The integration tests have long been painful to maintain with
settings in various places and copied to multiple types,
inconsistent variable names, and otherwise difficult to maintain
code. Now the settings for a test suite are all in one place and
they remain in the same settings type throughout the test.
The multi-cluster suite is also refactored to use the same install
and uninstall helpers as the other suites.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
Finally! We can now stop editing manually our crds definition. Simply
run `make crds-gen`. These two files:
* `cluster/examples/kubernetes/ceph/crds.yaml`
* `cluster/charts/rook-ceph/templates/resources.yaml`
will be autogenerated for us.
We rely on the controller-gen tool, it reads our API definitions from
`pkg/apis/` and produces the CRD files accordingly.
It uses "markers" to add extra yaml fields to the CRD, for instance we
have a lot fields with:
```
nullable: true
x-kubernetes-preserve-unknown-fields: true
```
The corresponding API type markers are:
```
// +kubebuilder:pruning:PreserveUnknownFields
// +nullable
```
For more API convention see
https://github.com/kubernetes/community/blob/master/contributors/devel/sig-architecture/api-conventions.md#optional-vs-required
and for the markers see: https://book.kubebuilder.io/reference/markers/crd-validation.html
Signed-off-by: Sébastien Han <seb@redhat.com>
We now create 3 disks which will give us 2 OSDs and potentially help us
to catch more errors in our scenarios, especially on iterations.
Signed-off-by: Sébastien Han <seb@redhat.com>
this commit removes file `config-admission-controller.sh`
as we don't need this anymore and update the doc to point
`tests/scripts/deploy_admission_controller.sh` to start
admission controller.
Signed-off-by: subhamkrai <srai@redhat.com>
this commit adds new crd to admission webhooks to check
if one of the port or securePort are set to non-zero
value in objectstore crd.
If both are set to 0 in crd we'll see error like
```
Error from server (invalid create: either of port or securePort
fields should be not be zero): error when creating "object-test.yaml":
admission webhook
"cephobjectstore-wh-rook-ceph-admission-controller-rook-ceph.rook.io"
denied the request: invalid create: either of port or securePort fields
should be not be zero.
```
Signed-off-by: subhamkrai <srai@redhat.com>
we are now using cert-manager for certificates
instead of a self-signed certificate for admission
webhooks.
Signed-off-by: subhamkrai <srai@redhat.com>
codegen is currently broken in master.
this commit fix the broken codegen by fixing
the correct working directory in gh action.
Signed-off-by: subhamkrai <srai@redhat.com>
The YugabyteDB team has decided to move support of their operator
to a new repo at https://github.com/yugabyte/yugabyte-operator.
The operator in Rook is no longer needed. Further usage of
the YugabyteDB operator is recommended at the new location.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
With Ceph Pacific, Rook can now deploy the cephfs-mirror daemon.
This initial commit covers the deployment of a single daemon only.
Multiple mirror daemons is currently untested.
Only a single mirror daemon is recommended.
The configuration of peers will come in a later PR since the mgr module
is still pending upstream: https://github.com/ceph/ceph/pull/39050
The same goes for integration tests, they will get added later once we
start testing on Pacific.
Closes: https://github.com/rook/rook/issues/7002
Signed-off-by: Sébastien Han <seb@redhat.com>
this commit update admission controller to v1 from
v1beta1. v1beta1 is deprecated in v1.16+ and unavailable
in v1.22+.
Signed-off-by: subhamkrai <srai@redhat.com>
The cockroachDB operator has not had community support in Rook.
Therefore, the time has come to deprecate and remove it.
If the sources are still needed, there is always git history.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
Currently, ValidatingWebhookConfiguration has two same named webhooks.
This causes kube-apiserver to create error logs
Signed-off-by: binoue <banji-inoue@cybozu.co.jp>
Minikube deprecates '--vm-driver' option. When user starts new minkube
run with '--driver=xxx', the test will fail and cause him to use the wrong
default value of 'virtualbox'.
Tested with minikube=v1.15.1, driver=kvm2 on Fedora32.
Signed-off-by: Shachar Sharon <ssharon@redhat.com>
Users may prefer to use docker alternatives, by setting DOCKERCMD
variable, which is set by 'common.sh'. Use it in 'copy_image_to_cluster'
instead of plain 'docker'.
Tested with DOCKERCMD=podman (podman-2.1.1).
Signed-off-by: Shachar Sharon <ssharon@redhat.com>
When we are done creating the partitions it's good to give the kernel
some time to reprobe the device and for udev to finish syncing up.
Signed-off-by: Sébastien Han <seb@redhat.com>
Permissions on the disk might changed due to the partitions being
created. So the CI user is not able to read the device correctly.
Closes: https://github.com/rook/rook/issues/6580
Signed-off-by: Sébastien Han <seb@redhat.com>
This updates the chart to make use of helm3 which has been released
for some time, and also permits CRDs to be installed pror to other objects
allowing the chart to be deployed at the same time as CRs for rook objects.
Co-authored-by: Pete Birley <pete@port.direct>
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
Found by running the following command:
codespell -S .git,*.png,*.jpg -L \
aks,keyserver,atleast,dne,ser,ist,files\',ba,dum,iam,te -f -H
Signed-off-by: Mateusz Gozdek <mgozdekof@gmail.com>
Add the following scenario:
* simple osd on pvc
* osd on pvc with db device
* osd on pvc with wal device
* encrypted simple osd on pvc
* encrypted osd on pvc with db device
* encrypted osd on pvc with wal device
Signed-off-by: Sébastien Han <seb@redhat.com>
When the Ceph cluster runs on PVC and the OSDs are encrypted we can
store LUKS's Key Encryption Key inside a Key Management System. Today,
Rook only supports HashiCorp Vault: https://www.vaultproject.io/
The CephCluster has now a new "security" field which will plug onto the
KMS. Here is an example:
security:
kms:
tokenSecretName: <name of the secret containing a Vault token, used
to authenticate>
connectionDetails: < a map of strings containing connection
information>
Refer to the ceph-cluster-crd documentation to lear more.
Closes: https://github.com/rook/rook/issues/6105
Signed-off-by: Sébastien Han <seb@redhat.com>
To be able to switch to helm v3, helm itself needs to be downloaded from
get.helm.sh. The old location from googleapis.com will only contain
helm v2 binaries. See [1].
[1] https://helm.sh/blog/get-helm-sh/
Signed-off-by: Thomas Bechtold <tbechtold@suse.com>
We can't use vm-drivers other than "docker" or "none" in minikube
scripts. It's because there is no device for OSD.
Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
Download the pre-defined helm by default to make the integration test simpler.
As a result, we can make PATH/TEST_HELM_PATH environment variable optional.
In addition, the default helm path can be simplified that doesn't include arch and os.
Signed-off-by: Takashi IIGUNI <iiguni.tks@gmail.com>
Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
It's messy to answer `y` everytime in `tests/script/kubeadm.sh clean.`
Since the cluster only exists for testing, it's safe to reset without prompting.
Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
This commit will remove "sudo rm /usr/local/bin/kube*" and "sudo rm kubectl" in "tests/scripts/kubeadm.sh".
I think that CI-test doesn't make those files.
Signed-off-by: tenzen-y <toyonomajyutushi@yahoo.co.jp>
It's not necessary to use random string for mon directory.
In addition, current implementation leaves garbage under /var/lib/rook.
Signed-off-by: Takashi IIGUNI <iiguni.tks@gmail.com>
moves the admission-controller server to use controller-runtime library for better support, maintainibility of code.
Signed-off-by: Vineet Badrinath <vbadrina@redhat.com>
Update the base operator image and cluster examples to use the latest
octopus release v15.2.4. Also cleanup some old examples and unit tests
that were still based on mimic.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>