Commit Graph
777 Commits
Author SHA1 Message Date
Travis Nielsen 4eed2a644f Merge pull request #15433 from SkalaNetworks/master
fix(csi-addons): bind cephfs and rbd provisionners on non-colliding p…
2025-02-24 12:06:57 -07:00
Skala Networks d3c3d25c60 csi: bind cephfs and rbd provisionners on non-colliding ports for hostNetwork setups
Signed-off-by: Skala Networks <contact@skala.network>
2025-02-23 06:31:43 -05:00
Travis Nielsen 2181170811 Merge pull request #15370 from travisn/osd-upgrade-checks
osd: Enable osd ok-to-stop checks on single node where there are at least three OSDs
2025-02-20 12:52:03 -07:00
Travis Nielsen 8f79b58edc Merge pull request #15392 from subhamkrai/update-ceph-v19.2.1
manifest: Update default ceph version to v19.2.1
2025-02-20 11:41:06 -07:00
subhamkrai 0e395f0a67 manifest: update default ceph version to v19.2.1
with ceph release v19.2.1 updating it to be dafult version
in rook.

Signed-off-by: subhamkrai <srai@redhat.com>
2025-02-20 23:24:54 +05:30
Blaine Gardner 73c931fc0a Merge pull request #15376 from BlaineEXE/obc-allow-list-obc-fields
object: disallow unsafe OBC fields by default
2025-02-19 12:00:54 -07:00
Niraj Yadav ece302f35b manifest: add list and watch capabilities to provisioners
This patch adds `list` and `watch` verbs to cephfs and rbd
provisioner roles for CSIAddonNode objects.

Signed-off-by: Niraj Yadav <niryadav@redhat.com>
2025-02-17 15:32:21 +05:30
Bipul Adhikari d25b26e890 csi: moves rbac for Tokenreview API from role to cluster role
CSI addons sidecar requires clusterrole permission for Tokenreview
Tokenreview is a cluster scoped API

Signed-off-by: Bipul Adhikari <badhikar@redhat.com>
2025-02-13 14:44:48 +05:45
Blaine Gardner 0e33536539 object: disallow unsafe OBC fields by default
Implement an allow list mechanism that disables potentially unsafe OBC
fields by default. OBC fields beyond `maxObjects` and `maxSize` don't
neatly fit into the OBC framework as it was originally envisioned and
implemented.

Some of the newly added configs could allow users to cause confusion for
themselves. Others might allow users to hijack others buckets. Some
might allow bricking the entire S3 store.

Out of an abundance of safety, allow-list the known-safe options by
default, and require administrators to enable potentially troublesome
options via the new operator-level config
`ROOK_OBC_ALLOW_ADDITIONAL_CONFIG_FIELDS`.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2025-02-12 14:18:01 -07:00
Travis Nielsen e068e156ce osd: enable osd ok-to-stop checks on single node for three osds
If there are at least three OSDs on a single node, we should
treat it as a potential production cluster and perform
the ok-to-stop checks during reconcile. Otherwise,
it may cause instability during upgrades on
single-node clusters.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-02-05 12:08:48 -07:00
Travis Nielsen 8ca9186038 Merge pull request #15326 from bipuladh/support-sidecar
csi: updates RBAC allow tokenreview creation
2025-02-05 07:39:41 -07:00
Bipul Adhikari 7ccd0cba13 csi: updates RBAC allow tokenreview creation
CSI addons sidecar requires tokenreview api access to verify authorization

Signed-off-by: Bipul Adhikari <badhikar@redhat.com>
2025-02-05 11:51:25 +05:45
parth 6cf97fd32b external: allow cephfs or rgw only deployments
currently there was a restriction to always create rbd pool
with this change only cephfs or rgw volumes created

Signed-off-by: parth-gr <partharora1010@gmail.com>
2025-02-04 14:27:36 +05:30
subhamkrai 3761fda37f csi: update csi-operator to v0.2.0
this commits updates the csi-operator to v0.2.0
and also brings latest yaml updates

Signed-off-by: subhamkrai <srai@redhat.com>
2025-01-31 16:26:25 +05:30
Praveen M 7a934393a9 csi: update RBACs needed for csi-omap-generator sidecar
ceph/ceph-csi/pull/4750 added a new controller that watches for the
VolumeGroupReplicationContent CR and regenerates the OMAP data.
This change needs RBACs for VolumeGroupReplicationContent and
VolumeGroupReplicationClass CR.

This commit updates the same for the `rbd-external-provisioner-runner`
ClusterRole.

Signed-off-by: Praveen M <m.praveen@ibm.com>
2025-01-29 12:01:40 +05:30
Artem Torubarov 25ee6b4f59 operator: custom hostname topology label
Signed-off-by: Artem Torubarov <artem.torubarov@clyso.com>
2025-01-24 15:59:07 +01:00
Niels de Vos 955fa9cae4 csi: update Kubernetes CSI sidecar images to current versions
The Kubernetes CSI sidecars have had several releases that were not
included in deployments by Rook yet, update them to the versions that
are available today:

- csi-node-driver-registrar:v2.13.0
- csi-provisioner:v5.1.0
- csi-attacher:v4.8.0
- csi-resizer:v1.13.1

Signed-off-by: Niels de Vos <ndevos@ibm.com>
2025-01-15 13:11:26 +01:00
parth-gr 61de34a11d external: fix rados namespace sc name
Currently, the sc name is hardcoded,
in future if we support multiple rados
namespace per tenant we need a variable name
updating sc names to contain rados-namespace name
ocs pr: https://github.com/red-hat-storage/ocs-operator/pull/2955

Signed-off-by: parth-gr <partharora1010@gmail.com>
2025-01-08 19:46:56 +05:30
Madhu Rajanna 2fdf7dab5f csi: remove extra RBAC access for create
With new version of external snapshotter
we dont need extra RBAC permission to
create the volumesnapshot and
volumesnapshotcontent

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2025-01-02 16:06:16 +01:00
Madhu Rajanna 610126c560 doc: update groupsnapshot to betav1
updating the groupsnapshot to betav1 api.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2025-01-02 16:06:16 +01:00
Blaine Gardner 52eab6cce4 Merge pull request #15199 from ideepika/wip-rgw-sidecar
object: add opsLogSidecar to gateway subsection from zone
2024-12-20 12:24:34 -07:00
Deepika Upadhyay e821edc24b object: move opsLogSidecar to gateway subsection from zone subsection
Update YAML configuration to correctly place the opsLogSidecar field
under gateway.opsLogSidecar instead of zone.opsLogSidecar, as it is a
configuration option specific to the RGW gateway.

Signed-off-by: Deepika Upadhyay <deepika.upadhyay@clyso.com>
2024-12-19 20:35:06 +05:30
Steven Kreitzer 463d9fb420 csi: csi-snapshotter flag typo; upgrade csi-snapshotter
Signed-off-by: Steven Kreitzer <skre@skre.me>
2024-12-18 09:09:29 -06:00
Travis Nielsen 1a44ab3fa3 Merge pull request #14646 from ideepika/wip-rgw-sidecar
add rgw ops sidecar for op logs
2024-12-17 10:35:08 -07:00
Deepika Upadhyay c5d27467d6 object: add rgw ops sidecar for op logs
the rgw operations for s3 can now be accessible using sidecar
rgw-ops-log availabe in json form that can be further filtered logging
for observability, this will set the rgw_enable_ops_log setting

Signed-off-by: Deepika Upadhyay <deepika.upadhyay@clyso.com>
2024-12-17 22:36:03 +05:30
Travis Nielsen 5baed04b6f Merge pull request #15153 from cobaltcore-dev/rgw-data-pool-bulk
rgw: bulk data pool by default
2024-12-17 07:16:00 -07:00
Artem Torubarov e3c3aafe09 rgw: bulk data pool by default
update CephObjecStore examples to set bulk=true for data pools by default

Signed-off-by: Artem Torubarov <artem.torubarov@clyso.com>
2024-12-17 09:47:59 +01:00
Blaine Gardner aaa16488de object: allow overriding rgw configs and flags
Implement #15119

Allow users to override RGW configurations by specifying Ceph config
options in the CephObjectStore. For configurations that require RGW to
be restarted when the config is applied, allow configs to be specified
as CLI arguments to the RGW as well.

This is an advanced option and is documented as such. Users should be
careful to understand the values they are setting, as there is no
validation to prevent the object store from breaking when these configs
are used.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-12-16 14:57:15 -07:00
Michael Adam c8a1bb21f6 build: update api go module dependencies
Signed-off-by: Michael Adam <obnox@samba.org>
2024-12-16 19:52:15 +01:00
Travis Nielsen fd3d301746 Merge pull request #15131 from travisn/squid-default
manifest: Update default ceph version to v19
2024-12-11 15:19:18 -07:00
Travis Nielsen 07d8012d36 manifest: update default ceph version to v19
With the v19.2.0 release being out for some time now,
update the default version to be deployed with Rook
as v19.2.0.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-12-11 14:45:26 -07:00
Madhu Rajanna 07f5700a87 csi: update cephcsi to latest release
cephcsi 3.13.0 is released today and
update the Rook to use the latest image

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-12-11 14:31:17 -07:00
Artem Torubarov 83c8ec8160 rgw: add rgw_enable_apis config option
Signed-off-by: Artem Torubarov <artem.torubarov@clyso.com>
2024-12-10 11:53:27 +01:00
Blaine Gardner e6db006501 Merge pull request #15035 from BlaineEXE/object-revert-cosi-user-autocreation
Revert "object: create cosi user for each object store"
2024-12-09 16:21:58 -07:00
Blaine Gardner 61ea12f65b Merge pull request #15105 from BlaineEXE/upgrade-guide-1.16
docs: update guides and examples for v1.16 release
2024-12-09 16:20:28 -07:00
Travis Nielsen a8b7dbfa60 Merge pull request #15056 from b1-systems/prs/add-support-for-named-mds-metadata-pools
file: Add support for named MDS metadata pool names
2024-12-09 13:59:54 -07:00
Blaine Gardner 79e767e0e7 docs: remove deprecated toplogyKey beta labels
Remove long-deprecated topologyKey beta label from examples:
failure-domain.beta.kubernetes.io/zone

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-12-09 11:59:20 -07:00
Tobias Wolf 675678fad6 file: add support for named mds metadata pool names
This commit adds optional support to specify the MDS metadata pool name. It defaults to `<fsName>-metadata` as current implementation expects but allows customization if needed e.g. if exisiting naming conventions used `<fsName>_metadata`. Additionally an "preservePoolNames" boolean has been added to indicate that no generated pool names should be used.

Signed-off-by: Tobias Wolf <wolf@b1-systems.de>
2024-12-06 09:16:47 +01:00
Santosh Pillai 85c81946ce osd: enable encryption as day-2 operation
Migrate OSDs to enable encryption as day-2 operation.

Signed-off-by: Santosh Pillai <sapillai@redhat.com>
2024-12-06 09:33:03 +05:30
subham rai ea3947351f Merge pull request #15071 from Madhu-1/add-rbac-csi-addons
csi: provide delete access to csiaddonsnode
2024-11-27 17:05:35 +05:30
Madhu Rajanna b34c0b9164 csi: provide delete access to csiaddonsnode
csiaddons sidecar needs the delete RBAC
to set the ownerRef on the csiaddonsnode
object.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-11-27 11:52:33 +01:00
Niels de Vos f1d448cc46 csi: update csi-addons to v0.11.0
The csi-addons v0.11.0 release is now available.

See-also: https://github.com/csi-addons/kubernetes-csi-addons/releases/tag/v0.11.0
Signed-off-by: Niels de Vos <ndevos@ibm.com>
2024-11-26 10:38:54 +01:00
Madhu Rajanna e599ef67ef csi: update to latest cephcsi release
cephcsi fixed a bug related to data loss
and its fixed in 3.12.3 release, This commit
updates the cephcsi to 3.12.3 release.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-11-25 19:02:25 +01:00
Blaine Gardner fc08e87d44 Revert "object: create cosi user for each object store"
This reverts commit a941b3c33f.

Stop creating the 'cosi' user in the CephObjectStore reconcile. This
step often fails for some amount of time during initial object store
creation, causing frequent user concern. It has also been the source of
some reported failures that would otherwise be non-breaking for certain
users.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-11-21 16:03:32 -07:00
Madhu Rajanna 158891a37c csi: add required finalizers for openshift
openshift cluster need to have access to
finalizers when we set the blockOwnerDeletion
if an ownerReference refers to a resource
we can't set finalizers on, This adds the extra
required permission

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-11-11 08:49:16 +01:00
Santosh Pillai a344ff53f3 core: add pool IDs to cephBlockPool CR status
Adding pool ID of the cephBlockPool in the CR status

Signed-off-by: Santosh Pillai <sapillai@redhat.com>
2024-11-08 21:07:48 +05:30
Travis Nielsen 721f934bb2 Merge pull request #14966 from parth-gr/monitor-blockpool-mirror
rbdmirror: fix mirroring monitoring settings for blockpool
2024-11-08 08:14:47 -07:00
parth-gr ed5013e9c6 rbdmirror: add disable check for status check
enable and disable the status of rados namespace
mirroring by looking at statusCheck spec of blockpool

Signed-off-by: parth-gr <partharora1010@gmail.com>
2024-11-06 22:42:46 +05:30
Madhu Rajanna 501e0ea0a4 csi: add new RBAC required for csiaddons
csiaddons required new RBAC in the next
release to create/update the csiaddonsnode
object based on the owner deployment/daemonset
names of the pods its running with.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-11-06 08:24:01 +01:00
Travis Nielsen 1ed625152a Merge pull request #14951 from cobaltcore-dev/keep-default-placement
rgw: keep default-placement in zone config
2024-11-05 09:17:17 -07:00