Commit Graph
260 Commits
Author SHA1 Message Date
travisn fd341ae928 ceph: set the fsgroup only on the top level of the mount
If setting the fsgroup recursively on a shared filesystem mount is
not desirable, the fsgroup capability on the flex driver
should first be disabled in the operator env vars. Now the driver
will apply the fsgroup only at the top level instead of
recursively for the entire shared filesystem.

Signed-off-by: travisn <tnielsen@redhat.com>
2019-06-06 17:17:29 -07:00
travisn 7cdfcc395a write flex settings to config file instead of env vars
The flex settings cannot be passed to the driver with environment variables.
There is no context available for returning the flex settings except
that the flex driver will look in a config file in the same directory.
These settings must be valid or else the driver will return the default
settings.

Signed-off-by: travisn <tnielsen@redhat.com>
2019-04-30 14:50:43 -06:00
travisn 20f6af8a4d remove obsolete flex driver version checks
The flex driver no longer needs to check whether a kubelet
restart is needed or whether the namespace-specific driver
can be supported. The copy of k8s 1.13 types can also
be removed since we have updated to a newer k8s client.

Signed-off-by: travisn <tnielsen@redhat.com>
2019-04-30 14:50:33 -06:00
Ashish Ranjan dac028ab24 enhance(nfs): remove one to one mapping for nfs provisioner
Signed-off-by: Ashish Ranjan <ashishranjan738@gmail.com>

This commit removes one to one mapping of NFS provisioner and adds a dedicated provisioner for nfs.
2019-04-26 20:52:30 +05:30
Ashish Ranjan 858c8eede7 refactor(operator): removed wild card from the operator
Signed-off-by: Ashish Ranjan <ashishranjan738@gmail.com>
2019-04-26 04:25:49 +05:30
Ashish Ranjan 23efbf658b enhance(NFS): adds dynamic provisoning for nfs
Signed-off-by: Ashish Ranjan <ashishranjan738@gmail.com>

This commit adds dynamic provisioning for nfs
2019-04-26 04:25:49 +05:30
travisn bc87b440fb update to the k8s 1.14 client libraries
Signed-off-by: travisn <tnielsen@redhat.com>
2019-04-18 07:51:41 -06:00
travisn 91e9a5cd04 reference K8s1.13 and client-go 1.10 and the external provisioner for flex
Signed-off-by: travisn <tnielsen@redhat.com>
2019-04-18 07:51:41 -06:00
Alexander Trost 0c6eb7aa3d crds: Set annotations pods, deployments and so on
Allow the user to set annotations in the CRDs of the following operators which will then be set on
the resulting Pods (Deployments, StatefulSets and so on).
Operators:
* Cassandra
* Ceph
* CockroachDB
* EdgeFS
* Minio
* NFS

The Annotations related structures have been added to the
rook.io/v1alpha2 pkg.

Signed-off-by: Alexander Trost <galexrt@googlemail.com>
2019-04-16 20:47:05 +02:00
Alexander Trost 8bc26d9096 k8sclient: Update all operators to use apps/v1
All usages of k8s go client are now also using the versioned `AppsV1() `
call for the client.

Updated MySQL and Wordpress, and Kube Registy examples to use apps/v1
Deployments.

Signed-off-by: Alexander Trost <galexrt@googlemail.com>
2019-04-12 09:25:42 +02:00
John Mulligan 7ee207b0fb ceph csi: tweak options handling around enabling csi
Simplify one function and improve option wording.

Signed-off-by: John Mulligan <jmulligan@redhat.com>
2019-04-10 17:53:28 -04:00
Madhu Rajanna d9dd81396c remove attacher statefulset for rbd csi driver
deploy attacher as a container inside  rbd provisioner
stateful set

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2019-04-10 18:27:08 +05:30
Noah Watkins 379cb98689 ceph: replace release name with fine-grained version
The basic idea here is to replace the release name in the ClusterInfo
object with the fine grained version information queried at runtime.
This patch also removes the Name field from the cluster spec, which was
also runtime determined and was redundant with ClusterInfo relase name.

Signed-off-by: Noah Watkins <noahwatkins@gmail.com>
2019-03-18 12:57:29 -07:00
Blaine Gardner 086fa8231c rgw: configure entirely in operator
Configure the Ceph rgw daemon completely from the operator a la the
recent changes to the Ceph mon, mgr, and mds operators.

Create the rgw deployment or daemonset first, and then create the
keyring secret for the object store with its owner reference as the
corresponding deployment or daemonset. When the replication controller
is deleted, the secret is also deleted.

The RGW's mime.types file is now stored in a configmap with a different
file created for each object store. This is primarily just a means to
get the mime.types file into the rgw pod, but the added benefit is that
the administrator can modify the configmap, which could reduce
susceptibility to file type execution vulnerabilities (worst case).

Signed-off-by: Blaine Gardner <blaine.gardner@suse.com>
2019-03-07 08:02:42 -07:00
Travis Nielsen a145f4dcb7 Merge pull request #2703 from travisn/osds-per-device-with-filter
Clean up provisioning of OSDs on devices
2019-03-04 07:58:56 -07:00
Blaine Gardner 4eb4fb7aa6 ceph mds: configure completely from operator
Configure the Ceph mds daemon completely from the operator a la the
recent changes to the Ceph mon and mgr operators.

Create the mds deployments first and then
create the keyring secrets for them with their owner reference as the
corresponding deployment. This will mean that the secrets do not need to
be micromanaged. When the deployment is deleted, the secret is also
deleted. This has not been necessary for the mons or the manager since
the mons share a keyring with a lifespan of the cluster, as does the
mgr, which currently has single-mgr support only.

Signed-off-by: Blaine Gardner <blaine.gardner@suse.com>
2019-02-28 12:31:43 -07:00
travisn bdc3cf8146 osd: fix the device filter and improve device provisioning reliability
All devices detected by the discovery pod were being passed to the OSD provisioning pod
thus not always honoring the desired device list that should be provisioned.
Now the provisioning pod will be given the desired state from the crd,
then apply that state depending on the actual devices detected.
Also added a helper to ensure OSDsPerDevice is always valid.

Signed-off-by: travisn <tnielsen@redhat.com>
2019-02-26 16:11:25 -07:00
Travis Nielsen eea375ece7 Merge pull request #2698 from darshanime/unhide_cobra
unhide cobra commands
2019-02-22 14:11:12 -07:00
darshanime f24230481f unhide cobra commands
Signed-off-by: darshanime <deathbullet@gmail.com>
2019-02-22 14:04:21 +05:30
Sébastien Han eb3c424d57 Ceph messengers 2 support
This commit introduces the necessary changes to support the new
messenger feature coming with Ceph Nautilus (currently in development).

What changes? Now the monitor listens on two port:

* old 6789 for messenger v1, which will help us support older client
(e,g: krbd)
* new 3300 for messengers v2, which brings new improvement in the
messaging layer. This new transport layer brings numerous advantages
such as encryption improvement, speed improvement, pluggable nature to
support different network stack than TCP and many more.

We still have one Service IP, however it has 2 ports, see:

```
NAME                      TYPE        CLUSTER-IP       EXTERNAL-IP   PORT(S)             AGE
rook-ceph-mon-a           ClusterIP   10.106.217.160   <none>        3300/TCP,6789/TCP   4h
rook-ceph-mon-b           ClusterIP   10.99.36.175     <none>        3300/TCP,6789/TCP   4h
rook-ceph-mon-c           ClusterIP   10.108.220.74    <none>        3300/TCP,6789/TCP   4h
````

The `ceph.conf` has changed and we don't force the port when using an IP
address (public addr etc). Ceph, depending on its version will naturally
start the monitors on their right port, 6789.

A new --ceph-version-name CLI argument has been added to the Rook binary
so that when the pod starts it passes the ceph version name and the
configuration of the ceph.conf, as well as daemon startup flags, happen
properly.

Given that the Rook Operator remembers the port of all the monitors it
deployed (through Pod definition), this change is not an issue and will
maintain backward compatibility.

Note that to test this you must build rook with dev container image,
which contains the dev Nautilus version. So you should do something
like:

`make -j4 BASEIMAGE='ceph/daemon-base:latest-master' IMAGES='ceph' build`

Resolves: #2525
Signed-off-by: Sébastien Han <seb@redhat.com>
2019-02-22 00:09:37 +01:00
Travis Nielsen 649f5977fc Merge pull request #2511 from humblec/final
This PR contains linter corrections on various sources.
2019-02-20 11:01:03 -07:00
Humble Chirammal 5a899a7c7d linter corrections on various sources.
*) Remove punctuation/newline at error strings.
*) Document exported functions and variables.

Signed-off-by: Humble Chirammal <hchiramm@redhat.com>
2019-02-20 19:29:54 +05:30
Travis Nielsen a5aadf0701 Merge pull request #2580 from rootfs/csi-driver
Deploy ceph-csi driver
2019-02-13 08:31:13 -07:00
Huamin Chen 3806baffe1 add ceph csi deploy options
Signed-off-by: Huamin Chen <hchen@redhat.com>
2019-02-12 21:20:41 -05:00
Blaine Gardner 03ea5f0a7c ceph mgr: configure completely from operator
Configure the Ceph mgr daemon completely from the operator a la the
recent changes to the Ceph mon operator.

The pod spec for the mgr changed quite a bit, and instead of updating
the unit tests of questionable use, some additional unit test tools
applicable to any Ceph daemon have been added and used with the mgr. The
mgrs unit tests should now be more useful and get in the way of devs
less, and they can be used by other daemons later.

Signed-off-by: Blaine Gardner <blaine.gardner@suse.com>
2019-02-11 14:35:01 -07:00
Blaine Gardner ec416cdd92 ceph mons: set up entirely in operator
Make the Rook config-init unnecessary for mons, and remove that init
container. Perform all mon configuration steps in the operator, and set
up the mon pods and k8s environment such that only Ceph containers are
needed for running mons.

This should help streamline changes to the mons, as there will be no
need to change the `daemon/mon` code or `cmd/rook/ceph` code with mon
changes in the future.

This work starts to lay the groundwork for supporting the
`design/ceph-config-updates.md` design.

Notable new bits:

Create a keyring secret store helper for storing dameon keyrings, and
use it to store the mon keyring. Mon pods mount the keyring into a
k8s secret-backed volume.

Create a configmap store for the Ceph config file which can be mounted
into pods/containers directly to /etc/ceph/ceph.conf. Also store
individual mon_host and mon_initial_members values which can be mapped
into pods as environment variables and used in Ceph commandline flags,
enabling the mon pods to have the most up-to-date information about the
mon cluster when restarting and without need for operator intervention.

Signed-off-by: Blaine Gardner <blaine.gardner@suse.com>
2019-02-05 06:19:59 -07:00
travisn bd25630d91 allow disabling of fsGroup in the flex driver
Signed-off-by: travisn <tnielsen@redhat.com>
2019-01-24 07:53:44 -07:00
Madhu Rajanna 6349ce8e0d cassandra,edgefs: Fix misspelled words
This PR fixes the misspelled words in comment
and struct fields.

Signed-off-by: Madhu Rajanna <mrajanna@redhat.com>
2019-01-17 15:40:05 +05:30
Humble Chirammal 36112b2a86 This PR contains linter corrections on various sources.
*) Remove punctation at error strings.
*) Document exported functions and variables.

Signed-off-by: Humble Chirammal <hchiramm@redhat.com>
2019-01-17 08:52:50 +05:30
travisnandjtlayton 37a005b71e nfs: configure and start daemons when the nfs crd is created
Co-authored-by: jtlayton <jlayton@redhat.com>
Signed-off-by: travisn <tnielsen@redhat.com>
2019-01-15 13:48:58 -07:00
Timothy Allen ae46f31882 Add ENV flag for selinux labeling
Signed-off-by: Timothy Allen <kex.allen13@gmail.com>
2019-01-10 15:05:39 +00:00
travisn 261aae3f46 mgr: set the server_addr for the dashboard and prometheus modules
Signed-off-by: travisn <tnielsen@redhat.com>
2018-12-20 12:08:37 -07:00
Jared Watts 99379308ba Merge pull request #2325 from yanniszark/cassandra-operator-scale-down-implementation
[cassandra operator] Scale Down Implementation
2018-12-07 12:28:06 -08:00
travisn fe4a645844 osd: detect existing osds not to be passed to ceph-volume
Signed-off-by: travisn <tnielsen@redhat.com>
2018-12-07 10:50:37 -07:00
travisn 1389cc56db ceph: enable multiple osds per device
Signed-off-by: travisn <tnielsen@redhat.com>
2018-12-07 09:29:15 -07:00
Yannis Zarkadas a9178ccb59 cassandra: sidecar-side implementation of scale down
The sidecar now has a control loop, which watches its ClusterIP
Service for the `cassandra.rook.io/decommissioned` label.
If it finds it, then it decommissions and updates the label to
value "true".

Signed-off-by: Yannis Zarkadas <yanniszarkadas@gmail.com>
2018-12-07 13:46:46 +02:00
Yannis Zarkadas f5a41e9a7c cassandra: controller-side implementation of scale down
Code handling the scale down on the side of the controller.
Also, some new util functions.

Signed-off-by: Yannis Zarkadas <yanniszarkadas@gmail.com>
2018-12-07 13:46:45 +02:00
travisn 78b8011226 osds: prototype provisioning with ceph-volume
Signed-off-by: travisn <tnielsen@redhat.com>
2018-12-06 21:28:58 -07:00
Dmitry Yusupov 63c30a03ec Edgefs CMDs
Signed-off-by: Dmitry Yusupov <dmitry.yusupov@nexenta.com>
2018-12-05 23:05:42 -08:00
travisn a29b876337 rename ceph v1 crds with the ceph prefix
Signed-off-by: travisn <tnielsen@redhat.com>
2018-12-05 16:23:55 -07:00
Yannis Zarkadas 367d485407 cassandra: sidecar implementation
Implementation of the cassandra sidecar logic.
This sidecar helps us inject our custom values during startup
and provides HTTP liveness and readiness checks.
In the future it will also be used for:
- Shutting Down / Decommissioning a cassandra instance
- Backups
- Restores

Signed-off-by: Yannis Zarkadas <yanniszarkadas@gmail.com>
2018-12-05 12:47:26 +02:00
Yannis Zarkadas 0ccc04cccd cassandra: controller scaffolding, image build and manifests
Scaffolding of a Kubernetes controller using the informer-workqueue
pattern.
Dockerfiles and Makefiles to build the cassandra operator image.
Manifests to deploy the Cassandra operator and create a Cluster CRD.

Signed-off-by: Yannis Zarkadas <yanniszarkadas@gmail.com>
2018-12-05 12:44:29 +02:00
Alexander Trost ac19f85fbb Allow specifying custom Ceph user and secret name for mounting
Introduce mount security mode for basic multi tenancy

Fixes #2164.

This adds three new parameters/options to StorageClass/flexvolume entry:
* `mountUser`
* `mountSecret`
* `mountSecretNamespace`

Signed-off-by: Alexander Trost <galexrt@googlemail.com>
2018-12-04 20:17:15 +01:00
Travis Nielsen 9654e51db1 Merge pull request #2290 from travisn/rbd-mirror
Enable rbd mirror daemon in the cluster crd
2018-11-30 08:54:40 -07:00
Blaine Gardner 9ae6dfcd25 Ceph osd: terminate fatal on pod init failures
Signed-off-by: Blaine Gardner <blaine.gardner@suse.com>
2018-11-28 14:56:03 -07:00
travisn fdd64bb95a enable rbd mirror daemon in the cluster crd
Signed-off-by: travisn <tnielsen@redhat.com>
2018-11-28 08:29:57 -07:00
Travis Nielsen b255d8fb75 Merge pull request #2219 from anguslees/norelabel
Disable SELinux relabelling
2018-11-13 23:32:56 -07:00
travisn 94a7a0d4bc run daemons with the ceph image instead of rook
Signed-off-by: travisn <tnielsen@redhat.com>
2018-11-01 11:49:35 -06:00
travisn 01dc5656f3 reduce frequency of device discovery
Signed-off-by: travisn <tnielsen@redhat.com>
2018-10-17 09:56:47 -06:00
Angus Lees 72278a7e15 Disable seLinux relabelling
seLinux relabelling breaks (times out) on large filesystems, and
doesn't work with cephfs ReadWriteMany volumes (last relabel wins).

See also https://github.com/kubernetes/kubernetes/blob/02cca1f11a8ae570369540564604d0cde06e0720/pkg/volume/cephfs/cephfs.go#L209

Fixes #2177

Signed-off-by: Angus Lees <gus@inodes.org>
2018-10-15 21:40:56 +11:00