Commit Graph
269 Commits
Author SHA1 Message Date
Jiffin Tony Thottan 01649a8cd2 docs: update vault kms with RGW details
The KMS encryption via HashiCorp Vault can be consumed for RGW, adding those details
in the doc.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2021-01-22 16:04:28 +05:30
Sébastien Han 758226294b ceph: convert CephClient CRD to controller-runtime
This was the last remaining CRD to not use the controller-runtime
library.
Small additions were added with the transition:

* the Kubernetes Secret that contains the CephX key has now an owner
  reference to the CephClient object
* the secret name is present in the Status field of the CephClient:

```
status:
  info:
    secretName: rook-ceph-client-glance
  phase: Ready
```

The controller will reconcile on CR updates and also if the Kubernetes
Secret is deleted.

Closes: https://github.com/rook/rook/issues/4938
Signed-off-by: Sébastien Han <seb@redhat.com>
2021-01-15 16:17:38 +01:00
Travis Nielsen 6b8315c53c docs: clear the pending release notes for 1.6
The pending release notes were for v1.5, now cleared for adding
v1.6 features.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-12-01 11:10:15 -07:00
Sébastien Han afc7ecff31 ceph: add snapshot scheduling for mirrored pools
Now, we can schedule snapshots on pools from the CephBlockPool CR when
the pool is mirrored.
It can be enabled like this:

```
mirroring:
  enabled: true
  mode: pool
  snapshotSchedules:
    - interval: 24h # daily snapshots
      startTime: 14:00:00-05:00
```

Multiple schedules are supported since snapshotSchedules is a list.

Signed-off-by: Sébastien Han <seb@redhat.com>
2020-11-18 09:50:09 +01:00
Alexander Trost fa62f4ac5d ceph: allow custom labels to be added to the discover daemonset
Signed-off-by: Alexander Trost <galexrt@googlemail.com>
2020-11-12 16:20:01 +01:00
Pete Birley 152a05c85e ceph: update to helm 3 for the rook chart
This updates the chart to make use of helm3 which has been released
for some time, and also permits CRDs to be installed pror to other objects
allowing the chart to be deployed at the same time as CRs for rook objects.

Co-authored-by: Pete Birley <pete@port.direct>
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-11-11 14:41:24 -07:00
Travis Nielsen b9f692a56e ceph: disable the discovery daemon by default
The discovery daemon is not needed in most scenarios, therefore we disable it
by default. More and more clusters are moving to the cluster-on-pvc scenario
which certainly does not need the local discovery. Even where clusters are not
running on PVCs, the discovery is not needed since the device discovery is again
performed in the osd prepare job.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-11-10 13:16:52 -07:00
Travis Nielsen b91f4211c9 ceph: configure a stretched cluster
In clusters where only two datacenters (or similar failure domains)
are available, a different mon and osd approach is needed to deal
with the network partitions or some other reason for one of the failure
domains going down. The Ceph stretched cluster makes the mons aware
of the failure domains by configuring one as the arbiter in a third
zone, while keeping two replicas of the data in each of the data
zoens.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-11-05 09:17:52 -07:00
Travis Nielsen 44bf443dca Merge pull request #6495 from LalitMaganti/preserve-fs
ceph: add option to preserve filesystem on CRD deletion
2020-10-30 16:56:38 -06:00
Lalit Maganti c6aec79c4f ceph: add option to preserve filesystem on CRD deletion
Due to #6492, preservePoolsOnDelete is not useful at all for CephFS;
after the filesystem is deleted, the leftover pools cannot be
reassocaited with a newly created filesystem without wiping all
metadata. The only way we can actually preserve data is keeping around
the entire filesystem.

This commit implements a `preserveFilesystemOnDelete` option which work
similar to the existing pool preservation option but instead keeps the
whole CephFS while taking it down and removing all MDSes.

This commit also changes all documentation to refer to this new option
with the intent of essentially deprecating `preservePoolsOnDelete`. IMO,
keeping around `preservePoolsOnDelete` is actively harmful because it
lulls users into thinking their data will be safe but, in reality,
recovering from this situation is highly complex and has large potential
for data loss.

Signed-off-by: Lalit Maganti <lalitm@google.com>
2020-10-30 17:04:18 +00:00
Sébastien Han ea1d71cbfb ceph: add vault kms support for osd encryption
When the Ceph cluster runs on PVC and the OSDs are encrypted we can
store LUKS's Key Encryption Key inside a Key Management System. Today,
Rook only supports HashiCorp Vault: https://www.vaultproject.io/

The CephCluster has now a new "security" field which will plug onto the
KMS. Here is an example:

security:
  kms:
    tokenSecretName: <name of the secret containing a Vault token, used
    to authenticate>
    connectionDetails: < a map of strings containing connection
    information>

Refer to the ceph-cluster-crd documentation to lear more.

Closes: https://github.com/rook/rook/issues/6105
Signed-off-by: Sébastien Han <seb@redhat.com>
2020-10-30 16:16:33 +01:00
subhamkraiandtravisn 1b2c15041f ceph: update deprecated CRD apiextensions.k8s.io/v1beta1 to v1
the apiextensions.k8s.io/v1beta1 version of CustomResourceDefinition
is deprecated in Kubernetes v1.16 and will no longer be supported from
v1.19. For now, we changing only for ceph and it's related documented.

Signed-off-by: subhamkrai <srai@redhat.com>
Co-authored-by: travisn <tnielsen@redhat.com>
Signed-off-by: subhamkrai <srai@redhat.com>
2020-10-29 06:26:10 +05:30
subhamkrai 62f8d641c5 docs: update PendingReleaseNotes.md
this commit update PendingReleaseNotes.md with
PR 6475 i.e export the storage capacity of
the ceph cluster.

Signed-off-by: subhamkrai <srai@redhat.com>
2020-10-27 19:54:41 +05:30
Sébastien Han b70b098405 ceph: add support for stretched cluster crush rule
The pool spec has now a new property called "replicasPerFailureDomain"
which essentially represents the number of replicas to store in each
failure domain.
Assuming the failure domain is a datacenter (if the cluster is
stretched) then you will have 2 replicas per datacenter where each
replica ends up on a different host. This gives you a total of 4
replicas and for this, the "size" must be set to 4.

Closes: https://github.com/rook/rook/issues/5591
Signed-off-by: Sébastien Han <seb@redhat.com>
2020-10-13 16:33:34 +02:00
Travis Nielsen c7e0338d5e ceph: require an odd number of mons and sufficient nodes
The ceph mons should never be started with an even number in quorum.
The desired state should always be an odd number of mons to ensure
a healthy majority quorum. The operator now rejects a request for
an even number of mons.

If there are not a sufficient number of nodes for mons to be on a
unique host, the operator also returns an early error instead of
getting stuck waiting for a pending mon. This is not foolproof since
there might be fewer available nodes for the mons, but at least it
is a quick check for the common case.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-10-12 15:21:27 -06:00
Sébastien Han 451622a955 ceph: add rbd-mirror configuration
Rook is now capable of configuring mirroring between sites. The
implementation works at different levels:

* CephBlockPool: which introduces a new `mirroring` configuration as well
as `statusCheck`. When turned on, Rook will enable mirroring on the
pool. It will also create a bootstrap peer token and store it in a
Kubernetes Secret. The name of that Secret can be found in the Status
field of the CephBlockPool CRD. This token can be fetched and used by
other clusters to configure the site as a peer. Mirroring can be
configured either at the pool or the image level.

* CephRBDMirror: which introduces a new `peers` configuration allowing
Rook to connect to peers by passing a Secret name. The administrator will
create a Kubernetes Secret with 2 keys: 'token' for the bootstrap peer
token and 'pool' for the name of pool. Once detected the rbd-mirror
controller will go ahead and import the peer configuration.

Pool mirroring status example:

```
status:
  info:
    rbdMirrorBootstrapPeerSecretName: pool-peer-token-test
  mirroringInfo:
    lastChanged: "2020-09-17T14:47:27Z"
    lastChecked: "2020-09-17T14:48:27Z"
    summary:
      summary:
        mode: image
        peers:
        - client_name: client.rbd-mirror-peer
          direction: rx-tx
          mirror_uuid: ""
          site_name: rhcs
          uuid: c50522a4-28a4-4bd3-ba68-e11780308882
        site_name: 91eae0dd-06b1-4d2c-91f3-1311c9df382b-rook-ceph
  mirroringStatus:
    lastChecked: "2020-09-17T14:48:27Z"
    summary:
      summary:
        daemon_health: OK
        health: OK
        image_health: OK
        states:
          replaying: 1
```

Signed-off-by: Sébastien Han <seb@redhat.com>
2020-09-17 19:05:04 +02:00
Travis Nielsen 07f4554a75 docs: reset the pending release notes
Since the v1.4 release is completed, reset the pending release notes
for v1.5.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-08-10 14:24:06 -06:00
Sébastien Han 89b3225441 ceph: add encryption support for osd pvc
We can now encrypted OSD device that were provisioned via a storage
class using the PV interface.
The encryption works at the storageClassDeviceSets level, which means we
can have encrypted and non-encrypted sets.
Using the new key `encrypted` we can turn it on.

Signed-off-by: Sébastien Han <seb@redhat.com>
2020-08-05 10:06:11 +02:00
Jiffin Tony Thottan ec5f13318c ceph: enable/disable dashboard for rgw
Provide permission for dashboard to collect the object store metrics.

Signed-off-by: Jiffin Tony Thottan <jthottan@redhat.com>
2020-08-03 10:26:54 +05:30
Blaine Gardner cb6881e401 Merge pull request #5909 from SUSE/ceph-add-daemon-type-label
ceph: add ceph_daemon_type label to Ceph daemon pods
2020-07-31 09:40:48 -06:00
Blaine Gardner 6ceaef8610 ceph: add new "ceph_daemon_type" label to nfs pods
Signed-off-by: Blaine Gardner <blaine.gardner@suse.com>
2020-07-30 11:16:29 -06:00
Jiffin Tony Thottan f4240cb31d ceph: add quota support for obc
Closes: #5274
Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2020-07-28 12:00:11 +05:30
Travis Nielsen 7c65df506f Merge pull request #5852 from yanniszark/feature-cassandra-update-jolokia-lib
cassandra: Update Jolokia lib in Cassandra sidecar image
2020-07-20 15:17:56 -06:00
Sébastien Han f3c4975e35 ceph: fail prepare pod if lvm2 pkg is missing
A long-standing issue that was only solved via a documentation note. Now,
during the prepare pod instantiation, we check for the presence of the
lvm binary on the host. Success will indicate that we can bootstrap
OSDs where failure will refuse to prepare the OSD.

Closes: https://github.com/rook/rook/issues/5627
Signed-off-by: Sébastien Han <seb@redhat.com>
2020-07-20 10:05:05 +02:00
Yannis Zarkadas bb24d8efa0 cassandra: update jolokia lib in operator sidecar image
The Cassandra sidecar uses the Jolokia javaagent to expose a REST API of
Cassandra's administrative interface, which is normally only exposed via
JMX, a Java-only RPC protocol. Update the Jolokia javaagent to a newer
version, containing new features and security bug fixes.

Signed-off-by: Yannis Zarkadas <yanniszark@arrikto.com>
2020-07-20 01:05:57 +03:00
Blaine Gardner 825f1e3eb2 ceph: support device names with special chars
Pass desired devices to the OSD provisioning container by
JSON-marshalling/-unmarshalling a disk ID with StorageConfig settings.
This will allow disks to be specified that contain special characters.
Notably, this will support /dev/disk/by-path/pci-HHHH:HH:HH.H devices
that were unsupported previously due to the format which separated
devices from params with colons (:).

Fixes #5056
Fixes #5535

Signed-off-by: Blaine Gardner <blaine.gardner@suse.com>
2020-07-17 09:44:26 -06:00
Sébastien Han 34ccb84aa3 ceph: add external prometheus endpoint
We can now connect an external prometheus exporter to Rook to collect
metrics and generate alerts from Prometheus.
Just enable this in the CephCluster CR:

```
spec:
  external:
    enable: true
   monitoring:
    enabled: true
    rulesNamespace: rook-ceph
    externalMgrEndpoints:
    - ip: 192.168.39.182
```

Closes: https://github.com/rook/rook/issues/5516
Signed-off-by: Sébastien Han <seb@redhat.com>
2020-07-17 11:29:48 +02:00
Blaine Gardner 7117fc12b7 ceph: osd: add drive groups spec to cluster CR
Add the ability to provision Ceph OSDs with Drive Groups.
This adds Drive Groups to the CephCluster CRD, and it sets code
in place for propagating this config to the OSD provisioning pod.

Signed-off-by: Blaine Gardner <blaine.gardner@suse.com>
2020-07-14 09:43:03 -06:00
Sébastien Han ccb52b84e6 ceph: configurable status checks and livenessprobe
This commit allows us to configure status check for each daemon:

* "mon": health check on the ceph monitors (quorum)
* "osd": health check on the ceph osds
* "status": ceph health status check

Each check is controlled by the following settings:

* disabled: whether to disable the check (default: false)
* internal: interval to run the check
* timeout: only valid for mons, is the timeout for unresponsive mon
before failling over.

Example to disable the status health check:

```yaml
healthCheck:
  daemonHealth:
    status:
      disabled: true
```

As part of that, pod's livenessprobe can now be configured via the
following settings:

* disabled: whether to enable or not
* probe: override the current probe in place by a new one

```yaml
healthCheck:
  livenessProbe:
    mon:
      disabled: true
```

Closes: https://github.com/rook/rook/issues/5772
Signed-off-by: Sébastien Han <seb@redhat.com>
2020-07-10 19:21:59 +02:00
Sébastien Han 07c7dd457f ceph: expose endpoint in the CephObjectStoreUser
Now, when an S3 user gets created, Rook will add the S3 endpoint to the
Secret along with the credentials.

Signed-off-by: Sébastien Han <seb@redhat.com>
2020-07-10 15:59:47 +02:00
Sébastien Han e4eaa91ede ceph: add rgw endpoint healthcheck
We have introduced a new goroutine to check the state of the rgw
endpoint. It will run every minute and perform operations on a bucket.
The success or failure will be reported as part of the status field of
the CephObjectStore CR.

A good status will look like:

status:
  endpointStatus:
    lastChanged: "2020-06-25T13:47:45Z"
    lastChecked: "2020-06-25T13:48:46Z"
  phase: Connected

A failed status:

status:
  endpointStatus:
    details: |-
      error creating bucket "rook-ceph-internal-s3-bucket-checker": RequestError: send request failed
      caused by: Put http://rook-ceph-rgw-my-store.rook-ceph:8080/rook-ceph-internal-s3-bucket-checker: dial tcp 10.108.189.148:8080: connect: connection refused
    health: ERROR

This check works for both converged and external modes. Note that the
CephObjectStore CRD has a new field called "externalRgwEndpoints" which
allows you to define a list of IP addresses pointing to rgws.

Closes: https://github.com/rook/rook/issues/5692
Signed-off-by: Sébastien Han <seb@redhat.com>
2020-07-02 16:34:10 +02:00
Alexander Trost 7229f5826e Merge pull request #5701 from cloudical-io/cassandra_alpine_update
cassandra: update base image to alpine:3.12
2020-07-01 14:59:46 +02:00
Jiffin Tony Thottan e4fae54e3c ceph: run bucket provisioner in multithreaded mode
The latest lib-bucket provisioner library supports multithreading via
env "LIB_BUCKET_PROVISIONER_THREADS"

Closes: #4907
Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2020-06-30 23:07:22 +05:30
Alexander Trost 849cf84bf8 cassandra: update base image to alpine:3.12
Due to CVEs in the alpine:3.8, we need to update the base image.

Signed-off-by: Alexander Trost <galexrt@googlemail.com>
2020-06-29 22:37:49 +02:00
Vineet Badrinath ce1003aef8 ceph: adds scripts and components to support admission controllers
adds deploy.sh script to deploy validatingwebhookconfiguration and create secrets.
adds new command ceph admission-controller to start webhook servers.
adds validation for various rook custom resources

Signed-off-by: Vineet Badrinath <vbadrina@redhat.com>
2020-06-24 14:59:00 +05:30
Sébastien Han 0a002dfae0 docs: fix wrong section
The multipath feature was in the wrong section (breaking changes).

Signed-off-by: Sébastien Han <seb@redhat.com>
2020-06-17 10:08:03 +02:00
Sébastien Han c7f255a0e8 ceph: add the ability to set any pool property
We can now explicitly set any property on a given pool by using the new
Property field in the CephBlockPool Spec.

Also, this fixes the case where both `CephBlockPool` and `CephCluster`
are created at the same time. When Rook creates the pool, the cluster is
still being bootstrapped and the global option
`osd_pool_default_pg_autoscale_mode` has not bee set yet. So the pool
gets created but its `pg_autoscale_mode` property is set to `warn`
instead of `on`.

Closes: https://github.com/rook/rook/issues/5608V
Signed-off-by: Sébastien Han <seb@redhat.com>
2020-06-17 10:08:00 +02:00
Satoru Takeuchi 75f0b0f159 ceph: write down the multipath support in the documents
OSD on PVC supports multipath thanks to the following commit.

ceph: add support for multipath devices
32730123ea

However, it's not documented yet.

Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
2020-05-12 17:11:02 +09:00
Sébastien Han f27fd207ce ceph: convert the CephCluster controller to the controller-runtime
This is the final conversion to controller-runtime conversion. This time the
CephCluster CRD has been converted to use the controller-runtime
library.
The controller incorporates all the previous watchers too, so the Node
and hot-plug configmap are been watched too.
Only the operator setting configmap is not being watcher since it's not
related to the CephCluster CRD.
Not only the patch converts to controller-runtime but also tries to
re-organize the tree of the repo to actually make the code more
readable and have better functions/methods/tests separations.

Closes: https://github.com/rook/rook/issues/4939
Signed-off-by: Sébastien Han <seb@redhat.com>
2020-04-28 09:40:35 +02:00
Travis Nielsen f8ffd2c2eb ceph: toolbox job for running a ceph script
As another option to run Ceph commands, a script can be executed
with Ceph commands as if running in the toolbox, but will instead
run in a job where the logs can be collected and analyzed
separately. This would be useful where automation is in place to collect
information about the cluster periodically or upon some failure
that is detected, without requiring an interactive shell.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-04-20 15:48:59 -06:00
Sébastien Han c1b8a7aa9e ceph: extract rbd-mirror to its own crd
Previously, the rbd-mirror daemon was integrated into the `CephCluster`
CRD. This wasn't really practical since we would have to wait for the
whole orchestration to be done to actually set it up. The same goes for
any CR update. Let's say you want to change the number of daemons, Rook
would go through mons, mgrs and osds until it get to rbd-mirror.
This triggers an undesired full orchestration.

With its own CRD this component just gains a lot more flexibility.

Closes: https://github.com/rook/rook/issues/5084
Signed-off-by: Sébastien Han <seb@redhat.com>
2020-04-15 09:12:56 +02:00
Sébastien Han dc364e17fa rook: reset PendingReleaseNotes
Since we ship 1.3, we need to reset this file.

Signed-off-by: Sébastien Han <seb@redhat.com>
2020-04-09 17:21:08 +02:00
Dmitry Yusupov afd8398a6b Merge pull request #5165 from dyusupov/master
edgefs: support for SMB CRD
2020-04-03 14:18:14 -07:00
Dmitry Yusupov 4920202c10 edgefs: support for SMB CRD
Signed-off-by: Dmitry Yusupov <dmitry.yusupov@nexenta.com>
2020-04-03 13:15:14 -07:00
Sébastien Han 20d1543507 ceph: add multus support
You can now use Rook along with Multus. Multus must be up and running
and the right ressources must exist such as NetworkAttachmentDefinition
CR.
The Cluster CR spec has new fields to work with multus:

network:
  provider: multus (or 'host' for hostNetworking)
  selectors:
    public: NetworkAttachmentDefinition name
    cluster: NetworkAttachmentDefinition name

If only a single NetworkAttachmentDefinition is provided Rook will use
both anyway for the Ceph traffic.

Please refer to the doc to learn more.

Closes: https://github.com/rook/rook/issues/4716
Signed-off-by: Sébastien Han <seb@redhat.com>
2020-04-03 18:00:15 +02:00
Travis Nielsen c79325f92c Merge pull request #5138 from cybozu-go/support-topology-spread-constraints
ceph: support topoplogySpreadConstraints
2020-04-02 12:00:45 -06:00
Satoru Takeuchi 06b10e248c ceph: support topoplogySpreadConstraints
Support topologySpreadConstraints to spread OSD pods among failure
domains as even as possible.

https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/

Without this feature, the number of OSD pods would be different
between the failure domains very much. At worst, there is
a possibility that a failure domain has many OSDs and other
failure domains have no OSDs. It can partly be mitigated
with podAntiAffinity. However, it only works if there are at most
one OSD per node. For more detail, please refer to the following
document.

https://github.com/rook/rook/blob/master/cluster/examples/kubernetes/ceph/cluster-on-pvc.yaml#L59

Closes: https://github.com/rook/rook/issues/4387
Signed-off-by: Hiroshi Muraoka <h.muraoka714@gmail.com>
Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
2020-04-02 16:40:58 +00:00
Travis Nielsen f30c8066d1 docs: update docs for Rook v1.3 release
Various updates are needed for the v1.3 release.
- The pending release notes were missing some features
- Added a section to the upgrade guide for breaking changes to OSDs
- Clarifications around Ceph prereqs and min version
- Other misc clarifications

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-04-02 10:26:00 -06:00
Sébastien Han 58f1971172 ceph: do not use host PID anymore
Thanks to https://github.com/ceph/ceph/pull/33633, when running on
Octopus, we don't need to use `--pid=host`. This means we are not using
the host PID but use the PID namespace of the pod.

Signed-off-by: Sébastien Han <seb@redhat.com>
2020-04-01 15:42:53 -06:00
ShyamsundarR de97b6a1d6 ceph: Add ability to specify compression mode for pools
This commit enables configuring a compression_mode for pools
that takes the values as specified for bluestore OSD
compression_mode values,
https://docs.ceph.com/docs/master/rados/configuration/bluestore-config-ref/#inline-compression

Signed-off-by: ShyamsundarR <srangana@redhat.com>
2020-04-01 14:24:30 -04:00