Commit Graph
455 Commits
Author SHA1 Message Date
Santosh Pillai 85c81946ce osd: enable encryption as day-2 operation
Migrate OSDs to enable encryption as day-2 operation.

Signed-off-by: Santosh Pillai <sapillai@redhat.com>
2024-12-06 09:33:03 +05:30
Madhu Rajanna 4e29717317 core: cleanup blockpool with annotation
This is similar to #14052 we did for radosnamespace
and this is an extension to support cleanup
at the blockpool level to cleanup the images
and the snapshots in a pool.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-10-23 12:20:31 +02:00
Travis Nielsen bc78f1d173 Merge pull request #14631 from sp98/fix-cleanup-jobs
core: fix host cleanup jobs to read flags correctly.
2024-08-22 10:32:11 -06:00
sp98 a44a22216f core: fix reading flags in cleanup job cmd
Cleanup job cli was not reading the flags correctly.
As a result, dataDirHostPath was never cleaned up.

Signed-off-by: sp98 <sapillai@redhat.com>
2024-08-22 19:46:55 +05:30
Blaine Gardner 58e3feaacf multus: fix default service account handling
The default service account isn't passed to the multus validation test
when no config file is used. Fix this.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-08-21 16:42:47 -06:00
Artem Torubarov 3f2d0eb1f8 mgr: lookup cluster crd on active mgr watch
Signed-off-by: Artem Torubarov <artem.torubarov@clyso.com>
2024-07-24 12:09:19 +02:00
Blaine Gardner 33f5407dd4 multus: add host checking to validation tool
In order to help users check that they have implemented the newly-added
Multus host configuration prerequisites, add a check to the validation
tool to verify connectivity.

Because users who are already running clusters with Multus enabled, add
a flag that allows users to only check for host configuration
prerequisites. This mode will not start the large number of clients that
would normally be started because those clients could disrupt a running
Rook cluster negatively.

Host checking pods require host network access. Many Kubernetes
distributions have pod security features enabled. In order to allow
non-Vanilla distros to run this tool, allow specifying a service account
that pods will run as, which can be configured by the admin to allow
test pods.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-07-10 13:41:38 -06:00
Redouane Kachach ee7c71c89e mgr: fix UpdateActiveMgrLabel to retry label update on failure
fix UpdateActiveMgrLabel to retry label update on failure. Previously,
the function always returned the current manager, even if update
failed, leading to inconsistent labels. This fix ensures retries on
failures.

Fixes: https://github.com/rook/rook/issues/13601

Signed-off-by: Redouane Kachach <rkachach@ibm.com>
2024-05-06 19:30:44 +02:00
momantech 496afdbad3 docs: delete duplicate words and revise the names of some methods
delete duplicate words and revise the names of some methods

Signed-off-by: momantech <cuimoman@qq.com>
2024-04-25 15:43:40 +08:00
sp98 f6b1449faa core: cephblockpoolRadosNamespace cleanup
Clean up pool images and snapshots in the
radosnamespace

Signed-off-by: sp98 <sapillai@redhat.com>
2024-04-12 21:49:49 +05:30
sp98 ef00fdac53 core: subvolumegroup clean up
Cleanup the resources created by subvolumegroup
when its deleted. Following resources will be cleaned up:
- OMAP value
- OMAP keys
- Clones
- Snapshots
- Subvolumes

Signed-off-by: sp98 <sapillai@redhat.com>
2024-04-10 17:34:45 +05:30
Thomas Way 97e3e69bf4 operator: use Linux container CPU quota
Go is not cgroup aware and by default will set GOMAXPROCS to the number
of available threads, regardless of whether it is within the allocated
quota. This behaviour causes high amount of CPU throttling and degraded
application performance.

Fixes: #13815

Signed-off-by: Thomas Way <thomas@6f.io>
2024-02-26 12:28:57 +00:00
sp98 94953f3f7b osd: create config before migration osd
create the ceph config and keyring file in the osd prepare pod
before starting the OSD migration. These files are needed to
run any ceph command.

Signed-off-by: sp98 <sapillai@redhat.com>
2024-01-08 15:35:45 +05:30
subhamkrai a30338ae6e Revert "osd: add callback function in osd removal"
This reverts commit 927af7c7f7.

Signed-off-by: subhamkrai <srai@redhat.com>
2023-12-07 21:01:04 +05:30
subhamkrai 927af7c7f7 osd: add callback function in osd removal
Adding callback function in the osd removal method
as in downstream there is requirement of adding extra
check before proceeding with osd removal.

Signed-off-by: subhamkrai <srai@redhat.com>
2023-11-30 10:48:24 +05:30
Sheetal Pamecha 06c176524a multus: improve the multus validation test's flakiness metric
Allow the flakiness threshold window to be tuned from the cli

Signed-off-by: Sheetal Pamecha <spamecha@redhat.com>
2023-10-31 15:23:10 +05:30
Blaine Gardner 0c721e05d5 multus: allow node profiles in validation test
Add the ability to specify node profiles in the multus validation test.

This addresses a few points of early feedback on the validation tool.
Statements below critique the tool's behavior before this patch.
1. The tool assumes all daemons are on public and cluster network, which
   means users who have a significantly smaller cluster net (a
   design choice) cannot run a single test to determine if Rook is
   likely to install correctly.
2. The tool does not have placement options to select only a subset of
   Kubernetes nodes to run validation on.
3. Users of multus seem to have a dedicated pool of storage nodes more
   often than the average Rook install. This makes sense for security-
   and perforance-minded users. The tool cannot run a single test to
   verify storage-only and general-workload nodes at one time.

These points are addressed by allowing users to specify configurations
for different "NodeTypes."

Each NodeType config has options for selecting the number of OSDs as
well as the number of other (non-OSD) Ceph daemons. This limits the
unnecessary exhaustion of cluster network addresses from critique 1.

Each NodeType config has its own placement (critique 2).

Users can define as many NodeTypes as needed to test the network for
their planned CephCluster. Specifically, this allows the tool to test
storage-only nodes and generalized-workload nodes at the same time. An
arbitrary number of NodeTypes are allowed to support even more highly
specialized cluster setups, such as multiple tiers of storage nodes
where some storage-only nodes may run more OSDs than others.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2023-10-04 15:26:35 -06:00
Redouane Kachach b3dd74ea20 docs: fixing some spelling issues
closes: https://github.com/rook/rook/issues/12987

Signed-off-by: Redouane Kachach <rkachach@redhat.com>
2023-10-03 13:50:17 +02:00
guoguangwu 235ac293ff core: import packages only once
Signed-off-by: guoguangwu <guoguangwu@magic-shield.com>
2023-09-16 13:40:17 +08:00
sp98 11b8d10a5a osd: replace existing OSDs to use new store
This follow up the #12507
- fixes replacing of encrypted OSDs.
- Updates OSD status at the end of reconcile

Signed-off-by: sp98 <sapillai@redhat.com>
2023-09-01 21:07:38 +05:30
sp98 886bb357ef osd: replace osd to use new backend store
If osd store is updated in the ceph cluster, then
delete OSDs one by one, cleanup disks and provision a new OSD on
the same disk

Signed-off-by: sp98 <sapillai@redhat.com>
2023-08-17 21:40:55 +05:30
Travis Nielsen 5f2a8bca61 Merge pull request #12561 from henrydavies1/remove-duplicate-ParseMonEndpoints
mon: delete ParseMonEndpoints from mon package
2023-08-03 08:00:46 -06:00
Henry Davies 2c8949e195 mon: delete ParseMonEndpoints from mon package
The function ParseMonEndpoints existed twice, once in the mon package
and once in the controller package. It has now been deleted from the
mon package. Usages in the mon package now reference the function
in the controller package.

Signed-off-by: Henry Davies <henrydavies@hotmail.co.uk>
2023-08-01 19:36:28 +01:00
Sheetal Pamecha d86fa2abbc osd: use cp -a command for copying init-containers
remove copy-binaries cmd and related code

Signed-off-by: Sheetal Pamecha <spamecha@redhat.com>
2023-07-31 09:31:38 +05:30
Blaine Gardner cc9514ad6c multus: revise kube config/client loading
The previous client loader routine assumed KUBECONFIG would be set in
CLI environments. Instead, now take this approach:

1. If KUBECONFIG is set, that is the de-facto override that informs the
   tool it is being run in a CLI environment.
2. Otherwise, try creating a client from the default kube config file.
3. If that fails, assume the tool is running in a Kubernetes Pod.

This will continue supporting dev/test environments so that building the
rook container is not necessary for development. It also allows support
for highly opinionated environments (like deployed by OpenShift CSVs)
where it's not possible to install the Rook operator without also
deploying a CephCluster.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2023-07-28 09:50:00 -06:00
sp98 c13d34f8d3 osd: configure backend store
Configure osd backend store from the cephCluster spec

Signed-off-by: sp98 <sapillai@redhat.com>
2023-07-24 09:16:30 +05:30
subhamkrai 39b5c057ce core: faster recovery from rbd rwo node loss
in the existing node watcher, we'll check for node update
event and see if there are `out-of-service` taints are applied
and `ROOK_WATCH_FOR_NODE_FAILURE` is enabled in rook-ceph-operator-configmap,
if then we'll create the networkFence cr and delete the cr if nodes come back.
And, added the unit test too.

Signed-off-by: subhamkrai <srai@redhat.com>
2023-07-07 21:16:25 +05:30
travisn fd66825dad core: set logger for controller runtime
The controller runtime logger has not been set, which means we are missing
information that could be useful in troubleshooting the controllers.
Now the logger is enabled to report this logging in the operator
log.

Signed-off-by: travisn <tnielsen@redhat.com>
2023-07-05 12:20:43 -06:00
Blaine Gardner f8d9076a38 multus: add config file for validation tool
Allow the validation tool to read test config from a yaml file. To help
users, also allow outputting a config file with default values and
comments instructing how to use the config file.

This work is in anticipation of adding more advanced configuration
options that would be too cumbersome to set using cli flags.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2023-06-20 11:54:37 -06:00
iPraveenParihar 78d6528153 test: allow specifying custom nginx image for multus validation
Allow overriding the nginx server image used for the web server and clients from CLI with --nginx-image flag.
Set default image in flag as 'nginxinc/nginx-unprivileged:stable-alpine'

Signed-off-by: iPraveenParihar <praveenparihar68@gmail.com>
2023-05-24 21:04:24 +05:30
Blaine Gardner 3a27cb60b3 operator: pull multus validation test images before test
Before starting multus validation test clients, pull the client image to
all nodes. This will ensure that variations in client readiness timing
will not be affected by variations in the time nodes take to pull the
image. This is intended to reduce the number of false reports of flaky
multus networks.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2023-05-11 16:00:33 -06:00
Blaine Gardner 3a16953a29 Merge pull request #12192 from BlaineEXE/internal-external-client
operator: use KUBECONFIG context for cli if present
2023-05-05 18:38:30 +02:00
Blaine Gardner b72761c1a1 operator: use KUBECONFIG context for cli if present
Use contents of KUBECONFIG var for creating Kubernetes client interface
if its present. This allows running rook CLI commands locally for
quicker development iteration.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2023-05-05 09:15:28 -06:00
Blaine Gardner 7e9a2481f0 Merge pull request #12187 from BlaineEXE/multus-tester-require-one-of-networks-as-input
operator: validate multus validation networks in cli
2023-05-04 22:15:03 +02:00
Blaine Gardner 60bf33f39c operator: validate multus validation networks in cli
Even though this is validated in the validation process, validating in
the cli gives better user feedback and doesn't spam the user with
suggestions for the failure that aren't relevant.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2023-05-04 12:49:57 -06:00
Blaine Gardner d38d4d7d1e operator: fix package logger name for rookcli
Name was accidentally modified in PR #12069.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2023-05-04 11:52:17 -06:00
Blaine Gardner 5a1d1f2175 Merge pull request #12069 from BlaineEXE/multus-golang-tester
test: add multus validation test routine to rook binary
2023-05-02 19:37:29 +02:00
Blaine Gardner 0f6e7ee921 test: add multus validation test routine to rook binary
Add a more involved multus validation test to the Rook binary. Because
this is intended to be end-user runnable, make sure operator-only
commands are hidden.

Build this into the rook binary instead of creating a separate binary
for ease, and because any binary built with the kube api becomes 40+
megabytes. We save quite a bit of space by including this in the Rook
binary, which is good for keeping container layers as small as possible.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2023-05-02 10:23:00 -06:00
Javier 884d5e9855 osd: allow to use filter device
this feature is to allow the use of filters using the deviceFilter flag
by skipping devices that do not match the filter

Closes: #10340
Signed-off-by: Javier <sjavierlopez@gmail.com>
2023-04-21 13:13:59 -06:00
Redouane Kachach f00bd790a8 mgr: using dynamic mgr_role label to implement mgr HA
Closes: https://github.com/rook/rook/issues/11844

Signed-off-by: Redouane Kachach <rkachach@redhat.com>
2023-03-27 18:38:55 +02:00
Rakshith R 71e011f731 osd: add rotate-key functionality to rook's key-management cmd
This commit adds functionality to be able to rotate
key encryption key of encrypted PVC backed OSDs.
Necessary changes such as adding update functionality
to kms and rbac changes are made as well.

Signed-off-by: Rakshith R <rar@redhat.com>
2023-03-08 12:07:26 +05:30
Redouane Kachach 456a0c328c Revert "mgr: remove mgr sidecar"
This reverts commit ff75ec96b7.

Signed-off-by: Redouane Kachach <rkachach@redhat.com>
2023-03-07 13:12:50 +01:00
Redouane Kachach ff75ec96b7 mgr: remove mgr sidecar
With the new mgr HA implementation (based on readiness probe) we
don't need the mgr sidecar (live-watch) anymore. This commit is
intended to remove all the related code.

Signed-off-by: Redouane Kachach <rkachach@redhat.com>
2023-02-21 17:25:39 +01:00
parth-gr a84daf9bf0 core: change io/ioutil package to use io and os package
few functions got change as they were deprecated
for ex: ioutil.Readfile change to os.Readfile
ioutil.TempFile change to os.CreateTemp
And fixed golang-ci-lint-issues

Signed-off-by: parth-gr <paarora@redhat.com>
2023-02-17 20:38:29 +05:30
Travis Nielsen 403335177a core: read mon secret from file instead of env var
Environment variables are not recommended for secrets in pods since
they can be easily leaked if the environemnt variables are logged.
By mounting the mon secret as a file, the mgr and osd prepare pods
can read the mon secret from a file for better security.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-12-14 16:24:44 -07:00
Travis Nielsen 33e824a323 core: remove unnecessary env vars from pod specs
The fsid, username, and user secrets were from legacy and no
longer needed on the osd daemon or mon pods. This removes the
unnecessary env vars from the pod specs.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-11-18 16:39:22 -07:00
Travis Nielsen 5ef8d15659 build: format comments for go 1.19
The tool gofmt in go 1.19 requires certain formatting
in the comments section for better rendering.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-08-11 12:41:10 -06:00
Jiffin Tony Thottan 5c8ca01bd0 object: adding support for sse s3 for RGW
The RGW support server side encryption with help of s3 protocol, till
now the `sse:kms` was support in which keys will be provided by the user
and but it will be saved in external management service like vault. Now
the support for `sse:s3` is added so the entire encryption key
management is performed by RGW itsels.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2022-07-28 11:50:48 +05:30
subhamkrai 24802c559e core: fix golangci linter
fix golangci linter

Signed-off-by: subhamkrai <srai@redhat.com>
2022-04-04 20:59:31 +05:30
Divyansh Kamboj 9008409f87 core: add context parameter to functions
This commit adds context parameter to various functions, and remove the
usage of context.TODO.

Closes: https://github.com/rook/rook/issues/8701
Signed-off-by: Divyansh Kamboj <dkamboj@redhat.com>
2022-03-22 08:19:07 +05:30