Add --skip-monitoring-endpoint to create-external-cluster-resources.py
to allow the script to work with Ceph clusters without an enabled
prometheus module.
Document the new flag in external-cluster.md and add relevant unit tests
Signed-off-by: Angelos Kolaitis <neoaggelos@gmail.com>
if restricted permission was on the . was appended to k8s secret and
failed to create the secret so added a alias name is user wan't to suuport
pool with . in name
Signed-off-by: parth-gr <paarora@redhat.com>
With the release of ceph v17.2.6, the examples and the base
image for the operator are updated to pick up the latest
and greatest.
Signed-off-by: travisn <tnielsen@redhat.com>
ClusterID uniquely identifies a cluster. It is used as a prefix to
nslookup exported services.
For example: <clusterid>.<svc>.<ns>.svc.clusterset.local
Signed-off-by: sp98 <sapillai@redhat.com>
The canary test is waiting for the prometheus module,
which is now disabled by default. For the canary test,
we need to enable the prometheus module for the external
cluster test.
Signed-off-by: travisn <tnielsen@redhat.com>
if the rge endint is not reachable don't block the creation
of rbd and cephfs sc, just print the error instead of raising exception
Signed-off-by: parth-gr <paarora@redhat.com>
adding a option to make AttachRequired field
as configurable and added a comment to explain
the consequences of changing the default value
resolves: #11805
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
The defaults in CRDs cause an update and trigger a new
reconcile if the value is not set. For the key rotation
setting, the default was only being updated when the kms
feature was enabled. This update was causing the reconcile
to fail in the kms tests. With the default now in code,
the default can remain empty and no cr update will trigger
a new reconcile unexpectedly.
Signed-off-by: travisn <tnielsen@redhat.com>
The rgw dashboard can be disabled by the setting in the
CephObjectStore `gateway.dashboardEnabled` if set to false.
Signed-off-by: xiaobaowen <xiaobaowen@deeproute.ai>
This commit adds functionality to be able to rotate
key encryption key of encrypted PVC backed OSDs.
Necessary changes such as adding update functionality
to kms and rbac changes are made as well.
Signed-off-by: Rakshith R <rar@redhat.com>
This commit adds KeyRotationSpec to cephcluster CR
to support encryption key rotation feature.
If enabled Rook will create a cronjob for each
encrypted PVC based OSD with given schedule set
to rotate their respective key encryption key.
Signed-off-by: Rakshith R <rar@redhat.com>
If the device class property is specified on any pool,
it must be specified on all pools so the pg autoscaler
will remain healthy.
Signed-off-by: travisn <tnielsen@redhat.com>
When the alerts were updated from the ceph repo, the cephadm
alerts were removed, now we also remove two other alerts that
don't apply to rook clusters. The pool growth warning alert
and prometheus job missing alerts need to be removed
as also seen in https://github.com/rook/rook/pull/10109.
Signed-off-by: travisn <tnielsen@redhat.com>
if a cluster won't use the deafult realm and try to
execute the python script it will fail to vaildate rgw
as the rgw-admin-user would be created on default realm
So creating user in specific realm if the realm name is passed
Signed-off-by: parth-gr <paarora@redhat.com>
Add a hostNetwork option for a Ganesha server.
This allows you to use host networking for the cluster but still
use regular pod networking for NFS Ganesha servers
Signed-off-by: Richard Bateman <taxilian@gmail.com>
With the new mgr HA implementation (based on readiness probe) we
don't need the mgr sidecar (live-watch) anymore. This commit is
intended to remove all the related code.
Signed-off-by: Redouane Kachach <rkachach@redhat.com>