Commit Graph
1370 Commits
Author SHA1 Message Date
Travis Nielsen baa67c8d5a Merge pull request #9287 from TomHellier/9286-add-mount-options-to-helm-chart
helm: addition of mountOptions into storage class configuration
2021-12-01 10:19:35 -07:00
Tom Hellier caa2c8323b helm: addition of mountOptions into storage class configuration
It should be possible to configure the storage classs mount options, this follows
the helm code used by the ceph-csi project for their ceph-csi-rbd and ceph-csi-cephfs
helm charts.

Signed-off-by: Tom Hellier <me@tomhellier.com>
2021-12-01 10:50:42 +00:00
Humble Chirammal e5f5d9be9f csi: mount host's /etc/selinux in node plugins
This commit introduces a new configuration option for
ceph csi driver to enable hostpath mounting of /etc/selinux
directory from the cluster node where csi plugin pods are
running, which inturn help the csi driver to specify
selinux-related mount options like context.

Ref# https://github.com/ceph/ceph-csi/issues/2295

The default value for this configuration is true and if cluster
nodes are running without selinux enabled, an admin can deploy
csi pods by specifying this option to `false` which skip the
host path mounting for the csi pods.

Signed-off-by: Humble Chirammal <hchiramm@redhat.com>
2021-12-01 11:13:26 +05:30
Sébastien Han c890710b63 core: change directory layout
As per discussion, proposing a new layout for the charts/yaml/olm files.

./deploy
├── charts
│   ├── rook-ceph
│   │   └── templates
│   └── rook-ceph-cluster
│       └── templates
├── examples
│   ├── csi
│   │   ├── cephfs
│   │   └── rbd
│   ├── flex
│   ├── monitoring
│   ├── pre-k8s-1.16
└── olm
    └── assemble

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-11-30 09:12:53 +01:00
Travis Nielsen ba54567e8f Merge pull request #9176 from TomHellier/9174-ingress-support-more-k8s-versions
helm: Allow further configurability of the ingress version
2021-11-23 13:47:33 -07:00
Travis Nielsen d340bccd44 Merge pull request #9202 from thotz/hpakedadoc
docs: add details about HPA via KEDA
2021-11-23 10:42:03 -07:00
Sébastien Han f9f08c88ca docs: move the test readme to the official doc
The instructions to deploy a developer environment are useful and should
be part of the official documentation instead of being hidden in the
repo's README.md. Also, remove ancient documentation to deploy with
kubespray a multi-node env.
Also, add a warning to always run tests env in a virtual machine.

Closes: https://github.com/rook/rook/issues/9166
Signed-off-by: Sébastien Han <seb@redhat.com>
2021-11-23 15:56:28 +01:00
Jiffin Tony Thottan d32c837e35 docs: add details about HPA via KEDA
By default HPA can use details about memory or CPU consumption for
autoscaling, but also it can use custom metrics as well. There are alot
provides supports HPA via customer and one of them is KEDA project. Here
it is done with help of Prometheus Scaler

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2021-11-23 16:50:18 +05:30
Tom Hellier ba44602477 helm: allow further configurability of ingress version
The ingress api version changed when it went to v1, and this has caused some upheaval
throughout the kubernetes ecosystem. This commit uses a common method of deciding which
ingress api to use, and allows the optional override of the kubernetes version
presented to helm using the helm build-in capabilities.
also add an ingress into the helm integration tests so any regressions to how ingresses
are handled in the future are caught easier.

Closes rook#9174

Signed-off-by: Tom Hellier <me@tomhellier.com>
2021-11-22 10:03:02 +00:00
Blaine Gardner b9faa9d82f Merge pull request #9187 from BlaineEXE/bluestore_fsck_quick_fix_on_mount-upgrade-warning
docs: add OMAP quick fix warning to upgrade guide
2021-11-18 12:47:11 -07:00
Blaine Gardner cd832e5832 Merge pull request #8579 from thotz/vaultsslsupport
ceph: add support in RGW to communicate vault with TLS
2021-11-18 12:32:38 -07:00
Blaine Gardner 1f8719650a docs: add OMAP quick fix warning to upgrade guide
Ceph has recently reported that it may be unsafe to upgrade clusters
from Nautilus/Octopus to Pacific v16.2.0 through v16.2.6. We are
tracking this in Rook issue https://github.com/rook/rook/issues/9185.
Add a warning to the upgrade doc about this.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-11-18 10:04:25 -07:00
subhamkrai 951940805d docs: remove old commitlint component ceph from doc
Removing `ceph` component from doc as component
`ceph` was removed from commitlint bot earlier.

Signed-off-by: subhamkrai <srai@redhat.com>
2021-11-17 21:24:28 +05:30
Jiffin Tony Thottan aba50d3ca9 object: add support in RGW to communicate vault with TLS
From ceph v16.2.6 onwards the vault TLS suppport in RGW was added,
include similar changes for RGW.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2021-11-17 10:19:28 +05:30
Travis Nielsen ad2a1eb2ec docs: generate correct doc links to master github branch
The latest docs should link to the master examples on github.
Only the docs were renamed to latest, but not the github branch.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-11-15 13:49:17 -07:00
Travis Nielsen c3b5d3b078 Merge pull request #9155 from travisn/latest-doc-links
docs: Fix the links from docs to github examples in master branch
2021-11-11 17:27:47 -07:00
Travis Nielsen 839fdfe95d docs: fix the links to examples in master branch
With the recent rename of master docs to the latest docs,
the links from the docs back to github need to be generated
with the latest url instead of master.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-11-11 15:32:29 -07:00
Madhu Rajanna 953cabf999 docs: fix ephemeral link for rbd pod
fixed the ephemeral link for the rbd pod.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2021-11-11 20:04:55 +05:30
Sébastien Han 889856b78f core: add s5cmd binary to operator image
The toolbox can now interact with S3 gateways using the `s5cmd` tool.
The binary is only 12M so this does not add up too much to the operator
image size.

Closes: https://github.com/rook/rook/issues/4968
Signed-off-by: Sébastien Han <seb@redhat.com>
2021-11-09 16:56:30 +01:00
Travis Nielsen 6dc0cc54b9 Merge pull request #8426 from yuvalif/ceph-bucket-notifications
ceph: support bucket notifications for object storage
2021-11-04 17:35:08 -06:00
Blaine Gardner 685cf0e6d7 Merge pull request #9092 from leseb/fix-bound_service_account_names
osd: use multiple service account for vault role
2021-11-04 16:00:20 -06:00
Travis Nielsen 41ef578859 Merge pull request #9055 from humblec/ephemeral
ceph: support ephemeral volumes with Ceph CSI RBD and CephFS driver
2021-11-04 09:03:56 -06:00
Sébastien Han 16729e0e38 osd: use multiple service account for vault role
We can pass bound_service_account_names with a comma separated list of
service accounts. Let's do this instead of remapping new values.
Earlier, we thought a single service account could be added per Vault
role and we were using other variables like
`VAULT_AUTH_KUBERNETES_ROOK_OPERATOR_ROLE` that we were remapping to
`VAULT_AUTH_KUBERNETES_ROLE` internal for the API calls to Vault.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-11-04 15:15:46 +01:00
Yuval Lifshitz 71ed45b69b rgw: implement bucket notifications for object storage
following the design from here:
https://github.com/rook/rook/blob/master/design/ceph/object/ceph-bucket-notification-crd.md

Closes: https://github.com/rook/rook/issues/5313
Signed-off-by: Yuval Lifshitz <ylifshit@redhat.com>
2021-11-04 11:20:40 +02:00
Humble Chirammal dcf522c37d csi: support ephemeral volumes with Ceph CSI RBD and CephFS driver
This commit make required changes for ceph csi drivers to work with
ephemeral volume support. With ephemeral volume support a user can
specify ephemeral volumes in its pod spec and tie the lifecycle
of the PVC with the POD.

An example POD spec looks like this:

```
kind: Pod
apiVersion: v1
metadata:
  name: csi-rbd-demo-ephemeral-pod
spec:
  containers:
    - name: web-server
      image: docker.io/library/nginx:latest
      volumeMounts:
        - mountPath: "/myspace"
          name: mypvc
  volumes:
    - name: mypvc
      ephemeral:
        volumeClaimTemplate:
          spec:
            accessModes: ["ReadWriteOnce"]
            storageClassName: "rook-ceph-block"
            resources:
              requests:
                storage: 1Gi
```

Signed-off-by: Humble Chirammal <hchiramm@redhat.com>
2021-11-02 19:53:39 +05:30
Sébastien Han c3d4ead6d6 Merge pull request #9040 from leseb/fix-9034
nfs: add pool setting CR option
2021-10-29 15:42:48 +02:00
Travis Nielsen 9e492bb5b3 Merge pull request #9065 from degorenko/doc-fix-for-objectstore
docs: add doc note for caBundleRef for cephobjectstore
2021-10-29 07:26:15 -06:00
Satoru Takeuchi f46e5ffe3a Merge pull request #9064 from leseb/update-toolbox-example
docs: stop pasting toolbox yaml in doc
2021-10-29 20:01:39 +09:00
Denis Egorenko 7f9f760d70 docs: add doc note for caBundleRef for cephobjectstore
Add missed doc note for caBundleRef added as fix for issue
https://github.com/rook/rook/issues/8490

Related-Issue: https://github.com/rook/rook/issues/8490
Signed-off-by: Denis Egorenko <degorenko@mirantis.com>
2021-10-29 14:19:35 +04:00
Sébastien Han ffd6ff3154 docs: stop pasting toolbox yaml in doc
We should only rely on the content of the repo and not copy YAML
examples into the documentation as it forces us to keep all versions in
sync all the time. The examples directory is the only source of truth.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-10-29 10:51:07 +02:00
Sébastien Han e0145b9643 nfs: add pool setting CR option
Ths NFS spec now supports the CephBlockPool spec which means that it can
take advantage of all the known settings like compression, size, failure
domain etc.

Closes: https://github.com/rook/rook/issues/9034
Signed-off-by: Sébastien Han <seb@redhat.com>
2021-10-29 09:04:31 +02:00
Travis Nielsen 71683917fd Merge pull request #9051 from travisn/helm-app-version
helm: Add appVersion property to the charts
2021-10-28 11:01:27 -06:00
Travis Nielsen bffe99c39d helm: add appversion property to the charts
The appVersion should be set to the version of the application. Since the helm
charts are built by Rook in the same release version as Rook itself, the
version and appVersion values will be the same.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-10-28 09:26:18 -06:00
Sébastien Han ecd01bb452 Merge pull request #9020 from leseb/fix-8993
rgw: read tls secret hint for insecure tls
2021-10-28 15:07:07 +02:00
Sébastien Han 86c9a8f3de rgw: read tls secret hint for insecure tls
If the admin wants to use insecure TLS to validate connections to rgw
internally, the TLS secret can have another entry "insecureSkipVerify"
and set it to "true".

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-10-28 11:27:00 +02:00
Sébastien Han 4f2c685ad9 ceph: ability to set label to crash collector
We can now set labels to the crash collector deployment by editing the
CephCluster CR with:

```yaml
spec:
  labels:
    crashcollector:
```

Closes: https://github.com/rook/rook/issues/9039
Signed-off-by: Sébastien Han <seb@redhat.com>
2021-10-27 12:29:50 +02:00
Travis Nielsen a861bf0d12 Merge pull request #8411 from Yuggupta27/async-dr-doc
docs: add document for failover and failback
2021-10-26 08:18:36 -06:00
Sébastien Han 3b5bbf28d5 Merge pull request #9003 from leseb/vault-k8s-auth
osd: add support for k8s with vault kms
2021-10-25 18:02:48 +02:00
Blaine Gardner 2f850b6ae6 Merge pull request #8613 from subhamkrai/remove-nautilus
ceph: remove ceph nautilus, ceph octopus to default
2021-10-25 09:09:18 -06:00
Sébastien Han 18a4047679 osd: add support for k8s with vault kms
Rook cluster-wide encryption can now use the native Kubernetes
authentication to interact with vault KMS instead of using the token
method.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-10-21 13:59:28 +02:00
Yug Gupta c0b8f5a708 docs: add documents for failover and failback
add a document to track the steps for failover
and failback in case of Async DR; for Planned
Migration and Disaster Recovery use case.

Signed-off-by: Yug Gupta <yuggupta27@gmail.com>
2021-10-21 01:07:22 +05:30
subhamkrai 0150966024 ceph: remove ceph nautilus, ceph octopus to default
since rook 1.8, ceph nautilus no longer supported,
ceph octopus will be the minimum ceph version.

Closes: https://github.com/rook/rook/issues/7908
Signed-off-by: subhamkrai <srai@redhat.com>
2021-10-20 14:45:12 +05:30
PixelJonas 8733bf6272 ceph: use normal quotation marks for comment
replaces all occurences of lduo/rduo quotation marks to make
sure that using the snippets in a k8s manifest will work

This fixes an issue with ArgoCD not being able
to apply `common.yaml` because of an encoding issue

Signed-off-by: PixelJonas <jonas@janz.digital>
2021-10-20 10:09:22 +02:00
Yug Gupta e584efa966 docs: add a document to set-up rbd mirroring
The document tracks the steps which are required
to set-up rbd mirroring on clusters.

Signed-off-by: Yug Gupta <yuggupta27@gmail.com>
2021-10-20 09:11:33 +05:30
Madhu Rajanna 83cd8cb300 csi: fix comment for the provisioner and clusterID
fixed provisioner and clusterID comment to match
the correct namespace.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2021-10-18 10:39:13 +05:30
Sébastien Han e33d905b59 Merge pull request #8501 from josephsawaya/ceph-nfs-remove-rados
ceph: remove RADOS options from CephNFS and use .nfs pool
2021-10-13 10:41:49 +02:00
parth-gr 7c99858a77 ceph: add finalizers to rook-ceph-mon secrets and configmap
Adding finalizers to rook-ceph-mon secrets
and rook-ceph-mon-endpoints configmap
We don't want to delete this resources during disaster
because these details are needed during disaster recovery

Closes: https://github.com/rook/rook/issues/8369
Signed-off-by: parth-gr <paarora@redhat.com>
2021-10-07 19:44:17 +00:00
Travis Nielsen c420f2309c csi: no longer install the volumereplication crds from rook
The volume replication CRDs are an external component, not owned by Rook.
Therefore, they should be installed as any other independent component
in case the admin will install other consumers of the volumereplication CRDs
in the future in addition to Rook and the CSI driver.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-10-06 16:27:44 +00:00
subhamkrai 7587704743 docs: add doc to recover from pod from lost node
This commit adds the doc which has the manual
steps to recover from the specific scenario
like
`on the node lost, the new pod can't mount the
same volume`.

Closes: https://github.com/rook/rook/issues/1507
Signed-off-by: subhamkrai <srai@redhat.com>
2021-10-05 21:13:13 +05:30
Joseph Sawaya ee791b09fd ceph: update CephNFS to use ".nfs" pool in newer ceph versions
This commit updates the CephNFS CR to make the RADOS settings optional
for Ceph versions above 16.2.7 due to the NFS module changes in Ceph.
The changes in Ceph make it so the RADOS pool is always ".nfs" and the
RADOS namespace is always the name of the NFS cluster.

This commit also handles the changes in Ceph Pacific versions before 16.2.7
where the default pool name is "nfs-ganesha" instead of ".nfs".

Closes: https://github.com/rook/rook/issues/8450
Signed-off-by: Joseph Sawaya <jsawaya@redhat.com>
2021-10-04 17:39:47 +00:00