Commit Graph
50 Commits
Author SHA1 Message Date
Satoru Takeuchi 1be47ea0b8 ceph: delete discovery daemon if it is disabled
discovery-daemon still exists even if it's disabled.

Closes: https://github.com/rook/rook/issues/6936

Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
2021-01-15 19:44:40 +00:00
Sébastien Han 7558d37420 core: bump to controller-runtime 0.7.0 version
Now using https://github.com/kubernetes-sigs/controller-runtime/releases/tag/v0.7.0

Closes: https://github.com/rook/rook/issues/6689
Signed-off-by: Sébastien Han <seb@redhat.com>
2021-01-13 11:00:43 +01:00
Travis Nielsen e56c68c9e9 ceph: remove unused operator namespace parameter
The operator namespace is not used in the StartOperatorSettingsWatch()
method. Instead, the method looks up the namespace from the
POD_NAMESPACE env var.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-12-18 11:45:14 -07:00
Arun Kumar Mohan ded16f779d ceph: changes for 'sigs.k8s.io/sig-storage-lib-external-provisioner/v6'
Signed-off-by: Arun Kumar Mohan <amohan@redhat.com>
2020-11-18 21:14:03 +05:30
rohan47 cb9f947c3b ceph: support ceph cluster and CSI on multus in diffrent namespace
Support ceph cluster and CSI on multus deployed in diffrent namespace.
Previously csi was looking for multus config from the cluster deployed
in the namespace in which rook-ceph-operator/csi was deployed.
Now it will look for multus configuration from ceph clusters from all
the namespaces.

Signed-off-by: rohan47 <rohgupta@redhat.com>
2020-11-16 20:47:09 +05:30
rohan47 8c4ede1edc ceph: added support for multus for csi
CSI pods now utilize multus networking and connect to public
network specified in the CephCluster CR.

Closes: https://github.com/rook/rook/issues/5356
Signed-off-by: rohan47 <rohgupta@redhat.com>
2020-08-20 18:25:09 +05:30
Madhu Rajanna 1989e0d8c5 ceph: remove csi support for kubernetes 1.13
as the kubernetes 1.13 is EOL and there is no major
functionalities available in 1.13 (resize,snapshot,clone
metrics etc) we are removing the support for kubernetes
for the same.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2020-08-05 21:19:59 +05:30
subhamkrai 465a0f0aec ceph: handling gosec error code g601
this commit handles all the gosec g601
error code (i.e Implicit memory aliasing
of items from a range statement).

Signed-off-by: subhamkrai <subhamkumarrai03@gmail.com>
2020-07-28 11:34:49 +05:30
subhamkrai 7f9f1690d2 ceph: remove csi drivers when disable
remove csi drivers and delete k8s
services that drivers create,when
the default setting of drivers changed
to false.

Signed-off-by: subhamkrai <subhamkumarrai03@gmail.com>
2020-07-06 13:33:52 +05:30
Vineet Badrinath ce1003aef8 ceph: adds scripts and components to support admission controllers
adds deploy.sh script to deploy validatingwebhookconfiguration and create secrets.
adds new command ceph admission-controller to start webhook servers.
adds validation for various rook custom resources

Signed-off-by: Vineet Badrinath <vbadrina@redhat.com>
2020-06-24 14:59:00 +05:30
Travis Nielsen 6c249e751b ceph: start csi driver in parallel of cluster
The csi driver does not need to be started before the cluster
is created. When the csi driver fails to load, neither should
it prevent the cluster from being created. Therefore, we
initialize the basic constructs in the csi driver that are required
for cluster creation, then start the csi driver in a goroutine
so the cluster creation can continue. If the csi driver fails
or takes a long time to load, it will no longer affect cluster
creation.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-05-29 16:42:22 -06:00
Satoru Takeuchi f6a3da2760 ceph: gave up to run the operator if the controller-runtime failed to start
The operator continues to run even though the controller-runtime
failed to start. Since the controller-runtime is essential, the operator
is non-functional after that. It makes troubleshooting more difficult.

Closes: https://github.com/rook/rook/issues/5434

Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
2020-05-18 17:38:35 +00:00
Travis Nielsen f47bb945c2 ceph: remove duplicate controller wait setting
The controller setting for requeuing an event moved to the
opcontroller package and was no longer needed in the main
controller package.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-05-14 16:52:24 -06:00
Madhu Rajanna 81688398f2 cleanup: use err.Wrap when the formatting is not required
Replaced err.Wrapf with err.Wrap when the formatting
is not required.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2020-04-29 17:42:59 +05:30
Sébastien Han f27fd207ce ceph: convert the CephCluster controller to the controller-runtime
This is the final conversion to controller-runtime conversion. This time the
CephCluster CRD has been converted to use the controller-runtime
library.
The controller incorporates all the previous watchers too, so the Node
and hot-plug configmap are been watched too.
Only the operator setting configmap is not being watcher since it's not
related to the CephCluster CRD.
Not only the patch converts to controller-runtime but also tries to
re-organize the tree of the repo to actually make the code more
readable and have better functions/methods/tests separations.

Closes: https://github.com/rook/rook/issues/4939
Signed-off-by: Sébastien Han <seb@redhat.com>
2020-04-28 09:40:35 +02:00
Umanga Chapagain 0e932c15eb Ceph: add CSI configurations to ConfigMap
This commit adds all the CSI configurations to ConfigMap.
This configMap can be used in combination with Env Vars
to configure Ceph CSI drivers in rook.

Signed-off-by: Umanga Chapagain <chapagainumanga@gmail.com>
2020-03-27 15:17:30 +05:30
Sébastien Han ca0a30f38d ceph: convert Filesystem controller to the controller-runtime
The CRD watcher has been replaced by the new controller-runtime
framework.
This brings robustness in our operator, meaning that any resources that
are modified will be reconciled into the desired state.

Closes: https://github.com/rook/rook/issues/4940
Signed-off-by: Sébastien Han <seb@redhat.com>
2020-03-19 23:34:58 +01:00
Sébastien Han f268c897e9 ceph: Convert the Ceph ObjectStore controller to the controller-runtime
The CRD watcher has been replaced by the new controller-runtime
framework.
This brings robustness in our operator, meaning that any resources that
are modified will be reconciled into the desired state.

Closes: https://github.com/rook/rook/issues/4937
Signed-off-by: Sébastien Han <seb@redhat.com>
2020-03-17 15:12:41 -06:00
Umanga Chapagain c54c0d16cf Ceph: adds watch to rook-ceph-operator-config ConfigMap
watches the rook-ceph-operator-config ConfigMap and updates
CSI driver

Signed-off-by: Umanga Chapagain <chapagainumanga@gmail.com>
2020-03-10 12:46:54 +05:30
Sébastien Han 9f2867e12a ceph: separate controller for CephObjectStoreUser CRD
Now, the CephObjectStoreUser CRD is managed with the controller-runtime.
So the watcher is outside of the main controller reconciliation loop of
CephCluster which brings numerous benefit such as:

* having its own reconciliation loop
* won't block anything from the main CephCluster controller loop
* fast than waiting for CephCluster loop to completion

Partially close: https://github.com/rook/rook/issues/1981
Signed-off-by: Sébastien Han <seb@redhat.com>
2020-03-06 11:53:40 +01:00
Sébastien Han a3068dee0b ceph: separate controller for CephBlockPool CRD
Now, the CephBlockPool CRD is managed with the controller-runtime.
So the watcher is outside of the main controller reconciliation loop of
CephCluster which brings numerous benefit such as:

* having its own reconciliation loop
* won't block anything from the main CephCluster controller loop
* fast than waiting for CephCluster loop to completion

Partially close: https://github.com/rook/rook/issues/1981
Signed-off-by: Sébastien Han <seb@redhat.com>
2020-03-02 17:31:03 +01:00
Stefan Haas b3cc4aeb44 ceph: ceph-csi version detection #3824
Checks the version of the configured ceph-csi image while starting the operator. The operator will fail if the image is not supported.
Added an additional parameter to operator to disable the check e.g. to test not yet supported csi images.

Signed-off-by: Stefan Haas <shaas@suse.com>
2020-02-28 14:14:40 +01:00
Elise Gafford de2c409d79 ceph: delete CSI drivers with deletion of last cluster
Prior attempts to delete CSI drivers using owner references to the
Ceph ConfigMap resulted in garbage collection of the driver
resources as described in rook#4590. This patch manually deletes these
resources by name as a stopgap to provide an appropriate user
experience while the team investigates this issue further.

Resolves: rook#4824
Signed-off-by: Elise Gafford <egafford@redhat.com>
2020-02-27 19:06:23 -05:00
Andrew DeMaria 60ec9c35fa ceph: limit watches to configured namespace
When ROOK_CURRENT_NAMESPACE_ONLY is true, watches should be limited to
the configured namespace

Signed-off-by: Andrew DeMaria <lostonamountain@gmail.com>
2020-02-14 18:34:57 -07:00
Travis Nielsen d0c7d28a63 build: remove operator kit dependency
The operator kit had more utility originally when the operator
was creating and managing the TPRs and CRDs directly. Since
the CRDs are now created from a manifest and no longer by the
operators, the utility of operator kit is limited to the
controller watcher. Since we are moving to the controller runtime
we simplify the code to make the transition smoother. Now
there is only a simple WatchCR method that will need to be
replaced as we maek that transition.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-01-07 08:30:14 -07:00
Sébastien Han 5ce2ed220e ceph: use "github.com/pkg/errors"
We now use the error package.
Kubernetes errors have been renamed kerrors since they are lower than
'errors'.

Closes: https://github.com/rook/rook/issues/4054
Signed-off-by: Sébastien Han <seb@redhat.com>
2019-12-09 16:58:32 +01:00
Elise Gafford 32e5d09336 ceph: remove CSI resources on deletion of last cluster
We create CSI resources when we create the first Ceph cluster.
This change deletes all CSI resources when we delete the last Ceph
cluster.

Partially resolves: #4234
Signed-off-by: Elise Gafford <egafford@redhat.com>
2019-11-22 10:33:39 -05:00
Elise Gafford 3adcb67755 ceph: add removeCallbacks hook to Operator and ClusterController
In order to remove Ceph-CSI resources after deletion of the last
Ceph cluster, the operator must be able to perform post-processing
actions on cluster deletion. This change creates a hook for the
addition of post-deletion operator callback functions.

Partially resolves: #4234
Signed-off-by: Elise Gafford <egafford@redhat.com>
2019-11-21 11:11:25 -05:00
Juan Miguel Olmo Martínez 7c942604f6 ceph: Get <ceph-volume inventory> data in dev. configmaps
**Description of your changes:**
This modification adds the information extracted from 'ceph-volume inventory':
command to the device configmaps generated by the discovery daemon when
"rook discover" starts with the new boolean "--use-ceph-volume" parameter.

Resolves #
https://github.com/rook/rook/issues/2606

Now the <cephVolumeData> field contains all the information returned
from <ceph-volume inventory> command.

Signed-off-by: Juan Miguel Olmo Martínez <jolmomar@redhat.com>
2019-11-06 10:22:56 +01:00
Rohan CJ 4072d14557 Add tests for the clusterdisruption controller and update the docs and
pending releas notes for managed PDBs.

Signed-off-by: Rohan CJ <rohantmp@gmail.com>
2019-08-30 14:04:23 +05:30
Rohan CJ 079c24883b Add a controller-runtime scaffolding
Signed-off-by: Rohan CJ <rohantmp@gmail.com>
2019-08-30 08:59:53 +05:30
Sébastien Han 50e8fced8c Merge pull request #3698 from travisn/skip-start-discovery
Start the ceph device discovery only based on env var
2019-08-26 22:27:22 +02:00
travisn f3e9a5adac ceph: starting the device discovery only based on env var
The decision to start the device discovery daemonset is made
by an env var on the operator pod since in some scenarios
the discovery needs to be started immediately with the operator
instead of being delayed to start with the cluster.

Signed-off-by: travisn <tnielsen@redhat.com>
2019-08-26 11:20:38 -06:00
Madhu Rajanna 78fb35a93d Use Deployment with leader election instead of StatefulSet
Deployment behaves better when a node gets disconnected
from the rest of the cluster - new provisioner leader
is elected in ~15 seconds, while it may take up to
5 minutes for StatefulSet to start a new replica.

if kube version is 1.13.x deploy provisioner as statefulset.
if kube version is higher than 1.14+ deploy provisioner
as deployment.

Refer: kubernetes-csi/external-provisioner@52d1fbc
Refer: ceph/ceph-csi#497

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2019-08-26 19:29:37 +05:30
travisn 7ab689ee8e ceph: skip local setup for an external ceph cluster
When configuring an external cluster the orchestration of discover and all the ceph
daemons will be skipped. The operator will still watch for the creation of
crds for this namespace. When a filesystem, object, object user, or
ganesha crd are created, the operator will simply print an error
to the log.

Signed-off-by: travisn <tnielsen@redhat.com>
Signed-off-by: Sébastien Han <seb@redhat.com>
2019-08-22 17:19:32 +02:00
John Mulligan 521680d100 ceph csi: disable csi if server version is too low
Previously, if csi was not supported by the k8s version the csi set-up
code was skipped but csi was "left on". This change ensures that if
csi is not supported the csi enablement flags are set to false so
that other code that needs csi support will not run.

Signed-off-by: John Mulligan <jmulligan@redhat.com>
2019-08-13 06:42:22 -04:00
John Mulligan 2b1ae54b84 ceph csi: clean up how templates are expressed
Avoid using global values that are not used anywhere in the code.
Split the object used to express the ceph csi templates into two
so only values that are set globally need to be managed globally,
all other values can be stored in the temporary local struct.

Signed-off-by: John Mulligan <jmulligan@redhat.com>
2019-08-12 16:41:26 -04:00
travisn 7b0a7fbfeb allow the discovery daemon to be optional
The discovery daemon is only necessary to be run when
OSDs are being created on raw devices and detect when
new devices are added to the cluster. If OSDs do not need
to be configured on devices, the discovery daemonset
has no need to be started.

Signed-off-by: travisn <tnielsen@redhat.com>
2019-08-07 10:01:29 -06:00
travisn af72af0633 add option to disable flex driver
The flex driver does not need to be started if
only the CSI drivers are going to be used. Therefore,
we allow the admin to stop launching the rook flex
agent with the setting ROOK_ENABLE_FLEX_DRIVER in
operator.yaml

Signed-off-by: travisn <tnielsen@redhat.com>
2019-08-07 10:01:26 -06:00
Blaine Gardner 2ef83c4027 ceph: use cmd-reporter for ceph version job
Use cmd-reporter to detect Ceph version.

The job to detect Ceph version needs to run in a security account context
capable of getting/creating ConfigMaps, so a new security account, role,
and role binding are created for the cmd-runner jobs. In the future, the
Ceph mgr may create jobs in this service account for running
`ceph-volume` on nodes, and this also keeps Rook operators controlling
multiple Ceph clusters independent.

Fixes #2686 - ceph version job not working correctly with graylog

Signed-off-by: Blaine Gardner <blaine.gardner@suse.com>
2019-07-05 15:37:14 -06:00
travisn c6c4a9b42a ceph: delay starting the system daemons until a cluster is created
When the operator first starts, the only operation needed
is to watch for new cephcluster crds to be created and
start the discovery to find available devices. The flexvolume
agent, the csi driver, and the volume provisioning can all be delayed
starting until the first cluster is created.

Signed-off-by: travisn <tnielsen@redhat.com>
2019-06-17 15:44:33 -06:00
travisn bc87b440fb update to the k8s 1.14 client libraries
Signed-off-by: travisn <tnielsen@redhat.com>
2019-04-18 07:51:41 -06:00
travisn eb74bf5547 Configure a cluster in the same namespace as the operator
To simplify the deployment of Rook, both the operator and cluster crd are now created in the
same namespace in the examples. By default the operator will only manage a cluster crd
in the same namespace instead of watching for clusters in all namespaces. To manage a cluster
in another namespace, the roles in latter half of operator-common.yaml need to point to the new
namespace and the operator env var ROOK_CURRENT_NAMESPACE_ONLY should be set to false.

Signed-off-by: travisn <tnielsen@redhat.com>
2019-04-04 12:42:08 -06:00
Huamin Chen 3806baffe1 add ceph csi deploy options
Signed-off-by: Huamin Chen <hchen@redhat.com>
2019-02-12 21:20:41 -05:00
travisn c9d3d1bf17 reference the k8s pvc provisioner and remove outdated in-tree provisioner
Signed-off-by: travisn <tnielsen@redhat.com>
2019-01-19 07:48:00 -07:00
travisn 62f7e5d6ea ceph: update docs, code, and tests to use v1 crd types
Signed-off-by: travisn <tnielsen@redhat.com>
2018-12-05 14:33:11 -07:00
Ben Zieglmeier 6d04bbf430 ceph: Add CRD for Object Store User
Add the ability to create and manage object store users with CRDs

Signed-off-by: Ben Zieglmeier <benjamin.zieglmeier@target.com>
2018-11-21 15:15:05 -06:00
travisn 55e0ee26c0 monitor the OSDs for the lifetime of the cluster
Signed-off-by: travisn <tnielsen@redhat.com>
2018-07-06 15:08:59 -06:00
travisn 6502cda3b4 refactor cluster roles for minimal rbac access
Signed-off-by: travisn <tnielsen@redhat.com>
2018-06-25 12:57:25 -06:00
Jared Watts f3df68e573 operator, daemon, and cmd updates for supporting multiple storage types
Signed-off-by: Jared Watts <jbw976@gmail.com>
2018-05-18 14:32:20 -07:00