create the ceph config and keyring file in the osd prepare pod
before starting the OSD migration. These files are needed to
run any ceph command.
Signed-off-by: sp98 <sapillai@redhat.com>
Use Quay as the source for the nginx-unprivileged image used for the
Multus validation tool because Quay does not rate limit image pulls,
which are a common complaint for users of the tool.
Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
Loop variables cannot be reliably uses since they will
change with each iteration. Update these loop variable
uses to be safe by indexing the slice rather than
using the loop variable directly.
Also suppress the linter issues for passwords used
in tests.
Signed-off-by: travisn <tnielsen@redhat.com>
This implements the "Ceph Config via Ceph Cluster CRD" design document
as a `cephConfig:` structure on the CRD.
This also fixes the `yq` commands used to manipulate the
`cluster-test.yaml` that caused CI issues for this PR and potentially
unknowingly others.
Signed-off-by: Alexander Trost <galexrt@googlemail.com>
Originally we create it using this cmd
ceph fs subvolume create <vol_name> <subvol_name>
So we can have 2 variables filesystem and subvolume name,
Currently the CR doesn't allow us to make subvolume-name
as constant as needed to "csi" because of k8s limitations
Signed-off-by: parth-gr <paarora@redhat.com>
Adding callback function in the osd removal method
as in downstream there is requirement of adding extra
check before proceeding with osd removal.
Signed-off-by: subhamkrai <srai@redhat.com>
This commit adds new CSIDriverOptions section in
cephCluster CR. This section contains settings
for read affinity and kernel+fuse Mount options
These settings will be injected directly into
rook-ceph-csi-config cm to be applicable per
ceph cluster.
Signed-off-by: Rakshith R <rar@redhat.com>
This patch adds `pgHealthyRegex` field to DisruptionManagementSpec.
`pgHealthyRegex` is a regular expression that is used to determine which
PG states should be considered healthy. The default value of
`pgHealthyRegex` is:
^(active\+clean|active\+clean\+scrubbing|active\+clean\+scrubbing\+deep)$
which is effectively the same as before.
Signed-off-by: Ryotaro Banno <ryotaro.banno@gmail.com>
This reverts commit 093125904b.
Once we introduced encrypted OSD on partition in #12924.
However, even though `encryptedDevice` field is `true`,
an non-encrypted OSD is created. To prevent the creation
of misconfigured OSD, it's better to revert #12924 for now.
Initially, I intended to correct this problem. However, I found
it will take long time because we need to change the KMS-related
code, init containers of both OSD pod and OSD prepare pod.
Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
Add the ability to specify node profiles in the multus validation test.
This addresses a few points of early feedback on the validation tool.
Statements below critique the tool's behavior before this patch.
1. The tool assumes all daemons are on public and cluster network, which
means users who have a significantly smaller cluster net (a
design choice) cannot run a single test to determine if Rook is
likely to install correctly.
2. The tool does not have placement options to select only a subset of
Kubernetes nodes to run validation on.
3. Users of multus seem to have a dedicated pool of storage nodes more
often than the average Rook install. This makes sense for security-
and perforance-minded users. The tool cannot run a single test to
verify storage-only and general-workload nodes at one time.
These points are addressed by allowing users to specify configurations
for different "NodeTypes."
Each NodeType config has options for selecting the number of OSDs as
well as the number of other (non-OSD) Ceph daemons. This limits the
unnecessary exhaustion of cluster network addresses from critique 1.
Each NodeType config has its own placement (critique 2).
Users can define as many NodeTypes as needed to test the network for
their planned CephCluster. Specifically, this allows the tool to test
storage-only nodes and generalized-workload nodes at the same time. An
arbitrary number of NodeTypes are allowed to support even more highly
specialized cluster setups, such as multiple tiers of storage nodes
where some storage-only nodes may run more OSDs than others.
Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
The activeStandby property of the filesystem CR was not
taking effect when changed from true to false. The standby
was only being enabled when true, but never applied when
changed to false.
Signed-off-by: travisn <tnielsen@redhat.com>
The json tag in struct MonMap had a spelling error where "json" was incorrectly splled as "josn". This commit corrects the spelling to "json".
Signed-off-by: go-bai <599500688@qq.com>
If osd store is updated in the ceph cluster, then
delete OSDs one by one, cleanup disks and provision a new OSD on
the same disk
Signed-off-by: sp98 <sapillai@redhat.com>
The vault server dependencies were pulling a lot of indirect modules
that are not necessary for Rook. The modules were only used
for testing. The vault github explicitly indicates that:
"Some other projects have made a practice of doing so in order to
take advantage of testing tooling that was developed for testing Vault itself.
This is not, and has never been, a supported way to use the Vault project."
When attempting to update to vault v1.13.3, we are hitting
such an unsupported configuration with go modules
that are impossible to satisfy. By removing the tests
that were using the vault server project, we can remove
this large set of dependencies, enable updating to v1.13.3,
and also reduce the modules pulled in by vault.
Signed-off-by: travisn <tnielsen@redhat.com>
The go modules are updated to the latest client-go, vault,
and other modules. There does not appear to be a combination
of modules that will allow us to use vault v1.13.3, so we
stick with v1.13.2.
Signed-off-by: travisn <tnielsen@redhat.com>
Allow the validation tool to read test config from a yaml file. To help
users, also allow outputting a config file with default values and
comments instructing how to use the config file.
This work is in anticipation of adding more advanced configuration
options that would be too cumbersome to set using cli flags.
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
Regarding Go templates: when inside a range, the base dot (.) context is
not available, so anything used within the range must be set to a
shell-style variable.
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
Allow overriding the nginx server image used for the web server and clients from CLI with --nginx-image flag.
Set default image in flag as 'nginxinc/nginx-unprivileged:stable-alpine'
Signed-off-by: iPraveenParihar <praveenparihar68@gmail.com>
Before starting multus validation test clients, pull the client image to
all nodes. This will ensure that variations in client readiness timing
will not be affected by variations in the time nodes take to pull the
image. This is intended to reduce the number of false reports of flaky
multus networks.
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
Add a more involved multus validation test to the Rook binary. Because
this is intended to be end-user runnable, make sure operator-only
commands are hidden.
Build this into the rook binary instead of creating a separate binary
for ease, and because any binary built with the kube api becomes 40+
megabytes. We save quite a bit of space by including this in the Rook
binary, which is good for keeping container layers as small as possible.
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
Dashboard ac-user-create cmd was taking more time
then the usual ceph command to run,
So increased the timeout to run the cmd, and
now dashboard admin user is sucessfully created
Closes: https://github.com/rook/rook/issues/12113
Signed-off-by: parth-gr <paarora@redhat.com>
this feature is to allow the use of filters using the deviceFilter flag
by skipping devices that do not match the filter
Closes: #10340
Signed-off-by: Javier <sjavierlopez@gmail.com>
Rook uses global or node-local device class configuration if device-level
configurations doesn't exist. However, after introducing device-class
level resource configuration, rook set the default value of device class.
So global or node-level device class configuration has never been used
after that.
Closes: https://github.com/rook/rook/issues/11871
Closes: https://github.com/rook/rook/issues/11826
Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
This commit adds functionality to be able to rotate
key encryption key of encrypted PVC backed OSDs.
Necessary changes such as adding update functionality
to kms and rbac changes are made as well.
Signed-off-by: Rakshith R <rar@redhat.com>