Implement an allow list mechanism that disables potentially unsafe OBC
fields by default. OBC fields beyond `maxObjects` and `maxSize` don't
neatly fit into the OBC framework as it was originally envisioned and
implemented.
Some of the newly added configs could allow users to cause confusion for
themselves. Others might allow users to hijack others buckets. Some
might allow bricking the entire S3 store.
Out of an abundance of safety, allow-list the known-safe options by
default, and require administrators to enable potentially troublesome
options via the new operator-level config
`ROOK_OBC_ALLOW_ADDITIONAL_CONFIG_FIELDS`.
Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
The Kubernetes CSI sidecars have had several releases that were not
included in deployments by Rook yet, update them to the versions that
are available today:
- csi-node-driver-registrar:v2.13.0
- csi-provisioner:v5.1.0
- csi-attacher:v4.8.0
- csi-resizer:v1.13.1
Signed-off-by: Niels de Vos <ndevos@ibm.com>
cephcsi fixed a bug related to data loss
and its fixed in 3.12.3 release, This commit
updates the cephcsi to 3.12.3 release.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
The version checks for the csi driver are removed now
since they are all obsolete. The K8s version and cephcsi
versions are no longer checked. Anyway, the move to the
csi operator would take ownership of version checks
needed in the future, so for now we simplify rook
deployment of the csi driver.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
Finish the process of deprecating holder pods by removing Rook's ability
to deploy them. The intent of this change is to make the most
superficial changes possible to accomplish this. There are still
remnants of code in Rook (particularly the CSI controller) that helped
configure or deploy holder pods. Due to the risk of breaking some
features, cleanup work of hose remnants will be deferred for future
work.
Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
The ROOK_ENFORCE_HOST_NETWORK option was implemented recently
and now we add the helm setting to expose this new setting
in the rook chart.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
This adds an operator config setting ROOK_REVISION_HISTORY_LIMIT
defaulting to kubernetes'value for RevisionHistoryLimit.
If configured, the provided value will be used as RevisionHistoryLimit
for all Deployments rook creates.
Fixes: #12722
Signed-off-by: Michael Adam <obnox@samba.org>
This commit adds the flexibility to configure kube apiserver qps
as per the user requirement and also keeps the existing values as
the default one.
Signed-off-by: yite.gu <yitegu0@gmail.com>
With the recent enhancements csi containers for using
logrotate, they need to run with securityContext to privileged,
on platform like openshift.
Used the ROOK_HOSTPATH_REQUIRES_PRIVILEGED flag
wich is set with operator deployment to see
if the securityCOntext is needed or not
Closes: https://github.com/rook/rook/issues/14400
Signed-off-by: parth-gr <partharora1010@gmail.com>
The default service account access is needed for the operator
and the toolbox to run on openshift. This is a follow-up from
PR 13362 that created a new default service account to use with
all ceph or rook components that were relying on the default
service account.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
Add new CSI_DISABLE_HOLDER_PODS option for rook-ceph-operator.
This option will disable holder pods when set to "true".
In the long term, Rook plans to deprecate the holder pods entirely.
This new option will allow users to choose to migrate their clusters to
non-holder clusters when they are ready and able, giving them time to
gracefully migrate before the holders are permanently removed.
This option is set to "false" by default so that upgrading users don't
have their CSI pods modified unexpectedly.
Example manifests are modified to set this value to true so that new
clusters will not deploy holder pods.
Migrating users are provided with documentation to instruct them about
the new requirements they need to satisfy to successfully remove holder
pods, a procedure for migrating pods from holder to non-holder mounts,
and a way to delete holder pods once they are no longer in use.
When users set CSI_DISABLE_HOLDER_PODS="true", the CSI controller will
no longer deploy or update the holder pod Daemonsets, but it does not
delete any existing Daemonsets. This allows already-attached PVCs to
continue operating normally with their network connection continuing to
exist in the current holder pod. This is critical to avoid causing
ia cluster-wide storage outage.
More info: https://github.com/rook/rook/issues/13055
Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
add an option to set prefix for the name of obc provisioner instead of
ceph cluster namespace.
Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
volumegroupsnapshot feature will be enabled
by default if the required CRD's are present
if not its disabled and user will have an option
to disable it if they dont require this feature.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
When CPU requests and limits are assigned to a pod,
the pod will be guaranteed the requests, up to the limits.
Even if there are spare CPU cycles, the pod cannot use
them. Thus, pods can be unnecessarily denied compute
when they need to burst if the limits are set.
Therefore, it is not recommended to set CPU limits
since the CPU requests are already guaranteeing that
no pod will be starved at least for its requests.
Signed-off-by: travisn <tnielsen@redhat.com>
This commit removes the `CSI_ENABLE_READ_AFFINITY` since
it is no longer utilized after addition of the read affinity
option per cluster via CSIDriverSpec.
Signed-off-by: Praveen M <m.praveen@ibm.com>
For now we are using the operator namespace name
as the prefix for the csi driver, This PR provides
an option for the users if someone wants to have
their own prefix for the csi driver, if someone tries
to change the prefix for existing csi driver rook
operator will fail to reconcile the csi driver.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
The operator needs to burst significantly when reconciling,
then will quiet down and nearly not consume any cpu.
Therefore, we allow the operator to burst to more than
a full cpu instead of limiting it to a half cpu.
Signed-off-by: travisn <tnielsen@redhat.com>
This commit adds the flexibility to configure
leader election flags as per the user
requirement and also keeps the existing values
as the default one.
resolve: #13475
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
This commit updates default cephcsi driver version
to v3.10.0 and filesystem reconciler now creates
csi subvolumegroup by default.
Signed-off-by: Rakshith R <rar@redhat.com>
This commits removes controller-runtime dependencies
from the apis dir and to achieve that we are removing
webhook.
Signed-off-by: subhamkrai <srai@redhat.com>