this commit update admission controller to v1 from
v1beta1. v1beta1 is deprecated in v1.16+ and unavailable
in v1.22+.
Signed-off-by: subhamkrai <srai@redhat.com>
The cockroachDB operator has not had community support in Rook.
Therefore, the time has come to deprecate and remove it.
If the sources are still needed, there is always git history.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
Currently, ValidatingWebhookConfiguration has two same named webhooks.
This causes kube-apiserver to create error logs
Signed-off-by: binoue <banji-inoue@cybozu.co.jp>
Minikube deprecates '--vm-driver' option. When user starts new minkube
run with '--driver=xxx', the test will fail and cause him to use the wrong
default value of 'virtualbox'.
Tested with minikube=v1.15.1, driver=kvm2 on Fedora32.
Signed-off-by: Shachar Sharon <ssharon@redhat.com>
Users may prefer to use docker alternatives, by setting DOCKERCMD
variable, which is set by 'common.sh'. Use it in 'copy_image_to_cluster'
instead of plain 'docker'.
Tested with DOCKERCMD=podman (podman-2.1.1).
Signed-off-by: Shachar Sharon <ssharon@redhat.com>
When we are done creating the partitions it's good to give the kernel
some time to reprobe the device and for udev to finish syncing up.
Signed-off-by: Sébastien Han <seb@redhat.com>
Permissions on the disk might changed due to the partitions being
created. So the CI user is not able to read the device correctly.
Closes: https://github.com/rook/rook/issues/6580
Signed-off-by: Sébastien Han <seb@redhat.com>
This updates the chart to make use of helm3 which has been released
for some time, and also permits CRDs to be installed pror to other objects
allowing the chart to be deployed at the same time as CRs for rook objects.
Co-authored-by: Pete Birley <pete@port.direct>
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
Found by running the following command:
codespell -S .git,*.png,*.jpg -L \
aks,keyserver,atleast,dne,ser,ist,files\',ba,dum,iam,te -f -H
Signed-off-by: Mateusz Gozdek <mgozdekof@gmail.com>
Add the following scenario:
* simple osd on pvc
* osd on pvc with db device
* osd on pvc with wal device
* encrypted simple osd on pvc
* encrypted osd on pvc with db device
* encrypted osd on pvc with wal device
Signed-off-by: Sébastien Han <seb@redhat.com>
When the Ceph cluster runs on PVC and the OSDs are encrypted we can
store LUKS's Key Encryption Key inside a Key Management System. Today,
Rook only supports HashiCorp Vault: https://www.vaultproject.io/
The CephCluster has now a new "security" field which will plug onto the
KMS. Here is an example:
security:
kms:
tokenSecretName: <name of the secret containing a Vault token, used
to authenticate>
connectionDetails: < a map of strings containing connection
information>
Refer to the ceph-cluster-crd documentation to lear more.
Closes: https://github.com/rook/rook/issues/6105
Signed-off-by: Sébastien Han <seb@redhat.com>
To be able to switch to helm v3, helm itself needs to be downloaded from
get.helm.sh. The old location from googleapis.com will only contain
helm v2 binaries. See [1].
[1] https://helm.sh/blog/get-helm-sh/
Signed-off-by: Thomas Bechtold <tbechtold@suse.com>
We can't use vm-drivers other than "docker" or "none" in minikube
scripts. It's because there is no device for OSD.
Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
Download the pre-defined helm by default to make the integration test simpler.
As a result, we can make PATH/TEST_HELM_PATH environment variable optional.
In addition, the default helm path can be simplified that doesn't include arch and os.
Signed-off-by: Takashi IIGUNI <iiguni.tks@gmail.com>
Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
It's messy to answer `y` everytime in `tests/script/kubeadm.sh clean.`
Since the cluster only exists for testing, it's safe to reset without prompting.
Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
This commit will remove "sudo rm /usr/local/bin/kube*" and "sudo rm kubectl" in "tests/scripts/kubeadm.sh".
I think that CI-test doesn't make those files.
Signed-off-by: tenzen-y <toyonomajyutushi@yahoo.co.jp>
It's not necessary to use random string for mon directory.
In addition, current implementation leaves garbage under /var/lib/rook.
Signed-off-by: Takashi IIGUNI <iiguni.tks@gmail.com>
moves the admission-controller server to use controller-runtime library for better support, maintainibility of code.
Signed-off-by: Vineet Badrinath <vbadrina@redhat.com>
Update the base operator image and cluster examples to use the latest
octopus release v15.2.4. Also cleanup some old examples and unit tests
that were still based on mimic.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
adds deploy.sh script to deploy validatingwebhookconfiguration and create secrets.
adds new command ceph admission-controller to start webhook servers.
adds validation for various rook custom resources
Signed-off-by: Vineet Badrinath <vbadrina@redhat.com>
The device name for OSD is fixed to /dev/xvdc. It works fine in the CI.
However, the name would be different in the developer's local environment.
Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
kubeadm installer tries to install the fixed versions of some packages.
So if the newer versions are already installed, this script fails.
Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
After running `swapoff -a`, systemd re-enable swap soon.
We should stop the corresponding unit to avoid this problem.
Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
- `helm_read` is not a command, but a variable
- If `helm` was installed in `helm.sh up`, the following `heml.sh clean`
fails since `helm_rest` can't find the installed `helm`.
Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
Only kubectl for amd64 is currently available.This modification adds
arm64 version of kubectl that can successfully deploy kubernetes on
arm64 machine.
Signed-off-by: Haichao Li <haichao.li@arm.com>
This commit adds a shell script to provision localPath PVs over the
disks in the nodes for OSDs and random host directoris for mons.
Note: currently it is hardcoded to select disk of `/dev/xvdb`.
Signed-off-by: Ashish Ranjan <ashishranjan738@gmail.com>
The minio operator has not had community support nor
any updates since being added to Rook. Support is being
removed from Rook due to this lack of community interest.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
The helper script to start minikube has dead code that is
no longer used. Specifically, the flex driver config isn't needed
anymore and the RBAC rules are all configured in the manifests.
Neither is there a need to have a restart option on minikube.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>