Commit Graph
634 Commits
Author SHA1 Message Date
Blaine Gardner 73c931fc0a Merge pull request #15376 from BlaineEXE/obc-allow-list-obc-fields
object: disallow unsafe OBC fields by default
2025-02-19 12:00:54 -07:00
Blaine Gardner 0e33536539 object: disallow unsafe OBC fields by default
Implement an allow list mechanism that disables potentially unsafe OBC
fields by default. OBC fields beyond `maxObjects` and `maxSize` don't
neatly fit into the OBC framework as it was originally envisioned and
implemented.

Some of the newly added configs could allow users to cause confusion for
themselves. Others might allow users to hijack others buckets. Some
might allow bricking the entire S3 store.

Out of an abundance of safety, allow-list the known-safe options by
default, and require administrators to enable potentially troublesome
options via the new operator-level config
`ROOK_OBC_ALLOW_ADDITIONAL_CONFIG_FIELDS`.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2025-02-12 14:18:01 -07:00
Joshua Hoblitt 37b7930e13 object: rm ReconcileObjectStoreUser.userConfig field
This field held state for a single reconciliation request, which
should not have been retrained / reused across multiple, possibly concurrent,
reconciliations.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-02-07 14:37:14 -07:00
Joshua Hoblitt 0eef85357a object: obc should not modify existing users
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-02-03 15:19:48 -07:00
Joshua Hoblitt 48a9b90642 object: add obc bucketOwner
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-01-31 08:48:41 -07:00
Blaine Gardner bcb1db361a Merge pull request #15255 from cobaltcore-dev/hostname-topology-label
Hostname topology label
2025-01-28 09:00:50 -07:00
Artem Torubarov 25ee6b4f59 operator: custom hostname topology label
Signed-off-by: Artem Torubarov <artem.torubarov@clyso.com>
2025-01-24 15:59:07 +01:00
Santosh Pillai e23e921f28 Merge pull request #15306 from sfackler/wait-for-secret
rgw: fix error handling for secret lookup
2025-01-24 12:06:39 +05:30
Joshua Hoblitt a55fdb3fbe object: add obc bucketLifecycle
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-01-21 16:01:37 -07:00
Joshua Hoblitt f52f48c477 ci: codespell: s/re-using/reusing/
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-01-21 15:11:33 -07:00
Steven Fackler 6935dfdc47 rgw: fix error handling for secret lookup
Get will return a non-nil pointer even in the error case.

Signed-off-by: Steven Fackler <sfackler@gmail.com>
2025-01-21 09:42:46 -05:00
Blaine Gardner ebd3c512b9 Merge pull request #15189 from BlaineEXE/test-fix-object-spec-test-added-flags
test: ignore rgw cli flag order in unit test
2024-12-17 12:41:16 -07:00
Blaine Gardner 37c3cc9fba test: ignore rgw cli flag order in unit test
In the unit test that ensures `rgwCommandFlags` works properly, ignore
the ordering of the flags. Golang maps are used underneath, which
results in random flag ordering. This is fine as long as the
`rgwCommandFlags` are still guaranteed to be appended to the args Rook
normally applies.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-12-17 12:21:50 -07:00
Blaine Gardner dde609a9d4 Merge pull request #15185 from BlaineEXE/test-fix-flaky-unit
test: fix flaky object config unit test
2024-12-17 10:35:19 -07:00
Blaine Gardner 92c95fcc16 test: fix flaky object config unit test
Use testify/assert.Equal() to compare maps. Comparing string
representations of maps is supposed to be stable but is flaking in GH
actions CI.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-12-17 10:12:04 -07:00
Deepika Upadhyay c5d27467d6 object: add rgw ops sidecar for op logs
the rgw operations for s3 can now be accessible using sidecar
rgw-ops-log availabe in json form that can be further filtered logging
for observability, this will set the rgw_enable_ops_log setting

Signed-off-by: Deepika Upadhyay <deepika.upadhyay@clyso.com>
2024-12-17 22:36:03 +05:30
Blaine Gardner aaa16488de object: allow overriding rgw configs and flags
Implement #15119

Allow users to override RGW configurations by specifying Ceph config
options in the CephObjectStore. For configurations that require RGW to
be restarted when the config is applied, allow configs to be specified
as CLI arguments to the RGW as well.

This is an advanced option and is documented as such. Users should be
careful to understand the values they are setting, as there is no
validation to prevent the object store from breaking when these configs
are used.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-12-16 14:57:15 -07:00
df511fb58f ci: update golangci-lint to the latest version (v1.62)
The ci was using a pretty old version og golangci-lint.
This updates to the latest version.

Additionally, it  silences some
gosec integer conversion overflow false positves
and fixes some real errors of this category
 and string format errors found by golangci-lint, while at it.

Co-authored-by: Blaine Gardner <b.blaine.gardner@gmail.com>
Co-authored-by: Travis Nielsen <tnielsen@redhat.com>
Signed-off-by: Michael Adam <obnox@samba.org>
2024-12-14 14:47:30 +01:00
Joshua Hoblitt 97b904c717 object: add obc bucketPolicy
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-12-12 13:36:26 -07:00
Joshua Hoblitt 57b7eeec80 object: add httpClient param to object.NewS3Agent()
To allow the caller to pass in their own transport when testing.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-12-12 10:20:41 -07:00
Joshua Hoblitt e5f79dba7f object: factor out bucket.setS3Agent()
Add a s3Agent field to bucket.Provisioner struct as a step towards
allowing the s3Agent / s3 client to be mocked in unit tests.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-12-12 10:20:41 -07:00
Artem Torubarov 83c8ec8160 rgw: add rgw_enable_apis config option
Signed-off-by: Artem Torubarov <artem.torubarov@clyso.com>
2024-12-10 11:53:27 +01:00
Blaine Gardner e6db006501 Merge pull request #15035 from BlaineEXE/object-revert-cosi-user-autocreation
Revert "object: create cosi user for each object store"
2024-12-09 16:21:58 -07:00
Blaine Gardner fc08e87d44 Revert "object: create cosi user for each object store"
This reverts commit a941b3c33f.

Stop creating the 'cosi' user in the CephObjectStore reconcile. This
step often fails for some amount of time during initial object store
creation, causing frequent user concern. It has also been the source of
some reported failures that would otherwise be non-breaking for certain
users.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-11-21 16:03:32 -07:00
Artem Torubarov 418d6e07e4 rgw: fix shared pools for zone
Signed-off-by: Artem Torubarov <artem.torubarov@clyso.com>
2024-11-21 14:58:40 +01:00
Artem Torubarov 8ad2bf88bb rgw: keep default-placement in zone config
Signed-off-by: Artem Torubarov <artem.torubarov@clyso.com>
2024-11-05 10:47:10 +01:00
Blaine Gardner 7bb72a0171 object: also use system certs for validating RGW cert
When generating the HTTP client used for RGW admin ops, use both system
certs as well as the user-given cert.

As a real world example, admins may use ACME to rotate Letsencrypt certs
every 2 months. For an external CephObjectStore, the cert used by Rook
and RGW may not be rotated at the same time. This can cause the Rook
operator to fail CephObjectStore reconciliation until both certs agree.

When Rook also relies on system certs in the container, Rook's
reconciliation will not have reconciliation failures because
Letsencrypt's well-known and trusted root certificates can be loaded
from the system to validate the RGW's newly-rotated cert.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-10-25 11:22:11 -06:00
Blaine Gardner c7dfe7837e Merge pull request #14884 from cobaltcore-dev/rgw-default-placement
rgw: support custom name for default pool placement
2024-10-25 10:30:58 -06:00
Artem Torubarov b47dff9770 rgw: support custom name for default pool placement
introduce Default flag to CRD

Signed-off-by: Artem Torubarov <artem.torubarov@clyso.com>
2024-10-25 12:52:06 +02:00
Joshua Hoblitt f51cfbdf6b object: add bucketMaxObjects & bucketMaxSize to obc
Two new keys are added to ObjectBucketClaim.spec.additionalConfig to
support the configuration of bucket scope quota(s). This differs from
the existing maxObjects & maxSize keys, which manage a user scope
quota(s) on the automatically generated rgw user.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-10-23 14:39:38 -07:00
Travis Nielsen 615086ccf2 Merge pull request #14715 from cobaltcore-dev/rgw_new_shared_pools
rgw: support new zone pools
2024-10-22 15:39:05 -06:00
Artem Torubarov f6a25b0c4b rgw: support v19 zone pools
add rgw shared pools rados ns to topics_pool, account_pool, and group_pool

Signed-off-by: Artem Torubarov <artem.torubarov@clyso.com>
2024-10-22 11:23:42 +02:00
Blaine Gardner 1c917743b4 Merge pull request #14827 from jhoblitt/feature/parseAdditionalConfig
object: set obc user quota(s) in one SetUserQuota() call
2024-10-18 16:57:50 -06:00
Joshua Hoblitt 9243764359 object: set obc user quota(s) in one SetUserQuota() call
Previously, up to 3 calls to SetUserQuota() could be made. This has been
consolidated into a single call. Additionally, the `addtionalConfigSpec`
struct is introduced to centralize handling of `.spec.additionalConfig`
keys and as foundational work to support new keys in the future.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-10-18 15:27:01 -07:00
Peter Razumovsky 516eab4d8a core: define empty securityContext for pods to fix CIS 5.7.3
Resolves CIS benchmark rule 5.7.3, Pods part. SecurityContext
should be explicitly defined in pod level of Pod spec section.
It is sufficient to specify empty securityContext to satisfy
CIS 5.7.3 rule.

5.7.3 Apply Security Context to Your Pods and Containers

When designing your containers and pods, make sure
that you configure the security context for your pods,
containers, and volumes.

Signed-off-by: Peter Razumovsky <prazumovsky@mirantis.com>
2024-10-09 16:10:03 +04:00
Travis Nielsen e26d5f80ed Merge pull request #14795 from travisn/remove-quincy
core: Remove support for Ceph Quincy
2024-10-03 12:07:39 -06:00
Joshua Hoblitt 9b952e0a55 rgw: fix cephObjectStore failing with pre-existing pools
When attempting to use pre-existing (or cephBlockPool managed) pools and
the cephObjectStore.spec.{metadataPool,dataPool} fields are not
specified, rgw creation will fail with this error:

    2024-09-25 21:00:17.744358 E | ceph-object-controller: failed to reconcile CephObjectStore "rook-ceph/test1". failed to create object store deployments: failed to create object pools: failed to create metadata pools: failed to create pool "test1.rgw.control": pool "test1.rgw.control" type is not defined as replicated or erasure coded

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-10-03 10:16:30 -07:00
Travis Nielsen b665d7a7b7 core: remove support for ceph quincy
Given that Ceph Quincy (v17) is past end of life,
remove Quincy from the supported Ceph versions,
examples, and documentation.

Supported versions now include only Reef and Squid.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-10-03 11:12:55 -06:00
Michael Adam ab8fd90aa6 core: add ROOK_REVISION_HISTORY_LIMIT operator setting
This adds an operator config setting ROOK_REVISION_HISTORY_LIMIT
defaulting to kubernetes'value for RevisionHistoryLimit.

If configured, the provided value will be used as RevisionHistoryLimit

for all Deployments rook creates.

Fixes: #12722

Signed-off-by: Michael Adam <obnox@samba.org>
2024-10-02 19:40:37 +02:00
Santosh Pillai 1a95d6f533 core: preserve pool application name change
default application name is updated inside the `CreatePool` method. Send
pool spec as address in order to preserve this change.

Signed-off-by: Santosh Pillai <sapillai@redhat.com>
2024-09-25 12:12:01 +05:30
Artem Torubarov 59175f0b40 rgw: pool placement
Signed-off-by: Artem Torubarov <torubarov.a.a@gmail.com>
2024-09-06 16:02:53 +02:00
Michael Adam e378588359 network: add a new operator config setting ROOK_ENFORCE_HOSTNETWORK
This new setting is of Boolean type and defaults to "false".

    When set to "true", it changes the behavior of the
     rook operator to
    nable host network on all pods created by the cephcluster controller

     new method to check the setting:  opcontroller.EnForceHostNetwork()

Signed-off-by: Michael Adam <obnox@samba.org>
2024-09-05 17:34:13 +02:00
Blaine Gardner eea43b7b79 rgw: allow users to add custom volume mounts
Allow RGW users to mount arbitrary volumes to RGW pods. This follows the
pattern that was established for NFS to support SSSD and LDAP, and
reuses much of the same code.

This opens the door wider for advanced users to take advantage of some
Ceph RGW features that Rook doesn't have first class support for.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-08-27 16:16:53 -06:00
Blaine Gardner 5f98d2ea3e Merge pull request #13807 from jklippel/feature/swift-and-keystone
rgw: implement support for authentication using keystone for s3 and swift
2024-08-08 09:55:34 -06:00
ee8bcad49d rgw: add support for keystone auth + swift/s3
For the specification see:
<https://github.com/rook/rook/blob/master/design/ceph/object/swift-and-keystone-integration.md>

* extend the API object specs for swift and keystone integration

* adapt rgw to the new go-ceph version

  - The parameter lists of the API call have changes, as parameters
    ignored by the RGW Admin Ops API are no longer serialized, therefore
    the mock has to be adapted.

  - There is now validation for the user keys that are passed to the
    User get API, therefore things failed when we had empty keys in our
    User proxy object.

* expand the reconcile loop for the swift and keystone integration

* fix minor mistakes in design document

* add env var to pass extra args to minikube

  Minikube decides CPU cores and memory automatically based on the
  available resources on the machine which may be insufficient to
  run rook. This commit adds an environment variable to add arbitrary
  arguments to the minikube command, so both can be specified if
  desired.

* integration tests for swift and keystone

  The new integration of swift or s3 and keystone support by rook
  does not have any integration tests yet.

  This commit introduces integration tests for swift and keystone. The
  tests are done against a minimal keystone setup (keystone container
  image from Yaook-project (https://yaook.cloud), sqlite as database
  backend, cert-manager and trust-manager for test certificate setup).

  To prevent hardcoded credentials, passwords are generated
  by the tests. The integration tests use the openstack client
  (keystone- and swift-functionality) (https://docs.openstack.org/
  python-openstackclient/ latest/). This was a concious design decision
  to use client tooling as close as possible to the end user instead of
  using other go-libraries (such as gophercloud).

* add documentation on swift and keystone

  Currently there is no documentation on the use of Swift to access
  an object store as well as the use of OpenStack keystone for
  authentication.

  This commit adds documentation on the use of Swift and OpenStack
  keystone, as well as CRD-related documentation and an example setup.

* add integration tests for S3 via keystone

  This commit introduces integration tests for s3 and keystone. The
  tests are run against the same minimal keystone setup that the tests
  for swift and keystone use.

  The integration tests use the aws s3 client to use client tooling as
  close as possible to the end user instead of using other go-libraries.

Co-authored-by: Jan Klippel <jan.klippel@uhurutec.com>
Co-authored-by: Silvio Ankermann <silvio.ankermann@cloudandheat.com>
Signed-off-by: Sebastian Riese <sebastian.riese@cloudandheat.com>
Signed-off-by: Jan Klippel <jan.klippel@uhurutec.com>
Signed-off-by: Silvio Ankermann <silvio.ankermann@cloudandheat.com>
2024-08-08 14:26:21 +02:00
Blaine Gardner b4a2285aa6 object: use advertise endpoint for admin ops
RGW can only serve a single certificate. This limitation means that the
prior behavior of using the default service for admin ops when TLS is
enabled may mean it requires additional complex certificate management
to make sure the object store uses a certificate valid for Rook internal
admin ops and user connections.

This is needlessly complex for users. Instead, change Rook's behavior
and documentation to clarify that it will use the same endpoint intended
for S3 client applications. This means that users have a more
straightforward path to enabling both Rook and consuming applications.

More info: https://github.com/rook/rook/issues/14530

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-08-05 14:32:59 -06:00
Blaine Gardner b76631ace9 Merge pull request #14467 from BlaineEXE/object-advertise-endpoint
object: add hosting.advertiseEndpoint config
2024-07-31 16:17:24 -06:00
Blaine Gardner a2b0b6449c object: add hosting.advertiseEndpoint config
Add CephObjectStore spec.hosting.advertiseEndpoint configuration. This
provides a clear documented default for which endpoint Rook "advertises"
to dependent resources like CephObjectStores, OBCs, and COSI
Buckets/Accesses and allows users to override the default behavior if
desired.

The current default is to round-robin an endpoint from
spec.hosting.dnsNames, which has proven to be troublesome for some
users' object store configurations. This change provides much-needed
disambiguation for users.

This may be a breaking change for some existing spec.hosting.dnsNames
users. This is unexpected but is documented.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-07-22 14:43:51 -06:00
yingshanghuangqiao 3d672a726a core: fix some comments
Signed-off-by: yingshanghuangqiao <yingshanghuangqiao@foxmail.com>
2024-07-22 22:09:52 +08:00
Travis Nielsen 28addd1301 Merge pull request #14216 from thotz/update-cosi-images
object: update cosi images
2024-07-10 12:47:07 -06:00