This patch adds `list` and `watch` verbs to cephfs and rbd
provisioner roles for CSIAddonNode objects.
Signed-off-by: Niraj Yadav <niryadav@redhat.com>
CSI addons sidecar requires clusterrole permission for Tokenreview
Tokenreview is a cluster scoped API
Signed-off-by: Bipul Adhikari <badhikar@redhat.com>
Implement an allow list mechanism that disables potentially unsafe OBC
fields by default. OBC fields beyond `maxObjects` and `maxSize` don't
neatly fit into the OBC framework as it was originally envisioned and
implemented.
Some of the newly added configs could allow users to cause confusion for
themselves. Others might allow users to hijack others buckets. Some
might allow bricking the entire S3 store.
Out of an abundance of safety, allow-list the known-safe options by
default, and require administrators to enable potentially troublesome
options via the new operator-level config
`ROOK_OBC_ALLOW_ADDITIONAL_CONFIG_FIELDS`.
Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
If there are at least three OSDs on a single node, we should
treat it as a potential production cluster and perform
the ok-to-stop checks during reconcile. Otherwise,
it may cause instability during upgrades on
single-node clusters.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
currently there was a restriction to always create rbd pool
with this change only cephfs or rgw volumes created
Signed-off-by: parth-gr <partharora1010@gmail.com>
ceph/ceph-csi/pull/4750 added a new controller that watches for the
VolumeGroupReplicationContent CR and regenerates the OMAP data.
This change needs RBACs for VolumeGroupReplicationContent and
VolumeGroupReplicationClass CR.
This commit updates the same for the `rbd-external-provisioner-runner`
ClusterRole.
Signed-off-by: Praveen M <m.praveen@ibm.com>
The Kubernetes CSI sidecars have had several releases that were not
included in deployments by Rook yet, update them to the versions that
are available today:
- csi-node-driver-registrar:v2.13.0
- csi-provisioner:v5.1.0
- csi-attacher:v4.8.0
- csi-resizer:v1.13.1
Signed-off-by: Niels de Vos <ndevos@ibm.com>
With new version of external snapshotter
we dont need extra RBAC permission to
create the volumesnapshot and
volumesnapshotcontent
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
Update YAML configuration to correctly place the opsLogSidecar field
under gateway.opsLogSidecar instead of zone.opsLogSidecar, as it is a
configuration option specific to the RGW gateway.
Signed-off-by: Deepika Upadhyay <deepika.upadhyay@clyso.com>
the rgw operations for s3 can now be accessible using sidecar
rgw-ops-log availabe in json form that can be further filtered logging
for observability, this will set the rgw_enable_ops_log setting
Signed-off-by: Deepika Upadhyay <deepika.upadhyay@clyso.com>
Implement #15119
Allow users to override RGW configurations by specifying Ceph config
options in the CephObjectStore. For configurations that require RGW to
be restarted when the config is applied, allow configs to be specified
as CLI arguments to the RGW as well.
This is an advanced option and is documented as such. Users should be
careful to understand the values they are setting, as there is no
validation to prevent the object store from breaking when these configs
are used.
Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
With the v19.2.0 release being out for some time now,
update the default version to be deployed with Rook
as v19.2.0.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
This commit adds optional support to specify the MDS metadata pool name. It defaults to `<fsName>-metadata` as current implementation expects but allows customization if needed e.g. if exisiting naming conventions used `<fsName>_metadata`. Additionally an "preservePoolNames" boolean has been added to indicate that no generated pool names should be used.
Signed-off-by: Tobias Wolf <wolf@b1-systems.de>
cephcsi fixed a bug related to data loss
and its fixed in 3.12.3 release, This commit
updates the cephcsi to 3.12.3 release.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
This reverts commit a941b3c33f.
Stop creating the 'cosi' user in the CephObjectStore reconcile. This
step often fails for some amount of time during initial object store
creation, causing frequent user concern. It has also been the source of
some reported failures that would otherwise be non-breaking for certain
users.
Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
openshift cluster need to have access to
finalizers when we set the blockOwnerDeletion
if an ownerReference refers to a resource
we can't set finalizers on, This adds the extra
required permission
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
enable and disable the status of rados namespace
mirroring by looking at statusCheck spec of blockpool
Signed-off-by: parth-gr <partharora1010@gmail.com>
csiaddons required new RBAC in the next
release to create/update the csiaddonsnode
object based on the owner deployment/daemonset
names of the pods its running with.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>