The helm charts allowed rendering a PodSecurityPolicy resource via the
configuration `pspEnable`. This option is removed and all references to
psp, PodSecurityPolicy, and Pod Security Policy have been cleaned up.
The PSP resource was only rendered if k8s version was lower than 1.25
when it was still supported. It has been deprecated since k8s 1.21.
Signed-off-by: Erik Sundell <erik@sundellopensource.se>
In the deb package's location of /usr/bin/minilube, a wrong version seems to be
reported but from /usr/local/bin it reports correctly.
Signed-off-by: Michael Adam <obnox@samba.org>
this change updates the k8s version to 1.34 and also updates
the cri-ctl version for minikube.
Signed-off-by: Michael Adam <obnox@samba.org>
Co-authored-by: Travis Nielsen <tnielsen@redhat.com>
Currently create-dev-cluster.sh will hang as the rook operator gets stuck like so:
```
2025-09-08 20:29:58.093909 E | ceph-cluster-controller: failed to reconcile CephCluster "rook-ceph/my-cluster". failed to reconcile cluster "my-cluster": failed to configure local ceph cluster: failed to create cluster: failed to start ceph monitors: failed to initialize ceph cluster info: failed to save mons: failed to create/update cephConnection: failed to get ceph connection CR: no matches for kind "CephConnection" in version "csi.ceph.io/v1"
```
Reconciling the mons is blocked until the new CephConnection CRD is available, and that CRD is new as of v1.18.
The simple fix is to simply install those CRDs in create-dev-cluster.sh. After doing this, the dev cluster bootstraps fine.
Signed-off-by: Elias Carter <elias@dropbox.com>
this commit add check to only run the csi-operator in
all the canary tests and upgrade suite only, other suite
like smoke and object will still test csi-driver.
Also, adding changes to make CI happy.
Signed-off-by: subhamkrai <srai@redhat.com>
Co-Authored-by: Travis Nielsen <tnielsen@redhat.com>
Signed-off-by: subhamkrai <srai@redhat.com>
For Rook v1.18 the min supported version of K8s is
v1.29. With the pending release of K8s 1.34, this
will be the typical six most recent releases that
Rook tests against.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
This PR implements the CSI cephx key rotation feature,
which follows overlapping rotation for non-daemon keys.
Refer to the cephx rotation API from design PR 15915 for details.
Signed-off-by: subhamkrai <srai@redhat.com>
Ceph has a new ceph auth rotate command currently
present in ceph:main
Add a new flag `--cephx-key-rotate` to rotate the
cephx keys genrated by external python script,
If we enable it, it will create a new user with suffix `.{x}`
Signed-off-by: parth-gr <partharora1010@gmail.com>
The create-dev-cluster script used the kvm2 minikube driver on Linux.
On newer Linux flavors like Fedora 41+, the kvm2 driver can have problems
and the qemu2 driver is recommended.
This changes the script to use the qemu2 driver for Linux
Signed-off-by: Michael Adam <obnox@samba.org>
Fixes quick disk shredding by using dd to shred data at additional offsets where ceph metadata is duplicated. For full shred, the shred utility remains in use.
Signed-off-by: Vilius Puškunalis <47086537+puskunalis@users.noreply.github.com>
The script tests/scripts/helm.sh was previously used by some ci
workflows to install helm.
Now that this is not used anymore, this change removes the script.
Signed-off-by: Michael Adam <obnox@samba.org>
tests/scripts/helm.sh clean is not implemented.
So remove frpom the script's help text
and from the development guilde
Signed-off-by: Michael Adam <obnox@samba.org>
The script sel-release-ver.sh was added in a somewhat unnatural place
tests/scripts .
This moves it to a more natural location build/release .
Signed-off-by: Michael Adam <obnox@samba.org>
This script updates examples and docs for a new release.
Invocation in principle: set-release-ver.sh NEW_VER
For example: set-release-ver.sh v1.16.8
Fixes: #15749
Signed-off-by: Michael Adam <obnox@samba.org>
Co-authored-by: Travis Nielsen <tnielsen@redhat.com>
Co-authored-by: Blaine Gardner <b.blaine.gardner@gmail.com>
this PR updates the Prometheus Operator URL references from
version v0.71.1 to the latest release v0.81.0 in documentation
and integration test scripts. This ensures we are aligned with
the latest features and improvements from
the Prometheus Operator project.
Signed-off-by: Oded Viner <oviner@redhat.com>
The helm charts will now only be published when it is
an officially tagged release build.
The images will only be published to all repos for
dockerhub, quay, and ghcr when it is a tagged release.
The images will be published only to dockerhub for all
master and interim release branch builds.
Remove obsolete makefile option for images.
Ceph is the only image Rook ever expects to build.
Simplify the makefile by removing the legacy option
to select which image to build.
Also included are other small improvements to clean up
the release scripts.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
s3cmd can take more time to put the data
of 1M to the bucket as it waits for
connection to get established
currently ci fails with, Retrying failed
request: /test1-1mib-test.dat ([Errno 111]
Connection refused)
also increase the timeout for creating objectstore
Signed-off-by: parth-gr <partharora1010@gmail.com>
in the ci lint file, we use a dependency
from a 3rd party lint, which updates
the black package, The underlined python script
file was not updated to the latest formatting,
so re-format the file and update the
3rd party dependency version
Signed-off-by: parth-gr <partharora1010@gmail.com>
This change continues an effort started earlier to make some
make targets and ci workflows more consistent and systematic.
see https://github.com/rook/rook/pull/14922
it adds a make target gen.helm-docs as an alias to helm-docs.
Additionally, gen.docs is added as alias to docs.
targets check.docs and check.helm-docs are removed because it was agreed
that targets using git are of little value to developers.
Their functionality is moved back into the corresponding docs workflow.
xiFinally, the redundant "Check helm-docs" check is removed from the
docs-check workflow
Signed-off-by: Michael Adam <obnox@samba.org>
Many of the canary tests have been failing much more
frequently in the past week or two. The test is typically
timing out pulling the image from quay.ceph.io since
it does not have as high bandwidth for the images.
A check is added to the test to wait specifically for the
first mon so it waits sufficiently for the image pull
before checking for other ceph daemons.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
With the release of K8s 1.32, we update the CI and docs
to support this new release, to maintain the most recent
six releases of K8s.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
Finish the process of deprecating holder pods by removing Rook's ability
to deploy them. The intent of this change is to make the most
superficial changes possible to accomplish this. There are still
remnants of code in Rook (particularly the CSI controller) that helped
configure or deploy holder pods. Due to the risk of breaking some
features, cleanup work of hose remnants will be deferred for future
work.
Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
This acceptance test demonstrates the creation of two CephObjectStore(s)
that share the same pool(s) manually managed by CephBlockPool(s).
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
This removes the execution of `sudo lsblk` three times for every single
invocation of the script. Usage of the BLOCK var is replaced with
functions which memoize the result of probing for block devices.
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
Factor out most of the CRs used by various canary tests to a new
deploy_cluster_full_of_cruft_please_stop_using_this() function.
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
Fix OSD isn't up.
As sdb device might change to vdb in the runner, let
find_extra_block_dev() exclude the nbd devices and find the proper
extra device for OSD.
Clean up the nbd devices after the test job is running.
Fix logs artifact upload twice and collect logs before clean up.
Signed-off-by: Xinliang Liu <xinliang.liu@linaro.org>
this commit upgrade the minikube, k8s, crictl versions
in CI and also fix permission error in the github runner.
Signed-off-by: subhamkrai <srai@redhat.com>