It should be possible to configure the storage classs mount options, this follows
the helm code used by the ceph-csi project for their ceph-csi-rbd and ceph-csi-cephfs
helm charts.
Signed-off-by: Tom Hellier <me@tomhellier.com>
This commit introduces a new configuration option for
ceph csi driver to enable hostpath mounting of /etc/selinux
directory from the cluster node where csi plugin pods are
running, which inturn help the csi driver to specify
selinux-related mount options like context.
Ref# https://github.com/ceph/ceph-csi/issues/2295
The default value for this configuration is true and if cluster
nodes are running without selinux enabled, an admin can deploy
csi pods by specifying this option to `false` which skip the
host path mounting for the csi pods.
Signed-off-by: Humble Chirammal <hchiramm@redhat.com>
The instructions to deploy a developer environment are useful and should
be part of the official documentation instead of being hidden in the
repo's README.md. Also, remove ancient documentation to deploy with
kubespray a multi-node env.
Also, add a warning to always run tests env in a virtual machine.
Closes: https://github.com/rook/rook/issues/9166
Signed-off-by: Sébastien Han <seb@redhat.com>
By default HPA can use details about memory or CPU consumption for
autoscaling, but also it can use custom metrics as well. There are alot
provides supports HPA via customer and one of them is KEDA project. Here
it is done with help of Prometheus Scaler
Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
The ingress api version changed when it went to v1, and this has caused some upheaval
throughout the kubernetes ecosystem. This commit uses a common method of deciding which
ingress api to use, and allows the optional override of the kubernetes version
presented to helm using the helm build-in capabilities.
also add an ingress into the helm integration tests so any regressions to how ingresses
are handled in the future are caught easier.
Closes rook#9174
Signed-off-by: Tom Hellier <me@tomhellier.com>
Ceph has recently reported that it may be unsafe to upgrade clusters
from Nautilus/Octopus to Pacific v16.2.0 through v16.2.6. We are
tracking this in Rook issue https://github.com/rook/rook/issues/9185.
Add a warning to the upgrade doc about this.
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
From ceph v16.2.6 onwards the vault TLS suppport in RGW was added,
include similar changes for RGW.
Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
The latest docs should link to the master examples on github.
Only the docs were renamed to latest, but not the github branch.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
With the recent rename of master docs to the latest docs,
the links from the docs back to github need to be generated
with the latest url instead of master.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
The toolbox can now interact with S3 gateways using the `s5cmd` tool.
The binary is only 12M so this does not add up too much to the operator
image size.
Closes: https://github.com/rook/rook/issues/4968
Signed-off-by: Sébastien Han <seb@redhat.com>
We can pass bound_service_account_names with a comma separated list of
service accounts. Let's do this instead of remapping new values.
Earlier, we thought a single service account could be added per Vault
role and we were using other variables like
`VAULT_AUTH_KUBERNETES_ROOK_OPERATOR_ROLE` that we were remapping to
`VAULT_AUTH_KUBERNETES_ROLE` internal for the API calls to Vault.
Signed-off-by: Sébastien Han <seb@redhat.com>
This commit make required changes for ceph csi drivers to work with
ephemeral volume support. With ephemeral volume support a user can
specify ephemeral volumes in its pod spec and tie the lifecycle
of the PVC with the POD.
An example POD spec looks like this:
```
kind: Pod
apiVersion: v1
metadata:
name: csi-rbd-demo-ephemeral-pod
spec:
containers:
- name: web-server
image: docker.io/library/nginx:latest
volumeMounts:
- mountPath: "/myspace"
name: mypvc
volumes:
- name: mypvc
ephemeral:
volumeClaimTemplate:
spec:
accessModes: ["ReadWriteOnce"]
storageClassName: "rook-ceph-block"
resources:
requests:
storage: 1Gi
```
Signed-off-by: Humble Chirammal <hchiramm@redhat.com>
We should only rely on the content of the repo and not copy YAML
examples into the documentation as it forces us to keep all versions in
sync all the time. The examples directory is the only source of truth.
Signed-off-by: Sébastien Han <seb@redhat.com>
Ths NFS spec now supports the CephBlockPool spec which means that it can
take advantage of all the known settings like compression, size, failure
domain etc.
Closes: https://github.com/rook/rook/issues/9034
Signed-off-by: Sébastien Han <seb@redhat.com>
The appVersion should be set to the version of the application. Since the helm
charts are built by Rook in the same release version as Rook itself, the
version and appVersion values will be the same.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
If the admin wants to use insecure TLS to validate connections to rgw
internally, the TLS secret can have another entry "insecureSkipVerify"
and set it to "true".
Signed-off-by: Sébastien Han <seb@redhat.com>
We can now set labels to the crash collector deployment by editing the
CephCluster CR with:
```yaml
spec:
labels:
crashcollector:
```
Closes: https://github.com/rook/rook/issues/9039
Signed-off-by: Sébastien Han <seb@redhat.com>
Rook cluster-wide encryption can now use the native Kubernetes
authentication to interact with vault KMS instead of using the token
method.
Signed-off-by: Sébastien Han <seb@redhat.com>
add a document to track the steps for failover
and failback in case of Async DR; for Planned
Migration and Disaster Recovery use case.
Signed-off-by: Yug Gupta <yuggupta27@gmail.com>
replaces all occurences of lduo/rduo quotation marks to make
sure that using the snippets in a k8s manifest will work
This fixes an issue with ArgoCD not being able
to apply `common.yaml` because of an encoding issue
Signed-off-by: PixelJonas <jonas@janz.digital>
Adding finalizers to rook-ceph-mon secrets
and rook-ceph-mon-endpoints configmap
We don't want to delete this resources during disaster
because these details are needed during disaster recovery
Closes: https://github.com/rook/rook/issues/8369
Signed-off-by: parth-gr <paarora@redhat.com>
The volume replication CRDs are an external component, not owned by Rook.
Therefore, they should be installed as any other independent component
in case the admin will install other consumers of the volumereplication CRDs
in the future in addition to Rook and the CSI driver.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
This commit adds the doc which has the manual
steps to recover from the specific scenario
like
`on the node lost, the new pod can't mount the
same volume`.
Closes: https://github.com/rook/rook/issues/1507
Signed-off-by: subhamkrai <srai@redhat.com>
This commit updates the CephNFS CR to make the RADOS settings optional
for Ceph versions above 16.2.7 due to the NFS module changes in Ceph.
The changes in Ceph make it so the RADOS pool is always ".nfs" and the
RADOS namespace is always the name of the NFS cluster.
This commit also handles the changes in Ceph Pacific versions before 16.2.7
where the default pool name is "nfs-ganesha" instead of ".nfs".
Closes: https://github.com/rook/rook/issues/8450
Signed-off-by: Joseph Sawaya <jsawaya@redhat.com>