Ceph-CSI support for fscrypt encryption of cephfs.
To achieve this commit add capability of mounting the
required `rook-ceph-csi-kms-config` configmap into
csi-cephfsplugin-provisioner and nodeplugin pods.
Further it modifies the ClusterRoles `cephfs-csi-nodeplugin` and
`cephfs-external-provisioner-runner` to grant privileges
required for reading encryption configuration and fetching
encryption secrets from either kubernetes secrets or
from a Key Management System (KMS).
These privileges are essential for the proper functioning of
ceph-csi-cephfs with fscrypt encryption.
The following privileges have been added:
- `secrets/get`: Allows reading of secrets for encryption.
- `configmaps/get`: Grants access to configuration maps,
this is used to read encryption configuration.
- `serviceaccounts/get`: Enables retrieval of service accounts for
authentication to KMS and for retrieving encryption secrets
stored there.
- `serviceaccounts/token/create`: Allows creation of service account tokens,
which are required for authenticating requests to KMS
when retrieving encryption secrets.
The commit also updated the csi documentation to include cephfs
in the encryption section, with examples updated accordingly.
Signed-off-by: NymanRobin <robin.nyman@est.tech>
When CPU requests and limits are assigned to a pod,
the pod will be guaranteed the requests, up to the limits.
Even if there are spare CPU cycles, the pod cannot use
them. Thus, pods can be unnecessarily denied compute
when they need to burst if the limits are set.
Therefore, it is not recommended to set CPU limits
since the CPU requests are already guaranteeing that
no pod will be starved at least for its requests.
Signed-off-by: travisn <tnielsen@redhat.com>
For now we are using the operator namespace name
as the prefix for the csi driver, This PR provides
an option for the users if someone wants to have
their own prefix for the csi driver, if someone tries
to change the prefix for existing csi driver rook
operator will fail to reconcile the csi driver.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
when a PVC is cloned external-provisioner
still required update access or else a warning
will be logged in the pvc describe output
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
Added hack in generate-rook-csv for proper
generation of csi nfs rbac in csv.
Added placeholder clusterrole and binding for
nfs nodeplugin sa, since operator-sdk
does not include sa without rules.
Signed-off-by: Rakshith R <rar@redhat.com>
Ceph-CSI supports LUKS encryption for RBD volumes.
This commit adds support for the same by adding capability
of mounting required `rook-ceph-csi-kms-config` configmap
into csi-rbdplugin-provisioner and nodeplugin pods.
Required documentations, helm charts and examples yamls
are also updated.
Resolved: #7032
Signed-off-by: Rakshith R <rar@redhat.com>
Because the NFS CSI driver is optional and rarely deployed, make RBAC
for this driver an optional example that is generated by the helm chart.
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
When creating EC fs, create replicated pool as primary
pool and ec pool as secondary pool, creating ec pool
as primary is not encouraged and it will lead to failure.
Also, changing the pool name in storageclass-ec file.
Closes: https://github.com/rook/rook/issues/8210
Signed-off-by: subhamkrai <srai@redhat.com>