NFS-Ganesha introduced a breaking change in its config parser that no
longer accepts single quotes around values. This seems to be working for
most Ceph release images, but this was seen in at least one dev build of
Ceph.
Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
Implement an allow list mechanism that disables potentially unsafe OBC
fields by default. OBC fields beyond `maxObjects` and `maxSize` don't
neatly fit into the OBC framework as it was originally envisioned and
implemented.
Some of the newly added configs could allow users to cause confusion for
themselves. Others might allow users to hijack others buckets. Some
might allow bricking the entire S3 store.
Out of an abundance of safety, allow-list the known-safe options by
default, and require administrators to enable potentially troublesome
options via the new operator-level config
`ROOK_OBC_ALLOW_ADDITIONAL_CONFIG_FIELDS`.
Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
If a locally mounted volume is blocked on reads because this OSD is
down, lvs will deadlock trying to read from it. To avoid this, tell LVM
to filter out RBD volumes from its scanning process.
Signed-off-by: Steven Fackler <sfackler@gmail.com>
This field held state for a single reconciliation request, which
should not have been retrained / reused across multiple, possibly concurrent,
reconciliations.
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
This PR addresses an issue where the CrashCollector Pruner
CronJob pods were stuck in a Pending state due to missing
tolerations in their PodTemplateSpec.
These tolerations were not being propagated from the
cephClusterSpec.placement.all field.
Added tolerations to the PodTemplateSpec of the
CrashCollector Pruner CronJob.
Signed-off-by: Oded Viner <oviner@redhat.com>
The Kubernetes CSI sidecars have had several releases that were not
included in deployments by Rook yet, update them to the versions that
are available today:
- csi-node-driver-registrar:v2.13.0
- csi-provisioner:v5.1.0
- csi-attacher:v4.8.0
- csi-resizer:v1.13.1
Signed-off-by: Niels de Vos <ndevos@ibm.com>
The operator namespace is where the csi driver resources
are being created. The prefix is expected to match the
namespace where the driver is being created.
It was an incorrect change from 15245 where it
had been assumed that the cluster prefix name was
required instead.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
When the cluster is in a different namespace from the rook
operator, the csi provider name was setting the incorrect
namespace prefix. Now the prefix will be the same as the
ceph cluster namespace.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
Cleanup obsolete code where the context no longer needs
to be passed as a parameter to determine the namespaces
to watch.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
Fix label selector for watch-active mgr container: during update active mgr label,
add missed app=rook-ceph-mgr label, to avoid setting label for mon pod.
Resolves: #15208
Signed-off-by: Denis Egorenko degorenko@mirantis.com
In the unit test that ensures `rgwCommandFlags` works properly, ignore
the ordering of the flags. Golang maps are used underneath, which
results in random flag ordering. This is fine as long as the
`rgwCommandFlags` are still guaranteed to be appended to the args Rook
normally applies.
Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
Use testify/assert.Equal() to compare maps. Comparing string
representations of maps is supposed to be stable but is flaking in GH
actions CI.
Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
the rgw operations for s3 can now be accessible using sidecar
rgw-ops-log availabe in json form that can be further filtered logging
for observability, this will set the rgw_enable_ops_log setting
Signed-off-by: Deepika Upadhyay <deepika.upadhyay@clyso.com>
Implement #15119
Allow users to override RGW configurations by specifying Ceph config
options in the CephObjectStore. For configurations that require RGW to
be restarted when the config is applied, allow configs to be specified
as CLI arguments to the RGW as well.
This is an advanced option and is documented as such. Users should be
careful to understand the values they are setting, as there is no
validation to prevent the object store from breaking when these configs
are used.
Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
With the updated dependencies, the csi unit tests
require new default fields in the comparison of the
json test blob.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
The ci was using a pretty old version og golangci-lint.
This updates to the latest version.
Additionally, it silences some
gosec integer conversion overflow false positves
and fixes some real errors of this category
and string format errors found by golangci-lint, while at it.
Co-authored-by: Blaine Gardner <b.blaine.gardner@gmail.com>
Co-authored-by: Travis Nielsen <tnielsen@redhat.com>
Signed-off-by: Michael Adam <obnox@samba.org>
Fix the issue when using with external ceph cluster, ceph exporter
secret isn't created which cause ceph-exporter fail to run. By
default this option is false means ceph-exporter will run for
external cluster.
monitoring
metricsDisabled: false
This patch also adds metricsDisabled option to helm values.yaml.
fixes#14275
Signed-off-by: Yaguang Tang <heut20008@gmail.com>
Add a s3Agent field to bucket.Provisioner struct as a step towards
allowing the s3Agent / s3 client to be mocked in unit tests.
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
With the v19.2.0 release being out for some time now,
update the default version to be deployed with Rook
as v19.2.0.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>