Commit Graph
290 Commits
Author SHA1 Message Date
Travis Nielsen 0d3d12c0fd Merge pull request #11198 from subhamkrai/latest-ceph-version
core: upgrade ceph to latest release v17.2.5
2022-10-26 09:51:47 -06:00
subhamkrai 270b565f18 core: upgrade ceph to latest release v17.2.5
Signed-off-by: subhamkrai <srai@redhat.com>
2022-10-26 19:59:53 +05:30
Blaine Gardner 0937eaee38 Merge pull request #11124 from BlaineEXE/object-revise-health-check
object: remove health checker
2022-10-24 11:31:23 -06:00
Travis Nielsen ba6adc60e1 build: update the go modules to the latest
The security scan is failing due to a go dependency
so we update the go modules and all dependencies to
the latest available.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-10-20 10:40:17 -06:00
Madhu Rajanna 729f2a8b32 csi: update csi to latest release
This updates the cephcsi to latest 3.7.2
release and also updates sidecar to the latest
release in some missing files.

Note:- sidecar images are upto date in most of
the places, in some places it was missing, This
PR updates it in missing place.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2022-10-20 09:16:05 +02:00
Travis Nielsen 67582fe0da operator: remove obsolete flex driver properties
The flex driver was deprecated and fully purged long ago,
and now finally we are purging the related properties
from the operator deployment that are no longer applied
anywhere.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-10-19 13:51:39 -06:00
Travis Nielsen d695a0f930 Merge pull request #11163 from gauravsitlani/gdb-coredump-tests
core: enabling logCollector by default for coredump collection
2022-10-19 12:34:54 -06:00
gauravsitlani cc02399c4c core: enabling logCollector by default for coredump
enabling logCollector by default will enable the coredump
generation in case a process terminates with a segmentation fault.

Signed-off-by: gauravsitlani <gauravsitlani@riseup.net>
2022-10-19 23:04:22 +05:30
Blaine Gardner a7c0c7ee93 object: remove health checker
Remove the health checker for CephObjectStore. The liveness and
readiness probes go through the same code paths in RGW as creating
buckets without as much affect on the storage backend.

Full discussion: https://github.com/rook/rook/issues/11031

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2022-10-18 13:41:46 -06:00
Travis Nielsen 87afc09e05 Merge pull request #11090 from parth-gr/external-rgw
external: fix endpoint_dial check for rgw endpoint
2022-10-18 09:11:10 -06:00
parth-gr fb7b67c3f4 external: fix endpoint_dial check for rgw endpoint
the validate rgw endpoint tls cert returns the certificate instead
of returning whether it exist or not,
So updatd the flow how to use it

Closes: https://github.com/rook/rook/issues/11060
Signed-off-by: parth-gr <paarora@redhat.com>
2022-10-14 19:16:30 +05:30
Travis Nielsen 4990e3c730 Merge pull request #11123 from parth-gr/wildcard-update
core: remove wildcard permission in rbac
2022-10-11 10:52:10 -06:00
Travis Nielsen b32152455d Merge pull request #11131 from parth-gr/test-ci
ci: update mon_data_avail_warn percentage
2022-10-10 10:14:49 -06:00
parth-gr d392129cdd ci: update mon_data_avail_warn percentage
I see the mon_data_avail_warn is set to 500M
but acording to ceph doc this should be in percentage
And by default this percentage is 30%,
So re assigned to 10% for the CI

Closes: https://github.com/rook/rook/issues/11130
Signed-off-by: parth-gr <paarora@redhat.com>
2022-10-10 18:58:12 +05:30
parth-gr 703c850b86 core: remove wildcard permission in rbac
Reduce the RBAC scope to the minimum necessary
permissions for rook to operator

Signed-off-by: parth-gr <paarora@redhat.com>
2022-10-10 15:05:56 +05:30
Travis Nielsen 4370d9c710 Merge pull request #11085 from humblec/sidecar-update
update sidecars to latest in CSI deployment
2022-09-29 08:46:30 -06:00
Humble Chirammal c847e6b98d csi: update sidecars to latest in CSI deployment
Signed-off-by: Humble Chirammal <hchiramm@redhat.com>
2022-09-29 19:35:17 +05:30
Humble Chirammal 4d435b224f csi: use ceph csi v3.7.1 for rook csi driver deployment
Signed-off-by: Humble Chirammal <hchiramm@redhat.com>
2022-09-29 16:46:43 +05:30
Travis Nielsen b6e5307f25 Merge pull request #11071 from nixpanic/strict-decoding/k8s-1.25
examples: CephBlockPool does not have spec.annotations
2022-09-28 08:28:58 -06:00
Travis Nielsen 0779618816 Merge pull request #10966 from avanthakkar/customizable-image-pull-policy
operator: make imagePullPolicy customizable for csi driver and ceph pods
2022-09-28 07:23:26 -06:00
Niels de Vos 69dc8897bb docs: the CephBlockPool CR does not have spec.annotations
With Kubernetes 1.25 it seems that applying the yaml files that have a
CephBlockPool with spec.annotations fail with errors like this:

    CephBlockPool in version "v1" cannot be handled as a CephBlockPool:
    strict decoding error: unknown field "spec.annotations"

Updates: ceph/ceph-csi#3362
Signed-off-by: Niels de Vos <ndevos@redhat.com>
2022-09-28 11:56:12 +02:00
Avan Thakkar 934aa91056 operator: make imagePullPolicy customizable for csi driver and ceph pods
Introduce a new env variable ROOK_CSI_IMAGE_PULL_POLICY in rook operator configmap which should be used to
customize the imagePullPolicy for the csi driver and imagePullPolicy property in cephVersionSpec for ceph pods.

Signed-off-by: Avan Thakkar <athakkar@redhat.com>
2022-09-27 11:57:43 +05:30
Niels de Vos 79adad7dc0 nfs: allow users to include additional files in the SSSD sidecar
The sssd.conf may refer to additional files, like a CA bundle or TLS
certificates. These files need to be made available in the SSSD sidecar.
With the new `sssdGenericFiles` reference to a VolumeSource and a
`MountPath`, a provided `sssd.conf` can use the additional files.

Signed-off-by: Niels de Vos <ndevos@redhat.com>
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2022-09-26 16:50:50 -06:00
Madhu Rajanna 80a96f8f32 csi: customize plugin volumes and volumemounts
This option open-up volumes and volumemounts
for user customization of the rbd,cephfs,nfs
plugin daemonset.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2022-09-16 09:57:37 +05:30
Travis Nielsen b4dcc9b633 Merge pull request #10990 from parth-gr/mon-ci-health
ci: add mon_data_avail_warn to canary ci test
2022-09-15 10:09:34 -06:00
parth-gr df8493d77b ci: add mon_data_avail_warn to canary ci test
ceph cluster on ci mostly have health error
mon disk low on size,
so overriding the min aval capacity to 0 from 30% default so this
error can be removed

Closes: rook#10971

Signed-off-by: parth-gr <paarora@redhat.com>
2022-09-15 15:20:47 +05:30
Travis Nielsen eaee34872b Merge pull request #10912 from parth-gr/restricted-upgrade
docs: add upgrade steps for multi-tenant custer
2022-09-14 07:44:07 -06:00
parth-gr 0ad1b52005 docs: add upgrade steps for multi-tenant custer
Currently for external clustr multitenancy is only applicable for new
deployments, but adding doc change so multi-tenancy can be achieved for
upgraded cluster also

Closes: https://github.com/rook/rook/issues/10678
Signed-off-by: parth-gr <paarora@redhat.com>
2022-09-14 12:48:18 +05:30
Travis Nielsen d7ca581ef9 Merge pull request #10700 from jdloft/fix-growth-rule
monitoring: fix pool growth warning grouping
2022-09-13 11:31:47 -06:00
Blaine Gardner 697f34fcee Merge pull request #10950 from BlaineEXE/nfs-kerberos-implementation
nfs: add kerberos client security support
2022-09-13 10:05:14 -06:00
Blaine Gardner 2b0eaa974f Merge pull request #10909 from subhamkrai/remove-import-error
external: fix import errors for python2
2022-09-13 08:49:12 -06:00
Blaine Gardner 005000212c nfs: add kerberos client security support
Add support for enabling kerberos for client authentication.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2022-09-13 08:46:52 -06:00
subhamkrai 9a952df419 external: fix import errors for python2
remove duplicate import urllib.parse which is handled below
with try and except no need to import separately. Also, change
the way to get the python version.

Signed-off-by: subhamkrai <srai@redhat.com>
2022-09-13 10:59:18 +05:30
Travis Nielsen 384fc4ab92 Merge pull request #10931 from parth-gr/rgw-fix-ceph-version
external: do not add info=read cap if ceph version doesn't support it
2022-09-12 15:15:47 -06:00
Travis Nielsen ef3f55460c Merge pull request #10728 from thotz/multisite-delete-zone-pools
rgw: delete zone/pools for multisite configuation
2022-09-12 13:42:42 -06:00
Jiffin Tony Thottan c98628eb0f rgw: delete zone/pools for multisite configuation
Allow option to delete the zone/pools created by ceph object zone CR.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2022-09-12 21:44:55 +05:30
Rakshith R 3c5a2f4142 csi: add topology provisioning support
This commit adds topology provisioning
support. This makes modification to rbac,
csi deployment and daemonset.

Signed-off-by: Rakshith R <rar@redhat.com>
2022-09-12 16:10:18 +05:30
parth-gr 54425803b6 external: do not add info=read cap if ceph version doesn't support it
The rgw ip validation feature was needing to update the rgw user
cap to add info=read permission, but this permission is only backported
till ceph pacific, so we added a check that only add this cap
when ceph version support it,
But this cap was also adding with the other caps, so removed it from there
Now it will only add this cap if ceph version support it

Signed-off-by: parth-gr <paarora@redhat.com>
2022-09-09 15:46:18 +05:30
Rakshith R 9c4592720c csi: add NFS expansion support
This commit adds resizer sidecar to
NFS driver and required storageclass
and rbac changes.

Signed-off-by: Rakshith R <rar@redhat.com>
2022-09-08 16:15:37 +05:30
Rakshith R f8eb2a2fbc csi: add NFS clone support
This commit reqired yaml and docs
changes too for NFS clone support.

Signed-off-by: Rakshith R <rar@redhat.com>
2022-09-08 16:15:37 +05:30
Rakshith R 73042c7531 csi: add NFS snapshot support
This commit adds snapshotter sidecar to
NFS driver and required yamls and docs too.

Signed-off-by: Rakshith R <rar@redhat.com>
2022-09-08 16:15:37 +05:30
Travis Nielsen 08c787e8d6 Merge pull request #10777 from yati1998/remove-vol-rep
rbd-mirror: remove volume replication sidecar
2022-09-07 08:27:07 -06:00
Travis Nielsen 46a832fe98 Merge pull request #10899 from khrisrichardson/found-unexpected-end-of-stream
manifest: fix unexpected end of stream
2022-09-07 07:41:32 -06:00
yati1998 9b4361b379 rbdmirror: remove volume replication sidecar
The volume replication operator is being moved to
kubernetes-csi-addons. This commit hence, removes
the volume replication sidecar and updates the
related documentation.
It will also update the csi-addons sidecar version
to the latest one.

Closes: #10655

Signed-off-by: yati1998 <ypadia@redhat.com>
2022-09-07 14:49:19 +05:30
Khris Richardson 9614428f54 manifest: fix unexpected end of stream
Signed-off-by: Khris Richardson <khris.richardson@gmail.com>
2022-09-06 15:04:06 -07:00
Travis Nielsen 1bbf8f7a43 Merge pull request #10791 from Rakshith-R/use-cephcsi-nfsnodeplugin
csi: use cephcsi image for nfs nodeserver + holder design
2022-09-06 10:52:30 -06:00
Rakshith R 7722226521 csi: remove nfs image
This commit remove nfs image
since it is no longer needed.
Cephcsi itself will act as nfs
nodeserver.

Signed-off-by: Rakshith R <rar@redhat.com>
2022-09-02 14:16:15 +05:30
Humble Chirammal 32ecc37d37 csi: change the default fsgroup policy for CSI driver object
This commit change the default fsgroup policy for csi driver object
to "File" type which is the better/correct setting for the CSI volumes
We have been using default value which is "ReadWriteOnceWithFSType".
with this change backward compatibility should be preserved.

Signed-off-by: Humble Chirammal <hchiramm@redhat.com>
2022-09-01 10:11:39 +05:30
Humble Chirammal 6ef366dc34 csi: use the latest sidecars for ceph csi driver
at present, the csi sidecars are older versions and not in parity
with the latest ceph csi release v3.7.0. This commit update the
same to make it.

Signed-off-by: Humble Chirammal <hchiramm@redhat.com>
2022-08-31 14:43:00 +05:30
Blaine Gardner 6c8f2e414f build: remove psp from common.yaml generation
Due to an oversight, PSP resources were left in generation of
common.yaml from #10797. Resolve that by setting
pspEnable=false when generating common.yaml.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2022-08-29 10:41:41 -06:00