Add optinal hostnetwork field for Ceph Mgr to control whether the
mgr pods to run in host network. If unset, this defaults to
cluster level Network.HostNetwork value. This particulary useful
when user wants to restrict ceph mgr pod from exposing metrics
port in all host interfaces.
Signed-off-by: Sunnatillo <sunnat.samadov@est.tech>
This change introduces support for setting the ceph cache memory limit
ratios that were previously hardcoded.
Codegen was drivey-by updated as the current version errored.
Resolves#16551
Signed-off-by: Tim Buchwaldt <tim.buchwaldt@deepl.com>
With the addition of the csi operator, the csi operator
image is added to the list of images that are required
for deploying rook.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
Add consistent metadata labels to resources that were missing them:
- configmap.yaml: Add labels to rook-ceph-operator-config ConfigMap
- securityContextConstraints.yaml: Add labels to both rook-ceph and rook-ceph-csi SCCs
- serviceaccount.yaml: Add labels to 6 CSI ServiceAccounts that were missing them
All new labels use the unified library.rook-ceph.labels template for consistency.
Regenerated deploy/examples/common.yaml and deploy/examples/csi/nfs/rbac.yaml
to reflect the updated label definitions.
This addresses reviewer feedback about missing labels in non-RBAC resources
and ensures consistent labeling across all Rook Ceph Helm chart resources.
Signed-off-by: fullstackjam <fullstackjam@outlook.com>
This PR addresses ArgoCD drift detection issues by adding consistent
metadata labels to RBAC resources in Rook Ceph Helm charts. The problem
occurs because many RBAC resources lack metadata labels, causing ArgoCD
to interpret them as 'labels: null' and report continuous drift.
Changes made:
- Added consistent labels to all RBAC templates in rook-ceph and library charts
- Created _recommended-labels.tpl template for standardized labeling
- Removed app.kubernetes.io/component label per consideRatio feedback to avoid scope creep
- Suppressed Helm-specific labels (version, instance, managed-by, created-by, chart) from static RBAC files
- Regenerated deploy/examples/common.yaml and deploy/examples/csi/nfs/rbac.yaml
Labels added to RBAC resources:
- operator: rook
- storage-backend: ceph
- app.kubernetes.io/name: rook-ceph
- app.kubernetes.io/part-of: rook-ceph-operator
Impact:
- Resolves ArgoCD 'OutOfSync' issues for Rook RBAC resources
- Improves resource identification and management
- Provides consistent labeling across all Rook Helm charts
- No functional changes to RBAC permissions
- Focuses on essential labels to avoid over-engineering
This addresses review feedback from travisn and consideRatio to maintain
scope and ensure static RBAC files only contain meaningful labels.
Signed-off-by: fullstackjam <fullstackjam@outlook.com>
The helm charts allowed rendering a PodSecurityPolicy resource via the
configuration `pspEnable`. This option is removed and all references to
psp, PodSecurityPolicy, and Pod Security Policy have been cleaned up.
The PSP resource was only rendered if k8s version was lower than 1.25
when it was still supported. It has been deprecated since k8s 1.21.
Signed-off-by: Erik Sundell <erik@sundellopensource.se>
The current behavior does not print the PHASE column, as most other
CRDs do. E.g.:
```
~ $ k get cephnfs nfs1
NAME AGE
nfs1 45d
```
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
The current behavior does not print the PHASE column, as most other
CRDs do. E.g.:
```
~ $ k get cephbn chorus
NAME AGE
chorus 10d
```
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
The current behavior does not print the PHASE column, as most other
CRDs do. E.g.:
```
~ $ k get cephor lfa
NAME AGE
lfa 45d
```
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
Resolves this incorrect field description:
~ $ k explain cephobjectzone.spec.zoneGroup
GROUP: ceph.rook.io
KIND: CephObjectZone
VERSION: v1
FIELD: zoneGroup <string>
DESCRIPTION:
The display name for the ceph users
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
Resolves this incorrect field description:
~ $ k explain cephobjectzonegroup.spec.realm
GROUP: ceph.rook.io
KIND: CephObjectZoneGroup
VERSION: v1
FIELD: realm <string>
DESCRIPTION:
The display name for the ceph users
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
This touches a lot where a typo could cause issues for someone, so I have self-
reviewed it many times line-by-line already.
There are a few types of changes:
- All resources get tied to their own YAML document separator (`---`)
before their definition, reducing the risk of not separating resources
correctly when rendering multiple into a file. I think the changes
will fix edge case bugs for people with mutiple items listed in
`cephFileSystems` and similar configuration.
- `toYaml ...` is made into `... | toYaml` consistently.
- `default A B` is made into `B | default A` consistently.
- Consistent whitespace chomping, so instead of `{{ end }}` you would
find `{{- end }}` typically. The system is that you should chomp left
almost all the time, and almost all the time _not_ chomp right. You
would chomp right in the beginning of a file or helper function in
order to clear some initial whitespace, otherwise not.
- Multiline helm template comments `{{- /* ... */ }}` get their content
indented 2 spaces.
- List items are consistently rendered with two spaces of indentation.
- `kind` is put before `apiVersion` consistently, to follow a practice
observed partially in the repo.
- Calls to the helm `template` function have been replaced with
`include` to be consistent and to stick with modern practices.
- Use of `indent` have been replaced with `nindent #` and a left
whitespace chomp for a consistent easy to follow practice that gets
good result.
- Several `if` statements like `if X -> render X` have been replaced
with `with X -> render .` to avoid repetition. The `with` statement
won't render if the provided context, making it function also like an
`if` statement.
- Fixed a bug with `if .Values.revisionHistoryLimit`, which should
really be `if not (typeIs "<nil>" .Values.revisionHistoryLimit)` to
handle situations when its set to `0`.
Signed-off-by: Erik Sundell <erik@sundellopensource.se>
Enabling crush updates is false by default, and can be enabled
if set to true. The setting needs to be nullable in case
we need to differentiate between the value being set
to false or just not set, to know if the default should be
different. This is necessary for rook consumers who are
refererencing the pool struct and want to change the default,
rather than using rook's default value of false.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
The value of userKey in CSI RBD provisioner secret was set to $CSI_RBD_PROVISIONER_SECRET_NAME because of a typo.
Fixed it by setting it to $CSI_RBD_PROVISIONER_SECRET.
Signed-off-by: Ruben Tsirunyan <rubentsirunyan@gmail.com>
The import-external-cluster.sh script uses $CSI_CEPHFS_NODE_SECRET as the value of userKey when patching the secrets of RBD node, RBD provisioner, CephFS node and CephFS provisioner.
Updated the patch data to use $CSI_RBD_NODE_SECRET, $CSI_RBD_PROVISIONER_SECRET, $CSI_CEPHFS_NODE_SECRET, $CSI_CEPHFS_PROVISIONER_SECRET respectively.
Signed-off-by: Ruben Tsirunyan <rubentsirunyan@gmail.com>
Implement CephX key rotation for Rook's client.admin user.
Admin user rotation is risky, so this has been tested extensively both
in unit tests as well as by manually injecting failures during runtime.
In testing, all failures were able to be recovered by the recovery
routine.
A mutex is also added to help ensure that two simultaneous admin key
rotation processes cannot be running simultaneously for any given
namespace. The mutex is tested in unit tests, and it was verified during
runtime via manual testing.
Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
this commit add check to only run the csi-operator in
all the canary tests and upgrade suite only, other suite
like smoke and object will still test csi-driver.
Also, adding changes to make CI happy.
Signed-off-by: subhamkrai <srai@redhat.com>
Co-Authored-by: Travis Nielsen <tnielsen@redhat.com>
Signed-off-by: subhamkrai <srai@redhat.com>
The CSI operator requires the SecurityContextConstraints to
be configured for the service accounts that have a different
name from the previous CSI driver, both via the manifest install
and the helm install.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
this commits enable the csi-operator by default,
moving it from experimental to stable.
Also, disable the csi-operator chart from generating
rbac in common.yaml
Signed-off-by: subhamkrai <srai@redhat.com>
Rotate fs mirror daemon cephx keys based on the cephXconfig in the
cephcluster spec and also update the fs mirror status with the latest
cephxStatus
Signed-off-by: Santosh Pillai <sapillai@redhat.com>
updating the csi operator API version
to latest version.
Adding the cephFS and RBD controllerPublish
secret that are required for the fencing
operation that is supported by ceph-csi
with csi-operator.
Updated the storageclass to include the
secrets incase if user wants to override
the defaults in the clientProfile for
new PVC's.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
csi never used adminID and adminKey for the
rbd secrets, This currently looks to be a
bug where we are creating the secret with userID
and userKey but updating it with adminID and
adminKey, This commits update the script to
use userID and userKey for RBD secrets.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
cephCSI already deprecated the adminID and
adminKey keys in the secrets and to be backward
compatible it still supports the adminID and
adminKey but it logs the warning, updating the
secrets created by Rook to use userID and userKey
instead of adminID and adminKey.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>