Commit Graph
224 Commits
Author SHA1 Message Date
Blaine Gardner 243a47bfc4 build: do not use cross build container for ceph
Do not use the cross build container when building, publishing, and
promoting rook/ceph images. It is no longer needed, and its complexity
can add flakiness.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-12-03 11:06:21 -07:00
Blaine Gardner 113e2f849d build: use yq for RBAC yaml parsing
Use yq instead of Python for parsing RBAC from the Helm chart. We need
to use yq v4.14.1 or higher to fix yq's handling of the yaml header
markers ('---'). Update the Makefile's yq version to v4, which also
requires updating the script to update the CRDs. This was quite easy.

It is very difficult, however, to change the version of yq used by the
CSV generating/parsing scripts, which already used their own yq
download. Continue using yq v3 for this.

In order to make sure the scripts are using the right version of yq, add
basic validation to them to verify they are running v3 or v4 as required
for their operation.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-11-30 08:08:08 -07:00
Sébastien Han c890710b63 core: change directory layout
As per discussion, proposing a new layout for the charts/yaml/olm files.

./deploy
├── charts
│   ├── rook-ceph
│   │   └── templates
│   └── rook-ceph-cluster
│       └── templates
├── examples
│   ├── csi
│   │   ├── cephfs
│   │   └── rbd
│   ├── flex
│   ├── monitoring
│   ├── pre-k8s-1.16
└── olm
    └── assemble

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-11-30 09:12:53 +01:00
Sébastien Han 7a223adde4 Merge pull request #9230 from leseb/osd-rm-check
osd: check if osd is safe-to-destroy before removal
2021-11-25 10:55:34 +01:00
Sébastien Han ad2c3c2ae6 Merge pull request #8931 from BlaineEXE/test-rgw-multisite-in-nightly-tests
test: test rgw multisite nightly
2021-11-25 10:25:57 +01:00
Sébastien Han 7402c2cce6 osd: check if osd is ok-to-stop before removal
If multiple removal jobs are fired in parallel, there is a risk of
losing data since we will forcefully remove the OSD. It's also simply
true if a single OSD is not safe to destroy, there is also a risk of
data loss.

So now, we check if the OSD is safe-to-destroy first and then proceed.
The code waits forever and retries every minute unless the
--force-osd-removal flag is passed.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-11-25 10:21:32 +01:00
Travis Nielsen ba54567e8f Merge pull request #9176 from TomHellier/9174-ingress-support-more-k8s-versions
helm: Allow further configurability of the ingress version
2021-11-23 13:47:33 -07:00
Tom Hellier ba44602477 helm: allow further configurability of ingress version
The ingress api version changed when it went to v1, and this has caused some upheaval
throughout the kubernetes ecosystem. This commit uses a common method of deciding which
ingress api to use, and allows the optional override of the kubernetes version
presented to helm using the helm build-in capabilities.
also add an ingress into the helm integration tests so any regressions to how ingresses
are handled in the future are caught easier.

Closes rook#9174

Signed-off-by: Tom Hellier <me@tomhellier.com>
2021-11-22 10:03:02 +00:00
Blaine Gardner e80368674d test: run RGW multisite test in nightly job
In the nightly job, run the test with the latest Ceph version so we can
detect if there are RGW changes in Ceph that might break multisite. Use
a reusable GitHub action workflow to duplicate as little code as
possible.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-11-19 09:56:41 -07:00
Jiffin Tony Thottan aba50d3ca9 object: add support in RGW to communicate vault with TLS
From ceph v16.2.6 onwards the vault TLS suppport in RGW was added,
include similar changes for RGW.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2021-11-17 10:19:28 +05:30
subhamkrai 99358688d8 ci: use github composition to reduce duplication
Using Github Compositoin to reduce the yaml duplication.
https://github.blog/changelog/2021-08-25-github-actions-reduce-duplication-with-action-composition/

Closes: https://github.com/rook/rook/issues/8637
Signed-off-by: subhamkrai <srai@redhat.com>
2021-11-09 16:41:55 +05:30
Sébastien Han 8cfaedcbf6 Merge pull request #9127 from leseb/fix-9090
ci: wait for kubeproxy to be ready
2021-11-08 18:16:57 +01:00
Sébastien Han 0e26176b54 ci: wait for kubeproxy to be ready
When requesting issuer, we run a local kubectl proxy command which spawn
a proxy server. However, we must wait for the proxy to be ready before
we actually start making requests to it.
Now the CI waits up to 10sec to retrieve the issuer.

Closes: https://github.com/rook/rook/issues/9090
Signed-off-by: Sébastien Han <seb@redhat.com>
2021-11-08 17:45:53 +01:00
Satoru Takeuchi cd4862a7f7 Merge pull request #9123 from leseb/fix-arm64
ci: fix arm64 job
2021-11-08 20:19:11 +09:00
Sébastien Han d081a3e764 ci: fix arm64 job
They are no arm64 packages for ceph-nfs so we must skip this validation
for the nightly arm64 CI job.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-11-08 09:18:23 +01:00
Sébastien Han d06a6f93a5 core: run operator with rook user
The rook operator as well as the toolbox pod run with the "rook" user
with UID 2016. The UID was chosen based on the year of the initial
commit in the rook/rook repository.
No more root user running.

Closes: https://github.com/rook/rook/issues/8734
Signed-off-by: Sébastien Han <seb@redhat.com>
2021-11-05 17:22:04 +01:00
Blaine Gardner cd480df581 Merge pull request #9112 from BlaineEXE/allow-push-image-build-on-tag-again
Revert "ci: trigger push build action after tag creation"
2021-11-04 14:48:36 -06:00
Blaine Gardner 30e02c1063 Revert "ci: trigger push build action after tag creation"
This reverts commit c53304c3b4.

After experimenting with this release, we have found that the
`workflow_run` action source doesn't work for branches. The
documentation was updated with this PR and has more detail.
https://github.com/github/docs/pull/531

For now, we will revert back to using on.push.tags = ["v*"]

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-11-04 14:40:37 -06:00
Travis Nielsen b3b8172e13 Merge pull request #9056 from leseb/fix-8851
docs: simplify dev guide
2021-11-03 12:34:41 -06:00
Sébastien Han 85f8fdec5a docs: simplify dev guide
We removed the obsolete `minikube.sh` script for a cleaner dev
procedure.

Closes: https://github.com/rook/rook/issues/8851
Signed-off-by: Sébastien Han <seb@redhat.com>
2021-11-03 18:56:33 +01:00
Yuzuki Mimura 536b59ef0f rgw: change the way to livenessProbe and introduce readinessProbe
rgw doesn't respond `livenessProbe` if the number of connection reaches its
limit (by default, 1000). Then rgw is out of service but still live.
Hense the current `livenessProbe` logic is suitiable for `readinessProbe`.
`tcpSocket` is enough for `livenessProbe`.

Closes: #8407

Signed-off-by: Yuzuki Mimura <yuzuki725.m@gmail.com>
Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
2021-10-29 15:07:29 +00:00
Satoru Takeuchi 79571d860a test: remove an unnecessary check in rgw-multisite-testing
The deployment of the OSD is already confirmed at the end of
`deploy first cluster rook' step.

Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
2021-10-29 13:52:35 +00:00
Sébastien Han f2cb792e9f rgw: add support for updating user caps
User's capabilities can now be updated from the admin ops API.

Closes: https://github.com/rook/rook/issues/8683
Signed-off-by: Sébastien Han <seb@redhat.com>
2021-10-28 14:17:13 +02:00
Sébastien Han 522fa7a782 ci: wait longer on fs mirroring
It looks like the CI needs more time.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-10-26 11:01:11 +02:00
Sébastien Han d8e9885fd6 ci: only run snyk on merges and not on PRs
We cannot use the secret when PRs are pushed from forks so let's run the
security scan only after PRs are merged.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-10-26 10:55:43 +02:00
subhamkrai 0ebbb78373 ci: update snyk token
Update snyk token, it was pointing to wrong token.

Signed-off-by: subhamkrai <srai@redhat.com>
2021-10-26 08:51:51 +05:30
Sébastien Han 3b5bbf28d5 Merge pull request #9003 from leseb/vault-k8s-auth
osd: add support for k8s with vault kms
2021-10-25 18:02:48 +02:00
subhamkrai faefd097b0 ci: add action for synk as rook licence
Adding github action for synk as licence for rook.
This will replace FOSSA licence in future.

Links to read about synk
1. https://snyk.io/
2. https://github.com/snyk/snyk

Signed-off-by: subhamkrai <srai@redhat.com>
2021-10-25 13:33:09 +05:30
Sébastien Han 18a4047679 osd: add support for k8s with vault kms
Rook cluster-wide encryption can now use the native Kubernetes
authentication to interact with vault KMS instead of using the token
method.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-10-21 13:59:28 +02:00
Sébastien Han 07f006ac43 ci: fix mirror scenario by removing ownerref
When we copy the peer token secret from a namespace to another we also
copy the ownerref, however the creation succeeds but the controller
removes the secret since the uid of the owner do not exist in that
namespace.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-10-21 12:11:10 +02:00
subhamkrai 6d0a06365f ci: update minikube and kubernetes version
Updating minikube version to `v1.23.2` and
k8s version to `v1.22.2`

Signed-off-by: subhamkrai <srai@redhat.com>
2021-10-20 10:04:31 +05:30
Blaine Gardner 65619c2677 test: get more partition info setting up ci disk
Add some commands to get more partition info when setting up the GH
action runner's disk for use in integration tests. This will both aid in
debugging and may "jog" the system such that it will no longer need to
reload the partition info when running the OSD prepare job.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-10-18 11:29:13 -06:00
Blaine Gardner ba7745d4af test: do not use head because of pipe errors
The `head` command exits once it has output which can result in a
SIGPIPE error if the command piping its output to head hasn't yet
finished. Use `awk 'FNR <= 1'` instead, which waits on the input pipe to
close before it exits.

See here for more info:
https://unix.stackexchange.com/a/256047

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-10-15 10:14:41 -06:00
Sébastien Han efa60b44c8 ci: only validate osds for mirror test
The Filesystem is deployed later in the run so at this point we only
need to validate the OSDs are running. This was failing since we were
validating the cephfs pool which is not present yet.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-10-15 10:36:15 +02:00
Blaine Gardner 34a8b42e97 test: try to un-flake multi-cluster-mirror test
Try to un-flake the multi-cluster-mirror test that keeps failing on this
PR.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-10-13 11:06:51 -06:00
Travis Nielsen 74dac725a4 test: run the daily arm tests against official builds
The daily arm test suite is failing due to the new local-build
image tag. Instead of waiting for the arm build to complete,
we can just pick up the latest tag from the same branch
that was already pushed to dockerhub and no need to build
again.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-10-12 15:26:18 -06:00
Travis Nielsen 7006b899c9 Merge pull request #8612 from subhamkrai/trigger-after-tag
ci: trigger push build action after tag creation
2021-10-12 11:38:04 -06:00
subhamkrai c53304c3b4 ci: trigger push build action after tag creation
earlier push build action was not triggered due
to github action limitation.
```
An action in a workflow run can’t trigger a new workflow run.
```

so now, we'll use user personal toke to create tag so that push
build action pick the user not github action who created the tag.

Closes: https://github.com/rook/rook/issues/8580
Signed-off-by: subhamkrai <srai@redhat.com>
2021-10-12 10:22:38 +05:30
Blaine Gardner 956430826c rgw: add integration test for committing period
Add to the RGW multisite integration test a verification that the RGW
period is committed on the first reconcile and not committed on the
second reconcile.

Do this in the multisite test so that we verify that this works for
both the primary and secondary multi-site cluster.

To add this test, the github-action-helper.sh script had to be modified
to
1. actually deploy the version of Rook under test
2. adjust how functions are called to not lose the `-e` in a subshell
3. fix wait_for_prepare_pod helper that had a failure in the middle
   of its operation that didn't cause failures in the past

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-10-11 15:24:59 -06:00
Travis Nielsen af29d1d801 build: run canary tests against the local-build tag
The canary tests were still picking up the tag from operator.yaml
and toolbox.yaml instead of the new test local-build tag.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
(cherry picked from commit 6f48dce3f5)
2021-09-30 15:33:48 -06:00
Travis Nielsen aa085c93b9 Merge pull request #8895 from leseb/mgr-weekly
ci: run the orch ceph manager test daily
2021-09-30 15:31:24 -06:00
Blaine Gardner e2ba16f710 build: start tracking rbac generated from helm chart
This is a starting step to be able to generate common.yaml from Helm
charts. For right now, we merely want to be able to determine when the
rendered output of the Helm chart changes.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-09-30 12:20:24 -06:00
Sébastien Han 04e1589a33 ci: run the orch ceph manager test daily
Let's run the test every day at midnight since the code is moving
fast and tends to fail. This gives us some time to fix the issues.
It can be triggered on PR too if the "run-mgr-suite" label is set.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-09-30 18:54:09 +02:00
Blaine Gardner 24bf99f31c build: use intermediate tmp for offline image gen
Reading from a file, processing the file in a pipe, and outputting the
piped content to the same file can have undefined results, often leading
to an empty file. Use an intermediate temp file for generating the
offline image list.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-09-29 17:31:02 -06:00
Sébastien Han cb3d342515 ci: fix the test name for upgrade suite
Since we were pointing at CephUpgradeSuite test only this was running
all the tests and thus some resources were created by other tests.
Let's just run the test we need.

Closes: https://github.com/rook/rook/issues/8843
Signed-off-by: Sébastien Han <seb@redhat.com>
2021-09-28 09:12:37 +02:00
Travis Nielsen 45fe8eadd5 Merge pull request #8838 from subhamkrai/comment-tmate-session
ci: run tmate session only on PR
2021-09-27 10:33:52 -06:00
subhamkrai fb13b5cad0 ci: run tmate session only on PR
run tmate only for `pull_request` event and
remove for other events. As during release
when tests fail it takes extra 30 min to fail the
test or someone manually has to end the test
which is painfully especially during release time.

Signed-off-by: subhamkrai <srai@redhat.com>
2021-09-27 19:52:37 +05:30
Sébastien Han 33dbaba38b ci: add daily jobs
We have new jobs now:

* one that runs both smoke and object on the next Pacific version
* one that runs both smoke and object on Ceph master
* one that tests the upgrade from the current pacific stable to the
  pacific devel
* one that tests the upgrade from the current octopus stable to the
  octopus devel

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-09-27 11:59:04 +02:00
Travis Nielsen f5c1543ddf build: update min k8s version to 1.16
In Rook v1.8 the min version of K8s supported is updated to 1.16.
Users running on older versions of K8s are recommended to update
to 1.16 or newer before updating to Rook v1.8.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-09-23 16:17:56 -06:00
Travis Nielsen 0a0b9c98bd build: remove obsolete flex driver
The flex driver has been fully deprecated and thus removed from Rook.
Before upgrading to v1.8, users will need to convert existing flex volumes
from flex to csi volumes.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-09-23 16:17:20 -06:00