Commit Graph
394 Commits
Author SHA1 Message Date
Blaine Gardner 88bf8dd475 doc: add obc allow list to pending release notes
Add a note about the upcoming potentially-breaking change to OBCs to the
v1.17 release notes. This covers usage of
`ROOK_OBC_ALLOW_ADDITIONAL_CONFIG_FIELDS` for OBC fields that some
admins might not want exposed to users.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2025-02-19 12:10:06 -07:00
Travis Nielsen 86a287030c docs: reset pending release notes
For the upcoming 4.17 release, we reset the pending release
notes so we can add new features to the list.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-01-14 09:57:27 -07:00
Blaine Gardner 80903df984 Merge pull request #15138 from jhoblitt/feature/obc-bucket-policy-alt1
object: add bucketPolicy to obc
2024-12-12 14:36:16 -07:00
Joshua Hoblitt 97b904c717 object: add obc bucketPolicy
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-12-12 13:36:26 -07:00
Travis Nielsen 7c2f41e72e build: add support for k8s 1.32
With the release of K8s 1.32, we update the CI and docs
to support this new release, to maintain the most recent
six releases of K8s.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-12-12 09:48:42 -07:00
Artem Torubarov 83c8ec8160 rgw: add rgw_enable_apis config option
Signed-off-by: Artem Torubarov <artem.torubarov@clyso.com>
2024-12-10 11:53:27 +01:00
Santosh Pillai 85c81946ce osd: enable encryption as day-2 operation
Migrate OSDs to enable encryption as day-2 operation.

Signed-off-by: Santosh Pillai <sapillai@redhat.com>
2024-12-06 09:33:03 +05:30
parth-gr 9785ef5c8d rbdmirror: enable periodic monitoring for rados namespace
enable monitoring for rados namespace

Signed-off-by: parth-gr <partharora1010@gmail.com>
2024-11-05 13:45:02 +05:30
Travis Nielsen 0fa21969df Merge pull request #14701 from parth-gr/rbd-mirror-rados
rbdmirror: enable rbd rados namespace mirroring
2024-10-10 09:35:22 -06:00
parth-gr 2cef47a9b7 rbdmirror: enable rbd rados namespace mirroring
Modify the CR to allow mirroring of an rados namespace
to a differently named namespace on the remote cluster

1) enable rados namesapce mirroring only
if the blockpool mirrroing is enabled

2) disable blockpool mirroing only if
all the namesapce mirroing is disabled

if the rbd mirroring fails and ceph version is not supported
provide a error message with supported version details
and reason of failing

Signed-off-by: parth-gr <partharora1010@gmail.com>
2024-10-10 14:23:11 +05:30
Travis Nielsen b665d7a7b7 core: remove support for ceph quincy
Given that Ceph Quincy (v17) is past end of life,
remove Quincy from the supported Ceph versions,
examples, and documentation.

Supported versions now include only Reef and Squid.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-10-03 11:12:55 -06:00
Travis Nielsen ceee04b671 docs: reset pending release notes
Since 1.15 is released, we reset the pending release notes
for the 1.16 release

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-08-28 15:22:46 -06:00
Zuhair AlSader 6714b86d3b manifest: add registry name to docker images
Signed-off-by: Zuhair AlSader <zuhair@devzero.io>
2024-08-20 13:35:08 -04:00
Travis Nielsen e157bb5a56 core: support k8s versions 1.26 through 1.31
With the release of K8s v1.31.0, we update the minimum
supported version to v1.26, and add v1.31 to the CI
so we can test the most recent six versions of K8s.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-08-13 16:54:52 -06:00
Blaine Gardner 6026fb1c36 docs: update upgrade docs for v1.15
Update Rook and Ceph upgrade docs for upcoming v1.15 release.
Tidy up pending release notes in the working text as well as official
doc texts.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-08-13 10:47:58 -06:00
ee8bcad49d rgw: add support for keystone auth + swift/s3
For the specification see:
<https://github.com/rook/rook/blob/master/design/ceph/object/swift-and-keystone-integration.md>

* extend the API object specs for swift and keystone integration

* adapt rgw to the new go-ceph version

  - The parameter lists of the API call have changes, as parameters
    ignored by the RGW Admin Ops API are no longer serialized, therefore
    the mock has to be adapted.

  - There is now validation for the user keys that are passed to the
    User get API, therefore things failed when we had empty keys in our
    User proxy object.

* expand the reconcile loop for the swift and keystone integration

* fix minor mistakes in design document

* add env var to pass extra args to minikube

  Minikube decides CPU cores and memory automatically based on the
  available resources on the machine which may be insufficient to
  run rook. This commit adds an environment variable to add arbitrary
  arguments to the minikube command, so both can be specified if
  desired.

* integration tests for swift and keystone

  The new integration of swift or s3 and keystone support by rook
  does not have any integration tests yet.

  This commit introduces integration tests for swift and keystone. The
  tests are done against a minimal keystone setup (keystone container
  image from Yaook-project (https://yaook.cloud), sqlite as database
  backend, cert-manager and trust-manager for test certificate setup).

  To prevent hardcoded credentials, passwords are generated
  by the tests. The integration tests use the openstack client
  (keystone- and swift-functionality) (https://docs.openstack.org/
  python-openstackclient/ latest/). This was a concious design decision
  to use client tooling as close as possible to the end user instead of
  using other go-libraries (such as gophercloud).

* add documentation on swift and keystone

  Currently there is no documentation on the use of Swift to access
  an object store as well as the use of OpenStack keystone for
  authentication.

  This commit adds documentation on the use of Swift and OpenStack
  keystone, as well as CRD-related documentation and an example setup.

* add integration tests for S3 via keystone

  This commit introduces integration tests for s3 and keystone. The
  tests are run against the same minimal keystone setup that the tests
  for swift and keystone use.

  The integration tests use the aws s3 client to use client tooling as
  close as possible to the end user instead of using other go-libraries.

Co-authored-by: Jan Klippel <jan.klippel@uhurutec.com>
Co-authored-by: Silvio Ankermann <silvio.ankermann@cloudandheat.com>
Signed-off-by: Sebastian Riese <sebastian.riese@cloudandheat.com>
Signed-off-by: Jan Klippel <jan.klippel@uhurutec.com>
Signed-off-by: Silvio Ankermann <silvio.ankermann@cloudandheat.com>
2024-08-08 14:26:21 +02:00
Blaine Gardner b76631ace9 Merge pull request #14467 from BlaineEXE/object-advertise-endpoint
object: add hosting.advertiseEndpoint config
2024-07-31 16:17:24 -06:00
Blaine Gardner a2b0b6449c object: add hosting.advertiseEndpoint config
Add CephObjectStore spec.hosting.advertiseEndpoint configuration. This
provides a clear documented default for which endpoint Rook "advertises"
to dependent resources like CephObjectStores, OBCs, and COSI
Buckets/Accesses and allows users to override the default behavior if
desired.

The current default is to round-robin an endpoint from
spec.hosting.dnsNames, which has proven to be troublesome for some
users' object store configurations. This change provides much-needed
disambiguation for users.

This may be a breaking change for some existing spec.hosting.dnsNames
users. This is unexpected but is documented.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-07-22 14:43:51 -06:00
Travis Nielsen 88e952a3ac osd: update the device class if desired state changes
Normally the device class of an OSD is determined at provisioning
and is not updated thereafter. In some scenarios the admin may
want to force update the device class to a new value. The device
classes can be updated by first setting allowDeviceClassUpdate
in the storage spec of the cephcluster, then updating the
device class specified on the deviceSets or other OSDs.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-07-17 13:54:21 -06:00
Travis Nielsen 22d4139b74 core: add support for ceph squid
With the release of the first squid RC, we add squid
to the supported versions and add tests to run
Rook against the squid release.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-07-15 10:04:32 -06:00
Travis Nielsen 0bea31ef7f pool: return error if device class update fails
Updating the device class swallowed any error if updated
for the pool. The error was not even logged, so we couldn't
troubleshoot why the new crush rule was not applied.
Log the error for troubleshooting and also fail the pool
reconcile since the desired configuration was not applied.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-07-10 12:59:43 -06:00
Jiffin Tony Thottan ba40f84123 object: update cosi images
Updating images for ceph cosi driver and side car.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2024-06-04 19:32:45 +05:30
Travis Nielsen 3abe851589 doc: reset pending release notes
Since v1.14 is released, we reset the pending release notes
for the v1.15 release.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-04-04 14:33:58 -06:00
Travis Nielsen 64f71d9258 helm: separate repository and tags for csi images
The csi images in the operator helm chart previously were a single
image name including the repository and tag in a single string.
Now the repository and tag values are separated to allow for
greater customization of the repository from the version tags.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-04-03 11:43:11 -06:00
Blaine Gardner 0736d7613d doc: update release notes and upgrade docs for v1.14
Update pending release notes, upgrade docs, and supplementary
documentation relevant for upgrades for the upcoming Rook v1.14 release.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-04-02 12:25:24 -06:00
Santosh Pillai b8ee8a46ec Merge pull request #13852 from sp98/support-azure-kms
core: azure kms support
2024-03-18 14:44:11 +05:30
sp98 4efe3982b0 core: azure kms support
Add support for store OSD encryption Keys in Azure KMS

Signed-off-by: sp98 <sapillai@redhat.com>
2024-03-15 11:23:25 +05:30
Blaine Gardner e41366bbcd Merge pull request #13890 from BlaineEXE/csi-disable-holder
csi: allow force disabling holder pods
2024-03-14 10:27:06 -06:00
Blaine Gardner 4f555dbbcb csi: allow force disabling holder pods
Add new CSI_DISABLE_HOLDER_PODS option for rook-ceph-operator.
This option will disable holder pods when set to "true".

In the long term, Rook plans to deprecate the holder pods entirely.
This new option will allow users to choose to migrate their clusters to
non-holder clusters when they are ready and able, giving them time to
gracefully migrate before the holders are permanently removed.

This option is set to "false" by default so that upgrading users don't
have their CSI pods modified unexpectedly.
Example manifests are modified to set this value to true so that new
clusters will not deploy holder pods.

Migrating users are provided with documentation to instruct them about
the new requirements they need to satisfy to successfully remove holder
pods, a procedure for migrating pods from holder to non-holder mounts,
and a way to delete holder pods once they are no longer in use.

When users set CSI_DISABLE_HOLDER_PODS="true", the CSI controller will
no longer deploy or update the holder pod Daemonsets, but it does not
delete any existing Daemonsets. This allows already-attached PVCs to
continue operating normally with their network connection continuing to
exist in the current holder pod. This is critical to avoid causing
ia cluster-wide storage outage.

More info: https://github.com/rook/rook/issues/13055

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-03-14 09:53:08 -06:00
Travis Nielsen 15f92a175d Merge pull request #13703 from thotz/prefix-provisioner-obc
object: provisoner prefix support
2024-03-12 12:16:45 -06:00
Travis Nielsen fdacfd51c5 object: create an object store based on shared pools
Until now, an object store would create all the necessary
metadata pools and the data pool that were exclusively
for its own object store. When isolation between object
stores is necessary, this would cause many pools and
PGs to be created in the cluster, which was not
manageable.

Now one set of pools can be created to be shared
by any number of object stores. The metadata and data
between each object store is isolated by
RADOS namespaces, which by design will keep the
data safe for multi-tenancy.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-03-11 11:20:57 -06:00
Jiffin Tony Thottan e0768f5e5f object: provisoner prefix support
add an option to set prefix for the name of obc provisioner instead of
ceph cluster namespace.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2024-03-11 13:42:11 +05:30
Jiffin Tony Thottan b0989ee1d2 object: add rgw dns names
The virtual hosting for bucket is provided with help of `rgw_dns_name`

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2024-03-08 13:43:25 +05:30
parth-gr ed6fb58bd1 ci: upgrade min k8s supported version to 1.25 combiner
upgrading minimum kubernetes supported version to v1.25.16
and max to k8s 1.29.2

Signed-off-by: parth-gr <partharora1010@gmail.com>
2024-03-07 21:59:04 +05:30
Madhu Rajanna 2611e924a2 csi: provide option to configure VGS
volumegroupsnapshot feature will be enabled
by default if the required CRD's are present
if not its disabled and user will have an option
to disable it if they dont require this feature.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-03-01 18:12:37 +01:00
Travis Nielsen d77cee791c Merge pull request #13362 from parth-gr/service-account-deafult
core: Set default service account on all Ceph daemons
2024-02-28 10:52:12 -07:00
Praveen M 10dea459ec doc: pending release notes for update netNamespaceFilePath PR
Signed-off-by: Praveen M <m.praveen@ibm.com>
2024-02-28 16:39:56 +05:30
parth-gr f7a9d8ff7b core: added rook-ceph-default service account
When a private docker registry is used and an
image pull secret is specified in the chart,
the pods with default Service Account fail to pull
the image due to authentication issues.
Added rook-ceph-default service account and modify the pods
specifications by adding the serviceAccountName

closes: https://github.com/rook/rook/issues/12786

Closes: https://github.com/rook/rook/issues/6673
Co-authored-by: Tareq Sharafy <tareq.sha@gmail.com>
Signed-off-by: parth-gr <partharora1010@gmail.com>
(cherry picked from commit 737fb099fe)
Signed-off-by: parth-gr <partharora1010@gmail.com>
2024-02-28 13:32:55 +05:30
travisn 806608cdbc pool: allow setting the application on a pool
Rook has been setting the application automatically on all
pools to rbd for CephBlockPools, rook-ceph-rgw for
CephObjectStores, mgr on the built-in .mgr pool,
and nfs on the built-in .nfs pool.

The legacy pool device_health_metrics is long gone
from Pacific which is no longer supported, so we can
remove special handling for that pool in the upgrade
guide and in the code.

The application setting is now available on the pool spec
although it is not expected to commonly need to override
the default applications set by Rook.

The application for CephFilesystem pools is now being
set to cephfs, where it was previously blank.

Signed-off-by: travisn <tnielsen@redhat.com>
2024-02-14 16:53:25 -07:00
subhamkrai 135307a4df ci: upgrade min k8s supported version to 1.24.17
upgrading minimum kubernetes supported version to v1.24.17
and also upgrading other kubernetes version to their latest
respective version.

Signed-off-by: subhamkrai <srai@redhat.com>
2024-02-13 22:11:44 +05:30
Praveen M d28febaa61 csi: remove CSI_ENABLE_READ_AFFINITY
This commit removes the `CSI_ENABLE_READ_AFFINITY` since
it is no longer utilized after addition of the read affinity
option per cluster via CSIDriverSpec.

Signed-off-by: Praveen M <m.praveen@ibm.com>
2024-02-06 20:21:57 +05:30
travisn 3863ed27e1 docs: clear the pending release notes for 1.14
Since the v1.13.0 release is out, clear the pending
release notes to make way for the v1.14 features.

Signed-off-by: travisn <tnielsen@redhat.com>
2023-12-13 14:51:10 -07:00
Blaine Gardner 06d18a7122 docs: update upgrade docs for v1.13 release
Update docs for the upcoming v1.13 release.

Ensure that the pending release doc has critical notes.

Ensure upgrade guide versions are updated and tested.

Clarify some minor documentation points regarding features present in pending release doc.

Special care has been taken to update notes and docs for removal of the admission controller, which may be confusing for the estimated-small number of acive users.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2023-12-08 14:12:20 -07:00
Rakshith R a3220d827d csi: update default cephcsi version to 3.10.0
This commit updates default cephcsi driver version
to v3.10.0 and filesystem reconciler now creates
csi subvolumegroup by default.

Signed-off-by: Rakshith R <rar@redhat.com>
2023-12-06 19:57:40 +05:30
Alexander Trost 3097455d78 Merge pull request #13246 from koor-tech/ceph_config_via_cluster_crd_impl
operator: allow setting ceph config options via ceph cluster crd
2023-12-02 11:27:20 +01:00
Alexander Trost 4ed35d6bd6 operator: allow setting ceph config options via ceph cluster crd
This implements the "Ceph Config via Ceph Cluster CRD" design document
as a `cephConfig:` structure on the CRD.
This also fixes the `yq` commands used to manipulate the
`cluster-test.yaml` that caused CI issues for this PR and potentially
unknowingly others.

Signed-off-by: Alexander Trost <galexrt@googlemail.com>
2023-12-02 00:05:48 +01:00
subhamkrai 28cc1ebc55 core: remove webhook & controller-runtime from apis
This commits removes controller-runtime dependencies
from the apis dir and to achieve that we are removing
webhook.

Signed-off-by: subhamkrai <srai@redhat.com>
2023-12-01 14:15:40 +05:30
travisn 03d077aa6b core: remove support for ceph pacific
Pacific is end of life and no longer necessary to
support in Rook with v1.13.

Signed-off-by: travisn <tnielsen@redhat.com>
2023-11-14 17:07:03 -07:00
travisn 673fb8a46e docs: reset the pending release notes for v1.13
The 1.13 pending release notes are now reset.

Signed-off-by: travisn <tnielsen@redhat.com>
2023-08-01 15:44:08 -06:00
Jiffin Tony Thottan b48dc8a335 object: intial cosi driver controller design
Adding CephCOSIDriver CRD and controller. The controller will bring up
the ceph cosi driver when first object store is created in the rook
operator namespace. Then admin can defined COSI CRDs like BucketClass
and BucketAccessClass for different object stores deployed via Rook.
Using the BucketClass and BucketAccessClass, user can define
BucketAccess for backend bucket in the RGW. The CephCOSIDriver CRD
defines configuration options for ceph cosi driver. In the first version
its usability is minimal. Even if it is not defined Rook will bring up
the ceph cosi driver with default values.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2023-07-18 22:49:41 +05:30