This patch adds `list` and `watch` verbs to cephfs and rbd
provisioner roles for CSIAddonNode objects.
Signed-off-by: Niraj Yadav <niryadav@redhat.com>
CSI addons sidecar requires clusterrole permission for Tokenreview
Tokenreview is a cluster scoped API
Signed-off-by: Bipul Adhikari <badhikar@redhat.com>
ceph/ceph-csi/pull/4750 added a new controller that watches for the
VolumeGroupReplicationContent CR and regenerates the OMAP data.
This change needs RBACs for VolumeGroupReplicationContent and
VolumeGroupReplicationClass CR.
This commit updates the same for the `rbd-external-provisioner-runner`
ClusterRole.
Signed-off-by: Praveen M <m.praveen@ibm.com>
With new version of external snapshotter
we dont need extra RBAC permission to
create the volumesnapshot and
volumesnapshotcontent
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
openshift cluster need to have access to
finalizers when we set the blockOwnerDeletion
if an ownerReference refers to a resource
we can't set finalizers on, This adds the extra
required permission
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
csiaddons required new RBAC in the next
release to create/update the csiaddonsnode
object based on the owner deployment/daemonset
names of the pods its running with.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
adding code changes,rbac changes required for create the new
Ceph-CSI operator CR named cephCluster in api group 'csi.ceph.io'.
Signed-off-by: subhamkrai <srai@redhat.com>
Ceph-CSI support for fscrypt encryption of cephfs.
To achieve this commit add capability of mounting the
required `rook-ceph-csi-kms-config` configmap into
csi-cephfsplugin-provisioner and nodeplugin pods.
Further it modifies the ClusterRoles `cephfs-csi-nodeplugin` and
`cephfs-external-provisioner-runner` to grant privileges
required for reading encryption configuration and fetching
encryption secrets from either kubernetes secrets or
from a Key Management System (KMS).
These privileges are essential for the proper functioning of
ceph-csi-cephfs with fscrypt encryption.
The following privileges have been added:
- `secrets/get`: Allows reading of secrets for encryption.
- `configmaps/get`: Grants access to configuration maps,
this is used to read encryption configuration.
- `serviceaccounts/get`: Enables retrieval of service accounts for
authentication to KMS and for retrieving encryption secrets
stored there.
- `serviceaccounts/token/create`: Allows creation of service account tokens,
which are required for authenticating requests to KMS
when retrieving encryption secrets.
The commit also updated the csi documentation to include cephfs
in the encryption section, with examples updated accordingly.
Signed-off-by: NymanRobin <robin.nyman@est.tech>
since networkFence is a cluster-based resource so that we don't need
the namespace and ownerReferences as it cause garbage-collector errors.
Also, now we create the networkFence with clusteUID label so when doing
cleanup we match the cephCluster uid and networkFence label clusterUID.
Signed-off-by: subhamkrai <srai@redhat.com>
This commit updates default cephcsi driver version
to v3.10.0 and filesystem reconciler now creates
csi subvolumegroup by default.
Signed-off-by: Rakshith R <rar@redhat.com>
This PR adds permissions to create or update k8s service by the
in the naemspaces other than rook operator namespace
Signed-off-by: sp98 <sapillai@redhat.com>
This commits removes controller-runtime dependencies
from the apis dir and to achieve that we are removing
webhook.
Signed-off-by: subhamkrai <srai@redhat.com>
Adding CephCOSIDriver CRD and controller. The controller will bring up
the ceph cosi driver when first object store is created in the rook
operator namespace. Then admin can defined COSI CRDs like BucketClass
and BucketAccessClass for different object stores deployed via Rook.
Using the BucketClass and BucketAccessClass, user can define
BucketAccess for backend bucket in the RGW. The CephCOSIDriver CRD
defines configuration options for ceph cosi driver. In the first version
its usability is minimal. Even if it is not defined Rook will bring up
the ceph cosi driver with default values.
Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
in the existing node watcher, we'll check for node update
event and see if there are `out-of-service` taints are applied
and `ROOK_WATCH_FOR_NODE_FAILURE` is enabled in rook-ceph-operator-configmap,
if then we'll create the networkFence cr and delete the cr if nodes come back.
And, added the unit test too.
Signed-off-by: subhamkrai <srai@redhat.com>
Without deletecollection capability the image pullers won't be deleted, causing multus validation to fail.
Added deletecollection verbs to the daemonsets resource in role rook-ceph-system
This is fix for Issue: https://github.com/rook/rook/issues/12435
Signed-off-by: Sudharsan Omprakash <sudharsan.omprakash@yahoo.com>
These rbac changes were introduced as part of #11845 PR to enable
sidecar accessing mgr pods but in fact they are not necessary
as rook-ceph-mgr role had already the ability to update pods
Closes: https://github.com/rook/rook/issues/12336
Signed-off-by: Redouane Kachach <rkachach@redhat.com>
This commit adds functionality to be able to rotate
key encryption key of encrypted PVC backed OSDs.
Necessary changes such as adding update functionality
to kms and rbac changes are made as well.
Signed-off-by: Rakshith R <rar@redhat.com>
Node access is only needed when we are using
volumeBindingMode: WaitForFirstConsumer in
the storageclass its not required for Immediate
BindingMode.
fixes: #11694
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
ceph orch command uses patch method to update cephcluster. Adding patch to verbs list of rook-ceph-mgr(Role) to make it work. It was allright with deploy/charts/rook-ceph-cluster/charts/library/templates/_cluster-role.tpl to justify the changes quite a bit.
Signed-off-by: Ben Gao <bengao168@msn.com>
when a PVC is cloned external-provisioner
still required update access or else a warning
will be logged in the pvc describe output
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
This commit adds topology provisioning
support. This makes modification to rbac,
csi deployment and daemonset.
Signed-off-by: Rakshith R <rar@redhat.com>
The volume replication operator is being moved to
kubernetes-csi-addons. This commit hence, removes
the volume replication sidecar and updates the
related documentation.
It will also update the csi-addons sidecar version
to the latest one.
Closes: #10655
Signed-off-by: yati1998 <ypadia@redhat.com>
Due to an oversight, PSP resources were left in generation of
common.yaml from #10797. Resolve that by setting
pspEnable=false when generating common.yaml.
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
CephFS CSI driver dont have/advertise controller publish/unpublish
capabilities, thus dont need attacher sidecar for its operations.
The presence of external-attacher adds on overhead and issues wrt
attachment in various scenarios. One of them would be the lack of
performance on syncing volumeattachment from api server..etc.
More or less we don't have controller publish and unpublish capabilities,
so we should not make use of this sidecar and cause
unnecessary addon here thus other issues.
similar changes have been added to CSI
https://github.com/ceph/ceph-csi/pull/3149
Signed-off-by: yati1998 <ypadia@redhat.com>
rbd nodeplugin need volumeattachment RBAC
to remount the volume incase of the nbd driver
is used to mount the volume.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
The `watch` verb is not required for the csi-snapshotter sidecar
to function, removing it from the deployment
Signed-off-by: Humble Chirammal <hchiramm@redhat.com>