Commit Graph
4552 Commits
Author SHA1 Message Date
Travis Nielsen 4eed2a644f Merge pull request #15433 from SkalaNetworks/master
fix(csi-addons): bind cephfs and rbd provisionners on non-colliding p…
2025-02-24 12:06:57 -07:00
Skala Networks d3c3d25c60 csi: bind cephfs and rbd provisionners on non-colliding ports for hostNetwork setups
Signed-off-by: Skala Networks <contact@skala.network>
2025-02-23 06:31:43 -05:00
Travis Nielsen 2181170811 Merge pull request #15370 from travisn/osd-upgrade-checks
osd: Enable osd ok-to-stop checks on single node where there are at least three OSDs
2025-02-20 12:52:03 -07:00
Blaine Gardner 73c931fc0a Merge pull request #15376 from BlaineEXE/obc-allow-list-obc-fields
object: disallow unsafe OBC fields by default
2025-02-19 12:00:54 -07:00
Blaine Gardner 13cf8f0996 Merge pull request #15393 from BlaineEXE/fix-broken-nfs
nfs: workaround broken nfs-ganesha config parser
2025-02-13 09:51:36 -07:00
Blaine Gardner 55d1a86755 nfs: workaround broken nfs-ganesha config parser
NFS-Ganesha introduced a breaking change in its config parser that no
longer accepts single quotes around values. This seems to be working for
most Ceph release images, but this was seen in at least one dev build of
Ceph.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2025-02-13 09:25:07 -07:00
Blaine Gardner 022d68e98b Merge pull request #15371 from jhoblitt/plumbing/user-controller-no-state
object: rm ReconcileObjectStoreUser.userConfig field
2025-02-13 08:53:31 -07:00
Satoru Takeuchi 9ddab0165b Merge pull request #15377 from sfackler/lvs-deadlock
osd: avoid lvm device scan deadlock in activate
2025-02-13 18:47:40 +09:00
Blaine Gardner 0e33536539 object: disallow unsafe OBC fields by default
Implement an allow list mechanism that disables potentially unsafe OBC
fields by default. OBC fields beyond `maxObjects` and `maxSize` don't
neatly fit into the OBC framework as it was originally envisioned and
implemented.

Some of the newly added configs could allow users to cause confusion for
themselves. Others might allow users to hijack others buckets. Some
might allow bricking the entire S3 store.

Out of an abundance of safety, allow-list the known-safe options by
default, and require administrators to enable potentially troublesome
options via the new operator-level config
`ROOK_OBC_ALLOW_ADDITIONAL_CONFIG_FIELDS`.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2025-02-12 14:18:01 -07:00
subhamkrai e546bdb370 build: update prometheus to latest version v0.80.0
Signed-off-by: subhamkrai <srai@redhat.com>
2025-02-11 11:38:55 +05:30
Steven Fackler bbe600aa20 osd: avoid lvm device scan deadlock in activate
If a locally mounted volume is blocked on reads because this OSD is
down, lvs will deadlock trying to read from it. To avoid this, tell LVM
to filter out RBD volumes from its scanning process.

Signed-off-by: Steven Fackler <sfackler@gmail.com>
2025-02-08 13:39:16 -05:00
Joshua Hoblitt 37b7930e13 object: rm ReconcileObjectStoreUser.userConfig field
This field held state for a single reconciliation request, which
should not have been retrained / reused across multiple, possibly concurrent,
reconciliations.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-02-07 14:37:14 -07:00
Blaine Gardner 1cf0a83ead Merge pull request #15311 from jhoblitt/feature/obc-bucket-owner
object: add obc bucketOwner
2025-02-07 13:48:35 -07:00
Travis Nielsen e068e156ce osd: enable osd ok-to-stop checks on single node for three osds
If there are at least three OSDs on a single node, we should
treat it as a potential production cluster and perform
the ok-to-stop checks during reconcile. Otherwise,
it may cause instability during upgrades on
single-node clusters.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-02-05 12:08:48 -07:00
subhamkrai d7be3318b6 build: updates spf13 pflag from 1.0.5 to 1.0.6
Signed-off-by: subhamkrai <srai@redhat.com>
2025-02-04 08:54:19 +05:30
Joshua Hoblitt 0eef85357a object: obc should not modify existing users
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-02-03 15:19:48 -07:00
Joshua Hoblitt 48a9b90642 object: add obc bucketOwner
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-01-31 08:48:41 -07:00
Blaine Gardner bcb1db361a Merge pull request #15255 from cobaltcore-dev/hostname-topology-label
Hostname topology label
2025-01-28 09:00:50 -07:00
Travis Nielsen 16daa7dc44 Merge pull request #15184 from OdedViner/err_msg_ok_to_stop
operator: improve operator error logging for ok-to-stop failures
2025-01-24 08:13:20 -07:00
Artem Torubarov 25ee6b4f59 operator: custom hostname topology label
Signed-off-by: Artem Torubarov <artem.torubarov@clyso.com>
2025-01-24 15:59:07 +01:00
Travis Nielsen e17ef88ae8 Merge pull request #15309 from cobaltcore-dev/mon-db-conf-trace-log
operator: log mon db config values with trace lvl
2025-01-24 07:55:27 -07:00
Artem Torubarov 58febcbeab operator: log mon db config values with trace lvl
log applied mon store config values with trace lvl for debug purpose

Signed-off-by: Artem Torubarov <artem.torubarov@clyso.com>
2025-01-24 15:18:19 +01:00
Santosh Pillai e23e921f28 Merge pull request #15306 from sfackler/wait-for-secret
rgw: fix error handling for secret lookup
2025-01-24 12:06:39 +05:30
Joshua Hoblitt a55fdb3fbe object: add obc bucketLifecycle
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-01-21 16:01:37 -07:00
Joshua Hoblitt f52f48c477 ci: codespell: s/re-using/reusing/
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-01-21 15:11:33 -07:00
Steven Fackler 6935dfdc47 rgw: fix error handling for secret lookup
Get will return a non-nil pointer even in the error case.

Signed-off-by: Steven Fackler <sfackler@gmail.com>
2025-01-21 09:42:46 -05:00
subhamkrai e1ce1e4416 build: update k8s and cntrl runtime pkg
this commits updates the k8s pkg to v0.32.1 and
controller runtime to v0.20.0

Signed-off-by: subhamkrai <srai@redhat.com>
2025-01-21 14:34:12 +05:30
Eng Zer Jun e68a7ea561 build: replace golang.org/x/exp/slices with stdlib slices
The experimental functions in `golang.org/x/exp/slices` are now
available in the standard library in Go 1.21.

Reference: https://go.dev/doc/go1.21#slices
Signed-off-by: Eng Zer Jun <engzerjun@gmail.com>
2025-01-21 15:02:35 +08:00
Oded Viner 3d7f5cff65 operator: improve operator error logging for ok-to-stop failures
this PR improves the error logging when ok-to-stop requests fail
in the Rook operator. Instead of only showing a generic exit status

Signed-off-by: Oded Viner <oviner@redhat.com>
2025-01-19 14:46:57 +02:00
Travis Nielsen f5833cf58f Merge pull request #15270 from cobaltcore-dev/remove-mon-db-conf-log
operator: omit values from mon db config logs
2025-01-16 11:29:37 -07:00
Travis Nielsen 53c419afdd Merge pull request #15258 from OdedViner/pruner_tollerations
core: add tolerations to crashcollector pruner cronJob pod
2025-01-16 10:00:34 -07:00
ArtemandTravis Nielsen db88970641 operator: omit mon db config value log
Co-authored-by: Travis Nielsen <tnielsen@redhat.com>
Signed-off-by: Artem Torubarov <artem.torubarov@clyso.com>
2025-01-16 16:42:34 +01:00
Oded Viner 8817a1a703 core: add tolerations to crashcollector pruner cronJob pod
This PR addresses an issue where the CrashCollector Pruner
CronJob pods were stuck in a Pending state due to missing
tolerations in their PodTemplateSpec.
These tolerations were not being propagated from the
cephClusterSpec.placement.all field.
Added tolerations to the PodTemplateSpec of the
CrashCollector Pruner CronJob.

Signed-off-by: Oded Viner <oviner@redhat.com>
2025-01-16 16:17:20 +02:00
Niels de Vos 955fa9cae4 csi: update Kubernetes CSI sidecar images to current versions
The Kubernetes CSI sidecars have had several releases that were not
included in deployments by Rook yet, update them to the versions that
are available today:

- csi-node-driver-registrar:v2.13.0
- csi-provisioner:v5.1.0
- csi-attacher:v4.8.0
- csi-resizer:v1.13.1

Signed-off-by: Niels de Vos <ndevos@ibm.com>
2025-01-15 13:11:26 +01:00
Artem Torubarov a44ae0fdc6 operator: omit values from mon db config logs
Signed-off-by: Artem Torubarov <artem.torubarov@clyso.com>
2025-01-14 18:14:04 +01:00
Travis Nielsen f9ebaf3418 csi: set driver name to same as the operator namespace
The operator namespace is where the csi driver resources
are being created. The prefix is expected to match the
namespace where the driver is being created.
It was an incorrect change from 15245 where it
had been assumed that the cluster prefix name was
required instead.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-01-13 16:34:43 -07:00
subham rai 77b6565c4f Merge pull request #15245 from travisn/csi-operator-cleanup
csi: Set correct driver name with csi operator
2025-01-09 12:26:24 +05:30
Travis Nielsen ac1767fa0f csi: set correct driver name with csi operator
When the cluster is in a different namespace from the rook
operator, the csi provider name was setting the incorrect
namespace prefix. Now the prefix will be the same as the
ceph cluster namespace.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-01-08 16:04:27 -07:00
Travis Nielsen 82c82bbe13 core: remove unnecessary param to watch namespaces
Cleanup obsolete code where the context no longer needs
to be passed as a parameter to determine the namespaces
to watch.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-01-08 16:02:27 -07:00
Santosh Pillai e44dd3ad74 osd: use bluestore if store type is empty
If store type is empty in the cephCluster spec, use bluestore

Signed-off-by: Santosh Pillai <sapillai@redhat.com>
2025-01-08 16:15:07 +05:30
Santosh Pillai c4bf5637d2 ci: update golang.org/x/net to 0.33
fixes the high severity DOS vulnerability mentioned in
https://security.snyk.io/vuln/SNYK-GOLANG-GOLANGORGXNETHTML-8535262

Signed-off-by: Santosh Pillai <sapillai@redhat.com>
2025-01-03 09:53:47 +05:30
Denis Egorenko 009a0d9f6f mgr: fix label selector when updating mgr active label
Fix label selector for watch-active mgr container: during update active mgr label,
add missed app=rook-ceph-mgr label, to avoid setting label for mon pod.

Resolves: #15208
Signed-off-by: Denis Egorenko degorenko@mirantis.com
2024-12-20 20:50:05 +04:00
Steven Kreitzer 463d9fb420 csi: csi-snapshotter flag typo; upgrade csi-snapshotter
Signed-off-by: Steven Kreitzer <skre@skre.me>
2024-12-18 09:09:29 -06:00
Blaine Gardner ebd3c512b9 Merge pull request #15189 from BlaineEXE/test-fix-object-spec-test-added-flags
test: ignore rgw cli flag order in unit test
2024-12-17 12:41:16 -07:00
Blaine Gardner 37c3cc9fba test: ignore rgw cli flag order in unit test
In the unit test that ensures `rgwCommandFlags` works properly, ignore
the ordering of the flags. Golang maps are used underneath, which
results in random flag ordering. This is fine as long as the
`rgwCommandFlags` are still guaranteed to be appended to the args Rook
normally applies.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-12-17 12:21:50 -07:00
Blaine Gardner dde609a9d4 Merge pull request #15185 from BlaineEXE/test-fix-flaky-unit
test: fix flaky object config unit test
2024-12-17 10:35:19 -07:00
Blaine Gardner 92c95fcc16 test: fix flaky object config unit test
Use testify/assert.Equal() to compare maps. Comparing string
representations of maps is supposed to be stable but is flaking in GH
actions CI.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-12-17 10:12:04 -07:00
Deepika Upadhyay c5d27467d6 object: add rgw ops sidecar for op logs
the rgw operations for s3 can now be accessible using sidecar
rgw-ops-log availabe in json form that can be further filtered logging
for observability, this will set the rgw_enable_ops_log setting

Signed-off-by: Deepika Upadhyay <deepika.upadhyay@clyso.com>
2024-12-17 22:36:03 +05:30
Blaine Gardner aaa16488de object: allow overriding rgw configs and flags
Implement #15119

Allow users to override RGW configurations by specifying Ceph config
options in the CephObjectStore. For configurations that require RGW to
be restarted when the config is applied, allow configs to be specified
as CLI arguments to the RGW as well.

This is an advanced option and is documented as such. Users should be
careful to understand the values they are setting, as there is no
validation to prevent the object store from breaking when these configs
are used.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-12-16 14:57:15 -07:00
Blaine Gardner c0799e0d39 Merge pull request #15115 from obnoxxx/update-api-deps
build: Update api gomod dependencies
2024-12-16 12:53:41 -07:00