Commit Graph
442 Commits
Author SHA1 Message Date
Erik Sundell e7a704ccf1 helm: remove legacy PodSecurityPolicy resource
The helm charts allowed rendering a PodSecurityPolicy resource via the
configuration `pspEnable`. This option is removed and all references to
psp, PodSecurityPolicy, and Pod Security Policy have been cleaned up.

The PSP resource was only rendered if k8s version was lower than 1.25
when it was still supported. It has been deprecated since k8s 1.21.

Signed-off-by: Erik Sundell <erik@sundellopensource.se>
2025-09-30 18:25:35 +02:00
Michael Adam 605e820fc8 ci: move minikube to a better location
In the deb package's location of /usr/bin/minilube, a wrong version seems to be
reported but from /usr/local/bin it reports correctly.

Signed-off-by: Michael Adam <obnox@samba.org>
2025-09-16 18:24:18 +02:00
Michael AdamandTravis Nielsen 40427d5c0d ci: update latest k8s version to 1.34
this change updates the k8s version to 1.34 and also updates
the  cri-ctl version for minikube.

Signed-off-by: Michael Adam <obnox@samba.org>
Co-authored-by: Travis Nielsen <tnielsen@redhat.com>
2025-09-16 17:57:28 +02:00
subham rai 90804fd61a Merge pull request #16449 from parth-gr/fix-vault
ci: fix the ci canary vault tests
2025-09-10 14:32:17 +05:30
parth-gr b4fa906202 ci: fix the ci canary valut test
use the official way for helm installation
and not use the cdn installation

Signed-off-by: parth-gr <partharora1010@gmail.com>
2025-09-10 12:16:11 +05:30
Elias Carter 3ed0d928b8 test: fix create-dev-cluster.sh hanging since v1.18
Currently create-dev-cluster.sh will hang as the rook operator gets stuck like so:
```
2025-09-08 20:29:58.093909 E | ceph-cluster-controller: failed to reconcile CephCluster "rook-ceph/my-cluster". failed to reconcile cluster "my-cluster": failed to configure local ceph cluster: failed to create cluster: failed to start ceph monitors: failed to initialize ceph cluster info: failed to save mons: failed to create/update cephConnection: failed to get ceph connection CR: no matches for kind "CephConnection" in version "csi.ceph.io/v1"
```

Reconciling the mons is blocked until the new CephConnection CRD is available, and that CRD is new as of v1.18.

The simple fix is to simply install those CRDs in create-dev-cluster.sh. After doing this, the dev cluster bootstraps fine.

Signed-off-by: Elias Carter <elias@dropbox.com>
2025-09-08 13:36:22 -07:00
subhamkraiandTravis Nielsen c57a47f774 ci: run csi-operator only in canary and upgrade suite
this commit add check to only run the csi-operator in
all the canary tests and upgrade suite only, other suite
like smoke and object will still test csi-driver.

Also, adding changes to make CI happy.

Signed-off-by: subhamkrai <srai@redhat.com>
Co-Authored-by: Travis Nielsen <tnielsen@redhat.com>
Signed-off-by: subhamkrai <srai@redhat.com>
2025-08-19 11:23:14 +05:30
Niels de Vos 17d53ed16b csi: update Kubernetes CSI-Addons sidecar to version 0.13.0
Signed-off-by: Niels de Vos <ndevos@ibm.com>
2025-08-12 17:56:37 +02:00
Travis Nielsen 3137244409 ci: update min k8s version to v1.29
For Rook v1.18 the min supported version of K8s is
v1.29. With the pending release of K8s 1.34, this
will be the typical six most recent releases that
Rook tests against.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-08-04 16:51:00 -06:00
Santosh Pillai c615967fa8 Merge pull request #16040 from subhamkrai/rotate-csi-keyrings
csi: automate CSI cephx key rotation
2025-07-29 11:09:50 +05:30
subhamkrai 6d5401c50d csi: automate CSI cephx key rotation
This PR implements the CSI cephx key rotation feature,
which follows overlapping rotation for non-daemon keys.
Refer to the cephx rotation API from design PR 15915 for details.

Signed-off-by: subhamkrai <srai@redhat.com>
2025-07-25 15:39:00 +05:30
parth-gr c592d36fc7 external: automate external users cephx key rotation
Ceph has a new ceph auth rotate command currently
present in ceph:main

Add a new flag `--cephx-key-rotate`  to rotate the
cephx keys genrated by external python script,
If we enable it, it will create a new user with suffix `.{x}`

Signed-off-by: parth-gr <partharora1010@gmail.com>
2025-07-24 14:41:51 +05:30
Travis Nielsen 009e8eb254 Merge pull request #15666 from puskunalis/cleanup-fix-disk-shredding
osd: fix cleanup job disk shredding
2025-07-10 10:28:46 -06:00
Michael Adam 849e9a48cb test: use the qemu2 minikube driver on Linyx for create-dev-cluster
The create-dev-cluster script used the kvm2 minikube driver on Linux.

On newer Linux flavors like Fedora 41+, the kvm2 driver can have problems
and the qemu2 driver is recommended.

This changes the script to use the qemu2 driver for  Linux

Signed-off-by: Michael Adam <obnox@samba.org>
2025-07-01 19:35:29 +02:00
Vilius Puškunalis 27010f96f3 osd: fix cleanup job disk shredding
Fixes quick disk shredding by using dd to shred data at additional offsets where ceph metadata is duplicated. For full shred, the shred utility remains in use.

Signed-off-by: Vilius Puškunalis <47086537+puskunalis@users.noreply.github.com>
2025-06-23 21:46:41 +03:00
Michael Adam a699bcec06 ci: remove unused script helm.sh
The script tests/scripts/helm.sh was previously used by some ci
workflows to install helm.

Now that this is not used anymore, this change removes the script.

Signed-off-by: Michael Adam <obnox@samba.org>
2025-06-12 19:47:24 +02:00
Michael Adam ef267ee8bf helm: remove mention of helm.sh clean
tests/scripts/helm.sh clean is not implemented.

So  remove frpom the script's help text
and from the development guilde

Signed-off-by: Michael Adam <obnox@samba.org>
2025-06-06 17:51:40 +02:00
Michael Adam 7c05f532ce helm: use the latest version
update the helm version used to the latest (v3.18.2)

Signed-off-by: Michael Adam <obnox@samba.org>
2025-06-04 19:01:47 +02:00
Michael Adam d7f2a4b4d8 build: move se-release-ver script to better place
The script sel-release-ver.sh was added in a somewhat unnatural place
tests/scripts .
This moves it to a more natural location build/release .

Signed-off-by: Michael Adam <obnox@samba.org>
2025-05-05 17:02:39 +02:00
a1b941f969 build: add a script for setting the release version in examples,docs, and charts
This script updates examples and docs for a new release.

Invocation in principle: set-release-ver.sh  NEW_VER
For example: set-release-ver.sh v1.16.8

Fixes: #15749

Signed-off-by: Michael Adam <obnox@samba.org>
Co-authored-by: Travis Nielsen <tnielsen@redhat.com>
Co-authored-by: Blaine Gardner <b.blaine.gardner@gmail.com>
2025-05-01 10:36:26 -06:00
subhamkrai 8c2f724f6d ci: update latest k8s version to 1.33
this commit update k8s version to 1.33 and also update
other version like for minikube cri-ctl and so.

Signed-off-by: subhamkrai <srai@redhat.com>
2025-04-29 20:53:47 +05:30
Travis Nielsen ae895770e2 Merge pull request #15750 from OdedViner/update_prometheus_version
test: update Prometheus Operator to v0.82.0
2025-04-23 11:44:14 -06:00
Oded Viner 5d143d990c test: update Prometheus Operator to v0.82.0
this PR updates the Prometheus Operator URL references from
version v0.71.1 to the latest release v0.81.0 in documentation
and integration test scripts. This ensures we are aligned with
the latest features and improvements from
the Prometheus Operator project.

Signed-off-by: Oded Viner <oviner@redhat.com>
2025-04-22 15:37:56 +03:00
Travis Nielsen 7d908d0a5e build: stop publishing charts in master branch
The helm charts will now only be published when it is
an officially tagged release build.

The images will only be published to all repos for
dockerhub, quay, and ghcr when it is a tagged release.

The images will be published only to dockerhub for all
master and interim release branch builds.

Remove obsolete makefile option for images.
Ceph is the only image Rook ever expects to build.
Simplify the makefile by removing the legacy option
to select which image to build.

Also included are other small improvements to clean up
the release scripts.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-04-18 10:40:29 -06:00
parth-gr 1a296dccd5 ci: fix rgw flaky ci test
s3cmd can take more time to put the data
of 1M to the bucket as it waits for
connection to get established

currently ci fails with, Retrying failed
request: /test1-1mib-test.dat ([Errno 111]
Connection refused)

also increase the timeout for creating objectstore

Signed-off-by: parth-gr <partharora1010@gmail.com>
2025-04-08 21:15:59 +05:30
Niels de Vos 25d3b6d5fc csi: update csi-addons to v0.12.0
The csi-addons v0.12.0 release is now available.

See-also: https://github.com/csi-addons/kubernetes-csi-addons/releases/tag/v0.12.0
Signed-off-by: Niels de Vos <ndevos@ibm.com>
2025-03-05 09:35:41 +01:00
Travis Nielsen 98a3d20c43 Merge pull request #15486 from parth-gr/fix-black
ci: update the python black package
2025-03-03 07:42:33 -07:00
parth-gr a3bde46ad3 ci: update the python black package
in the ci lint file, we use a dependency
from a 3rd party lint, which updates
the black package, The underlined python script
file was not updated to the latest formatting,
so re-format the file and update the
3rd party dependency version

Signed-off-by: parth-gr <partharora1010@gmail.com>
2025-03-03 18:48:39 +05:30
subhamkrai 0dda801488 ci: test rgw multisite test
Signed-off-by: subhamkrai <srai@redhat.com>
2025-02-27 23:19:13 +05:30
Joshua Hoblitt f52f48c477 ci: codespell: s/re-using/reusing/
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-01-21 15:11:33 -07:00
Michael Adam 795e188024 ci: rework docs-related workflow and make targets a bit
This change continues an effort started earlier to make some
make targets and ci workflows more consistent and systematic.
see https://github.com/rook/rook/pull/14922

it adds a  make target gen.helm-docs as an alias to helm-docs.
Additionally, gen.docs is added as alias to docs.
targets check.docs and check.helm-docs are removed because it was agreed
that targets using git are of little value to developers.
Their functionality is moved back into the corresponding docs workflow.

xiFinally, the  redundant "Check helm-docs" check is removed from the
docs-check workflow

Signed-off-by: Michael Adam <obnox@samba.org>
2025-01-09 20:31:14 +01:00
Travis Nielsen 56c6659655 tests: canary tests to wait for first mon to start
Many of the canary tests have been failing much more
frequently in the past week or two. The test is typically
timing out pulling the image from quay.ceph.io since
it does not have as high bandwidth for the images.
A check is added to the test to wait specifically for the
first mon so it waits sufficiently for the image pull
before checking for other ceph daemons.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-12-20 13:53:21 -07:00
Travis Nielsen 7c2f41e72e build: add support for k8s 1.32
With the release of K8s 1.32, we update the CI and docs
to support this new release, to maintain the most recent
six releases of K8s.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-12-12 09:48:42 -07:00
Niels de Vos f1d448cc46 csi: update csi-addons to v0.11.0
The csi-addons v0.11.0 release is now available.

See-also: https://github.com/csi-addons/kubernetes-csi-addons/releases/tag/v0.11.0
Signed-off-by: Niels de Vos <ndevos@ibm.com>
2024-11-26 10:38:54 +01:00
Travis Nielsen 3b94c50d8b Merge pull request #14818 from iPraveenParihar/kms/vault-keyrotation
kms: key rotation support for vault kms
2024-10-24 11:38:33 -06:00
Blaine Gardner 5539eedd1b multus: finish deprecating holder pods
Finish the process of deprecating holder pods by removing Rook's ability
to deploy them. The intent of this change is to make the most
superficial changes possible to accomplish this. There are still
remnants of code in Rook (particularly the CSI controller) that helped
configure or deploy holder pods. Due to the risk of breaking some
features, cleanup work of hose remnants will be deferred for future
work.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-10-23 16:29:02 -06:00
Praveen M c9bc3a2685 ci: add test for vault key rotation
Signed-off-by: Praveen M <m.praveen@ibm.com>
2024-10-23 12:58:11 +05:30
Joshua Hoblitt 100c8bd7a9 test: require ceph tag param to replace_ceph_image
To prevent silent failures where the ceph image tag is not updated.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-10-18 12:08:57 -07:00
Joshua Hoblitt edd65e5686 test: when collecting logs, describe instead of get CRs
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-10-14 16:54:39 -07:00
Joshua Hoblitt 16dd6257c2 test: when collecting logs, use get in secret filename
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-10-14 16:54:39 -07:00
Joshua Hoblitt 11250013a0 test: add two-object-one-zone canary test
This acceptance test demonstrates the creation of two CephObjectStore(s)
that share the same pool(s) manually managed by CephBlockPool(s).

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-10-14 16:54:39 -07:00
Joshua Hoblitt 92d9f994c2 test: improve reliability of canary rgw-multisite-testing
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-10-12 12:42:58 -07:00
Joshua Hoblitt d301114680 test: do not always run sudo lsblk in github-action-helper.sh
This removes the execution of `sudo lsblk` three times for every single
invocation of the script.  Usage of the BLOCK var is replaced with
functions which memoize the result of probing for block devices.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-10-03 16:40:10 -07:00
Joshua Hoblitt 581fd5c197 test: convert all github-action-helper functs to $REPO_DIR
This allows all functions to be called in any order without concern for
the CWD.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-10-03 10:18:17 -07:00
Joshua Hoblitt 31d55b90fe test: mv canary test specific resources out of deploy_cluster()
Factor out most of the CRs used by various canary tests to a new
deploy_cluster_full_of_cruft_please_stop_using_this() function.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-10-03 10:18:17 -07:00
Joshua Hoblitt ed8156017e test: add object-with-cephblockpool canary test
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-10-03 10:16:30 -07:00
Joshua Hoblitt cb1dd152ad test: add github-action-helper toolbox functions
Added these functions for running commands in the toolbox pod:

- toolbox()
- ceph()
- rbd()
- radosgw-admin()

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-10-03 10:16:30 -07:00
Xinliang Liu 05ac99c0c0 ci: fix canary-arm64 job
Fix OSD isn't up.
As sdb device might change to vdb in the runner, let
find_extra_block_dev() exclude the nbd devices and find the proper
extra device for OSD.

Clean up the nbd devices after the test job is running.

Fix logs artifact upload twice and collect logs before clean up.

Signed-off-by: Xinliang Liu <xinliang.liu@linaro.org>
2024-10-01 12:05:32 -06:00
subhamkrai f647444515 ci: fix ci permission issue with minikube start
this commit upgrade the minikube, k8s, crictl versions
in CI and also fix permission error in the github runner.

Signed-off-by: subhamkrai <srai@redhat.com>
2024-09-19 15:55:18 +05:30
Praveen M afad40e404 csi: update csi-addons to v0.10.0
The csi-addons v0.10.0 release is now available.
Ref: https://github.com/csi-addons/kubernetes-csi-addons/releases/tag/v0.10.0

Signed-off-by: Praveen M <m.praveen@ibm.com>
2024-09-18 12:19:46 +05:30