Commit Graph
107 Commits
Author SHA1 Message Date
Humble Chirammal e5f5d9be9f csi: mount host's /etc/selinux in node plugins
This commit introduces a new configuration option for
ceph csi driver to enable hostpath mounting of /etc/selinux
directory from the cluster node where csi plugin pods are
running, which inturn help the csi driver to specify
selinux-related mount options like context.

Ref# https://github.com/ceph/ceph-csi/issues/2295

The default value for this configuration is true and if cluster
nodes are running without selinux enabled, an admin can deploy
csi pods by specifying this option to `false` which skip the
host path mounting for the csi pods.

Signed-off-by: Humble Chirammal <hchiramm@redhat.com>
2021-12-01 11:13:26 +05:30
Sébastien Han c890710b63 core: change directory layout
As per discussion, proposing a new layout for the charts/yaml/olm files.

./deploy
├── charts
│   ├── rook-ceph
│   │   └── templates
│   └── rook-ceph-cluster
│       └── templates
├── examples
│   ├── csi
│   │   ├── cephfs
│   │   └── rbd
│   ├── flex
│   ├── monitoring
│   ├── pre-k8s-1.16
└── olm
    └── assemble

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-11-30 09:12:53 +01:00
Travis Nielsen bffe99c39d helm: add appversion property to the charts
The appVersion should be set to the version of the application. Since the helm
charts are built by Rook in the same release version as Rook itself, the
version and appVersion values will be the same.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-10-28 09:26:18 -06:00
subhamkrai 0150966024 ceph: remove ceph nautilus, ceph octopus to default
since rook 1.8, ceph nautilus no longer supported,
ceph octopus will be the minimum ceph version.

Closes: https://github.com/rook/rook/issues/7908
Signed-off-by: subhamkrai <srai@redhat.com>
2021-10-20 14:45:12 +05:30
Humble Chirammal 966a88ea81 ceph: update the csi sidecar versions in templates and documentation
Signed-off-by: Humble Chirammal <hchiramm@redhat.com>
2021-09-24 18:25:12 +05:30
Travis Nielsen 0a0b9c98bd build: remove obsolete flex driver
The flex driver has been fully deprecated and thus removed from Rook.
Before upgrading to v1.8, users will need to convert existing flex volumes
from flex to csi volumes.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-09-23 16:17:20 -06:00
Madhu Rajanna ed5f281a74 ceph: make provisioner replicas configurable
added new option to set the provisioner replicas.
with this new option the user/admin can choose
how many replicas he want for provisioner pod if
number of nodes is greater than 1.

fixes #8153

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2021-09-22 11:24:53 +05:30
Travis Nielsen 6b7062eda5 docs: refactor documentation for ceph provider
With the nfs and cassandra providers moving to their own repo
we can simplify the docs a bit. Some obsolete documentation
is also removed.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-09-13 10:40:47 -06:00
Humble Chirammal 8034a4ef98 ceph: set default FsGroupChangePolicy value to 'None'
The `None` value Indicates that volumes will be mounted
with no modifications, as the CSI volume driver does not
support these operations. While volumes are provisioned
by the CephFS CSI driver the global permissions are set
on the volume and we dont expect the Fsgroup policy or
check from CO side  to play a role here.

Ref #ceph/ceph-csi/../internal/cephfs/nodeserver.go#L190

```
!csicommon.MountOptionContains(fuseMountOptions, readOnly) {
		// #nosec - allow anyone to write inside the stagingtarget path
		err = os.Chmod(stagingTargetPath, 0o777)
```

The current default value ie `ReadWriteOnceWithFSType` cause
volumes to be examined to determine if volume ownership and permissions
should be modified to match the pod's security policy. Changes could occur
if the fsType is defined and the persistent volume's accessModes contains
ReadWriteOnce.

Signed-off-by: Humble Chirammal <hchiramm@redhat.com>
2021-08-03 16:54:10 +05:30
Madhu Rajanna b556dbf109 ceph: update cephcsi to v3.4.0
This PR updates the required RBAC, templates,
CSI image version and examples for new
cephcsi v3.4.0 release.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2021-08-02 10:22:54 +05:30
Rakshith R 2baf50771e ceph: update csi node-driver-registrar to latest release
This commit updates csi node-driver-registrar to latest
release v2.2.0.
https://github.com/kubernetes-csi/node-driver-registrar/releases

Signed-off-by: Rakshith R <rar@redhat.com>
2021-06-24 10:22:51 +05:30
Travis Nielsen ec867d6a55 docs: helm chart command should directly create namespace
The helm doc example is more natural with the command to directly
create the namespace when needed instead of as a separate command.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-06-17 15:03:31 -06:00
Madhu Rajanna 08997434ac ceph: update csi sidecar images to latest release
This commit updates all the kubernetes sidecar
images to latest available release version.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2021-06-15 08:09:27 +05:30
Travis Nielsen 5e86ef8b0c docs: clarify not to change crdsenabled in helm chart
Changing the crds.enabled setting in a running cluster will cause the
CRs to be deleted, which could be disastrous for a cluster. Add
and clarify the warning in the docs to prevent it and link
to recovery steps if it does happen.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-06-03 14:04:47 -06:00
Rakshith R 87cf668b28 ceph: add option for adding csi pods' tolerations & affinity separately
This commit adds support for adding tolerations and affinities for
cephfs and rbd (provisioner & nodeplugin) pods separately.

Closes: #7060

Signed-off-by: Rakshith R <rar@redhat.com>
2021-06-02 11:30:38 +05:30
Rakshith R 7987e1b8a2 ceph: update snapshot APIs from v1beta1 to v1
This commit updates external-snapshotter version to
v4.0.0 which supports snapshots v1.
Rook now defaults to enabling RBD and CephFS snapshotter
for K8s >= v1.17 and disabling it for K8s <= v1.16.
Supporting changes in documents and examples yaml files
are made.

Signed-off-by: Rakshith R <rar@redhat.com>
2021-05-05 21:04:10 +05:30
Madhu Rajanna 6bc3c1ac3a ceph: update cephcsi to v3.3.1
As we have cephcsi v3.3.1 release
with couple of bug fixes and a CVE fix
updating the cephcsi to latest release.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2021-04-22 13:57:01 +05:30
Rakshith R f5a3f6fa71 ceph: add option to toggle host networking in csi plugin pods
As host networking is no longer necessary for CSI driver,
it will be disabled by default.
An option CSI_ENABLE_HOST_NETWORK is added to rook-ceph-operator-config
configmap and enableCSIHostNetwork in helm chart values.yaml to
enable/disable host network in CSI plugin pods.

Closes: #7203

Signed-off-by: Rakshith R <rar@redhat.com>
2021-04-20 12:57:09 +05:30
bipuladh 7d5cc8d06b ceph: adds a container to support volume replication controller
this commit adds a new container inside of rbd-provisioner.

Signed-off-by: bipuladh <badhikar@redhat.com>
2021-04-15 21:39:26 +05:30
Madhu Rajanna fd28e48664 ceph: update csi image to v3.3.0
as we are having v3.3.0 cephcsi latest release
updating the cephcsi image to the same.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2021-04-15 19:36:31 +05:30
Madhu Rajanna 0a81ce2251 ceph: disable CSI GRPC metrics by default
The GRPC metrics exposed by both the provisioner pod
and the node plugin pod on some port. Provisioner pod
is running on the pod network and the daemonset pods
run on the host network. sometimes starting the GRPC
metrics by default can lead to node plugin pods
crashloopback state this is due to the port conflict.
Moreover, the GRPC metrics are not for the user it's
for the one which will help to debug the time taken
by cephcsi to serve each GRPC call. Enabling it by
default won't be a good idea. So the plan is to
disable it by default, If someone faces any issue it
can be enabled later at some point in time.

closes #7378

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2021-03-10 11:30:50 +05:30
ᗪєνιη ᗷυнʟ 64a0fbc91c ceph: set helm resource policy keep annotation on CRDs in Helm chart
When uninstalling the helm chart do not remove the CRDs, instead
document the way to remove the CRDs after the user uninstalls
the chart.

Closes: https://github.com/rook/rook/issues/6617
Signed-off-by: Devin Buhl <devin.kray@gmail.com>
2021-02-04 12:26:46 -05:00
Madhu Rajanna e305810bf0 ceph: add option to set FSGroupPolicy for CSI PVC
in kubernetes 1.19 it added a support to set FSGroupPolicy
in the csidriver object, same supported is added to both
CephFS and RBD. where user will have an option to set
the FSGroupPolicy for CephFS and RBD separately.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2021-01-22 14:26:56 +05:30
Travis Nielsen 3a6deb8775 Merge pull request #7008 from TomHellier/master
#7007 Ability to configure ROOK_ALLOW_MULTIPLE_FILESYSTEMS environment to rook operator pod in helm chart
2021-01-21 11:15:34 -07:00
Madhu Rajanna 05c75b7084 ceph: add support to disable snapshotter sidecar
In some cases the user dont want to run snapshotter
container either for CephFS or RBD. In that case the
user wont install the required snapshot CRD's due
to that the snapshotter sidecar container produces
lot of noisy logs.
Snapshotter will be enabled by default for both
CephFS and RBD, but with this PR we are providing
an option to disable snapshotter sidecar deployment
either for CephFS or RBD.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2021-01-21 15:29:55 +05:30
Tom Hellier 5d6f4ef4d4 ceph: allowMultipleFilesystems in helm-operator
This change allows the setting of the ROOK_ALLOW_MULTIPLE_FILESYSTEMS in the helm operator

Signed-off-by: Tom Hellier <me@tomhellier.com>
2021-01-21 01:17:49 +00:00
Madhu Rajanna 5392bc0d07 ceph: update csi to v3.2.0
updating cephcsi to latest release version

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2020-12-11 20:22:36 +05:30
Madhu Rajanna ca3e23853e ceph: update cephcsi to latest release
updating cephcsi to v3.1.2 which is a latest
bugfix release.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2020-11-19 12:20:11 +05:30
Travis Nielsen ba534ce285 docs: clarify helm warning that could delete cluster
In the helm chart the CRDs are installed if crds.enabled is set to
true. If false, the helm chart will not install them. If changed
to false during an upgrade, the CRDs will be removed and the cluster
is destroyed. There is no way to prevent this while still being flexible
about CRD management, so we make the warnings as clear as possible.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-11-17 15:45:33 -07:00
Alexander Trost fa62f4ac5d ceph: allow custom labels to be added to the discover daemonset
Signed-off-by: Alexander Trost <galexrt@googlemail.com>
2020-11-12 16:20:01 +01:00
Alexander Trost 34930020ab ceph: allow pod labels to be added to CSI components
This adds the functionality to add custom pod labels to the CSI
components through the operator configuration way of env vars or config
map.

Resolves #6593

Signed-off-by: Alexander Trost <galexrt@googlemail.com>
2020-11-12 13:06:24 +01:00
Pete Birley 152a05c85e ceph: update to helm 3 for the rook chart
This updates the chart to make use of helm3 which has been released
for some time, and also permits CRDs to be installed pror to other objects
allowing the chart to be deployed at the same time as CRs for rook objects.

Co-authored-by: Pete Birley <pete@port.direct>
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-11-11 14:41:24 -07:00
Travis Nielsen 6c19f1f63d Merge pull request #6490 from xiaods/issue-6460-fix
fix: issue#6460 remove helm2 section, upgrade helm3
2020-11-11 07:57:48 -07:00
Satoru Takeuchi c7990777d2 ceph: make the placement of admission controller configurable
If users want to restrict the nodes where Ceph daemons should exist,
it's better to make the placement of admission controller configurable
as other daemons.

Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
2020-11-09 11:54:52 +00:00
Deshi XiaoandAlexander Trost 0ada78ecb0 docs: fix issue#6460 remove helm2 section
1. only helm3 support,deprecated helm2.x docs
2. remove useless helm3 comments
3. update documentation for helm-operator.md

Co-authored-by: Alexander Trost <Galexrt@googlemail.com>
Signed-off-by: Deshi Xiao <xiaods@gmail.com>
2020-10-31 10:52:24 +08:00
Madhu Rajanna 2fa3e71733 ceph: update cephcsi to v3.1.1
as cephcsi v3.1.1 is released today
with many bug fixes and enhancements,
more details can be found at
https://github.com/ceph/ceph-csi/releases/tag/v3.1.1

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2020-09-29 14:03:44 +05:30
Mudit Agarwal c547b36aa0 ceph: update csi sidecar images
This PR makes the changes in csi templates and
upgrade documentation required for updating
csi sidecar images.

Signed-off-by: Mudit Agarwal <muagarwa@redhat.com>
2020-09-28 18:58:52 +05:30
Alexander Trost 2288ec90ed docs: fix helm command usage
This fixes the helm commands to be compatible with Helm v3.x and adds an
example / notes for Helm v2.x users.

Resolves #5491

Signed-off-by: Alexander Trost <galexrt@googlemail.com>
2020-08-17 22:04:26 +02:00
Humble Chirammal 97a3283099 ceph: add snapshot create/delete and restore doc for cephfs
Signed-off-by: Humble Chirammal <hchiramm@redhat.com>
2020-08-13 22:17:01 +05:30
Madhu Rajanna 031e3145a5 ceph: update cephcsi to v3.0.0
update cephcsi to latest available release

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2020-07-24 10:21:59 +05:30
Madhu Rajanna 3f46b437c6 ceph: remove CSI_ENABLE_SNAPSHOTTER from CSI config
removed CSI_ENABLE_SNAPSHOTTER from the configuration
to enable or disable csi-snapshotter as snapshot
is moved to beta and enabled by default in kubernetes
1.17+

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2020-07-01 07:20:04 +05:30
Madhu Rajanna 6699dba25a ceph: update sidecar images version
updated snapshotter from v1.x to v2.x
as its supports snapshot beta, the required
provisioner version to support snapshot beta
is v1.5.x+.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2020-07-01 07:20:04 +05:30
Madhu Rajanna 09ccf55453 ceph: update cephcsi to v2.1.2
Cephcsi v2.1.2 is released with bug fixes,
refer https://github.com/ceph/ceph-csi/releases/tag/v2.1.2
for release details.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2020-06-05 14:43:05 +05:30
Travis Nielsen f82a07d441 Merge pull request #5394 from Madhu-1/csi-prio
CSI: Set PriorityClassName for CSI pods
2020-05-06 07:08:54 -06:00
Madhu Rajanna ec3ab55d94 CSI: Set PriorityClassName for CSI provisioner pods
provide an option to set PriorityclassName on the
CSI provisioner pods to avoid pod eviction, as the CSI provisioner
pods a critical in system for storage. the default value
for the CSI provisioner pods is set to system-cluster-critical.

provisioner pods are less priority than plugin pods.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2020-05-06 15:45:06 +05:30
Madhu Rajanna cc6ec58891 CSI: Set PriorityClassName for CSI plugin pods
provide an option to set Priorityclassname on the
CSI plugin pods to avoid pod eviction, as the CSI plugin pods are
critical in system for storage. the default value
for the CSI plugin pods is set to system-node-critical.
more info can be found at
https://kubernetes.io/docs/tasks/administer-cluster/guaranteed-scheduling-critical-addon-pods/

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2020-05-06 15:45:01 +05:30
Madhu Rajanna 73c74d8a42 CSI: Update CSI version to v2.1.1
cephcsi v2.1.1 is released with fix for xfs formatting
issue. This PR updates the cephcsi image version to
v2.1.1

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2020-05-05 13:08:23 +05:30
Madhu Rajanna 4495d1fffd CSI: Add helm documentation for CSI resource
Updated helm documentation for CSI resources
which will be applied for CSI sidecar and plugin
containers.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2020-04-29 10:26:56 +05:30
Madhu Rajanna 5684c4cc37 CSI: update cephcsi to v2.1.0
cephcsi v2.1.0 is released and doesnot need any deployment
template changes. This PR updates the cephcsi image
version to v2.1.0

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2020-04-20 14:58:25 +05:30
Juan Miguel Olmo Martínez 08821f1d61 Ceph: Update Helm Chart documentation
Add <unreachableNodeTolerationSeconds> parameter to Helm chart documentation

Signed-off-by: Juan Miguel Olmo Martínez <jolmomar@redhat.com>
2020-04-14 08:32:37 +02:00