Commit Graph
23 Commits
Author SHA1 Message Date
Olivier 561cede1ef object: fix rgw ceph config
use Zone and ZoneGroup instead of storename for rgw_zone and rgw_zonegroup

Signed-off-by: Olivier Bouffet <olivier.bouffet@infomaniak.com>
(cherry picked from commit c92270cd66)
2021-11-25 18:38:42 +01:00
Jiffin Tony Thottan aba50d3ca9 object: add support in RGW to communicate vault with TLS
From ceph v16.2.6 onwards the vault TLS suppport in RGW was added,
include similar changes for RGW.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2021-11-17 10:19:28 +05:30
Denis Egorenko fb04908315 ceph: add ability to specify ca bundle for rgw
Specify ca Bundle for RGW spec and mount inside pods.

Related-Issue: https://github.com/rook/rook/issues/8490
Signed-off-by: Denis Egorenko <degorenko@mirantis.com>
2021-08-10 23:18:26 +04:00
Jiffin Tony Thottan 1665ad6ea7 ceph: add support for tls certs via k8s tls secrets for rgw
With this PR the RGW can accept TLS certs as K8s TLS secrets

Fixes: 2079
Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2021-07-06 16:30:16 +05:30
Jiffin Tony Thottan 867474e405 ceph: initialise httpclient for bucketchecker and objectstoreuser
For the TLS communication for AdminOps Api, httpclient is required and
filled with TLS certs, currently it is set to nil pointer in
`buckethealthchecker` and `cephobjectstoreuser`.

Thanks @Krast76 finding the issue even proposing the fix.

Fixes: #8132
Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2021-06-21 10:59:58 +05:30
Jiffin Tony Thottan aea21d9c84 ceph: service server cert support for rgw
Service serving certificates are intended to applications that require
encryption in openshift. These certificates are issued as TLS web server
certificates. Currently RGW supports TLS authentication with help of
certs passed as secrets, in this case we add following details as
`service.annotations` in the Objectstore Gateway Spec :
```
service:
  annotations:
    service.beta.openshift.io/serving-cert-secret-name: <name for
autogenerated secret>
```

More details about service serving cert can be found at :
https://docs.openshift.com/container-platform/4.6/security/certificates/service-serving-certificate.html

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2021-04-26 18:15:12 +05:30
Satoru Takeuchi 26c8fd9bd1 ceph: improve owner reference management
It's better to validate ownerReferences when setting them. In addition, we should use
controllerrutil.Set{Controller,Owner}Reference, that have such validation, as possible.

Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
2021-03-16 10:29:33 +00:00
Travis Nielsen e74c7eaef8 ceph: refactor context and clusterInfo passed to the ceph commands
To provide more context for executing commands in a ceph cluster,
the full clusterInfo is now passed to the ceph execution commands.
All information about the cluster will now be available throughout
all the areas of the operator. The namespace, ceph credentials,
mon endpoints, and other info is a core part of that cluster info.

Arguments passed through the controllers are also simplified for
mons, mgr, osds, and other daemons where the parameters had
become too complex.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-07-16 15:54:54 -06:00
n.fraison 6b9a70cb9a ceph: remove specific rgw configuration on mon configuration database
Remove specific rgw config added to the mon configuration database when deleting a CephObjectstore
or when scaling down number of rgw

Signed-off-by: n.fraison <n.fraison@criteo.com>
2020-04-21 22:36:11 +02:00
Sébastien Han f136105951 ceph: use a different port for rgw on sdn
When running on SDN, the container is not privileged and the network
stack is not exposed so running the gw on port 80 will not work (not
enough privileged).

Closes: https://github.com/rook/rook/issues/5106
Signed-off-by: Sébastien Han <seb@redhat.com>
2020-03-30 19:37:11 +02:00
Sébastien Han f268c897e9 ceph: Convert the Ceph ObjectStore controller to the controller-runtime
The CRD watcher has been replaced by the new controller-runtime
framework.
This brings robustness in our operator, meaning that any resources that
are modified will be reconciled into the desired state.

Closes: https://github.com/rook/rook/issues/4937
Signed-off-by: Sébastien Han <seb@redhat.com>
2020-03-17 15:12:41 -06:00
Sébastien Han 45118185cf ceph: remove mimic support, default to nautilus
As of 1.3, Rook will only support Ceph Nautilus 14.2.5.

Signed-off-by: Sébastien Han <seb@redhat.com>
2020-02-13 09:17:34 +01:00
Sébastien Han dde9e189b4 ceph: rgw fix fronted flag
rgw needs the fronted on its cli line to select the fronted as well the
port. This option is not supported in the mon config store.

Closes: https://github.com/rook/rook/issues/4471
Signed-off-by: Sébastien Han <seb@redhat.com>
2019-12-11 15:24:26 +01:00
Sébastien Han 5ce2ed220e ceph: use "github.com/pkg/errors"
We now use the error package.
Kubernetes errors have been renamed kerrors since they are lower than
'errors'.

Closes: https://github.com/rook/rook/issues/4054
Signed-off-by: Sébastien Han <seb@redhat.com>
2019-12-09 16:58:32 +01:00
Mateusz Los 0daec4a7d6 ceph: change rgw client prefix
add rgw prefix to objectstore user

Signed-off-by: Mateusz Los <los.mateusz@gmail.com>
2019-12-09 12:49:24 +01:00
Sébastien Han 334827fb95 ceph: rgw use ceph mon config store
The Ceph Mimic release introduced the monitor config store which allows
us to set configuration flag per daemon in a centralized fashion. Let's
use it for Mimic and newer and keep the CLI flag of daemon startup for
older versions.
The main benefit is that the config of a daemon can now be overridden.

Closes: https://github.com/rook/rook/issues/4307
Signed-off-by: Sébastien Han <seb@redhat.com>
2019-11-26 23:20:52 +01:00
egafford 8ec1256af8 ceph: Generate RGW keyrings before creating dependent deployments
Failure to create a keyring prior to creating a deployment
dependent on that keyring created a race conditition resulting
in an intermittent and unnecessary pod failure. This change
creates a keyring prior to any RGW deployment.

Partially fixes: #4089
Signed-off-by: egafford <egafford@redhat.com>
2019-11-05 14:58:46 -05:00
Blaine Gardner 1be43290be Ceph: override configs in CRD
Allow users to specify overrides in the CephCluster CRD. The override
ConfigMap still exists for emergency situations and is mounted into
daemon pods directly instead of being merged into a Rook-created config
file.

Rook Ceph no longer uses a config file for managing daemons with the
exception of the OSDs which still generate a config in an init
container.

Signed-off-by: Blaine Gardner <blaine.gardner@suse.com>
2019-08-29 15:38:27 -06:00
Sébastien Han 7d54cac453 ceph: rgw: set proper port syntax on beast
The beast fronted configuration for rgw is quite different than civetweb
so we adapted the construct of the arg line based on that configuration
requirement.

Closes: https://github.com/rook/rook/issues/3411
Signed-off-by: Sébastien Han <seb@redhat.com>
2019-07-08 17:54:43 +02:00
Sébastien Han 93b2448619 ceph: refactor rgw bootstrap
This commit does multiple things:

* remove support for AllNodes where we would deploy one rgw per node on
all the nodes.
* a transition path is implemented in the code so that if someone has an
existing deployment, daemonsets will be removed and replaced by an
deployments.
* when using "instances", each rgw deployed has its own key which makes
Ceph reporting the exact number of rgw running, see:

```
[root@rook-ceph-operator-775cf575c5-bh4sr /]# ceph -s
  cluster:
    id:     611fcf39-0669-4864-9a12-debb35c0397a
    health: HEALTH_OK

  services:
    mon: 3 daemons, quorum a,b,c (age 12h)
    mgr: a(active, since 12h)
    osd: 3 osds: 3 up (since 12h), 3 in (since 12h)
    rgw: 3 daemons active (my.store.a, my.store.b, my.store.c)

  data:
    pools:   6 pools, 600 pgs
    objects: 235 objects, 3.8 KiB
    usage:   3.0 GiB used, 84 GiB / 87 GiB avail
    pgs:     600 active+clean
```

Closes: https://github.com/rook/rook/issues/2474, https://github.com/rook/rook/issues/2957 and https://github.com/rook/rook/issues/3245
Signed-off-by: Sébastien Han <seb@redhat.com>
2019-06-14 17:55:15 +02:00
Sébastien Han f6f1aa772f rgw: remove legacy code
This code can be removed since 1.0 shipped.

Signed-off-by: Sébastien Han <seb@redhat.com>
2019-06-14 16:28:17 +02:00
Sébastien Han 0317de9096 rgw: change default frontend on nautilus
As per: ceph/ceph#26599, Beast is now the
default fronted for rados gateway.
Newly created cluster as of Nautilus will use it by default.

Re-added version of 03587352d5
Resolves: #2707
Signed-off-by: Sébastien Han <seb@redhat.com>
2019-06-07 23:10:11 +02:00
Blaine Gardner 086fa8231c rgw: configure entirely in operator
Configure the Ceph rgw daemon completely from the operator a la the
recent changes to the Ceph mon, mgr, and mds operators.

Create the rgw deployment or daemonset first, and then create the
keyring secret for the object store with its owner reference as the
corresponding deployment or daemonset. When the replication controller
is deleted, the secret is also deleted.

The RGW's mime.types file is now stored in a configmap with a different
file created for each object store. This is primarily just a means to
get the mime.types file into the rgw pod, but the added benefit is that
the administrator can modify the configmap, which could reduce
susceptibility to file type execution vulnerabilities (worst case).

Signed-off-by: Blaine Gardner <blaine.gardner@suse.com>
2019-03-07 08:02:42 -07:00