The crash collector does not have the command line arguments
to run as ceph user id 167, so we set the security context
to run as the ceph user in the main crash collector
container.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
The osd arguments had a few duplicate lines that could be
factored out and thus simplified for code maintainability.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
Removing the finalizers from cluster resources can intermittently fail
in the CI if other updates are made at similar times. The controller
runtime will retry after the failure, but if something external
removes the finalizer on the cephcluster CR, the deletion will not
continue with the removal of finalizers from the other configmap
and secret critical resources.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
If the host network setting is changed in the cluster CR,
the existing mons must continue using the same network
settings or else the operator would update their pod
specs with the incorrect settings and cause mon quorum
to go down. Now the network setting is preserved so
the admin could switch between host and non-host network
configuration without reinstalling.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
This updates the cephcsi to latest 3.7.2
release and also updates sidecar to the latest
release in some missing files.
Note:- sidecar images are upto date in most of
the places, in some places it was missing, This
PR updates it in missing place.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
The `periodWillChange()` implementation to detect map keys to ignore.
Previously, we relied on the `GoString()` method to output the same
format always to determine the current path to the
map[string]interface{} node, but that may change depending on the underlying
implementation of go-cmp.
Instead, parse the go-cmp `Path` step by step and construct a JSON path
to the node in a stable format.
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
Remove the health checker for CephObjectStore. The liveness and
readiness probes go through the same code paths in RGW as creating
buckets without as much affect on the storage backend.
Full discussion: https://github.com/rook/rook/issues/11031
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
The omap generator sidecar is the one who
sets the pvc name and clustername in the metadata
if the pv is re-attached to a new pvc or if the
clustername changes, for that reason we need to
set these flags on the omap generator sidecar
also.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
Rook currently knows rbd pools only if they defined through CephBlockPool, so it overrides the config
mgr/prometheus/rbd_stats_pools which may have already been set for pools external to Rook. Check config
before running set command and if there some existing pools append them to enableStatsForCephBlockPools.
Signed-off-by: Avan Thakkar <athakkar@redhat.com>
Run the ganesha-rados-grace command in a remote pod when multus
networking is enabled.
Signed-off-by: parth-gr <paarora@redhat.com>
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
If the port is greater than 1024, for backward compatibility the port and
targetPort should be the same value. If the port is less than 1024,
the internal port must use a higher port number. In that case, the internal
port will be the default port numbers and only the public port will be
the desired port in the cluster CR.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
Introduce a new env variable ROOK_CSI_IMAGE_PULL_POLICY in rook operator configmap which should be used to
customize the imagePullPolicy for the csi driver and imagePullPolicy property in cephVersionSpec for ceph pods.
Signed-off-by: Avan Thakkar <athakkar@redhat.com>
The sssd.conf may refer to additional files, like a CA bundle or TLS
certificates. These files need to be made available in the SSSD sidecar.
With the new `sssdGenericFiles` reference to a VolumeSource and a
`MountPath`, a provided `sssd.conf` can use the additional files.
Signed-off-by: Niels de Vos <ndevos@redhat.com>
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
if Multus is enabled the clusterinfo should be updated with
network as multus as to run the ceph cmds in remote
executor
Signed-off-by: parth-gr <paarora@redhat.com>
On removing or setting params to false in operator config map, make sure
to set CSIParam to their appropriate defaults, since we are not restarting the
operator we cannot just assume these params/variables/flags are defaulted,
everytime we need to makesure some defaults are specified.
This is what happens without these changes:
* Set CSI_ENABLE_METADATA to true, this will tune CSIParam.CSIEnableMetadata
to true from false
* Create a PVC and check the metadata is added to the rbd/cephfs volumes
* Now Set CSI_ENABLE_METADATA to false, we assume CSIParam.CSIEnableMetadata
will be set to false, but that is not happening because the earlier value
of `CSIParam.CSIEnableMetadata = true` still persist.
(we are not restarting operator to assume value of CSIParam.CSIEnableMetadata
to be reset to false)
This happens with CSI_ENABLE_OMAP_GENERATOR and many other flags too,
fixing them all with these changes.
Thanks to Madhu for debugging the issue and testing it along.
Credit: Madhu Rajanna <madhupr007@gmail.com>
Signed-off-by: Prasanna Kumar Kalever <prasanna.kalever@redhat.com>
OBC provisioner ignores insecure skip flag even if it is declared for
TLS auth, hence bucket creation was failing
Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
I guesstimate that around 50% of the operator log volume when set to log
level `DEBUG` are messages about cm's which aren't relevant to rook.
E.g.:
```
2022-09-16 23:03:05.430839 D | ceph-cluster-controller: hot-plug cm watcher: only reconcile on hot plug cm changes, this "ingress-controller-leader" cm is handled by another watcher
2022-09-16 23:03:05.643255 D | ceph-cluster-controller: hot-plug cm watcher: only reconcile on hot plug cm changes, this "fleet-agent-lock" cm is handled by another watcher
2022-09-16 23:03:05.799526 D | ceph-cluster-controller: hot-plug cm watcher: only reconcile on hot plug cm changes, this "cattle-controllers" cm is handled by another watcher
```
Yes, it is `DEBUG` and noise is expected. However, there is no message
about checking the status of the cm's rook actually needs to watch and
these messages don't seem very useful. I have been resorting to piping
the operators logs through `| grep -v 'hot-plug cm watcher'` to cut down
the noise.
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
This option open-up volumes and volumemounts
for user customization of the rbd,cephfs,nfs
plugin daemonset.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
this commit uses the ceph feature assimilate-conf to set
multiple configurations for ceph global/pods at one file and
use that in command to set the required configuration in one
line command.
for example:
`ceph config assimilate-conf -i <input file> -o <output file>`
Signed-off-by: subhamkrai <srai@redhat.com>
stability issues have been observed with 1s.
socket latency is expected whenever CPUs are
under minor pressure. Increasing value to
5s should cover most small-medium scale envs.
Resolves BZ: 2126566
Signed-off-by: Randy J. Martinez <randy@cephtips.com>
`rbd pool init` cmd initializes pool for rbd images.
This commit makes modification to init only
rbd application pools, since it is not required
by other pools like ".nfs",".mgr" & "mgr_devicehealth".
Signed-off-by: Rakshith R <rar@redhat.com>
This commit adds topology provisioning
support. This makes modification to rbac,
csi deployment and daemonset.
Signed-off-by: Rakshith R <rar@redhat.com>
The cluster-wide encryption feature now
supports KMIP (Key Management Interoperability Protocol)
kms.
KMIP is an extensible communication protocol that defines
message formats for the manipulation of cryptographic keys
on a key management server.
For more information, refer:
https://en.wikipedia.org/wiki/Key_Management_Interoperability_Protocol
Signed-off-by: Rakshith R <rar@redhat.com>