.io/v1
metadata :
name : cephfs-csi-provisioner-role-cfg
namespace : rook-ceph # namespace:operator
subjects :
- kind : ServiceAccount
name : rook-csi-cephfs-provisioner-sa
namespace : rook-ceph # namespace:operator
roleRef :
kind : Role
name : cephfs-external-provisioner-cfg
apiGroup : rbac.authorization.k8s.io
---
kind : RoleBinding
apiVersion : rbac.authorization.k8s.io/v1
metadata :
name : rbd-csi-provisioner-role-cfg
namespace : rook-ceph # namespace:operator
subjects :
- kind : ServiceAccount
name : rook-csi-rbd-provisioner-sa
namespace : rook-ceph # namespace:operator
roleRef :
kind : Role
name : rbd-external-provisioner-cfg
apiGroup : rbac.authorization.k8s.io
---
# Allow the operator to create resources in this cluster's namespace
kind : RoleBinding
apiVersion : rbac.authorization.k8s.io/v1
metadata :
name : rook-ceph-cluster-mgmt
namespace : rook-ceph # namespace:cluster
roleRef :
apiGroup : rbac.authorization.k8s.io
kind : ClusterRole
name : rook-ceph-cluster-mgmt
subjects :
- kind : ServiceAccount
name : rook-ceph-system
namespace : rook-ceph # namespace:operator
---
kind : RoleBinding
apiVersion : rbac.authorization.k8s.io/v1
metadata :
name : rook-ceph-cmd-reporter
namespace : rook-ceph # namespace:cluster
roleRef :
apiGroup : rbac.authorization.k8s.io
kind : Role
name : rook-ceph-cmd-reporter
subjects :
- kind : ServiceAccount
name : rook-ceph-cmd-reporter
namespace : rook-ceph # namespace:cluster
---
apiVersion : rbac.authorization.k8s.io/v1
kind : RoleBinding
metadata :
name : rook-ceph-cmd-reporter-psp
namespace : rook-ceph # namespace:cluster
roleRef :
apiGroup : rbac.authorization.k8s.io
kind : ClusterRole
name : psp:rook
subjects :
- kind : ServiceAccount
name : rook-ceph-cmd-reporter
namespace : rook-ceph # namespace:cluster
---
apiVersion : rbac.authorization.k8s.io/v1
kind : RoleBinding
metadata :
name : rook-ceph-default-psp
namespace : rook-ceph # namespace:cluster
roleRef :
apiGroup : rbac.authorization.k8s.io
kind : ClusterRole
name : psp:rook
subjects :
- kind : ServiceAccount
name : default
namespace : rook-ceph # namespace:cluster
---
# Allow the ceph mgr to access the cluster-specific resources necessary for the mgr modules
kind : RoleBinding
apiVersion : rbac.authorization.k8s.io/v1
metadata :
name : rook-ceph-mgr
namespace : rook-ceph # namespace:cluster
roleRef :
apiGroup : rbac.authorization.k8s.io
kind : Role
name : rook-ceph-mgr
subjects :
- kind : ServiceAccount
name : rook-ceph-mgr
namespace : rook-ceph # namespace:cluster
---
apiVersion : rbac.authorization.k8s.io/v1
kind : RoleBinding
metadata :
name : rook-ceph-mgr-psp
namespace : rook-ceph # namespace:cluster
roleRef :
apiGroup : rbac.authorization.k8s.io
kind : ClusterRole
name : psp:rook
subjects :
- kind : ServiceAccount
name : rook-ceph-mgr
namespace : rook-ceph # namespace:cluster
---
# Allow the ceph mgr to access the rook system resources necessary for the mgr modules
kind : RoleBinding
apiVersion : rbac.authorization.k8s.io/v1
metadata :
name : rook-ceph-mgr-system
namespace : rook-ceph # namespace:operator
roleRef :
apiGroup : rbac.authorization.k8s.io
kind : ClusterRole
name : rook-ceph-mgr-system
subjects :
- kind : ServiceAccount
name : rook-ceph-mgr
namespace : rook-ceph # namespace:cluster
---
# Allow the osd pods in this namespace to work with configmaps
kind : RoleBinding
apiVersion : rbac.authorization.k8s.io/v1
metadata :
name : rook-ceph-osd
namespace : rook-ceph # namespace:cluster
roleRef :
apiGroup : rbac.authorization.k8s.io
kind : Role
name : rook-ceph-osd
subjects :
- kind : ServiceAccount
name : rook-ceph-osd
namespace : rook-ceph # namespace:cluster
---
apiVersion : rbac.authorization.k8s.io/v1
kind : RoleBinding
metadata :
name : rook-ceph-osd-psp
namespace : rook-ceph # namespace:cluster
roleRef :
apiGroup : rbac.authorization.k8s.io
kind : ClusterRole
name : psp:rook
subjects :
- kind : ServiceAccount
name : rook-ceph-osd
namespace : rook-ceph # namespace:cluster
---
2021-07-19 17:09:35 +02:00
# Allow the osd purge job to run in this namespace
kind : RoleBinding
apiVersion : rbac.authorization.k8s.io/v1
metadata :
name : rook-ceph-purge-osd
2021-10-19 12:06:42 -06:00
namespace : rook-ceph # namespace:cluster
2021-07-19 17:09:35 +02:00
roleRef :
apiGroup : rbac.authorization.k8s.io
kind : Role
name : rook-ceph-purge-osd
subjects :
- kind : ServiceAccount
name : rook-ceph-purge-osd
2021-10-19 12:06:42 -06:00
namespace : rook-ceph # namespace:cluster
2021-07-19 17:09:35 +02:00
---
2021-11-30 12:31:54 -07:00
# Grant the operator, agent, and discovery agents access to resources in the namespace
kind : RoleBinding
apiVersion : rbac.authorization.k8s.io/v1
metadata :
name : rook-ceph-system
namespace : rook-ceph # namespace:operator
labels :
operator : rook
storage-backend : ceph
roleRef :
apiGroup : rbac.authorization.k8s.io
kind : Role
name : rook-ceph-system
subjects :
- kind : ServiceAccount
name : rook-ceph-system
namespace : rook-ceph # namespace:operator
---
apiVersion : v1
kind : ServiceAccount
metadata :
name : rook-ceph-cmd-reporter
namespace : rook-ceph # namespace:cluster
---
# Service account for the Ceph Mgr. Must exist and cannot be renamed.
apiVersion : v1
kind : ServiceAccount
metadata :
name : rook-ceph-mgr
namespace : rook-ceph # namespace:cluster
# imagePullSecrets:
# - name: my-registry-secret
---
apiVersion : v1
kind : ServiceAccount
metadata :
name : rook-ceph-osd
namespace : rook-ceph # namespace:cluster
# imagePullSecrets:
# - name: my-registry-secret
---
2021-07-19 17:09:35 +02:00
apiVersion : v1
kind : ServiceAccount
metadata :
name : rook-ceph-purge-osd
2021-10-19 12:06:42 -06:00
namespace : rook-ceph # namespace:cluster
2021-11-30 12:31:54 -07:00
---
# The rook system service account used by the operator, agent, and discovery pods
apiVersion : v1
kind : ServiceAccount
metadata :
name : rook-ceph-system
namespace : rook-ceph # namespace:operator
labels :
operator : rook
storage-backend : ceph
# imagePullSecrets:
# - name: my-registry-secret
---
apiVersion : v1
kind : ServiceAccount
metadata :
name : rook-csi-cephfs-plugin-sa
namespace : rook-ceph # namespace:operator
---
apiVersion : v1
kind : ServiceAccount
metadata :
name : rook-csi-cephfs-provisioner-sa
namespace : rook-ceph # namespace:operator
---
apiVersion : v1
kind : ServiceAccount
metadata :
name : rook-csi-rbd-plugin-sa
namespace : rook-ceph # namespace:operator
---
apiVersion : v1
kind : ServiceAccount
metadata :
name : rook-csi-rbd-provisioner-sa
namespace : rook-ceph # namespace:operator