Commit Graph
80 Commits
Author SHA1 Message Date
Niraj Yadav ece302f35b manifest: add list and watch capabilities to provisioners
This patch adds `list` and `watch` verbs to cephfs and rbd
provisioner roles for CSIAddonNode objects.

Signed-off-by: Niraj Yadav <niryadav@redhat.com>
2025-02-17 15:32:21 +05:30
Bipul Adhikari d25b26e890 csi: moves rbac for Tokenreview API from role to cluster role
CSI addons sidecar requires clusterrole permission for Tokenreview
Tokenreview is a cluster scoped API

Signed-off-by: Bipul Adhikari <badhikar@redhat.com>
2025-02-13 14:44:48 +05:45
Travis Nielsen 8ca9186038 Merge pull request #15326 from bipuladh/support-sidecar
csi: updates RBAC allow tokenreview creation
2025-02-05 07:39:41 -07:00
Bipul Adhikari 7ccd0cba13 csi: updates RBAC allow tokenreview creation
CSI addons sidecar requires tokenreview api access to verify authorization

Signed-off-by: Bipul Adhikari <badhikar@redhat.com>
2025-02-05 11:51:25 +05:45
Praveen M 7a934393a9 csi: update RBACs needed for csi-omap-generator sidecar
ceph/ceph-csi/pull/4750 added a new controller that watches for the
VolumeGroupReplicationContent CR and regenerates the OMAP data.
This change needs RBACs for VolumeGroupReplicationContent and
VolumeGroupReplicationClass CR.

This commit updates the same for the `rbd-external-provisioner-runner`
ClusterRole.

Signed-off-by: Praveen M <m.praveen@ibm.com>
2025-01-29 12:01:40 +05:30
Madhu Rajanna 2fdf7dab5f csi: remove extra RBAC access for create
With new version of external snapshotter
we dont need extra RBAC permission to
create the volumesnapshot and
volumesnapshotcontent

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2025-01-02 16:06:16 +01:00
Madhu Rajanna b34c0b9164 csi: provide delete access to csiaddonsnode
csiaddons sidecar needs the delete RBAC
to set the ownerRef on the csiaddonsnode
object.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-11-27 11:52:33 +01:00
Madhu Rajanna 158891a37c csi: add required finalizers for openshift
openshift cluster need to have access to
finalizers when we set the blockOwnerDeletion
if an ownerReference refers to a resource
we can't set finalizers on, This adds the extra
required permission

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-11-11 08:49:16 +01:00
Madhu Rajanna 501e0ea0a4 csi: add new RBAC required for csiaddons
csiaddons required new RBAC in the next
release to create/update the csiaddonsnode
object based on the owner deployment/daemonset
names of the pods its running with.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-11-06 08:24:01 +01:00
Praveen M 1efe3b6ee9 csi: add csinodes rbac rule for cephfs provisioner
Signed-off-by: Praveen M <m.praveen@ibm.com>
2024-08-20 22:08:21 +05:30
subhamkrai 1ad20d07e7 csi: add csi-operator operator config cr
Signed-off-by: subhamkrai <srai@redhat.com>
2024-08-08 11:21:49 +05:30
subhamkrai 667e044013 csi: add new CSI-operator config CR
adding changes to create CSI-operator config CR based on
every radosnamesapce and subvolumegroup.

Signed-off-by: subhamkrai <srai@redhat.com>
2024-08-08 11:21:49 +05:30
subhamkrai 4b0b3a55d9 csi: add code for new CSI operator CR cephcluster
adding code changes,rbac changes required for create the new
Ceph-CSI operator CR named cephCluster in api group 'csi.ceph.io'.

Signed-off-by: subhamkrai <srai@redhat.com>
2024-08-08 11:21:45 +05:30
NymanRobin 05315ae64f csi: add cephfs encryption support
Ceph-CSI support for fscrypt encryption of cephfs.
To achieve this commit add capability of mounting the
required `rook-ceph-csi-kms-config` configmap into
csi-cephfsplugin-provisioner and nodeplugin pods.

Further it modifies the ClusterRoles `cephfs-csi-nodeplugin` and
`cephfs-external-provisioner-runner` to grant privileges
required for reading encryption configuration and fetching
encryption secrets from either kubernetes secrets or
from a Key Management System (KMS).

These privileges are essential for the proper functioning of
ceph-csi-cephfs with fscrypt encryption.

The following privileges have been added:
- `secrets/get`: Allows reading of secrets for encryption.
- `configmaps/get`: Grants access to configuration maps,
    this is used to read encryption configuration.
- `serviceaccounts/get`: Enables retrieval of service accounts for
    authentication to KMS and for retrieving encryption secrets
    stored there.
- `serviceaccounts/token/create`: Allows creation of service account tokens,
    which are required for authenticating requests to KMS
    when retrieving encryption secrets.

The commit also updated the csi documentation to include cephfs
in the encryption section, with examples updated accordingly.

Signed-off-by: NymanRobin <robin.nyman@est.tech>
2024-05-20 14:03:02 +03:00
subhamkrai dd8c3c9974 build: remove csv related files
remove csv related files/content which are not used/required for
upstream uses.

Signed-off-by: subhamkrai <srai@redhat.com>
2024-03-11 21:01:53 +05:30
Madhu Rajanna 77bfcd46e7 csi: add rbac required for vgs
Added required rbac's for required rbac
for volumegroupsnapshot feature.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-03-01 09:15:17 +01:00
parth-gr f7a9d8ff7b core: added rook-ceph-default service account
When a private docker registry is used and an
image pull secret is specified in the chart,
the pods with default Service Account fail to pull
the image due to authentication issues.
Added rook-ceph-default service account and modify the pods
specifications by adding the serviceAccountName

closes: https://github.com/rook/rook/issues/12786

Closes: https://github.com/rook/rook/issues/6673
Co-authored-by: Tareq Sharafy <tareq.sha@gmail.com>
Signed-off-by: parth-gr <partharora1010@gmail.com>
(cherry picked from commit 737fb099fe)
Signed-off-by: parth-gr <partharora1010@gmail.com>
2024-02-28 13:32:55 +05:30
subhamkrai 5bff860380 core: remove namespace/ownerRef from networkFence
since networkFence is a cluster-based resource so that we don't need
the namespace and ownerReferences as it cause garbage-collector errors.
Also, now we create the networkFence with clusteUID label so when doing
cleanup we match the cephCluster uid and networkFence label clusterUID.

Signed-off-by: subhamkrai <srai@redhat.com>
2024-02-13 21:47:04 +05:30
Praveen M a80396df1b csi: update cmdline args as used by ceph-csi
This commit adds cmdline args to enable
1. RecoverVolumeExpansionFailure
2. PreventVolumeModeConversion
3. HonorPVReclaimPolicy

Signed-off-by: Praveen M <m.praveen@ibm.com>
2024-01-12 15:24:07 +05:30
Travis Nielsen 6fba73621b Merge pull request #13338 from sp98/update-clusterroole
core: ability to create, update and delete services in other namespaces
2023-12-06 11:19:41 -07:00
Rakshith R a3220d827d csi: update default cephcsi version to 3.10.0
This commit updates default cephcsi driver version
to v3.10.0 and filesystem reconciler now creates
csi subvolumegroup by default.

Signed-off-by: Rakshith R <rar@redhat.com>
2023-12-06 19:57:40 +05:30
sp98 1dea93794a core: create/update/delete services in other namespaces
This PR adds permissions to create or update k8s service by the
in the naemspaces other than rook operator namespace

Signed-off-by: sp98 <sapillai@redhat.com>
2023-12-06 14:37:41 +05:30
subhamkrai 28cc1ebc55 core: remove webhook & controller-runtime from apis
This commits removes controller-runtime dependencies
from the apis dir and to achieve that we are removing
webhook.

Signed-off-by: subhamkrai <srai@redhat.com>
2023-12-01 14:15:40 +05:30
Jiffin Tony Thottan b48dc8a335 object: intial cosi driver controller design
Adding CephCOSIDriver CRD and controller. The controller will bring up
the ceph cosi driver when first object store is created in the rook
operator namespace. Then admin can defined COSI CRDs like BucketClass
and BucketAccessClass for different object stores deployed via Rook.
Using the BucketClass and BucketAccessClass, user can define
BucketAccess for backend bucket in the RGW. The CephCOSIDriver CRD
defines configuration options for ceph cosi driver. In the first version
its usability is minimal. Even if it is not defined Rook will bring up
the ceph cosi driver with default values.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2023-07-18 22:49:41 +05:30
subhamkrai 39b5c057ce core: faster recovery from rbd rwo node loss
in the existing node watcher, we'll check for node update
event and see if there are `out-of-service` taints are applied
and `ROOK_WATCH_FOR_NODE_FAILURE` is enabled in rook-ceph-operator-configmap,
if then we'll create the networkFence cr and delete the cr if nodes come back.
And, added the unit test too.

Signed-off-by: subhamkrai <srai@redhat.com>
2023-07-07 21:16:25 +05:30
Sud 2547372527 multus: add deletecollection capability for validation tool
Without deletecollection capability the image pullers won't be deleted, causing multus validation to fail.
    Added deletecollection verbs to the daemonsets resource in role rook-ceph-system
    This is fix for Issue: https://github.com/rook/rook/issues/12435

    Signed-off-by: Sudharsan Omprakash <sudharsan.omprakash@yahoo.com>
2023-06-28 17:45:18 -04:00
Redouane Kachach 08754f6197 mgr: removing unnecessary rook-ceph-mgr rbac entries
These rbac changes were introduced as part of #11845 PR to enable
sidecar accessing mgr pods but in fact they are not necessary
as rook-ceph-mgr role had already the ability to update pods

Closes: https://github.com/rook/rook/issues/12336

Signed-off-by: Redouane Kachach <rkachach@redhat.com>
2023-06-06 22:12:23 +02:00
Travis Nielsen 4a23260955 Merge pull request #11845 from rkachach/fix_issue_11844
mgr: use mgr_role dynamic label to tag the active ceph manager
2023-03-28 13:08:18 -06:00
Redouane Kachach f00bd790a8 mgr: using dynamic mgr_role label to implement mgr HA
Closes: https://github.com/rook/rook/issues/11844

Signed-off-by: Redouane Kachach <rkachach@redhat.com>
2023-03-27 18:38:55 +02:00
Vincent Kling bd857cc5c5 manifest: add missing quote
Signed-off-by: Vincent Kling <v.kling@vinniict.nl>
2023-03-11 11:44:58 +01:00
Rakshith R f39a32fcdb osd: add capability to reconcile key rotation cron jobs
This commits adds code to reconcile key rotation cron jobs.

Signed-off-by: Rakshith R <rar@redhat.com>
2023-03-08 12:07:26 +05:30
Rakshith R 71e011f731 osd: add rotate-key functionality to rook's key-management cmd
This commit adds functionality to be able to rotate
key encryption key of encrypted PVC backed OSDs.
Necessary changes such as adding update functionality
to kms and rbac changes are made as well.

Signed-off-by: Rakshith R <rar@redhat.com>
2023-03-08 12:07:26 +05:30
sp98 7292ac5927 core: export mon and OSD services
Signed-off-by: sp98 <sapillai@redhat.com>
2023-02-27 21:36:59 +05:30
Travis Nielsen b632ba10ff Merge pull request #11697 from Madhu-1/fix-11694
csi: add missing node access to cephfs driver
2023-02-17 12:18:38 -07:00
subhamkrai 4699e8885a build: add rbac which are required
adding necessary rbac and also updating
csv-gen script.

Closes: https://github.com/rook/rook/issues/10141
Signed-off-by: subhamkrai <srai@redhat.com>
2023-02-17 23:00:03 +05:30
Madhu Rajanna 1cfa7eefae csi: add missing node access to cephfs driver
Node access is only needed when we are using
volumeBindingMode: WaitForFirstConsumer in
the storageclass its not required for Immediate
BindingMode.

fixes: #11694

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2023-02-17 07:50:53 +01:00
Ben Gao 84296a997a mgr: role rook-ceph-mgr is lack of patch verb to compete ceph request
ceph orch command uses patch method to update cephcluster. Adding patch to verbs list of rook-ceph-mgr(Role) to make it work. It was allright with deploy/charts/rook-ceph-cluster/charts/library/templates/_cluster-role.tpl to justify the changes quite a bit.

Signed-off-by: Ben Gao <bengao168@msn.com>
2023-01-18 16:39:54 +08:00
Madhu Rajanna 61c533ba41 csi: add missing update rbac
when a PVC is cloned external-provisioner
still required update access or else a warning
will be logged in the pvc describe output

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2022-12-21 11:11:48 +01:00
Rakshith R 3c5a2f4142 csi: add topology provisioning support
This commit adds topology provisioning
support. This makes modification to rbac,
csi deployment and daemonset.

Signed-off-by: Rakshith R <rar@redhat.com>
2022-09-12 16:10:18 +05:30
yati1998 9b4361b379 rbdmirror: remove volume replication sidecar
The volume replication operator is being moved to
kubernetes-csi-addons. This commit hence, removes
the volume replication sidecar and updates the
related documentation.
It will also update the csi-addons sidecar version
to the latest one.

Closes: #10655

Signed-off-by: yati1998 <ypadia@redhat.com>
2022-09-07 14:49:19 +05:30
Blaine Gardner 6c8f2e414f build: remove psp from common.yaml generation
Due to an oversight, PSP resources were left in generation of
common.yaml from #10797. Resolve that by setting
pspEnable=false when generating common.yaml.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2022-08-29 10:41:41 -06:00
Mudit Agarwal 40081cbcd2 Revert "csi: remove attacher sidecar from CephFS rook deployment"
This reverts commit 4bfd88dc4d.

Signed-off-by: Mudit Agarwal <muagarwa@redhat.com>
2022-08-10 13:04:14 +05:30
yati1998 4bfd88dc4d csi: remove attacher sidecar from CephFS rook deployment
CephFS CSI driver dont have/advertise controller publish/unpublish
capabilities, thus dont need attacher sidecar for its operations.
The presence of external-attacher adds on overhead and issues wrt
attachment in various scenarios. One of them would be the lack of
performance on syncing volumeattachment from api server..etc.
More or less we don't have controller publish and unpublish capabilities,
so we should not make use of this sidecar and cause
unnecessary addon here thus other issues.

similar changes have been added to CSI
https://github.com/ceph/ceph-csi/pull/3149

Signed-off-by: yati1998 <ypadia@redhat.com>
2022-08-03 19:56:39 +05:30
parth-gr 50daeb29e5 core: remove all wildcard permissions in rbac definations
Reduce the RBAC scope to the minimum necessary
permissions for rook to operator

Signed-off-by: parth-gr <paarora@redhat.com>
2022-07-08 20:50:59 +05:30
Rakshith R 623c5159d5 csi: add token create rbac for rbd csi clusterrole
This rbac is required to fetch serviceaccount
token for vault tenant sa encryption type on k8s 1.24+.
refer: https://github.com/ceph/ceph-csi/pull/3174

Signed-off-by: Rakshith R <rar@redhat.com>
2022-06-14 10:18:20 +05:30
Madhu Rajanna 02b9f199d7 csi: add volumeattachment list rbac
rbd nodeplugin need volumeattachment RBAC
to remount the volume incase of the nbd driver
is used to mount the volume.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2022-05-31 15:09:34 +05:30
Travis Nielsen 1fe71fc76f Merge pull request #10271 from humblec/rbac-cleanup-2
Adjust PV object RBAC  for CSI PODs
2022-05-17 07:26:00 -06:00
Travis Nielsen 362e3a6578 Merge pull request #10247 from Madhu-1/remove-cephfs-node-rbac
csi: Remove extra cephfs node rbac
2022-05-16 08:40:16 -06:00
Humble Chirammal 34e88776e7 csi: remove unwanted verbs for pv object
pv object patch verb is enough for the csi sidecar to function.

Signed-off-by: Humble Chirammal <hchiramm@redhat.com>
2022-05-16 14:35:34 +05:30
Humble Chirammal 0812d08a75 csi: remove watch verb from csi-snapshottter sidecar RBAC
The `watch` verb is not required for the csi-snapshotter sidecar
to function, removing it from the deployment

Signed-off-by: Humble Chirammal <hchiramm@redhat.com>
2022-05-16 13:21:42 +05:30