Commit Graph
135 Commits
Author SHA1 Message Date
Skala Networks d3c3d25c60 csi: bind cephfs and rbd provisionners on non-colliding ports for hostNetwork setups
Signed-off-by: Skala Networks <contact@skala.network>
2025-02-23 06:31:43 -05:00
Blaine Gardner 0e33536539 object: disallow unsafe OBC fields by default
Implement an allow list mechanism that disables potentially unsafe OBC
fields by default. OBC fields beyond `maxObjects` and `maxSize` don't
neatly fit into the OBC framework as it was originally envisioned and
implemented.

Some of the newly added configs could allow users to cause confusion for
themselves. Others might allow users to hijack others buckets. Some
might allow bricking the entire S3 store.

Out of an abundance of safety, allow-list the known-safe options by
default, and require administrators to enable potentially troublesome
options via the new operator-level config
`ROOK_OBC_ALLOW_ADDITIONAL_CONFIG_FIELDS`.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2025-02-12 14:18:01 -07:00
Artem Torubarov 25ee6b4f59 operator: custom hostname topology label
Signed-off-by: Artem Torubarov <artem.torubarov@clyso.com>
2025-01-24 15:59:07 +01:00
Niels de Vos 955fa9cae4 csi: update Kubernetes CSI sidecar images to current versions
The Kubernetes CSI sidecars have had several releases that were not
included in deployments by Rook yet, update them to the versions that
are available today:

- csi-node-driver-registrar:v2.13.0
- csi-provisioner:v5.1.0
- csi-attacher:v4.8.0
- csi-resizer:v1.13.1

Signed-off-by: Niels de Vos <ndevos@ibm.com>
2025-01-15 13:11:26 +01:00
Steven Kreitzer 463d9fb420 csi: csi-snapshotter flag typo; upgrade csi-snapshotter
Signed-off-by: Steven Kreitzer <skre@skre.me>
2024-12-18 09:09:29 -06:00
Madhu Rajanna 07f5700a87 csi: update cephcsi to latest release
cephcsi 3.13.0 is released today and
update the Rook to use the latest image

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-12-11 14:31:17 -07:00
Niels de Vos f1d448cc46 csi: update csi-addons to v0.11.0
The csi-addons v0.11.0 release is now available.

See-also: https://github.com/csi-addons/kubernetes-csi-addons/releases/tag/v0.11.0
Signed-off-by: Niels de Vos <ndevos@ibm.com>
2024-11-26 10:38:54 +01:00
Madhu Rajanna e599ef67ef csi: update to latest cephcsi release
cephcsi fixed a bug related to data loss
and its fixed in 3.12.3 release, This commit
updates the cephcsi to 3.12.3 release.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-11-25 19:02:25 +01:00
Travis Nielsen 2ff429e479 csi: remove version check for k8s and cephcsi
The version checks for the csi driver are removed now
since they are all obsolete. The K8s version and cephcsi
versions are no longer checked. Anyway, the move to the
csi operator would take ownership of version checks
needed in the future, so for now we simplify rook
deployment of the csi driver.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-10-30 14:03:51 -06:00
Blaine Gardner 5539eedd1b multus: finish deprecating holder pods
Finish the process of deprecating holder pods by removing Rook's ability
to deploy them. The intent of this change is to make the most
superficial changes possible to accomplish this. There are still
remnants of code in Rook (particularly the CSI controller) that helped
configure or deploy holder pods. Due to the risk of breaking some
features, cleanup work of hose remnants will be deferred for future
work.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-10-23 16:29:02 -06:00
Madhu Rajanna 55441ee408 csi: fix typo in image version
add missing `v` in the cephcsi
image version

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-10-21 10:53:55 +02:00
Travis Nielsen 810de394e7 helm: add enforce host network setting
The ROOK_ENFORCE_HOST_NETWORK option was implemented recently
and now we add the helm setting to expose this new setting
in the rook chart.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-10-02 15:14:46 -06:00
Michael Adam ab8fd90aa6 core: add ROOK_REVISION_HISTORY_LIMIT operator setting
This adds an operator config setting ROOK_REVISION_HISTORY_LIMIT
defaulting to kubernetes'value for RevisionHistoryLimit.

If configured, the provided value will be used as RevisionHistoryLimit

for all Deployments rook creates.

Fixes: #12722

Signed-off-by: Michael Adam <obnox@samba.org>
2024-10-02 19:40:37 +02:00
Praveen M afad40e404 csi: update csi-addons to v0.10.0
The csi-addons v0.10.0 release is now available.
Ref: https://github.com/csi-addons/kubernetes-csi-addons/releases/tag/v0.10.0

Signed-off-by: Praveen M <m.praveen@ibm.com>
2024-09-18 12:19:46 +05:30
Madhu Rajanna d041be4bcf csi: update to new cephcsi release
we have 3.12.2 as the new cephcsi release
updating the rook to use the same.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-09-06 16:17:24 +02:00
Madhu Rajanna 05d579b607 csi: update csi-addons to v0.9.1
updating csi-addons to latest
v0.9.1 release.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-09-03 12:52:00 +02:00
Travis Nielsen 3d747f399e Merge pull request #14598 from jrcichra/configurable-metrics-bind-address
core: add configuration option for metrics bindAddress
2024-08-20 12:13:43 -06:00
Justin Cichra 74a79b24b3 core: add configuration option for metrics bindAddress
Alerting on controller-runtime's workqueue_depth can be useful for
debugging controllers. Also having a prometheus target for a pod gives
another data point that the system is working as expected. It is useful
for uptime alerts.

Make the bind address configurable via the configmap while still retaining the default
behavior that it is disabled.

Resolves: #14538

Signed-off-by: Justin Cichra <jcichra@cloudflare.com>
2024-08-20 13:38:38 -04:00
Zuhair AlSader 6714b86d3b manifest: add registry name to docker images
Signed-off-by: Zuhair AlSader <zuhair@devzero.io>
2024-08-20 13:35:08 -04:00
Praveen M a1ddf4535d csi: update csi sidecars' image version
Below csi sidecars are updated with latest available versions

csi-resizer: v1.11.1
csi-provisioner: v5.0.1
csi-attacher: v4.6.1
csi-snapshotter: v8.0.1
csi-node-driver-registrar: v2.11.1

Signed-off-by: Praveen M <m.praveen@ibm.com>
2024-08-20 22:08:19 +05:30
Madhu Rajanna 7c7e8a2b32 csi: update cephcsi to 3.12.0
updating cephcsi image to 3.12.0
release.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-08-16 10:47:44 +02:00
Madhu Rajanna 123025f22c csi: update csi-addons to v0.9.0
As we have new csi-addons v0.9.0
updating the same here as well.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-08-16 07:57:16 +02:00
subhamkrai 4b0b3a55d9 csi: add code for new CSI operator CR cephcluster
adding code changes,rbac changes required for create the new
Ceph-CSI operator CR named cephCluster in api group 'csi.ceph.io'.

Signed-off-by: subhamkrai <srai@redhat.com>
2024-08-08 11:21:45 +05:30
Travis Nielsen 9967b161f9 Merge pull request #14420 from YiteGu/make-kube-api-limit-configurable
csi: make kube apiserver qps configurable
2024-07-16 07:40:56 -06:00
yite.gu 80541a23c9 csi: make kube apiserver qps configurable
This commit adds the flexibility to configure kube apiserver qps
as per the user requirement and also keeps the existing values as
the default one.

Signed-off-by: yite.gu <yitegu0@gmail.com>
2024-07-16 18:39:16 +08:00
parth-gr 2ca0d1390b csi: add securityContext to csi containers
With the recent enhancements csi containers for using
logrotate, they need to run with securityContext to privileged,
on platform like openshift.
Used the ROOK_HOSTPATH_REQUIRES_PRIVILEGED flag
wich is set with operator deployment to see
if the securityCOntext is needed or not

Closes: https://github.com/rook/rook/issues/14400

Signed-off-by: parth-gr <partharora1010@gmail.com>
2024-07-08 18:47:26 +05:30
Praveen M faf7837621 csi: update csi sidecars' image version
Below sidecars are updated with latest available versions

csi-node-driver-registrar: v2.10.1
csi-resizer: v1.10.1
csi-provisioner: v4.0.1
csi-attacher: v4.5.1
csi-snapshotter: v7.0.2

Signed-off-by: Praveen M <m.praveen@ibm.com>
2024-04-25 18:58:00 +05:30
Blaine Gardner 04ccc53b71 Merge pull request #13997 from BlaineEXE/upgrade-docs
doc: update release notes and upgrade docs for v1.14
2024-04-02 12:31:28 -06:00
Blaine Gardner 0736d7613d doc: update release notes and upgrade docs for v1.14
Update pending release notes, upgrade docs, and supplementary
documentation relevant for upgrades for the upcoming Rook v1.14 release.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-04-02 12:25:24 -06:00
Praveen M f985018f57 csi: update cephcsi to v3.11.0 release
This commit updates default cephcsi driver version
to v3.11.0

Signed-off-by: Praveen M <m.praveen@ibm.com>
2024-04-02 20:13:56 +05:30
parth-gr a72e029459 csi: add a new flag to disable csi driver
added a new flag ROOK_CSI_DISABLE_DRIVER
to disable csi controller.

Signed-off-by: parth-gr <partharora1010@gmail.com>
2024-03-22 18:22:51 +05:30
Blaine Gardner e41366bbcd Merge pull request #13890 from BlaineEXE/csi-disable-holder
csi: allow force disabling holder pods
2024-03-14 10:27:06 -06:00
Blaine Gardner 4f555dbbcb csi: allow force disabling holder pods
Add new CSI_DISABLE_HOLDER_PODS option for rook-ceph-operator.
This option will disable holder pods when set to "true".

In the long term, Rook plans to deprecate the holder pods entirely.
This new option will allow users to choose to migrate their clusters to
non-holder clusters when they are ready and able, giving them time to
gracefully migrate before the holders are permanently removed.

This option is set to "false" by default so that upgrading users don't
have their CSI pods modified unexpectedly.
Example manifests are modified to set this value to true so that new
clusters will not deploy holder pods.

Migrating users are provided with documentation to instruct them about
the new requirements they need to satisfy to successfully remove holder
pods, a procedure for migrating pods from holder to non-holder mounts,
and a way to delete holder pods once they are no longer in use.

When users set CSI_DISABLE_HOLDER_PODS="true", the CSI controller will
no longer deploy or update the holder pod Daemonsets, but it does not
delete any existing Daemonsets. This allows already-attached PVCs to
continue operating normally with their network connection continuing to
exist in the current holder pod. This is critical to avoid causing
ia cluster-wide storage outage.

More info: https://github.com/rook/rook/issues/13055

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-03-14 09:53:08 -06:00
Jiffin Tony Thottan e0768f5e5f object: provisoner prefix support
add an option to set prefix for the name of obc provisioner instead of
ceph cluster namespace.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2024-03-11 13:42:11 +05:30
Travis Nielsen 7ca738e7b2 Merge pull request #13832 from Madhu-1/template-change-vgsc-rook
csi: support volumegroup snapshot
2024-03-01 11:21:42 -07:00
Madhu Rajanna 43fa57fa57 csi: update sidecars to latest release
updating all the csi sidecars to the
latest release.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-03-01 18:13:38 +01:00
Madhu Rajanna 2611e924a2 csi: provide option to configure VGS
volumegroupsnapshot feature will be enabled
by default if the required CRD's are present
if not its disabled and user will have an option
to disable it if they dont require this feature.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-03-01 18:12:37 +01:00
Travis Nielsen 5ce7fd97bd Merge pull request #13736 from Madhu-1/csi-3.10.2
csi: update cephcsi image to 3.10.2
2024-02-09 11:20:10 -07:00
Travis Nielsen 142ac703d7 Merge pull request #13665 from iPraveenParihar/remove/CSI_ENABLE_READ_AFFINITY
csi: remove CSI_ENABLE_READ_AFFINITY
2024-02-09 07:46:27 -07:00
Madhu Rajanna c22597a32c csi: update cephcsi image to 3.10.2
Updating the cephcsi image to 3.10.2
which is the latest released one.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-02-09 08:21:05 +01:00
travisn 27265ff279 helm: remove cpu limits from all pods
When CPU requests and limits are assigned to a pod,
the pod will be guaranteed the requests, up to the limits.
Even if there are spare CPU cycles, the pod cannot use
them. Thus, pods can be unnecessarily denied compute
when they need to burst if the limits are set.

Therefore, it is not recommended to set CPU limits
since the CPU requests are already guaranteeing that
no pod will be starved at least for its requests.

Signed-off-by: travisn <tnielsen@redhat.com>
2024-02-07 17:36:59 -07:00
Praveen M d28febaa61 csi: remove CSI_ENABLE_READ_AFFINITY
This commit removes the `CSI_ENABLE_READ_AFFINITY` since
it is no longer utilized after addition of the read affinity
option per cluster via CSIDriverSpec.

Signed-off-by: Praveen M <m.praveen@ibm.com>
2024-02-06 20:21:57 +05:30
Travis Nielsen 3b1a428688 Merge pull request #13622 from Madhu-1/csi-name-prefix
csi: option to customize csi driver name prefix
2024-01-29 10:55:55 -07:00
Madhu Rajanna c35a8532aa csi: option to customize csi driver name prefix
For now we are using the operator namespace name
as the prefix for the csi driver, This PR provides
an option for the users if someone wants to have
their own prefix for the csi driver, if someone tries
to change the prefix for existing csi driver rook
operator will fail to reconcile the csi driver.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-01-29 10:54:25 +01:00
travisn ca28887403 operator: increase cpu limits
The operator needs to burst significantly when reconciling,
then will quiet down and nearly not consume any cpu.
Therefore, we allow the operator to burst to more than
a full cpu instead of limiting it to a half cpu.

Signed-off-by: travisn <tnielsen@redhat.com>
2024-01-25 10:12:55 -07:00
Travis Nielsen f46c0845ee Merge pull request #13573 from Madhu-1/fix-13475
csi: make leader election flags configurable
2024-01-18 11:55:38 -07:00
Madhu Rajanna 85b86efee1 csi: update csi provisioner to 3.6.3
updating csi provisioner to 3.6.3 to
as we have a bug in 3.6.2

resolves: #13475

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-01-17 11:02:08 +01:00
Madhu Rajanna 9b418d24a1 csi: make leader election flags configurable
This commit adds the flexibility to configure
leader election flags as per the user
requirement and also keeps the existing values
as the default one.

resolve: #13475

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-01-17 10:02:49 +01:00
Riya Singhal ef1ee6ebae csi: update default cephcsi version to 3.10.1
This commit updates default cephcsi driver version
to v3.10.1

Signed-off-by: Riya Singhal <rsinghal@redhat.com>
2023-12-19 23:42:26 +05:30
Niels de Vos 1ca1257c65 csi: update the CSI-Addons sidecar to v0.8.0
Quite some improvements have been included in the recently released
v0.8.0 of the CSI-Addons sidecar for Kubernetes. Rook users will benefit
from running the latest version of the sidecar when deploying Ceph-CSI.

See-also: https://github.com/csi-addons/kubernetes-csi-addons/releases/tag/v0.8.0
Signed-off-by: Niels de Vos <ndevos@ibm.com>
2023-12-15 15:13:42 +01:00