This commit updates default cephcsi driver version
to v3.10.0 and filesystem reconciler now creates
csi subvolumegroup by default.
Signed-off-by: Rakshith R <rar@redhat.com>
This PR adds permissions to create or update k8s service by the
in the naemspaces other than rook operator namespace
Signed-off-by: sp98 <sapillai@redhat.com>
This commits removes controller-runtime dependencies
from the apis dir and to achieve that we are removing
webhook.
Signed-off-by: subhamkrai <srai@redhat.com>
Adding CephCOSIDriver CRD and controller. The controller will bring up
the ceph cosi driver when first object store is created in the rook
operator namespace. Then admin can defined COSI CRDs like BucketClass
and BucketAccessClass for different object stores deployed via Rook.
Using the BucketClass and BucketAccessClass, user can define
BucketAccess for backend bucket in the RGW. The CephCOSIDriver CRD
defines configuration options for ceph cosi driver. In the first version
its usability is minimal. Even if it is not defined Rook will bring up
the ceph cosi driver with default values.
Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
in the existing node watcher, we'll check for node update
event and see if there are `out-of-service` taints are applied
and `ROOK_WATCH_FOR_NODE_FAILURE` is enabled in rook-ceph-operator-configmap,
if then we'll create the networkFence cr and delete the cr if nodes come back.
And, added the unit test too.
Signed-off-by: subhamkrai <srai@redhat.com>
Without deletecollection capability the image pullers won't be deleted, causing multus validation to fail.
Added deletecollection verbs to the daemonsets resource in role rook-ceph-system
This is fix for Issue: https://github.com/rook/rook/issues/12435
Signed-off-by: Sudharsan Omprakash <sudharsan.omprakash@yahoo.com>
These rbac changes were introduced as part of #11845 PR to enable
sidecar accessing mgr pods but in fact they are not necessary
as rook-ceph-mgr role had already the ability to update pods
Closes: https://github.com/rook/rook/issues/12336
Signed-off-by: Redouane Kachach <rkachach@redhat.com>
This commit adds functionality to be able to rotate
key encryption key of encrypted PVC backed OSDs.
Necessary changes such as adding update functionality
to kms and rbac changes are made as well.
Signed-off-by: Rakshith R <rar@redhat.com>
Node access is only needed when we are using
volumeBindingMode: WaitForFirstConsumer in
the storageclass its not required for Immediate
BindingMode.
fixes: #11694
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
ceph orch command uses patch method to update cephcluster. Adding patch to verbs list of rook-ceph-mgr(Role) to make it work. It was allright with deploy/charts/rook-ceph-cluster/charts/library/templates/_cluster-role.tpl to justify the changes quite a bit.
Signed-off-by: Ben Gao <bengao168@msn.com>
when a PVC is cloned external-provisioner
still required update access or else a warning
will be logged in the pvc describe output
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
This commit adds topology provisioning
support. This makes modification to rbac,
csi deployment and daemonset.
Signed-off-by: Rakshith R <rar@redhat.com>
The volume replication operator is being moved to
kubernetes-csi-addons. This commit hence, removes
the volume replication sidecar and updates the
related documentation.
It will also update the csi-addons sidecar version
to the latest one.
Closes: #10655
Signed-off-by: yati1998 <ypadia@redhat.com>
Due to an oversight, PSP resources were left in generation of
common.yaml from #10797. Resolve that by setting
pspEnable=false when generating common.yaml.
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
CephFS CSI driver dont have/advertise controller publish/unpublish
capabilities, thus dont need attacher sidecar for its operations.
The presence of external-attacher adds on overhead and issues wrt
attachment in various scenarios. One of them would be the lack of
performance on syncing volumeattachment from api server..etc.
More or less we don't have controller publish and unpublish capabilities,
so we should not make use of this sidecar and cause
unnecessary addon here thus other issues.
similar changes have been added to CSI
https://github.com/ceph/ceph-csi/pull/3149
Signed-off-by: yati1998 <ypadia@redhat.com>
rbd nodeplugin need volumeattachment RBAC
to remount the volume incase of the nbd driver
is used to mount the volume.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
The `watch` verb is not required for the csi-snapshotter sidecar
to function, removing it from the deployment
Signed-off-by: Humble Chirammal <hchiramm@redhat.com>
This commit adds psp RoleBindings to rook-ceph-rgw role and
rook-ceph-purge-osd role. Without this commit, I cannot perform
rook-ceph-purge-osd job on PSP-enabled cluster.
Signed-off-by: Yuichiro Ueno <ueno@preferred.jp>
With https://github.com/rook/rook/pull/10108 a placeholder role
and role binding were added for the rgw service account so
the csv generation would generate the service account. That
workaround also requires a rule to be added to the role or else
the generation is invalid. Now a rule is added to avoid that
issue. In the future we need to remove this role and binding
when the operator sdk is updated as explained in
https://github.com/rook/rook/issues/10141
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
The csv will not properly include the rook-ceph-rgw service
account unless there is a role and binding that references
the service account. No roles are needed yet for the rgw
daemon, so this will add a placeholder only for the purposes
of csv generation.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
Because the NFS CSI driver is optional and rarely deployed, make RBAC
for this driver an optional example that is generated by the helm chart.
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
finally, admission controller will be enabled default
without any script/manual step. But it still requires cert-manager
to be installed which I believe is already installed in clusters.
**Note**
Code doesn't return error it just logs the error since
we don't want to stop reconciling if the admission controller fails.
We can work on this once the admission controller is stable.
Signed-off-by: subhamkrai <srai@redhat.com>
The CSI driver pods dont need to update the node objects for
its operations. This commit remove the unwanted access to node
object update in the RBAC of CSI pods.
Signed-off-by: Humble Chirammal <hchiramm@redhat.com>
This introduces a new CRD to add the ability
to create rados namespace for a given
ceph block pool. Typically the name of the pool
is the name of the blockpool created by rook.
Closes: #7035
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
For supporting features like service account authentication for vault
KMS , a service account account need to attach with pod.
Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
The purge job is intended to clean up all the resources
related to an OSD that is to be removed. An OSD with
a metadata, wal, and data PVC was only cleaning up the
data PVC. Now the metadata and wal PVCs will also be
cleaned up.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>