Commit Graph
1037 Commits
Author SHA1 Message Date
Travis Nielsen 9d2aa1f6bd test: generate long node name depending on test suite
The generation of a long node name in the integration tests was
being done based on the k8s version. In the past, older K8s versions
did not support the changing name. Now it's more maintainable if
we generate the long name depending on the test suite.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-12-06 08:03:56 -07:00
Blaine Gardner 243a47bfc4 build: do not use cross build container for ceph
Do not use the cross build container when building, publishing, and
promoting rook/ceph images. It is no longer needed, and its complexity
can add flakiness.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-12-03 11:06:21 -07:00
Travis Nielsen d9ac8ce490 test: upgrade integration test from 1.7 to master
The upgrade integration test was from rook v1.6 to the latest master.
This was necessary until we are ready for the v1.8 release, from which
time we want to focus the upgrade testing from v1.7 to the latest
master.

The duplication in the test CRs and other resources is now reduced
by the upgrade calling a thin wrapper to forward a call to the
master version of the resource. When a new feature is added that
needs to be differentiated from the previous version, the method
then can be implemented instead of wrapping the master implementation.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-11-30 08:07:42 -07:00
Sébastien Han c890710b63 core: change directory layout
As per discussion, proposing a new layout for the charts/yaml/olm files.

./deploy
├── charts
│   ├── rook-ceph
│   │   └── templates
│   └── rook-ceph-cluster
│       └── templates
├── examples
│   ├── csi
│   │   ├── cephfs
│   │   └── rbd
│   ├── flex
│   ├── monitoring
│   ├── pre-k8s-1.16
└── olm
    └── assemble

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-11-30 09:12:53 +01:00
Sébastien Han 7a223adde4 Merge pull request #9230 from leseb/osd-rm-check
osd: check if osd is safe-to-destroy before removal
2021-11-25 10:55:34 +01:00
Sébastien Han ad2c3c2ae6 Merge pull request #8931 from BlaineEXE/test-rgw-multisite-in-nightly-tests
test: test rgw multisite nightly
2021-11-25 10:25:57 +01:00
Sébastien Han 7402c2cce6 osd: check if osd is ok-to-stop before removal
If multiple removal jobs are fired in parallel, there is a risk of
losing data since we will forcefully remove the OSD. It's also simply
true if a single OSD is not safe to destroy, there is also a risk of
data loss.

So now, we check if the OSD is safe-to-destroy first and then proceed.
The code waits forever and retries every minute unless the
--force-osd-removal flag is passed.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-11-25 10:21:32 +01:00
Travis Nielsen ba54567e8f Merge pull request #9176 from TomHellier/9174-ingress-support-more-k8s-versions
helm: Allow further configurability of the ingress version
2021-11-23 13:47:33 -07:00
Travis Nielsen d340bccd44 Merge pull request #9202 from thotz/hpakedadoc
docs: add details about HPA via KEDA
2021-11-23 10:42:03 -07:00
Sébastien Han f9f08c88ca docs: move the test readme to the official doc
The instructions to deploy a developer environment are useful and should
be part of the official documentation instead of being hidden in the
repo's README.md. Also, remove ancient documentation to deploy with
kubespray a multi-node env.
Also, add a warning to always run tests env in a virtual machine.

Closes: https://github.com/rook/rook/issues/9166
Signed-off-by: Sébastien Han <seb@redhat.com>
2021-11-23 15:56:28 +01:00
Jiffin Tony Thottan d32c837e35 docs: add details about HPA via KEDA
By default HPA can use details about memory or CPU consumption for
autoscaling, but also it can use custom metrics as well. There are alot
provides supports HPA via customer and one of them is KEDA project. Here
it is done with help of Prometheus Scaler

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2021-11-23 16:50:18 +05:30
Tom Hellier ba44602477 helm: allow further configurability of ingress version
The ingress api version changed when it went to v1, and this has caused some upheaval
throughout the kubernetes ecosystem. This commit uses a common method of deciding which
ingress api to use, and allows the optional override of the kubernetes version
presented to helm using the helm build-in capabilities.
also add an ingress into the helm integration tests so any regressions to how ingresses
are handled in the future are caught easier.

Closes rook#9174

Signed-off-by: Tom Hellier <me@tomhellier.com>
2021-11-22 10:03:02 +00:00
Blaine Gardner e80368674d test: run RGW multisite test in nightly job
In the nightly job, run the test with the latest Ceph version so we can
detect if there are RGW changes in Ceph that might break multisite. Use
a reusable GitHub action workflow to duplicate as little code as
possible.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-11-19 09:56:41 -07:00
Travis Nielsen 1afd322650 core: ensure cluster name is available on cluster info
The cluster info is important context for the cluster controller to
create the cluster, and all the fields must be properly set.
A test cluster name was being set temporarily, resulting in
mons incorrectly getting the wrong cluster CR name. There is no
known issue from the temporary value, it was just exposed by
https://github.com/rook/rook/pull/8678 setting the value to a label.

Now the functions are more clearly named so only unit and
integration tests should be using the test value for the cluster
name where it is not important.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-11-18 15:30:26 -07:00
Jiffin Tony Thottan aba50d3ca9 object: add support in RGW to communicate vault with TLS
From ceph v16.2.6 onwards the vault TLS suppport in RGW was added,
include similar changes for RGW.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2021-11-17 10:19:28 +05:30
Yuichiro Ueno 4cc716a7ca core: add context parameter to k8sutil node
This commit adds context parameter to k8sutil node functions. By this,
we can handle cancellation during API call of node resource.

Signed-off-by: Yuichiro Ueno <y1r.ueno@gmail.com>
2021-11-15 22:45:59 +09:00
Sébastien Han ecd7fa7880 Merge pull request #9164 from y1r/add-context-k8sutil-pod
core: add context parameter to k8sutil pod
2021-11-15 11:58:36 +01:00
Yuichiro Ueno 0559977b8a core: add context parameter to k8sutil pod
This commit adds context parameter to k8sutil pod functions. By this, we
can handle cancellation during API call of pod resource.

Signed-off-by: Yuichiro Ueno <y1r.ueno@gmail.com>
2021-11-13 15:39:41 +09:00
Yuichiro Ueno 0b575703c7 core: add context parameter to k8sutil deployment
This commit adds context parameter to k8sutil deployment functions. By
this, we can handle cancellation during API call of deployment resource.

Signed-off-by: Yuichiro Ueno <y1r.ueno@gmail.com>
2021-11-13 14:58:13 +09:00
Sébastien Han 0e26176b54 ci: wait for kubeproxy to be ready
When requesting issuer, we run a local kubectl proxy command which spawn
a proxy server. However, we must wait for the proxy to be ready before
we actually start making requests to it.
Now the CI waits up to 10sec to retrieve the issuer.

Closes: https://github.com/rook/rook/issues/9090
Signed-off-by: Sébastien Han <seb@redhat.com>
2021-11-08 17:45:53 +01:00
Travis Nielsen 6dc0cc54b9 Merge pull request #8426 from yuvalif/ceph-bucket-notifications
ceph: support bucket notifications for object storage
2021-11-04 17:35:08 -06:00
Sébastien Han 16729e0e38 osd: use multiple service account for vault role
We can pass bound_service_account_names with a comma separated list of
service accounts. Let's do this instead of remapping new values.
Earlier, we thought a single service account could be added per Vault
role and we were using other variables like
`VAULT_AUTH_KUBERNETES_ROOK_OPERATOR_ROLE` that we were remapping to
`VAULT_AUTH_KUBERNETES_ROLE` internal for the API calls to Vault.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-11-04 15:15:46 +01:00
Yuval Lifshitz 71ed45b69b rgw: implement bucket notifications for object storage
following the design from here:
https://github.com/rook/rook/blob/master/design/ceph/object/ceph-bucket-notification-crd.md

Closes: https://github.com/rook/rook/issues/5313
Signed-off-by: Yuval Lifshitz <ylifshit@redhat.com>
2021-11-04 11:20:40 +02:00
Travis Nielsen b3b8172e13 Merge pull request #9056 from leseb/fix-8851
docs: simplify dev guide
2021-11-03 12:34:41 -06:00
Sébastien Han 85f8fdec5a docs: simplify dev guide
We removed the obsolete `minikube.sh` script for a cleaner dev
procedure.

Closes: https://github.com/rook/rook/issues/8851
Signed-off-by: Sébastien Han <seb@redhat.com>
2021-11-03 18:56:33 +01:00
Yuzuki Mimura 536b59ef0f rgw: change the way to livenessProbe and introduce readinessProbe
rgw doesn't respond `livenessProbe` if the number of connection reaches its
limit (by default, 1000). Then rgw is out of service but still live.
Hense the current `livenessProbe` logic is suitiable for `readinessProbe`.
`tcpSocket` is enough for `livenessProbe`.

Closes: #8407

Signed-off-by: Yuzuki Mimura <yuzuki725.m@gmail.com>
Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
2021-10-29 15:07:29 +00:00
Sébastien Han e0145b9643 nfs: add pool setting CR option
Ths NFS spec now supports the CephBlockPool spec which means that it can
take advantage of all the known settings like compression, size, failure
domain etc.

Closes: https://github.com/rook/rook/issues/9034
Signed-off-by: Sébastien Han <seb@redhat.com>
2021-10-29 09:04:31 +02:00
Travis Nielsen 2c61ea2fc3 test: create volume replication crds for yaml validation
The yaml validation of the examples folder requires all the CRDs
to be created in advance of the dry-run command.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-10-26 23:28:40 -06:00
Sébastien Han 871932cc8e ci: log and describe all the pod/deploys on errors
When the CI fails, we want to collect more logs and describe from the
entire environment.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-10-26 08:29:51 +00:00
Sébastien Han 3b5bbf28d5 Merge pull request #9003 from leseb/vault-k8s-auth
osd: add support for k8s with vault kms
2021-10-25 18:02:48 +02:00
Blaine Gardner 2f850b6ae6 Merge pull request #8613 from subhamkrai/remove-nautilus
ceph: remove ceph nautilus, ceph octopus to default
2021-10-25 09:09:18 -06:00
Sébastien Han 18a4047679 osd: add support for k8s with vault kms
Rook cluster-wide encryption can now use the native Kubernetes
authentication to interact with vault KMS instead of using the token
method.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-10-21 13:59:28 +02:00
Travis Nielsen 8f639c61de Merge pull request #8938 from subhamkrai/update-minikube
ci: update minikube and kubernetes version
2021-10-20 07:52:06 -06:00
subhamkrai 0150966024 ceph: remove ceph nautilus, ceph octopus to default
since rook 1.8, ceph nautilus no longer supported,
ceph octopus will be the minimum ceph version.

Closes: https://github.com/rook/rook/issues/7908
Signed-off-by: subhamkrai <srai@redhat.com>
2021-10-20 14:45:12 +05:30
subhamkrai 6be9071a22 ci: update minikube.sh script to use minikube command
using `docker-env` command to copy image giving error
`X Exiting due to ENV_DRIVER_CONFLICT: 'none' driver does not support 'minikube docker-env' command`
so, using `minikube image load <image>` commmand to copy
image.

Signed-off-by: subhamkrai <srai@redhat.com>
2021-10-20 14:26:50 +05:30
subhamkrai e49cdf0a8d ci: clean validate_cluster.sh script
removing `trap display_status SIGINT ERR` command
from the file as `display_status` func has been removed.

Closes: https://github.com/rook/rook/issues/9004
Signed-off-by: subhamkrai <srai@redhat.com>
2021-10-20 10:43:50 +05:30
Blaine Gardner 65619c2677 test: get more partition info setting up ci disk
Add some commands to get more partition info when setting up the GH
action runner's disk for use in integration tests. This will both aid in
debugging and may "jog" the system such that it will no longer need to
reload the partition info when running the OSD prepare job.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-10-18 11:29:13 -06:00
Blaine Gardner ba7745d4af test: do not use head because of pipe errors
The `head` command exits once it has output which can result in a
SIGPIPE error if the command piping its output to head hasn't yet
finished. Use `awk 'FNR <= 1'` instead, which waits on the input pipe to
close before it exits.

See here for more info:
https://unix.stackexchange.com/a/256047

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-10-15 10:14:41 -06:00
Sébastien Han 73970a56c5 ci: fix prepare pod wrong selector
We missed the `app=` in the selector.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-10-15 10:36:15 +02:00
Blaine Gardner 9593bdd471 Merge pull request #8982 from BlaineEXE/fix-prepare-pod-log-collection
test: fix prepare pod log collection in CI
2021-10-14 11:20:28 -06:00
Blaine Gardner f287df70ee test: fix prepare pod log collection in CI
In the CI tests that use `validate_cluster.sh display_status` to gather
logs, the prepare pod log collection failed. Fix this.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-10-14 11:15:59 -06:00
Sébastien Han 07986bcf8c Merge pull request #8867 from leseb/kv-auto-detect-with-certs
ceph: fix kms auto-detection when full TLS
2021-10-14 11:30:13 +02:00
Blaine Gardner 34a8b42e97 test: try to un-flake multi-cluster-mirror test
Try to un-flake the multi-cluster-mirror test that keeps failing on this
PR.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-10-13 11:06:51 -06:00
Blaine Gardner 65c4972038 rgw: make CephObjectRealm controller idempotent
The CephObjectRealm controller would fail all subsequent reconciles if
the first reconcile created the Kubernetes Secret containing the access
keys for the realm but where the radosgw-admin command failed to create
the realm. This was the only idempotency issue found after reviewing the
CephObjectRealm controller.

Resolves #8954

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-10-13 11:06:51 -06:00
Sébastien Han 5e3ecaadbb Merge pull request #8966 from leseb/rm-compression-mode
ceph: remove default value for pool compression
2021-10-13 18:13:24 +02:00
Sébastien Han 61afadd97e ceph: fix kms auto-detection when full TLS
When TLS is used and includes a caert, client key/cert, we need to copy
the content of the secret to a file in the operator's container
filesystem so that we can build the TLS config and thus the HTTP Client,
which reads those files.
Also, removing the files after each API call so they don't persist on
the filesystem forever.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-10-13 18:12:58 +02:00
Sébastien Han 28cc6f5514 ceph: remove default value for pool compression
Using a default value for CompressionMode to none effectively overrides
any values for Parameters. It is deprecated but still takes precedence.
Which means that in its previous form, Parameters was always ignored
since CompressionMode was always set to none when empty.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-10-13 17:06:22 +02:00
Travis Nielsen 74dac725a4 test: run the daily arm tests against official builds
The daily arm test suite is failing due to the new local-build
image tag. Instead of waiting for the arm build to complete,
we can just pick up the latest tag from the same branch
that was already pushed to dockerhub and no need to build
again.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-10-12 15:26:18 -06:00
Blaine Gardner a1dd256d4b Merge pull request #8911 from BlaineEXE/rgw-commands-use-staging-flag
rgw: replace period update --commit with function
2021-10-12 08:22:41 -06:00
Blaine Gardner 956430826c rgw: add integration test for committing period
Add to the RGW multisite integration test a verification that the RGW
period is committed on the first reconcile and not committed on the
second reconcile.

Do this in the multisite test so that we verify that this works for
both the primary and secondary multi-site cluster.

To add this test, the github-action-helper.sh script had to be modified
to
1. actually deploy the version of Rook under test
2. adjust how functions are called to not lose the `-e` in a subshell
3. fix wait_for_prepare_pod helper that had a failure in the middle
   of its operation that didn't cause failures in the past

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-10-11 15:24:59 -06:00