Commit Graph
449 Commits
Author SHA1 Message Date
subhamkrai 45e76204bf ci: wait for pod before exec into pod
keystone integration test has recentally starting to fail
as pod with lable osc-admin-admin was not in running status
and we're trying to exec into the pod.

Signed-off-by: subhamkrai <srai@redhat.com>
2025-02-20 12:25:07 +05:30
Joshua Hoblitt 9d21fe0f5c test: add obc bucketOwner integration test
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-02-04 12:10:20 -07:00
Joshua Hoblitt b689038ffc test: add obc bucketLifecycle integration test
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-01-21 16:01:37 -07:00
df511fb58f ci: update golangci-lint to the latest version (v1.62)
The ci was using a pretty old version og golangci-lint.
This updates to the latest version.

Additionally, it  silences some
gosec integer conversion overflow false positves
and fixes some real errors of this category
 and string format errors found by golangci-lint, while at it.

Co-authored-by: Blaine Gardner <b.blaine.gardner@gmail.com>
Co-authored-by: Travis Nielsen <tnielsen@redhat.com>
Signed-off-by: Michael Adam <obnox@samba.org>
2024-12-14 14:47:30 +01:00
Joshua Hoblitt 8fd34e88bb test: add obc bucketPolicy integration test
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-12-12 13:36:26 -07:00
Joshua Hoblitt 57b7eeec80 object: add httpClient param to object.NewS3Agent()
To allow the caller to pass in their own transport when testing.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-12-12 10:20:41 -07:00
Travis Nielsen 23f3db1261 ci: suppress the error from creating the dashboard admin user
The dashboard admin rgw user has timing isssues in the CI.
For now, just suppress the CI failure and log the error
until we can spend more time to get a reliable wait for the
user creation.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-12-11 09:42:59 -07:00
Blaine Gardner e6db006501 Merge pull request #15035 from BlaineEXE/object-revert-cosi-user-autocreation
Revert "object: create cosi user for each object store"
2024-12-09 16:21:58 -07:00
Travis Nielsen 506407b5ea tests: upgrade from rook 1.15 to master
The upgrade tests in master have been upgrading from 1.14 to
master. In anticipation of the v1.16 release, we change
the upgrade tests to start from v1.15 to test if there
are any regressions in the supported upgrades.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-11-22 10:40:02 -07:00
Blaine Gardner fc08e87d44 Revert "object: create cosi user for each object store"
This reverts commit a941b3c33f.

Stop creating the 'cosi' user in the CephObjectStore reconcile. This
step often fails for some amount of time during initial object store
creation, causing frequent user concern. It has also been the source of
some reported failures that would otherwise be non-breaking for certain
users.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-11-21 16:03:32 -07:00
Travis Nielsen f60f4443df test: remove obsolete object user test flag
In Rook v1.6 some new properties were added for
ceph object store users, so the CI was skipping
validation of that setting in the upgrade test.
Now we are far past the need for that flag, and we
can assume the latest flags exist for the tests.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-10-30 15:03:24 -06:00
Joshua Hoblitt f64027bf43 test: add obc bucketMaxObjects integration test
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-10-23 14:39:38 -07:00
Travis Nielsen b665d7a7b7 core: remove support for ceph quincy
Given that Ceph Quincy (v17) is past end of life,
remove Quincy from the supported Ceph versions,
examples, and documentation.

Supported versions now include only Reef and Squid.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-10-03 11:12:55 -06:00
Travis Nielsen 8b60c52f31 build: generate the local build tag with docker io
The docker.io image prefix is expected to be prepended
to the image names in the test images. This was missed
in 14550 related to some CI tests, which was now causing
the CI failures in the 1.15 branch where the search and
replace was missing the new docker.io prefix.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
(cherry picked from commit 3045076db8)
2024-08-21 10:21:31 -06:00
Zuhair AlSader 6714b86d3b manifest: add registry name to docker images
Signed-off-by: Zuhair AlSader <zuhair@devzero.io>
2024-08-20 13:35:08 -04:00
ee8bcad49d rgw: add support for keystone auth + swift/s3
For the specification see:
<https://github.com/rook/rook/blob/master/design/ceph/object/swift-and-keystone-integration.md>

* extend the API object specs for swift and keystone integration

* adapt rgw to the new go-ceph version

  - The parameter lists of the API call have changes, as parameters
    ignored by the RGW Admin Ops API are no longer serialized, therefore
    the mock has to be adapted.

  - There is now validation for the user keys that are passed to the
    User get API, therefore things failed when we had empty keys in our
    User proxy object.

* expand the reconcile loop for the swift and keystone integration

* fix minor mistakes in design document

* add env var to pass extra args to minikube

  Minikube decides CPU cores and memory automatically based on the
  available resources on the machine which may be insufficient to
  run rook. This commit adds an environment variable to add arbitrary
  arguments to the minikube command, so both can be specified if
  desired.

* integration tests for swift and keystone

  The new integration of swift or s3 and keystone support by rook
  does not have any integration tests yet.

  This commit introduces integration tests for swift and keystone. The
  tests are done against a minimal keystone setup (keystone container
  image from Yaook-project (https://yaook.cloud), sqlite as database
  backend, cert-manager and trust-manager for test certificate setup).

  To prevent hardcoded credentials, passwords are generated
  by the tests. The integration tests use the openstack client
  (keystone- and swift-functionality) (https://docs.openstack.org/
  python-openstackclient/ latest/). This was a concious design decision
  to use client tooling as close as possible to the end user instead of
  using other go-libraries (such as gophercloud).

* add documentation on swift and keystone

  Currently there is no documentation on the use of Swift to access
  an object store as well as the use of OpenStack keystone for
  authentication.

  This commit adds documentation on the use of Swift and OpenStack
  keystone, as well as CRD-related documentation and an example setup.

* add integration tests for S3 via keystone

  This commit introduces integration tests for s3 and keystone. The
  tests are run against the same minimal keystone setup that the tests
  for swift and keystone use.

  The integration tests use the aws s3 client to use client tooling as
  close as possible to the end user instead of using other go-libraries.

Co-authored-by: Jan Klippel <jan.klippel@uhurutec.com>
Co-authored-by: Silvio Ankermann <silvio.ankermann@cloudandheat.com>
Signed-off-by: Sebastian Riese <sebastian.riese@cloudandheat.com>
Signed-off-by: Jan Klippel <jan.klippel@uhurutec.com>
Signed-off-by: Silvio Ankermann <silvio.ankermann@cloudandheat.com>
2024-08-08 14:26:21 +02:00
Travis Nielsen 4cf349836f tests: check for correct base rook version during upgrade
The daily upgrade tests were checking for a specific
version of the rook image instead of the local_build tag
that is set as the rook base image since 14486.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-07-25 12:44:30 -06:00
Travis Nielsen 099c603a43 tests: upgrade from rook 1.14 to master
The upgrade tests in master have been upgrading from 1.13 to
master. In anticipation of the v1.15 release, we change
the upgrade tests to start from v1.14 to test if there
are any regressions in the supported upgrades.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-07-24 08:12:31 -06:00
Travis Nielsen 1d8d55e1ad tests: daily ceph upgrade tests on rook master
The daily ceph upgrade tests were running on Rook v1.13.
This was causing the squid upgrade tests to fail since
1.13 does not support Squid. The purpose of the upgrade
tests is to test the ceph upgrades, therefore the daily
tests will just test them based on rook master.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-07-23 16:19:19 -06:00
Travis Nielsen 22d4139b74 core: add support for ceph squid
With the release of the first squid RC, we add squid
to the supported versions and add tests to run
Rook against the squid release.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-07-15 10:04:32 -06:00
Travis Nielsen 2e8468a47c core: upgrade test from 1.13 to master
The upgrade test should always upgrade from the
previous minor release to the latest master. With 1.14
releasing soon, now we upgrade from 1.13 to master,
to confirm if there are any upgrade issues to 1.14.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-03-07 16:31:09 -07:00
subhamkrai 28cc1ebc55 core: remove webhook & controller-runtime from apis
This commits removes controller-runtime dependencies
from the apis dir and to achieve that we are removing
webhook.

Signed-off-by: subhamkrai <srai@redhat.com>
2023-12-01 14:15:40 +05:30
travisn 6c16c0eb83 tests: upgrade from 1.12 to master
The upgrade test should always upgrade from the previous
minor release to the latest master. With 1.13 releasing
soon, now we uprade from 1.12 to master, to confirm
if there are any upgrade issues to 1.13.

Signed-off-by: travisn <tnielsen@redhat.com>
2023-11-15 16:11:14 -07:00
travisn 03d077aa6b core: remove support for ceph pacific
Pacific is end of life and no longer necessary to
support in Rook with v1.13.

Signed-off-by: travisn <tnielsen@redhat.com>
2023-11-14 17:07:03 -07:00
parth-gr 46c241433d object: improve the error handling for multisite objs
here is the https://go.dev/play/p/SS9Q-dAiIx3 example which says the
error handling was wrongly implemented

Signed-off-by: parth-gr <paarora@redhat.com>
2023-11-14 15:12:15 +05:30
parth-gr 40295a989c ci: fix objectsuite flakiness
objectstore deletion was failing with not found error,
Could Not get resource in k8s -- Failed to run:
kubectl [get -n object-ns CephObjectStore
other-tls-test-store -o json]
So added a check if it not found then donot check its
further condition

Signed-off-by: parth-gr <paarora@redhat.com>
2023-11-08 15:33:03 +05:30
Jiffin Tony Thottan a941b3c33f object: create cosi user for each object store
Create each cosi user for each object store and secret which holds
credentials.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2023-09-19 13:48:58 +05:30
travisn 0bd7d4ac84 tests: use same ceph version for toolbox in multicluster
The multicluster test was using a different ceph image for the
toolbox than from the original cluster. For efficiency of
pulling images in the test, the toolbox of the external cluster
will now use the same ceph image as the internal cluster.

Signed-off-by: travisn <tnielsen@redhat.com>
2023-08-16 15:50:57 -06:00
parth-gr 715bd31a0a ci: fix testobjectsuite ci
Current reason for failure
clients: "cephbuckettopic" "my-topic" exist, but ARN was not set

Added some more re-try as it might take some more time to
update the ARN in status

OBC bound status was failing and going into
race condition adding a seprate timeout
makes recover it from that state

Signed-off-by: parth-gr <paarora@redhat.com>
2023-08-08 23:46:02 +05:30
Jiffin Tony Thottan b48dc8a335 object: intial cosi driver controller design
Adding CephCOSIDriver CRD and controller. The controller will bring up
the ceph cosi driver when first object store is created in the rook
operator namespace. Then admin can defined COSI CRDs like BucketClass
and BucketAccessClass for different object stores deployed via Rook.
Using the BucketClass and BucketAccessClass, user can define
BucketAccess for backend bucket in the RGW. The CephCOSIDriver CRD
defines configuration options for ceph cosi driver. In the first version
its usability is minimal. Even if it is not defined Rook will bring up
the ceph cosi driver with default values.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2023-07-18 22:49:41 +05:30
Javier 46cb9435a6 test: support Ceph Reef v18 with updated integration tests
update test files to support the next version of ceph, ceph reef v18

Signed-off-by: Javier <sjavierlopez@gmail.com>
2023-07-10 15:24:36 -06:00
travisn 557a3e06cc core: api updates for controller runtime v0.15
For the controller runtime v0.15 there are some breaking
changes to the api that need to be updated.

Signed-off-by: travisn <tnielsen@redhat.com>
2023-06-22 10:33:28 -06:00
Sheetal Pamecha a6d57c164d test: upgrade tests to update from v1.11
With the upcoming v1.12 release, Rook upgrade tests
should upgrade from v1.11.x to master instead of
from v1.10.x to master.

Signed-off-by: Sheetal Pamecha <spamecha@redhat.com>
2023-06-13 03:48:45 +05:30
travisn 0484a3973f csi: update port to 3300 if msgr2 is required
When msgr2 is required, ensure the mon endpoints passed to
the csi configmap are on port 3300. The mons will be
listening on both 6789 and 3300. Existing volumes can
continue using port 6789 while new volumes will use
port 3300.

Signed-off-by: travisn <tnielsen@redhat.com>
2023-03-10 10:34:56 -07:00
parth-grandBlaine Gardner 69ae9569cd build: update k8s version to 1.26.1
Update the Kubernetes API version used to 1.26.1, and start testing
against Kubernetes version 1.26.1 in CI.

Co-authored-by: parth-gr <paarora@redhat.com>
Co-authored-by: Blaine Gardner <blaine.gardner@redhat.com>

Signed-off-by: parth-gr <paarora@redhat.com>
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2023-02-23 20:18:47 -07:00
parth-gr a84daf9bf0 core: change io/ioutil package to use io and os package
few functions got change as they were deprecated
for ex: ioutil.Readfile change to os.Readfile
ioutil.TempFile change to os.CreateTemp
And fixed golang-ci-lint-issues

Signed-off-by: parth-gr <paarora@redhat.com>
2023-02-17 20:38:29 +05:30
Travis Nielsen a4f71baf8a core: option to require msgrv2 even without encryption
Enabling msgr v2 and disabling msgr v1 currently requires enabling
either encryption on the wire or compression on the wire.
As more clients are running on the latest kernel, allow
the clients to run on v2 even when encryption and compression
are not enabled. Clusters that are fully running on v2
will more easily be able to change configuration between
enabling or disabling msgr v2 features.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2023-02-10 09:45:57 -07:00
Travis Nielsen 230e635611 test: upgrade tests to update from v1.10
With the v1.11 release approaching, the upgrade tests in
master are not updated to upgrade starting from v1.10
instead of from v1.9.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2023-02-06 16:50:07 -07:00
Blaine Gardner a777b1d7d1 object: do not create service for external object stores
External CephObjectStores already have endpoints defined by
spec.gateway.externalRgwEndpoints, and if the external store is
configured with TLS (HTTPS), the store's certificates will likely not
accept connections intended for the Service endpoint Rook creates. Some
users might not be able to easily add the service endpoint to their
certificates. Therefore, don't even bother creating a Service for
external clusters.

This does introduce a few issues. The Service seems to have been
initially created to allow multiple external RGW endpoints to be
addressable via a single address in Rook. For all connections to an
external CephObjectStore with multiple endpoints, simply choose an
endpoint at random. Random selection will prevent Rook from failing to
create buckets or users on an external store if one of the external
store's endpoints fails.

The latest OBC library (lib-bucket-provisioner) allows updating the
endpoints on ObjectBuckets after they are created. This allows Rook
users to change endpoints on external CephObjectStores without breaking
all existing OBCs. It requires implementation of the new GetUserID()
library call, requires updating Provision() and Grant() calls to be
idempotent, and it requires removing the Update() call.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2022-11-04 17:30:30 -06:00
Blaine Gardner 0937eaee38 Merge pull request #11124 from BlaineEXE/object-revise-health-check
object: remove health checker
2022-10-24 11:31:23 -06:00
Blaine Gardner a7c0c7ee93 object: remove health checker
Remove the health checker for CephObjectStore. The liveness and
readiness probes go through the same code paths in RGW as creating
buckets without as much affect on the storage backend.

Full discussion: https://github.com/rook/rook/issues/11031

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2022-10-18 13:41:46 -06:00
Rakshith R 914e01e77d ci: add nfs clone e2e testcase
Signed-off-by: Rakshith R <rar@redhat.com>
2022-10-18 15:07:01 +05:30
Rakshith R db56ba22d2 ci: add nfs snap & restore e2e testcases
Signed-off-by: Rakshith R <rar@redhat.com>
2022-10-18 15:06:58 +05:30
Rakshith R be10dac98c ci: enable and fixes for nfs ci
This commit anabled nfs csi ci and
add fixes/improvements to it like the
following:
- verify deletion of cephnfs and .nfs pool before proceeding
- verify pv deletion
- do not enable rook module
- reduce activeCount to 1 to save resources
- run cephnfs ci before cephfs ci since it cephfs
  ci is more resource intensive.

Signed-off-by: Rakshith R <rar@redhat.com>
2022-10-06 11:53:46 +00:00
Travis Nielsen 25ee33f029 ci: ceph master images renamed to main
The ceph master images were recently renamed to main
so we need to pick up the new tag.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-10-05 16:46:04 -06:00
Liang Zheng f9c360e609 osd: optimize device probe
1. Eliminate possible memory leaks of timer.
2. Eliminate duplicated events between udev events and kernel events.
3. Empty struct have the lowest size.

Signed-off-by: Liang Zheng <zhengliang0901@gmail.com>
2022-09-20 10:41:51 +08:00
Travis Nielsen a6dfb77827 build: update min version to k8s 1.19
Rook will support the most recent seven K8s releases,
so we update the min version to 1.19 for Rook v1.10.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-08-30 15:15:20 -06:00
Travis Nielsen 3696a560d8 build: test upgrade from 1.9 to master
With the pending release of 1.10, the upgrade tests
in master should be testing the upgrade from 1.9
to the master branch.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-08-26 10:04:37 -06:00
Blaine Gardner b98efbb320 nfs: add support for running SSSD as a sidecar
Implement the SSSD sidecar design for NFS.

Because NFS documents are getting long, create an NFS
`Storage-Configuration` section with separated topics to keep the `NFS
Overview` document sane.

Adjust the SSSD design to allow any VolumeSource, not just ConfigMaps.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2022-08-11 14:59:23 -06:00
Travis Nielsen a596471757 test: pass test suite by value
The latest go modules come with a sync mutex that requires
us to pass the test suite by reference for proper use
of the mutex.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-08-11 12:31:49 -06:00