Commit Graph
9 Commits
Author SHA1 Message Date
Sébastien Han d06a6f93a5 core: run operator with rook user
The rook operator as well as the toolbox pod run with the "rook" user
with UID 2016. The UID was chosen based on the year of the initial
commit in the rook/rook repository.
No more root user running.

Closes: https://github.com/rook/rook/issues/8734
Signed-off-by: Sébastien Han <seb@redhat.com>
2021-11-05 17:22:04 +01:00
Sébastien Han b89730d895 ceph: refactor operator initialization sequence
This commit is a large refactor on how the operator starts, stops and
how it starts various sub-components such as the ceph-csi driver. It
also refines the way we cancel orchestrations. We don't use breakpoints
anymore but send our self a SIGUP to reload our controller runtime
manager.
The reload will happen under different circonstances like:

* a new adminission controller secret is created/deleted/changed
* a CephCluster CR is edited

As mentioned earlier, the csi driver now has its own controller, just
like flex. It reacts to change in the operator config map for particular
ROOK_CSI_ fields.

A second new controller for the operator's general config has been
created, it manages:

* the logging level
* the ceph CLI command timeout
* the discovery daemon

The operator reacts much more rapidly to cancellation events by stopping
the manager's context and reloading it.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-09-17 16:57:12 +02:00
Sébastien Han 656dd0f334 ceph: move the admission webhook to the operator
Our admission webhooks will now run as part of the Operator container
and not an additional deployment. This has the advantage of consuming
fewer resources in the cluster and not having to manage affinities and
tolerations. This only drawback is that the Secret containing the
certificates is not mounted anymore and the content needs to be written
inside the Operator. This is not practical since we also need to watch
for the Secret content to change. Meaning that the certificates have
been renewed and the webhook server needs to use them.
A new approach is on its way to hopefully simplify this last issue and
implement a watcher for the Secret.
In the meantime, users need to use the cert-manager or renew
certificates manually. Additionally, they must update the
ValidatingWebhookConfiguration object with the new CA bundle.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-08-24 19:07:04 +02:00
Blaine Gardner 795124b7a8 ceph: update osds in parallel
Update OSDs in parallel per the design in
design/ceph/update-osds-in-parallel.md

The max number of OSDs updated in parallel is currently fixed at 20.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-03-29 10:55:28 -06:00
Arun Kumar Mohan ded16f779d ceph: changes for 'sigs.k8s.io/sig-storage-lib-external-provisioner/v6'
Signed-off-by: Arun Kumar Mohan <amohan@redhat.com>
2020-11-18 21:14:03 +05:30
Satoru Takeuchi c7990777d2 ceph: make the placement of admission controller configurable
If users want to restrict the nodes where Ceph daemons should exist,
it's better to make the placement of admission controller configurable
as other daemons.

Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
2020-11-09 11:54:52 +00:00
Satoru Takeuchi 081c7c4dba ceph: reduce the number of admission controller pods in small cluster
The number of admission controller pods is 2. When there is only one
node as the CI environment, one of these becomes Pending state.
Although it's harmless, it's better to reduce this value to 1.

Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
2020-10-21 11:47:08 +00:00
subhamkrai bcd7faed4e ceph: suppress gosec errors for g204, g304, g101
this commit suppress the gosec errors for

g204: Audit use of command execution.
g304: File path provided as taint input.
g101: Look for hard coded credentials.

Signed-off-by: subhamkrai <subhamkumarrai03@gmail.com>
2020-07-28 11:10:48 +05:30
Vineet Badrinath ce1003aef8 ceph: adds scripts and components to support admission controllers
adds deploy.sh script to deploy validatingwebhookconfiguration and create secrets.
adds new command ceph admission-controller to start webhook servers.
adds validation for various rook custom resources

Signed-off-by: Vineet Badrinath <vbadrina@redhat.com>
2020-06-24 14:59:00 +05:30