Signed-off-by: Ashish Ranjan <ashishranjan738@gmail.com>
This commit removes one to one mapping of NFS provisioner and adds a dedicated provisioner for nfs.
Signed-off-by: Ashish Ranjan <ashishranjan738@gmail.com>
This commit moves claimPath information from annotation to parameters and adds option to enable/disable storageclass creation.
The ClusterRoles in the manifests (and helm chart) for the ceph provider
have been updated to use [aggregated ClusterRoles][1].
All ClusterRoles have been split into 2 ClusterRoles.
An aggregated ClusterRole without any rules, named the same, but with an
aggregationRule that matches labels in the format
'rbac.ceph.rook.io/aggregate-to-<ClusterRole name>: "true"'.
A second ClusterRole which contains the existing rules named
'<ClusterRole name>-rules', with label
'rbac.ceph.rook.io/aggregate-to-<ClusterRole name>: "true"'.
These two ClusterRoles give the same behaviour as the previous
ClusterRole.
Additional rules to a ClusterRole can now be provided by creating a new
ClusterRole with the correct label. This should help make updates
simpler.
Fixes#2634.
[1]: https://kubernetes.io/docs/reference/access-authn-authz/rbac/#aggregated-clusterroles
Signed-off-by: Kaushal M <kshlmster@gmail.com>
All usages of k8s go client are now also using the versioned `AppsV1() `
call for the client.
Updated MySQL and Wordpress, and Kube Registy examples to use apps/v1
Deployments.
Signed-off-by: Alexander Trost <galexrt@googlemail.com>
The CephCluster resource will now expose the health of the ceph cluster
so admins can query the status with k8s api or kubectl instead of
needing to run the rook toolbox. The operator will query the
ceph status periodically and update the status in the custom resource.
Signed-off-by: travisn <tnielsen@redhat.com>
socket directory name need not follow
the driver name format,renamed socket directory
to simple names.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
When deleting a CephObjectStoreUser the deleteUser function
attempts to delete the stored secret using the wrong name. This
patch updates deleteUser to use the same fmt.Sprintf call used in
the createUser function.
Updated CI to delete the correct CRD and check the secret is deleted.
Signed-off-by: Keith Schincke <keith.schincke@gmail.com>
The RBAC is tedious to copy everywhere with the cluster.yaml and is confusing to newcomers.
The common resources are now factored into the operator-common.yaml for the common scenario
of creating a single cluster. Examples are now added for configuration of the operator
and cluster crds to provide a more complete set.
Signed-off-by: travisn <tnielsen@redhat.com>
Nautilus has an issue targeting Luminous when running the rbd info command.
Rook already has the info it needs for the call and can return it
after the rbd create command succeeds.
Signed-off-by: travisn <tnielsen@redhat.com>
To target a Nautilus image with msgr2 and configure the nfs ganesha feature
for Ceph, we need to update the base image to Nautilus.
Signed-off-by: travisn <tnielsen@redhat.com>
The basic idea here is to replace the release name in the ClusterInfo
object with the fine grained version information queried at runtime.
This patch also removes the Name field from the cluster spec, which was
also runtime determined and was redundant with ClusterInfo relase name.
Signed-off-by: Noah Watkins <noahwatkins@gmail.com>
Configure the Ceph rgw daemon completely from the operator a la the
recent changes to the Ceph mon, mgr, and mds operators.
Create the rgw deployment or daemonset first, and then create the
keyring secret for the object store with its owner reference as the
corresponding deployment or daemonset. When the replication controller
is deleted, the secret is also deleted.
The RGW's mime.types file is now stored in a configmap with a different
file created for each object store. This is primarily just a means to
get the mime.types file into the rgw pod, but the added benefit is that
the administrator can modify the configmap, which could reduce
susceptibility to file type execution vulnerabilities (worst case).
Signed-off-by: Blaine Gardner <blaine.gardner@suse.com>
Various kubectl helper methods return strings from calls to
create, delete, or apply resources. There is no need for this.
It is sufficient and complete to check the err from these calls to determine failure.
Signed-off-by: travisn <tnielsen@redhat.com>
All devices detected by the discovery pod were being passed to the OSD provisioning pod
thus not always honoring the desired device list that should be provisioned.
Now the provisioning pod will be given the desired state from the crd,
then apply that state depending on the actual devices detected.
Also added a helper to ensure OSDsPerDevice is always valid.
Signed-off-by: travisn <tnielsen@redhat.com>
I had some trouble with RBAC under minikube when testing some
ceph-mgr functionality. This patch tweaks rook-ceph-mgr-system to
be a ClusterRole, and rook-ceph-mgr-cluster to use a
ClusterRoleBinding.
While we're in there, remove the namespace fields from the
ClusterRoleBindings since they just get ignored.
Finally, also fix up the upgrade test to remove the objects that have
changed and reinstantiate them properly.
Suggested-by: Travis Nielsen <tnielsen@redhat.com>
Signed-off-by: Jeff Layton <jlayton@redhat.com>
Rook's behavior should not be to create a default OSD in dataDirHostPath
when no devices are present on a node. Any preexisting fallback osd
should be kept as long as no dirs or disks have been specified to keep
the legacy behavior for those clusters running with these osds in place.
The legacy deletion behavior is also kept, removing the osd as soon as
any dir or device is specified other than the dataDirHostPath dir.
Signed-off-by: Blaine Gardner <blaine.gardner@suse.com>