Commit Graph
49 Commits
Author SHA1 Message Date
Peter Razumovsky 516eab4d8a core: define empty securityContext for pods to fix CIS 5.7.3
Resolves CIS benchmark rule 5.7.3, Pods part. SecurityContext
should be explicitly defined in pod level of Pod spec section.
It is sufficient to specify empty securityContext to satisfy
CIS 5.7.3 rule.

5.7.3 Apply Security Context to Your Pods and Containers

When designing your containers and pods, make sure
that you configure the security context for your pods,
containers, and volumes.

Signed-off-by: Peter Razumovsky <prazumovsky@mirantis.com>
2024-10-09 16:10:03 +04:00
Michael Adam ab8fd90aa6 core: add ROOK_REVISION_HISTORY_LIMIT operator setting
This adds an operator config setting ROOK_REVISION_HISTORY_LIMIT
defaulting to kubernetes'value for RevisionHistoryLimit.

If configured, the provided value will be used as RevisionHistoryLimit

for all Deployments rook creates.

Fixes: #12722

Signed-off-by: Michael Adam <obnox@samba.org>
2024-10-02 19:40:37 +02:00
Michael Adam e378588359 network: add a new operator config setting ROOK_ENFORCE_HOSTNETWORK
This new setting is of Boolean type and defaults to "false".

    When set to "true", it changes the behavior of the
     rook operator to
    nable host network on all pods created by the cephcluster controller

     new method to check the setting:  opcontroller.EnForceHostNetwork()

Signed-off-by: Michael Adam <obnox@samba.org>
2024-09-05 17:34:13 +02:00
Louis Bailleul e56122cbce operator: config default interval value for discovery daemon
Correctly set discoveryInterval default value by passing defaultDiscoverInterval to k8sutil.GetValue
Allow to set ROOK_DISCOVER_DEVICES_INTERVAL env var through discoveryDaemonInterval helm value

Signed-off-by: Louis Bailleul <louis.bailleul@pgs.com>
2023-09-07 10:28:13 +01:00
subhamkrai fb39580067 operator: move most of discover pod setting to cm
It's better to move most of discover daemon setting
from env to configmap rook-ceph-operator-config.
Although, we are moving to configmap, we keep reading settings
from env but the priority will be configmap settings.

Signed-off-by: subhamkrai <srai@redhat.com>
2023-08-16 22:17:47 +05:30
parth-gr 8e317ee074 ci: update golangci-lint version as it fails for some k8s version in 1.10
Closes: https://github.com/rook/rook/issues/11896

Signed-off-by: parth-gr <paarora@redhat.com>
2023-03-16 20:59:22 +05:30
Travis Nielsen e0d1cabfda Merge pull request #11278 from parth-gr/resources-discovery
core: Add ability to add resources on discovery DaemonSet
2022-11-10 07:59:23 -07:00
parth-gr 9f432b4ecb core: add ability to add resources on discovery daemon set
Closes: https://github.com/rook/rook/issues/11265

Signed-off-by: parth-gr <paarora@redhat.com>
2022-11-10 17:50:06 +05:30
Shinya Hayashi 05875a3f4f osd: support loop devices for test clusters
A new variable is added to rook-ceph-operator-config
ConfigMap to allow using loop devices for osd.

This feature is intended to be used for testing purposes only.

Signed-off-by: Shinya Hayashi <shinya-hayashi@cybozu.co.jp>
2022-11-09 06:45:41 +00:00
Eng Zer Jun 8a25b1d903 test: use T.Setenv to set env vars in tests
This commit replaces `os.Setenv` with `t.Setenv` in tests. The
environment variable is automatically restored to its original value
when the test and all its subtests complete.

Reference: https://pkg.go.dev/testing#T.Setenv
Signed-off-by: Eng Zer Jun <engzerjun@gmail.com>
2022-07-15 23:07:19 +08:00
xakdwch 5057b9771f operator: discovery parameters use camelCase instead of snake_case
regulate the variable names to unite standard

Signed-off-by: xakdwch <xakdwch@163.com>
2022-06-18 02:50:24 +08:00
Sébastien Han dd67b866dc core: run discover daemonset as root uid
So that the tool inside the container has the permission to run
correctly, e.g: sgdisk.

Clsoes: https://github.com/rook/rook/issues/9493
Signed-off-by: Sébastien Han <seb@redhat.com>
2022-01-03 12:36:23 +01:00
parth-gr 0a86d26b2e core: create rook resources with k8s recommended labels
Adding Recommended Labels on the resources created by rook
    and using Recommended Labels in the helm chart,
    for better visuals and management of k8s object

Closes: https://github.com/rook/rook/issues/8400
Signed-off-by: parth-gr <paarora@redhat.com>
2021-12-07 18:16:44 +05:30
Yuichiro Ueno 4cc716a7ca core: add context parameter to k8sutil node
This commit adds context parameter to k8sutil node functions. By this,
we can handle cancellation during API call of node resource.

Signed-off-by: Yuichiro Ueno <y1r.ueno@gmail.com>
2021-11-15 22:45:59 +09:00
Yuichiro Ueno 0559977b8a core: add context parameter to k8sutil pod
This commit adds context parameter to k8sutil pod functions. By this, we
can handle cancellation during API call of pod resource.

Signed-off-by: Yuichiro Ueno <y1r.ueno@gmail.com>
2021-11-13 15:39:41 +09:00
Sébastien Han b89730d895 ceph: refactor operator initialization sequence
This commit is a large refactor on how the operator starts, stops and
how it starts various sub-components such as the ceph-csi driver. It
also refines the way we cancel orchestrations. We don't use breakpoints
anymore but send our self a SIGUP to reload our controller runtime
manager.
The reload will happen under different circonstances like:

* a new adminission controller secret is created/deleted/changed
* a CephCluster CR is edited

As mentioned earlier, the csi driver now has its own controller, just
like flex. It reacts to change in the operator config map for particular
ROOK_CSI_ fields.

A second new controller for the operator's general config has been
created, it manages:

* the logging level
* the ceph CLI command timeout
* the discovery daemon

The operator reacts much more rapidly to cancellation events by stopping
the manager's context and reloading it.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-09-17 16:57:12 +02:00
Travis Nielsen b0a63711f5 build: refactor to consolidate the rook.io/v1 package
The rook.io/v1 package was only an internal implementation detail and
does not have any CRDs that rely on it. The CRD deserialization should
handle the change in internal types without any issue. This separation
gives more flexibility for the storage providers to implement exactly
what is needed for their storage provider instead of forcing to use the
same types and risk affecting another storage provider.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-05-18 19:55:37 -06:00
Satoru Takeuchi 1be47ea0b8 ceph: delete discovery daemon if it is disabled
discovery-daemon still exists even if it's disabled.

Closes: https://github.com/rook/rook/issues/6936

Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
2021-01-15 19:44:40 +00:00
Arun Kumar Mohan 65d16bfc94 ceph: manual changes needed for kubernetes api updates
Fetched latest lib-bucket-provisioner changes as well.

Signed-off-by: Arun Kumar Mohan <amohan@redhat.com>
2020-11-18 21:14:01 +05:30
Alexander Trost fa62f4ac5d ceph: allow custom labels to be added to the discover daemonset
Signed-off-by: Alexander Trost <galexrt@googlemail.com>
2020-11-12 16:20:01 +01:00
subhamkrai 0fddfcf307 ceph: handle golangci-lint linter errcheck error
this commit handle golangci-lint linter errcheck.

`errcheck` - Errcheck is a program for checking for
unchecked errors in go programs. These unchecked errors
can be critical bugs in some cases

To see only staticcheck linter output
`golangci-lint run --disable-all -E errcheck`

Signed-off-by: subhamkrai <srai@redhat.com>
2020-09-30 22:24:34 +05:30
Travis Nielsen bcb99d86ce crds: pick up the rook types in the v1 package
The rook types used across the storage providers moved from the v1alpha2
package to the v1 package. This commit points the packages at their new
location. Implementation is expected to remain unchanged.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-02-26 11:18:17 -07:00
Nizamudeen 53883f68cf ceph: Handling Unhandled errors
This commit is to handle all those unhandled errors which raises the gosec warning.

Fixed G104: Unhandled Errors are handled now

Signed-off-by: Nizamudeen <nia@redhat.com>
2020-02-21 22:48:24 +05:30
Travis Nielsen 5d24710fd2 ceph: set discover ownerrefs without blocking parent deletion
An owner reference cannot be set with BlockOwnerDeletion: true
if the operator does not have privs to add a finalizer to the parent.
The discover resources don't need to block deletion based on the
parent so we remove that property from the owner reference.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2019-12-13 15:22:21 -07:00
Sébastien Han 2396e64525 rook: add owner reference to discover cm
Add owner reference to the discover config map so that when the
discover pod goes away we also remove its configmap.

Signed-off-by: Sébastien Han <seb@redhat.com>
2019-12-12 15:10:06 +01:00
Sébastien Han 90b4e74457 rook: add owner reference to the discover daemon
Attach owner reference to the discover daemon set so that when the
opetator goes away, the discover pod gets removed too.

Signed-off-by: Sébastien Han <seb@redhat.com>
2019-12-12 11:07:18 +01:00
d-luu 9c755fac66 ceph: added priority classes to components
Adds priority class support to Ceph components
  to influence scheduler's pod preemption

Signed-off-by: d-luu <david@davidluu.info>
2019-11-15 16:28:41 -06:00
Juan Miguel Olmo Martínez 7c942604f6 ceph: Get <ceph-volume inventory> data in dev. configmaps
**Description of your changes:**
This modification adds the information extracted from 'ceph-volume inventory':
command to the device configmaps generated by the discovery daemon when
"rook discover" starts with the new boolean "--use-ceph-volume" parameter.

Resolves #
https://github.com/rook/rook/issues/2606

Now the <cephVolumeData> field contains all the information returned
from <ceph-volume inventory> command.

Signed-off-by: Juan Miguel Olmo Martínez <jolmomar@redhat.com>
2019-11-06 10:22:56 +01:00
Madhu Rajanna 55e9340737 rename kserrors to k8serrors
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2019-09-27 10:05:45 +05:30
Madhu Rajanna 3af3cd63ab Rename AddNodeAffinity to GenerateNodeAffinity
function AddNodeAffinity was not adding any node
affinity instead it was forming the nodeaffinity
object. renamed it to GenerateNodeAffinity for more
meaningful

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2019-09-27 10:05:45 +05:30
rohan47andAshish Ranjan d2f52aebe5 Adds support for storageClassDeviceSet in rook-ceph operator
- Added code to support StorageClassDeviceSet spec provided in the cluster-on-pvc.yaml
- The code reads the StorageClassDeviceSet spec and creates pvc based on the ‘count’ field for each device set.
- OSD prepare job is started for each PVC which activates the ceph-volume on each PVC
- Finally OSD is started on each of the PVC device.

Co-authored-by: rohan47 <rohgupta@redhat.com>
Co-authored-by: Ashish Ranjan <aranjan@redhat.com>
Signed-off-by: Santosh Pillai <sapillai@redhat.com>
2019-08-12 09:24:13 -06:00
Mateusz Gozdek f936394764 ceph: allow to set multiple tolerations for agent and discover pods
Closes #2896

Signed-off-by: Mateusz Gozdek <mgozdekof@gmail.com>
2019-07-17 23:11:18 +02:00
Dmitry Yusupov 1f1f58ac1e Merge pull request #3375 from dyusupov/master
support for rook Device.FullPath
2019-07-05 07:40:47 -07:00
Umanga Chapagain 25e4275082 Rook: Added NodeAffinity to agent and discovery daemon
Previously, Rook Agent and Discovery DaemonSet deployment didn't allow
adding nodeAffinity. This commit adds nodeAffinity spec to daemonSet
deployment, which can be configured through environment variables in
operator deployment yaml.

+ Support multiple LabelKey, each with multiple LabelValue
+ Support multiple LabelKey with no value

Signed-off-by: Umanga Chapagain <chapagainumanga@gmail.com>
2019-07-05 13:48:09 +05:30
Dmitry Yusupov 5ffe2f037c support for rook Device.FullPath
Signed-off-by: Dmitry Yusupov <dmitry.yusupov@nexenta.com>
2019-07-03 23:06:58 -07:00
Alexander Trost 8bc26d9096 k8sclient: Update all operators to use apps/v1
All usages of k8s go client are now also using the versioned `AppsV1() `
call for the client.

Updated MySQL and Wordpress, and Kube Registy examples to use apps/v1
Deployments.

Signed-off-by: Alexander Trost <galexrt@googlemail.com>
2019-04-12 09:25:42 +02:00
travisn bdc3cf8146 osd: fix the device filter and improve device provisioning reliability
All devices detected by the discovery pod were being passed to the OSD provisioning pod
thus not always honoring the desired device list that should be provisioned.
Now the provisioning pod will be given the desired state from the crd,
then apply that state depending on the actual devices detected.
Also added a helper to ensure OSDsPerDevice is always valid.

Signed-off-by: travisn <tnielsen@redhat.com>
2019-02-26 16:11:25 -07:00
Huamin Chen 1b21e42a90 convert extensions to apps
Signed-off-by: Huamin Chen <hchen@redhat.com>
2019-02-14 16:06:05 -05:00
Alexander Trost b12d1e82cf Use truncated node name "everywhere"
Signed-off-by: Alexander Trost <galexrt@googlemail.com>
2018-11-23 10:02:35 +01:00
travisn 01dc5656f3 reduce frequency of device discovery
Signed-off-by: travisn <tnielsen@redhat.com>
2018-10-17 09:56:47 -06:00
travisn 7d97b6ad76 osd: use the node hostname labels instead of node names
Signed-off-by: travisn <tnielsen@redhat.com>
2018-10-01 08:09:06 -06:00
Blaine Gardner fe5fb394c7 Fix spellcheck and trailing space/newline issues
Fix some basic spellcheck errors. Also remove trailing spaces and make
sure files have a newline (my editor does automatically).

Signed-off-by: Blaine Gardner <blaine.gardner@suse.com>
2018-07-26 11:36:09 -06:00
travisn 962b4f22da osd: available devices should include previously configured devices
Signed-off-by: travisn <tnielsen@redhat.com>
2018-07-10 12:41:43 -06:00
Huamin Chen 82425aafcc prepare osd in a job per node. Once all osds are prepared, store osd info in orchestration configmap.
Operator watches the configmap, starts one osd replica set per osd.

Signed-off-by: Huamin Chen <hchen@redhat.com>
2018-07-05 16:02:27 -06:00
travisn 4f7f9b6daa device uuid discovery requires privileged
Signed-off-by: travisn <tnielsen@redhat.com>
2018-06-25 13:56:54 -06:00
travisn 6502cda3b4 refactor cluster roles for minimal rbac access
Signed-off-by: travisn <tnielsen@redhat.com>
2018-06-25 12:57:25 -06:00
Alexander Trost 098d4f2473 Update Rook Discover DaemonSet when it already exists
Signed-off-by: Alexander Trost <galexrt@googlemail.com>
2018-06-07 10:30:00 +02:00
Jared Watts f3df68e573 operator, daemon, and cmd updates for supporting multiple storage types
Signed-off-by: Jared Watts <jbw976@gmail.com>
2018-05-18 14:32:20 -07:00
Huamin Chen 6c11ff52d4 add device discovery daemon to operator:
run "rook discover" on storage nodes and discover devices on each node. The discovered disks are saved in a per node configmap, local-device-nodename.
Device information consits of name and persistent names, uuid, partition, filesystem, rotational, readonly, size, etc.

Signed-off-by: Huamin Chen <hchen@redhat.com>
2018-05-07 17:49:02 +00:00