we have changed the --cluster-name flag to --k8s-cluster-name
but to support automation while upgrade we should support
the legacy flag
Signed-off-by: parth-gr <partharora1010@gmail.com>
change the json output of storageclass to also inclusde rados namespace,
and also added the changes in the csi secret
Signed-off-by: parth-gr <paarora@redhat.com>
if the monitoring endpoint is not present
we were not returning any error, but the
field is the mandatory output, so return error if not found
Signed-off-by: parth-gr <paarora@redhat.com>
Sometimes the pool is not enabled and the ceph cluster
shows health warning, so automatically initalize the pool
from the script
Signed-off-by: parth-gr <paarora@redhat.com>
if the client.health checker already exited it was
returning extra information, It was making the structure and
return JSON non idempotent output, So fixed
that problem by returning a single value
Signed-off-by: parth-gr <paarora@redhat.com>
when creating networkFence CR, it requires IP's to block
which we get from running `rbd status ...` command. But,
the client.healthchecker user didn't had the right caps
to run hence it was giving error. Now, adding the required
caps `profile rbd-read-only` to osd so that rbd command can
be executed.
Signed-off-by: subhamkrai <srai@redhat.com>
We need to create the namespace with the import script,
As per the documentation
The import script creates the secrets and
cm which is later used by the operator for cluster creation.
Signed-off-by: parth-gr <paarora@redhat.com>
When the ceph.conf is not in a well-known location, it is typical
for a custom ceph.keyring to be required as well. Currently, the
create-external-cluster-resources.py only tries to load the keyring
from well-known paths, and fails.
This commit adds a new optional argument `--keyring` to help in this
situation. When specified, create-external-cluster-resources.py will
attempt to use this as the keyring to authenticate with Ceph.
Signed-off-by: Angelos Kolaitis <neoaggelos@gmail.com>
set the csi subvolume to pin type distributed and pin setting 1
So to statically balance the PVs across all MDS ranks
Signed-off-by: parth-gr <paarora@redhat.com>
1) donot change rgw fqdn to ip if provided,
As now the bucket class supports the
entry of fqdn
2) update crds with new description in EndpointAddress
Signed-off-by: parth-gr <paarora@redhat.com>
if there is no multisite config pass, it will still checks for
the zones and zones group and not able to query anything
Signed-off-by: parth-gr <paarora@redhat.com>
the check validate_rgw_multisite was always checking for realm
updated it to check the specific config
fixed validate_rgw_endpoint pool validation
added missing realm zonegroup and zone while interacting with user resources
Co-authored-by: Sergio Pérez Fernández <sergioperez794@gmail.com>
Signed-off-by: parth-gr <paarora@redhat.com>
Add --skip-monitoring-endpoint to create-external-cluster-resources.py
to allow the script to work with Ceph clusters without an enabled
prometheus module.
Document the new flag in external-cluster.md and add relevant unit tests
Signed-off-by: Angelos Kolaitis <neoaggelos@gmail.com>
if restricted permission was on the . was appended to k8s secret and
failed to create the secret so added a alias name is user wan't to suuport
pool with . in name
Signed-off-by: parth-gr <paarora@redhat.com>
if the rge endint is not reachable don't block the creation
of rbd and cephfs sc, just print the error instead of raising exception
Signed-off-by: parth-gr <paarora@redhat.com>
if a cluster won't use the deafult realm and try to
execute the python script it will fail to vaildate rgw
as the rgw-admin-user would be created on default realm
So creating user in specific realm if the realm name is passed
Signed-off-by: parth-gr <paarora@redhat.com>
Currently for external clustr multitenancy is only applicable for new
deployments, but adding doc change so multi-tenancy can be achieved for
upgraded cluster also
Closes: https://github.com/rook/rook/issues/10678
Signed-off-by: parth-gr <paarora@redhat.com>
remove duplicate import urllib.parse which is handled below
with try and except no need to import separately. Also, change
the way to get the python version.
Signed-off-by: subhamkrai <srai@redhat.com>
The rgw ip validation feature was needing to update the rgw user
cap to add info=read permission, but this permission is only backported
till ceph pacific, so we added a check that only add this cap
when ceph version support it,
But this cap was also adding with the other caps, so removed it from there
Now it will only add this cap if ceph version support it
Signed-off-by: parth-gr <paarora@redhat.com>
Using subvolume group and rados namespace for external deployment
was complicated and not documented,
Automating the process for the users, so they just need to pass
the respective names by cli flag for creation
Closes: rook#10427
Signed-off-by: parth-gr <paarora@redhat.com>
For using restricted auth users we need to update the
restricted users in the Storage class, so updating
it in the json output for external cluster
Signed-off-by: parth-gr <paarora@redhat.com>
remove the restriction of per rados namespace as
there can be multiple namespaces and the csi-users
can only have 1 type in a storage class
Signed-off-by: parth-gr <paarora@redhat.com>
`black` is python formatter tool which
automatically formats python files without
manual changing. just run `black <python-file>`
and done.
Signed-off-by: subhamkrai <srai@redhat.com>
During the recent addtions of rgw validation
changes there are too many places where we use
rgwendpoint, so making fqdn to ip conversion globally
Signed-off-by: parth-gr <paarora@redhat.com>