Loop variables cannot be reliably uses since they will
change with each iteration. Update these loop variable
uses to be safe by indexing the slice rather than
using the loop variable directly.
Also suppress the linter issues for passwords used
in tests.
Signed-off-by: travisn <tnielsen@redhat.com>
This commits removes controller-runtime dependencies
from the apis dir and to achieve that we are removing
webhook.
Signed-off-by: subhamkrai <srai@redhat.com>
During certain maintenance tasks the admin will own running
operations on the ceph mgr, rgw, mds and rbd-mirror daemons
and the operator should not interfere with those operations.
Co-authored-by: gauravsitlani <gaurav.sitlani@live.com>
Signed-off-by: subhamkrai <srai@redhat.com>
In Reef the is_master changed from a string to a bool
so we must update the type for proper json
serialization.
Signed-off-by: travisn <tnielsen@redhat.com>
There are 2 cases of randomly generated secrets copied into Rook's unit
test code that have been flagged by Gitleaks. Add a comment to both
cases to help the tool understand that these aren't real production
secrets -- just unit test stand-ins.
Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
For an OBC's name we cannot simply use the OBC's namespace and name,
because they can be reused, while the preceding bucket might be
retained by reclaimPolicy. (Commit 2733375ca4 also didn't solve
this issue, as it is an intra-cluster issue.) Therefore we instead
use the OBC's UID which should be unique within the cluster and
across clusters.
Signed-off-by: Sebastian Hasler <sebastian.hasler@stuvus.uni-stuttgart.de>
Change how Rook detects network CIDRs for Multus networks. The IPAM
configuration is only defined as an arbitrary string JSON blob with a
"type" field and nothing more. Rook's detection of CIDRs for whereabouts
had already grown out of date since the initial implementation.
Additionally, Rook did not support DHCP IPAM, which is a reasonable
choice for users. And more, Rook did not support CNI plugin chaining,
which further complicates NADs. Based on the CNI spec, network chaning
can result in any changes to network CIDRs from the first-given plugin.
All these problems make it more and more difficult for Rook to support
Multus by inspecting the NAD itself to predict network CIDRs. Instead,
it is better for Rook to treat the CNI process as a black box. To
preserve legacy functionality of auto-detecting networks and to make
that as robust as possible, change to a canary-style architecture like
that used for Ceph mons, from which Rook will detect the network CIDRs
if possible.
Also allow users to specify overrides for CIDR ranges. This allows Rook
to still support esoteric and unexpected NAD or network configurations
where a CIDR range is not detectable or where the range detected would
be incomplete. Because it may be impossible for Rook to understand the
network CIDRs wholistically while residing only on a portion of the
network, this feature should have been present from Multus's inception.
Improving CIDR auto-detection and allowing users to specify overrides
for auto-detected CIDRs rounds out Rook's Multus support for CephCluster
(core/RADOS) installations. No further architectural changes should be
needed for CephClusters as regards application of public/cluster network
CIDRs for Multus networks.
Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
We need to restart all the ceph daemons whenever
cephCluster network settings are modified like
requiremsgr2, encryption and compression. This
required for Ceph to consider the new settings
it require new ceph daemons all over.
Signed-off-by: subhamkrai <srai@redhat.com>
If bucket exists for Provision(), then check whether user in the OBC and
owner of bucket are same.
Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
The object user was previously required to be created in the
same namespace as the object store and the cluster. Now,
the object user can be reconciled even in a different namespace
from the cluster and object store. The namespace would be specified
in the object user CR.
Signed-off-by: travisn <tnielsen@redhat.com>
Some logging instructions use formatting syntax `%q`, but the logging method is
`Info` or `Debug` instead of `Debugf` and `Infof`. As a result, the arguments of
the method were concatenated instead of formatted properly.
Signed-off-by: Lucas Henry <polyedre@disroot.org>
Update the ceph cosi driver image to v0.1.1, so that it can
work on both amd and arm platforms.
Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
Gateways that do not run the sync threads should not be accessible from one of
the Zone endpoint. If this is the case, the synchronization might stop working.
When the CephObjectStore has the option
`spec.gateway.disableMultisiteSyncTraffic` set to `true`, we must ensure that
the objectstore endpoint is not present in the Zone endpoint.
Signed-off-by: Lucas Henry <polyedre@disroot.org>
The controller was attempting to delete the cosi driver
again and again, always failing the reconcile when the
driver did not exist. Since the desired state is for the
driver not to exist when disabled, return a successful
reconcile.
Signed-off-by: travisn <tnielsen@redhat.com>
Adding CephCOSIDriver CRD and controller. The controller will bring up
the ceph cosi driver when first object store is created in the rook
operator namespace. Then admin can defined COSI CRDs like BucketClass
and BucketAccessClass for different object stores deployed via Rook.
Using the BucketClass and BucketAccessClass, user can define
BucketAccess for backend bucket in the RGW. The CephCOSIDriver CRD
defines configuration options for ceph cosi driver. In the first version
its usability is minimal. Even if it is not defined Rook will bring up
the ceph cosi driver with default values.
Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
Some users want to deploy two CephObjectStores for a single Zone. The first
configures RGWs to process the synchronization of the data, while the second
CephObjectStore configures the client RGWs.
Currently, this can be implemented by setting the RGW option
'rgw_run_sync_thread' in the 'rook-config-override' ConfigMap, though it is not
really user friendly.
Ref: https://docs.ceph.com/en/latest/radosgw/config-ref/#confval-rgw_run_sync_thread
This commit adds a new option in the CephObjectStore CRD as defined in issue
https://github.com/rook/rook/issues/12272. The new option
'disableMultisiteSyncTraffic' determine whether the operator should disable the
multisite sync threads for the RGWs.
If the option is set to 'false', or if the option is not specified, the operator
does nothing. This ensures that the multisite sync threads will not be enabled
for users that disabled explicitely the multisite sync threads either manually
or with the 'rook-config-override' ConfigMap.
This commit also recommends to use two objectstore when scaling Ceph Objectstore
Multisite replication, with one objectstore configured with disabled replication
traffic.
Signed-off-by: Lucas Henry <polyedre@disroot.org>
users & buckets admin capabilities aren't spelled the same
way between rook crd (singular) and ceph (plural). It's a bit
misleading when comparing ceph admin cap and rook users.
Signed-off-by: Peter Goron <peter.goron@gmail.com>
The bucket health checker was removed in 1.10. Now in 1.12
we no longer need this removal of the bucket health
checker since it will no longer exist to remove.
Signed-off-by: travisn <tnielsen@redhat.com>
When creating a CephObjectStoreUser with a value spec.store that refers to an
unexisting CephObjectStore, after the reconciliation loop the
CephObjectStoreUser is in the ReconcileFailed state. However, a
ReconcileSucceeded event is created with this message:
"successfully configured CephObjectStoreUser"
The success message results of the return value for the error which is currently
`nil`. Let's replace it with the error message.
Signed-off-by: Lucas Henry <polyedre@disroot.org>
There is no reference for ssl in cephobjectstore Secret, so users won't
have much idea why tls secret need to used. Hence give reference
object stores tls secret ref in the Secret.
Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
The radosgw-admin command uses the network spec from ceph cluster spec
in object context but it is not filled properly in the object package.
But with PR 10898, network spec is available in clusterinfo which can
be used directly. Also removed cluserspec from object context.
Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
With the release of ceph v17.2.6, the examples and the base
image for the operator are updated to pick up the latest
and greatest.
Signed-off-by: travisn <tnielsen@redhat.com>
The rgw dashboard can be disabled by the setting in the
CephObjectStore `gateway.dashboardEnabled` if set to false.
Signed-off-by: xiaobaowen <xiaobaowen@deeproute.ai>
if a cluster won't use the deafult realm and try to
execute the python script it will fail to vaildate rgw
as the rgw-admin-user would be created on default realm
So creating user in specific realm if the realm name is passed
Signed-off-by: parth-gr <paarora@redhat.com>
Removing user caps will be skipped as the UserCaps is empty, which will cause updating user caps to not take effect.
Signed-off-by: Liang Zheng <zhengliang0901@gmail.com>
few functions got change as they were deprecated
for ex: ioutil.Readfile change to os.Readfile
ioutil.TempFile change to os.CreateTemp
And fixed golang-ci-lint-issues
Signed-off-by: parth-gr <paarora@redhat.com>