Update docs for the upcoming v1.13 release.
Ensure that the pending release doc has critical notes.
Ensure upgrade guide versions are updated and tested.
Clarify some minor documentation points regarding features present in pending release doc.
Special care has been taken to update notes and docs for removal of the admission controller, which may be confusing for the estimated-small number of acive users.
Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
This commit updates default cephcsi driver version
to v3.10.0 and filesystem reconciler now creates
csi subvolumegroup by default.
Signed-off-by: Rakshith R <rar@redhat.com>
This implements the "Ceph Config via Ceph Cluster CRD" design document
as a `cephConfig:` structure on the CRD.
This also fixes the `yq` commands used to manipulate the
`cluster-test.yaml` that caused CI issues for this PR and potentially
unknowingly others.
Signed-off-by: Alexander Trost <galexrt@googlemail.com>
This commits removes controller-runtime dependencies
from the apis dir and to achieve that we are removing
webhook.
Signed-off-by: subhamkrai <srai@redhat.com>
Adding CephCOSIDriver CRD and controller. The controller will bring up
the ceph cosi driver when first object store is created in the rook
operator namespace. Then admin can defined COSI CRDs like BucketClass
and BucketAccessClass for different object stores deployed via Rook.
Using the BucketClass and BucketAccessClass, user can define
BucketAccess for backend bucket in the RGW. The CephCOSIDriver CRD
defines configuration options for ceph cosi driver. In the first version
its usability is minimal. Even if it is not defined Rook will bring up
the ceph cosi driver with default values.
Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
in the existing node watcher, we'll check for node update
event and see if there are `out-of-service` taints are applied
and `ROOK_WATCH_FOR_NODE_FAILURE` is enabled in rook-ceph-operator-configmap,
if then we'll create the networkFence cr and delete the cr if nodes come back.
And, added the unit test too.
Signed-off-by: subhamkrai <srai@redhat.com>
For the feature work that will happen in the v1.12
timeframe, we reset the pending release notes in
the master branch.
Signed-off-by: travisn <tnielsen@redhat.com>
The PSPs have long since been deprected. In K8s 1.21 the PSPs
were first deprecated, and support was completely removed
for them in 1.25. With Rook v1.11, the min supported version of
K8s is now 1.21. To reduce confusion in the documentation,
mention of the PSPs is now removed from the 1.11 docs.
For the corner case that users still require the PSPs,
the helm chart still contains the option for creating PSPs
or other users can still create the psp.yaml.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
Enabling msgr v2 and disabling msgr v1 currently requires enabling
either encryption on the wire or compression on the wire.
As more clients are running on the latest kernel, allow
the clients to run on v2 even when encryption and compression
are not enabled. Clusters that are fully running on v2
will more easily be able to change configuration between
enabling or disabling msgr v2 features.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
Bucket notifications and topics have been implemented since
v1.8 and have been stable. Therefore, with v1.11 we move
the feature to stable.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
The machine disruption budgets for handling openshift
machines and machinesets are now removed since they
have been unused and unmaintained since implemented.
This feature is expected to be handled with the more
common Pod Disruption Budgets. A workaround is for the
cluster admin to set up their machine sets so they
match the zone topology. See the original design
doc from the feature here:
https://github.com/rook/rook/blob/master/design/ceph/ceph-openshift-fencing-mitigation.md
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
User can define his desired endpoint list in Zone CR so that it will
overwrite the default service name for rgw.
Resolves#6432
Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
Signed-off-by: Jiffin Tony Thottan <jthottan@redhat.com>
CephFS CSI driver dont have/advertise controller publish/unpublish
capabilities, thus dont need attacher sidecar for its operations.
The presence of external-attacher adds on overhead and issues wrt
attachment in various scenarios. One of them would be the lack of
performance on syncing volumeattachment from api server..etc.
More or less we don't have controller publish and unpublish capabilities,
so we should not make use of this sidecar and cause
unnecessary addon here thus other issues.
similar changes have been added to CSI
https://github.com/ceph/ceph-csi/pull/3149
Signed-off-by: yati1998 <ypadia@redhat.com>
The RGW support server side encryption with help of s3 protocol, till
now the `sse:kms` was support in which keys will be provided by the user
and but it will be saved in external management service like vault. Now
the support for `sse:s3` is added so the entire encryption key
management is performed by RGW itsels.
Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
With octopus coming to end of life, we remove support from
Rook for deploying Ceph Octopus and assume a min version of
Pacific v16. Any checks for octopus or earlier are removed
from the reconciles since they are obsolete.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
The toolbox is really only used for ceph commands. The main reason
the rook image was being used in the toolbox pod was for the script
that generates the ceph.conf and updates it whenever the mons are
updated during mon failover.
Now the ceph image can be specified directly by moving the script
inline with the container definition instead of being required
in the image.
The rook image will still contain the script for backward compatibility
and for scenarios where the rook binary may still be needed
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
The cross build container is not used anymore since the conversion
to github actions. Now the obsolete scripts and makefiles are
cleaned up to remove some confusing leftovers from the
cross container.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
Update upgrade and supporting docs for release of Rook v1.9.
Include pending release notes as part of this update.
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
This introduces a new CRD to add the ability
to create rados namespace for a given
ceph block pool. Typically the name of the pool
is the name of the blockpool created by rook.
Closes: #7035
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
For supporting features like service account authentication for vault
KMS , a service account account need to attach with pod.
Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
The aws go lang sdk needs value for region, it is set differently in
various part of current code. With PR the value is always `us-east-1` so
that it will work RGW server without any issues.
This reverts commit 280c29f330.
Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
The prometheus rules had been previously created if the cephcluster CR
setting monitoring.enabled was set to true. The rules were not customizable
and therefore not flexible enough. Now the rules are installed by the helm
chart. To customize the rules, a post-processor can be applied to the helm
chart.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
msgr2 allows for encryption and/or compression across the wire.
Settings for enabling the encryption and compression are now
available in the cluster CR to that ceph will be automatically
configured with these settings when desired.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
To ensure the mgr is not the single point of failure, the mgr
daemon count is now set to 2 by default in the cluster examples.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
Currently, the admin/user can configure the ceph.conf
for daemon pods using https://rook.io/docs/rook/v1.7/
ceph-advanced-configuration.html#custom-cephconf-settings.
This the above custom ceph.conf is only for ceph pods.
the support to provide constom ceph.conf for cephcsi
is added in cephcsi PR 2476
This PR adds the support to create/update
ceph.conf for csi pods.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
Added unit test for probes changes and
did re-naming of liveness probes file
as it will contain multiple types of probes
Signed-off-by: parth-gr <paarora@redhat.com>
The failure domain is baked into the crush rule that is
created for a pool. To allow for an updated failure domain
on the pool, create a new crush rule specific for that
failure domain and update the pool with the new rule.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
The toolbox can now interact with S3 gateways using the `s5cmd` tool.
The binary is only 12M so this does not add up too much to the operator
image size.
Closes: https://github.com/rook/rook/issues/4968
Signed-off-by: Sébastien Han <seb@redhat.com>
The rook operator as well as the toolbox pod run with the "rook" user
with UID 2016. The UID was chosen based on the year of the initial
commit in the rook/rook repository.
No more root user running.
Closes: https://github.com/rook/rook/issues/8734
Signed-off-by: Sébastien Han <seb@redhat.com>
Rook cluster-wide encryption can now use the native Kubernetes
authentication to interact with vault KMS instead of using the token
method.
Signed-off-by: Sébastien Han <seb@redhat.com>
Adding finalizers to rook-ceph-mon secrets
and rook-ceph-mon-endpoints configmap
We don't want to delete this resources during disaster
because these details are needed during disaster recovery
Closes: https://github.com/rook/rook/issues/8369
Signed-off-by: parth-gr <paarora@redhat.com>
We don't need to use tini.
We don't have anything in the rook operator that would
either create zombie processes (no threads) or use
exec (to fork). The Go binary has a really good
signal handling mechanism.
Closes: https://github.com/rook/rook/issues/8794
Signed-off-by: Sébastien Han <seb@redhat.com>