currently there was a restriction to always create rbd pool
with this change only cephfs or rgw volumes created
Signed-off-by: parth-gr <partharora1010@gmail.com>
When generating the HTTP client used for RGW admin ops, use both system
certs as well as the user-given cert.
As a real world example, admins may use ACME to rotate Letsencrypt certs
every 2 months. For an external CephObjectStore, the cert used by Rook
and RGW may not be rotated at the same time. This can cause the Rook
operator to fail CephObjectStore reconciliation until both certs agree.
When Rook also relies on system certs in the container, Rook's
reconciliation will not have reconciliation failures because
Letsencrypt's well-known and trusted root certificates can be loaded
from the system to validate the RGW's newly-rotated cert.
Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
for cephfs fencing in external mode, we run command `ceph tell mds ***`
which requires user user to include cap mds allow * in permission. So,
we need to add this in healthchercker and cephfs provisioner user
Signed-off-by: subhamkrai <srai@redhat.com>
currently we created a new config file or user creation,
Which was have the user config.
We were also appending the script deafult values to the config file
With that all the boolean values were appended to the config.ini file
v2-port-enable = False
....
But the config.ini treat all the bolean values as true, irrespective of they
are set to, it is because the boolean cli flag doesnt accept the argument
So now removed all the false values from the config.ini
Signed-off-by: parth-gr <partharora1010@gmail.com>
currently the output in the cm was not human readable
and can not easily used to create a config.ini file
Also for now removed the support of printing arg in upstream
Signed-off-by: parth-gr <partharora1010@gmail.com>
Priority: command-line-args > config.ini file values > default values
Currently default was having more priority so fixed it
Signed-off-by: parth-gr <partharora1010@gmail.com>
Recently we have introuced external-cluster-user-command cm
Which help user to look at the previous command run,
So with this PR we will add another data field arg
on this confimap which will have the final processed flags
that are being used
So user can use them directly either in config.ini or cmd line args
Signed-off-by: parth-gr <partharora1010@gmail.com>
Now user can pass the cli flags using config file and
also command line argument,
if mentioned at both the place priority is given to
command line argument
Signed-off-by: parth-gr <partharora1010@gmail.com>
user can look back to there configurations by
looking at the configmap created with command
line arguments
This will be useful for them during upgrades when they
need to re run the python script with the same flags
Signed-off-by: parth-gr <partharora1010@gmail.com>
Afte pylint was updated to version 3.2.0
a set of new errors appeared. This makes
ci passing by either fixing the problem
or ignoring it in the check
Signed-off-by: NymanRobin <robin.nyman@est.tech>
csi pr get merged ceph/ceph-csi#4459
so, This reverts commit 812a9c02b0.
The csi PR removes the dependency of the pool parameter from the
rbd storage class if the topology pools are passed,
so removing them in the examples and making it optional
Signed-off-by: parth-gr <partharora1010@gmail.com>
with topologyconstrain pool we can enable any
replica pool usage and also can store data at any
topology
Signed-off-by: parth-gr <partharora1010@gmail.com>
currently the script requires to have both v2 and v1 port
to enable v2 port, but that is not the necessary condition,
so removing the chek, and enabling it only v2 is present to
successfully configure with v2 only
part-of: https://github.com/rook/rook/issues/13827
Signed-off-by: parth-gr <partharora1010@gmail.com>
we have changed the --cluster-name flag to --k8s-cluster-name
but to support automation while upgrade we should support
the legacy flag
Signed-off-by: parth-gr <partharora1010@gmail.com>
change the json output of storageclass to also inclusde rados namespace,
and also added the changes in the csi secret
Signed-off-by: parth-gr <paarora@redhat.com>
if the monitoring endpoint is not present
we were not returning any error, but the
field is the mandatory output, so return error if not found
Signed-off-by: parth-gr <paarora@redhat.com>
Sometimes the pool is not enabled and the ceph cluster
shows health warning, so automatically initalize the pool
from the script
Signed-off-by: parth-gr <paarora@redhat.com>
if the client.health checker already exited it was
returning extra information, It was making the structure and
return JSON non idempotent output, So fixed
that problem by returning a single value
Signed-off-by: parth-gr <paarora@redhat.com>
when creating networkFence CR, it requires IP's to block
which we get from running `rbd status ...` command. But,
the client.healthchecker user didn't had the right caps
to run hence it was giving error. Now, adding the required
caps `profile rbd-read-only` to osd so that rbd command can
be executed.
Signed-off-by: subhamkrai <srai@redhat.com>
We need to create the namespace with the import script,
As per the documentation
The import script creates the secrets and
cm which is later used by the operator for cluster creation.
Signed-off-by: parth-gr <paarora@redhat.com>
When the ceph.conf is not in a well-known location, it is typical
for a custom ceph.keyring to be required as well. Currently, the
create-external-cluster-resources.py only tries to load the keyring
from well-known paths, and fails.
This commit adds a new optional argument `--keyring` to help in this
situation. When specified, create-external-cluster-resources.py will
attempt to use this as the keyring to authenticate with Ceph.
Signed-off-by: Angelos Kolaitis <neoaggelos@gmail.com>
set the csi subvolume to pin type distributed and pin setting 1
So to statically balance the PVs across all MDS ranks
Signed-off-by: parth-gr <paarora@redhat.com>
1) donot change rgw fqdn to ip if provided,
As now the bucket class supports the
entry of fqdn
2) update crds with new description in EndpointAddress
Signed-off-by: parth-gr <paarora@redhat.com>
if there is no multisite config pass, it will still checks for
the zones and zones group and not able to query anything
Signed-off-by: parth-gr <paarora@redhat.com>
the check validate_rgw_multisite was always checking for realm
updated it to check the specific config
fixed validate_rgw_endpoint pool validation
added missing realm zonegroup and zone while interacting with user resources
Co-authored-by: Sergio Pérez Fernández <sergioperez794@gmail.com>
Signed-off-by: parth-gr <paarora@redhat.com>