Commit Graph
926 Commits
Author SHA1 Message Date
Travis Nielsen 4eed2a644f Merge pull request #15433 from SkalaNetworks/master
fix(csi-addons): bind cephfs and rbd provisionners on non-colliding p…
2025-02-24 12:06:57 -07:00
Skala Networks d3c3d25c60 csi: bind cephfs and rbd provisionners on non-colliding ports for hostNetwork setups
Signed-off-by: Skala Networks <contact@skala.network>
2025-02-23 06:31:43 -05:00
Fabian Ponce 7467f19c23 helm: quote object store ingress hostname
Kubernetes permits wildcards as leading members of this field, but if it is not quoted, then there will be a YAML parsing error.

Signed-off-by: Fabian Ponce <me@fabianponce.com>
2025-02-21 22:26:58 -05:00
Travis Nielsen 2181170811 Merge pull request #15370 from travisn/osd-upgrade-checks
osd: Enable osd ok-to-stop checks on single node where there are at least three OSDs
2025-02-20 12:52:03 -07:00
Travis Nielsen 8f79b58edc Merge pull request #15392 from subhamkrai/update-ceph-v19.2.1
manifest: Update default ceph version to v19.2.1
2025-02-20 11:41:06 -07:00
subhamkrai 0e395f0a67 manifest: update default ceph version to v19.2.1
with ceph release v19.2.1 updating it to be dafult version
in rook.

Signed-off-by: subhamkrai <srai@redhat.com>
2025-02-20 23:24:54 +05:30
Blaine Gardner 73c931fc0a Merge pull request #15376 from BlaineEXE/obc-allow-list-obc-fields
object: disallow unsafe OBC fields by default
2025-02-19 12:00:54 -07:00
Travis Nielsen 3e52c6a59e Merge pull request #15399 from black-dragon74/add-csiaddonsnode-watcher-rbacs
manifest: Add list and watch capabilities to provisioners
2025-02-18 07:29:02 -07:00
Travis Nielsen 2e3c8c1f2a Merge pull request #15372 from hans-fischer/operator-podlabels
helm: add support for custom pod labels in operator deployment config…
2025-02-18 06:55:49 -07:00
Travis Nielsen c6c4ec2e87 Merge pull request #15402 from KarolGongola/fix_helm_chart_hardcoded_namespace_in_cephecblockpool
helm: Fix hardcoded namespace in cephECBlockPool StorageClass
2025-02-17 16:14:00 -07:00
Hans Fischer 1d37ac02c5 helm: add support for custom pod labels in operator deployment configuration
This adds a podLabel to the values yaml that will be
propagated to the rook-ceph-operator pod.

Signed-off-by: Hans Fischer <mail@hans-fischer.com>
2025-02-17 15:16:41 -07:00
Karol Gongola cf67cc26db helm: fix hardcoded namespace in cephecblockpool storageclass
I have realised that in cephECBlockPool is hardcocded 'rook-ceph' namespace, so this chart is not working if cluster has been created in different namespace. This change replaces hardcoded namespace with templated one.

Signed-off-by: Karol Gongola <karol.gongola@gmail.com>
2025-02-17 23:08:23 +01:00
Travis Nielsen 87e4092792 Merge pull request #15385 from ulagbulag/helm/add-support-for-ingress-path-type
helm: add support for ingress path type
2025-02-17 14:40:24 -07:00
Niraj Yadav ece302f35b manifest: add list and watch capabilities to provisioners
This patch adds `list` and `watch` verbs to cephfs and rbd
provisioner roles for CSIAddonNode objects.

Signed-off-by: Niraj Yadav <niryadav@redhat.com>
2025-02-17 15:32:21 +05:30
jcookin 70afe3c97c helm: fix deploy notes documentation link to CRDs
Signed-off-by: jcookin <56096898+jcookin@users.noreply.github.com>
2025-02-15 20:49:39 -07:00
Bipul Adhikari d25b26e890 csi: moves rbac for Tokenreview API from role to cluster role
CSI addons sidecar requires clusterrole permission for Tokenreview
Tokenreview is a cluster scoped API

Signed-off-by: Bipul Adhikari <badhikar@redhat.com>
2025-02-13 14:44:48 +05:45
Blaine Gardner 0e33536539 object: disallow unsafe OBC fields by default
Implement an allow list mechanism that disables potentially unsafe OBC
fields by default. OBC fields beyond `maxObjects` and `maxSize` don't
neatly fit into the OBC framework as it was originally envisioned and
implemented.

Some of the newly added configs could allow users to cause confusion for
themselves. Others might allow users to hijack others buckets. Some
might allow bricking the entire S3 store.

Out of an abundance of safety, allow-list the known-safe options by
default, and require administrators to enable potentially troublesome
options via the new operator-level config
`ROOK_OBC_ALLOW_ADDITIONAL_CONFIG_FIELDS`.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2025-02-12 14:18:01 -07:00
Ho Kim 0ed667b806 helm: add support for ingress path type 2025-02-11 06:14:52 +00:00
Travis Nielsen e068e156ce osd: enable osd ok-to-stop checks on single node for three osds
If there are at least three OSDs on a single node, we should
treat it as a potential production cluster and perform
the ok-to-stop checks during reconcile. Otherwise,
it may cause instability during upgrades on
single-node clusters.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-02-05 12:08:48 -07:00
Travis Nielsen 8ca9186038 Merge pull request #15326 from bipuladh/support-sidecar
csi: updates RBAC allow tokenreview creation
2025-02-05 07:39:41 -07:00
Bipul Adhikari 7ccd0cba13 csi: updates RBAC allow tokenreview creation
CSI addons sidecar requires tokenreview api access to verify authorization

Signed-off-by: Bipul Adhikari <badhikar@redhat.com>
2025-02-05 11:51:25 +05:45
parth 6cf97fd32b external: allow cephfs or rgw only deployments
currently there was a restriction to always create rbd pool
with this change only cephfs or rgw volumes created

Signed-off-by: parth-gr <partharora1010@gmail.com>
2025-02-04 14:27:36 +05:30
subhamkrai 3761fda37f csi: update csi-operator to v0.2.0
this commits updates the csi-operator to v0.2.0
and also brings latest yaml updates

Signed-off-by: subhamkrai <srai@redhat.com>
2025-01-31 16:26:25 +05:30
Praveen M 7a934393a9 csi: update RBACs needed for csi-omap-generator sidecar
ceph/ceph-csi/pull/4750 added a new controller that watches for the
VolumeGroupReplicationContent CR and regenerates the OMAP data.
This change needs RBACs for VolumeGroupReplicationContent and
VolumeGroupReplicationClass CR.

This commit updates the same for the `rbd-external-provisioner-runner`
ClusterRole.

Signed-off-by: Praveen M <m.praveen@ibm.com>
2025-01-29 12:01:40 +05:30
Artem Torubarov 25ee6b4f59 operator: custom hostname topology label
Signed-off-by: Artem Torubarov <artem.torubarov@clyso.com>
2025-01-24 15:59:07 +01:00
Niels de Vos 955fa9cae4 csi: update Kubernetes CSI sidecar images to current versions
The Kubernetes CSI sidecars have had several releases that were not
included in deployments by Rook yet, update them to the versions that
are available today:

- csi-node-driver-registrar:v2.13.0
- csi-provisioner:v5.1.0
- csi-attacher:v4.8.0
- csi-resizer:v1.13.1

Signed-off-by: Niels de Vos <ndevos@ibm.com>
2025-01-15 13:11:26 +01:00
parth-gr 61de34a11d external: fix rados namespace sc name
Currently, the sc name is hardcoded,
in future if we support multiple rados
namespace per tenant we need a variable name
updating sc names to contain rados-namespace name
ocs pr: https://github.com/red-hat-storage/ocs-operator/pull/2955

Signed-off-by: parth-gr <partharora1010@gmail.com>
2025-01-08 19:46:56 +05:30
Madhu Rajanna 2fdf7dab5f csi: remove extra RBAC access for create
With new version of external snapshotter
we dont need extra RBAC permission to
create the volumesnapshot and
volumesnapshotcontent

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2025-01-02 16:06:16 +01:00
Madhu Rajanna 610126c560 doc: update groupsnapshot to betav1
updating the groupsnapshot to betav1 api.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2025-01-02 16:06:16 +01:00
Blaine Gardner 52eab6cce4 Merge pull request #15199 from ideepika/wip-rgw-sidecar
object: add opsLogSidecar to gateway subsection from zone
2024-12-20 12:24:34 -07:00
Deepika Upadhyay e821edc24b object: move opsLogSidecar to gateway subsection from zone subsection
Update YAML configuration to correctly place the opsLogSidecar field
under gateway.opsLogSidecar instead of zone.opsLogSidecar, as it is a
configuration option specific to the RGW gateway.

Signed-off-by: Deepika Upadhyay <deepika.upadhyay@clyso.com>
2024-12-19 20:35:06 +05:30
Steven Kreitzer 463d9fb420 csi: csi-snapshotter flag typo; upgrade csi-snapshotter
Signed-off-by: Steven Kreitzer <skre@skre.me>
2024-12-18 09:09:29 -06:00
Travis Nielsen 1a44ab3fa3 Merge pull request #14646 from ideepika/wip-rgw-sidecar
add rgw ops sidecar for op logs
2024-12-17 10:35:08 -07:00
Deepika Upadhyay c5d27467d6 object: add rgw ops sidecar for op logs
the rgw operations for s3 can now be accessible using sidecar
rgw-ops-log availabe in json form that can be further filtered logging
for observability, this will set the rgw_enable_ops_log setting

Signed-off-by: Deepika Upadhyay <deepika.upadhyay@clyso.com>
2024-12-17 22:36:03 +05:30
Travis Nielsen 5baed04b6f Merge pull request #15153 from cobaltcore-dev/rgw-data-pool-bulk
rgw: bulk data pool by default
2024-12-17 07:16:00 -07:00
Artem Torubarov e3c3aafe09 rgw: bulk data pool by default
update CephObjecStore examples to set bulk=true for data pools by default

Signed-off-by: Artem Torubarov <artem.torubarov@clyso.com>
2024-12-17 09:47:59 +01:00
Blaine Gardner aaa16488de object: allow overriding rgw configs and flags
Implement #15119

Allow users to override RGW configurations by specifying Ceph config
options in the CephObjectStore. For configurations that require RGW to
be restarted when the config is applied, allow configs to be specified
as CLI arguments to the RGW as well.

This is an advanced option and is documented as such. Users should be
careful to understand the values they are setting, as there is no
validation to prevent the object store from breaking when these configs
are used.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-12-16 14:57:15 -07:00
Blaine Gardner c0799e0d39 Merge pull request #15115 from obnoxxx/update-api-deps
build: Update api gomod dependencies
2024-12-16 12:53:41 -07:00
Michael Adam c8a1bb21f6 build: update api go module dependencies
Signed-off-by: Michael Adam <obnox@samba.org>
2024-12-16 19:52:15 +01:00
Yaguang Tang 1563d32fbb external: fix exporter secret isn't created with external cluster
Fix the issue when using with external ceph cluster, ceph exporter
secret isn't created which cause ceph-exporter fail to run. By
default this option is false means ceph-exporter will run for
external cluster.

monitoring
  metricsDisabled: false

This patch also adds metricsDisabled option to helm values.yaml.

fixes #14275

Signed-off-by: Yaguang Tang <heut20008@gmail.com>
2024-12-13 17:01:08 -07:00
Travis Nielsen fd3d301746 Merge pull request #15131 from travisn/squid-default
manifest: Update default ceph version to v19
2024-12-11 15:19:18 -07:00
Travis Nielsen 07d8012d36 manifest: update default ceph version to v19
With the v19.2.0 release being out for some time now,
update the default version to be deployed with Rook
as v19.2.0.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-12-11 14:45:26 -07:00
Madhu Rajanna 07f5700a87 csi: update cephcsi to latest release
cephcsi 3.13.0 is released today and
update the Rook to use the latest image

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-12-11 14:31:17 -07:00
Artem Torubarov 83c8ec8160 rgw: add rgw_enable_apis config option
Signed-off-by: Artem Torubarov <artem.torubarov@clyso.com>
2024-12-10 11:53:27 +01:00
Blaine Gardner e6db006501 Merge pull request #15035 from BlaineEXE/object-revert-cosi-user-autocreation
Revert "object: create cosi user for each object store"
2024-12-09 16:21:58 -07:00
Blaine Gardner 61ea12f65b Merge pull request #15105 from BlaineEXE/upgrade-guide-1.16
docs: update guides and examples for v1.16 release
2024-12-09 16:20:28 -07:00
Travis Nielsen a8b7dbfa60 Merge pull request #15056 from b1-systems/prs/add-support-for-named-mds-metadata-pools
file: Add support for named MDS metadata pool names
2024-12-09 13:59:54 -07:00
Blaine Gardner 79e767e0e7 docs: remove deprecated toplogyKey beta labels
Remove long-deprecated topologyKey beta label from examples:
failure-domain.beta.kubernetes.io/zone

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-12-09 11:59:20 -07:00
Tobias Wolf 675678fad6 file: add support for named mds metadata pool names
This commit adds optional support to specify the MDS metadata pool name. It defaults to `<fsName>-metadata` as current implementation expects but allows customization if needed e.g. if exisiting naming conventions used `<fsName>_metadata`. Additionally an "preservePoolNames" boolean has been added to indicate that no generated pool names should be used.

Signed-off-by: Tobias Wolf <wolf@b1-systems.de>
2024-12-06 09:16:47 +01:00
Santosh Pillai 85c81946ce osd: enable encryption as day-2 operation
Migrate OSDs to enable encryption as day-2 operation.

Signed-off-by: Santosh Pillai <sapillai@redhat.com>
2024-12-06 09:33:03 +05:30