Commit Graph
74 Commits
Author SHA1 Message Date
Travis Nielsen 1afd322650 core: ensure cluster name is available on cluster info
The cluster info is important context for the cluster controller to
create the cluster, and all the fields must be properly set.
A test cluster name was being set temporarily, resulting in
mons incorrectly getting the wrong cluster CR name. There is no
known issue from the temporary value, it was just exposed by
https://github.com/rook/rook/pull/8678 setting the value to a label.

Now the functions are more clearly named so only unit and
integration tests should be using the test value for the cluster
name where it is not important.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-11-18 15:30:26 -07:00
Sébastien Han b89730d895 ceph: refactor operator initialization sequence
This commit is a large refactor on how the operator starts, stops and
how it starts various sub-components such as the ceph-csi driver. It
also refines the way we cancel orchestrations. We don't use breakpoints
anymore but send our self a SIGUP to reload our controller runtime
manager.
The reload will happen under different circonstances like:

* a new adminission controller secret is created/deleted/changed
* a CephCluster CR is edited

As mentioned earlier, the csi driver now has its own controller, just
like flex. It reacts to change in the operator config map for particular
ROOK_CSI_ fields.

A second new controller for the operator's general config has been
created, it manages:

* the logging level
* the ceph CLI command timeout
* the discovery daemon

The operator reacts much more rapidly to cancellation events by stopping
the manager's context and reloading it.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-09-17 16:57:12 +02:00
Santosh Pillai 7480f6ba62 ceph: reconcile osd pdb if allowed disruption is 0
Rook checks for down OSDs by checking the `ReadyReplicas` count
in the OSD deployement. When an OSD pod goes into CBLO due to
disk failure, there is a delay before this `ReadyReplicas` count
becomes 0. The deplay is very small but may result in rook missing
OSD down event. As a result no blocking PDBs will be created and
only default PDB with `AllowedDisruptions` count as 0 is available.
This PR tries to solve this. The OSD pdb reconciler will be
reconciled again if `AllowedDisruptions` count in the main
PDB is 0.

Signed-off-by: Santosh Pillai <sapillai@redhat.com>
2021-09-14 15:56:59 +05:30
parth-gr 72e4bb8099 ceph: remove legacy PDBs methods
Removing the deleteLegacyPDBForOSD method
because we don't support legacyPDBs

Closes: https://github.com/rook/rook/issues/8360
Signed-off-by: parth-gr <paarora@redhat.com>
2021-08-20 21:24:52 +05:30
Sébastien Han 2d55e69416 ceph: move scheme initialization to the same place
Let's initialize the schemes in a single place instead of doing it
when each controller initializes.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-08-06 11:33:10 +02:00
Sébastien Han 6d77a9976c ceph: remove unnecessary exec helpers
Both `ExecuteCommandWithOutputFileTimeout()` and
`ExecuteCommandWithOutputFile()` generate unnecessary system calls by
creating/reading/removing files where the stream output of the command
can simply be used. So sticking with `ExecuteCommandWithOutput()` and
`ExecuteCommandWithCombinedOutput()` for reading outputs is sufficient.

Closes: https://github.com/rook/rook/issues/8343
Signed-off-by: Sébastien Han <seb@redhat.com>
2021-07-23 09:16:33 +02:00
parth-gr 77813f7093 ceph: update PodDisruptionBudget from v1beta1 to v1
This commit update the PodDisruptionBudget policy to use version v1
Updated to policy/v1 as policy/v1beta1 PodDisruptionBudget is deprecated in v1.21+

Closes: https://github.com/rook/rook/issues/7917
Signed-off-by: parth-gr <paarora@redhat.com>
2021-07-22 14:09:33 +05:30
Satoru Takeuchi 5418d2dceb ceph: create pdb for all rgw and cephfs
Fix the improper breaking from the loops to add pdbs.

Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
2021-07-13 05:23:51 +00:00
Satoru Takeuchi 7885b775ec ceph: fix pdb of RGW instances
It's better to create PDB of RGW if ObjectStore's `instances` field is 2.
In the current implementation, at least three desired RGW instances are needed
to create this. If `instances` is 1, we can still safely skip the creation
of PDB because it's useless.

Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
2021-07-07 13:22:33 +00:00
Santosh Pillai aee8f56853 ceph: update podDisruptionBudget controller for OSD
This PR has following changes around OSD pdbs
- Detect node drains more reliably. When OSD is down and OSD pod is not scheduled to any node or if the scheduled node is not ready, then assume that node is draining.
- Don't set no-out flag on the failure domain if the OSD is down due to reasons other than node drain (say disk failure)
- update unit tests
- update design doc to reflect above changes

Signed-off-by: Santosh Pillai <sapillai@redhat.com>
2021-05-10 12:59:40 +05:30
Lars Lehtonen 41c567beaf ceph: fix multiple imports
This fixes additional double-imports.

Signed-off-by: Lars Lehtonen <lars.lehtonen@gmail.com>
2021-04-13 02:02:09 -07:00
Blaine Gardner 0f6a5bac76 Merge pull request #7442 from sp98/mon-drain-on-failover
ceph: prevent voluntary mon drain while another mon is failing over
2021-03-30 09:40:14 -06:00
Santosh Pillai 42121e909e ceph: update mon PDBs
- Update mon PDB to use maxUnavailable=1 instead of minAvailable. The maxUnavailable will always be 1 irrespective of the number of mons in the cluster
- Move mon PDB reconcile logic from Disruption Controller to Cluster Controller

Signed-off-by: Santosh Pillai <sapillai@redhat.com>
2021-03-30 12:21:21 +05:30
Satoru Takeuchi 9eb3160d8b ceph: validate all owner references
Remaining work of #7259

Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
2021-03-26 06:43:54 +00:00
Satoru Takeuchi bdfabba75c ceph: replace setting controller reference with utility function
Some settinc controller reference code can be replaced
with `controllerutil.SetControllerReference`. It's better to use it
since it provides ownerReference verification.

Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
2021-02-09 12:03:38 +00:00
Santosh Pillai b780e5b5c0 ceph: skip pdb reconcile on create and delete events
This PR makes create and delete events on pdb a no-op. Update event only triggers reconcile if its the main OSD pdb and allowed disruptions is 0.
This prevents controller to reconcile on pdb events namespaces outside rook ceph.

Signed-off-by: Santosh Pillai <sapillai@redhat.com>
2021-02-03 22:43:20 +05:30
Sébastien Han 8d033efb5a ceph: silence harmless errors
If the ceph cli outputs an error with "error calling conf_read_file"
this means that the operator has not written its ceph configuration
file. Thus ceph cli commands will fail, so we can just ignore that since
the operator will soon write this file in its initialization sequence.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-02-03 17:28:44 +01:00
Travis Nielsen d150980241 ceph: skip logging error for mon pdbs if single mon
If there is a single mon, we don't expect the PDBs to be created
and neither do we need to log that it is an error condition.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-02-01 07:57:53 -07:00
Sébastien Han 7558d37420 core: bump to controller-runtime 0.7.0 version
Now using https://github.com/kubernetes-sigs/controller-runtime/releases/tag/v0.7.0

Closes: https://github.com/rook/rook/issues/6689
Signed-off-by: Sébastien Han <seb@redhat.com>
2021-01-13 11:00:43 +01:00
Santosh Pillai 049b44f990 ceph: requeue clusterDisruption controller more proactively
Currently the reconcile of the clusterDisruption controller was triggered mainly due to the
ceph status update in the cephCluster CR. This PR adds reconciles the cluster when:
1. Reconcile when the cluster is created. (This will trigger the first reconcile)
2. Reconcile only when the clusterSpec is updated. (This will avoid triggers when cluster status is updated)
3. Reconcile for events on cephblockpool, cephfilesystem and cephObjectStore.
4. Reconcile for events on Main PDB and when `DisruptionsAllowed` is 0. (that is, when one of the OSD goes down).
5. Reconcile after 30 seconds when there is an active drain going on, that is, pdbStateMap has `draining-failure-domain` as not empty.

Signed-off-by: Santosh Pillai <sapillai@redhat.com>
2020-12-14 16:22:52 +05:30
Santosh Pillai 8602b9c116 ceph: osd pdb reconciler changes
-creates a single PDB (max-unavailable=1) for all OSDs.  This PDB allows one OSD to go down at a given time.
-When a drain is detected, blocking PDBs (max-unavailable=0) will be created for each failure domain that is not being drained and the main PDB (max-unavilable=1) will be deleted. This will allow all the OSDs in the currently drained failure domain to be removed while blocking the deletion  of OSDs in other failure domains.
-Once the PGs are healthy again, the blocking PDBs will be deleted and the main PDB will be restored.
-Add PG healthcheck timeout
-Delete any legacy node drain pods and blocking OSD PDBs

Signed-off-by: Santosh Pillai <sapillai@redhat.com>
2020-11-18 18:25:07 +05:30
Mateusz Gozdek 8ba3762fa4 docs: fix bunch of typos
Found by running the following command:

codespell -S .git,*.png,*.jpg -L \
aks,keyserver,atleast,dne,ser,ist,files\',ba,dum,iam,te -f -H

Signed-off-by: Mateusz Gozdek <mgozdekof@gmail.com>
2020-11-06 10:01:04 +01:00
Santosh Pillai 28cd611eb4 ceph: fix mon pdb reconcile
updated mon pdb reconcile to delete mon pdb and create a new one when mon count changes in the cluster spec

Signed-off-by: Santosh Pillai <sapillai@redhat.com>
2020-10-21 23:15:29 +05:30
subhamkrai de8dbbcdcc ceph: handle golangci-lint linter staticcheck error
this commit handle golangci-lint linter staticcheck error.

`staticcheck` - Staticcheck is a go vet on steroids,
applying a ton of static analysis checks.

To see only `staticcheck` linter output

`golangci-lint run --disable-all -E staticcheck`

Signed-off-by: subhamkrai <srai@redhat.com>
2020-09-24 15:04:55 +05:30
subhamkrai 1e9bb8e6e2 ceph: handle golangci-lint linter deadcode
this commit will enable one more linter `deadcode`
in golangci-lint .

Signed-off-by: subhamkrai <subhamkumarrai03@gmail.com>
2020-09-18 16:53:49 +05:30
subhamkrai f9fafe62d4 ceph: handle golangci-lint linter unused
this commit will enable one more linter
in golangci-lint.

Signed-off-by: subhamkrai <subhamkumarrai03@gmail.com>
2020-09-17 22:53:24 +05:30
subhamkrai 25c116a4bd ceph: handle golangci-lint linter gosimple
this commit handles all the errors  check for
golangci-lint linter gosimple.

Signed-off-by: subhamkrai <subhamkumarrai03@gmail.com>
2020-09-17 15:10:27 +05:30
subhamkrai 465a0f0aec ceph: handling gosec error code g601
this commit handles all the gosec g601
error code (i.e Implicit memory aliasing
of items from a range statement).

Signed-off-by: subhamkrai <subhamkumarrai03@gmail.com>
2020-07-28 11:34:49 +05:30
Travis Nielsen e74c7eaef8 ceph: refactor context and clusterInfo passed to the ceph commands
To provide more context for executing commands in a ceph cluster,
the full clusterInfo is now passed to the ceph execution commands.
All information about the cluster will now be available throughout
all the areas of the operator. The namespace, ceph credentials,
mon endpoints, and other info is a core part of that cluster info.

Arguments passed through the controllers are also simplified for
mons, mgr, osds, and other daemons where the parameters had
become too complex.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-07-16 15:54:54 -06:00
Madhu Rajanna 81688398f2 cleanup: use err.Wrap when the formatting is not required
Replaced err.Wrapf with err.Wrap when the formatting
is not required.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2020-04-29 17:42:59 +05:30
Sébastien Han f27fd207ce ceph: convert the CephCluster controller to the controller-runtime
This is the final conversion to controller-runtime conversion. This time the
CephCluster CRD has been converted to use the controller-runtime
library.
The controller incorporates all the previous watchers too, so the Node
and hot-plug configmap are been watched too.
Only the operator setting configmap is not being watcher since it's not
related to the CephCluster CRD.
Not only the patch converts to controller-runtime but also tries to
re-organize the tree of the repo to actually make the code more
readable and have better functions/methods/tests separations.

Closes: https://github.com/rook/rook/issues/4939
Signed-off-by: Sébastien Han <seb@redhat.com>
2020-04-28 09:40:35 +02:00
Umanga Chapagain 654efb6d0a Ceph: fixes unhandled type assertions
unhandled type assertions can lead to runtime panic. using
the boolean 'ok' flag to handle failure to assert type.

Issue: #4566
Signed-off-by: Umanga Chapagain <chapagainumanga@gmail.com>
2020-04-04 14:00:19 +05:30
Rohan CJ 03e92da102 Ceph: handle not-found error on delete.
Previously, delete was returning an error causing the drain-canary
to reconcile even though it no longer existed.

Signed-off-by: Rohan CJ <rohantmp@gmail.com>
2020-04-03 19:10:45 +05:30
Travis Nielsen ba07a63033 ceph: properly lookup the K8s topology labels for OSDs
The OSDs pick up on several topology labels for CRUSH hierarchy.
The GA label topology.kubernetes.io was partially implemented, but
not picked up by the OSDs. Now the OSDs will pick up both the topology
labels from pre-1.17 such as failure-domain.beta.kubernetes.io/zone
and topology.kubernetes.io/zone.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-03-10 12:06:34 -06:00
Nizamudeen 53883f68cf ceph: Handling Unhandled errors
This commit is to handle all those unhandled errors which raises the gosec warning.

Fixed G104: Unhandled Errors are handled now

Signed-off-by: Nizamudeen <nia@redhat.com>
2020-02-21 22:48:24 +05:30
Travis Nielsen c46aeffc4f Merge pull request #4584 from jmolmo/issue_4565
ceph: Remove ineffectual assignments
2020-02-06 11:26:34 -07:00
Sébastien Han 2e9ee105ed ceph: nits from https://github.com/rook/rook/pull/4679
- Use %q when possible
- don't use fmt.Errorf
- use the right type when returning errors

Signed-off-by: Sébastien Han <seb@redhat.com>
2020-02-06 16:40:19 +01:00
Rohan CJ eaab7b161d Ceph: Info log significant events in the nodedrain controller.
Info log events where a drain canary is either scheduled on a new node
or removed from a node.

Signed-off-by: Rohan CJ <rohantmp@gmail.com>
2020-02-05 16:24:56 +05:30
Rohan CJ 9d1419864e Ceph: Improve detection of stale canaries.
In the case where the node disappears abrubtly,
there was nothing to trigger the nodedrain reconciler to clean up
the stale canary.

Signed-off-by: Rohan CJ <rohantmp@gmail.com>
2020-02-05 16:21:22 +05:30
Juan Miguel Olmo Martínez e27dcdd419 ceph: Remove ineffectual assignments
Description of your changes:
Fix security issues identified by TrailOfBits

Modifications in osd/status.go:
I opted by remove the offending variables because "c.checkNodesCompleted"
provides this variables always, so no need to initialize them.
var was not used, so i have replaced it by the blank identifier.

Modifications in machinelabel/add.go:
I have followed the same criteria used in other disruption packages,
and return the error if it is produced when we try to "watch" machines.

Closes: https://github.com/rook/rook/issues/4565

[test ceph]

Signed-off-by: Juan Miguel Olmo Martínez <jolmomar@redhat.com>
2020-01-10 10:12:49 +01:00
Sébastien Han ad95c7296f ceph: do not print extended format for loggers.
When using the "errors" package, using `%+v` (extended format),
each Frame of the error's StackTrace will be printed in detail.
Let's only print `%v` to print the error.
If the error has a Cause it will be printed recursively.

Basically `%+v` has been replaced with `%v` for all `error` type
interfaces, whether the logger is Info, Warning or Error.

Signed-off-by: Sébastien Han <seb@redhat.com>
2019-12-16 18:35:54 +01:00
Sébastien Han 5ce2ed220e ceph: use "github.com/pkg/errors"
We now use the error package.
Kubernetes errors have been renamed kerrors since they are lower than
'errors'.

Closes: https://github.com/rook/rook/issues/4054
Signed-off-by: Sébastien Han <seb@redhat.com>
2019-12-09 16:58:32 +01:00
Rohan CJ e408c5fd7f Ceph: Add delay between drain switches
Earlier, simultaneous drains could allow the drain detection to switch
disabled PDBs before the Ceph health had fully reflected the effects.

Signed-off-by: Rohan CJ <rohantmp@gmail.com>
2019-11-21 07:22:22 +05:30
Travis Nielsen 93543a2565 Merge pull request #4321 from leseb/reorganize-design-dir
design: add backends to their respective directories
2019-11-15 11:01:15 -07:00
Sébastien Han 91b76cc24c doc: update design links
Since we re-organized the design directory we need to update the links
in various files.

Signed-off-by: Sébastien Han <seb@redhat.com>
2019-11-15 11:29:46 +01:00
Rohan CJ e8198d44d5 Ceph: Fix bug: clusterdisruption noout timestamp was being reset periodically
The timestamp was being periodically cleared and reset, so the noout never expired.

Signed-off-by: Rohan CJ <rohantmp@gmail.com>
2019-11-14 15:29:12 +05:30
Rohan CJ e51e9f3ec9 Ceph: Ensure draining state is set and checked correctly.
- Checking whether drain was incorrectly checked precense in map instead
  of string length. The actual zero value was an empty string.
- Unsetting drain did not check if the cluster was clean.

Signed-off-by: Rohan CJ <rohantmp@gmail.com>
2019-11-14 13:20:55 +05:30
Rohan CJ 1ba2633c27 Ceph: Clean up canaries on nodes that no longer have OSDs or when the node is deleted.
This prevents long-lasting false positives that prevent the ordered progression
of drains.

Signed-off-by: Rohan CJ <rohantmp@gmail.com>
2019-11-13 16:04:45 +05:30
Rohan CJ dd3f0ca63c Ceph: Set the drain-canaries deployment ownerReference to the rook operator.
The drain canary was not being garbage collected properly.

Signed-off-by: Rohan CJ <rohantmp@gmail.com>
2019-11-13 16:04:45 +05:30
Rohan CJ a930264b55 Ceph: Add node topology labels to the drain-canary.
This serves to make the drain-canary selectable by failure domain.

Signed-off-by: Rohan CJ <rohantmp@gmail.com>
2019-11-13 16:04:45 +05:30