Commit Graph
2829 Commits
Author SHA1 Message Date
Travis Nielsen df6d7af355 security: run the crash collector as ceph user
The crash collector does not have the command line arguments
to run as ceph user id 167, so we set the security context
to run as the ceph user in the main crash collector
container.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-10-27 13:12:21 -06:00
Travis Nielsen 6c7a17a8df Merge pull request #11211 from travisn/mon-host-network
mon: The mon daemons maintain host network settings to allow change in config
2022-10-27 11:34:20 -06:00
Satoru Takeuchi ee0497c444 Merge pull request #11220 from travisn/osd-spec-cleanup
osd: Reduce duplication of arguments
2022-10-27 13:12:28 +09:00
Travis Nielsen faf5eba8dc osd: reduce duplication of arguments
The osd arguments had a few duplicate lines that could be
factored out and thus simplified for code maintainability.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-10-26 16:50:04 -06:00
Travis Nielsen 0ede2946a8 core: remove finalizer from cluster cr last
Removing the finalizers from cluster resources can intermittently fail
in the CI if other updates are made at similar times. The controller
runtime will retry after the failure, but if something external
removes the finalizer on the cephcluster CR, the deletion will not
continue with the removal of finalizers from the other configmap
and secret critical resources.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-10-26 14:17:03 -06:00
Travis Nielsen 61840324be mon: the mon daemons maintain host network settings
If the host network setting is changed in the cluster CR,
the existing mons must continue using the same network
settings or else the operator would update their pod
specs with the incorrect settings and cause mon quorum
to go down. Now the network setting is preserved so
the admin could switch between host and non-host network
configuration without reinstalling.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-10-26 13:40:33 -06:00
Travis Nielsen 0d3d12c0fd Merge pull request #11198 from subhamkrai/latest-ceph-version
core: upgrade ceph to latest release v17.2.5
2022-10-26 09:51:47 -06:00
subhamkrai 270b565f18 core: upgrade ceph to latest release v17.2.5
Signed-off-by: subhamkrai <srai@redhat.com>
2022-10-26 19:59:53 +05:30
Blaine Gardner 0937eaee38 Merge pull request #11124 from BlaineEXE/object-revise-health-check
object: remove health checker
2022-10-24 11:31:23 -06:00
Blaine Gardner 93416fa447 Merge pull request #11183 from BlaineEXE/object-fix-rgw-period-commit-logic
object: fix logic for rgw period commit detection
2022-10-20 09:59:07 -06:00
Madhu Rajanna 729f2a8b32 csi: update csi to latest release
This updates the cephcsi to latest 3.7.2
release and also updates sidecar to the latest
release in some missing files.

Note:- sidecar images are upto date in most of
the places, in some places it was missing, This
PR updates it in missing place.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2022-10-20 09:16:05 +02:00
Blaine Gardner 5320830781 object: fix logic for rgw period commit detection
The `periodWillChange()` implementation to detect map keys to ignore.
Previously, we relied on the `GoString()` method to output the same
format always to determine the current path to the
map[string]interface{} node, but that may change depending on the underlying
implementation of go-cmp.

Instead, parse the go-cmp `Path` step by step and construct a JSON path
to the node in a stable format.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2022-10-19 14:56:56 -06:00
Blaine Gardner a7c0c7ee93 object: remove health checker
Remove the health checker for CephObjectStore. The liveness and
readiness probes go through the same code paths in RGW as creating
buckets without as much affect on the storage backend.

Full discussion: https://github.com/rook/rook/issues/11031

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2022-10-18 13:41:46 -06:00
Madhu Rajanna ffdfeb5bec csi: add setmetadata and clustername flag to omap
The omap generator sidecar is the one who
sets the pvc name and clustername in the metadata
if the pv is re-attached to a new pvc or if the
clustername changes, for that reason we need to
set these flags on the omap generator sidecar
also.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2022-10-18 15:29:58 +02:00
Travis Nielsen 7f0c83ad18 Merge pull request #10986 from randymtz/increase-liveness-timeout
core: increase liveness probe timeout to 5s
2022-10-17 11:49:18 -06:00
Travis Nielsen 95b84a6c12 Merge pull request #11099 from avanthakkar/fix-configure-rbd-stat-pools
operator: Don't remove existing pools for mgr/prometheus/rbd_stats_pools
2022-10-12 14:20:47 -06:00
Avan Thakkar e8b74207dd operator: don't remove existing pools for mgr/prometheus/rbd_stats_pools
Rook currently knows rbd pools only if they defined through CephBlockPool, so it overrides the config
mgr/prometheus/rbd_stats_pools which may have already been set for pools external to Rook. Check config
before running set command and if there some existing pools append them to enableStatsForCephBlockPools.

Signed-off-by: Avan Thakkar <athakkar@redhat.com>
2022-10-12 20:59:44 +05:30
Travis Nielsen 4c11ba76d7 Merge pull request #10721 from zhucan/bugfix-10712
pool: add timeout to ceph cmd
2022-10-12 08:31:52 -06:00
Blaine Gardner 51fac0a993 nfs: fix nfs grace period when multus is enabled
Run the ganesha-rados-grace command in a remote pod when multus
networking is enabled.

Signed-off-by: parth-gr <paarora@redhat.com>
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2022-10-05 16:28:36 -06:00
Travis Nielsen f79ff42e0c mgr: set the public dashboard port differently from the target port
If the port is greater than 1024, for backward compatibility the port and
targetPort should be the same value. If the port is less than 1024,
the internal port must use a higher port number. In that case, the internal
port will be the default port numbers and only the public port will be
the desired port in the cluster CR.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-10-05 11:37:37 -06:00
Blaine Gardner 61279e9820 Merge pull request #11018 from thotz/obc-tls-insecurity-flag-skip
rgw: handle insecure flag skip for obc in the tls config
2022-09-30 10:36:42 -06:00
Travis Nielsen 4370d9c710 Merge pull request #11085 from humblec/sidecar-update
update sidecars to latest in CSI deployment
2022-09-29 08:46:30 -06:00
Humble Chirammal b9fb023edf csi: explicitly set default fstype for attacher sidecar
With the attacher sidecar update to v4.0.0 this has to be set
explictly.

Signed-off-by: Humble Chirammal <hchiramm@redhat.com>
2022-09-29 19:35:24 +05:30
Humble Chirammal c847e6b98d csi: update sidecars to latest in CSI deployment
Signed-off-by: Humble Chirammal <hchiramm@redhat.com>
2022-09-29 19:35:17 +05:30
Humble Chirammal 4d435b224f csi: use ceph csi v3.7.1 for rook csi driver deployment
Signed-off-by: Humble Chirammal <hchiramm@redhat.com>
2022-09-29 16:46:43 +05:30
Travis Nielsen 0779618816 Merge pull request #10966 from avanthakkar/customizable-image-pull-policy
operator: make imagePullPolicy customizable for csi driver and ceph pods
2022-09-28 07:23:26 -06:00
Blaine Gardner 3081817302 Merge pull request #11042 from BlaineEXE/nfs-sssd-arbitrary-files
nfs: allow users to include additional files in the SSSD sidecar
2022-09-27 11:51:40 -06:00
Avan Thakkar 934aa91056 operator: make imagePullPolicy customizable for csi driver and ceph pods
Introduce a new env variable ROOK_CSI_IMAGE_PULL_POLICY in rook operator configmap which should be used to
customize the imagePullPolicy for the csi driver and imagePullPolicy property in cephVersionSpec for ceph pods.

Signed-off-by: Avan Thakkar <athakkar@redhat.com>
2022-09-27 11:57:43 +05:30
Niels de Vos 79adad7dc0 nfs: allow users to include additional files in the SSSD sidecar
The sssd.conf may refer to additional files, like a CA bundle or TLS
certificates. These files need to be made available in the SSSD sidecar.
With the new `sssdGenericFiles` reference to a VolumeSource and a
`MountPath`, a provided `sssd.conf` can use the additional files.

Signed-off-by: Niels de Vos <ndevos@redhat.com>
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2022-09-26 16:50:50 -06:00
Blaine Gardner 2965373ea9 Merge pull request #10898 from parth-gr/test-nfs
nfs: fix nfs if multus is enabled
2022-09-22 12:27:47 -06:00
parth-gr 26584fc6e5 core: update loadclusterInfo with multus check
if Multus is enabled the clusterinfo should be updated with
network as multus as to run the ceph cmds in remote
executor

Signed-off-by: parth-gr <paarora@redhat.com>
2022-09-22 14:46:51 +05:30
Prasanna Kumar Kalever bf3a3aa92e csi: make sure we reset CSIParam booleans to default
On removing or setting params to false in operator config map, make sure
to set CSIParam to their appropriate defaults, since we are not restarting the
operator we cannot just assume these params/variables/flags are defaulted,
everytime we need to makesure some defaults are specified.

This is what happens without these changes:
* Set CSI_ENABLE_METADATA to true, this will tune CSIParam.CSIEnableMetadata
  to true from false
* Create a PVC and check the metadata is added to the rbd/cephfs volumes
* Now Set CSI_ENABLE_METADATA to false, we assume CSIParam.CSIEnableMetadata
  will be set to false, but that is not happening because the earlier value
  of `CSIParam.CSIEnableMetadata = true` still persist.
  (we are not restarting operator to assume value of CSIParam.CSIEnableMetadata
   to be reset to false)

This happens with CSI_ENABLE_OMAP_GENERATOR and many other flags too,
fixing them all with these changes.

Thanks to Madhu for debugging the issue and testing it along.

Credit: Madhu Rajanna <madhupr007@gmail.com>
Signed-off-by: Prasanna Kumar Kalever <prasanna.kalever@redhat.com>
2022-09-21 17:23:37 +05:30
Jiffin Tony Thottan d605ba4cf8 rgw: handle insecure flag skip for obc in the tls config
OBC provisioner ignores insecure skip flag even if it is declared for
TLS auth, hence bucket creation was failing

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2022-09-20 00:05:43 +05:30
Joshua Hoblitt 0763f91f93 operator: silence 'cm is handled by another watcher' DEBUG messages
I guesstimate that around 50% of the operator log volume when set to log
level `DEBUG` are messages about cm's which aren't relevant to rook.

E.g.:

```
2022-09-16 23:03:05.430839 D | ceph-cluster-controller: hot-plug cm watcher: only reconcile on hot plug cm changes, this "ingress-controller-leader" cm is handled by another watcher
2022-09-16 23:03:05.643255 D | ceph-cluster-controller: hot-plug cm watcher: only reconcile on hot plug cm changes, this "fleet-agent-lock" cm is handled by another watcher
2022-09-16 23:03:05.799526 D | ceph-cluster-controller: hot-plug cm watcher: only reconcile on hot plug cm changes, this "cattle-controllers" cm is handled by another watcher
```

Yes, it is `DEBUG` and noise is expected. However, there is no message
about checking the status of the cm's rook actually needs to watch and
these messages don't seem very useful. I have been resorting to piping
the operators logs through `| grep -v 'hot-plug cm watcher'` to cut down
the noise.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2022-09-16 16:23:19 -07:00
Madhu Rajanna 80a96f8f32 csi: customize plugin volumes and volumemounts
This option open-up volumes and volumemounts
for user customization of the rbd,cephfs,nfs
plugin daemonset.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2022-09-16 09:57:37 +05:30
zhucan aa41742c83 pool: add timeout to rbd cmd
Signed-off-by: zhucan <zhucan.k8s@gmail.com>
2022-09-16 10:26:20 +08:00
subhamkrai cfc5f19f92 core: use assimilate-conf command to run commands
this commit uses the ceph feature assimilate-conf to set
multiple configurations for ceph global/pods at one file and
use that in command to set the required configuration in one
line command.
for example:
`ceph config assimilate-conf -i <input file> -o <output file>`

Signed-off-by: subhamkrai <srai@redhat.com>
2022-09-15 17:53:58 +05:30
Randy J. Martinez ac9df66b76 core: increase liveness probe timeout to 5s
stability issues have been observed with 1s.
socket latency is expected whenever CPUs are
under minor pressure. Increasing value to
5s should cover most small-medium scale envs.

Resolves BZ: 2126566

Signed-off-by: Randy J. Martinez <randy@cephtips.com>
2022-09-13 17:32:43 -05:00
Blaine Gardner 697f34fcee Merge pull request #10950 from BlaineEXE/nfs-kerberos-implementation
nfs: add kerberos client security support
2022-09-13 10:05:14 -06:00
Blaine Gardner 005000212c nfs: add kerberos client security support
Add support for enabling kerberos for client authentication.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2022-09-13 08:46:52 -06:00
Rakshith R c02f3194d1 pool: initialize only rbd application pools
`rbd pool init` cmd initializes pool for rbd images.
This commit makes modification to init only
rbd application pools, since it is not required
by other pools like ".nfs",".mgr" & "mgr_devicehealth".

Signed-off-by: Rakshith R <rar@redhat.com>
2022-09-13 18:18:26 +05:30
Travis Nielsen ef3f55460c Merge pull request #10728 from thotz/multisite-delete-zone-pools
rgw: delete zone/pools for multisite configuation
2022-09-12 13:42:42 -06:00
Jiffin Tony Thottan c98628eb0f rgw: delete zone/pools for multisite configuation
Allow option to delete the zone/pools created by ceph object zone CR.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2022-09-12 21:44:55 +05:30
Rakshith R 3c5a2f4142 csi: add topology provisioning support
This commit adds topology provisioning
support. This makes modification to rbac,
csi deployment and daemonset.

Signed-off-by: Rakshith R <rar@redhat.com>
2022-09-12 16:10:18 +05:30
Travis Nielsen 91ede0279e Merge pull request #10889 from Rakshith-R/add-kmip-support
osd: add kmip encryption support
2022-09-09 14:23:19 -06:00
Rakshith R f21c12234d osd: add kmip encryption support
The cluster-wide encryption feature now
supports KMIP (Key Management Interoperability Protocol)
kms.
KMIP is an extensible communication protocol that defines
message formats for the manipulation of cryptographic keys
on a key management server.

For more information, refer:
https://en.wikipedia.org/wiki/Key_Management_Interoperability_Protocol

Signed-off-by: Rakshith R <rar@redhat.com>
2022-09-09 11:39:33 +05:30
Rakshith R 9c4592720c csi: add NFS expansion support
This commit adds resizer sidecar to
NFS driver and required storageclass
and rbac changes.

Signed-off-by: Rakshith R <rar@redhat.com>
2022-09-08 16:15:37 +05:30
Rakshith R 73042c7531 csi: add NFS snapshot support
This commit adds snapshotter sidecar to
NFS driver and required yamls and docs too.

Signed-off-by: Rakshith R <rar@redhat.com>
2022-09-08 16:15:37 +05:30
Blaine Gardner 270579e144 Merge pull request #10776 from motorailgun/better-healthcheck-message
operator: improve ProbeHandler error message
2022-09-07 11:49:59 -06:00
Travis Nielsen 80e80ffeb2 Merge pull request #10906 from Madhu-1/fix-csi-config
csi: remove findCSIChange from predicate
2022-09-07 09:10:55 -06:00