Commit Graph
209 Commits
Author SHA1 Message Date
Blaine Gardner 2c4b66957c build: generate CSV from helm charts
In order to generate common.yaml from Helm charts, we have to have a
different way of generating CSV than from meta-comments in common.yaml.
This implementation changes what appears in the CSV's RBAC somewhat, but
these changes could be considered bugs fixed by using the new Helm
generation method.
- a few PSP related resources are removed from CSV
- resources related to 'rook-ceph-purge-osd' Job are added to CSV
- ClusterRoleBinding 'rook-ceph-object-bucket' is added to CSV

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-11-30 08:35:54 -07:00
Blaine Gardner 51fc36d591 build: prevent parallel build collisions for ceph
Prevent parallel build collisions in the 'ceph' image by building
prerequisites for the builds before running the build targets in
parallel. Build targets can collide and try to create the same target at
nearly the same time, causing failures.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-11-30 08:09:24 -07:00
Blaine Gardner 113e2f849d build: use yq for RBAC yaml parsing
Use yq instead of Python for parsing RBAC from the Helm chart. We need
to use yq v4.14.1 or higher to fix yq's handling of the yaml header
markers ('---'). Update the Makefile's yq version to v4, which also
requires updating the script to update the CRDs. This was quite easy.

It is very difficult, however, to change the version of yq used by the
CSV generating/parsing scripts, which already used their own yq
download. Continue using yq v3 for this.

In order to make sure the scripts are using the right version of yq, add
basic validation to them to verify they are running v3 or v4 as required
for their operation.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-11-30 08:08:08 -07:00
Sébastien Han c890710b63 core: change directory layout
As per discussion, proposing a new layout for the charts/yaml/olm files.

./deploy
├── charts
│   ├── rook-ceph
│   │   └── templates
│   └── rook-ceph-cluster
│       └── templates
├── examples
│   ├── csi
│   │   ├── cephfs
│   │   └── rbd
│   ├── flex
│   ├── monitoring
│   ├── pre-k8s-1.16
└── olm
    └── assemble

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-11-30 09:12:53 +01:00
Sébastien Han 619f5eee6e build: revert "build: images/cross/Dockerfile to reduce vulnerabilities"
This reverts commit ceec0bc48c. The build
is failing to push images to master. This is not a critical update so
let's remove.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-11-25 14:53:21 +01:00
snyk-bot ceec0bc48c build: images/cross/Dockerfile to reduce vulnerabilities
The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-UBUNTU1604-LIBGCRYPT20-1585790
- https://snyk.io/vuln/SNYK-UBUNTU1604-SYSTEMD-1320131
- https://snyk.io/vuln/SNYK-UBUNTU1604-SYSTEMD-1320131
- https://snyk.io/vuln/SNYK-UBUNTU1604-SYSTEMD-1320131
- https://snyk.io/vuln/SNYK-UBUNTU1604-SYSTEMD-1320131

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-11-25 11:59:22 +01:00
snyk-bot 38b2af711a build: images/cross/Dockerfile to reduce vulnerabilities
The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-UBUNTU1604-LIBGCRYPT20-1585790
- https://snyk.io/vuln/SNYK-UBUNTU1604-SYSTEMD-1320131
- https://snyk.io/vuln/SNYK-UBUNTU1604-SYSTEMD-1320131
- https://snyk.io/vuln/SNYK-UBUNTU1604-SYSTEMD-1320131
- https://snyk.io/vuln/SNYK-UBUNTU1604-SYSTEMD-1320131

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-11-24 15:38:15 +01:00
Travis Nielsen 59729765bf build: default to amd64 arch for the the s5cmd tool
On mac, the docker build was failing due to an unspecified
S5CMD_ARCH. Now we default to build amd64 always and override
it if the arch is arm64.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-11-10 12:25:57 -07:00
Sébastien Han 889856b78f core: add s5cmd binary to operator image
The toolbox can now interact with S3 gateways using the `s5cmd` tool.
The binary is only 12M so this does not add up too much to the operator
image size.

Closes: https://github.com/rook/rook/issues/4968
Signed-off-by: Sébastien Han <seb@redhat.com>
2021-11-09 16:56:30 +01:00
Sébastien Han 3b85de420f Merge pull request #8744 from leseb/fix-8734
ceph: run operator with rook user
2021-11-05 17:56:54 +01:00
Sébastien Han d06a6f93a5 core: run operator with rook user
The rook operator as well as the toolbox pod run with the "rook" user
with UID 2016. The UID was chosen based on the year of the initial
commit in the rook/rook repository.
No more root user running.

Closes: https://github.com/rook/rook/issues/8734
Signed-off-by: Sébastien Han <seb@redhat.com>
2021-11-05 17:22:04 +01:00
Sébastien Han 6fb67a297d build: only produce binary for linux
We now build rook to build only for linux platforms and not darwin nor
windows anymore.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-11-04 15:13:40 +01:00
Travis Nielsen 9655e3a21e Merge pull request #8927 from synarete/aarch64-graviton
build: support build of rook on aarch64 (AWS/graviton)
2021-10-20 07:55:20 -06:00
Blaine Gardner 221281cab3 build: fix offline image build race condition
When generating the offline image list, the threaded crossbuild can
try to generate the image list from muliple jobs at once, resulting in
undefined behavior (usually an empty file) for the output file. To fix
this, we can generate this file in the `build.common` step which is not
run in parallel.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-10-11 16:07:28 -06:00
Travis Nielsen c420f2309c csi: no longer install the volumereplication crds from rook
The volume replication CRDs are an external component, not owned by Rook.
Therefore, they should be installed as any other independent component
in case the admin will install other consumers of the volumereplication CRDs
in the future in addition to Rook and the CSI driver.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-10-06 16:27:44 +00:00
Shachar Sharon c3e2c77da6 build: support build of rook on aarch64 (AWS/graviton)
Build rook in AWS/Graviton (ARM64) platform. Upon installation of
operator-sdk, make sure that the downloaded binary can actually be
executed on local machine by invoking 'operator-sdk version'.

issue: https://github.com/rook/rook/issues/8926

Signed-off-by: Shachar Sharon <ssharon@redhat.com>
2021-10-06 18:29:00 +03:00
Blaine Gardner 24bf99f31c build: use intermediate tmp for offline image gen
Reading from a file, processing the file in a pipe, and outputting the
piped content to the same file can have undefined results, often leading
to an empty file. Use an intermediate temp file for generating the
offline image list.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-09-29 17:31:02 -06:00
subhamkrai 2d7755ca15 build: update command to generate image list
While build.all we have race condition where images.txt
file was update with duplicate entries. So, removing `-a`
from 1st tee and also add `sort -h`and `uniq` command to
confirm no duplicate entry is in the file.

Signed-off-by: subhamkrai <srai@redhat.com>
2021-09-29 15:00:05 +05:30
Sébastien Han 121c2987e3 ceph: stop using tini
We don't need to use tini.
We don't have anything in the rook operator that would
either create zombie processes (no threads) or use
exec (to fork). The Go binary has a really good
signal handling mechanism.

Closes: https://github.com/rook/rook/issues/8794
Signed-off-by: Sébastien Han <seb@redhat.com>
2021-09-27 10:54:16 +02:00
Travis Nielsen 0a0b9c98bd build: remove obsolete flex driver
The flex driver has been fully deprecated and thus removed from Rook.
Before upgrading to v1.8, users will need to convert existing flex volumes
from flex to csi volumes.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-09-23 16:17:20 -06:00
Travis Nielsen fb74e7b2d5 ceph: pick up latest ceph base image 16.2.6-20210918
The previous base image in use by rook v16.2.6-20210916 disappeared
from quay.io.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-09-23 15:11:34 -06:00
Sébastien Han 0c33493f27 ceph: bump manifests to ceph pacific 16.2.6
New version is out so let's use it.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-09-21 09:16:32 +02:00
subhamkrai 284dbc0a0e build: use pkg/operator/ceph/csi/spec.go for csi images
it has happened more than once that the manifests do not
reflect the images so now reading from `pkg/operator/ceph/csi/spec.go`
as this what code uses.

Closes: https://github.com/rook/rook/issues/8687
Signed-off-by: subhamkrai <srai@redhat.com>
2021-09-13 17:16:52 +05:30
subhamkrai 7bc9a138f2 ci: image list for offline installation
create file tests/scripts/rook-ceph-image.txt which
will have list of images required for offline installation.

Closes: https://github.com/rook/rook/issues/6406
Signed-off-by: subhamkrai <srai@redhat.com>
2021-09-08 19:52:05 +05:30
Blaine Gardner 97075a2422 build: fix cross build run script
Fixes issues with the `build/run` tooling, notably for publishing images
where `build/run make <args>` would only result in `make` being called
without args.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-09-01 14:11:03 -06:00
Blaine Gardner 7febd4e303 ci: add debugging to release build script
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-09-01 13:58:21 -06:00
Blaine Gardner 9531c252a5 ceph: remove NFS and Cassandra make targets
Remove all make-related references to NFS and Cassandra. This is limited
purely to make targets. Leave CRD and codegen script references to be
removed in a different commit.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-08-31 14:05:33 -06:00
subhamkrai ebe21c8f68 ci: add action for shellcheck linter
we are adding new linter for shellcheck.
As we are writing more shell scripts this
will help maintain quality.

Also, doing all the changes required in
bash files to pass this shellcheck.

Closes: https://github.com/rook/rook/issues/8431
Signed-off-by: subhamkrai <srai@redhat.com>
2021-08-26 10:03:32 +05:30
Sébastien Han 579fc27783 ceph: embed ceph-csi templates in rook binary
Thanks to Golang 1.16, we can now embed files in the Go binary. This
means we don't need to add the CSI templates files to the container
image. They are added in the Go binary at build time.

The existing location of the template must be in the package calling it.
So they moved to pkg/operator/ceph/csi/template. All the files have been
symlinked back to cluster/examples/kubernetes/ceph/csi/template.

Closes: https://github.com/rook/rook/issues/7609
Signed-off-by: Sébastien Han <seb@redhat.com>
2021-08-24 16:22:20 +02:00
Travis Nielsen df36270e33 Merge pull request #8534 from kam1kaze/upgrade_nfs_ganesha
nfs: upgrade nfs-ganesha to 3.5 version
2021-08-17 12:40:29 -06:00
Oleksii Kravchenko 62463dc61d nfs: bump nfs-ganesha to 3.5 version
Signed-off-by: Oleksii Kravchenko <kamikaze.ua@gmail.com>
2021-08-17 13:14:47 +04:00
Blaine Gardner 1592c9b9da build: use latest golang v1.16.7 (Go CVE-2021-34558)
Rook CephObjectStore S3 connections may be affected by CVE-2021-34558.
This is fixed in Go v1.16.6, so we update to the latest Go version
available to ensure this is fixed in future builds.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-08-16 11:43:44 -06:00
Blaine Gardner 9138732c81 build: stage CSV files into tmp while building
If a user were to `make build` Rook, and after the Ceph CSV was
generated and before make had finished, the Rook repo would be left with
changes caused by the build modifying files temporarily in-place.

All CSV template generation in the Ceph makefile is now self-contained
and can be configured to operate outside of the main repo so that files
are not modified in-place.

In-place modification of files was also incorrect. On Mac some files
with `-e` trailing were left, and in-place backups were also present in
the form `<filename>''`. Therefore, also fix the generation to fix
in-place modifications.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-07-27 16:11:58 -06:00
Sébastien Han c8ee5674dd Merge pull request #8103 from leseb/rm-jenkins
ci: remove jenkins from master branch
2021-07-23 18:20:10 +02:00
Sébastien Han 6bce1ff3e9 ceph: move all of our docker.io reference to quay.io
Recently, the builds of `ceph/ceph` image moved to quay.io, see
https://github.com/ceph/ceph-build/pull/1883 for more details.
Current images will remain but new builds will happen on quay.io only.

This means that tags such as `v14.2`, `v15.2`,`v16.2` will need to
switch to quay.io to get updates.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-07-22 11:17:05 +02:00
Travis Nielsen 64df4cdbb6 ceph: update default ceph image to latest v16.2.5
The latest pacific release is 16.2.5 so we set this as the default
for Rook to deploy.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-07-16 10:21:48 -06:00
Sébastien Han 18b1477352 ci: remove jenkins from master branch
Thank you Jenkins for all those years, but it's to retire.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-06-10 15:34:15 +02:00
Blaine Gardner 285dad339b ceph: update references to v15.2.11 to v16.2.4
Ceph v16 will be the default in Rook v1.7. Update references in the
master branch from v15 (currently v15.2.11) to v16 (currently v16.2.4).

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-05-26 12:30:18 -06:00
Blaine Gardner 5245ceaf06 ceph: update images to v16.2.2
Ceph v16.2.2 is released with dated tag v16.2.2-20210505. Update Ceph
images to match with or without date as appropriate.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-05-05 11:35:34 -06:00
Travis Nielsen eba91a4bd6 ceph: remove obsolete references to filestore
Filestore support has been long gone with only bluestore
currently supported.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-05-04 15:50:20 -06:00
Sébastien Han 0f7128ece9 build: fix parallel build
We now the generate the CRDs as well as the CSV on a single GOARCH only:
amd64. This helps us avoiding builds colliding with each others.

Closes: https://github.com/rook/rook/issues/7655
Signed-off-by: Sébastien Han <seb@redhat.com>
2021-04-29 17:31:22 +02:00
Satoru Takeuchi a4277d2913 Merge pull request #7723 from travisn/build-linux-only
build: Only build linux platform
2021-04-22 17:35:05 +09:00
Travis Nielsen 2398b1636b build: only build linux platform
No need to include darwin and windows in the list of platforms
since rook is only containerized and expected to run in a linux
environment.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-04-21 14:57:31 -06:00
Sébastien Han 4a425eddca ceph: use v16.2.1 for operator image
This is the first bugfix release in the Pacific stable series. It
addresses a security vulnerability in the Ceph authentication framework.
 We recommend users to update to this release. For a detailed release
notes with links & changelog please refer to the official blog entry at
https://ceph.io/releases/v16-2-1-pacific-released.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-04-21 16:01:20 +02:00
Sébastien Han 57131e1a90 ci: build and run various make commands on MacOS
Introducing a small action on MacOS to help us catch errors with various
'make' command on OSX, most notably 'sed' versus 'gnu-sed'.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-04-20 17:21:08 +02:00
Travis Nielsen 31c4ef622e build: update the build to use go 1.16
With the release of go 1.16, we update the tools. The -i flag is
now deprecated, no longer necessary for building in a private directory.
The go modules are cleaned up at the same time.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-04-12 15:01:14 -06:00
Blaine Gardner f2f622412c build: allow CSV gen on mac
CSV generation now requires versions of yq and operator-sdk that are
downloaded by the makefiles. Previously Ceph image creation used
makefile versions but `make csv-ceph` used versions present on the
system.

`sed -i 's///g' $FILE` doesn't work on Unix/Mac.
`sed -i'' -e 's///g' $FILE` is portable.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-04-09 13:22:15 -06:00
Travis Nielsen 665856b90a ceph: enable pacific as a supported ceph version
With the Ceph Pacific release coming this week we add support
in Rook for Pacific with the Rook v1.6 release coming soon.
The integration tests will now run across nautilus, octopus,
and pacific to cover all supported Ceph versions. The default
examples still specify Octopus until there is more bake time
for Pacific.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-04-07 06:59:04 -06:00
Sébastien Han 3d1d659e28 ci: do not include ob/obc/volumes crds in csv
We don't want to include those CRDs anymore, as they get imported from
another operator.
This trims further down the size of our CSV generation.

Additionally, we always clean the csv directory before proceeding.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-04-06 17:08:39 +02:00
Sébastien Han 5a194af3b1 ceph: strip crd description for csv generation
The CSV file size cannot be bigger than 1MB so let's remove all the
description fields make it lighter.

With that change the CRDs size went from 692K to 372K so the size was
reduced by almost 50%.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-04-06 14:13:07 +02:00