Commit Graph
570 Commits
Author SHA1 Message Date
travisn 6f8e42422d core: fix golang linter issues with variables in loops
Loop variables cannot be reliably uses since they will
change with each iteration. Update these loop variable
uses to be safe by indexing the slice rather than
using the loop variable directly.

Also suppress the linter issues for passwords used
in tests.

Signed-off-by: travisn <tnielsen@redhat.com>
2023-12-05 14:14:58 -07:00
subhamkrai 28cc1ebc55 core: remove webhook & controller-runtime from apis
This commits removes controller-runtime dependencies
from the apis dir and to achieve that we are removing
webhook.

Signed-off-by: subhamkrai <srai@redhat.com>
2023-12-01 14:15:40 +05:30
gauravsitlani 3d0049c547 core: operator to skip reconcile of mgr, rgw, mds and rbd-mirror daemons in debug
During certain maintenance tasks the admin will own running
operations on the ceph mgr, rgw, mds and rbd-mirror daemons
and the operator should not interfere with those operations.

Co-authored-by: gauravsitlani <gaurav.sitlani@live.com>
Signed-off-by: subhamkrai <srai@redhat.com>
2023-11-21 20:14:16 +05:30
travisn 03d077aa6b core: remove support for ceph pacific
Pacific is end of life and no longer necessary to
support in Rook with v1.13.

Signed-off-by: travisn <tnielsen@redhat.com>
2023-11-14 17:07:03 -07:00
parth-gr 46c241433d object: improve the error handling for multisite objs
here is the https://go.dev/play/p/SS9Q-dAiIx3 example which says the
error handling was wrongly implemented

Signed-off-by: parth-gr <paarora@redhat.com>
2023-11-14 15:12:15 +05:30
travisn 80244fa6ba object: change is_master from string to bool
In Reef the is_master changed from a string to a bool
so we must update the type for proper json
serialization.

Signed-off-by: travisn <tnielsen@redhat.com>
2023-10-25 15:26:17 -06:00
Blaine Gardner 3c7499facf test: mark unit test secrets as not secret
There are 2 cases of randomly generated secrets copied into Rook's unit
test code that have been flagged by Gitleaks. Add a comment to both
cases to help the tool understand that these aren't real production
secrets -- just unit test stand-ins.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2023-10-11 16:42:29 -06:00
Blaine Gardner e74333ddcd Merge pull request #12633 from thotz/cosi-user-creation
object: create cosi user for each object store
2023-10-04 10:05:36 -06:00
Redouane Kachach b3dd74ea20 docs: fixing some spelling issues
closes: https://github.com/rook/rook/issues/12987

Signed-off-by: Redouane Kachach <rkachach@redhat.com>
2023-10-03 13:50:17 +02:00
Jiffin Tony Thottan a941b3c33f object: create cosi user for each object store
Create each cosi user for each object store and secret which holds
credentials.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2023-09-19 13:48:58 +05:30
guoguangwu 235ac293ff core: import packages only once
Signed-off-by: guoguangwu <guoguangwu@magic-shield.com>
2023-09-16 13:40:17 +08:00
Sebastian Hasler 041fc1a71c object: unique username for OBC even when preceding OBC was retained
For an OBC's name we cannot simply use the OBC's namespace and name,
because they can be reused, while the preceding bucket might be
retained by reclaimPolicy. (Commit 2733375ca4 also didn't solve
this issue, as it is an intra-cluster issue.) Therefore we instead
use the OBC's UID which should be unique within the cluster and
across clusters.

Signed-off-by: Sebastian Hasler <sebastian.hasler@stuvus.uni-stuttgart.de>
2023-09-11 23:31:39 +02:00
Blaine Gardner 17f0072d9d Merge pull request #12778 from BlaineEXE/multus-allow-cidr-spec
multus: allow using NADs without inspectable CIDRs
2023-09-07 13:42:41 -06:00
Blaine Gardner 3c43268d0a multus: detect network CIDRs via canary
Change how Rook detects network CIDRs for Multus networks. The IPAM
configuration is only defined as an arbitrary string JSON blob with a
"type" field and nothing more. Rook's detection of CIDRs for whereabouts
had already grown out of date since the initial implementation.
Additionally, Rook did not support DHCP IPAM, which is a reasonable
choice for users. And more, Rook did not support CNI plugin chaining,
which further complicates NADs. Based on the CNI spec, network chaning
can result in any changes to network CIDRs from the first-given plugin.

All these problems make it more and more difficult for Rook to support
Multus by inspecting the NAD itself to predict network CIDRs. Instead,
it is better for Rook to treat the CNI process as a black box. To
preserve legacy functionality of auto-detecting networks and to make
that as robust as possible, change to a canary-style architecture like
that used for Ceph mons, from which Rook will detect the network CIDRs
if possible.

Also allow users to specify overrides for CIDR ranges. This allows Rook
to still support esoteric and unexpected NAD or network configurations
where a CIDR range is not detectable or where the range detected would
be incomplete. Because it may be impossible for Rook to understand the
network CIDRs wholistically while residing only on a portion of the
network, this feature should have been present from Multus's inception.

Improving CIDR auto-detection and allowing users to specify overrides
for auto-detected CIDRs rounds out Rook's Multus support for CephCluster
(core/RADOS) installations. No further architectural changes should be
needed for CephClusters as regards application of public/cluster network
CIDRs for Multus networks.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2023-09-07 10:12:55 -06:00
Travis Nielsen 3f67a7861f Merge pull request #12791 from subhamkrai/restart-ceph-pods
core: restart ceph daemons when network updated
2023-09-01 08:42:08 -06:00
subhamkrai 29d2b6a071 core: restart ceph daemons when network updated
We need to restart all the ceph daemons whenever
cephCluster network settings are modified like
requiremsgr2, encryption and compression. This
required for Ceph to consider the new settings
it require new ceph daemons all over.

Signed-off-by: subhamkrai <srai@redhat.com>
2023-09-01 11:30:48 +05:30
Jiffin Tony Thottan b39e813290 object: avoid creating same bucket for two different OBC
If bucket exists for Provision(), then check whether user in the OBC and
owner of bucket are same.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2023-08-28 18:19:24 +05:30
travisn 2b1cc4c7b8 object: allow creating an object user in different namespace
The object user was previously required to be created in the
same namespace as the object store and the cluster. Now,
the object user can be reconciled even in a different namespace
from the cluster and object store. The namespace would be specified
in the object user CR.

Signed-off-by: travisn <tnielsen@redhat.com>
2023-08-25 11:54:57 -06:00
Lucas Henry c948183c0e operator: fix formatting of some logger methods
Some logging instructions use formatting syntax `%q`, but the logging method is
`Info` or `Debug` instead of `Debugf` and `Infof`. As a result, the arguments of
the method were concatenated instead of formatted properly.

Signed-off-by: Lucas Henry <polyedre@disroot.org>
2023-08-04 15:45:54 +02:00
Blaine Gardner 5979b38162 Merge pull request #12560 from polyedre/do-not-add-objectstore-endpoint-to-zone-when-sync-is-disabled
object: do not add objectstore endpoint to zone when sync is disabled
2023-07-25 15:31:42 -06:00
Jiffin Tony Thottan 1bf33f125e object: update ceph cosi driver image to v0.1.1
Update the ceph cosi driver image to v0.1.1, so that it can
work on both amd and arm platforms.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2023-07-20 14:19:15 +05:30
Lucas Henry 564afef4c7 object: do not add objectstore endpoint to zone when sync is disabled
Gateways that do not run the sync threads should not be accessible from one of
the Zone endpoint. If this is the case, the synchronization might stop working.

When the CephObjectStore has the option
`spec.gateway.disableMultisiteSyncTraffic` set to `true`, we must ensure that
the objectstore endpoint is not present in the Zone endpoint.

Signed-off-by: Lucas Henry <polyedre@disroot.org>
2023-07-20 08:34:41 +02:00
travisn 4c98669148 cosi: handle deletion of the cosi driver
The controller was attempting to delete the cosi driver
again and again, always failing the reconcile when the
driver did not exist. Since the desired state is for the
driver not to exist when disabled, return a successful
reconcile.

Signed-off-by: travisn <tnielsen@redhat.com>
2023-07-18 14:53:22 -06:00
travisn 990cb40043 cosi: change the default deployment strategy to never
While experimental, the cosi driver should not be enabled by
default.

Signed-off-by: travisn <tnielsen@redhat.com>
2023-07-18 14:35:54 -06:00
Travis Nielsen 2e7f9045ab Merge pull request #12460 from pgoron/admin-caps-spelling
object: align spelling of user admin capabilities with ceph
2023-07-18 13:23:15 -06:00
Travis Nielsen 91fea5395e Merge pull request #12415 from thotz/ceph-cosi-driver
object: adding ceph cosi driver
2023-07-18 12:12:12 -06:00
Jiffin Tony Thottan b48dc8a335 object: intial cosi driver controller design
Adding CephCOSIDriver CRD and controller. The controller will bring up
the ceph cosi driver when first object store is created in the rook
operator namespace. Then admin can defined COSI CRDs like BucketClass
and BucketAccessClass for different object stores deployed via Rook.
Using the BucketClass and BucketAccessClass, user can define
BucketAccess for backend bucket in the RGW. The CephCOSIDriver CRD
defines configuration options for ceph cosi driver. In the first version
its usability is minimal. Even if it is not defined Rook will bring up
the ceph cosi driver with default values.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2023-07-18 22:49:41 +05:30
Lucas Henry 393d09347e rgw: add option to disable synchronization traffic
Some users want to deploy two CephObjectStores for a single Zone. The first
configures RGWs to process the synchronization of the data, while the second
CephObjectStore configures the client RGWs.

Currently, this can be implemented by setting the RGW option
'rgw_run_sync_thread' in the 'rook-config-override' ConfigMap, though it is not
really user friendly.

Ref: https://docs.ceph.com/en/latest/radosgw/config-ref/#confval-rgw_run_sync_thread

This commit adds a new option in the CephObjectStore CRD as defined in issue
https://github.com/rook/rook/issues/12272. The new option
'disableMultisiteSyncTraffic' determine whether the operator should disable the
multisite sync threads for the RGWs.

If the option is set to 'false', or if the option is not specified, the operator
does nothing. This ensures that the multisite sync threads will not be enabled
for users that disabled explicitely the multisite sync threads either manually
or with the 'rook-config-override' ConfigMap.

This commit also recommends to use two objectstore when scaling Ceph Objectstore
Multisite replication, with one objectstore configured with disabled replication
traffic.

Signed-off-by: Lucas Henry <polyedre@disroot.org>
2023-07-17 09:27:20 +02:00
Peter Goron 40eed236cf object: align spelling of user admin capabilities with ceph
users & buckets admin capabilities aren't spelled the same
way between rook crd (singular) and ceph (plural). It's a bit
misleading when comparing ceph admin cap and rook users.

Signed-off-by: Peter Goron <peter.goron@gmail.com>
2023-07-01 19:05:26 +02:00
travisn 4ff18dadf4 object: remove obsolete bucket health checker removal
The bucket health checker was removed in 1.10. Now in 1.12
we no longer need this removal of the bucket health
checker since it will no longer exist to remove.

Signed-off-by: travisn <tnielsen@redhat.com>
2023-06-28 16:07:51 -06:00
travisn 557a3e06cc core: api updates for controller runtime v0.15
For the controller runtime v0.15 there are some breaking
changes to the api that need to be updated.

Signed-off-by: travisn <tnielsen@redhat.com>
2023-06-22 10:33:28 -06:00
Travis Nielsen d7dcf58f7c Merge pull request #12406 from polyedre/confusing-message
Fix confusing successful message when reconciling CephObjectStoreUser
2023-06-20 13:12:55 -06:00
Lucas Henry 87bc3dfcdc operator: remove confusing successful message when reconciling CephObjectStoreUser
When creating a CephObjectStoreUser with a value spec.store that refers to an
unexisting CephObjectStore, after the reconciliation loop the
CephObjectStoreUser is in the ReconcileFailed state. However, a
ReconcileSucceeded event is created with this message:

"successfully configured CephObjectStoreUser"

The success message results of the return value for the error which is currently
`nil`. Let's replace it with the error message.

Signed-off-by: Lucas Henry <polyedre@disroot.org>
2023-06-20 11:02:04 +02:00
Jiffin Tony Thottan 6ea24cb11b object: add ssl ref in cephobjectstore user secret
There is no reference for ssl in cephobjectstore Secret, so users won't
have much idea why tls secret need to used. Hence give reference
object stores tls secret ref in the Secret.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2023-06-09 12:42:35 +05:30
Travis Nielsen 6417ed4047 Merge pull request #12256 from thotz/add-missing-caps-object-user
object: add missing caps for object store user
2023-05-30 16:37:18 -06:00
Jiffin Tony Thottan 1f45cfa581 object: use networkspec from clusterinfo spec while running radosgw-admin
The radosgw-admin command uses the network spec from ceph cluster spec
in object context but it is not filled properly in the object package.
But with PR 10898, network spec is available in clusterinfo which can
be used directly. Also removed cluserspec from object context.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2023-05-30 11:06:03 +05:30
Jiffin Tony Thottan ad0c000e6a object: add missing caps for object store user
Lot of new caps added to rgw users, reflecting same changes on the
object store user CRD.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2023-05-26 17:36:00 +05:30
sp98 e87338fbc4 core: skip OBC and Notification controllers
Skip running Object Bucket and Object bucket notification
controllers based on env variable.

Signed-off-by: sp98 <sapillai@redhat.com>
2023-04-24 19:16:06 +05:30
travisn 609ac91cb1 core: update default image to ceph v17.2.6
With the release of ceph v17.2.6, the examples and the base
image for the operator are updated to pick up the latest
and greatest.

Signed-off-by: travisn <tnielsen@redhat.com>
2023-04-11 14:07:11 -06:00
Jiffin Tony Thottan 01a3dd0baf object: check obc provisioner for bucket notification
obc-label-controller needs to check only obc provisioned by Rook operator.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2023-03-31 14:56:18 +05:30
Travis Nielsen e3fa098c1d Merge pull request #11908 from thenamehasbeentake/enableRGWDashboard_by_custom
rgw: enableRGWDashboard can be configured by custom
2023-03-17 08:18:52 -06:00
parth-gr 8e317ee074 ci: update golangci-lint version as it fails for some k8s version in 1.10
Closes: https://github.com/rook/rook/issues/11896

Signed-off-by: parth-gr <paarora@redhat.com>
2023-03-16 20:59:22 +05:30
root 253d4123f6 rgw: allow the rgw dashboard to be disabled
The rgw dashboard can be disabled by the setting in the
CephObjectStore `gateway.dashboardEnabled` if set to false.

Signed-off-by: xiaobaowen <xiaobaowen@deeproute.ai>
2023-03-16 22:58:32 +08:00
Blaine Gardner 29ad3282a0 Merge pull request #11665 from BlaineEXE/object-make-obc-gen-user-name-work-for-multisite
object: make OBC genUserID unique across clusters
2023-03-01 15:29:09 -07:00
parth-gr 96ea7817f8 external: add realm support for external cluster
if a cluster won't use the deafult realm and try to
execute the python script it will fail to vaildate rgw
as the rgw-admin-user would be created on default realm
So creating user in specific realm if the realm name is passed

Signed-off-by: parth-gr <paarora@redhat.com>
2023-03-01 20:55:48 +05:30
parth-grandBlaine Gardner 69ae9569cd build: update k8s version to 1.26.1
Update the Kubernetes API version used to 1.26.1, and start testing
against Kubernetes version 1.26.1 in CI.

Co-authored-by: parth-gr <paarora@redhat.com>
Co-authored-by: Blaine Gardner <blaine.gardner@redhat.com>

Signed-off-by: parth-gr <paarora@redhat.com>
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2023-02-23 20:18:47 -07:00
Liang Zheng c81aa7f856 object: update os user caps
Removing user caps will be skipped as the UserCaps is empty, which will cause updating user caps to not take effect.

Signed-off-by: Liang Zheng <zhengliang0901@gmail.com>
2023-02-21 17:06:41 +08:00
parth-gr a84daf9bf0 core: change io/ioutil package to use io and os package
few functions got change as they were deprecated
for ex: ioutil.Readfile change to os.Readfile
ioutil.TempFile change to os.CreateTemp
And fixed golang-ci-lint-issues

Signed-off-by: parth-gr <paarora@redhat.com>
2023-02-17 20:38:29 +05:30
Travis Nielsen ace2e152e8 Merge pull request #11673 from travisn/rgw-pool-pgs
object: RGW metadata pg count reduction on 16.2.11
2023-02-15 12:20:23 -07:00
Travis Nielsen 3dabc6dcb6 Merge pull request #11317 from avanthakkar/introduce-ceph-exporter
core: introduce ceph-exporter
2023-02-15 11:59:05 -07:00