Commit Graph
197 Commits
Author SHA1 Message Date
Blaine Gardner 0e33536539 object: disallow unsafe OBC fields by default
Implement an allow list mechanism that disables potentially unsafe OBC
fields by default. OBC fields beyond `maxObjects` and `maxSize` don't
neatly fit into the OBC framework as it was originally envisioned and
implemented.

Some of the newly added configs could allow users to cause confusion for
themselves. Others might allow users to hijack others buckets. Some
might allow bricking the entire S3 store.

Out of an abundance of safety, allow-list the known-safe options by
default, and require administrators to enable potentially troublesome
options via the new operator-level config
`ROOK_OBC_ALLOW_ADDITIONAL_CONFIG_FIELDS`.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2025-02-12 14:18:01 -07:00
Joshua Hoblitt 48a9b90642 object: add obc bucketOwner
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-01-31 08:48:41 -07:00
Joshua Hoblitt a55fdb3fbe object: add obc bucketLifecycle
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-01-21 16:01:37 -07:00
Niels de Vos 955fa9cae4 csi: update Kubernetes CSI sidecar images to current versions
The Kubernetes CSI sidecars have had several releases that were not
included in deployments by Rook yet, update them to the versions that
are available today:

- csi-node-driver-registrar:v2.13.0
- csi-provisioner:v5.1.0
- csi-attacher:v4.8.0
- csi-resizer:v1.13.1

Signed-off-by: Niels de Vos <ndevos@ibm.com>
2025-01-15 13:11:26 +01:00
Joshua Hoblitt 59c5c045b7 doc: add basic obc bucketPolicy description
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-01-13 10:56:24 -07:00
Madhu Rajanna d65c62e743 doc: update the vgs doc for beta API
updating the VGS document to match the
betav1 API.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2025-01-02 16:44:34 +01:00
Steven Kreitzer 463d9fb420 csi: csi-snapshotter flag typo; upgrade csi-snapshotter
Signed-off-by: Steven Kreitzer <skre@skre.me>
2024-12-18 09:09:29 -06:00
Travis Nielsen 5baed04b6f Merge pull request #15153 from cobaltcore-dev/rgw-data-pool-bulk
rgw: bulk data pool by default
2024-12-17 07:16:00 -07:00
Artem Torubarov e3c3aafe09 rgw: bulk data pool by default
update CephObjecStore examples to set bulk=true for data pools by default

Signed-off-by: Artem Torubarov <artem.torubarov@clyso.com>
2024-12-17 09:47:59 +01:00
Silvio Ankermann fcce3ca520 docs: fix misleading example for urlPrefix
The default value for protocols.swift.urlPrefix is "swift", which makes
the Swift API available at http://host:port/swift/v1. However, in the
documentation our example says "/swift", which resulted in the
unexpected endpoint http://host:port//swift/v1.

Apparently, Ceph distinguishes between both values even though their
docs[1] seem to suggest that using leading slashes is fine.

This commit fixes the examples in the documentation to use the default
value "swift".

[1]
https://docs.ceph.com/en/reef/radosgw/config-ref/#confval-rgw_swift_url_prefix

Fixes #15065

Signed-off-by: Silvio Ankermann <silvio.ankermann@cloudandheat.com>
2024-12-12 21:08:20 +01:00
Madhu Rajanna 07f5700a87 csi: update cephcsi to latest release
cephcsi 3.13.0 is released today and
update the Rook to use the latest image

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-12-11 14:31:17 -07:00
Artem Torubarov 83c8ec8160 rgw: add rgw_enable_apis config option
Signed-off-by: Artem Torubarov <artem.torubarov@clyso.com>
2024-12-10 11:53:27 +01:00
Travis Nielsen 2c207202c9 Merge pull request #15086 from zdover23/wip-doc-2024-12-04-Storage-Configuration-Block-Storage-RBD-block-storage-provision-storage
block-storage.md: Add formatting to namespaces
2024-12-09 16:39:53 -07:00
Blaine Gardner e6db006501 Merge pull request #15035 from BlaineEXE/object-revert-cosi-user-autocreation
Revert "object: create cosi user for each object store"
2024-12-09 16:21:58 -07:00
Santosh Pillai 85c81946ce osd: enable encryption as day-2 operation
Migrate OSDs to enable encryption as day-2 operation.

Signed-off-by: Santosh Pillai <sapillai@redhat.com>
2024-12-06 09:33:03 +05:30
Zac Dover fb682e2e24 doc: block-storage.md: Add formatting to namespaces
Add formatting to some namespace names and provisioner values in order
to make the
Storage-Configuration/Block-Storage-RBD/block-storage/provision-storage
section more legible.

Signed-off-by: Zac Dover <zac.dover@proton.me>
2024-12-04 13:39:06 +01:00
Niels de Vos f1d448cc46 csi: update csi-addons to v0.11.0
The csi-addons v0.11.0 release is now available.

See-also: https://github.com/csi-addons/kubernetes-csi-addons/releases/tag/v0.11.0
Signed-off-by: Niels de Vos <ndevos@ibm.com>
2024-11-26 10:38:54 +01:00
Madhu Rajanna e599ef67ef csi: update to latest cephcsi release
cephcsi fixed a bug related to data loss
and its fixed in 3.12.3 release, This commit
updates the cephcsi to 3.12.3 release.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-11-25 19:02:25 +01:00
Blaine Gardner fc08e87d44 Revert "object: create cosi user for each object store"
This reverts commit a941b3c33f.

Stop creating the 'cosi' user in the CephObjectStore reconcile. This
step often fails for some amount of time during initial object store
creation, causing frequent user concern. It has also been the source of
some reported failures that would otherwise be non-breaking for certain
users.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-11-21 16:03:32 -07:00
Satoru Takeuchi 62d99330d6 doc: clarify dataDirHostPath must be unique for each cluster
If there are multiple clusters, `dataDirHostPath` must be unique
for each cluster. However, it's not documented yet.
In addition, `ceph-teardown.md` was also updated because
the original document assumes that `dataDirHostPath` is
`/var/lib/rook` and the files for a cluster `rook-ceph` is
under `/var/lib/rook/rook-ceph`.

related issue:
https://github.com/rook/rook/issues/14790

Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
2024-10-31 22:15:17 +00:00
Blaine Gardner c7dfe7837e Merge pull request #14884 from cobaltcore-dev/rgw-default-placement
rgw: support custom name for default pool placement
2024-10-25 10:30:58 -06:00
Artem Torubarov b47dff9770 rgw: support custom name for default pool placement
introduce Default flag to CRD

Signed-off-by: Artem Torubarov <artem.torubarov@clyso.com>
2024-10-25 12:52:06 +02:00
Travis Nielsen 3b94c50d8b Merge pull request #14818 from iPraveenParihar/kms/vault-keyrotation
kms: key rotation support for vault kms
2024-10-24 11:38:33 -06:00
Travis Nielsen 58df41e0cf Merge pull request #14895 from Madhu-1/cleanup-block
core: Cleanup blockpool with annotation
2024-10-24 10:28:31 -06:00
Joshua Hoblitt f51cfbdf6b object: add bucketMaxObjects & bucketMaxSize to obc
Two new keys are added to ObjectBucketClaim.spec.additionalConfig to
support the configuration of bucket scope quota(s). This differs from
the existing maxObjects & maxSize keys, which manage a user scope
quota(s) on the automatically generated rgw user.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-10-23 14:39:38 -07:00
Madhu Rajanna 4e29717317 core: cleanup blockpool with annotation
This is similar to #14052 we did for radosnamespace
and this is an extension to support cleanup
at the blockpool level to cleanup the images
and the snapshots in a pool.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-10-23 12:20:31 +02:00
Niraj Yadav b040a02336 Revert "docs: add documentation for rbd volumegroupsnapshot"
This reverts commit 524b6071d2.

Signed-off-by: Niraj Yadav <niryadav@redhat.com>
2024-10-23 11:44:47 +05:30
Praveen M 01ccb5e20a docs: update docs for vault KMS key rotation support
Signed-off-by: Praveen M <m.praveen@ibm.com>
2024-10-23 11:43:55 +05:30
Niraj Yadav 524b6071d2 docs: add documentation for rbd volumegroupsnapshot
This PR adds the sample YAMLs and documentation
for the RBD VolumeGroupSnapshot.

Signed-off-by: Niraj Yadav <niryadav@redhat.com>
2024-10-15 16:09:01 +05:30
Madhu Rajanna 1d1ed5e962 csi: disable fencing in Rook
Disabling the RBD and CephFS fencing
in Rook for now as its having bugs where
Rook is blocklisting wrong IP address
due to timing issues.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-10-10 19:28:15 +02:00
Travis Nielsen b665d7a7b7 core: remove support for ceph quincy
Given that Ceph Quincy (v17) is past end of life,
remove Quincy from the supported Ceph versions,
examples, and documentation.

Supported versions now include only Reef and Squid.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-10-03 11:12:55 -06:00
Travis Nielsen 1c9727c271 docs: declare cephconfig settings stable
The cephConfig settings in the CephCluster CR have been
stable and there are no planned changes, so remove the
experimental documentation indicator. Also, clarify
the usage and the precedence of the ceph config
options.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-09-23 11:12:53 -06:00
Travis Nielsen 19ab0eab76 Merge pull request #14720 from black-dragon74/docs-add-vgs
docs: Add documentation for VolumeGroupSnapshot
2024-09-18 13:46:49 -06:00
Praveen M afad40e404 csi: update csi-addons to v0.10.0
The csi-addons v0.10.0 release is now available.
Ref: https://github.com/csi-addons/kubernetes-csi-addons/releases/tag/v0.10.0

Signed-off-by: Praveen M <m.praveen@ibm.com>
2024-09-18 12:19:46 +05:30
Niraj Yadav 1e3d08f114 docs: add documentation for volumegroupsnapshot
This PR adds the sample YAMLs and documentation
for the VolumeGroupSnapshot feature.

Signed-off-by: Niraj Yadav <niryadav@redhat.com>
2024-09-17 16:55:14 +05:30
Travis Nielsen 45cdbb6767 Merge pull request #14679 from galexrt/add_grafana_dashboards
docs: add grafana dashboards files to docs
2024-09-12 10:42:26 -06:00
Alexander TrostandTravis Nielsen 36f6807fbe docs: add grafana dashboards files to docs
Co-authored-by: Travis Nielsen <tnielsen@redhat.com>
Signed-off-by: Alexander Trost <galexrt@googlemail.com>
2024-09-12 15:44:16 +02:00
Travis Nielsen 58a0c834bf Merge pull request #14702 from parth-gr/csi-addons-docs
doc: add the pv encryption key rotation job
2024-09-10 08:12:57 -06:00
parth-gr 4af5b6a331 doc: add the pv encryption key rotation job
Add missing csi addon's feature in the Rook document

Signed-off-by: parth-gr <partharora1010@gmail.com>
2024-09-10 15:54:20 +05:30
Travis Nielsen b16c1f223e Merge pull request #14588 from cobaltcore-dev/rgw-pool-placement
Rgw pool placement
2024-09-09 11:16:54 -06:00
Madhu Rajanna d041be4bcf csi: update to new cephcsi release
we have 3.12.2 as the new cephcsi release
updating the rook to use the same.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-09-06 16:17:24 +02:00
Artem Torubarov 59175f0b40 rgw: pool placement
Signed-off-by: Artem Torubarov <torubarov.a.a@gmail.com>
2024-09-06 16:02:53 +02:00
Madhu Rajanna 05d579b607 csi: update csi-addons to v0.9.1
updating csi-addons to latest
v0.9.1 release.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-09-03 12:52:00 +02:00
Vamsi Krishna Sethu a26565d922 docs: fix ceph object multisite and update source code layout
Signed-off-by: Vamsi Krishna Sethu <sethuvamsikrishna@gmail.com>
2024-08-23 20:55:32 +05:30
Praveen M a1ddf4535d csi: update csi sidecars' image version
Below csi sidecars are updated with latest available versions

csi-resizer: v1.11.1
csi-provisioner: v5.0.1
csi-attacher: v4.6.1
csi-snapshotter: v8.0.1
csi-node-driver-registrar: v2.11.1

Signed-off-by: Praveen M <m.praveen@ibm.com>
2024-08-20 22:08:19 +05:30
Madhu Rajanna 7c7e8a2b32 csi: update cephcsi to 3.12.0
updating cephcsi image to 3.12.0
release.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-08-16 10:47:44 +02:00
Madhu Rajanna 123025f22c csi: update csi-addons to v0.9.0
As we have new csi-addons v0.9.0
updating the same here as well.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-08-16 07:57:16 +02:00
Blaine Gardner 5f98d2ea3e Merge pull request #13807 from jklippel/feature/swift-and-keystone
rgw: implement support for authentication using keystone for s3 and swift
2024-08-08 09:55:34 -06:00
ee8bcad49d rgw: add support for keystone auth + swift/s3
For the specification see:
<https://github.com/rook/rook/blob/master/design/ceph/object/swift-and-keystone-integration.md>

* extend the API object specs for swift and keystone integration

* adapt rgw to the new go-ceph version

  - The parameter lists of the API call have changes, as parameters
    ignored by the RGW Admin Ops API are no longer serialized, therefore
    the mock has to be adapted.

  - There is now validation for the user keys that are passed to the
    User get API, therefore things failed when we had empty keys in our
    User proxy object.

* expand the reconcile loop for the swift and keystone integration

* fix minor mistakes in design document

* add env var to pass extra args to minikube

  Minikube decides CPU cores and memory automatically based on the
  available resources on the machine which may be insufficient to
  run rook. This commit adds an environment variable to add arbitrary
  arguments to the minikube command, so both can be specified if
  desired.

* integration tests for swift and keystone

  The new integration of swift or s3 and keystone support by rook
  does not have any integration tests yet.

  This commit introduces integration tests for swift and keystone. The
  tests are done against a minimal keystone setup (keystone container
  image from Yaook-project (https://yaook.cloud), sqlite as database
  backend, cert-manager and trust-manager for test certificate setup).

  To prevent hardcoded credentials, passwords are generated
  by the tests. The integration tests use the openstack client
  (keystone- and swift-functionality) (https://docs.openstack.org/
  python-openstackclient/ latest/). This was a concious design decision
  to use client tooling as close as possible to the end user instead of
  using other go-libraries (such as gophercloud).

* add documentation on swift and keystone

  Currently there is no documentation on the use of Swift to access
  an object store as well as the use of OpenStack keystone for
  authentication.

  This commit adds documentation on the use of Swift and OpenStack
  keystone, as well as CRD-related documentation and an example setup.

* add integration tests for S3 via keystone

  This commit introduces integration tests for s3 and keystone. The
  tests are run against the same minimal keystone setup that the tests
  for swift and keystone use.

  The integration tests use the aws s3 client to use client tooling as
  close as possible to the end user instead of using other go-libraries.

Co-authored-by: Jan Klippel <jan.klippel@uhurutec.com>
Co-authored-by: Silvio Ankermann <silvio.ankermann@cloudandheat.com>
Signed-off-by: Sebastian Riese <sebastian.riese@cloudandheat.com>
Signed-off-by: Jan Klippel <jan.klippel@uhurutec.com>
Signed-off-by: Silvio Ankermann <silvio.ankermann@cloudandheat.com>
2024-08-08 14:26:21 +02:00
Blaine Gardner b4a2285aa6 object: use advertise endpoint for admin ops
RGW can only serve a single certificate. This limitation means that the
prior behavior of using the default service for admin ops when TLS is
enabled may mean it requires additional complex certificate management
to make sure the object store uses a certificate valid for Rook internal
admin ops and user connections.

This is needlessly complex for users. Instead, change Rook's behavior
and documentation to clarify that it will use the same endpoint intended
for S3 client applications. This means that users have a more
straightforward path to enabling both Rook and consuming applications.

More info: https://github.com/rook/rook/issues/14530

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-08-05 14:32:59 -06:00