2019-03-13 23:15:14 -06:00
#################################################################################################################
# Create the rook operator and necessary security context constraints for running
# Rook in an OpenShift cluster.
# For example, to create the rook-ceph cluster:
2020-11-12 15:19:01 -07:00
# oc create -f crds.yaml -f common.yaml -f operator-openshift.yaml
# oc create -f cluster.yaml
2019-03-13 23:15:14 -06:00
#################################################################################################################
2019-08-01 14:25:10 -06:00
# scc for the Rook and Ceph daemons
2019-03-13 23:15:14 -06:00
kind : SecurityContextConstraints
apiVersion : security.openshift.io/v1
metadata :
name : rook-ceph
allowPrivilegedContainer : true
allowHostDirVolumePlugin : true
2021-10-28 20:27:52 +05:30
allowHostPID : false
2021-09-29 21:39:39 +05:30
# set to true if running rook with host networking enabled
allowHostNetwork : false
# set to true if running rook with the provider as host
allowHostPorts : false
2019-03-13 23:15:14 -06:00
priority :
2021-11-24 11:22:47 +01:00
allowedCapabilities : [ "MKNOD" ]
2019-03-13 23:15:14 -06:00
allowHostIPC : true
readOnlyRootFilesystem : false
requiredDropCapabilities : []
defaultAddCapabilities : []
runAsUser :
type : RunAsAny
seLinuxContext :
type : MustRunAs
fsGroup :
type : MustRunAs
supplementalGroups :
type : RunAsAny
volumes :
- configMap
- downwardAPI
- emptyDir
- hostPath
- persistentVolumeClaim
- projected
- secret
users :
# A user needs to be added for each rook service account.
# This assumes running in the default sample "rook-ceph" namespace.
# If other namespaces or service accounts are configured, they need to be updated here.
2020-12-09 13:21:15 -07:00
- system:serviceaccount:rook-ceph:rook-ceph-system # serviceaccount:namespace:operator
2021-04-08 11:44:23 -06:00
- system:serviceaccount:rook-ceph:default # serviceaccount:namespace:cluster
2020-12-09 13:21:15 -07:00
- system:serviceaccount:rook-ceph:rook-ceph-mgr # serviceaccount:namespace:cluster
- system:serviceaccount:rook-ceph:rook-ceph-osd # serviceaccount:namespace:cluster
2019-03-13 23:15:14 -06:00
---
2019-08-01 14:25:10 -06:00
# scc for the CSI driver
2019-08-01 16:31:50 -06:00
kind : SecurityContextConstraints
apiVersion : security.openshift.io/v1
metadata :
name : rook-ceph-csi
2021-09-17 18:59:01 +02:00
# To allow running privilegedContainers
2019-08-01 16:31:50 -06:00
allowPrivilegedContainer : true
2021-09-17 18:59:01 +02:00
# CSI daemonset pod needs hostnetworking
2019-08-01 16:31:50 -06:00
allowHostNetwork : true
2021-09-17 18:59:01 +02:00
# This need to be set to true as we use HostPath
2019-08-01 16:31:50 -06:00
allowHostDirVolumePlugin : true
priority :
2021-09-17 18:59:01 +02:00
# SYS_ADMIN is needed for rbd to execture rbd map command
allowedCapabilities : [ "SYS_ADMIN" ]
# Needed as we run liveness container on daemonset pods
2019-08-01 16:31:50 -06:00
allowHostPorts : true
2021-09-17 18:59:01 +02:00
# Needed as we are setting this in RBD plugin pod
2019-08-01 16:31:50 -06:00
allowHostPID : true
2021-09-17 18:59:01 +02:00
# Required for encryption
2019-08-01 16:31:50 -06:00
allowHostIPC : true
2021-09-17 18:59:01 +02:00
# Set to false as we write to RootFilesystem inside csi containers
2019-08-01 16:31:50 -06:00
readOnlyRootFilesystem : false
runAsUser :
type : RunAsAny
seLinuxContext :
type : RunAsAny
fsGroup :
type : RunAsAny
supplementalGroups :
type : RunAsAny
2021-09-17 18:59:01 +02:00
# The type of volumes which are mounted to csi pods
volumes :
- configMap
- projected
- emptyDir
- hostPath
2019-08-01 16:31:50 -06:00
users :
# A user needs to be added for each rook service account.
# This assumes running in the default sample "rook-ceph" namespace.
# If other namespaces or service accounts are configured, they need to be updated here.
2020-12-09 13:21:15 -07:00
- system:serviceaccount:rook-ceph:rook-csi-rbd-plugin-sa # serviceaccount:namespace:operator
- system:serviceaccount:rook-ceph:rook-csi-rbd-provisioner-sa # serviceaccount:namespace:operator
- system:serviceaccount:rook-ceph:rook-csi-cephfs-plugin-sa # serviceaccount:namespace:operator
- system:serviceaccount:rook-ceph:rook-csi-cephfs-provisioner-sa # serviceaccount:namespace:operator
2019-08-01 16:31:50 -06:00
---
2020-02-12 14:07:03 +05:30
# Rook Ceph Operator Config
# Use this ConfigMap to override operator configurations
2020-03-20 17:07:23 +05:30
# Precedence will be given to this config in case Env Var also exists for the same
2020-02-12 14:07:03 +05:30
#
kind : ConfigMap
apiVersion : v1
metadata :
name : rook-ceph-operator-config
# should be in the namespace of the operator
2020-12-09 13:21:15 -07:00
namespace : rook-ceph # namespace:operator
2020-02-12 14:07:03 +05:30
data :
2021-09-23 10:56:42 -06:00
# The logging level for the operator: ERROR | WARNING | INFO | DEBUG
2021-05-24 18:56:18 +05:30
ROOK_LOG_LEVEL : "INFO"
2020-03-20 17:07:23 +05:30
# Enable the CSI driver.
# To run the non-default version of the CSI driver, see the override-able image properties in operator.yaml
ROOK_CSI_ENABLE_CEPHFS : "true"
# Enable the default version of the CSI RBD driver. To start another version of the CSI driver, see image properties below.
ROOK_CSI_ENABLE_RBD : "true"
2021-03-10 11:30:50 +05:30
ROOK_CSI_ENABLE_GRPC_METRICS : "false"
2020-03-20 17:07:23 +05:30
2021-03-15 18:01:12 +05:30
# Set to true to enable host networking for CSI CephFS and RBD nodeplugins. This may be necessary
# in some network configurations where the SDN does not provide access to an external cluster or
# there is significant drop in read/write performance.
# CSI_ENABLE_HOST_NETWORK: "true"
2020-03-20 17:07:23 +05:30
# Set logging level for csi containers.
# Supported values from 0 to 5. 0 for general useful logs, 5 for trace level verbosity.
# CSI_LOG_LEVEL: "0"
2020-04-03 11:08:19 -06:00
2021-09-16 11:04:34 +05:30
# Set replicas for csi provisioner deployment.
CSI_PROVISIONER_REPLICAS : "2"
2020-12-04 15:23:34 +05:30
# OMAP generator generates the omap mapping between the PV name and the RBD image
# which helps CSI to identify the rbd images for CSI operations.
# CSI_ENABLE_OMAP_GENERATOR need to be enabled when we are using rbd mirroring feature.
# By default OMAP generator is disabled and when enabled it willbe deployed as a
# sidecar with CSI provisioner pod, to enable set it to true.
# CSI_ENABLE_OMAP_GENERATOR: "true"
2021-01-21 15:29:55 +05:30
# set to false to disable deployment of snapshotter container in CephFS provisioner pod.
CSI_ENABLE_CEPHFS_SNAPSHOTTER : "true"
# set to false to disable deployment of snapshotter container in RBD provisioner pod.
CSI_ENABLE_RBD_SNAPSHOTTER : "true"
2020-03-20 17:07:23 +05:30
# Enable Ceph Kernel clients on kernel < 4.17 which support quotas for Cephfs
# If you disable the kernel client, your application may be disrupted during upgrade.
2021-09-22 12:39:16 -06:00
# See the upgrade guide: https://rook.io/docs/rook/latest/ceph-upgrade.html
2020-03-20 17:07:23 +05:30
CSI_FORCE_CEPHFS_KERNEL_CLIENT : "true"
2020-04-03 11:08:19 -06:00
2020-12-23 11:59:11 +05:30
# (Optional) policy for modifying a volume's ownership or permissions when the RBD PVC is being mounted.
# supported values are documented at https://kubernetes-csi.github.io/docs/support-fsgroup.html
CSI_RBD_FSGROUPPOLICY : "ReadWriteOnceWithFSType"
# (Optional) policy for modifying a volume's ownership or permissions when the CephFS PVC is being mounted.
# supported values are documented at https://kubernetes-csi.github.io/docs/support-fsgroup.html
2021-08-03 14:53:29 +05:30
CSI_CEPHFS_FSGROUPPOLICY : "None"
2020-12-23 11:59:11 +05:30
2020-03-20 17:07:23 +05:30
# (Optional) Allow starting unsupported ceph-csi image
ROOK_CSI_ALLOW_UNSUPPORTED_VERSION : "false"
2021-08-17 09:50:54 +05:30
# (Optional) control the host mount of /etc/selinux for csi plugin pods.
CSI_PLUGIN_ENABLE_SELINUX_HOST_MOUNT : "false"
2020-03-20 17:07:23 +05:30
# The default version of CSI supported by Rook will be started. To change the version
# of the CSI driver to something other than what is officially supported, change
# these images to the desired release of the CSI driver.
2021-07-29 10:51:09 +05:30
# ROOK_CSI_CEPH_IMAGE: "quay.io/cephcsi/cephcsi:v3.4.0"
2021-09-24 16:27:15 +05:30
# ROOK_CSI_REGISTRAR_IMAGE: "k8s.gcr.io/sig-storage/csi-node-driver-registrar:v2.3.0"
# ROOK_CSI_RESIZER_IMAGE: "k8s.gcr.io/sig-storage/csi-resizer:v1.3.0"
# ROOK_CSI_PROVISIONER_IMAGE: "k8s.gcr.io/sig-storage/csi-provisioner:v3.0.0"
# ROOK_CSI_SNAPSHOTTER_IMAGE: "k8s.gcr.io/sig-storage/csi-snapshotter:v4.2.0"
# ROOK_CSI_ATTACHER_IMAGE: "k8s.gcr.io/sig-storage/csi-attacher:v3.3.0"
2020-04-03 11:08:19 -06:00
2020-05-05 12:23:36 +05:30
# (Optional) set user created priorityclassName for csi plugin pods.
2020-05-09 08:46:21 +05:30
# CSI_PLUGIN_PRIORITY_CLASSNAME: "system-node-critical"
2020-05-05 12:23:36 +05:30
2020-05-05 13:25:48 +05:30
# (Optional) set user created priorityclassName for csi provisioner pods.
2020-05-09 08:46:21 +05:30
# CSI_PROVISIONER_PRIORITY_CLASSNAME: "system-cluster-critical"
2020-05-05 13:25:48 +05:30
2020-03-20 17:07:23 +05:30
# CSI CephFS plugin daemonset update strategy, supported values are OnDelete and RollingUpdate.
# Default value is RollingUpdate.
# CSI_CEPHFS_PLUGIN_UPDATE_STRATEGY: "OnDelete"
# CSI RBD plugin daemonset update strategy, supported values are OnDelete and RollingUpdate.
# Default value is RollingUpdate.
# CSI_RBD_PLUGIN_UPDATE_STRATEGY: "OnDelete"
2020-04-03 11:08:19 -06:00
2020-03-20 17:07:23 +05:30
# kubelet directory path, if kubelet configured to use other than /var/lib/kubelet path.
# ROOK_CSI_KUBELET_DIR_PATH: "/var/lib/kubelet"
2020-04-03 11:08:19 -06:00
2020-11-11 00:05:21 +01:00
# Labels to add to the CSI CephFS Deployments and DaemonSets Pods.
# ROOK_CSI_CEPHFS_POD_LABELS: "key1=value1,key2=value2"
# Labels to add to the CSI RBD Deployments and DaemonSets Pods.
# ROOK_CSI_RBD_POD_LABELS: "key1=value1,key2=value2"
2021-05-17 11:25:49 +05:30
# (Optional) CephCSI provisioner NodeAffinity(applied to both CephFS and RBD provisioner).
2020-02-12 14:07:03 +05:30
# CSI_PROVISIONER_NODE_AFFINITY: "role=storage-node; storage=rook, ceph"
2021-05-17 11:25:49 +05:30
# (Optional) CephCSI provisioner tolerations list(applied to both CephFS and RBD provisioner).
# Put here list of taints you want to tolerate in YAML format.
2020-03-20 17:07:23 +05:30
# CSI provisioner would be best to start on the same nodes as other ceph daemons.
2020-02-12 14:07:03 +05:30
# CSI_PROVISIONER_TOLERATIONS: |
# - effect: NoSchedule
# key: node-role.kubernetes.io/controlplane
# operator: Exists
# - effect: NoExecute
# key: node-role.kubernetes.io/etcd
# operator: Exists
2021-05-17 11:25:49 +05:30
# (Optional) CephCSI plugin NodeAffinity(applied to both CephFS and RBD plugin).
2020-02-12 14:07:03 +05:30
# CSI_PLUGIN_NODE_AFFINITY: "role=storage-node; storage=rook, ceph"
2021-05-17 11:25:49 +05:30
# (Optional) CephCSI plugin tolerations list(applied to both CephFS and RBD plugin).
# Put here list of taints you want to tolerate in YAML format.
2020-03-20 17:07:23 +05:30
# CSI plugins need to be started on all the nodes where the clients need to mount the storage.
2020-02-12 14:07:03 +05:30
# CSI_PLUGIN_TOLERATIONS: |
# - effect: NoSchedule
# key: node-role.kubernetes.io/controlplane
# operator: Exists
# - effect: NoExecute
# key: node-role.kubernetes.io/etcd
# operator: Exists
2020-04-03 11:08:19 -06:00
2021-05-17 11:25:49 +05:30
# (Optional) CephCSI RBD provisioner NodeAffinity(if specified, overrides CSI_PROVISIONER_NODE_AFFINITY).
# CSI_RBD_PROVISIONER_NODE_AFFINITY: "role=rbd-node"
# (Optional) CephCSI RBD provisioner tolerations list(if specified, overrides CSI_PROVISIONER_TOLERATIONS).
# Put here list of taints you want to tolerate in YAML format.
# CSI provisioner would be best to start on the same nodes as other ceph daemons.
# CSI_RBD_PROVISIONER_TOLERATIONS: |
# - key: node.rook.io/rbd
# operator: Exists
# (Optional) CephCSI RBD plugin NodeAffinity(if specified, overrides CSI_PLUGIN_NODE_AFFINITY).
# CSI_RBD_PLUGIN_NODE_AFFINITY: "role=rbd-node"
# (Optional) CephCSI RBD plugin tolerations list(if specified, overrides CSI_PLUGIN_TOLERATIONS).
# Put here list of taints you want to tolerate in YAML format.
# CSI plugins need to be started on all the nodes where the clients need to mount the storage.
# CSI_RBD_PLUGIN_TOLERATIONS: |
# - key: node.rook.io/rbd
# operator: Exists
# (Optional) CephCSI CephFS provisioner NodeAffinity(if specified, overrides CSI_PROVISIONER_NODE_AFFINITY).
# CSI_CEPHFS_PROVISIONER_NODE_AFFINITY: "role=cephfs-node"
# (Optional) CephCSI CephFS provisioner tolerations list(if specified, overrides CSI_PROVISIONER_TOLERATIONS).
# Put here list of taints you want to tolerate in YAML format.
# CSI provisioner would be best to start on the same nodes as other ceph daemons.
# CSI_CEPHFS_PROVISIONER_TOLERATIONS: |
# - key: node.rook.io/cephfs
# operator: Exists
# (Optional) CephCSI CephFS plugin NodeAffinity(if specified, overrides CSI_PLUGIN_NODE_AFFINITY).
# CSI_CEPHFS_PLUGIN_NODE_AFFINITY: "role=cephfs-node"
# (Optional) CephCSI CephFS plugin tolerations list(if specified, overrides CSI_PLUGIN_TOLERATIONS).
# Put here list of taints you want to tolerate in YAML format.
# CSI plugins need to be started on all the nodes where the clients need to mount the storage.
# CSI_CEPHFS_PLUGIN_TOLERATIONS: |
# - key: node.rook.io/cephfs
# operator: Exists
2020-04-28 14:55:52 +05:30
# (Optional) CEPH CSI RBD provisioner resource requirement list, Put here list of resource
# requests and limits you want to apply for provisioner pod
# CSI_RBD_PROVISIONER_RESOURCE: |
# - name : csi-provisioner
# resource:
# requests:
# memory: 128Mi
# cpu: 100m
# limits:
# memory: 256Mi
# cpu: 200m
# - name : csi-resizer
# resource:
# requests:
# memory: 128Mi
# cpu: 100m
# limits:
# memory: 256Mi
# cpu: 200m
# - name : csi-attacher
# resource:
# requests:
# memory: 128Mi
# cpu: 100m
# limits:
# memory: 256Mi
# cpu: 200m
# - name : csi-snapshotter
# resource:
# requests:
# memory: 128Mi
# cpu: 100m
# limits:
# memory: 256Mi
# cpu: 200m
# - name : csi-rbdplugin
# resource:
# requests:
# memory: 512Mi
# cpu: 250m
# limits:
# memory: 1Gi
# cpu: 500m
# - name : liveness-prometheus
# resource:
# requests:
# memory: 128Mi
# cpu: 50m
# limits:
# memory: 256Mi
# cpu: 100m
# (Optional) CEPH CSI RBD plugin resource requirement list, Put here list of resource
# requests and limits you want to apply for plugin pod
# CSI_RBD_PLUGIN_RESOURCE: |
# - name : driver-registrar
# resource:
# requests:
# memory: 128Mi
# cpu: 50m
# limits:
# memory: 256Mi
# cpu: 100m
# - name : csi-rbdplugin
# resource:
# requests:
# memory: 512Mi
# cpu: 250m
# limits:
# memory: 1Gi
# cpu: 500m
# - name : liveness-prometheus
# resource:
# requests:
# memory: 128Mi
# cpu: 50m
# limits:
# memory: 256Mi
# cpu: 100m
# (Optional) CEPH CSI CephFS provisioner resource requirement list, Put here list of resource
# requests and limits you want to apply for provisioner pod
# CSI_CEPHFS_PROVISIONER_RESOURCE: |
# - name : csi-provisioner
# resource:
# requests:
# memory: 128Mi
# cpu: 100m
# limits:
# memory: 256Mi
# cpu: 200m
# - name : csi-resizer
# resource:
# requests:
# memory: 128Mi
# cpu: 100m
# limits:
# memory: 256Mi
# cpu: 200m
# - name : csi-attacher
# resource:
# requests:
# memory: 128Mi
# cpu: 100m
# limits:
# memory: 256Mi
# cpu: 200m
# - name : csi-cephfsplugin
# resource:
# requests:
# memory: 512Mi
# cpu: 250m
# limits:
# memory: 1Gi
# cpu: 500m
# - name : liveness-prometheus
# resource:
# requests:
# memory: 128Mi
# cpu: 50m
# limits:
# memory: 256Mi
# cpu: 100m
# (Optional) CEPH CSI CephFS plugin resource requirement list, Put here list of resource
# requests and limits you want to apply for plugin pod
# CSI_CEPHFS_PLUGIN_RESOURCE: |
# - name : driver-registrar
# resource:
# requests:
# memory: 128Mi
# cpu: 50m
# limits:
# memory: 256Mi
# cpu: 100m
# - name : csi-cephfsplugin
# resource:
# requests:
# memory: 512Mi
# cpu: 250m
# limits:
# memory: 1Gi
# cpu: 500m
# - name : liveness-prometheus
# resource:
# requests:
# memory: 128Mi
# cpu: 50m
# limits:
# memory: 256Mi
# cpu: 100m
2020-03-20 17:07:23 +05:30
# Configure CSI Ceph FS grpc and liveness metrics port
# CSI_CEPHFS_GRPC_METRICS_PORT: "9091"
# CSI_CEPHFS_LIVENESS_METRICS_PORT: "9081"
# Configure CSI RBD grpc and liveness metrics port
# CSI_RBD_GRPC_METRICS_PORT: "9090"
# CSI_RBD_LIVENESS_METRICS_PORT: "9080"
2020-05-12 11:18:32 +02:00
# Whether the OBC provisioner should watch on the operator namespace or not, if not the namespace of the cluster will be used
ROOK_OBC_WATCH_OPERATOR_NAMESPACE : "true"
2020-10-22 23:10:00 +00:00
2021-03-11 14:36:09 -07:00
# Whether to start the discovery daemon to watch for raw storage devices on nodes in the cluster.
# This daemon does not need to run if you are only going to create your OSDs based on StorageClassDeviceSets with PVCs.
ROOK_ENABLE_DISCOVERY_DAEMON : "false"
2021-09-27 15:50:11 -06:00
# Enable the volume replication controller
# Before enabling, ensure the Volume Replication CRDs are created.
# See https://rook.io/docs/rook/latest/ceph-csi-drivers.html#rbd-mirroring
2021-03-15 13:22:43 +05:30
CSI_ENABLE_VOLUME_REPLICATION : "false"
2021-02-22 10:19:21 +00:00
# The timeout value (in seconds) of Ceph commands. It should be >= 1. If this variable is not set or is an invalid value, it's default to 15.
ROOK_CEPH_COMMANDS_TIMEOUT_SECONDS : "15"
2021-03-15 13:22:43 +05:30
# CSI_VOLUME_REPLICATION_IMAGE: "quay.io/csiaddons/volumereplication-operator:v0.1.0"
2020-02-12 14:07:03 +05:30
---
2019-03-13 23:15:14 -06:00
# The deployment for the rook operator
2019-03-13 17:48:41 +01:00
# OLM: BEGIN OPERATOR DEPLOYMENT
2019-03-13 23:15:14 -06:00
apiVersion : apps/v1
kind : Deployment
metadata :
name : rook-ceph-operator
2020-12-09 13:21:15 -07:00
namespace : rook-ceph # namespace:operator
2019-03-13 23:15:14 -06:00
labels :
operator : rook
storage-backend : ceph
spec :
selector :
matchLabels :
app : rook-ceph-operator
replicas : 1
template :
metadata :
labels :
app : rook-ceph-operator
spec :
serviceAccountName : rook-ceph-system
containers :
2021-03-08 12:18:21 +05:30
- name : rook-ceph-operator
image : rook/ceph:master
args : [ "ceph" , "operator" ]
2021-11-05 16:16:27 +01:00
securityContext :
runAsNonRoot : true
runAsUser : 2016
runAsGroup : 2016
2021-03-08 12:18:21 +05:30
volumeMounts :
- mountPath : /var/lib/rook
name : rook-config
- mountPath : /etc/ceph
name : default-config-dir
2021-08-05 14:09:17 +02:00
- mountPath : /etc/webhook
name : webhook-cert
ports :
- containerPort : 9443
name : https-webhook
protocol : TCP
2021-03-08 12:18:21 +05:30
env :
- name : ROOK_CURRENT_NAMESPACE_ONLY
value : "false"
# Rook Discover toleration. Will tolerate all taints with all keys.
# Choose between NoSchedule, PreferNoSchedule and NoExecute:
# - name: DISCOVER_TOLERATION
# value: "NoSchedule"
# (Optional) Rook Discover toleration key. Set this to the key of the taint you want to tolerate
# - name: DISCOVER_TOLERATION_KEY
# value: "<KeyOfTheTaintToTolerate>"
# (Optional) Rook Discover priority class name to set on the pod(s)
# - name: DISCOVER_PRIORITY_CLASS_NAME
# value: "<PriorityClassName>"
# (Optional) Discover Agent NodeAffinity.
# - name: DISCOVER_AGENT_NODE_AFFINITY
# value: "role=storage-node; storage=rook, ceph"
# (Optional) Discover Agent Pod Labels.
# - name: DISCOVER_AGENT_POD_LABELS
# value: "key1=value1,key2=value2"
2021-03-02 16:09:38 +01:00
2021-03-08 12:18:21 +05:30
# The duration between discovering devices in the rook-discover daemonset.
- name : ROOK_DISCOVER_DEVICES_INTERVAL
value : "60m"
# Whether to start pods as privileged that mount a host path, which includes the Ceph mon and osd pods.
# Set this to true if SELinux is enabled (e.g. OpenShift) to workaround the anyuid issues.
# For more details see https://github.com/rook/rook/issues/1314#issuecomment-355799641
- name : ROOK_HOSTPATH_REQUIRES_PRIVILEGED
value : "true"
# In some situations SELinux relabelling breaks (times out) on large filesystems, and doesn't work with cephfs ReadWriteMany volumes (last relabel wins).
# Disable it here if you have similar issues.
# For more details see https://github.com/rook/rook/issues/2417
- name : ROOK_ENABLE_SELINUX_RELABELING
value : "true"
# In large volumes it will take some time to chown all the files. Disable it here if you have performance issues.
# For more details see https://github.com/rook/rook/issues/2254
- name : ROOK_ENABLE_FSGROUP
value : "true"
# Disable automatic orchestration when new devices are discovered
- name : ROOK_DISABLE_DEVICE_HOTPLUG
value : "false"
# Provide customised regex as the values using comma. For eg. regex for rbd based volume, value will be like "(?i)rbd[0-9]+".
# In case of more than one regex, use comma to separate between them.
# Default regex will be "(?i)dm-[0-9]+,(?i)rbd[0-9]+,(?i)nbd[0-9]+"
# add regex expression after putting a comma to blacklist a disk
# If value is empty, the default regex will be used.
- name : DISCOVER_DAEMON_UDEV_BLACKLIST
value : "(?i)dm-[0-9]+,(?i)rbd[0-9]+,(?i)nbd[0-9]+"
2019-08-01 14:25:10 -06:00
2021-03-08 12:18:21 +05:30
# Whether to start machineDisruptionBudget and machineLabel controller to watch for the osd pods and MDBs.
- name : ROOK_ENABLE_MACHINE_DISRUPTION_BUDGET
value : "false"
2019-09-06 12:50:34 -06:00
2021-03-08 12:18:21 +05:30
# Time to wait until the node controller will move Rook pods to other
# nodes after detecting an unreachable node.
# Pods affected by this setting are:
# mgr, rbd, mds, rgw, nfs, PVC based mons and osds, and ceph toolbox
# The value used in this variable replaces the default value of 300 secs
# added automatically by k8s as Toleration for
# <node.kubernetes.io/unreachable>
# The total amount of time to reschedule Rook pods in healthy nodes
# before detecting a <not ready node> condition will be the sum of:
# --> node-monitor-grace-period: 40 seconds (k8s kube-controller-manager flag)
# --> ROOK_UNREACHABLE_NODE_TOLERATION_SECONDS: 5 seconds
- name : ROOK_UNREACHABLE_NODE_TOLERATION_SECONDS
value : "5"
2019-11-19 12:10:24 +01:00
2021-03-08 12:18:21 +05:30
# The name of the node to pass with the downward API
- name : NODE_NAME
valueFrom :
fieldRef :
fieldPath : spec.nodeName
# The pod name to pass with the downward API
- name : POD_NAME
valueFrom :
fieldRef :
fieldPath : metadata.name
# The pod namespace to pass with the downward API
- name : POD_NAMESPACE
valueFrom :
fieldRef :
fieldPath : metadata.namespace
2020-06-16 13:55:47 +05:30
2021-06-18 09:24:58 -06:00
# Recommended resource requests and limits, if desired
#resources:
# limits:
# cpu: 500m
# memory: 256Mi
# requests:
# cpu: 100m
# memory: 128Mi
2021-03-08 12:18:21 +05:30
# Uncomment it to run lib bucket provisioner in multithreaded mode
#- name: LIB_BUCKET_PROVISIONER_THREADS
# value: "5"
2020-06-16 13:55:47 +05:30
2019-03-13 23:15:14 -06:00
volumes :
2021-03-08 12:18:21 +05:30
- name : rook-config
emptyDir : {}
- name : default-config-dir
emptyDir : {}
2021-08-05 14:09:17 +02:00
- name : webhook-cert
emptyDir : {}
2019-08-01 16:31:50 -06:00
# OLM: END OPERATOR DEPLOYMENT