Commit Graph
335 Commits
Author SHA1 Message Date
Travis Nielsen 591ddf2c3d Merge pull request #13420 from iPraveenParihar/api/csi-config-map
csi: use ceph-csi exposed csi config map API
2024-01-16 12:34:11 -07:00
Praveen M a80396df1b csi: update cmdline args as used by ceph-csi
This commit adds cmdline args to enable
1. RecoverVolumeExpansionFailure
2. PreventVolumeModeConversion
3. HonorPVReclaimPolicy

Signed-off-by: Praveen M <m.praveen@ibm.com>
2024-01-12 15:24:07 +05:30
Praveen M dfd3d625a8 csi: use ceph-csi exposed csi config map API
This commit uses an csi config map API exposed by Ceph-CSI.
This will reduce the efforts of keeping the configuration in
sync with Ceph-CSI.

Signed-off-by: Praveen M <m.praveen@ibm.com>
2024-01-12 15:04:20 +05:30
Riya Singhal 4dfe1da59c csi: updating the comment explaining the requirements
this commit updates the comment to explain the requirement of
giving 'all' permissions to MDS.

Signed-off-by: Riya Singhal <rsinghal@redhat.com>
2024-01-02 22:59:30 +05:30
Travis Nielsen c8d2955f98 Merge pull request #13348 from riya-singhal31/fencing
csi: implement network fencing for cephFS
2023-12-19 12:22:14 -07:00
Riya Singhal ef1ee6ebae csi: update default cephcsi version to 3.10.1
This commit updates default cephcsi driver version
to v3.10.1

Signed-off-by: Riya Singhal <rsinghal@redhat.com>
2023-12-19 23:42:26 +05:30
Travis Nielsen 20559ac7a4 Merge pull request #13439 from iPraveenParihar/fix/remove-gRPC-metrics-svc
csi: remove gRPC metrics service
2023-12-19 10:12:21 -07:00
Praveen M 17c9a069bd csi: remove gRPC metrics service
This commit removes the gRPC metrics svc which was missed in PR #13166.

Signed-off-by: Praveen M <m.praveen@ibm.com>
2023-12-19 15:24:56 +05:30
Riya Singhal 9202e20829 csi: implement network fencing for cephFS
Signed-off-by: Riya Singhal <rsinghal@redhat.com>
2023-12-18 21:44:47 +05:30
Niels de Vos 1ca1257c65 csi: update the CSI-Addons sidecar to v0.8.0
Quite some improvements have been included in the recently released
v0.8.0 of the CSI-Addons sidecar for Kubernetes. Rook users will benefit
from running the latest version of the sidecar when deploying Ceph-CSI.

See-also: https://github.com/csi-addons/kubernetes-csi-addons/releases/tag/v0.8.0
Signed-off-by: Niels de Vos <ndevos@ibm.com>
2023-12-15 15:13:42 +01:00
Rakshith R a3220d827d csi: update default cephcsi version to 3.10.0
This commit updates default cephcsi driver version
to v3.10.0 and filesystem reconciler now creates
csi subvolumegroup by default.

Signed-off-by: Rakshith R <rar@redhat.com>
2023-12-06 19:57:40 +05:30
travisn 6f8e42422d core: fix golang linter issues with variables in loops
Loop variables cannot be reliably uses since they will
change with each iteration. Update these loop variable
uses to be safe by indexing the slice rather than
using the loop variable directly.

Also suppress the linter issues for passwords used
in tests.

Signed-off-by: travisn <tnielsen@redhat.com>
2023-12-05 14:14:58 -07:00
Rakshith R 59cb0dd4bf csi: add CSIDriverOptions section in cephCluster CR
This commit adds new CSIDriverOptions section in
cephCluster CR. This section contains settings
for read affinity and kernel+fuse Mount options
These settings will be injected directly into
rook-ceph-csi-config cm to be applicable per
ceph cluster.

Signed-off-by: Rakshith R <rar@redhat.com>
2023-11-29 19:34:28 +05:30
Travis Nielsen 510d2721b4 Merge pull request #13247 from riya-singhal31/master
csi: add csi-addons sidecar to cephfs deployment
2023-11-21 16:13:31 -07:00
Riya Singhal 401ce4697a csi: add csi-addons sidecar to cephfs deployment
this commit adds csi-addon sidecar to
cephfsplugin provisioner deployment

Signed-off-by: Riya Singhal <rsinghal@redhat.com>
2023-11-22 02:50:45 +05:30
Praveen M ddf03bce6f csi: update csi sidecars' image version
csi-node-driver-registrar: v2.9.1
csi-resizer: v1.9.2
csi-provisioner: v3.6.2
csi-attacher: v4.4.2
csi-snapshotter: v6.3.2
Signed-off-by: Praveen M <m.praveen@ibm.com>
2023-11-21 14:41:57 +05:30
Travis Nielsen 297e8400e5 Merge pull request #12850 from parth-gr/node-telemetry
core: report node metrics using ceph telemetry
2023-11-16 14:55:44 -07:00
parth-gr f007f2aca1 core: report node metrics using ceph telemetry
Add this reporting with the cephcluster reconcile,
Similar way we reported other telemetry's

Closes: https://github.com/rook/rook/issues/12344

Signed-off-by: parth-gr <paarora@redhat.com>
2023-11-16 19:13:22 +05:30
Madhu Rajanna 5658e026cb csi: remove deprecated grpc metrics code
GRPC metrics got deprecated in cephcsi
3.7.0 and the deprecated flags will get
removed in the next release. This PR
removes the deprecated metrics code which
allow us to run with older cephcsi as well.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2023-11-07 11:24:17 +01:00
Madhu Rajanna 9f2b7d572d csi: fix indentation for mountinfo
Fixed the indentation for the mountinfo
or else an emptyDir is getting created
for it.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2023-10-12 09:01:26 +02:00
Madhu Rajanna 54ce2a96da csi: add mountinfo path for cephfs daemonset
If mountinfo path is available cephcsi will
try to recover the fuse client. adding the
support for the same in Rook.

fixes: #13009

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2023-10-06 11:16:23 +02:00
Eng Zer Jun 77bff6a07c core: remove redundant len check
From the Go specification [1]:

  "1. For a nil slice, the number of iterations is 0."
  "3. If the map is nil, the number of iterations is 0."

`len` returns 0 if the slice or map is nil [2]. Therefore, checking
`len(v) > 0` before a loop is unnecessary.

[1]: https://go.dev/ref/spec#For_range
[2]: https://pkg.go.dev/builtin#len

Signed-off-by: Eng Zer Jun <engzerjun@gmail.com>
2023-10-05 20:16:46 +08:00
guoguangwu 235ac293ff core: import packages only once
Signed-off-by: guoguangwu <guoguangwu@magic-shield.com>
2023-09-16 13:40:17 +08:00
Blaine Gardner 17f0072d9d Merge pull request #12778 from BlaineEXE/multus-allow-cidr-spec
multus: allow using NADs without inspectable CIDRs
2023-09-07 13:42:41 -06:00
Blaine Gardner 3c43268d0a multus: detect network CIDRs via canary
Change how Rook detects network CIDRs for Multus networks. The IPAM
configuration is only defined as an arbitrary string JSON blob with a
"type" field and nothing more. Rook's detection of CIDRs for whereabouts
had already grown out of date since the initial implementation.
Additionally, Rook did not support DHCP IPAM, which is a reasonable
choice for users. And more, Rook did not support CNI plugin chaining,
which further complicates NADs. Based on the CNI spec, network chaning
can result in any changes to network CIDRs from the first-given plugin.

All these problems make it more and more difficult for Rook to support
Multus by inspecting the NAD itself to predict network CIDRs. Instead,
it is better for Rook to treat the CNI process as a black box. To
preserve legacy functionality of auto-detecting networks and to make
that as robust as possible, change to a canary-style architecture like
that used for Ceph mons, from which Rook will detect the network CIDRs
if possible.

Also allow users to specify overrides for CIDR ranges. This allows Rook
to still support esoteric and unexpected NAD or network configurations
where a CIDR range is not detectable or where the range detected would
be incomplete. Because it may be impossible for Rook to understand the
network CIDRs wholistically while residing only on a portion of the
network, this feature should have been present from Multus's inception.

Improving CIDR auto-detection and allowing users to specify overrides
for auto-detected CIDRs rounds out Rook's Multus support for CephCluster
(core/RADOS) installations. No further architectural changes should be
needed for CephClusters as regards application of public/cluster network
CIDRs for Multus networks.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2023-09-07 10:12:55 -06:00
subhamkrai a755ec156a csi: enable csi-addons-side when crds are deployed
when deploying csi, we'll check if csi-addons crds
are deployed we'll enable csi-addons sidecar by default.

Signed-off-by: subhamkrai <srai@redhat.com>
2023-08-31 11:28:49 +05:30
Madhu Rajanna d7a4f0038c csi: set ceph cluster as ControllerRef for holder
Setting ceph cluster as the ControllerRef
for the holder daemonset set so that when
a ceph cluster is deleted the holder daemoset
will also gets deleted.

fixes: #12645

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2023-08-22 10:41:17 +02:00
karthik-us 2675c976d5 csi: add maxUnavailable for cephfs csi daemonset
Adding maxUnavailable parameter to the cephfs csi daemonset. The
default value of maxUnavailable = 1 can make the upgrade process
slower in environments with large number of nodes.

Fixes: #12636
Signed-off-by: karthik-us <ksubrahm@redhat.com>
2023-08-07 19:48:21 +05:30
Travis Nielsen 65f413ce1f Merge pull request #12286 from subhamkrai/fix-node-loss-rbd
core: faster recovery from rbd rwo node loss
2023-07-07 10:35:59 -06:00
subhamkrai 39b5c057ce core: faster recovery from rbd rwo node loss
in the existing node watcher, we'll check for node update
event and see if there are `out-of-service` taints are applied
and `ROOK_WATCH_FOR_NODE_FAILURE` is enabled in rook-ceph-operator-configmap,
if then we'll create the networkFence cr and delete the cr if nodes come back.
And, added the unit test too.

Signed-off-by: subhamkrai <srai@redhat.com>
2023-07-07 21:16:25 +05:30
Travis Nielsen 3ffec84100 Merge pull request #12462 from Madhu-1/fix-holderpod
csi: update csi holder daemonset template
2023-07-07 08:32:00 -06:00
Travis Nielsen 18e2502a69 Merge pull request #12295 from subhamkrai/remve-default-scc
security: remove default scc privileges
2023-07-07 08:24:37 -06:00
subhamkrai 48f84b37e8 security: drop all capabilities to the container
adding drop `ALL` capabilities in rook operator container
as this is not required and will remove warning in ocp cluster.

Signed-off-by: subhamkrai <srai@redhat.com>
2023-07-07 17:06:48 +05:30
Travis Nielsen 46dd374e30 Merge pull request #12478 from Rakshith-R/csi/rm-checks
csi: drop checks for k8s version below the support minimum version
2023-07-06 11:53:47 -06:00
Rakshith R aa0aa34c23 csi: update csi sidecars' image version
Signed-off-by: Rakshith R <rar@redhat.com>
2023-07-06 16:18:35 +05:30
Rakshith R 76f4b1f586 csi: remove code related to betav1CsiDriver
This commit removes code related to betav1CsiDriver
since minimum k8s version support by rook is now
k8s v1.22 which does not support betav1 csi driver crd.

Signed-off-by: Rakshith R <rar@redhat.com>
2023-07-06 15:55:57 +05:30
Rakshith R d6b8a8f380 csi: remove k8s version check for oidc token
This commit removes k8s version check for oidc token
which required k8s v1.20 or above since minimum
k8s version that rook supports now is v1.22.

Signed-off-by: Rakshith R <rar@redhat.com>
2023-07-06 15:44:45 +05:30
Madhu Rajanna 1ba3aa4d19 csi: update csi holder daemonset template
Currently the holder daemonset is never updated
which will leaves the images the daemonset also
not updated. we should update the daemonset
template but not restart the csi holder pods
which causes the CSI volume access problem,
set the updateStrategy to OnDelete (already set in
yaml files) which allow us to update the holder
daemonset but not restart/update the pods, when a
pod is deleted or node is rebooted
the new changes will take effect.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2023-07-03 14:13:38 +02:00
Rakshith R fa1be14bca csi: update csiaddons k8s-sidecar to v0.7.0
This commit updates k8s-sidecar to v0.7.0
and all links now point to v0.7.0 tag.

Signed-off-by: Rakshith R <rar@redhat.com>
2023-06-28 20:38:29 +05:30
Rakshith R 1af70aca60 csi: update cephcsi to v3.9.0
This commit updates cephcsi image to
v3.9.0 release and also removes support
for v3.7.x.

refer:
https://github.com/ceph/ceph-csi/releases/tag/v3.8.0

Signed-off-by: Rakshith R <rar@redhat.com>
2023-06-28 20:38:29 +05:30
Rakshith R c488693cb3 csi: add SeLinuxMount: true Option to csidriver obj
This feature is alpha and available from k8s 1.25.
This enabled faster mounting of volumes using
RWOP access pod.

refer:
https://kubernetes.io/blog/2023/04/18/kubernetes-1-27-\
efficient-selinux-relabeling-beta/

Signed-off-by: Rakshith R <rar@redhat.com>
2023-06-28 20:23:51 +05:30
travisn 557a3e06cc core: api updates for controller runtime v0.15
For the controller runtime v0.15 there are some breaking
changes to the api that need to be updated.

Signed-off-by: travisn <tnielsen@redhat.com>
2023-06-22 10:33:28 -06:00
travisn bbfba5425f csi: ipv6 compatibility for requiring msgr2
The msgr2 conversion assumed the endpoints were formatted
with a single :, which is not compatible with ipv6.
Now if the endpoint ends with the v1 port, it will
simply update the prefix to v2.

Signed-off-by: travisn <tnielsen@redhat.com>
2023-03-28 15:13:51 -06:00
Madhu Rajanna 4c710de791 csi: make AttachRequired as configurable
adding a option to make AttachRequired field
as configurable and added a comment to explain
the consequences of changing the default value

resolves: #11805

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2023-03-22 12:55:32 +01:00
Madhu Rajanna 3017d563f2 csi: remove default-fstype for cephfs
we dont need to have fstype for cephfs
pvc, removing the unwanted argument
for cephfs.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2023-03-22 12:55:32 +01:00
Madhu Rajanna 4bdab21db0 nfs: add csi-attacher to NFS provisioner
Add attacher sidecar to NFS provisioner pod
to avoid mounting RWO volumes on two nodes

details: https://github.com/rook/rook/issues/10692

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2023-03-22 12:55:32 +01:00
travisn 0484a3973f csi: update port to 3300 if msgr2 is required
When msgr2 is required, ensure the mon endpoints passed to
the csi configmap are on port 3300. The mons will be
listening on both 6789 and 3300. Existing volumes can
continue using port 6789 while new volumes will use
port 3300.

Signed-off-by: travisn <tnielsen@redhat.com>
2023-03-10 10:34:56 -07:00
Madhu Rajanna b01180580c csi: update cephcsi to v3.8.0
updating the cephcsi image to v3.8.0
release and also removing support for
3.6.0 as its deprecated and not supported
any more.

More details at
https://github.com/ceph/ceph-csi/releases/tag/v3.8.0
and https://github.com/ceph/ceph-csi/tree/release-v3.8
\#ceph-csi-container-images-and-release-compatibility

fixes #11688

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2023-02-22 15:49:36 +01:00
Rakshith R 8b9ded1f77 csi: add option to enable read affinity for rbd volumes
This commit adds code to supply variables required
to enable read affinity for rbd volumes.
It leverages `read_from_replica=localize,crush_locations=key:value`
krbd map option from ceph to serve reads from the most local OSD.
refer:
https://docs.ceph.com/en/latest/man/8/rbd/#kernel-rbd-krbd-options

Signed-off-by: Rakshith R <rar@redhat.com>
2023-02-16 19:09:39 +05:30
Madhu Rajanna d7dc12d834 csi: provide way to set cephfs kernel mount options
Exposing CSI configuration for the user to
set the cephfs kernel mount options.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2023-02-10 08:26:41 +01:00