Commit Graph
111 Commits
Author SHA1 Message Date
morimoto-cybozu 0c3439c707 ceph: check LV availability by "ceph-volume lvm list"
This commit adds support for LVs to the device availability check
in the OSD prepare pod.
The availability of an LV is checked by "ceph-volume lvm list".
If it returns non-empty result, the LV is in use and not available.

Closes: https://github.com/rook/rook/issues/5075
Signed-off-by: morimoto-cybozu <kenji_morimoto@cybozu.co.jp>
2020-03-27 13:30:08 +00:00
morimoto-cybozu ab83738aac ceph: fix device path passed to "ceph-volume inventory"
This commit fixes the argument for "ceph-volume inventory".
When a device "/dev/mapper/foo" is being checked for its availability,
the argument should not be "/dev/foo" nor "/dev/dm-1".

Signed-off-by: morimoto-cybozu <kenji_morimoto@cybozu.co.jp>
2020-03-27 11:24:47 +00:00
Satoru Takeuchi 8a13310ddb ceph: Consider the various paths of sgdisk
The path of sgdisk depends on the systems.

Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
2020-03-25 12:27:14 +00:00
Sébastien Han e96dc646a2 rook: add ExecuteCommandWithEnv
We can now execute commands and pass env variables to the executor.

Signed-off-by: Sébastien Han <seb@redhat.com>
2020-03-20 17:37:58 +01:00
Travis Nielsen e8f9cfcb71 exec: always write commands to debug log
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-03-19 07:49:54 -06:00
Travis Nielsen f2ecaa2bda exec: remove the unused actionName param
The helpers for executing a process have long required an actionName
param which is not being used. Now we remove the old param
while also cleaning up various other usages of the exec
package.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-03-19 07:49:53 -06:00
Travis Nielsen 84b8cdcf75 exec: simplify the exec package from unused methods and logging
The methods and arguments to the exec methods are not all used anymore.
This cleans up the methods to only what is necessary to improve
the readability and maintainability.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-03-19 07:49:53 -06:00
Travis Nielsen 7d2811bfb6 ceph: remove obsolete ipv4 command line flags
Long ago the ipv4 flags were renamed to public-ip and private-ip
so we can go ahead and remove the obsolete flags.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-03-19 07:49:53 -06:00
Travis Nielsen 0344074c82 ceph: remove dead code for process management
Rook no longer relies on its own process management, now we can rely
completely on Kubernetes to manage the pod lifecycle. The code
to check for running processes and replacement them hasn't been
used for a long while.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-03-19 07:49:53 -06:00
Sébastien Han a3068dee0b ceph: separate controller for CephBlockPool CRD
Now, the CephBlockPool CRD is managed with the controller-runtime.
So the watcher is outside of the main controller reconciliation loop of
CephCluster which brings numerous benefit such as:

* having its own reconciliation loop
* won't block anything from the main CephCluster controller loop
* fast than waiting for CephCluster loop to completion

Partially close: https://github.com/rook/rook/issues/1981
Signed-off-by: Sébastien Han <seb@redhat.com>
2020-03-02 17:31:03 +01:00
Sébastien Han 65e1c054a3 ceph: only print command when running debug mode
We don't need commands e run under the hood. Enable debug logs to see
that.

Signed-off-by: Sébastien Han <seb@redhat.com>
2020-03-02 09:29:48 +01:00
Nizamudeen 53883f68cf ceph: Handling Unhandled errors
This commit is to handle all those unhandled errors which raises the gosec warning.

Fixed G104: Unhandled Errors are handled now

Signed-off-by: Nizamudeen <nia@redhat.com>
2020-02-21 22:48:24 +05:30
Nizamudeen 78ef4abeec ceph: Fixing the potential file inclusion error
This commit is also part of gosec error handling which handles the following issue:

Fixed G304: Potential File inclusion by cleaning up the file path

Signed-off-by: Nizamudeen <nia@redhat.com>
2020-02-14 12:22:49 +05:30
Sébastien Han c08c3ced05 ceph: add support for metadata PVC for OSD on PVC
We now support the addition of the PVC that acts as a metadata device
for a given OSD.
For this, you need to create a new `volumeClaimTemplates`, its name must
be "metadata" otherwise, Rook won't pick it up.

A template will look like this:

```
volumeClaimTemplates:
- metadata:
    name: data
  spec:
    resources:
      requests:
        storage: 10Gi
    # IMPORTANT: Change the storage class depending on your environment (e.g. local-storage, gp2)
    storageClassName: gp2
    volumeMode: Block
    accessModes:
      - ReadWriteOnce
- metadata:
    name: metadata
  spec:
    resources:
      requests:
        storage: 6Gi
    # IMPORTANT: Change the storage class depending on your environment (e.g. local-storage, gp2)
    storageClassName: gp2
    volumeMode: Block
    accessModes:
      - ReadWriteOnce
```

We now map block and block.db directly inside the container instead of
running ceph-volume activate. This is much cleaner.

Closes: https://github.com/rook/rook/issues/3852
Signed-off-by: Sébastien Han <seb@redhat.com>
2020-02-11 17:30:02 +01:00
Sébastien Han 227d2d527a ceph: osd store refactor
Multiple things:

1. We removed all the function/methods/tests that were used to
create and manage rook legacy OSDS as well as bringing support to
Bluestore OSD only.
It also fixes various go-lint issues in the respectives files.

2. use c-v inventory to detect available devices:
Now we rely on the 'ceph-volume inventory' command to tell us if a
device is available or not.

3. implement raw mode for osd on pvc
When an OSD will be bootstrap on a PVC, the new c-v raw mode will be
used. It consists of putting block, db and wal under the same device.
Here LVM is out of the picture and the raw device is used as is. The
implementation is backward compatible so existing OSD on PVC will LVM
will continue to operate.

Closes: https://github.com/rook/rook/issues/4363
Signed-off-by: Sébastien Han <seb@redhat.com>
2020-01-23 19:13:09 +01:00
Sébastien Han dd659de46f ceph: add partition support
We now support partitions via 2 ways:

* if `useAllDevice: true`: partitions will be taken into account and
presented as OSD candidate
* if specified in the cluster CR: it'll picked up as well

Signed-off-by: Sébastien Han <seb@redhat.com>
2020-01-16 09:34:46 +01:00
Travis Nielsen e2dcfc6330 util: no verbose logging for retry messages
The retry messages are too verbose with the stack trace
since the aggregated messages were added. This change
turns off the verbose message.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-01-07 12:18:54 -07:00
Juan Miguel Olmo Martínez 7b3e2b006e ceph: Do not log sensitive information in debug mode
Fix security issues identified by TrailOfBits:
Logging of sensitive information in debug mode

Problematic debug lines which can contain sensitive data have been removed

Resolves: #4568

Signed-off-by: Juan Miguel Olmo Martínez <jolmomar@redhat.com>
2020-01-03 17:16:25 +01:00
Sébastien Han 04ad1636c8 ceph: reject ceph dm devices
Since https://github.com/rook/rook/pull/4219, lv devices are now
presented to ceph-volume when preparing the device.
So on this initial run, this won't fail because the dm hasn't been
created yet but if an orchestration is re-triggered, the prepare pod
ensures idempotency with the ceph-volume batch command.
Unfortunately, c-v seems to have a bug where it doesn't read the dm to
detect whether or not they are ceph members already.
Ceph bug: https://tracker.ceph.com/issues/43209

Signed-off-by: Sébastien Han <seb@redhat.com>
2019-12-09 16:17:26 +01:00
dulltzandSatoru Takeuchi dfe45ac6b0 ceph: support OSD on PVC backed by LV
"OSD on PVC" doesn't work for PV backed by LV. Fixing this problem
by the following changes.

- Rook accepts LVM disk type.
- If a LV-backed device is passed, Rook/Ceph invokes
  "ceph-volume lvm prepare" with "--data vg/lv"
  instead of "--data /path/to/device".
- If a LV-backed device is passed, Rook/Ceph suppresses
  activation/deactivation of VG that owns this LV.

Fixes: https://github.com/rook/rook/issues/4185
Signed-off-by: dulltz <isrgnoe@gmail.com>
Co-authored-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
2019-12-05 17:26:27 +00:00
Guangming Wang 950af10e62 cleanup: cleanup codebase
device.go: replace string func Index with Contains.

Signed-off-by: Guangming Wang <guangming.wang@daocloud.io>
2019-11-07 19:45:43 +08:00
Guangming Wang a9063c27e9 cleanup: cleanup codebase
monitoredproc_test.go: remove redundant break.

Signed-off-by: Guangming Wang <guangming.wang@daocloud.io>
2019-11-07 19:45:39 +08:00
Guangming Wang e5e0369e37 cleanup: cleanup codebase
exec.go: use String method of bytes itself.

Signed-off-by: Guangming Wang <guangming.wang@daocloud.io>
2019-11-07 19:45:32 +08:00
Juan Miguel Olmo Martínez 7c942604f6 ceph: Get <ceph-volume inventory> data in dev. configmaps
**Description of your changes:**
This modification adds the information extracted from 'ceph-volume inventory':
command to the device configmaps generated by the discovery daemon when
"rook discover" starts with the new boolean "--use-ceph-volume" parameter.

Resolves #
https://github.com/rook/rook/issues/2606

Now the <cephVolumeData> field contains all the information returned
from <ceph-volume inventory> command.

Signed-off-by: Juan Miguel Olmo Martínez <jolmomar@redhat.com>
2019-11-06 10:22:56 +01:00
Santosh Pillai 8ea693a740 ceph: fix operator reconcile to restart osds daemons
OSD on PVC does not upgrade when the user upgrades the ceph version on cluster-on-pvc yaml.
The solution incudes:
   - upgrade osd prepare and daemon pods on upgrade
   - skip c-v prepare if filesystem is already present on the pvc device.
   - skip lvm release in case of upgrade.

Signed-off-by: Santosh Pillai <sapillai@redhat.com>
2019-10-23 16:56:15 +05:30
Mikaël Cluseau 0267433484 fix: PARTNAME override ID_PART_ENTRY_NAME
When both PARTNAME and ID_PART_ENTRY_NAME are specified, rook takes
PARTNAME in account, overriding ID_PART_ENTRY_NAME. As PARTNAME is not
always updated by the kernel after sgdisk --change-name, it's better to
do the opposite. It also makes GetDevicePartitions coherent with
parsePartLabel (called by GetPartitionLabel).

Signed-off-by: Mikaël Cluseau <mikael.cluseau@gmail.com>
2019-10-22 09:23:48 +11:00
rohan47andAshish Ranjan d2f52aebe5 Adds support for storageClassDeviceSet in rook-ceph operator
- Added code to support StorageClassDeviceSet spec provided in the cluster-on-pvc.yaml
- The code reads the StorageClassDeviceSet spec and creates pvc based on the ‘count’ field for each device set.
- OSD prepare job is started for each PVC which activates the ceph-volume on each PVC
- Finally OSD is started on each of the PVC device.

Co-authored-by: rohan47 <rohgupta@redhat.com>
Co-authored-by: Ashish Ranjan <aranjan@redhat.com>
Signed-off-by: Santosh Pillai <sapillai@redhat.com>
2019-08-12 09:24:13 -06:00
Ash Wu e6d43d9d0b Add linear to support diskType
Linear raid can be created using `mdadm --create --level=linear`,

By creating a linear raid disk on top of a logical volume,
we can pass the linear device to `ceph-volume lvm batch --prepare`
to provision a new OSD on top of the logical volume since
`ceph-volume` does not take lv as the data device.

Signed-off-by: Ash Wu <hSATAC@gmail.com>
2019-07-10 11:14:26 +08:00
Guy Margalit 2ce2382676 Refactor operator context init and allow to run local
Signed-off-by: Guy Margalit <guymguym@gmail.com>
Co-Authored-By: Sébastien Han <seb@redhat.com>
Co-Authored-By: Travis Nielsen <tnielsen@redhat.com>

This change is meant to allow running operators locally on a developer machine.
The idea is to allow faster development cycles by reducing the time and complexity of building -> deploying -> debugging on cluster.

For operators that rely only on kubernetes API this works easily - see cockroachdb and minio examples in development-flow doc.

The change includes:

- rook.NewContext() - Refactored to remove repeating initialization code that was copy-pasted in most of the operators in order to create the clusterd.Context and the Clientsets. Also it detects the mode of working in-cluster vs external and sets up the external mode with standard user config (~/.kube/config) and a job executor.
- rook.GetOperatorImage() - Refactor this repeating code in many operators to detect the operator pod image. Also added a global flag --operator-image that developers can use to override this when running locally.
- rook.TerminateOnError() - Added a convenient function.
2019-06-19 20:47:55 +03:00
Noah Watkins b29ba26b12 exec: add timeout variant of exec with output file
the existing exec interface with timeout is effectively the same as
ExecuteCommandWithOutput plus a timeout. this patch adds a variant of
ExecuteCommandWithOutputFile that uses a timeout.

Signed-off-by: Noah Watkins <noahwatkins@gmail.com>
2019-05-06 10:10:05 -07:00
Sébastien Han 871054e887 ceph: implement pod restriction on memory
If someone sets limits to pod, we want to ensure the possible
experience, so we want to make sure that people do not configure
inapropriate values for certain daemons.
We decide to fail if the memory.limit is too low.

Signed-off-by: Sébastien Han <seb@redhat.com>
2019-03-15 17:35:44 +01:00
travisn bdc3cf8146 osd: fix the device filter and improve device provisioning reliability
All devices detected by the discovery pod were being passed to the OSD provisioning pod
thus not always honoring the desired device list that should be provisioned.
Now the provisioning pod will be given the desired state from the crd,
then apply that state depending on the actual devices detected.
Also added a helper to ensure OSDsPerDevice is always valid.

Signed-off-by: travisn <tnielsen@redhat.com>
2019-02-26 16:11:25 -07:00
Noah Watkins fbb56c41ed exec: interleave stdout/stderr logging
The io.MultiReader(r1, r2) reads r1 until EOF before moving on to r2.
When used for stdout/stderr stderr will not be written to the log until
stdout reaches EOF. This patch reads stderr in a go routine so that the
two streams can be interleaved properly.

Fixes: #2479

Signed-off-by: Noah Watkins <noahwatkins@gmail.com>
2019-01-24 13:10:46 -08:00
travisn f7c266f7ec skip sgdisk detection if not found in nautilus image
Signed-off-by: travisn <tnielsen@redhat.com>
2018-12-06 21:28:57 -07:00
Alexander Trost b12d1e82cf Use truncated node name "everywhere"
Signed-off-by: Alexander Trost <galexrt@googlemail.com>
2018-11-23 10:02:35 +01:00
Angus Lees 9c95ed5f6f Don't misinterpret command output as string format
Previous code tried to interpret the string output as a `fmt.Sprintf`
string formatter, mangling `%` into `%!(MISSING)`, etc.

Thanks to go, I don't belive these are exploitable (unlike the similar
error in C).

Since this seemed to be a common error in the codebase, I did a quick
audit by visually inspecting the results of `git grep 'f([^"]'`.  I
don't have a good suggestion for automated tests to prevent this in
future :(

Example error (look for `(MISSING)`):
```
E0927 05:31:07.618429   11227 driver-call.go:237] Failed to unmarshal output for command: unmount, output: "2018-09-27 05:31:07.191711 I | exec: Running command: df --type ceph /var/lib/kubelet/pods/95461479-c216-11e8-bcf0-02030782ac80/volumes/ceph.rook.io~rook/oe-scratch\n2018-09-27 05:46:43.808596 I | Filesystem                                                 1K-blocks     Used Available Use%!M(MISSING)ounted on\n2018-09-27 05:46:43.808659 I | 10.107.25.147:6790,10.109.173.79:6790,10.104.85.255:6790:/ 151678976 49410048 102268928  33%!/(MISSING)var/lib/kubelet/pods/95461479-c216-11e8-bcf0-02030782ac80/volumes/ceph.rook.io~rook/oe-scratch\n{\"status\":\"Success\"}\n", error: invalid character '-' after top-level value
```

Signed-off-by: Angus Lees <gus@inodes.org>
2018-10-15 15:59:13 +11:00
Ganesh Maharaj Mahalingam 30dcd26da9 Enable glog logging
Change enables glog logging and also make default flag values
configurable.

Signed-off-by: Ganesh Maharaj Mahalingam <ganesh.mahalingam@intel.com>
2018-09-24 13:17:25 -07:00
Ganesh Maharaj Mahalingam 92f91ab156 golang 1.11 support
Signed-off-by: Ganesh Maharaj Mahalingam <ganesh.mahalingam@intel.com>
2018-09-12 10:53:53 -07:00
Dennis Chen 9cfafaa0a7 Enhancement of Ceph volume manager kmod detection
Current Ceph volume manager code doesn't take the builtin
kernel module into the account, so the `modinfo` will fail
in this case. Also, we need to add error handling code to
make sure the volume manager does work when proceeding to
continue, otherwise we will encounter the `rbd` related issue
in the following step even we have an artificial `agent` pod
in running state.

Signed-off-by: Dennis Chen <dennis.chen@arm.com>
2018-07-31 16:56:40 +08:00
Blaine Gardner fe5fb394c7 Fix spellcheck and trailing space/newline issues
Fix some basic spellcheck errors. Also remove trailing spaces and make
sure files have a newline (my editor does automatically).

Signed-off-by: Blaine Gardner <blaine.gardner@suse.com>
2018-07-26 11:36:09 -06:00
Huamin Chen dc1e827cce get partlabel from udev info PARTNAME
Signed-off-by: Huamin Chen <hchen@redhat.com>
2018-07-05 16:09:21 -06:00
travisn f1ad88e0ac tests: enable osds on devices
Signed-off-by: travisn <tnielsen@redhat.com>
2018-07-05 16:09:20 -06:00
Huamin Chen 82425aafcc prepare osd in a job per node. Once all osds are prepared, store osd info in orchestration configmap.
Operator watches the configmap, starts one osd replica set per osd.

Signed-off-by: Huamin Chen <hchen@redhat.com>
2018-07-05 16:02:27 -06:00
Evgeniy Klemin 759ec55f64 Fix retrieve device label
Signed-off-by: Evgeniy Klemin <evgeniy.klemin@gmail.com>
2018-06-27 13:31:46 +03:00
Jared Watts 48b879e0ad Merge pull request #1769 from ucloudlab/ipv6-support
support ipv6
2018-06-19 20:33:12 -07:00
travisn d5d3540497 osd: detect disk uuid with sgdisk
Signed-off-by: travisn <tnielsen@redhat.com>
2018-06-19 13:05:51 -07:00
Aayush Sarva 80f3e8ebf4 Replace custom Awk and remove related tests
Signed-off-by: Aayush Sarva <checkaayush@gmail.com>

Return error if field not found

Signed-off-by: Aayush Sarva <checkaayush@gmail.com>
2018-06-19 05:03:28 +05:30
Zhang Miaolei 100e80250f support ipv6 host-port pair
deprecate NetworkInfo.PublicAddrIPv4, use NetworkInfo.PublicAddr instead
deprecate NetworkInfo.ClusterAddrIPv4, use NetworkInfo.ClusterAddr instead
deprecate command flag public-ipv4, use public-ip instead
deprecate command flag private-ipv4, use private-ip instead
change ROOK_PUBLIC_IPV4 to ROOK_PUBLIC_IP
change ROOK_PRIVATE_IPV4 to ROOK_PRIVATE_IP

Signed-off-by: Zhang Miaolei <zmlcc@outlook.com>
2018-06-15 14:26:42 +08:00
Huamin Chen 6c11ff52d4 add device discovery daemon to operator:
run "rook discover" on storage nodes and discover devices on each node. The discovered disks are saved in a per node configmap, local-device-nodename.
Device information consits of name and persistent names, uuid, partition, filesystem, rotational, readonly, size, etc.

Signed-off-by: Huamin Chen <hchen@redhat.com>
2018-05-07 17:49:02 +00:00
Jared Watts 6a2e20aaa8 include stderr output in CommandError.Error() output
Signed-off-by: Jared Watts <jbw976@gmail.com>
2018-03-28 13:26:00 -07:00