Commit Graph
129 Commits
Author SHA1 Message Date
Mateusz Gozdek 8ba3762fa4 docs: fix bunch of typos
Found by running the following command:

codespell -S .git,*.png,*.jpg -L \
aks,keyserver,atleast,dne,ser,ist,files\',ba,dum,iam,te -f -H

Signed-off-by: Mateusz Gozdek <mgozdekof@gmail.com>
2020-11-06 10:01:04 +01:00
Sébastien Han 1168dbc6ca ceph: assert error type before using it
We don't always get an error of the type "*exec.ExitError" so we must
validate the type before printing it otherwise the interface conversion
will fail.

Signed-off-by: Sébastien Han <seb@redhat.com>
2020-10-28 17:08:38 +01:00
Sébastien Han 9b980d136f ceph: log stderr in error when exec with output file
In order to properly debug errors, we need to merge stderr inside the
`err` reported so that we don't only see the stdout.
We were doing this when executing without file output, doing the same
for the output file.

Signed-off-by: Sébastien Han <seb@redhat.com>
2020-10-07 14:47:09 +02:00
subhamkrai 0fddfcf307 ceph: handle golangci-lint linter errcheck error
this commit handle golangci-lint linter errcheck.

`errcheck` - Errcheck is a program for checking for
unchecked errors in go programs. These unchecked errors
can be critical bugs in some cases

To see only staticcheck linter output
`golangci-lint run --disable-all -E errcheck`

Signed-off-by: subhamkrai <srai@redhat.com>
2020-09-30 22:24:34 +05:30
subhamkrai 829778f251 ceph: handle golangci-lint linter ineffassign
this commit will enable one more linter ineffassign
in golangci-lint.

This linter throws an error when variable is assigned and never used.

`golangci-lint run --disable-all -E ineffassign` is used detects ineffassign
errors only.

Signed-off-by: subhamkrai <subhamkumarrai03@gmail.com>
2020-09-21 14:31:18 +05:30
subhamkrai 1e9bb8e6e2 ceph: handle golangci-lint linter deadcode
this commit will enable one more linter `deadcode`
in golangci-lint .

Signed-off-by: subhamkrai <subhamkumarrai03@gmail.com>
2020-09-18 16:53:49 +05:30
subhamkrai 25c116a4bd ceph: handle golangci-lint linter gosimple
this commit handles all the errors  check for
golangci-lint linter gosimple.

Signed-off-by: subhamkrai <subhamkumarrai03@gmail.com>
2020-09-17 15:10:27 +05:30
Sébastien Han 89b3225441 ceph: add encryption support for osd pvc
We can now encrypted OSD device that were provisioned via a storage
class using the PV interface.
The encryption works at the storageClassDeviceSets level, which means we
can have encrypted and non-encrypted sets.
Using the new key `encrypted` we can turn it on.

Signed-off-by: Sébastien Han <seb@redhat.com>
2020-08-05 10:06:11 +02:00
Satoru Takeuchi 88f4b9c148 ceph: support crypt type device in OSD on PVC
Ceph supported encrypted OSD in the following two ways.

- Encrypt OSD by Ceph itself
- Encrypt OSD by user

However, Rook supports only the first way. Let's support this way too.

With supporting this way, Rook can use variety of encryption methods.
For example, TPM can be used to manage encrypt key. In fact, I use TPM
as follows.

https://github.com/cybozu-go/sabakan/blob/57ff3ab560acb99d23aa8901c1018bf865f9ff4d/docs/disk_encryption.md#disk-encryption

Signed-off-by: UMEZAWA Takeshi <takeshi-umezawa@cybozu.co.jp>
Signed-off-by: morimoto-cybozu <kenji_morimoto@cybozu.co.jp>
Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
2020-08-03 21:17:06 +00:00
subhamkrai c938849cf8 ceph: closing file which are open for writing
using defer for closing file which are open
for writing is not safe. so closing file again
following  below steps:
1. open files
2. defer file.close()
3. write
4.file.close()

these will make sure files are closed.

Signed-off-by: subhamkrai <subhamkumarrai03@gmail.com>
2020-07-30 22:37:56 +05:30
subhamkrai 0279025e9e ceph: handling all the gosec errors
a few of the gosec errors were left. so
this commit will resolve all the errors.

Signed-off-by: subhamkrai <subhamkumarrai03@gmail.com>
2020-07-30 08:19:55 +05:30
subhamkrai de8e93274d ceph: handling gosec errors code g104
this commit handles all the gosec g104
(i.e Audit errors not checked) error.

Signed-off-by: subhamkrai <subhamkumarrai03@gmail.com>
2020-07-28 23:52:23 +05:30
subhamkrai bcd7faed4e ceph: suppress gosec errors for g204, g304, g101
this commit suppress the gosec errors for

g204: Audit use of command execution.
g304: File path provided as taint input.
g101: Look for hard coded credentials.

Signed-off-by: subhamkrai <subhamkumarrai03@gmail.com>
2020-07-28 11:10:48 +05:30
Travis Nielsen cf53467380 core: suppress gosec errors for closing files
To ensure a file handle is closed, we defer the close command
so it is guaranteed to run when the method returns. The closing
of the file handle is not going to fail in our usage since we aren't
using the SetDeadline on the files that would cancel a request
and return an error.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-07-24 12:31:13 -06:00
Sébastien Han fa32f5323d ceph: fix exec output
The previous code was overriding the content of `out`, now we just
return after the error.

Signed-off-by: Sébastien Han <seb@redhat.com>
2020-06-25 17:05:07 +02:00
Sébastien Han 5f74e493ef ceph: small user delete refactor
Do not return error code, interpret it directly, put the error as part
of the output on failures.

Signed-off-by: Sébastien Han <seb@redhat.com>
2020-06-18 18:49:03 +02:00
Sébastien Han 84d1e28c99 ceph: add external support for objectstoreuser
Now, the object store user is capable of creating s3 users on an
external Ceph cluster.

Signed-off-by: Sébastien Han <seb@redhat.com>
2020-06-18 16:34:01 +02:00
Travis Nielsen 32730123ea ceph: add support for multipath devices
Add mpath to the list of supported device types,
although it will only work for OSDs on PVCs.
OSDs on a raw device without PVCs have not
yet been tested.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-05-06 17:12:25 -06:00
morimoto-cybozu 0c3439c707 ceph: check LV availability by "ceph-volume lvm list"
This commit adds support for LVs to the device availability check
in the OSD prepare pod.
The availability of an LV is checked by "ceph-volume lvm list".
If it returns non-empty result, the LV is in use and not available.

Closes: https://github.com/rook/rook/issues/5075
Signed-off-by: morimoto-cybozu <kenji_morimoto@cybozu.co.jp>
2020-03-27 13:30:08 +00:00
morimoto-cybozu ab83738aac ceph: fix device path passed to "ceph-volume inventory"
This commit fixes the argument for "ceph-volume inventory".
When a device "/dev/mapper/foo" is being checked for its availability,
the argument should not be "/dev/foo" nor "/dev/dm-1".

Signed-off-by: morimoto-cybozu <kenji_morimoto@cybozu.co.jp>
2020-03-27 11:24:47 +00:00
Satoru Takeuchi 8a13310ddb ceph: Consider the various paths of sgdisk
The path of sgdisk depends on the systems.

Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
2020-03-25 12:27:14 +00:00
Sébastien Han e96dc646a2 rook: add ExecuteCommandWithEnv
We can now execute commands and pass env variables to the executor.

Signed-off-by: Sébastien Han <seb@redhat.com>
2020-03-20 17:37:58 +01:00
Travis Nielsen e8f9cfcb71 exec: always write commands to debug log
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-03-19 07:49:54 -06:00
Travis Nielsen f2ecaa2bda exec: remove the unused actionName param
The helpers for executing a process have long required an actionName
param which is not being used. Now we remove the old param
while also cleaning up various other usages of the exec
package.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-03-19 07:49:53 -06:00
Travis Nielsen 84b8cdcf75 exec: simplify the exec package from unused methods and logging
The methods and arguments to the exec methods are not all used anymore.
This cleans up the methods to only what is necessary to improve
the readability and maintainability.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-03-19 07:49:53 -06:00
Travis Nielsen 7d2811bfb6 ceph: remove obsolete ipv4 command line flags
Long ago the ipv4 flags were renamed to public-ip and private-ip
so we can go ahead and remove the obsolete flags.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-03-19 07:49:53 -06:00
Travis Nielsen 0344074c82 ceph: remove dead code for process management
Rook no longer relies on its own process management, now we can rely
completely on Kubernetes to manage the pod lifecycle. The code
to check for running processes and replacement them hasn't been
used for a long while.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-03-19 07:49:53 -06:00
Sébastien Han a3068dee0b ceph: separate controller for CephBlockPool CRD
Now, the CephBlockPool CRD is managed with the controller-runtime.
So the watcher is outside of the main controller reconciliation loop of
CephCluster which brings numerous benefit such as:

* having its own reconciliation loop
* won't block anything from the main CephCluster controller loop
* fast than waiting for CephCluster loop to completion

Partially close: https://github.com/rook/rook/issues/1981
Signed-off-by: Sébastien Han <seb@redhat.com>
2020-03-02 17:31:03 +01:00
Sébastien Han 65e1c054a3 ceph: only print command when running debug mode
We don't need commands e run under the hood. Enable debug logs to see
that.

Signed-off-by: Sébastien Han <seb@redhat.com>
2020-03-02 09:29:48 +01:00
Nizamudeen 53883f68cf ceph: Handling Unhandled errors
This commit is to handle all those unhandled errors which raises the gosec warning.

Fixed G104: Unhandled Errors are handled now

Signed-off-by: Nizamudeen <nia@redhat.com>
2020-02-21 22:48:24 +05:30
Nizamudeen 78ef4abeec ceph: Fixing the potential file inclusion error
This commit is also part of gosec error handling which handles the following issue:

Fixed G304: Potential File inclusion by cleaning up the file path

Signed-off-by: Nizamudeen <nia@redhat.com>
2020-02-14 12:22:49 +05:30
Sébastien Han c08c3ced05 ceph: add support for metadata PVC for OSD on PVC
We now support the addition of the PVC that acts as a metadata device
for a given OSD.
For this, you need to create a new `volumeClaimTemplates`, its name must
be "metadata" otherwise, Rook won't pick it up.

A template will look like this:

```
volumeClaimTemplates:
- metadata:
    name: data
  spec:
    resources:
      requests:
        storage: 10Gi
    # IMPORTANT: Change the storage class depending on your environment (e.g. local-storage, gp2)
    storageClassName: gp2
    volumeMode: Block
    accessModes:
      - ReadWriteOnce
- metadata:
    name: metadata
  spec:
    resources:
      requests:
        storage: 6Gi
    # IMPORTANT: Change the storage class depending on your environment (e.g. local-storage, gp2)
    storageClassName: gp2
    volumeMode: Block
    accessModes:
      - ReadWriteOnce
```

We now map block and block.db directly inside the container instead of
running ceph-volume activate. This is much cleaner.

Closes: https://github.com/rook/rook/issues/3852
Signed-off-by: Sébastien Han <seb@redhat.com>
2020-02-11 17:30:02 +01:00
Sébastien Han 227d2d527a ceph: osd store refactor
Multiple things:

1. We removed all the function/methods/tests that were used to
create and manage rook legacy OSDS as well as bringing support to
Bluestore OSD only.
It also fixes various go-lint issues in the respectives files.

2. use c-v inventory to detect available devices:
Now we rely on the 'ceph-volume inventory' command to tell us if a
device is available or not.

3. implement raw mode for osd on pvc
When an OSD will be bootstrap on a PVC, the new c-v raw mode will be
used. It consists of putting block, db and wal under the same device.
Here LVM is out of the picture and the raw device is used as is. The
implementation is backward compatible so existing OSD on PVC will LVM
will continue to operate.

Closes: https://github.com/rook/rook/issues/4363
Signed-off-by: Sébastien Han <seb@redhat.com>
2020-01-23 19:13:09 +01:00
Sébastien Han dd659de46f ceph: add partition support
We now support partitions via 2 ways:

* if `useAllDevice: true`: partitions will be taken into account and
presented as OSD candidate
* if specified in the cluster CR: it'll picked up as well

Signed-off-by: Sébastien Han <seb@redhat.com>
2020-01-16 09:34:46 +01:00
Travis Nielsen e2dcfc6330 util: no verbose logging for retry messages
The retry messages are too verbose with the stack trace
since the aggregated messages were added. This change
turns off the verbose message.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-01-07 12:18:54 -07:00
Juan Miguel Olmo Martínez 7b3e2b006e ceph: Do not log sensitive information in debug mode
Fix security issues identified by TrailOfBits:
Logging of sensitive information in debug mode

Problematic debug lines which can contain sensitive data have been removed

Resolves: #4568

Signed-off-by: Juan Miguel Olmo Martínez <jolmomar@redhat.com>
2020-01-03 17:16:25 +01:00
Sébastien Han 04ad1636c8 ceph: reject ceph dm devices
Since https://github.com/rook/rook/pull/4219, lv devices are now
presented to ceph-volume when preparing the device.
So on this initial run, this won't fail because the dm hasn't been
created yet but if an orchestration is re-triggered, the prepare pod
ensures idempotency with the ceph-volume batch command.
Unfortunately, c-v seems to have a bug where it doesn't read the dm to
detect whether or not they are ceph members already.
Ceph bug: https://tracker.ceph.com/issues/43209

Signed-off-by: Sébastien Han <seb@redhat.com>
2019-12-09 16:17:26 +01:00
dulltzandSatoru Takeuchi dfe45ac6b0 ceph: support OSD on PVC backed by LV
"OSD on PVC" doesn't work for PV backed by LV. Fixing this problem
by the following changes.

- Rook accepts LVM disk type.
- If a LV-backed device is passed, Rook/Ceph invokes
  "ceph-volume lvm prepare" with "--data vg/lv"
  instead of "--data /path/to/device".
- If a LV-backed device is passed, Rook/Ceph suppresses
  activation/deactivation of VG that owns this LV.

Fixes: https://github.com/rook/rook/issues/4185
Signed-off-by: dulltz <isrgnoe@gmail.com>
Co-authored-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
2019-12-05 17:26:27 +00:00
Guangming Wang 950af10e62 cleanup: cleanup codebase
device.go: replace string func Index with Contains.

Signed-off-by: Guangming Wang <guangming.wang@daocloud.io>
2019-11-07 19:45:43 +08:00
Guangming Wang a9063c27e9 cleanup: cleanup codebase
monitoredproc_test.go: remove redundant break.

Signed-off-by: Guangming Wang <guangming.wang@daocloud.io>
2019-11-07 19:45:39 +08:00
Guangming Wang e5e0369e37 cleanup: cleanup codebase
exec.go: use String method of bytes itself.

Signed-off-by: Guangming Wang <guangming.wang@daocloud.io>
2019-11-07 19:45:32 +08:00
Juan Miguel Olmo Martínez 7c942604f6 ceph: Get <ceph-volume inventory> data in dev. configmaps
**Description of your changes:**
This modification adds the information extracted from 'ceph-volume inventory':
command to the device configmaps generated by the discovery daemon when
"rook discover" starts with the new boolean "--use-ceph-volume" parameter.

Resolves #
https://github.com/rook/rook/issues/2606

Now the <cephVolumeData> field contains all the information returned
from <ceph-volume inventory> command.

Signed-off-by: Juan Miguel Olmo Martínez <jolmomar@redhat.com>
2019-11-06 10:22:56 +01:00
Santosh Pillai 8ea693a740 ceph: fix operator reconcile to restart osds daemons
OSD on PVC does not upgrade when the user upgrades the ceph version on cluster-on-pvc yaml.
The solution incudes:
   - upgrade osd prepare and daemon pods on upgrade
   - skip c-v prepare if filesystem is already present on the pvc device.
   - skip lvm release in case of upgrade.

Signed-off-by: Santosh Pillai <sapillai@redhat.com>
2019-10-23 16:56:15 +05:30
Mikaël Cluseau 0267433484 fix: PARTNAME override ID_PART_ENTRY_NAME
When both PARTNAME and ID_PART_ENTRY_NAME are specified, rook takes
PARTNAME in account, overriding ID_PART_ENTRY_NAME. As PARTNAME is not
always updated by the kernel after sgdisk --change-name, it's better to
do the opposite. It also makes GetDevicePartitions coherent with
parsePartLabel (called by GetPartitionLabel).

Signed-off-by: Mikaël Cluseau <mikael.cluseau@gmail.com>
2019-10-22 09:23:48 +11:00
rohan47andAshish Ranjan d2f52aebe5 Adds support for storageClassDeviceSet in rook-ceph operator
- Added code to support StorageClassDeviceSet spec provided in the cluster-on-pvc.yaml
- The code reads the StorageClassDeviceSet spec and creates pvc based on the ‘count’ field for each device set.
- OSD prepare job is started for each PVC which activates the ceph-volume on each PVC
- Finally OSD is started on each of the PVC device.

Co-authored-by: rohan47 <rohgupta@redhat.com>
Co-authored-by: Ashish Ranjan <aranjan@redhat.com>
Signed-off-by: Santosh Pillai <sapillai@redhat.com>
2019-08-12 09:24:13 -06:00
Ash Wu e6d43d9d0b Add linear to support diskType
Linear raid can be created using `mdadm --create --level=linear`,

By creating a linear raid disk on top of a logical volume,
we can pass the linear device to `ceph-volume lvm batch --prepare`
to provision a new OSD on top of the logical volume since
`ceph-volume` does not take lv as the data device.

Signed-off-by: Ash Wu <hSATAC@gmail.com>
2019-07-10 11:14:26 +08:00
Guy Margalit 2ce2382676 Refactor operator context init and allow to run local
Signed-off-by: Guy Margalit <guymguym@gmail.com>
Co-Authored-By: Sébastien Han <seb@redhat.com>
Co-Authored-By: Travis Nielsen <tnielsen@redhat.com>

This change is meant to allow running operators locally on a developer machine.
The idea is to allow faster development cycles by reducing the time and complexity of building -> deploying -> debugging on cluster.

For operators that rely only on kubernetes API this works easily - see cockroachdb and minio examples in development-flow doc.

The change includes:

- rook.NewContext() - Refactored to remove repeating initialization code that was copy-pasted in most of the operators in order to create the clusterd.Context and the Clientsets. Also it detects the mode of working in-cluster vs external and sets up the external mode with standard user config (~/.kube/config) and a job executor.
- rook.GetOperatorImage() - Refactor this repeating code in many operators to detect the operator pod image. Also added a global flag --operator-image that developers can use to override this when running locally.
- rook.TerminateOnError() - Added a convenient function.
2019-06-19 20:47:55 +03:00
Noah Watkins b29ba26b12 exec: add timeout variant of exec with output file
the existing exec interface with timeout is effectively the same as
ExecuteCommandWithOutput plus a timeout. this patch adds a variant of
ExecuteCommandWithOutputFile that uses a timeout.

Signed-off-by: Noah Watkins <noahwatkins@gmail.com>
2019-05-06 10:10:05 -07:00
Sébastien Han 871054e887 ceph: implement pod restriction on memory
If someone sets limits to pod, we want to ensure the possible
experience, so we want to make sure that people do not configure
inapropriate values for certain daemons.
We decide to fail if the memory.limit is too low.

Signed-off-by: Sébastien Han <seb@redhat.com>
2019-03-15 17:35:44 +01:00
travisn bdc3cf8146 osd: fix the device filter and improve device provisioning reliability
All devices detected by the discovery pod were being passed to the OSD provisioning pod
thus not always honoring the desired device list that should be provisioned.
Now the provisioning pod will be given the desired state from the crd,
then apply that state depending on the actual devices detected.
Also added a helper to ensure OSDsPerDevice is always valid.

Signed-off-by: travisn <tnielsen@redhat.com>
2019-02-26 16:11:25 -07:00