255 Commits
Author SHA1 Message Date
Artem Torubarov 514bd21552 osd: implement osd replacement controller
adds support of osd-replacement flow to cluster controller:
- predicate for osd deployment annotation
- validation of osd replacement annotation
- osd deployment recreation logic for replaced OSD

Signed-off-by: Artem Torubarov <artem.torubarov@sap.com>
2026-07-27 18:42:07 +02:00
Travis Nielsen 955f7c5428 Merge pull request #17785 from beyondcloud-co/fix/17761-duplicate-mgr-ips-in-endpointslice
fix(ceph): deduplicate external MGR endpoints in EndpointSlice
2026-07-22 09:05:31 -06:00
Joshua Hoblitt 49612461a4 docs: fix function comments to match their declaration names
Several godoc comments led with a stale or incorrect identifier, left
over from renames, exported/unexported changes, copy-paste between
sibling declarations, or plain typos. As a result the documented name no
longer matched the function, method, type, or var it describes. Correct
each leading word to the name of the declaration it documents.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2026-06-26 12:52:39 -07:00
beyondcloud-co 8134d683e3 external: deduplicate external MGR endpoints in EndpointSlice
When the active MGR IP already exists at a non-zero position in the
externalMgrEndpoints list, the rotation logic that replaces endpoints[0]
creates duplicate IPs. Also guards against mgr map failure which could
overwrite endpoints[0] with an empty string.

Fixes: #17761

Signed-off-by: beyondcloud-co <87993136+beyondcloud-co@users.noreply.github.com>
2026-06-18 17:16:46 -04:00
Santosh Pillai 6feb856a9f Merge pull request #17670 from jhoblitt/maint-remove-dead-lockingbool
operator: remove dead code from the operator tree
2026-06-17 15:05:49 +05:30
Joshua Hoblitt b30ba09bda operator: remove unused AddCephVersionLabelToDaemonSet
AddCephVersionLabelToDaemonSet had no callers anywhere in the repo
(verified with deadcode and repo-wide grep); rook applies ceph version
labels to Deployments, Jobs, and object metas, but never to DaemonSets.
The shared addCephVersionLabel helper remains in use by the live
siblings.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2026-06-11 15:44:18 -07:00
Joshua Hoblitt 8dd1778655 Merge pull request #17561 from jhoblitt/maint-ref-all-containers-by-name-instead-of-index
core: reference all containers in a spec by name instead of index
2026-05-26 12:10:09 -07:00
Joshua Hoblitt d059c351fc core: reference all containers in a spec by name instead of index
This changeset excludes converting _test.go code as there may be a
legitimate reasons (E.g. convenience) for unit test to be sensitive to
ordering.

Related to:
- https://github.com/rook/rook/issues/15291
- https://github.com/rook/rook/pull/16969

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2026-05-26 10:09:23 -07:00
Blaine Gardner 645aa741eb Merge pull request #17530 from rook/maint-rm-unused-consts-opus-4.7
core: rm unused consts
2026-05-20 09:01:05 -06:00
Sunnatillo 0bd299aa60 build: fix gosec and go vet lint errors for Go 1.26
Signed-off-by: Sunnatillo <sunnat.samadov@est.tech>
2026-05-15 21:45:06 +03:00
Joshua Hoblitt 9eec9c730e core: rm unused consts
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2026-05-14 09:34:52 -07:00
Santosh 925acb3e92 core: remove newlines from liveness probe scripts
Strip unnecessary leading and trailing newlines from osdLivenessProbeScript and livenessProbeScript raw string literals in spec.go

Signed-off-by: Santosh <sapillai@redhat.com>
2026-04-24 14:24:51 +05:30
Jongwoo Han d59b4dcb84 core: replace custom contains() with slices.Contains()
Signed-off-by: Jongwoo Han <jongwooo.han@gmail.com>
2025-12-24 13:28:05 +09:00
Parth Arora c1247b19d7 Merge pull request #16792 from parth-gr/fix-mgr-external
external: fix endpoint slice type for ipv6 clusters
2025-12-08 16:29:06 +05:30
parth-gr 0a3d9b8517 external: fix endpoint slice type for ipv6 clusters
in endpoint slice for the mgr and rgw service
it was harcoded to use the ipv4,
now dynamically assign the type based on the endpoint
ip adrress type

Signed-off-by: parth-gr <partharora1010@gmail.com>
2025-12-08 15:52:50 +05:30
Travis Nielsen 023608e6fd core: enhance logging with namespaced names
For all of the controllers besides the cluster controller,
the logging now includes the namespaced name of the resource
that is being reconciled. This will help with log troubleshooting
to help analyze logs consistently for the resource being
reconciled.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-12-04 12:00:42 -07:00
subhamkrai 304cdc8c83 core: remove support for reef v18 in Rook v1.19
For Rook v1.19,removing support for Ceph Reef. It is at end of life.
Users on Reef can continue to use Rook v1.18.x or older.
The latest two Ceph versions Squid and Tentacle are supported.

Signed-off-by: subhamkrai <srai@redhat.com>
2025-12-04 13:11:35 +05:30
huyejia a6239dedfe osd: replace Split in loops with more efficient SplitSeq
Signed-off-by: huyejia <huyejia@outlook.jp>
2025-11-12 16:52:12 +08:00
subhamkrai 7004213f92 mgr: add required k8s label for endpointSlice
k8s requires the endpointSlice must have label
`kubernetes.io/service-name` to be associated with
service. Without this label, the k8s service controller
can't link the EndpointSlice to the service.

Signed-off-by: subhamkrai <srai@redhat.com>
2025-10-17 15:50:55 +05:30
parth-gr e1873cb2e7 external: fix ipv6 monitoring endpoint reconcile
currently the extraction ipv6 was not correct
used the net package to extract the host ip from
the ipadress

Signed-off-by: parth-gr <partharora1010@gmail.com>
2025-09-12 12:50:05 +05:30
Travis Nielsen 3edbe6c550 Merge pull request #16402 from cuiweixie/reflect.TypeFor
operator: refactor to use reflect.TypeFor
2025-08-28 10:29:28 -06:00
Travis Nielsen 57bdd548e2 Merge pull request #16399 from travisn/update-client-profile
csi: Set the cephfs kernel mount options when network encryption is enabled
2025-08-28 10:27:02 -06:00
cuiweixie 20b3b9deef operator: refactor to use reflect.TypeFor
Signed-off-by: cuiweixie <cuiweixie@gmail.com>
2025-08-28 23:02:19 +08:00
Travis Nielsen 6309cd367e csi: default to secure kernel mount options if network encrypted
If the network is encrypted with msgr2, cephfs requires
the mount options to include ms_mode=secure. Now this
will be set by default if the mount options are not
already set in the cephcluster CR or the operator env
var CSI_CEPHFS_KERNEL_MOUNT_OPTIONS.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-08-27 16:30:47 -06:00
Travis Nielsen eeebfbf496 csi: set kernel mount options from env var if not in cluster spec
If the cephfs kernel mount options are not specified in the
cephcluster.spec.csi CR settings, fall back to the setting
in the operator env var CSI_CEPHFS_KERNEL_MOUNT_OPTIONS.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-08-27 16:11:34 -06:00
Blaine Gardner 7c33186e72 core: admin cephx key rotation
Implement CephX key rotation for Rook's client.admin user.

Admin user rotation is risky, so this has been tested extensively both
in unit tests as well as by manually injecting failures during runtime.
In testing, all failures were able to be recovered by the recovery
routine.

A mutex is also added to help ensure that two simultaneous admin key
rotation processes cannot be running simultaneously for any given
namespace. The mutex is tested in unit tests, and it was verified during
runtime via  manual testing.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2025-08-27 14:47:45 -06:00
Blaine Gardner 2fd9c9a88c core: finalize CephCluster CephX status handling
Cleanup up overall usage of CephX statuses in CephCluster.

Convert all CephX statuses to non-pointer types. There is no specific
need for pointer types, and keeping these as non-pointers means there is
not a risk of nil pointer exceptions in all the various Rook controllers
for upgraded clusters.

Move initialization of CephCluster CephX status items to
`preMonStartupActions()`. This helps resolve 2 issues:

1. 'Uninitialized' state was being set for external CephClusters where
   CephX statuses are not relevant.
2. 'Uninitialized' state was being set for upgraded clusters whose key
   status cannot be determined.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2025-08-18 14:53:08 -06:00
Travis Nielsen 36a47ac01a Merge pull request #16176 from sp98/mon-key-rotation
mon: rotate cephx key
2025-08-15 11:06:31 -06:00
Santosh Pillai fe42fe102f mon: rotate keys
rotate mon daemon keys and update the cephx status for mons in the
cephcluster resource.

Signed-off-by: Santosh Pillai <sapillai@redhat.com>
2025-08-14 11:16:39 +05:30
Blaine Gardner 59ca78229d Merge pull request #16075 from sp98/mirror-key-rotation
rbd mirror peer key rotation
2025-08-11 10:54:20 -06:00
Santosh Pillai ee0b137d75 core: rotate rbd mirror peer key
rotate the client.rbd-mirror-peer key based on the cephxconfig.
Also update the cephxStatus in the cephcluster as well as the
mirrored cephblockpool.

Signed-off-by: Santosh Pillai <sapillai@redhat.com>
2025-08-11 21:53:14 +05:30
Travis Nielsen 7b2dfdba17 Merge pull request #16150 from OdedViner/log_panics_controller
core: log panics in controller reconcile functions
2025-07-29 09:59:27 -06:00
Oded Viner cf13deee6f core: log panics in controller reconcile functions
add RecoverAndLogException() helper to log panics with stack trace.
added defer call in all rook controller Reconcile() methods for
better error visibility in operator logs

Signed-off-by: Oded Viner <oviner@redhat.com>
2025-07-29 13:20:38 +03:00
subhamkrai 1bde614eb5 core: migrate from v1.Endpoints to discoveryv1.EndpointSlice
This change updates the codebase to replace the deprecated
v1.Endpoints API with discoveryv1.EndpointSlice.
The v1.Endpoints API has been deprecated in Kubernetes v1.33+

Signed-off-by: subhamkrai <srai@redhat.com>
2025-07-23 21:02:02 +05:30
Patryk Rostkowski 7f3e6bd7fa mon: allow running mon pods as root
This change addresses a permission issue where mon pods crashloop
on some Kubernetes setups with SELinux enabled, even when
ROOK_HOSTPATH_REQUIRES_PRIVILEGED is set.

To resolve this, a new function makeMonSecurityContext() was introduced
to explicitly set runAsUser: 0 at the pod level for mon pods
when the environment variable ROOK_CEPH_MON_RUN_AS_ROOT is set to true.

Additionally, the function previously named PodSecurityContext() was renamed
to DefaultContainerSecurityContext() to avoid confusion between
container-level and pod-level security context configuration. All container
SecurityContext usages across Ceph daemons were updated to reflect this change.

This ensures the root user configuration is applied
automatically and consistently in environments where it is required
for mon pod startup, while preserving clear separation of container
and pod-level security logic.

Signed-off-by: Patryk Rostkowski <patrostkowski@gmail.com>
2025-06-16 18:29:31 +02:00
Blaine Gardner 029c345372 Merge pull request #15813 from BlaineEXE/auth-rotate
object: automate RGW cephx key rotation
2025-06-10 12:51:50 -06:00
Blaine Gardner 5f50e85a25 object: implement cephx key rotation for rgw keys
This is the first implementation of CephX key rotation in Rook.
Adds key rotation API from design PR 15915.

Also add helper methods for rotating keys, determining when keys
need to be rotated, and for generating CephX key statuses. These will be
reusable for other Rook reconciles beyond object/RGW.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2025-06-10 09:06:58 -06:00
parth-gr 79f44a4660 nfs: fix the skip reconcile call
currently nfs is used as the unique selector
for daemon id, which returns  nfs: ocs-storagecluster-cephnfs-a

Updating the has() to function to check the same label value
(n.Name + "-" + id)

Signed-off-by: parth-gr <partharora1010@gmail.com>
2025-05-30 09:11:49 +05:30
Travis Nielsen 1d93da0987 Merge pull request #15889 from patrostkowski/feature/skip-nfs-15876
nfs: skip NFS daemon reconciliation when labeled with skip-reconcile
2025-05-27 16:11:08 -06:00
Carlos Barria c63ebbe0e3 core: fix golangci-lint check ST1019
This change cleans up and standardizes import statements across the Ceph operator code. It removes redundant or duplicate imports and reorganizes alias names for improved clarity and consistency. Additionally, the ST1019 exception was removed from .golangci.yaml now that the code complies with the rule.

Signed-off-by: Carlos Barria <cbarria@yahoo.com>
2025-05-27 17:38:22 -04:00
Patryk Rostkowski 612e54e1ae nfs: skip NFS daemon reconciliation when labeled with skip-reconcile
This change adds support for skipping reconciliation of CephNFS daemons
that are labeled with `ceph.rook.io/skip-reconcile=true`.
Similar to MDS, MGR, and RGW components, this allows cluster operators
to prevent Rook from modifying specific NFS daemon deployments.

Signed-off-by: Patryk Rostkowski <patrostkowski@gmail.com>
2025-05-27 23:35:53 +02:00
Carlos Barria 4555522335 core: fix golangci-lint check ST1023 QF1011
Signed-off-by: Carlos Barria <cbarria@yahoo.com>
2025-05-20 14:53:10 -04:00
Artem Torubarov c1fd2f2ee8 rgw: use pod name in ops log filename
Signed-off-by: Artem Torubarov <artem.torubarov@sap.com>
2025-04-29 09:43:35 +02:00
Travis Nielsen f7fb1bc0f2 core: skip reconcile when adding the finalizers
When finalizers are added to the CRs, a follow-up reconcile
will be triggered due to the increased generation on the CR.
Therefore, abort the initial reconcile when adding the finalizer,
and allow the follow-up reconcile to complete the configuration.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-04-08 13:42:58 -06:00
Joshua Hoblitt 9f1ed201db core: typed watch handlers and predicates
All existing controller runtime watches are converted to use "typed"
handlers and predicates instead of operating on `client.Object`.  The
intent is to be bug for bug equivalent with the existing logic while
replacing run time type assertions and switch statements with compile
time type constraints and type casts. In several cases, functions using
assertions were split up such that each function only handles a single
Kind at a time. It is hoped that this will improve readability and
maintainability while facilitating future refactoring such as migrating
some watches to using IndexFields.

Of particular note is that the massive switch statement in
`WatchControllerPredicate()`  from
`pkg/operator/ceph/controller/predicate.go` has been replaced with
generics, reflection, and splitting the obc logic into its own predicate
function. There are still many helper functions operating on
`client.Object`. These were not updated unless required by the compiler
in order to limit the size of this change. The type safety of these
funcs should be improved as followup work.

 It is strongly suggested that going forward, handlers and predicates
 only handle a single Kind (generic or not) and that switches / type
 assertions are heavily discouraged or forbidden. This PR removed all
 but a single switch statement in a predicate, which should be addressed
 in future work.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-04-04 09:40:56 -07:00
Joshua Hoblitt 3cb343f62a core: run gofumpt on all files
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-03-26 10:41:48 -07:00
Joshua Hoblitt 607e328e6f core: rm controller-runtime predicate support for ceph_version label
This label is not currently in use by rook.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-03-21 09:34:27 -07:00
Tarun Gupta Akirala 95a911f8c3 operator: formatting issue in cosi log statement
updates the debug log line to ensure the formatting
is applied correctly.

Signed-off-by: Tarun Gupta Akirala <tarun.akirala@nutanix.com>
2025-03-05 16:47:06 -07:00
Artem Torubarov 0b2e830111 mon: support external mons in local rook cluster
Implements #14733. Allows to set IDs of external mons to
Cluster CRD. Rook will not remove external mons from quorum
and will add external mon addresses to mon endpoints.
Use-case for external mon is to maintain quorum for 2-AZ
k8s cluster in case of zone outage.

Signed-off-by: Artem Torubarov <artem.torubarov@clyso.com>
2025-03-03 14:49:39 +01:00
Travis Nielsen 3bd5881fe5 core: suppress mgr module health errors during reconcile
Some ceph health errors should not block the reconcile
of the cluster. Mgr modules do not have cause to block
the reconcile, as the cluster can usually work even
if a module is failing.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-02-27 08:10:52 -07:00