The KMS encryption via HashiCorp Vault can be consumed for RGW, adding those details
in the doc.
Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
v1 version of admission controller require minimum v1.16.0
of k8s. So, this commits disable admission controller when
k8s version older than v1.16.0.
Signed-off-by: subhamkrai <srai@redhat.com>
In some cases the user dont want to run snapshotter
container either for CephFS or RBD. In that case the
user wont install the required snapshot CRD's due
to that the snapshotter sidecar container produces
lot of noisy logs.
Snapshotter will be enabled by default for both
CephFS and RBD, but with this PR we are providing
an option to disable snapshotter sidecar deployment
either for CephFS or RBD.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
The cockroachDB operator has not had community support in Rook.
Therefore, the time has come to deprecate and remove it.
If the sources are still needed, there is always git history.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
Describe `rook-ceph-purge-osd` job in the document of OSD management
to ease day2 operations.
Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
With the 1.5 schema added to the CRDs, the devices at the root
level of the storage element were missed. Now the ability to
specify devices at the root storage level to apply to all
nodes is restored.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
Update to the latest lib bucket provisioner code.
Fixes issue 6650
Modifies CRD for objectbucketclaims to fix an additional bug where an
ObjectBucket's 'ClaimRef' is lost due to the CRD validation being
specified incorrectly.
Changes OBC deletion/cleanup to delete the bucket before the user. A
user cannot be deleted without an unsafe purge option if the user has
buckets associated to it.
Does not reintroduce bug 6767 from previous fix for 6650
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
The latest octopus release is now out with v15.2.8. We update the
operator base image and the examples to run with this version.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
Update the upgrade docs to allow users with different cluster/operator
namespaces to use a `sed` command and the new manifest meta-comments for
updates.
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
Add meta-comments to manifests to allow basic templating via `sed`.
Add the following types of meta-comments:
- # namespace:X
- A basic namespace
- replace the field with a namespace for X
- # serviceaccount:namespace:X
- A service account namespace for SCC
- e.g., "system:serviceaccount:<ns>:rook-ceph-system"
- Replace the namespace "<ns>" with with a namespace for X
- # provisioner:namespace:X
- A provisioner identifier with namespace prefix
- e.g., "<ns>.cephfs.csi.ceph.com"
- e.g., "<ns>.ceph.rook.io/bucket"
- Replace the namespace "<ns>" with a namespace for X
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
The arbiter may have unique requirements for placement settings. Thus, if the arbiter
placement is specified in the cluster CR, that placement will be applied to the arbiter
mon and the other mons will retain their placement from the other mon or all
sections of the placement.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
This commit updates the OSD capacity thresholds to match the cluster capacity alert thresholds.
Also updated device_class info to provide info about which type of storage needs to be added.
Signed-off-by: Anmol Sachan <anmol13694@gmail.com>
When the cluster is external we want to expose manager service port
along with the endpoints.
This allows us to connect but Rook will keep on using 9283 as a facing
port for Prometheus and more.
```
monitoring:
enabled: true
...
...
externalMgrPrometheusPort: 9283
```
Signed-off-by: Sébastien Han <seb@redhat.com>
With the release of the latest octopus v15.2.7 we update the base
of the operator image and set the examples to use the same release
to pick up the security and other bug fixes.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
We can now collect logs directly into a side-car container.
A new CRD spec has been added:
spec:
logCollector:
enabled: true
periodicity: 24h
Every 24h we will rotate log files for each Ceph daemon.
Signed-off-by: Sébastien Han <seb@redhat.com>
Rook's crashcollector pod posts entries to the ceph cluster when a crash occurs.
Over time the number cluster may hold crash entries needlessly.
To clean up old crash entries, this PR adds a field to the ceph cluster CR for the user to specify the number of days a crash entry should be kept for.
Providing a value for the field keepXDays creates a cronjob that runs every day at midnight, calling "ceph crash prune <keepXDays>".
Closes: https://github.com/rook/rook/issues/6332
Signed-off-by: Renan Campos <rcampos@redhat.com>
-creates a single PDB (max-unavailable=1) for all OSDs. This PDB allows one OSD to go down at a given time.
-When a drain is detected, blocking PDBs (max-unavailable=0) will be created for each failure domain that is not being drained and the main PDB (max-unavilable=1) will be deleted. This will allow all the OSDs in the currently drained failure domain to be removed while blocking the deletion of OSDs in other failure domains.
-Once the PGs are healthy again, the blocking PDBs will be deleted and the main PDB will be restored.
-Add PG healthcheck timeout
-Delete any legacy node drain pods and blocking OSD PDBs
Signed-off-by: Santosh Pillai <sapillai@redhat.com>
Now, we can schedule snapshots on pools from the CephBlockPool CR when
the pool is mirrored.
It can be enabled like this:
```
mirroring:
enabled: true
mode: pool
snapshotSchedules:
- interval: 24h # daily snapshots
startTime: 14:00:00-05:00
```
Multiple schedules are supported since snapshotSchedules is a list.
Signed-off-by: Sébastien Han <seb@redhat.com>
Added the support of NAD from diffrent namespaces.
they can be referrenced as <namespace>/<name-of-nad> e.g.,
default/public-nw.
Updated the multus doc to explain the same.
Signed-off-by: rohan47 <rohgupta@redhat.com>
The CRs must be created in a separate kubectl create command
from the creation of the CRDs, otherwise the create command
will fail.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
Use common.yaml to apply changes to resources instead of keeping an
upgrade-*-apply.yaml file. Update the upgrade docs to reflect this also.
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
This adds the functionality to add custom pod labels to the CSI
components through the operator configuration way of env vars or config
map.
Resolves#6593
Signed-off-by: Alexander Trost <galexrt@googlemail.com>
The CRDs need to be installed and updated separately from the
rest of the manifests. Helm charts also do not have a way to update
CRDs, therefore, any updates to the CRD schema must be done separately
from the helm chart. Now the CRDs are created in a new crd.yaml that must
be created along with common.yaml and before creating the operator.
The helm chart still contains the CRDs for initial creation, though
the helm chart will never update or remove them.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>