Commit Graph
1413 Commits
Author SHA1 Message Date
Travis Nielsen 8f79b58edc Merge pull request #15392 from subhamkrai/update-ceph-v19.2.1
manifest: Update default ceph version to v19.2.1
2025-02-20 11:41:06 -07:00
subhamkrai 0e395f0a67 manifest: update default ceph version to v19.2.1
with ceph release v19.2.1 updating it to be dafult version
in rook.

Signed-off-by: subhamkrai <srai@redhat.com>
2025-02-20 23:24:54 +05:30
subhamkrai 45e76204bf ci: wait for pod before exec into pod
keystone integration test has recentally starting to fail
as pod with lable osc-admin-admin was not in running status
and we're trying to exec into the pod.

Signed-off-by: subhamkrai <srai@redhat.com>
2025-02-20 12:25:07 +05:30
Blaine Gardner 0e33536539 object: disallow unsafe OBC fields by default
Implement an allow list mechanism that disables potentially unsafe OBC
fields by default. OBC fields beyond `maxObjects` and `maxSize` don't
neatly fit into the OBC framework as it was originally envisioned and
implemented.

Some of the newly added configs could allow users to cause confusion for
themselves. Others might allow users to hijack others buckets. Some
might allow bricking the entire S3 store.

Out of an abundance of safety, allow-list the known-safe options by
default, and require administrators to enable potentially troublesome
options via the new operator-level config
`ROOK_OBC_ALLOW_ADDITIONAL_CONFIG_FIELDS`.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2025-02-12 14:18:01 -07:00
Joshua Hoblitt 9d21fe0f5c test: add obc bucketOwner integration test
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-02-04 12:10:20 -07:00
Joshua Hoblitt b689038ffc test: add obc bucketLifecycle integration test
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-01-21 16:01:37 -07:00
Joshua Hoblitt f52f48c477 ci: codespell: s/re-using/reusing/
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-01-21 15:11:33 -07:00
Michael Adam 795e188024 ci: rework docs-related workflow and make targets a bit
This change continues an effort started earlier to make some
make targets and ci workflows more consistent and systematic.
see https://github.com/rook/rook/pull/14922

it adds a  make target gen.helm-docs as an alias to helm-docs.
Additionally, gen.docs is added as alias to docs.
targets check.docs and check.helm-docs are removed because it was agreed
that targets using git are of little value to developers.
Their functionality is moved back into the corresponding docs workflow.

xiFinally, the  redundant "Check helm-docs" check is removed from the
docs-check workflow

Signed-off-by: Michael Adam <obnox@samba.org>
2025-01-09 20:31:14 +01:00
Travis Nielsen 56c6659655 tests: canary tests to wait for first mon to start
Many of the canary tests have been failing much more
frequently in the past week or two. The test is typically
timing out pulling the image from quay.ceph.io since
it does not have as high bandwidth for the images.
A check is added to the test to wait specifically for the
first mon so it waits sufficiently for the image pull
before checking for other ceph daemons.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-12-20 13:53:21 -07:00
Steven Kreitzer 463d9fb420 csi: csi-snapshotter flag typo; upgrade csi-snapshotter
Signed-off-by: Steven Kreitzer <skre@skre.me>
2024-12-18 09:09:29 -06:00
df511fb58f ci: update golangci-lint to the latest version (v1.62)
The ci was using a pretty old version og golangci-lint.
This updates to the latest version.

Additionally, it  silences some
gosec integer conversion overflow false positves
and fixes some real errors of this category
 and string format errors found by golangci-lint, while at it.

Co-authored-by: Blaine Gardner <b.blaine.gardner@gmail.com>
Co-authored-by: Travis Nielsen <tnielsen@redhat.com>
Signed-off-by: Michael Adam <obnox@samba.org>
2024-12-14 14:47:30 +01:00
Blaine Gardner 80903df984 Merge pull request #15138 from jhoblitt/feature/obc-bucket-policy-alt1
object: add bucketPolicy to obc
2024-12-12 14:36:16 -07:00
Joshua Hoblitt 8fd34e88bb test: add obc bucketPolicy integration test
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-12-12 13:36:26 -07:00
Joshua Hoblitt 57b7eeec80 object: add httpClient param to object.NewS3Agent()
To allow the caller to pass in their own transport when testing.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-12-12 10:20:41 -07:00
Travis Nielsen 7c2f41e72e build: add support for k8s 1.32
With the release of K8s 1.32, we update the CI and docs
to support this new release, to maintain the most recent
six releases of K8s.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-12-12 09:48:42 -07:00
Travis Nielsen 6db75b76b8 ci: use correct ceph-ci repo
The repo should be quay.ceph.io, instead of quay.io

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-12-11 15:24:08 -07:00
Travis Nielsen 07d8012d36 manifest: update default ceph version to v19
With the v19.2.0 release being out for some time now,
update the default version to be deployed with Rook
as v19.2.0.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-12-11 14:45:26 -07:00
Travis Nielsen 85375bf073 ci: use ceph-ci instead of daemon-base images
Ceph has changed the image build process to only require a
dockerfile and stop using the ceph-container repo. The
daily images are pushed to the quay.io/ceph-ci/ceph repo,
so the Rook CI will now start using those images.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-12-11 14:04:46 -07:00
Travis Nielsen 23f3db1261 ci: suppress the error from creating the dashboard admin user
The dashboard admin rgw user has timing isssues in the CI.
For now, just suppress the CI failure and log the error
until we can spend more time to get a reliable wait for the
user creation.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-12-11 09:42:59 -07:00
Blaine Gardner e6db006501 Merge pull request #15035 from BlaineEXE/object-revert-cosi-user-autocreation
Revert "object: create cosi user for each object store"
2024-12-09 16:21:58 -07:00
Travis Nielsen 232d046e3c Merge pull request #15045 from travisn/upgrade-1.16
tests: Upgrade from Rook 1.15 to master
2024-12-09 16:19:14 -07:00
Niels de Vos f1d448cc46 csi: update csi-addons to v0.11.0
The csi-addons v0.11.0 release is now available.

See-also: https://github.com/csi-addons/kubernetes-csi-addons/releases/tag/v0.11.0
Signed-off-by: Niels de Vos <ndevos@ibm.com>
2024-11-26 10:38:54 +01:00
Travis Nielsen 506407b5ea tests: upgrade from rook 1.15 to master
The upgrade tests in master have been upgrading from 1.14 to
master. In anticipation of the v1.16 release, we change
the upgrade tests to start from v1.15 to test if there
are any regressions in the supported upgrades.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-11-22 10:40:02 -07:00
Blaine Gardner fc08e87d44 Revert "object: create cosi user for each object store"
This reverts commit a941b3c33f.

Stop creating the 'cosi' user in the CephObjectStore reconcile. This
step often fails for some amount of time during initial object store
creation, causing frequent user concern. It has also been the source of
some reported failures that would otherwise be non-breaking for certain
users.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-11-21 16:03:32 -07:00
Travis Nielsen b229240faa ci: default to the latest stable squid instead of devel
The devel images have been fairly stable for Rook to test
against, but on occasion there are regressions from
Ceph development that affect the Rook CI. For stability during
Rook development, use the latest stable version of ceph for
PRs, master, and release tests. The daily CI will still use
the devel images from Ceph.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-11-04 14:10:36 -07:00
Travis Nielsen f60f4443df test: remove obsolete object user test flag
In Rook v1.6 some new properties were added for
ceph object store users, so the CI was skipping
validation of that setting in the upgrade test.
Now we are far past the need for that flag, and we
can assume the latest flags exist for the tests.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-10-30 15:03:24 -06:00
Travis Nielsen b52ba6baca test: wait for mon daemons rather than mon canaries
The mon canaries may be created even when the mon daemons
are not created thereafter during the integration tests.
Therefore, the integration tests need to also query a label
specific to the mon daemon so the canaries are not a distraction
to the test.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-10-25 09:17:02 -06:00
Travis Nielsen 3b94c50d8b Merge pull request #14818 from iPraveenParihar/kms/vault-keyrotation
kms: key rotation support for vault kms
2024-10-24 11:38:33 -06:00
Blaine Gardner 7a4cf8d93c Merge pull request #14819 from BlaineEXE/holder-pods-remove-config
multus: finish deprecating holder pods
2024-10-24 10:55:02 -06:00
Blaine Gardner 5539eedd1b multus: finish deprecating holder pods
Finish the process of deprecating holder pods by removing Rook's ability
to deploy them. The intent of this change is to make the most
superficial changes possible to accomplish this. There are still
remnants of code in Rook (particularly the CSI controller) that helped
configure or deploy holder pods. Due to the risk of breaking some
features, cleanup work of hose remnants will be deferred for future
work.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-10-23 16:29:02 -06:00
Joshua Hoblitt f64027bf43 test: add obc bucketMaxObjects integration test
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-10-23 14:39:38 -07:00
Praveen M c9bc3a2685 ci: add test for vault key rotation
Signed-off-by: Praveen M <m.praveen@ibm.com>
2024-10-23 12:58:11 +05:30
Joshua Hoblitt 100c8bd7a9 test: require ceph tag param to replace_ceph_image
To prevent silent failures where the ceph image tag is not updated.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-10-18 12:08:57 -07:00
Travis Nielsen 95578a63ed Merge pull request #14793 from jhoblitt/feature/cephobjectzone-existing-pools
test: add two-object-one-zone canary test
2024-10-18 09:00:56 -06:00
Joshua Hoblitt edd65e5686 test: when collecting logs, describe instead of get CRs
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-10-14 16:54:39 -07:00
Joshua Hoblitt 16dd6257c2 test: when collecting logs, use get in secret filename
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-10-14 16:54:39 -07:00
Joshua Hoblitt 11250013a0 test: add two-object-one-zone canary test
This acceptance test demonstrates the creation of two CephObjectStore(s)
that share the same pool(s) manually managed by CephBlockPool(s).

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-10-14 16:54:39 -07:00
Travis Nielsen 7ed77ddd13 core: remove obsolete creation of v1beta1 pruner cron jobs
The v1beta1 cron jobs have been obsolete since K8s 1.21,
and Rook has not supported that version of K8s
for many moons, so we can remove the obsolete code
for the handling of v1beta1 cron jobs for crash pruning.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-10-14 17:13:06 -06:00
Joshua Hoblitt 92d9f994c2 test: improve reliability of canary rgw-multisite-testing
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-10-12 12:42:58 -07:00
subham rai 0c236b7406 Merge pull request #14800 from jhoblitt/maint/github-action-helper-less-lsblk
test: do not always run `sudo lsblk` in github-action-helper.sh
2024-10-07 15:27:07 +05:30
Joshua Hoblitt d301114680 test: do not always run sudo lsblk in github-action-helper.sh
This removes the execution of `sudo lsblk` three times for every single
invocation of the script.  Usage of the BLOCK var is replaced with
functions which memoize the result of probing for block devices.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-10-03 16:40:10 -07:00
Travis Nielsen e26d5f80ed Merge pull request #14795 from travisn/remove-quincy
core: Remove support for Ceph Quincy
2024-10-03 12:07:39 -06:00
Joshua Hoblitt 581fd5c197 test: convert all github-action-helper functs to $REPO_DIR
This allows all functions to be called in any order without concern for
the CWD.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-10-03 10:18:17 -07:00
Joshua Hoblitt 31d55b90fe test: mv canary test specific resources out of deploy_cluster()
Factor out most of the CRs used by various canary tests to a new
deploy_cluster_full_of_cruft_please_stop_using_this() function.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-10-03 10:18:17 -07:00
Joshua Hoblitt ed8156017e test: add object-with-cephblockpool canary test
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-10-03 10:16:30 -07:00
Joshua Hoblitt cb1dd152ad test: add github-action-helper toolbox functions
Added these functions for running commands in the toolbox pod:

- toolbox()
- ceph()
- rbd()
- radosgw-admin()

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-10-03 10:16:30 -07:00
Travis Nielsen b665d7a7b7 core: remove support for ceph quincy
Given that Ceph Quincy (v17) is past end of life,
remove Quincy from the supported Ceph versions,
examples, and documentation.

Supported versions now include only Reef and Squid.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-10-03 11:12:55 -06:00
Travis Nielsen 810de394e7 helm: add enforce host network setting
The ROOK_ENFORCE_HOST_NETWORK option was implemented recently
and now we add the helm setting to expose this new setting
in the rook chart.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-10-02 15:14:46 -06:00
Xinliang Liu 05ac99c0c0 ci: fix canary-arm64 job
Fix OSD isn't up.
As sdb device might change to vdb in the runner, let
find_extra_block_dev() exclude the nbd devices and find the proper
extra device for OSD.

Clean up the nbd devices after the test job is running.

Fix logs artifact upload twice and collect logs before clean up.

Signed-off-by: Xinliang Liu <xinliang.liu@linaro.org>
2024-10-01 12:05:32 -06:00
subhamkrai f647444515 ci: fix ci permission issue with minikube start
this commit upgrade the minikube, k8s, crictl versions
in CI and also fix permission error in the github runner.

Signed-off-by: subhamkrai <srai@redhat.com>
2024-09-19 15:55:18 +05:30