Commit Graph
353 Commits
Author SHA1 Message Date
travisn 3863ed27e1 docs: clear the pending release notes for 1.14
Since the v1.13.0 release is out, clear the pending
release notes to make way for the v1.14 features.

Signed-off-by: travisn <tnielsen@redhat.com>
2023-12-13 14:51:10 -07:00
Blaine Gardner 06d18a7122 docs: update upgrade docs for v1.13 release
Update docs for the upcoming v1.13 release.

Ensure that the pending release doc has critical notes.

Ensure upgrade guide versions are updated and tested.

Clarify some minor documentation points regarding features present in pending release doc.

Special care has been taken to update notes and docs for removal of the admission controller, which may be confusing for the estimated-small number of acive users.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2023-12-08 14:12:20 -07:00
Rakshith R a3220d827d csi: update default cephcsi version to 3.10.0
This commit updates default cephcsi driver version
to v3.10.0 and filesystem reconciler now creates
csi subvolumegroup by default.

Signed-off-by: Rakshith R <rar@redhat.com>
2023-12-06 19:57:40 +05:30
Alexander Trost 3097455d78 Merge pull request #13246 from koor-tech/ceph_config_via_cluster_crd_impl
operator: allow setting ceph config options via ceph cluster crd
2023-12-02 11:27:20 +01:00
Alexander Trost 4ed35d6bd6 operator: allow setting ceph config options via ceph cluster crd
This implements the "Ceph Config via Ceph Cluster CRD" design document
as a `cephConfig:` structure on the CRD.
This also fixes the `yq` commands used to manipulate the
`cluster-test.yaml` that caused CI issues for this PR and potentially
unknowingly others.

Signed-off-by: Alexander Trost <galexrt@googlemail.com>
2023-12-02 00:05:48 +01:00
subhamkrai 28cc1ebc55 core: remove webhook & controller-runtime from apis
This commits removes controller-runtime dependencies
from the apis dir and to achieve that we are removing
webhook.

Signed-off-by: subhamkrai <srai@redhat.com>
2023-12-01 14:15:40 +05:30
travisn 03d077aa6b core: remove support for ceph pacific
Pacific is end of life and no longer necessary to
support in Rook with v1.13.

Signed-off-by: travisn <tnielsen@redhat.com>
2023-11-14 17:07:03 -07:00
travisn 673fb8a46e docs: reset the pending release notes for v1.13
The 1.13 pending release notes are now reset.

Signed-off-by: travisn <tnielsen@redhat.com>
2023-08-01 15:44:08 -06:00
Jiffin Tony Thottan b48dc8a335 object: intial cosi driver controller design
Adding CephCOSIDriver CRD and controller. The controller will bring up
the ceph cosi driver when first object store is created in the rook
operator namespace. Then admin can defined COSI CRDs like BucketClass
and BucketAccessClass for different object stores deployed via Rook.
Using the BucketClass and BucketAccessClass, user can define
BucketAccess for backend bucket in the RGW. The CephCOSIDriver CRD
defines configuration options for ceph cosi driver. In the first version
its usability is minimal. Even if it is not defined Rook will bring up
the ceph cosi driver with default values.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2023-07-18 22:49:41 +05:30
subhamkrai 39b5c057ce core: faster recovery from rbd rwo node loss
in the existing node watcher, we'll check for node update
event and see if there are `out-of-service` taints are applied
and `ROOK_WATCH_FOR_NODE_FAILURE` is enabled in rook-ceph-operator-configmap,
if then we'll create the networkFence cr and delete the cr if nodes come back.
And, added the unit test too.

Signed-off-by: subhamkrai <srai@redhat.com>
2023-07-07 21:16:25 +05:30
travisn a4bc1b5300 docs: reset the pending release notes for v1.12
For the feature work that will happen in the v1.12
timeframe, we reset the pending release notes in
the master branch.

Signed-off-by: travisn <tnielsen@redhat.com>
2023-03-07 15:30:32 -07:00
sp98 7292ac5927 core: export mon and OSD services
Signed-off-by: sp98 <sapillai@redhat.com>
2023-02-27 21:36:59 +05:30
parth-gr 2346dd382f docs: update k8s version to 1.26.1 in release notes
Signed-off-by: parth-gr <paarora@redhat.com>
2023-02-27 12:44:31 +05:30
parth-gr b81ee215a7 build: update golang version to v1.19
Updated the go mod and ci to use gov1.19 as
minimum and removed support for go1.18

Closes: https://github.com/rook/rook/issues/11681
Signed-off-by: parth-gr <paarora@redhat.com>
2023-02-17 18:39:05 +05:30
Rakshith R f8c7a62c3b docs: add documentation about rbd read affinity
This commit documents steps to enable read affinity
for rbd volumes.

Signed-off-by: Rakshith R <rar@redhat.com>
2023-02-16 19:10:10 +05:30
Travis Nielsen 3dabc6dcb6 Merge pull request #11317 from avanthakkar/introduce-ceph-exporter
core: introduce ceph-exporter
2023-02-15 11:59:05 -07:00
Avan Thakkar 460900756c core: add service monitor for ceph-exporter service
Signed-off-by: Avan Thakkar <athakkar@redhat.com>
2023-02-15 15:44:56 +05:30
Travis Nielsen eb4a727658 docs: remove mention of psps from documentation
The PSPs have long since been deprected. In K8s 1.21 the PSPs
were first deprecated, and support was completely removed
for them in 1.25. With Rook v1.11, the min supported version of
K8s is now 1.21. To reduce confusion in the documentation,
mention of the PSPs is now removed from the 1.11 docs.
For the corner case that users still require the PSPs,
the helm chart still contains the option for creating PSPs
or other users can still create the psp.yaml.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2023-02-13 13:30:32 -07:00
Travis Nielsen a4f71baf8a core: option to require msgrv2 even without encryption
Enabling msgr v2 and disabling msgr v1 currently requires enabling
either encryption on the wire or compression on the wire.
As more clients are running on the latest kernel, allow
the clients to run on v2 even when encryption and compression
are not enabled. Clusters that are fully running on v2
will more easily be able to change configuration between
enabling or disabling msgr v2 features.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2023-02-10 09:45:57 -07:00
Travis Nielsen 7c9ef07659 object: move bucket notifications to stable
Bucket notifications and topics have been implemented since
v1.8 and have been stable. Therefore, with v1.11 we move
the feature to stable.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2023-01-04 10:30:14 -07:00
Travis Nielsen 25ac236b5c core: remove support for machine disruption budgets
The machine disruption budgets for handling openshift
machines and machinesets are now removed since they
have been unused and unmaintained since implemented.
This feature is expected to be handled with the more
common Pod Disruption Budgets. A workaround is for the
cluster admin to set up their machine sets so they
match the zone topology. See the original design
doc from the feature here:
https://github.com/rook/rook/blob/master/design/ceph/ceph-openshift-fencing-mitigation.md

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-12-16 11:15:12 -07:00
Zuhair AlSader 1454d5a7a6 security: change pspEnable default value to false
Disable PodSecurityPolicy in Ceph Operator helm charts by default.

Signed-off-by: Zuhair AlSader <zalsader@hotmail.com>
2022-11-07 21:40:07 +00:00
Travis Nielsen 7548c18f50 docs: reset pending release notes for 4.11
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-09-06 09:05:46 -06:00
Jiffin Tony Thottan 8003e764f9 rgw: add custom endpoint list option for zone
User can define his desired endpoint list in Zone CR so that it will
overwrite the default service name for rgw.

Resolves #6432

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
Signed-off-by: Jiffin Tony Thottan <jthottan@redhat.com>
2022-08-17 10:03:12 +05:30
Mudit Agarwal 40081cbcd2 Revert "csi: remove attacher sidecar from CephFS rook deployment"
This reverts commit 4bfd88dc4d.

Signed-off-by: Mudit Agarwal <muagarwa@redhat.com>
2022-08-10 13:04:14 +05:30
yati1998 4bfd88dc4d csi: remove attacher sidecar from CephFS rook deployment
CephFS CSI driver dont have/advertise controller publish/unpublish
capabilities, thus dont need attacher sidecar for its operations.
The presence of external-attacher adds on overhead and issues wrt
attachment in various scenarios. One of them would be the lack of
performance on syncing volumeattachment from api server..etc.
More or less we don't have controller publish and unpublish capabilities,
so we should not make use of this sidecar and cause
unnecessary addon here thus other issues.

similar changes have been added to CSI
https://github.com/ceph/ceph-csi/pull/3149

Signed-off-by: yati1998 <ypadia@redhat.com>
2022-08-03 19:56:39 +05:30
Jiffin Tony Thottan 5c8ca01bd0 object: adding support for sse s3 for RGW
The RGW support server side encryption with help of s3 protocol, till
now the `sse:kms` was support in which keys will be provided by the user
and but it will be saved in external management service like vault. Now
the support for `sse:s3` is added so the entire encryption key
management is performed by RGW itsels.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2022-07-28 11:50:48 +05:30
Travis Nielsen dad97f3425 core: remove support for ceph octopus
With octopus coming to end of life, we remove support from
Rook for deploying Ceph Octopus and assume a min version of
Pacific v16. Any checks for octopus or earlier are removed
from the reconciles since they are obsolete.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-07-07 15:03:26 -06:00
Travis Nielsen febce342b7 manifest: inline toolbox script for direct use of ceph image
The toolbox is really only used for ceph commands. The main reason
the rook image was being used in the toolbox pod was for the script
that generates the ceph.conf and updates it whenever the mons are
updated during mon failover.

Now the ceph image can be specified directly by moving the script
inline with the container definition instead of being required
in the image.

The rook image will still contain the script for backward compatibility
and for scenarios where the rook binary may still be needed

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-06-28 17:19:22 -06:00
Travis Nielsen 518901305a docs: reset the release notes for 1.10
With the 1.9 release out we go ahead and clear the
release notes for 1.10 feature work.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-04-26 11:18:35 -06:00
Travis Nielsen 738a300827 build: remove obsolete cross build container
The cross build container is not used anymore since the conversion
to github actions. Now the obsolete scripts and makefiles are
cleaned up to remove some confusing leftovers from the
cross container.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-04-07 13:42:18 -06:00
Blaine Gardner 8d619501fe docs: update docs for 1.9 release
Update upgrade and supporting docs for release of Rook v1.9.
Include pending release notes as part of this update.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2022-04-06 09:06:26 -06:00
Madhu Rajanna b0fc7c9b92 namespace: add new CRD
This introduces a new CRD to add the ability
to create rados namespace for a given
ceph block pool. Typically the name of the pool
is the name of the blockpool created by rook.

Closes: #7035

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2022-04-05 10:10:04 +05:30
Jiffin Tony Thottan 5e72b26948 object: add service account for RGW pod
For supporting features like service account authentication for vault
KMS , a service account account need to attach with pod.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2022-04-04 11:24:50 +05:30
Jiffin Tony Thottan fc2b8012c6 object: use us-east-1 for aws go lang sdk
The aws go lang sdk needs value for region, it is set differently in
various part of current code. With PR the value is always `us-east-1` so
that it will work RGW server without any issues.

This reverts commit 280c29f330.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2022-03-24 14:37:39 +05:30
Travis Nielsen 4edcff04f7 monitoring: create prometheus rules with helm chart
The prometheus rules had been previously created if the cephcluster CR
setting monitoring.enabled was set to true. The rules were not customizable
and therefore not flexible enough. Now the rules are installed by the helm
chart. To customize the rules, a post-processor can be applied to the helm
chart.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-03-21 14:47:52 -06:00
Yuval Manor ff7a5c2d2d helm: enable resource defaults on rook components
This PR assign default values to the resources of all Rook and Ceph components

Closes: https://github.com/rook/rook/issues/9858
Signed-off-by: Yuval Manor <yuvalman958@gmail.com>
2022-03-21 21:23:35 +02:00
Travis Nielsen 03c7164b15 mon: options for enabling msgr2 encryption and compression
msgr2 allows for encryption and/or compression across the wire.
Settings for enabling the encryption and compression are now
available in the cluster CR to that ceph will be automatically
configured with these settings when desired.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-03-10 11:50:42 -07:00
Travis Nielsen bc9914e99d mgr: set the default count of mgr daemons to 2
To ensure the mgr is not the single point of failure, the mgr
daemon count is now set to 2 by default in the cluster examples.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-03-02 13:35:05 -07:00
Madhu Rajanna 2076a3c788 csi: add custom ceph.conf for csi pods
Currently, the admin/user can configure the ceph.conf
for daemon pods using https://rook.io/docs/rook/v1.7/
ceph-advanced-configuration.html#custom-cephconf-settings.
This the above custom ceph.conf is only for ceph pods.
the support to provide constom ceph.conf for cephcsi
is added in cephcsi PR 2476

This PR adds the support to create/update
ceph.conf for csi pods.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2022-03-01 12:42:59 +05:30
parth-gr 413662d475 core: change livenessProbe file name to probes
Added unit test for probes changes and
did re-naming of liveness probes file
as it will contain multiple types of probes

Signed-off-by: parth-gr <paarora@redhat.com>
2022-02-23 17:20:07 +05:30
Travis Nielsen 6d89747b21 docs: reset the pending release notes for 1.9
With the v1.8 release pending, we can reset the pending
release notes for v1.9.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-12-09 12:48:11 -07:00
Travis Nielsen 8e55dd9d41 pool: update the desired failure domain when changed
The failure domain is baked into the crush rule that is
created for a pool. To allow for an updated failure domain
on the pool, create a new crush rule specific for that
failure domain and update the pool with the new rule.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-12-08 08:10:53 -07:00
Sébastien Han c890710b63 core: change directory layout
As per discussion, proposing a new layout for the charts/yaml/olm files.

./deploy
├── charts
│   ├── rook-ceph
│   │   └── templates
│   └── rook-ceph-cluster
│       └── templates
├── examples
│   ├── csi
│   │   ├── cephfs
│   │   └── rbd
│   ├── flex
│   ├── monitoring
│   ├── pre-k8s-1.16
└── olm
    └── assemble

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-11-30 09:12:53 +01:00
Sébastien Han 889856b78f core: add s5cmd binary to operator image
The toolbox can now interact with S3 gateways using the `s5cmd` tool.
The binary is only 12M so this does not add up too much to the operator
image size.

Closes: https://github.com/rook/rook/issues/4968
Signed-off-by: Sébastien Han <seb@redhat.com>
2021-11-09 16:56:30 +01:00
Sébastien Han d06a6f93a5 core: run operator with rook user
The rook operator as well as the toolbox pod run with the "rook" user
with UID 2016. The UID was chosen based on the year of the initial
commit in the rook/rook repository.
No more root user running.

Closes: https://github.com/rook/rook/issues/8734
Signed-off-by: Sébastien Han <seb@redhat.com>
2021-11-05 17:22:04 +01:00
Yuval Lifshitz 71ed45b69b rgw: implement bucket notifications for object storage
following the design from here:
https://github.com/rook/rook/blob/master/design/ceph/object/ceph-bucket-notification-crd.md

Closes: https://github.com/rook/rook/issues/5313
Signed-off-by: Yuval Lifshitz <ylifshit@redhat.com>
2021-11-04 11:20:40 +02:00
Sébastien Han 18a4047679 osd: add support for k8s with vault kms
Rook cluster-wide encryption can now use the native Kubernetes
authentication to interact with vault KMS instead of using the token
method.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-10-21 13:59:28 +02:00
parth-gr 7c99858a77 ceph: add finalizers to rook-ceph-mon secrets and configmap
Adding finalizers to rook-ceph-mon secrets
and rook-ceph-mon-endpoints configmap
We don't want to delete this resources during disaster
because these details are needed during disaster recovery

Closes: https://github.com/rook/rook/issues/8369
Signed-off-by: parth-gr <paarora@redhat.com>
2021-10-07 19:44:17 +00:00
Sébastien Han 121c2987e3 ceph: stop using tini
We don't need to use tini.
We don't have anything in the rook operator that would
either create zombie processes (no threads) or use
exec (to fork). The Go binary has a really good
signal handling mechanism.

Closes: https://github.com/rook/rook/issues/8794
Signed-off-by: Sébastien Han <seb@redhat.com>
2021-09-27 10:54:16 +02:00