This commit introduces a new configuration option for
ceph csi driver to enable hostpath mounting of /etc/selinux
directory from the cluster node where csi plugin pods are
running, which inturn help the csi driver to specify
selinux-related mount options like context.
Ref# https://github.com/ceph/ceph-csi/issues/2295
The default value for this configuration is true and if cluster
nodes are running without selinux enabled, an admin can deploy
csi pods by specifying this option to `false` which skip the
host path mounting for the csi pods.
Signed-off-by: Humble Chirammal <hchiramm@redhat.com>
The appVersion should be set to the version of the application. Since the helm
charts are built by Rook in the same release version as Rook itself, the
version and appVersion values will be the same.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
The flex driver has been fully deprecated and thus removed from Rook.
Before upgrading to v1.8, users will need to convert existing flex volumes
from flex to csi volumes.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
added new option to set the provisioner replicas.
with this new option the user/admin can choose
how many replicas he want for provisioner pod if
number of nodes is greater than 1.
fixes#8153
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
With the nfs and cassandra providers moving to their own repo
we can simplify the docs a bit. Some obsolete documentation
is also removed.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
The `None` value Indicates that volumes will be mounted
with no modifications, as the CSI volume driver does not
support these operations. While volumes are provisioned
by the CephFS CSI driver the global permissions are set
on the volume and we dont expect the Fsgroup policy or
check from CO side to play a role here.
Ref #ceph/ceph-csi/../internal/cephfs/nodeserver.go#L190
```
!csicommon.MountOptionContains(fuseMountOptions, readOnly) {
// #nosec - allow anyone to write inside the stagingtarget path
err = os.Chmod(stagingTargetPath, 0o777)
```
The current default value ie `ReadWriteOnceWithFSType` cause
volumes to be examined to determine if volume ownership and permissions
should be modified to match the pod's security policy. Changes could occur
if the fsType is defined and the persistent volume's accessModes contains
ReadWriteOnce.
Signed-off-by: Humble Chirammal <hchiramm@redhat.com>
This PR updates the required RBAC, templates,
CSI image version and examples for new
cephcsi v3.4.0 release.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
The helm doc example is more natural with the command to directly
create the namespace when needed instead of as a separate command.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
Changing the crds.enabled setting in a running cluster will cause the
CRs to be deleted, which could be disastrous for a cluster. Add
and clarify the warning in the docs to prevent it and link
to recovery steps if it does happen.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
This commit adds support for adding tolerations and affinities for
cephfs and rbd (provisioner & nodeplugin) pods separately.
Closes: #7060
Signed-off-by: Rakshith R <rar@redhat.com>
This commit updates external-snapshotter version to
v4.0.0 which supports snapshots v1.
Rook now defaults to enabling RBD and CephFS snapshotter
for K8s >= v1.17 and disabling it for K8s <= v1.16.
Supporting changes in documents and examples yaml files
are made.
Signed-off-by: Rakshith R <rar@redhat.com>
As we have cephcsi v3.3.1 release
with couple of bug fixes and a CVE fix
updating the cephcsi to latest release.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
As host networking is no longer necessary for CSI driver,
it will be disabled by default.
An option CSI_ENABLE_HOST_NETWORK is added to rook-ceph-operator-config
configmap and enableCSIHostNetwork in helm chart values.yaml to
enable/disable host network in CSI plugin pods.
Closes: #7203
Signed-off-by: Rakshith R <rar@redhat.com>
The GRPC metrics exposed by both the provisioner pod
and the node plugin pod on some port. Provisioner pod
is running on the pod network and the daemonset pods
run on the host network. sometimes starting the GRPC
metrics by default can lead to node plugin pods
crashloopback state this is due to the port conflict.
Moreover, the GRPC metrics are not for the user it's
for the one which will help to debug the time taken
by cephcsi to serve each GRPC call. Enabling it by
default won't be a good idea. So the plan is to
disable it by default, If someone faces any issue it
can be enabled later at some point in time.
closes#7378
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
in kubernetes 1.19 it added a support to set FSGroupPolicy
in the csidriver object, same supported is added to both
CephFS and RBD. where user will have an option to set
the FSGroupPolicy for CephFS and RBD separately.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
In some cases the user dont want to run snapshotter
container either for CephFS or RBD. In that case the
user wont install the required snapshot CRD's due
to that the snapshotter sidecar container produces
lot of noisy logs.
Snapshotter will be enabled by default for both
CephFS and RBD, but with this PR we are providing
an option to disable snapshotter sidecar deployment
either for CephFS or RBD.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
In the helm chart the CRDs are installed if crds.enabled is set to
true. If false, the helm chart will not install them. If changed
to false during an upgrade, the CRDs will be removed and the cluster
is destroyed. There is no way to prevent this while still being flexible
about CRD management, so we make the warnings as clear as possible.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
This adds the functionality to add custom pod labels to the CSI
components through the operator configuration way of env vars or config
map.
Resolves#6593
Signed-off-by: Alexander Trost <galexrt@googlemail.com>
This updates the chart to make use of helm3 which has been released
for some time, and also permits CRDs to be installed pror to other objects
allowing the chart to be deployed at the same time as CRs for rook objects.
Co-authored-by: Pete Birley <pete@port.direct>
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
If users want to restrict the nodes where Ceph daemons should exist,
it's better to make the placement of admission controller configurable
as other daemons.
Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
This PR makes the changes in csi templates and
upgrade documentation required for updating
csi sidecar images.
Signed-off-by: Mudit Agarwal <muagarwa@redhat.com>
This fixes the helm commands to be compatible with Helm v3.x and adds an
example / notes for Helm v2.x users.
Resolves#5491
Signed-off-by: Alexander Trost <galexrt@googlemail.com>
removed CSI_ENABLE_SNAPSHOTTER from the configuration
to enable or disable csi-snapshotter as snapshot
is moved to beta and enabled by default in kubernetes
1.17+
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
updated snapshotter from v1.x to v2.x
as its supports snapshot beta, the required
provisioner version to support snapshot beta
is v1.5.x+.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
provide an option to set PriorityclassName on the
CSI provisioner pods to avoid pod eviction, as the CSI provisioner
pods a critical in system for storage. the default value
for the CSI provisioner pods is set to system-cluster-critical.
provisioner pods are less priority than plugin pods.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
cephcsi v2.1.1 is released with fix for xfs formatting
issue. This PR updates the cephcsi image version to
v2.1.1
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
Updated helm documentation for CSI resources
which will be applied for CSI sidecar and plugin
containers.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
cephcsi v2.1.0 is released and doesnot need any deployment
template changes. This PR updates the cephcsi image
version to v2.1.0
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>