Commit Graph
3017 Commits
Author SHA1 Message Date
Skala Networks d3c3d25c60 csi: bind cephfs and rbd provisionners on non-colliding ports for hostNetwork setups
Signed-off-by: Skala Networks <contact@skala.network>
2025-02-23 06:31:43 -05:00
Blaine Gardner 73c931fc0a Merge pull request #15376 from BlaineEXE/obc-allow-list-obc-fields
object: disallow unsafe OBC fields by default
2025-02-19 12:00:54 -07:00
Blaine Gardner 13cf8f0996 Merge pull request #15393 from BlaineEXE/fix-broken-nfs
nfs: workaround broken nfs-ganesha config parser
2025-02-13 09:51:36 -07:00
Blaine Gardner 55d1a86755 nfs: workaround broken nfs-ganesha config parser
NFS-Ganesha introduced a breaking change in its config parser that no
longer accepts single quotes around values. This seems to be working for
most Ceph release images, but this was seen in at least one dev build of
Ceph.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2025-02-13 09:25:07 -07:00
Blaine Gardner 022d68e98b Merge pull request #15371 from jhoblitt/plumbing/user-controller-no-state
object: rm ReconcileObjectStoreUser.userConfig field
2025-02-13 08:53:31 -07:00
Blaine Gardner 0e33536539 object: disallow unsafe OBC fields by default
Implement an allow list mechanism that disables potentially unsafe OBC
fields by default. OBC fields beyond `maxObjects` and `maxSize` don't
neatly fit into the OBC framework as it was originally envisioned and
implemented.

Some of the newly added configs could allow users to cause confusion for
themselves. Others might allow users to hijack others buckets. Some
might allow bricking the entire S3 store.

Out of an abundance of safety, allow-list the known-safe options by
default, and require administrators to enable potentially troublesome
options via the new operator-level config
`ROOK_OBC_ALLOW_ADDITIONAL_CONFIG_FIELDS`.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2025-02-12 14:18:01 -07:00
Steven Fackler bbe600aa20 osd: avoid lvm device scan deadlock in activate
If a locally mounted volume is blocked on reads because this OSD is
down, lvs will deadlock trying to read from it. To avoid this, tell LVM
to filter out RBD volumes from its scanning process.

Signed-off-by: Steven Fackler <sfackler@gmail.com>
2025-02-08 13:39:16 -05:00
Joshua Hoblitt 37b7930e13 object: rm ReconcileObjectStoreUser.userConfig field
This field held state for a single reconciliation request, which
should not have been retrained / reused across multiple, possibly concurrent,
reconciliations.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-02-07 14:37:14 -07:00
Joshua Hoblitt 0eef85357a object: obc should not modify existing users
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-02-03 15:19:48 -07:00
Joshua Hoblitt 48a9b90642 object: add obc bucketOwner
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-01-31 08:48:41 -07:00
Blaine Gardner bcb1db361a Merge pull request #15255 from cobaltcore-dev/hostname-topology-label
Hostname topology label
2025-01-28 09:00:50 -07:00
Artem Torubarov 25ee6b4f59 operator: custom hostname topology label
Signed-off-by: Artem Torubarov <artem.torubarov@clyso.com>
2025-01-24 15:59:07 +01:00
Travis Nielsen e17ef88ae8 Merge pull request #15309 from cobaltcore-dev/mon-db-conf-trace-log
operator: log mon db config values with trace lvl
2025-01-24 07:55:27 -07:00
Artem Torubarov 58febcbeab operator: log mon db config values with trace lvl
log applied mon store config values with trace lvl for debug purpose

Signed-off-by: Artem Torubarov <artem.torubarov@clyso.com>
2025-01-24 15:18:19 +01:00
Santosh Pillai e23e921f28 Merge pull request #15306 from sfackler/wait-for-secret
rgw: fix error handling for secret lookup
2025-01-24 12:06:39 +05:30
Joshua Hoblitt a55fdb3fbe object: add obc bucketLifecycle
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-01-21 16:01:37 -07:00
Joshua Hoblitt f52f48c477 ci: codespell: s/re-using/reusing/
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-01-21 15:11:33 -07:00
Steven Fackler 6935dfdc47 rgw: fix error handling for secret lookup
Get will return a non-nil pointer even in the error case.

Signed-off-by: Steven Fackler <sfackler@gmail.com>
2025-01-21 09:42:46 -05:00
Eng Zer Jun e68a7ea561 build: replace golang.org/x/exp/slices with stdlib slices
The experimental functions in `golang.org/x/exp/slices` are now
available in the standard library in Go 1.21.

Reference: https://go.dev/doc/go1.21#slices
Signed-off-by: Eng Zer Jun <engzerjun@gmail.com>
2025-01-21 15:02:35 +08:00
Travis Nielsen f5833cf58f Merge pull request #15270 from cobaltcore-dev/remove-mon-db-conf-log
operator: omit values from mon db config logs
2025-01-16 11:29:37 -07:00
Travis Nielsen 53c419afdd Merge pull request #15258 from OdedViner/pruner_tollerations
core: add tolerations to crashcollector pruner cronJob pod
2025-01-16 10:00:34 -07:00
ArtemandTravis Nielsen db88970641 operator: omit mon db config value log
Co-authored-by: Travis Nielsen <tnielsen@redhat.com>
Signed-off-by: Artem Torubarov <artem.torubarov@clyso.com>
2025-01-16 16:42:34 +01:00
Oded Viner 8817a1a703 core: add tolerations to crashcollector pruner cronJob pod
This PR addresses an issue where the CrashCollector Pruner
CronJob pods were stuck in a Pending state due to missing
tolerations in their PodTemplateSpec.
These tolerations were not being propagated from the
cephClusterSpec.placement.all field.
Added tolerations to the PodTemplateSpec of the
CrashCollector Pruner CronJob.

Signed-off-by: Oded Viner <oviner@redhat.com>
2025-01-16 16:17:20 +02:00
Niels de Vos 955fa9cae4 csi: update Kubernetes CSI sidecar images to current versions
The Kubernetes CSI sidecars have had several releases that were not
included in deployments by Rook yet, update them to the versions that
are available today:

- csi-node-driver-registrar:v2.13.0
- csi-provisioner:v5.1.0
- csi-attacher:v4.8.0
- csi-resizer:v1.13.1

Signed-off-by: Niels de Vos <ndevos@ibm.com>
2025-01-15 13:11:26 +01:00
Artem Torubarov a44ae0fdc6 operator: omit values from mon db config logs
Signed-off-by: Artem Torubarov <artem.torubarov@clyso.com>
2025-01-14 18:14:04 +01:00
Travis Nielsen f9ebaf3418 csi: set driver name to same as the operator namespace
The operator namespace is where the csi driver resources
are being created. The prefix is expected to match the
namespace where the driver is being created.
It was an incorrect change from 15245 where it
had been assumed that the cluster prefix name was
required instead.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-01-13 16:34:43 -07:00
subham rai 77b6565c4f Merge pull request #15245 from travisn/csi-operator-cleanup
csi: Set correct driver name with csi operator
2025-01-09 12:26:24 +05:30
Travis Nielsen ac1767fa0f csi: set correct driver name with csi operator
When the cluster is in a different namespace from the rook
operator, the csi provider name was setting the incorrect
namespace prefix. Now the prefix will be the same as the
ceph cluster namespace.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-01-08 16:04:27 -07:00
Travis Nielsen 82c82bbe13 core: remove unnecessary param to watch namespaces
Cleanup obsolete code where the context no longer needs
to be passed as a parameter to determine the namespaces
to watch.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-01-08 16:02:27 -07:00
Santosh Pillai e44dd3ad74 osd: use bluestore if store type is empty
If store type is empty in the cephCluster spec, use bluestore

Signed-off-by: Santosh Pillai <sapillai@redhat.com>
2025-01-08 16:15:07 +05:30
Denis Egorenko 009a0d9f6f mgr: fix label selector when updating mgr active label
Fix label selector for watch-active mgr container: during update active mgr label,
add missed app=rook-ceph-mgr label, to avoid setting label for mon pod.

Resolves: #15208
Signed-off-by: Denis Egorenko degorenko@mirantis.com
2024-12-20 20:50:05 +04:00
Steven Kreitzer 463d9fb420 csi: csi-snapshotter flag typo; upgrade csi-snapshotter
Signed-off-by: Steven Kreitzer <skre@skre.me>
2024-12-18 09:09:29 -06:00
Blaine Gardner ebd3c512b9 Merge pull request #15189 from BlaineEXE/test-fix-object-spec-test-added-flags
test: ignore rgw cli flag order in unit test
2024-12-17 12:41:16 -07:00
Blaine Gardner 37c3cc9fba test: ignore rgw cli flag order in unit test
In the unit test that ensures `rgwCommandFlags` works properly, ignore
the ordering of the flags. Golang maps are used underneath, which
results in random flag ordering. This is fine as long as the
`rgwCommandFlags` are still guaranteed to be appended to the args Rook
normally applies.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-12-17 12:21:50 -07:00
Blaine Gardner dde609a9d4 Merge pull request #15185 from BlaineEXE/test-fix-flaky-unit
test: fix flaky object config unit test
2024-12-17 10:35:19 -07:00
Blaine Gardner 92c95fcc16 test: fix flaky object config unit test
Use testify/assert.Equal() to compare maps. Comparing string
representations of maps is supposed to be stable but is flaking in GH
actions CI.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-12-17 10:12:04 -07:00
Deepika Upadhyay c5d27467d6 object: add rgw ops sidecar for op logs
the rgw operations for s3 can now be accessible using sidecar
rgw-ops-log availabe in json form that can be further filtered logging
for observability, this will set the rgw_enable_ops_log setting

Signed-off-by: Deepika Upadhyay <deepika.upadhyay@clyso.com>
2024-12-17 22:36:03 +05:30
Blaine Gardner aaa16488de object: allow overriding rgw configs and flags
Implement #15119

Allow users to override RGW configurations by specifying Ceph config
options in the CephObjectStore. For configurations that require RGW to
be restarted when the config is applied, allow configs to be specified
as CLI arguments to the RGW as well.

This is an advanced option and is documented as such. Users should be
careful to understand the values they are setting, as there is no
validation to prevent the object store from breaking when these configs
are used.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-12-16 14:57:15 -07:00
Blaine Gardner c0799e0d39 Merge pull request #15115 from obnoxxx/update-api-deps
build: Update api gomod dependencies
2024-12-16 12:53:41 -07:00
Travis Nielsen 2fdf173ddf test: add new default fields to csi unit test
With the updated dependencies, the csi unit tests
require new default fields in the comparison of the
json test blob.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-12-16 19:52:15 +01:00
Travis Nielsen a6595e9754 Merge pull request #14456 from yaguangtang/exporter-secret-not-create-issue
external: fix exporter secret isn't created with external cluster
2024-12-16 10:58:23 -07:00
df511fb58f ci: update golangci-lint to the latest version (v1.62)
The ci was using a pretty old version og golangci-lint.
This updates to the latest version.

Additionally, it  silences some
gosec integer conversion overflow false positves
and fixes some real errors of this category
 and string format errors found by golangci-lint, while at it.

Co-authored-by: Blaine Gardner <b.blaine.gardner@gmail.com>
Co-authored-by: Travis Nielsen <tnielsen@redhat.com>
Signed-off-by: Michael Adam <obnox@samba.org>
2024-12-14 14:47:30 +01:00
Yaguang Tang 1563d32fbb external: fix exporter secret isn't created with external cluster
Fix the issue when using with external ceph cluster, ceph exporter
secret isn't created which cause ceph-exporter fail to run. By
default this option is false means ceph-exporter will run for
external cluster.

monitoring
  metricsDisabled: false

This patch also adds metricsDisabled option to helm values.yaml.

fixes #14275

Signed-off-by: Yaguang Tang <heut20008@gmail.com>
2024-12-13 17:01:08 -07:00
Joshua Hoblitt 97b904c717 object: add obc bucketPolicy
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-12-12 13:36:26 -07:00
Joshua Hoblitt 57b7eeec80 object: add httpClient param to object.NewS3Agent()
To allow the caller to pass in their own transport when testing.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-12-12 10:20:41 -07:00
Joshua Hoblitt e5f79dba7f object: factor out bucket.setS3Agent()
Add a s3Agent field to bucket.Provisioner struct as a step towards
allowing the s3Agent / s3 client to be mocked in unit tests.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-12-12 10:20:41 -07:00
Travis Nielsen fd3d301746 Merge pull request #15131 from travisn/squid-default
manifest: Update default ceph version to v19
2024-12-11 15:19:18 -07:00
Travis Nielsen 07d8012d36 manifest: update default ceph version to v19
With the v19.2.0 release being out for some time now,
update the default version to be deployed with Rook
as v19.2.0.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-12-11 14:45:26 -07:00
Madhu Rajanna 07f5700a87 csi: update cephcsi to latest release
cephcsi 3.13.0 is released today and
update the Rook to use the latest image

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-12-11 14:31:17 -07:00
Travis Nielsen 0f45b88f5d Merge pull request #15064 from cobaltcore-dev/rgw_enable_apis
Add rgw_enable_apis option to ObjectStore CRD
2024-12-10 09:57:13 -07:00