Commit Graph
14 Commits
Author SHA1 Message Date
Praveen M c9bc3a2685 ci: add test for vault key rotation
Signed-off-by: Praveen M <m.praveen@ibm.com>
2024-10-23 12:58:11 +05:30
subhamkrai 70f29be748 ci: fix ci test encryption-pvc-kms-vault-token-auth
we need to wait for the rgw pod to be delete and not
only the cephobjectsore, sometime the pod could be in
terminating state. Also, in some place it require proper
command to wait for pod to be ready/delete and get the
pod name only.

Signed-off-by: subhamkrai <srai@redhat.com>
2023-07-05 14:49:18 +05:30
subhamkrai cc65134d55 ci: create vault secret manually for k8s 1.24
The service account generated a secret that is required for
configuration automatically in Kubernetes 1.23. In Kubernetes
1.24+, you need to create the secret explicitly.

Signed-off-by: subhamkrai <srai@redhat.com>
2022-09-30 18:36:33 +05:30
Jiffin Tony Thottan 0b4cdb992b object: fix backend path for transit engine for rgw kms
The backend path was added with additional `transit` to it.
Also added PR test case to check transit engine

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2022-02-15 18:49:31 +05:30
Jiffin Tony Thottan aba50d3ca9 object: add support in RGW to communicate vault with TLS
From ceph v16.2.6 onwards the vault TLS suppport in RGW was added,
include similar changes for RGW.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2021-11-17 10:19:28 +05:30
Sébastien Han 0e26176b54 ci: wait for kubeproxy to be ready
When requesting issuer, we run a local kubectl proxy command which spawn
a proxy server. However, we must wait for the proxy to be ready before
we actually start making requests to it.
Now the CI waits up to 10sec to retrieve the issuer.

Closes: https://github.com/rook/rook/issues/9090
Signed-off-by: Sébastien Han <seb@redhat.com>
2021-11-08 17:45:53 +01:00
Sébastien Han 16729e0e38 osd: use multiple service account for vault role
We can pass bound_service_account_names with a comma separated list of
service accounts. Let's do this instead of remapping new values.
Earlier, we thought a single service account could be added per Vault
role and we were using other variables like
`VAULT_AUTH_KUBERNETES_ROOK_OPERATOR_ROLE` that we were remapping to
`VAULT_AUTH_KUBERNETES_ROLE` internal for the API calls to Vault.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-11-04 15:15:46 +01:00
Sébastien Han 18a4047679 osd: add support for k8s with vault kms
Rook cluster-wide encryption can now use the native Kubernetes
authentication to interact with vault KMS instead of using the token
method.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-10-21 13:59:28 +02:00
subhamkrai ebe21c8f68 ci: add action for shellcheck linter
we are adding new linter for shellcheck.
As we are writing more shell scripts this
will help maintain quality.

Also, doing all the changes required in
bash files to pass this shellcheck.

Closes: https://github.com/rook/rook/issues/8431
Signed-off-by: subhamkrai <srai@redhat.com>
2021-08-26 10:03:32 +05:30
parth-gr 33bf21ba69 ceph: update CSR from v1beta1 to v1
This commit update the certificates.k8s.io to use version v1
Updated to v1 as v1beta1 certificates.k8s.io is deprecated in v1.19+

Closes: https://github.com/rook/rook/issues/8308
Signed-off-by: parth-gr <paarora@redhat.com>
2021-08-12 20:27:05 +05:30
Sébastien Han 99e00dea1e ceph: auto detect vault k/v version
Rook will now auto detect the kv version of the vault server. This
allows users not having to pass the VAULT_BACKEND configuration in the
CephCluster CR.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-07-29 10:16:31 +02:00
Jiffin Tony Thottan 3cacd8db32 test: add seperate test for rgw vault integration
RGW supports only v2 version of kv engine, current integration test is written for kv v1,
hence seperating existing test into two.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2021-04-28 14:40:08 +05:30
Jiffin Tony Thottan 968b002a6f test: validation test for RGW vault authentication
Extending existing deploy-validate-vault.sh to include RGW as well

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2021-01-22 10:44:17 +05:30
Sébastien Han ea1d71cbfb ceph: add vault kms support for osd encryption
When the Ceph cluster runs on PVC and the OSDs are encrypted we can
store LUKS's Key Encryption Key inside a Key Management System. Today,
Rook only supports HashiCorp Vault: https://www.vaultproject.io/

The CephCluster has now a new "security" field which will plug onto the
KMS. Here is an example:

security:
  kms:
    tokenSecretName: <name of the secret containing a Vault token, used
    to authenticate>
    connectionDetails: < a map of strings containing connection
    information>

Refer to the ceph-cluster-crd documentation to lear more.

Closes: https://github.com/rook/rook/issues/6105
Signed-off-by: Sébastien Han <seb@redhat.com>
2020-10-30 16:16:33 +01:00