From 6cfd2ee11ab5afbf0efbde39f6ff00a3a7ba6ace Mon Sep 17 00:00:00 2001 From: travisn Date: Wed, 31 Oct 2018 16:30:39 -0600 Subject: [PATCH] port 7000 for the luminous dashboard and 8443 for mimic and above Signed-off-by: travisn --- Documentation/ceph-dashboard.md | 36 +++++++++++-------- .../ceph/dashboard-external-http.yaml | 19 ++++++++++ ...nal.yaml => dashboard-external-https.yaml} | 2 +- pkg/operator/ceph/cluster/mgr/dashboard.go | 7 ++-- .../ceph/cluster/mgr/dashboard_test.go | 4 +-- pkg/operator/ceph/cluster/mgr/mgr.go | 9 +++-- pkg/operator/ceph/cluster/mgr/spec.go | 12 +++---- pkg/operator/ceph/cluster/mgr/spec_test.go | 6 ++-- 8 files changed, 63 insertions(+), 32 deletions(-) create mode 100644 cluster/examples/kubernetes/ceph/dashboard-external-http.yaml rename cluster/examples/kubernetes/ceph/{dashboard-external.yaml => dashboard-external-https.yaml} (87%) diff --git a/Documentation/ceph-dashboard.md b/Documentation/ceph-dashboard.md index f9e8a0677..7363bc8f9 100644 --- a/Documentation/ceph-dashboard.md +++ b/Documentation/ceph-dashboard.md @@ -14,7 +14,7 @@ and more. Rook makes it simple to enable the dashboard. ## Enable the Dashboard -The [dashboard](http://docs.ceph.com/docs/luminous/mgr/dashboard/) can be enabled with settings in the cluster CRD. The cluster CRD must have the dashboard `enabled` setting set to `true`. +The [dashboard](http://docs.ceph.com/docs/mimic/mgr/dashboard/) can be enabled with settings in the cluster CRD. The cluster CRD must have the dashboard `enabled` setting set to `true`. This is the default setting in the example manifests. ```yaml spec: @@ -22,19 +22,23 @@ This is the default setting in the example manifests. enabled: true ``` -The Rook operator will enable the ceph-mgr dashboard module to listen on the default port 8443. -A K8s service will also be created to expose that port inside the cluster. +The Rook operator will enable the ceph-mgr dashboard module. A K8s service will be created to expose that port inside the cluster. The ports enabled by Rook will depend +on the version of Ceph that is running: +- Luminous: Port 7000 on http +- Mimic and newer: Port 8443 on https + +This example shows that port 8443 was configured for Mimic or newer. ```bash kubectl -n rook-ceph get service -NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE -rook-ceph-mgr ClusterIP 10.108.111.192 9283/TCP 3h -rook-ceph-mgr-dashboard ClusterIP 10.110.113.240 8443/TCP 3h +NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE +rook-ceph-mgr ClusterIP 10.108.111.192 9283/TCP 3h +rook-ceph-mgr-dashboard ClusterIP 10.110.113.240 8443/TCP 3h ``` The first service is for reporting the [Prometheus metrics](monitoring.md), while the latter service is for the dashboard. If you are on a node in the cluster, you will be able to connect to the dashboard by using either the -DNS name of the service at `http://rook-ceph-mgr-dashboard:8443` or by connecting to the cluster IP, -in this example at `http://10.110.113.240:8443`. +DNS name of the service at `https://rook-ceph-mgr-dashboard-https:8443` or by connecting to the cluster IP, +in this example at `https://10.110.113.240:8443`. ### Credentials @@ -55,12 +59,14 @@ You can use an [Ingress Controller](https://kubernetes.io/docs/concepts/services NodePort, LoadBalancer, or ExternalIPs. The simplest way to expose the service in minikube or similar environment is using the NodePort to open a port on the -VM that can be accessed by the host. To create a service with the NodePort, save this yaml as `dashboard-external.yaml`: +VM that can be accessed by the host. To create a service with the NodePort, save this yaml as `dashboard-external-https.yaml`. +(For Luminous you will need to set the `port` and `targetPort` to 7000 and connect via `http`.) + ```yaml apiVersion: v1 kind: Service metadata: - name: rook-ceph-mgr-dashboard-external + name: rook-ceph-mgr-dashboard-external-https namespace: rook-ceph labels: app: rook-ceph-mgr @@ -86,12 +92,12 @@ $ kubectl create -f dashboard-external.yaml You will see the new service `rook-ceph-mgr-dashboard-external` created: ```bash $ kubectl -n rook-ceph get service -NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE -rook-ceph-mgr ClusterIP 10.108.111.192 9283/TCP 4h -rook-ceph-mgr-dashboard ClusterIP 10.110.113.240 8443/TCP 4h -rook-ceph-mgr-dashboard-external NodePort 10.101.209.6 8443:31176/TCP 4h +NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE +rook-ceph-mgr ClusterIP 10.108.111.192 9283/TCP 4h +rook-ceph-mgr-dashboard ClusterIP 10.110.113.240 8443/TCP 4h +rook-ceph-mgr-dashboard-external-https NodePort 10.101.209.6 8443:31176/TCP 4h ``` In this example, port `31176` will be opened to expose port `8443` from the ceph-mgr pod. Find the ip address of the VM. If using minikube, you can run `minikube ip` to find the ip address. -Now you can enter the URL in your browser such as `http://192.168.99.110:31176` and the dashboard will appear. +Now you can enter the URL in your browser such as `https://192.168.99.110:31176` and the dashboard will appear. diff --git a/cluster/examples/kubernetes/ceph/dashboard-external-http.yaml b/cluster/examples/kubernetes/ceph/dashboard-external-http.yaml new file mode 100644 index 000000000..c67ac4c5e --- /dev/null +++ b/cluster/examples/kubernetes/ceph/dashboard-external-http.yaml @@ -0,0 +1,19 @@ +apiVersion: v1 +kind: Service +metadata: + name: rook-ceph-mgr-dashboard-external-http + namespace: rook-ceph + labels: + app: rook-ceph-mgr + rook_cluster: rook-ceph +spec: + ports: + - name: dashboard + port: 7000 + protocol: TCP + targetPort: 7000 + selector: + app: rook-ceph-mgr + rook_cluster: rook-ceph + sessionAffinity: None + type: NodePort diff --git a/cluster/examples/kubernetes/ceph/dashboard-external.yaml b/cluster/examples/kubernetes/ceph/dashboard-external-https.yaml similarity index 87% rename from cluster/examples/kubernetes/ceph/dashboard-external.yaml rename to cluster/examples/kubernetes/ceph/dashboard-external-https.yaml index 4ee0c10df..4b94a3778 100644 --- a/cluster/examples/kubernetes/ceph/dashboard-external.yaml +++ b/cluster/examples/kubernetes/ceph/dashboard-external-https.yaml @@ -1,7 +1,7 @@ apiVersion: v1 kind: Service metadata: - name: rook-ceph-mgr-dashboard-external + name: rook-ceph-mgr-dashboard-external-https namespace: rook-ceph labels: app: rook-ceph-mgr diff --git a/pkg/operator/ceph/cluster/mgr/dashboard.go b/pkg/operator/ceph/cluster/mgr/dashboard.go index 53f6eed98..3d3572e6a 100644 --- a/pkg/operator/ceph/cluster/mgr/dashboard.go +++ b/pkg/operator/ceph/cluster/mgr/dashboard.go @@ -34,7 +34,8 @@ import ( const ( dashboardModuleName = "dashboard" - dashboardPort = 8443 + dashboardPortHttps = 8443 + dashboardPortHttp = 7000 dashboardUsername = "admin" dashboardPasswordName = "rook-ceph-dashboard-password" passwordLength = 10 @@ -50,13 +51,13 @@ func init() { rand.Seed(time.Now().UnixNano()) } -func (c *Cluster) configureDashboard() error { +func (c *Cluster) configureDashboard(port int) error { // enable or disable the dashboard module if err := c.configureDashboardModule(); err != nil { return fmt.Errorf("failed to enable mgr dashboard module. %+v", err) } - dashboardService := c.makeDashboardService(appName) + dashboardService := c.makeDashboardService(appName, port) if c.dashboard.Enabled { // expose the dashboard service if _, err := c.context.Clientset.CoreV1().Services(c.Namespace).Create(dashboardService); err != nil { diff --git a/pkg/operator/ceph/cluster/mgr/dashboard_test.go b/pkg/operator/ceph/cluster/mgr/dashboard_test.go index 650cecfe6..d0418e160 100644 --- a/pkg/operator/ceph/cluster/mgr/dashboard_test.go +++ b/pkg/operator/ceph/cluster/mgr/dashboard_test.go @@ -82,7 +82,7 @@ func TestStartSecureDashboard(t *testing.T) { c := &Cluster{context: &clusterd.Context{Clientset: test.New(3), Executor: executor}, Namespace: "myns", dashboard: cephv1beta1.DashboardSpec{Enabled: true}, cephVersion: cephv1beta1.CephVersionSpec{Name: cephv1beta1.Mimic, Image: "ceph/ceph:v13.2.2"}} dashboardInitWaitTime = 0 - err := c.configureDashboard() + err := c.configureDashboard(dashboardPortHttp) assert.Nil(t, err) // the dashboard is enabled, then disabled and enabled again to restart it with the cert assert.Equal(t, 2, enables) @@ -94,7 +94,7 @@ func TestStartSecureDashboard(t *testing.T) { // disable the dashboard c.dashboard.Enabled = false - err = c.configureDashboard() + err = c.configureDashboard(dashboardPortHttp) assert.Nil(t, err) assert.Equal(t, 2, enables) assert.Equal(t, 2, disables) diff --git a/pkg/operator/ceph/cluster/mgr/mgr.go b/pkg/operator/ceph/cluster/mgr/mgr.go index ccb20f037..b4dafe384 100644 --- a/pkg/operator/ceph/cluster/mgr/mgr.go +++ b/pkg/operator/ceph/cluster/mgr/mgr.go @@ -85,6 +85,11 @@ func New(context *clusterd.Context, namespace, rookVersion string, cephVersion c func (c *Cluster) Start() error { logger.Infof("start running mgr") + dashboardPort := dashboardPortHttps + if c.cephVersion.Name == cephv1beta1.Luminous { + dashboardPort = dashboardPortHttp + } + for i := 0; i < c.Replicas; i++ { if i >= len(mgrNames) { logger.Errorf("cannot have more than %d mgrs", len(mgrNames)) @@ -103,7 +108,7 @@ func (c *Cluster) Start() error { } // start the deployment - deployment := c.makeDeployment(mgrConfig) + deployment := c.makeDeployment(mgrConfig, dashboardPort) if _, err := c.context.Clientset.ExtensionsV1beta1().Deployments(c.Namespace).Create(deployment); err != nil { if !errors.IsAlreadyExists(err) { return fmt.Errorf("failed to create %s deployment. %+v", resourceName, err) @@ -122,7 +127,7 @@ func (c *Cluster) Start() error { logger.Errorf("failed to enable mgr prometheus module. %+v", err) } - if err := c.configureDashboard(); err != nil { + if err := c.configureDashboard(dashboardPort); err != nil { logger.Errorf("failed to enable mgr dashboard. %+v", err) } diff --git a/pkg/operator/ceph/cluster/mgr/spec.go b/pkg/operator/ceph/cluster/mgr/spec.go index c9fa92a55..e9cacfa4a 100644 --- a/pkg/operator/ceph/cluster/mgr/spec.go +++ b/pkg/operator/ceph/cluster/mgr/spec.go @@ -33,7 +33,7 @@ const ( mgrDaemonCommand = "ceph-mgr" ) -func (c *Cluster) makeDeployment(mgrConfig *mgrConfig) *extensions.Deployment { +func (c *Cluster) makeDeployment(mgrConfig *mgrConfig, port int) *extensions.Deployment { podSpec := v1.PodTemplateSpec{ ObjectMeta: metav1.ObjectMeta{ Name: mgrConfig.ResourceName, @@ -47,7 +47,7 @@ func (c *Cluster) makeDeployment(mgrConfig *mgrConfig) *extensions.Deployment { c.makeConfigInitContainer(mgrConfig), }, Containers: []v1.Container{ - c.makeMgrDaemonContainer(mgrConfig), + c.makeMgrDaemonContainer(mgrConfig, port), }, RestartPolicy: v1.RestartPolicyAlways, Volumes: opspec.PodVolumes(""), @@ -102,7 +102,7 @@ func (c *Cluster) makeConfigInitContainer(mgrConfig *mgrConfig) v1.Container { } } -func (c *Cluster) makeMgrDaemonContainer(mgrConfig *mgrConfig) v1.Container { +func (c *Cluster) makeMgrDaemonContainer(mgrConfig *mgrConfig, port int) v1.Container { container := v1.Container{ Name: "mgr", Command: []string{ @@ -128,7 +128,7 @@ func (c *Cluster) makeMgrDaemonContainer(mgrConfig *mgrConfig) v1.Container { }, { Name: "dashboard", - ContainerPort: int32(dashboardPort), + ContainerPort: int32(port), Protocol: v1.ProtocolTCP, }, }, @@ -164,7 +164,7 @@ func (c *Cluster) makeMetricsService(name string) *v1.Service { return svc } -func (c *Cluster) makeDashboardService(name string) *v1.Service { +func (c *Cluster) makeDashboardService(name string, port int) *v1.Service { labels := opspec.AppLabels(appName, c.Namespace) svc := &v1.Service{ ObjectMeta: metav1.ObjectMeta{ @@ -178,7 +178,7 @@ func (c *Cluster) makeDashboardService(name string) *v1.Service { Ports: []v1.ServicePort{ { Name: "https-dashboard", - Port: int32(dashboardPort), + Port: int32(port), Protocol: v1.ProtocolTCP, }, }, diff --git a/pkg/operator/ceph/cluster/mgr/spec_test.go b/pkg/operator/ceph/cluster/mgr/spec_test.go index 2f3521019..e3ae386e9 100644 --- a/pkg/operator/ceph/cluster/mgr/spec_test.go +++ b/pkg/operator/ceph/cluster/mgr/spec_test.go @@ -61,7 +61,7 @@ func TestPodSpec(t *testing.T) { ResourceName: "mgr-a", } - d := c.makeDeployment(&mgrTestConfig) + d := c.makeDeployment(&mgrTestConfig, dashboardPortHttp) assert.NotNil(t, d) assert.Equal(t, "mgr-a", d.Name) @@ -126,7 +126,7 @@ func TestPodSpec(t *testing.T) { Protocol: v1.ProtocolTCP}, {ContainerPort: int32(metricsPort), Protocol: v1.ProtocolTCP}, - {ContainerPort: int32(dashboardPort), + {ContainerPort: int32(dashboardPortHttp), Protocol: v1.ProtocolTCP}}, IsPrivileged: nil, // not set in spec } @@ -172,7 +172,7 @@ func TestHostNetwork(t *testing.T) { ResourceName: "mgr-a", } - d := c.makeDeployment(&mgrTestConfig) + d := c.makeDeployment(&mgrTestConfig, dashboardPortHttp) assert.NotNil(t, d) assert.Equal(t, true, d.Spec.Template.Spec.HostNetwork)