Added failureDomains and osdsPerDomain fields to the
ErasureCodedSpec, which maps to the crush-num-failure-domains and
crush-osds-per-failure-domain Ceph EC profile parameters. This enables
creating EC pools that distribute chunks across fewer, larger hosts
without needing one host per data chunk.
Signed-off-by: Prabhala Tara Aasrita <taraprabhala@Prabhalas-MacBook-Pro.local>
Document spec.server.port for host-network port conflicts, and describe
how user-managed LoadBalancer and NodePort Services must align port and
targetPort with the CR.
Signed-off-by: raaizik <raaizik@yahoo.com>
Co-Authored-By: Blaine Gardner <b.blaine.gardner@gmail.com>
When NFS runs with host networking, port 2049 may already be in use.
Add CephNFS spec.server.port (default 2049), wire it through Ganesha
config, the operator Service, and probes, and regenerate CRDs.
Signed-off-by: raaizik <raaizik@yahoo.com>
Add VolumeGroupSnapshotClass and VolumeGroupSnapshot example manifests
for RBD and NFS, similar to the existing CephFS examples.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Signed-off-by: Praveen M <m.praveen@ibm.com>
Changes:
- Use a dedicated .nvmeof pool (via CephBlockPool CR named
builtin-nvmeof) for the NVMe-oF gateway internal state.
- Use a separate nvmeof pool for the StorageClass data.
- Remove the pool field from the CephNVMeOFGateway CRD.
The gateway now always uses the .nvmeof pool, hardcoded
in the operator.
- Add .nvmeof to the allowed CephBlockPool name overrides.
- Create a production example nvmeof.yaml (instances: 2,
replicas: 3) and a CI-only nvmeof-test.yaml (instances: 1,
replicas: 1).
- Update documentation and CI test script accordingly.
Signed-off-by: Oded Viner <oviner@redhat.com>
create the csi secret before creating the mon cm
as the cluster controller will look for the csi
secrets for creating client profile
Signed-off-by: parth-gr <partharora1010@gmail.com>
the order of creating the svg and rns is important,
the svg and rns controller is dependent on the ceph health,
so first we should create the mon secret to get the cephcluster `health ok`
Signed-off-by: parth-gr <partharora1010@gmail.com>
ceph-csi has updated the VolumeGroupSnapshot API version to v1.
Update the example YAMLs to use groupsnapshot.storage.k8s.io/v1
instead of v1beta1.
Signed-off-by: Praveen M <m.praveen@ibm.com>
this commit add support for updating rgw caps with
`user-info-without-key` and `accounts` to cephobjectstoreuser crd
Adding the check for min ceph version from which these caps
are available.
Co-Authoured-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
Signed-off-by: subhamkrai <srai@redhat.com>
Add annotations to RBD node secrets in
import-external-cluster.sh so that externally
created secrets with
custom names can be discovered at runtime.
Update CreateUpdateClientProfileRadosNamespace to
look up secrets by annotation
instead of using hardcoded names.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
Aggregate pool usage by pool before predict_linear to avoid duplicate series after mgr pod replacement, and add a one-hour hold time to match the source rule update in ceph/ceph#68621.
Signed-off-by: Jeff Wallace <jeff@tjwallace.ca>
Add annotations to CephFS and RBD provisioner secrets in
import-external-cluster.sh so that externally created secrets with
custom names can be discovered at runtime.
Update CreateUpdateClientProfileRadosNamespace and
generateProfileSubVolumeGroupSpec to look up secrets by annotation
instead of using hardcoded names.
closes: https://github.com/rook/rook/issues/16956
Signed-off-by: parth-gr <partharora1010@gmail.com>
Updated the required documentation and yamls
where we are adding support for the QoS for
the rbd pvc that uses the krbd mounter.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
Fix duplicate words, incorrect articles (a/an), it's/its, and other small
grammar mistakes in Go comments and user-facing messages across pkg/, cmd/,
and tests/.
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
The MGR watch-active sidecar needs Kubernetes API access to
read configmaps and monitor active-standby state. The API
server is host-networked and cannot be targeted by
pod/namespace selectors, making egress restrictions
impractical.
Switch the rook-ceph-mgr NetworkPolicy from egress-only to
ingress-only:
- Allow MON/OSD/MDS/tools pods on ports 6800-7300
- Allow Prometheus scraping on port 9283
- Remove egress rules that blocked API server access and
caused CrashLoopBackOff in the watch-active container
Signed-off-by: Oded Viner <oviner@redhat.com>
Several godoc comments led with a stale or incorrect identifier, left
over from renames, exported/unexported changes, copy-paste between
sibling declarations, or plain typos. As a result the documented name no
longer matched the function, method, type, or var it describes. Correct
each leading word to the name of the declaration it documents.
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
before the csi op, the unblish grpc call was not present,
and it has no op
But with csi op, the unpublish grpc is called before the
volumeattachment get remove, and the unpublish call need a
unpublish secret, currently it is getting the secret from the
client profile, but the client profile secret is hardcoded to default
So to override this secret we are adding the secret name in the
storageclass parameter
Signed-off-by: parth-gr <partharora1010@gmail.com>
The rgw endpoint validation issued an HTTP request to the admin ops
api without a timeout. If the RGW is accepting connections but slow to
respond, for example right after the object store was created, the
script hangs indefinitely instead of reporting a validation error that
the caller could retry on.
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
Add a single example YAML with NetworkPolicy definitions
for all Ceph operand pods (mon, osd, mgr, mds, exporter,
osd-prepare, crashcollector, tools).
Users can apply these policies to restrict egress/ingress
traffic for Rook-Ceph daemon pods.
Signed-off-by: Oded Viner <oviner@redhat.com>
adding api changes to mute/unmute ceph warnings
based on user configuration. The field is map[string]string
key is ceph warning and value is duration how longs
the warnings will be muted.
Signed-off-by: subhamkrai <srai@redhat.com>
Make the NVMe-oF gateway image optional in the CR spec.
When not specified, the operator fetches the image from
the Ceph mon config store using the key
mgr/cephadm/container_image_nvmeof. Falls back to the
hardcoded default if the config is unavailable.
Signed-off-by: Oded Viner <oviner@redhat.com>
updated the external cluster doc, and helm and manifest
install to make use of csi operator as it is the default
offering now
Signed-off-by: parth-gr <partharora1010@gmail.com>
adding rook compatible Ceph-Csi driver values.yaml
file making sure, upgrading to 1.20 doesn't break
when csi-driver is moved to admin.
Co-authored-by: Travis Nielsen <tnielsen@redhat.com>
Signed-off-by: subhamkrai <srai@redhat.com>
having csi-addons enabled by default is causing random
pod restart on non-openshift cluster. Let's disable
it by default.
Signed-off-by: subhamkrai <srai@redhat.com>
this command adds some examples on how users can add/update
the settings based on new way of managing CSI resources.
Signed-off-by: subhamkrai <srai@redhat.com>