As like RBD, CephFS provisioner pod need not to
run as privileged. as its not doing any operation
like plugin pods which does mounting and unmounting
removing the permissions for the same.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
There was a log line that informed that the object store status would
not be updated because the status was deleting erroneously. Move the
line to the correct position.
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
added new option to set the provisioner replicas.
with this new option the user/admin can choose
how many replicas he want for provisioner pod if
number of nodes is greater than 1.
fixes#8153
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
With the release of Ceph CSI 3.4.0, Ceph CSI project came up
with a new support policy where we support only versions >= 3.3.0
The supported window of Ceph CSI versions is known as "N.(x-1)":
(N (Latest major release) . (x (Latest minor release) - 1)).
For example, if Ceph CSI latest major version is 3.4.0 today,
support is provided for the versions above 3.3.0.
If users are running an unsupported Ceph CSI version, they will be
asked to upgrade when requesting support for the cluster.
This PR lift the minimum supported version of Ceph CSI to 3.3.0
in this repo.
Fix https://github.com/rook/rook/issues/8709
Ref #
https://github.com/ceph/ceph-csi/releases/tag/v3.4.0https://github.com/ceph/ceph-csi/#known-to-work-co-platforms
Signed-off-by: Humble Chirammal <hchiramm@redhat.com>
If the cluster where the rgw is started is secondary and not primary,
trying to create the admin ops user will fail with:
```
Please run the command on master zone.
Performing this operation on non-master zone
leads to inconsistent metadata between zones
```
So we need to force the creation regardless, it is fine the creation will
return UserAlreadyExist and then we just read the current user.
Closes: https://github.com/rook/rook/issues/8671
Signed-off-by: Sébastien Han <seb@redhat.com>
The MDS core team suggested with deploy the MDS daemon first and then do
the filesystem creation and configuration. Reversing the sequence lets
us avoid spurious FS_DOWN warnings when creating the filesystem.
Closes: #8745
Signed-off-by: Sébastien Han <seb@redhat.com>
The new version v16.2.6 has a different behavior when it comes to the
number of cephfs-mirror socket files. Previous version had exactly 3 and
now has like way more...
So let's just check for the presence of more sockets.
Signed-off-by: Sébastien Han <seb@redhat.com>
Rook now exports both ceph and csi SCCs to run on openshift so any
program pulling rook can inject the right SCCs.
In the meantime, default SCC has been reinforced to be less permissive.
Documentation has been reworked and a new path for openshift
installations has been created. Rook still provides the YAML files for
manual installations.
Closes: #8713
Signed-off-by: Sébastien Han <seb@redhat.com>
When private/public network have been defined in the Ceph rook cluster it is not
possible to configure properly the ip address of the liveness probe
for the manager.
Changes in the manager in Pacific introduced this regression.
This change replaces the http probe by a command probe, avoiding thus to
determine what is going to be the ip address of the manager before launching
the pod.
fixes: https://github.com/rook/rook/issues/8510
Signed-off-by: Juan Miguel Olmo Martínez <jolmomar@redhat.com>
The `*SuiteMinimalTestVersion` vars in
`tests/integration/ceph_base_deploy_test.go` are no longer needed with
Jenkins no longer being used. Remove them.
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
If the CephObjectStore health checker fails to be created, return a
reconcile failure so that the reconcile will be run again and Rook will
retry creating the health checker. This also means that Rook will not
list the CephObjectStore as ready if the health checker can't be
started.
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
The CephSmokeSuite is becoming quite large and long, and most of the
length is now related to the object e2e tests. Separate the full object
e2e test into CephObjectSuite, and only test the object 'lite' test in
the CephSmokeSuite.
Resolves#8714
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
This commit is a large refactor on how the operator starts, stops and
how it starts various sub-components such as the ceph-csi driver. It
also refines the way we cancel orchestrations. We don't use breakpoints
anymore but send our self a SIGUP to reload our controller runtime
manager.
The reload will happen under different circonstances like:
* a new adminission controller secret is created/deleted/changed
* a CephCluster CR is edited
As mentioned earlier, the csi driver now has its own controller, just
like flex. It reacts to change in the operator config map for particular
ROOK_CSI_ fields.
A second new controller for the operator's general config has been
created, it manages:
* the logging level
* the ceph CLI command timeout
* the discovery daemon
The operator reacts much more rapidly to cancellation events by stopping
the manager's context and reloading it.
Signed-off-by: Sébastien Han <seb@redhat.com>
We don't need to use github.com/ghodss/yaml since
"k8s.io/apimachinery/pkg/util/yaml" provides the same functionality and
we already import it.
Signed-off-by: Sébastien Han <seb@redhat.com>
Let's force v16.2.5 since the CI is broken with 16.2.6. This gives us
time to continue to merge work and work on fixing deployments with
16.2.6 in parallel.
Signed-off-by: Sébastien Han <seb@redhat.com>
The steps to configure the peers are detailed in the CephFilesystem
section. Only the CephFilesystem is holding the peer configuration, not
the CephFilesystemMirror which only controls the bootstrap of the
daemon.
Signed-off-by: Sébastien Han <seb@redhat.com>
Let's be a bit more aggressive to ensure a consistent amount of
in-progress PRs and issues.
So now PR will go stale after 30 days and issues after 60 days.
Signed-off-by: Sébastien Han <seb@redhat.com>
Remove legacy documentation for configuring RBD mirroring. While we
still support legacy mirroring configs, we want to encourage new users
to use the CephBlockPool configuration for mirroring.
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>