Commit Graph
62 Commits
Author SHA1 Message Date
Praveen M a80396df1b csi: update cmdline args as used by ceph-csi
This commit adds cmdline args to enable
1. RecoverVolumeExpansionFailure
2. PreventVolumeModeConversion
3. HonorPVReclaimPolicy

Signed-off-by: Praveen M <m.praveen@ibm.com>
2024-01-12 15:24:07 +05:30
Travis Nielsen 6fba73621b Merge pull request #13338 from sp98/update-clusterroole
core: ability to create, update and delete services in other namespaces
2023-12-06 11:19:41 -07:00
Rakshith R a3220d827d csi: update default cephcsi version to 3.10.0
This commit updates default cephcsi driver version
to v3.10.0 and filesystem reconciler now creates
csi subvolumegroup by default.

Signed-off-by: Rakshith R <rar@redhat.com>
2023-12-06 19:57:40 +05:30
sp98 1dea93794a core: create/update/delete services in other namespaces
This PR adds permissions to create or update k8s service by the
in the naemspaces other than rook operator namespace

Signed-off-by: sp98 <sapillai@redhat.com>
2023-12-06 14:37:41 +05:30
subhamkrai 28cc1ebc55 core: remove webhook & controller-runtime from apis
This commits removes controller-runtime dependencies
from the apis dir and to achieve that we are removing
webhook.

Signed-off-by: subhamkrai <srai@redhat.com>
2023-12-01 14:15:40 +05:30
Jiffin Tony Thottan b48dc8a335 object: intial cosi driver controller design
Adding CephCOSIDriver CRD and controller. The controller will bring up
the ceph cosi driver when first object store is created in the rook
operator namespace. Then admin can defined COSI CRDs like BucketClass
and BucketAccessClass for different object stores deployed via Rook.
Using the BucketClass and BucketAccessClass, user can define
BucketAccess for backend bucket in the RGW. The CephCOSIDriver CRD
defines configuration options for ceph cosi driver. In the first version
its usability is minimal. Even if it is not defined Rook will bring up
the ceph cosi driver with default values.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2023-07-18 22:49:41 +05:30
subhamkrai 39b5c057ce core: faster recovery from rbd rwo node loss
in the existing node watcher, we'll check for node update
event and see if there are `out-of-service` taints are applied
and `ROOK_WATCH_FOR_NODE_FAILURE` is enabled in rook-ceph-operator-configmap,
if then we'll create the networkFence cr and delete the cr if nodes come back.
And, added the unit test too.

Signed-off-by: subhamkrai <srai@redhat.com>
2023-07-07 21:16:25 +05:30
Sud 2547372527 multus: add deletecollection capability for validation tool
Without deletecollection capability the image pullers won't be deleted, causing multus validation to fail.
    Added deletecollection verbs to the daemonsets resource in role rook-ceph-system
    This is fix for Issue: https://github.com/rook/rook/issues/12435

    Signed-off-by: Sudharsan Omprakash <sudharsan.omprakash@yahoo.com>
2023-06-28 17:45:18 -04:00
Redouane Kachach 08754f6197 mgr: removing unnecessary rook-ceph-mgr rbac entries
These rbac changes were introduced as part of #11845 PR to enable
sidecar accessing mgr pods but in fact they are not necessary
as rook-ceph-mgr role had already the ability to update pods

Closes: https://github.com/rook/rook/issues/12336

Signed-off-by: Redouane Kachach <rkachach@redhat.com>
2023-06-06 22:12:23 +02:00
Travis Nielsen 4a23260955 Merge pull request #11845 from rkachach/fix_issue_11844
mgr: use mgr_role dynamic label to tag the active ceph manager
2023-03-28 13:08:18 -06:00
Redouane Kachach f00bd790a8 mgr: using dynamic mgr_role label to implement mgr HA
Closes: https://github.com/rook/rook/issues/11844

Signed-off-by: Redouane Kachach <rkachach@redhat.com>
2023-03-27 18:38:55 +02:00
Vincent Kling bd857cc5c5 manifest: add missing quote
Signed-off-by: Vincent Kling <v.kling@vinniict.nl>
2023-03-11 11:44:58 +01:00
Rakshith R f39a32fcdb osd: add capability to reconcile key rotation cron jobs
This commits adds code to reconcile key rotation cron jobs.

Signed-off-by: Rakshith R <rar@redhat.com>
2023-03-08 12:07:26 +05:30
Rakshith R 71e011f731 osd: add rotate-key functionality to rook's key-management cmd
This commit adds functionality to be able to rotate
key encryption key of encrypted PVC backed OSDs.
Necessary changes such as adding update functionality
to kms and rbac changes are made as well.

Signed-off-by: Rakshith R <rar@redhat.com>
2023-03-08 12:07:26 +05:30
sp98 7292ac5927 core: export mon and OSD services
Signed-off-by: sp98 <sapillai@redhat.com>
2023-02-27 21:36:59 +05:30
Travis Nielsen b632ba10ff Merge pull request #11697 from Madhu-1/fix-11694
csi: add missing node access to cephfs driver
2023-02-17 12:18:38 -07:00
subhamkrai 4699e8885a build: add rbac which are required
adding necessary rbac and also updating
csv-gen script.

Closes: https://github.com/rook/rook/issues/10141
Signed-off-by: subhamkrai <srai@redhat.com>
2023-02-17 23:00:03 +05:30
Madhu Rajanna 1cfa7eefae csi: add missing node access to cephfs driver
Node access is only needed when we are using
volumeBindingMode: WaitForFirstConsumer in
the storageclass its not required for Immediate
BindingMode.

fixes: #11694

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2023-02-17 07:50:53 +01:00
Ben Gao 84296a997a mgr: role rook-ceph-mgr is lack of patch verb to compete ceph request
ceph orch command uses patch method to update cephcluster. Adding patch to verbs list of rook-ceph-mgr(Role) to make it work. It was allright with deploy/charts/rook-ceph-cluster/charts/library/templates/_cluster-role.tpl to justify the changes quite a bit.

Signed-off-by: Ben Gao <bengao168@msn.com>
2023-01-18 16:39:54 +08:00
Madhu Rajanna 61c533ba41 csi: add missing update rbac
when a PVC is cloned external-provisioner
still required update access or else a warning
will be logged in the pvc describe output

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2022-12-21 11:11:48 +01:00
Rakshith R 3c5a2f4142 csi: add topology provisioning support
This commit adds topology provisioning
support. This makes modification to rbac,
csi deployment and daemonset.

Signed-off-by: Rakshith R <rar@redhat.com>
2022-09-12 16:10:18 +05:30
yati1998 9b4361b379 rbdmirror: remove volume replication sidecar
The volume replication operator is being moved to
kubernetes-csi-addons. This commit hence, removes
the volume replication sidecar and updates the
related documentation.
It will also update the csi-addons sidecar version
to the latest one.

Closes: #10655

Signed-off-by: yati1998 <ypadia@redhat.com>
2022-09-07 14:49:19 +05:30
Blaine Gardner 6c8f2e414f build: remove psp from common.yaml generation
Due to an oversight, PSP resources were left in generation of
common.yaml from #10797. Resolve that by setting
pspEnable=false when generating common.yaml.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2022-08-29 10:41:41 -06:00
Mudit Agarwal 40081cbcd2 Revert "csi: remove attacher sidecar from CephFS rook deployment"
This reverts commit 4bfd88dc4d.

Signed-off-by: Mudit Agarwal <muagarwa@redhat.com>
2022-08-10 13:04:14 +05:30
yati1998 4bfd88dc4d csi: remove attacher sidecar from CephFS rook deployment
CephFS CSI driver dont have/advertise controller publish/unpublish
capabilities, thus dont need attacher sidecar for its operations.
The presence of external-attacher adds on overhead and issues wrt
attachment in various scenarios. One of them would be the lack of
performance on syncing volumeattachment from api server..etc.
More or less we don't have controller publish and unpublish capabilities,
so we should not make use of this sidecar and cause
unnecessary addon here thus other issues.

similar changes have been added to CSI
https://github.com/ceph/ceph-csi/pull/3149

Signed-off-by: yati1998 <ypadia@redhat.com>
2022-08-03 19:56:39 +05:30
parth-gr 50daeb29e5 core: remove all wildcard permissions in rbac definations
Reduce the RBAC scope to the minimum necessary
permissions for rook to operator

Signed-off-by: parth-gr <paarora@redhat.com>
2022-07-08 20:50:59 +05:30
Rakshith R 623c5159d5 csi: add token create rbac for rbd csi clusterrole
This rbac is required to fetch serviceaccount
token for vault tenant sa encryption type on k8s 1.24+.
refer: https://github.com/ceph/ceph-csi/pull/3174

Signed-off-by: Rakshith R <rar@redhat.com>
2022-06-14 10:18:20 +05:30
Madhu Rajanna 02b9f199d7 csi: add volumeattachment list rbac
rbd nodeplugin need volumeattachment RBAC
to remount the volume incase of the nbd driver
is used to mount the volume.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2022-05-31 15:09:34 +05:30
Travis Nielsen 1fe71fc76f Merge pull request #10271 from humblec/rbac-cleanup-2
Adjust PV object RBAC  for CSI PODs
2022-05-17 07:26:00 -06:00
Travis Nielsen 362e3a6578 Merge pull request #10247 from Madhu-1/remove-cephfs-node-rbac
csi: Remove extra cephfs node rbac
2022-05-16 08:40:16 -06:00
Humble Chirammal 34e88776e7 csi: remove unwanted verbs for pv object
pv object patch verb is enough for the csi sidecar to function.

Signed-off-by: Humble Chirammal <hchiramm@redhat.com>
2022-05-16 14:35:34 +05:30
Humble Chirammal 0812d08a75 csi: remove watch verb from csi-snapshottter sidecar RBAC
The `watch` verb is not required for the csi-snapshotter sidecar
to function, removing it from the deployment

Signed-off-by: Humble Chirammal <hchiramm@redhat.com>
2022-05-16 13:21:42 +05:30
Madhu Rajanna e4133857e9 csi: remove extra cephfs RBAC
Remove unwanted cephfs clusterRole
RBAC.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2022-05-16 10:52:21 +05:30
Travis Nielsen bb5812316d Merge pull request #10244 from y1r/add-psp
build: add psp for missing roles
2022-05-11 11:55:45 -06:00
Yuichiro Ueno 1ccc185a79 build: add psp for missing roles
This commit adds psp RoleBindings to rook-ceph-rgw role and
rook-ceph-purge-osd role. Without this commit, I cannot perform
rook-ceph-purge-osd job on PSP-enabled cluster.

Signed-off-by: Yuichiro Ueno <ueno@preferred.jp>
2022-05-11 13:50:37 +09:00
Madhu Rajanna 19f77c6174 csi: remove unwanted RBAC of csi driver
Removed unwanted RBAC from the
previous versions of driver.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2022-05-11 10:16:37 +05:30
Travis Nielsen 1dd343ed7e build: add a placeholder rule to rgw rbac
With https://github.com/rook/rook/pull/10108 a placeholder role
and role binding were added for the rgw service account so
the csv generation would generate the service account. That
workaround also requires a rule to be added to the role or else
the generation is invalid. Now a rule is added to avoid that
issue. In the future we need to remove this role and binding
when the operator sdk is updated as explained in
https://github.com/rook/rook/issues/10141

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-04-22 10:38:58 -06:00
Travis Nielsen e1550e7551 build: add a placeholder rgw role for csv generation
The csv will not properly include the rook-ceph-rgw service
account unless there is a role and binding that references
the service account. No roles are needed yet for the rgw
daemon, so this will add a placeholder only for the purposes
of csv generation.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-04-20 07:53:17 -06:00
Travis Nielsen 221fc5d81b Merge pull request #10046 from Madhu-1/webhook-rados
ceph: add webhooks to reject update on subvolume group and radosnamespace
2022-04-13 11:06:20 -06:00
Madhu Rajanna 024c034a95 core: add code to update the webhook configurations
As we are adding new webhook configuration we
need to update the webhooks validations.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2022-04-13 10:38:38 +05:30
Blaine Gardner bca2f128ab build: generate a separate NFS CSI RBAC manifest
Because the NFS CSI driver is optional and rarely deployed, make RBAC
for this driver an optional example that is generated by the helm chart.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2022-04-12 16:57:11 -06:00
Rakshith R 5f48ad8026 csi: add nfs provisioner deployment
This commit adds nfs provisioner deployment.
This will allow rook to deploy nfs provisioner
which can create backend cephfs subvolumes to be
exported as nfs volumes.

refer:
https://github.com/ceph/ceph-csi/blob/devel/docs/design/proposals/nfs.md

Signed-off-by: Rakshith R <rar@redhat.com>
2022-04-12 11:25:08 +05:30
Rakshith R 34162c3dc5 csi: add nfs nodeplugin daemonset
This commit adds nfs nodeplugin daemonset.
This will allow rook to deploy nfs nodeplugin
which can mount/unmount nfs volumes.

refer:
- https://github.com/ceph/ceph-csi/blob/devel/docs/design/proposals/nfs.md
- https://github.com/kubernetes-csi/csi-driver-nfs

Signed-off-by: Rakshith R <rar@redhat.com>
2022-04-12 11:07:38 +05:30
Travis Nielsen 7eaef3871d Merge pull request #10009 from humblec/remove-update
csi: remove node object update rbac for csi deamonset pods
2022-04-11 09:55:10 -06:00
subhamkrai f6f03d272b core: start admission controller without any script
finally, admission controller will be enabled default
without any script/manual step. But it still requires cert-manager
to be installed which I believe is already installed in clusters.

**Note**
Code doesn't return error it just logs the error since
we don't want to stop reconciling if the admission controller fails.
We can work on this once the admission controller is stable.

Signed-off-by: subhamkrai <srai@redhat.com>
2022-04-11 19:44:54 +05:30
Humble Chirammal e2a95ac51e csi: remove node object update rbac for csi deamonset pods
The CSI driver pods dont need to update the node objects for
its operations. This commit remove the unwanted access to node
object update in the RBAC of CSI pods.

Signed-off-by: Humble Chirammal <hchiramm@redhat.com>
2022-04-07 11:11:16 +05:30
Madhu Rajanna b0fc7c9b92 namespace: add new CRD
This introduces a new CRD to add the ability
to create rados namespace for a given
ceph block pool. Typically the name of the pool
is the name of the blockpool created by rook.

Closes: #7035

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2022-04-05 10:10:04 +05:30
Jiffin Tony Thottan 5e72b26948 object: add service account for RGW pod
For supporting features like service account authentication for vault
KMS , a service account account need to attach with pod.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2022-04-04 11:24:50 +05:30
Travis Nielsen b3ca0f1b87 osd: purge job will remove all pvcs for the osd
The purge job is intended to clean up all the resources
related to an OSD that is to be removed. An OSD with
a metadata, wal, and data PVC was only cleaning up the
data PVC. Now the metadata and wal PVCs will also be
cleaned up.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-02-24 12:05:15 -07:00
Travis Nielsen 3e4edc0f1d csi: add patch permission to volumesnapshotcontents
The update to the snaphots 5.0 controller requires
rbac for patching the volumesnapshotcontents.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-01-27 11:35:06 -07:00