Commit Graph
911 Commits
Author SHA1 Message Date
Travis Nielsen a5180adb92 Merge pull request #16617 from Nordix/Sunnatillo/add-networkHost-field-cephMgr
mgr: add hostNetwork field to Manager spec
2025-11-06 09:28:19 -07:00
Sunnatillo b9a4685f65 mgr: add hostNetwork field to Manager spec
Add optinal hostnetwork field for Ceph Mgr to control whether the
mgr pods to run in host network. If unset, this defaults to
cluster level Network.HostNetwork value. This particulary useful
when user wants to restrict ceph mgr pod from exposing metrics
port in all host interfaces.

Signed-off-by: Sunnatillo <sunnat.samadov@est.tech>
2025-11-05 21:52:49 +02:00
Joshua Hoblitt 43f26534ed osd: add CephCluster.spec.storage.OSDMaxUpdatesInParallel
Configures the maximum number of OSDs to update in parallel.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-11-03 12:10:28 -07:00
Blaine Gardner c08a7742b0 Merge pull request #14821 from sp98/rgw-hpa
rgw: add scale subresource to CephObjectStore CR
2025-10-27 09:54:11 -06:00
Travis Nielsen 4aa9bfee40 Merge pull request #16507 from fullstackjam/fix-rbac-labels-null
fix: add missing labels to RBAC resources to prevent ArgoCD drift
2025-10-09 11:28:29 -06:00
Tim Buchwaldt 8db5274703 operator: allow overriding MDS cache memory limit
This change introduces support for setting the ceph cache memory limit
ratios that were previously hardcoded.
Codegen was drivey-by updated as the current version errored.

Resolves #16551

Signed-off-by: Tim Buchwaldt <tim.buchwaldt@deepl.com>
2025-10-07 09:15:56 +02:00
Travis Nielsen 535f9f0868 build: add csi operator image to images.txt
With the addition of the csi operator, the csi operator
image is added to the list of images that are required
for deploying rook.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-10-02 08:04:24 -06:00
Madhu Rajanna 5ea7410d58 csi: update operator to 0.4.1
Updating the operator dependency to
0.4.1

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2025-10-02 15:27:01 +02:00
fullstackjam 8656bd493c helm: add missing labels to ConfigMap, SCC, and ServiceAccount resources
Add consistent metadata labels to resources that were missing them:
- configmap.yaml: Add labels to rook-ceph-operator-config ConfigMap
- securityContextConstraints.yaml: Add labels to both rook-ceph and rook-ceph-csi SCCs
- serviceaccount.yaml: Add labels to 6 CSI ServiceAccounts that were missing them

All new labels use the unified library.rook-ceph.labels template for consistency.
Regenerated deploy/examples/common.yaml and deploy/examples/csi/nfs/rbac.yaml
to reflect the updated label definitions.

This addresses reviewer feedback about missing labels in non-RBAC resources
and ensures consistent labeling across all Rook Ceph Helm chart resources.

Signed-off-by: fullstackjam <fullstackjam@outlook.com>
2025-10-01 14:43:29 +08:00
fullstackjam f635d96ae9 helm: add missing labels to RBAC resources to prevent ArgoCD drift
This PR addresses ArgoCD drift detection issues by adding consistent
metadata labels to RBAC resources in Rook Ceph Helm charts. The problem
occurs because many RBAC resources lack metadata labels, causing ArgoCD
to interpret them as 'labels: null' and report continuous drift.

Changes made:
- Added consistent labels to all RBAC templates in rook-ceph and library charts
- Created _recommended-labels.tpl template for standardized labeling
- Removed app.kubernetes.io/component label per consideRatio feedback to avoid scope creep
- Suppressed Helm-specific labels (version, instance, managed-by, created-by, chart) from static RBAC files
- Regenerated deploy/examples/common.yaml and deploy/examples/csi/nfs/rbac.yaml

Labels added to RBAC resources:
- operator: rook
- storage-backend: ceph
- app.kubernetes.io/name: rook-ceph
- app.kubernetes.io/part-of: rook-ceph-operator

Impact:
- Resolves ArgoCD 'OutOfSync' issues for Rook RBAC resources
- Improves resource identification and management
- Provides consistent labeling across all Rook Helm charts
- No functional changes to RBAC permissions
- Focuses on essential labels to avoid over-engineering

This addresses review feedback from travisn and consideRatio to maintain
scope and ensure static RBAC files only contain meaningful labels.

Signed-off-by: fullstackjam <fullstackjam@outlook.com>
2025-10-01 14:43:25 +08:00
Erik Sundell e7a704ccf1 helm: remove legacy PodSecurityPolicy resource
The helm charts allowed rendering a PodSecurityPolicy resource via the
configuration `pspEnable`. This option is removed and all references to
psp, PodSecurityPolicy, and Pod Security Policy have been cleaned up.

The PSP resource was only rendered if k8s version was lower than 1.25
when it was still supported. It has been deprecated since k8s 1.21.

Signed-off-by: Erik Sundell <erik@sundellopensource.se>
2025-09-30 18:25:35 +02:00
Blaine Gardner 85dc50f66a Merge pull request #16542 from jhoblitt/feature/cephor-printcolumn-phase
core: add PHASE column to cephor
2025-09-26 12:21:25 -06:00
Blaine Gardner 2397e2b90d Merge pull request #16543 from jhoblitt/feature/cephnfs-printcolumn-phase
core: add PHASE column to cephnfs
2025-09-26 12:20:46 -06:00
Joshua Hoblitt 5ee982f1e1 core: add PHASE column to cephnfs
The current behavior does not print the PHASE column, as most other
CRDs do. E.g.:

```
 ~ $ k get cephnfs nfs1
NAME   AGE
nfs1   45d
```

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-09-26 09:39:32 -07:00
Joshua Hoblitt 8866d47d92 core: add PHASE column to cephbn
The current behavior does not print the PHASE column, as most other
CRDs do. E.g.:

```
~ $ k get cephbn chorus
NAME     AGE
chorus   10d
```

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-09-26 09:28:49 -07:00
Joshua Hoblitt 6d9c884259 core: add PHASE column to cephor
The current behavior does not print the PHASE column, as most other
CRDs do. E.g.:

```
 ~ $ k get cephor lfa
NAME   AGE
lfa    45d
```

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-09-26 09:27:15 -07:00
SantoshPillai 67b44b47df rgw: make hpa update rgw resource
Signed-off-by: Santosh Pillai <sapillai@redhat.com>
2025-09-19 12:22:30 +05:30
Travis Nielsen 67e48bb701 Merge pull request #16494 from consideRatio/pr/helm-refactor-2
helm: refactoring to modernize templates
2025-09-18 13:53:21 -06:00
subham rai 68e0dfbb8b Merge pull request #16496 from jhoblitt/maint/fix-zonegroup-and-zone-field-desc
core: fix ObjectZoneSpec.ZoneGroup and ObjectZoneGroupSpec.Realm field descriptions
2025-09-17 17:16:25 +05:30
dependabot[bot] 5a980c8b7a build(deps): bump the k8s-dependencies group with 8 updates
Bumps the k8s-dependencies group with 8 updates:

| Package | From | To |
| --- | --- | --- |
| [k8s.io/api](https://github.com/kubernetes/api) | `0.33.4` | `0.34.0` |
| [k8s.io/apiextensions-apiserver](https://github.com/kubernetes/apiextensions-apiserver) | `0.33.4` | `0.34.0` |
| [k8s.io/apimachinery](https://github.com/kubernetes/apimachinery) | `0.33.4` | `0.34.0` |
| [k8s.io/cli-runtime](https://github.com/kubernetes/cli-runtime) | `0.33.4` | `0.34.0` |
| [k8s.io/client-go](https://github.com/kubernetes/client-go) | `0.33.4` | `0.34.0` |
| [k8s.io/cloud-provider](https://github.com/kubernetes/cloud-provider) | `0.33.4` | `0.34.0` |
| [sigs.k8s.io/controller-runtime](https://github.com/kubernetes-sigs/controller-runtime) | `0.21.0` | `0.22.0` |
| [sigs.k8s.io/mcs-api](https://github.com/kubernetes-sigs/mcs-api) | `0.2.0` | `0.3.0` |

Updates `k8s.io/api` from 0.33.4 to 0.34.0
- [Commits](https://github.com/kubernetes/api/compare/v0.33.4...v0.34.0)

Updates `k8s.io/apiextensions-apiserver` from 0.33.4 to 0.34.0
- [Release notes](https://github.com/kubernetes/apiextensions-apiserver/releases)
- [Commits](https://github.com/kubernetes/apiextensions-apiserver/compare/v0.33.4...v0.34.0)

Updates `k8s.io/apimachinery` from 0.33.4 to 0.34.0
- [Commits](https://github.com/kubernetes/apimachinery/compare/v0.33.4...v0.34.0)

Updates `k8s.io/cli-runtime` from 0.33.4 to 0.34.0
- [Commits](https://github.com/kubernetes/cli-runtime/compare/v0.33.4...v0.34.0)

Updates `k8s.io/client-go` from 0.33.4 to 0.34.0
- [Changelog](https://github.com/kubernetes/client-go/blob/master/CHANGELOG.md)
- [Commits](https://github.com/kubernetes/client-go/compare/v0.33.4...v0.34.0)

Updates `k8s.io/cloud-provider` from 0.33.4 to 0.34.0
- [Commits](https://github.com/kubernetes/cloud-provider/compare/v0.33.4...v0.34.0)

Updates `sigs.k8s.io/controller-runtime` from 0.21.0 to 0.22.0
- [Release notes](https://github.com/kubernetes-sigs/controller-runtime/releases)
- [Changelog](https://github.com/kubernetes-sigs/controller-runtime/blob/main/RELEASE.md)
- [Commits](https://github.com/kubernetes-sigs/controller-runtime/compare/v0.21.0...v0.22.0)

Updates `sigs.k8s.io/mcs-api` from 0.2.0 to 0.3.0
- [Release notes](https://github.com/kubernetes-sigs/mcs-api/releases)
- [Changelog](https://github.com/kubernetes-sigs/mcs-api/blob/master/RELEASE.md)
- [Commits](https://github.com/kubernetes-sigs/mcs-api/compare/v0.2.0...v0.3.0)

---
updated-dependencies:
- dependency-name: k8s.io/api
  dependency-version: 0.34.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: k8s-dependencies
- dependency-name: k8s.io/apiextensions-apiserver
  dependency-version: 0.34.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: k8s-dependencies
- dependency-name: k8s.io/apimachinery
  dependency-version: 0.34.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: k8s-dependencies
- dependency-name: k8s.io/cli-runtime
  dependency-version: 0.34.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: k8s-dependencies
- dependency-name: k8s.io/client-go
  dependency-version: 0.34.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: k8s-dependencies
- dependency-name: k8s.io/cloud-provider
  dependency-version: 0.34.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: k8s-dependencies
- dependency-name: sigs.k8s.io/controller-runtime
  dependency-version: 0.22.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: k8s-dependencies
- dependency-name: sigs.k8s.io/mcs-api
  dependency-version: 0.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: k8s-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: subhamkrai <srai@redhat.com>
2025-09-16 10:30:46 -06:00
Joshua Hoblitt 8b58d68592 core: fix ObjectZoneSpec.ZoneGroup field description
Resolves this incorrect field description:

     ~ $ k explain cephobjectzone.spec.zoneGroup
    GROUP:      ceph.rook.io
    KIND:       CephObjectZone
    VERSION:    v1

    FIELD: zoneGroup <string>

    DESCRIPTION:
        The display name for the ceph users

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-09-16 09:12:20 -07:00
Joshua Hoblitt 1a1478a342 core: fix ObjectZoneGroupSpec.Realm field description
Resolves this incorrect field description:

     ~ $ k explain cephobjectzonegroup.spec.realm
    GROUP:      ceph.rook.io
    KIND:       CephObjectZoneGroup
    VERSION:    v1

    FIELD: realm <string>

    DESCRIPTION:
        The display name for the ceph users

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-09-16 09:08:50 -07:00
Erik Sundell 039f158950 helm: refactoring to modernize templates
This touches a lot where a typo could cause issues for someone, so I have self-
reviewed it many times line-by-line already.

There are a few types of changes:
- All resources get tied to their own YAML document separator (`---`)
  before their definition, reducing the risk of not separating resources
  correctly when rendering multiple into a file. I think the changes
  will fix edge case bugs for people with mutiple items listed in
  `cephFileSystems` and similar configuration.
- `toYaml ...` is made into `... | toYaml` consistently.
- `default A B` is made into `B | default A` consistently.
- Consistent whitespace chomping, so instead of `{{ end }}` you would
  find `{{- end }}` typically. The system is that you should chomp left
  almost all the time, and almost all the time _not_ chomp right. You
  would chomp right in the beginning of a file or helper function in
  order to clear some initial whitespace, otherwise not.
- Multiline helm template comments `{{- /* ... */ }}` get their content
  indented 2 spaces.
- List items are consistently rendered with two spaces of indentation.
- `kind` is put before `apiVersion` consistently, to follow a practice
  observed partially in the repo.
- Calls to the helm `template` function have been replaced with
  `include` to be consistent and to stick with modern practices.
- Use of `indent` have been replaced with `nindent #` and a left
  whitespace chomp for a consistent easy to follow practice that gets
  good result.
- Several `if` statements like `if X -> render X` have been replaced
  with `with X -> render .` to avoid repetition. The `with` statement
  won't render if the provided context, making it function also like an
  `if` statement.
- Fixed a bug with `if .Values.revisionHistoryLimit`, which should
  really be `if not (typeIs "<nil>" .Values.revisionHistoryLimit)` to
  handle situations when its set to `0`.

Signed-off-by: Erik Sundell <erik@sundellopensource.se>
2025-09-16 09:55:10 +02:00
Travis Nielsen df49ca1247 pool: allow enablecrushupdates to be nil
Enabling crush updates is false by default, and can be enabled
if set to true. The setting needs to be nullable in case
we need to differentiate between the value being set
to false or just not set, to know if the default should be
different. This is necessary for rook consumers who are
refererencing the pool struct and want to change the default,
rather than using rook's default value of false.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-09-11 16:40:37 -06:00
Blaine Gardner 1c3ebbd01a Merge pull request #16456 from subhamkrai/rotate-nfs-keys
nfs: rotate nfs cephx key
2025-09-11 10:43:22 -06:00
Ruben Tsirunyan 4ab4cdc0de external: fixing a typo in import-external-cluster script
The value of userKey in CSI RBD provisioner secret was set to $CSI_RBD_PROVISIONER_SECRET_NAME because of a typo.
Fixed it by setting it to $CSI_RBD_PROVISIONER_SECRET.

Signed-off-by: Ruben Tsirunyan <rubentsirunyan@gmail.com>
2025-09-11 15:17:31 +04:00
subhamkrai 5e21d43365 nfs: rotate nfs cephx key
Signed-off-by: subhamkrai <srai@redhat.com>
2025-09-11 16:10:46 +05:30
Travis Nielsen c35d433961 Merge pull request #16388 from obnoxxx/support-go-v1.25
build: add support for golang v1.25
2025-09-09 11:13:16 -06:00
Ruben Tsirunyan 2169a3e784 external: fixing secret values in import-external-cluster script
The import-external-cluster.sh script uses $CSI_CEPHFS_NODE_SECRET as the value of userKey when patching the secrets of RBD node, RBD provisioner, CephFS node and CephFS provisioner.
Updated the patch data to use $CSI_RBD_NODE_SECRET, $CSI_RBD_PROVISIONER_SECRET, $CSI_CEPHFS_NODE_SECRET, $CSI_CEPHFS_PROVISIONER_SECRET respectively.

Signed-off-by: Ruben Tsirunyan <rubentsirunyan@gmail.com>
2025-09-08 13:09:42 +04:00
Michael AdamandTravis Nielsen e268c09c4e build: bump controller-gen to v1.19.0
Co-Authored-by: Travis Nielsen <tnielsen@redhat.com>
Signed-off-by: Michael Adam <obnox@samba.org>
2025-09-04 17:06:01 +02:00
Blaine Gardner 7c33186e72 core: admin cephx key rotation
Implement CephX key rotation for Rook's client.admin user.

Admin user rotation is risky, so this has been tested extensively both
in unit tests as well as by manually injecting failures during runtime.
In testing, all failures were able to be recovered by the recovery
routine.

A mutex is also added to help ensure that two simultaneous admin key
rotation processes cannot be running simultaneously for any given
namespace. The mutex is tested in unit tests, and it was verified during
runtime via  manual testing.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2025-08-27 14:47:45 -06:00
Praveen M 5fc4e15bb1 csi: update ceph-csi to v3.15.0
We have new release for Ceph-CSI v3.15.0 -
https://github.com/ceph/ceph-csi/releases/tag/v3.15.0

Signed-off-by: Praveen M <m.praveen@ibm.com>
2025-08-19 20:56:00 +05:30
subham rai dfff81761a Merge pull request #16320 from subhamkrai/ci-enable-csi-operator
csi: make csi-operator default deployment
2025-08-19 19:00:17 +05:30
subhamkraiandTravis Nielsen c57a47f774 ci: run csi-operator only in canary and upgrade suite
this commit add check to only run the csi-operator in
all the canary tests and upgrade suite only, other suite
like smoke and object will still test csi-driver.

Also, adding changes to make CI happy.

Signed-off-by: subhamkrai <srai@redhat.com>
Co-Authored-by: Travis Nielsen <tnielsen@redhat.com>
Signed-off-by: subhamkrai <srai@redhat.com>
2025-08-19 11:23:14 +05:30
Travis Nielsen f7d2e208c8 Merge pull request #16313 from sp98/fs-mirror-key-rotation
core: rotate fs mirror daemon cephx key
2025-08-18 15:17:06 -06:00
Travis Nielsen 7e92d2fb03 Merge pull request #16311 from travisn/csi-op-scc
security: Configure sccs for the ceph-csi operator
2025-08-18 08:22:08 -06:00
Travis Nielsen 36a47ac01a Merge pull request #16176 from sp98/mon-key-rotation
mon: rotate cephx key
2025-08-15 11:06:31 -06:00
Travis Nielsen cb6da09a44 security: configure sccs for the csi operator
The CSI operator requires the SecurityContextConstraints to
be configured for the service accounts that have a different
name from the previous CSI driver, both via the manifest install
and the helm install.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-08-14 13:20:37 -06:00
subhamkrai 506ac2a3ff csi: make csi-operator default deployment
this commits enable the csi-operator by default,
moving it from experimental to stable.

Also, disable the csi-operator chart from generating
rbac in common.yaml

Signed-off-by: subhamkrai <srai@redhat.com>
2025-08-14 22:33:07 +05:30
Santosh Pillai 8df6b8d0d0 core: rotate fs mirror daemon cephx key
Rotate fs mirror daemon cephx keys based on the cephXconfig in the
cephcluster spec and also update the fs mirror status with the latest
cephxStatus

Signed-off-by: Santosh Pillai <sapillai@redhat.com>
2025-08-14 16:16:51 +05:30
Santosh Pillai fe42fe102f mon: rotate keys
rotate mon daemon keys and update the cephx status for mons in the
cephcluster resource.

Signed-off-by: Santosh Pillai <sapillai@redhat.com>
2025-08-14 11:16:39 +05:30
Madhu Rajanna 3d024ce3c7 csi: update the csi-operator API
updating the csi operator API version
to latest version.

Adding the cephFS and RBD controllerPublish
secret that are required for the fencing
operation that is supported by ceph-csi
with csi-operator.

Updated the storageclass to include the
secrets incase if user wants to override
the defaults in the clientProfile for
new PVC's.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2025-08-13 09:30:50 +02:00
Travis Nielsen ce92d9cb33 Merge pull request #16295 from subhamkrai/update-csi-op-deployment
csi: update csi-operator yaml to version v0.4.0
2025-08-12 11:33:13 -06:00
Travis Nielsen 3ea967df70 Merge pull request #16294 from nixpanic/csi-addons/v0.13.0
csi: update Kubernetes CSI-Addons sidecar to version 0.13.0
2025-08-12 11:26:27 -06:00
Travis Nielsen 9f67ee1e20 Merge pull request #16289 from Madhu-1/fix-rbd-user
external: user userID and userKey for rbd
2025-08-12 11:25:15 -06:00
subhamkrai 850ef60a31 csi: update csi-operator yaml to version v0.4.0
this yaml contains all the rbac, crds and csi-operator
deployment all-in-one.

Signed-off-by: subhamkrai <srai@redhat.com>
2025-08-12 22:30:46 +05:30
Niels de Vos 17d53ed16b csi: update Kubernetes CSI-Addons sidecar to version 0.13.0
Signed-off-by: Niels de Vos <ndevos@ibm.com>
2025-08-12 17:56:37 +02:00
Madhu Rajanna db44ef3645 external: user userID and userKey for rbd
csi never used adminID and adminKey for the
rbd secrets, This currently looks to be a
bug where we are creating the secret with userID
and userKey but updating it with adminID and
adminKey, This commits update the script to
use userID and userKey for RBD secrets.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2025-08-12 09:55:35 +02:00
Madhu Rajanna cb89f351ed csi: update cephfs user and key in secret
cephCSI already deprecated the adminID and
adminKey keys in the secrets and to be backward
compatible it still supports the adminID and
adminKey but it logs the warning, updating the
secrets created by Rook to use userID and userKey
instead of adminID and adminKey.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2025-08-12 09:53:55 +02:00
Blaine Gardner 59ca78229d Merge pull request #16075 from sp98/mirror-key-rotation
rbd mirror peer key rotation
2025-08-11 10:54:20 -06:00