forked from rook/rook
port 7000 for the luminous dashboard and 8443 for mimic and above
Signed-off-by: travisn <tnielsen@redhat.com>
This commit is contained in:
@@ -14,7 +14,7 @@ and more. Rook makes it simple to enable the dashboard.
|
||||
|
||||
## Enable the Dashboard
|
||||
|
||||
The [dashboard](http://docs.ceph.com/docs/luminous/mgr/dashboard/) can be enabled with settings in the cluster CRD. The cluster CRD must have the dashboard `enabled` setting set to `true`.
|
||||
The [dashboard](http://docs.ceph.com/docs/mimic/mgr/dashboard/) can be enabled with settings in the cluster CRD. The cluster CRD must have the dashboard `enabled` setting set to `true`.
|
||||
This is the default setting in the example manifests.
|
||||
```yaml
|
||||
spec:
|
||||
@@ -22,19 +22,23 @@ This is the default setting in the example manifests.
|
||||
enabled: true
|
||||
```
|
||||
|
||||
The Rook operator will enable the ceph-mgr dashboard module to listen on the default port 8443.
|
||||
A K8s service will also be created to expose that port inside the cluster.
|
||||
The Rook operator will enable the ceph-mgr dashboard module. A K8s service will be created to expose that port inside the cluster. The ports enabled by Rook will depend
|
||||
on the version of Ceph that is running:
|
||||
- Luminous: Port 7000 on http
|
||||
- Mimic and newer: Port 8443 on https
|
||||
|
||||
This example shows that port 8443 was configured for Mimic or newer.
|
||||
```bash
|
||||
kubectl -n rook-ceph get service
|
||||
NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE
|
||||
rook-ceph-mgr ClusterIP 10.108.111.192 <none> 9283/TCP 3h
|
||||
rook-ceph-mgr-dashboard ClusterIP 10.110.113.240 <none> 8443/TCP 3h
|
||||
NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE
|
||||
rook-ceph-mgr ClusterIP 10.108.111.192 <none> 9283/TCP 3h
|
||||
rook-ceph-mgr-dashboard ClusterIP 10.110.113.240 <none> 8443/TCP 3h
|
||||
```
|
||||
|
||||
The first service is for reporting the [Prometheus metrics](monitoring.md), while the latter service is for the dashboard.
|
||||
If you are on a node in the cluster, you will be able to connect to the dashboard by using either the
|
||||
DNS name of the service at `http://rook-ceph-mgr-dashboard:8443` or by connecting to the cluster IP,
|
||||
in this example at `http://10.110.113.240:8443`.
|
||||
DNS name of the service at `https://rook-ceph-mgr-dashboard-https:8443` or by connecting to the cluster IP,
|
||||
in this example at `https://10.110.113.240:8443`.
|
||||
|
||||
### Credentials
|
||||
|
||||
@@ -55,12 +59,14 @@ You can use an [Ingress Controller](https://kubernetes.io/docs/concepts/services
|
||||
NodePort, LoadBalancer, or ExternalIPs.
|
||||
|
||||
The simplest way to expose the service in minikube or similar environment is using the NodePort to open a port on the
|
||||
VM that can be accessed by the host. To create a service with the NodePort, save this yaml as `dashboard-external.yaml`:
|
||||
VM that can be accessed by the host. To create a service with the NodePort, save this yaml as `dashboard-external-https.yaml`.
|
||||
(For Luminous you will need to set the `port` and `targetPort` to 7000 and connect via `http`.)
|
||||
|
||||
```yaml
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: rook-ceph-mgr-dashboard-external
|
||||
name: rook-ceph-mgr-dashboard-external-https
|
||||
namespace: rook-ceph
|
||||
labels:
|
||||
app: rook-ceph-mgr
|
||||
@@ -86,12 +92,12 @@ $ kubectl create -f dashboard-external.yaml
|
||||
You will see the new service `rook-ceph-mgr-dashboard-external` created:
|
||||
```bash
|
||||
$ kubectl -n rook-ceph get service
|
||||
NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE
|
||||
rook-ceph-mgr ClusterIP 10.108.111.192 <none> 9283/TCP 4h
|
||||
rook-ceph-mgr-dashboard ClusterIP 10.110.113.240 <none> 8443/TCP 4h
|
||||
rook-ceph-mgr-dashboard-external NodePort 10.101.209.6 <none> 8443:31176/TCP 4h
|
||||
NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE
|
||||
rook-ceph-mgr ClusterIP 10.108.111.192 <none> 9283/TCP 4h
|
||||
rook-ceph-mgr-dashboard ClusterIP 10.110.113.240 <none> 8443/TCP 4h
|
||||
rook-ceph-mgr-dashboard-external-https NodePort 10.101.209.6 <none> 8443:31176/TCP 4h
|
||||
```
|
||||
|
||||
In this example, port `31176` will be opened to expose port `8443` from the ceph-mgr pod. Find the ip address
|
||||
of the VM. If using minikube, you can run `minikube ip` to find the ip address.
|
||||
Now you can enter the URL in your browser such as `http://192.168.99.110:31176` and the dashboard will appear.
|
||||
Now you can enter the URL in your browser such as `https://192.168.99.110:31176` and the dashboard will appear.
|
||||
|
||||
@@ -0,0 +1,19 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: rook-ceph-mgr-dashboard-external-http
|
||||
namespace: rook-ceph
|
||||
labels:
|
||||
app: rook-ceph-mgr
|
||||
rook_cluster: rook-ceph
|
||||
spec:
|
||||
ports:
|
||||
- name: dashboard
|
||||
port: 7000
|
||||
protocol: TCP
|
||||
targetPort: 7000
|
||||
selector:
|
||||
app: rook-ceph-mgr
|
||||
rook_cluster: rook-ceph
|
||||
sessionAffinity: None
|
||||
type: NodePort
|
||||
+1
-1
@@ -1,7 +1,7 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: rook-ceph-mgr-dashboard-external
|
||||
name: rook-ceph-mgr-dashboard-external-https
|
||||
namespace: rook-ceph
|
||||
labels:
|
||||
app: rook-ceph-mgr
|
||||
@@ -34,7 +34,8 @@ import (
|
||||
|
||||
const (
|
||||
dashboardModuleName = "dashboard"
|
||||
dashboardPort = 8443
|
||||
dashboardPortHttps = 8443
|
||||
dashboardPortHttp = 7000
|
||||
dashboardUsername = "admin"
|
||||
dashboardPasswordName = "rook-ceph-dashboard-password"
|
||||
passwordLength = 10
|
||||
@@ -50,13 +51,13 @@ func init() {
|
||||
rand.Seed(time.Now().UnixNano())
|
||||
}
|
||||
|
||||
func (c *Cluster) configureDashboard() error {
|
||||
func (c *Cluster) configureDashboard(port int) error {
|
||||
// enable or disable the dashboard module
|
||||
if err := c.configureDashboardModule(); err != nil {
|
||||
return fmt.Errorf("failed to enable mgr dashboard module. %+v", err)
|
||||
}
|
||||
|
||||
dashboardService := c.makeDashboardService(appName)
|
||||
dashboardService := c.makeDashboardService(appName, port)
|
||||
if c.dashboard.Enabled {
|
||||
// expose the dashboard service
|
||||
if _, err := c.context.Clientset.CoreV1().Services(c.Namespace).Create(dashboardService); err != nil {
|
||||
|
||||
@@ -82,7 +82,7 @@ func TestStartSecureDashboard(t *testing.T) {
|
||||
c := &Cluster{context: &clusterd.Context{Clientset: test.New(3), Executor: executor}, Namespace: "myns",
|
||||
dashboard: cephv1beta1.DashboardSpec{Enabled: true}, cephVersion: cephv1beta1.CephVersionSpec{Name: cephv1beta1.Mimic, Image: "ceph/ceph:v13.2.2"}}
|
||||
dashboardInitWaitTime = 0
|
||||
err := c.configureDashboard()
|
||||
err := c.configureDashboard(dashboardPortHttp)
|
||||
assert.Nil(t, err)
|
||||
// the dashboard is enabled, then disabled and enabled again to restart it with the cert
|
||||
assert.Equal(t, 2, enables)
|
||||
@@ -94,7 +94,7 @@ func TestStartSecureDashboard(t *testing.T) {
|
||||
|
||||
// disable the dashboard
|
||||
c.dashboard.Enabled = false
|
||||
err = c.configureDashboard()
|
||||
err = c.configureDashboard(dashboardPortHttp)
|
||||
assert.Nil(t, err)
|
||||
assert.Equal(t, 2, enables)
|
||||
assert.Equal(t, 2, disables)
|
||||
|
||||
@@ -85,6 +85,11 @@ func New(context *clusterd.Context, namespace, rookVersion string, cephVersion c
|
||||
func (c *Cluster) Start() error {
|
||||
logger.Infof("start running mgr")
|
||||
|
||||
dashboardPort := dashboardPortHttps
|
||||
if c.cephVersion.Name == cephv1beta1.Luminous {
|
||||
dashboardPort = dashboardPortHttp
|
||||
}
|
||||
|
||||
for i := 0; i < c.Replicas; i++ {
|
||||
if i >= len(mgrNames) {
|
||||
logger.Errorf("cannot have more than %d mgrs", len(mgrNames))
|
||||
@@ -103,7 +108,7 @@ func (c *Cluster) Start() error {
|
||||
}
|
||||
|
||||
// start the deployment
|
||||
deployment := c.makeDeployment(mgrConfig)
|
||||
deployment := c.makeDeployment(mgrConfig, dashboardPort)
|
||||
if _, err := c.context.Clientset.ExtensionsV1beta1().Deployments(c.Namespace).Create(deployment); err != nil {
|
||||
if !errors.IsAlreadyExists(err) {
|
||||
return fmt.Errorf("failed to create %s deployment. %+v", resourceName, err)
|
||||
@@ -122,7 +127,7 @@ func (c *Cluster) Start() error {
|
||||
logger.Errorf("failed to enable mgr prometheus module. %+v", err)
|
||||
}
|
||||
|
||||
if err := c.configureDashboard(); err != nil {
|
||||
if err := c.configureDashboard(dashboardPort); err != nil {
|
||||
logger.Errorf("failed to enable mgr dashboard. %+v", err)
|
||||
}
|
||||
|
||||
|
||||
@@ -33,7 +33,7 @@ const (
|
||||
mgrDaemonCommand = "ceph-mgr"
|
||||
)
|
||||
|
||||
func (c *Cluster) makeDeployment(mgrConfig *mgrConfig) *extensions.Deployment {
|
||||
func (c *Cluster) makeDeployment(mgrConfig *mgrConfig, port int) *extensions.Deployment {
|
||||
podSpec := v1.PodTemplateSpec{
|
||||
ObjectMeta: metav1.ObjectMeta{
|
||||
Name: mgrConfig.ResourceName,
|
||||
@@ -47,7 +47,7 @@ func (c *Cluster) makeDeployment(mgrConfig *mgrConfig) *extensions.Deployment {
|
||||
c.makeConfigInitContainer(mgrConfig),
|
||||
},
|
||||
Containers: []v1.Container{
|
||||
c.makeMgrDaemonContainer(mgrConfig),
|
||||
c.makeMgrDaemonContainer(mgrConfig, port),
|
||||
},
|
||||
RestartPolicy: v1.RestartPolicyAlways,
|
||||
Volumes: opspec.PodVolumes(""),
|
||||
@@ -102,7 +102,7 @@ func (c *Cluster) makeConfigInitContainer(mgrConfig *mgrConfig) v1.Container {
|
||||
}
|
||||
}
|
||||
|
||||
func (c *Cluster) makeMgrDaemonContainer(mgrConfig *mgrConfig) v1.Container {
|
||||
func (c *Cluster) makeMgrDaemonContainer(mgrConfig *mgrConfig, port int) v1.Container {
|
||||
container := v1.Container{
|
||||
Name: "mgr",
|
||||
Command: []string{
|
||||
@@ -128,7 +128,7 @@ func (c *Cluster) makeMgrDaemonContainer(mgrConfig *mgrConfig) v1.Container {
|
||||
},
|
||||
{
|
||||
Name: "dashboard",
|
||||
ContainerPort: int32(dashboardPort),
|
||||
ContainerPort: int32(port),
|
||||
Protocol: v1.ProtocolTCP,
|
||||
},
|
||||
},
|
||||
@@ -164,7 +164,7 @@ func (c *Cluster) makeMetricsService(name string) *v1.Service {
|
||||
return svc
|
||||
}
|
||||
|
||||
func (c *Cluster) makeDashboardService(name string) *v1.Service {
|
||||
func (c *Cluster) makeDashboardService(name string, port int) *v1.Service {
|
||||
labels := opspec.AppLabels(appName, c.Namespace)
|
||||
svc := &v1.Service{
|
||||
ObjectMeta: metav1.ObjectMeta{
|
||||
@@ -178,7 +178,7 @@ func (c *Cluster) makeDashboardService(name string) *v1.Service {
|
||||
Ports: []v1.ServicePort{
|
||||
{
|
||||
Name: "https-dashboard",
|
||||
Port: int32(dashboardPort),
|
||||
Port: int32(port),
|
||||
Protocol: v1.ProtocolTCP,
|
||||
},
|
||||
},
|
||||
|
||||
@@ -61,7 +61,7 @@ func TestPodSpec(t *testing.T) {
|
||||
ResourceName: "mgr-a",
|
||||
}
|
||||
|
||||
d := c.makeDeployment(&mgrTestConfig)
|
||||
d := c.makeDeployment(&mgrTestConfig, dashboardPortHttp)
|
||||
|
||||
assert.NotNil(t, d)
|
||||
assert.Equal(t, "mgr-a", d.Name)
|
||||
@@ -126,7 +126,7 @@ func TestPodSpec(t *testing.T) {
|
||||
Protocol: v1.ProtocolTCP},
|
||||
{ContainerPort: int32(metricsPort),
|
||||
Protocol: v1.ProtocolTCP},
|
||||
{ContainerPort: int32(dashboardPort),
|
||||
{ContainerPort: int32(dashboardPortHttp),
|
||||
Protocol: v1.ProtocolTCP}},
|
||||
IsPrivileged: nil, // not set in spec
|
||||
}
|
||||
@@ -172,7 +172,7 @@ func TestHostNetwork(t *testing.T) {
|
||||
ResourceName: "mgr-a",
|
||||
}
|
||||
|
||||
d := c.makeDeployment(&mgrTestConfig)
|
||||
d := c.makeDeployment(&mgrTestConfig, dashboardPortHttp)
|
||||
assert.NotNil(t, d)
|
||||
|
||||
assert.Equal(t, true, d.Spec.Template.Spec.HostNetwork)
|
||||
|
||||
Reference in New Issue
Block a user