Commit Graph
43 Commits
Author SHA1 Message Date
Sébastien Han c890710b63 core: change directory layout
As per discussion, proposing a new layout for the charts/yaml/olm files.

./deploy
├── charts
│   ├── rook-ceph
│   │   └── templates
│   └── rook-ceph-cluster
│       └── templates
├── examples
│   ├── csi
│   │   ├── cephfs
│   │   └── rbd
│   ├── flex
│   ├── monitoring
│   ├── pre-k8s-1.16
└── olm
    └── assemble

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-11-30 09:12:53 +01:00
Sébastien Han ad2c3c2ae6 Merge pull request #8931 from BlaineEXE/test-rgw-multisite-in-nightly-tests
test: test rgw multisite nightly
2021-11-25 10:25:57 +01:00
Jiffin Tony Thottan d32c837e35 docs: add details about HPA via KEDA
By default HPA can use details about memory or CPU consumption for
autoscaling, but also it can use custom metrics as well. There are alot
provides supports HPA via customer and one of them is KEDA project. Here
it is done with help of Prometheus Scaler

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2021-11-23 16:50:18 +05:30
Blaine Gardner e80368674d test: run RGW multisite test in nightly job
In the nightly job, run the test with the latest Ceph version so we can
detect if there are RGW changes in Ceph that might break multisite. Use
a reusable GitHub action workflow to duplicate as little code as
possible.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-11-19 09:56:41 -07:00
Travis Nielsen b3b8172e13 Merge pull request #9056 from leseb/fix-8851
docs: simplify dev guide
2021-11-03 12:34:41 -06:00
Sébastien Han 85f8fdec5a docs: simplify dev guide
We removed the obsolete `minikube.sh` script for a cleaner dev
procedure.

Closes: https://github.com/rook/rook/issues/8851
Signed-off-by: Sébastien Han <seb@redhat.com>
2021-11-03 18:56:33 +01:00
Yuzuki Mimura 536b59ef0f rgw: change the way to livenessProbe and introduce readinessProbe
rgw doesn't respond `livenessProbe` if the number of connection reaches its
limit (by default, 1000). Then rgw is out of service but still live.
Hense the current `livenessProbe` logic is suitiable for `readinessProbe`.
`tcpSocket` is enough for `livenessProbe`.

Closes: #8407

Signed-off-by: Yuzuki Mimura <yuzuki725.m@gmail.com>
Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
2021-10-29 15:07:29 +00:00
Travis Nielsen 2c61ea2fc3 test: create volume replication crds for yaml validation
The yaml validation of the examples folder requires all the CRDs
to be created in advance of the dry-run command.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-10-26 23:28:40 -06:00
Blaine Gardner 65619c2677 test: get more partition info setting up ci disk
Add some commands to get more partition info when setting up the GH
action runner's disk for use in integration tests. This will both aid in
debugging and may "jog" the system such that it will no longer need to
reload the partition info when running the OSD prepare job.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-10-18 11:29:13 -06:00
Blaine Gardner ba7745d4af test: do not use head because of pipe errors
The `head` command exits once it has output which can result in a
SIGPIPE error if the command piping its output to head hasn't yet
finished. Use `awk 'FNR <= 1'` instead, which waits on the input pipe to
close before it exits.

See here for more info:
https://unix.stackexchange.com/a/256047

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-10-15 10:14:41 -06:00
Sébastien Han 73970a56c5 ci: fix prepare pod wrong selector
We missed the `app=` in the selector.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-10-15 10:36:15 +02:00
Blaine Gardner 65c4972038 rgw: make CephObjectRealm controller idempotent
The CephObjectRealm controller would fail all subsequent reconciles if
the first reconcile created the Kubernetes Secret containing the access
keys for the realm but where the radosgw-admin command failed to create
the realm. This was the only idempotency issue found after reviewing the
CephObjectRealm controller.

Resolves #8954

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-10-13 11:06:51 -06:00
Travis Nielsen 74dac725a4 test: run the daily arm tests against official builds
The daily arm test suite is failing due to the new local-build
image tag. Instead of waiting for the arm build to complete,
we can just pick up the latest tag from the same branch
that was already pushed to dockerhub and no need to build
again.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-10-12 15:26:18 -06:00
Blaine Gardner 956430826c rgw: add integration test for committing period
Add to the RGW multisite integration test a verification that the RGW
period is committed on the first reconcile and not committed on the
second reconcile.

Do this in the multisite test so that we verify that this works for
both the primary and secondary multi-site cluster.

To add this test, the github-action-helper.sh script had to be modified
to
1. actually deploy the version of Rook under test
2. adjust how functions are called to not lose the `-e` in a subshell
3. fix wait_for_prepare_pod helper that had a failure in the middle
   of its operation that didn't cause failures in the past

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2021-10-11 15:24:59 -06:00
Travis Nielsen af29d1d801 build: run canary tests against the local-build tag
The canary tests were still picking up the tag from operator.yaml
and toolbox.yaml instead of the new test local-build tag.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
(cherry picked from commit 6f48dce3f5)
2021-09-30 15:33:48 -06:00
Sébastien Han e3f7d2f046 ci: retry on image pull error
Try to avoid the following:

```
error pulling image configuration: received unexpected HTTP status: 500 Internal Server Error
```

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-09-29 16:03:38 +02:00
Travis Nielsen 4583a80001 Merge pull request #8790 from travisn/test-local-build
test: Run all integration tests against the local build
2021-09-22 14:31:18 -06:00
Travis Nielsen 9ff0753514 test: run all integration tests against the local build
The integration tests must always be run against the local
build of rook, and an image should never be pulled from dockerhub.
To prevent pulling a release or master tag, the local build
will use a tag specific to the build and not ever published
elsewhere.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
(cherry picked from commit a8a40428b0)
2021-09-22 07:39:42 -06:00
Sébastien Han 7c8dc4bc1a ci: fix multisite test
We just need to wait a little for the object to be replicated to the
other gateway. A simple retry solves this.

Closes: https://github.com/rook/rook/issues/8671
Signed-off-by: Sébastien Han <seb@redhat.com>
2021-09-22 10:23:02 +02:00
Sébastien Han 8786b40d64 rgw: do not create the rgw ops user on the secondary cluster
If the cluster where the rgw is started is secondary and not primary,
trying to create the admin ops user will fail with:

```
Please run the command on master zone.
Performing this operation on non-master zone
leads to inconsistent metadata between zones
```

So we need to force the creation regardless, it is fine the creation will
return UserAlreadyExist and then we just read the current user.

Closes: https://github.com/rook/rook/issues/8671
Signed-off-by: Sébastien Han <seb@redhat.com>
2021-09-21 16:58:03 +02:00
subhamkrai 038031ddbd ci: dry-run is deprecated and replaced with --dry-run=client
--dry-run is deprecated and replaced with --dry-run=client

Signed-off-by: subhamkrai <srai@redhat.com>
2021-09-14 16:13:27 +05:30
Sébastien Han 0e961c4bdc ci: stop build 3 times
This time for real.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-09-09 17:51:03 +02:00
Sébastien Han 73c340ded7 ci: fix pod list
We should not use .items[0].metadata.name if the array length is 0. This
is the case when nothing has been initialized yet. Instead, we should
use .items[*].metadata.name, the wildcard ensures to always return 0
even if nothing is present yet.

Fixes: https://github.com/rook/rook/issues/8676
Signed-off-by: Sébastien Han <seb@redhat.com>
2021-09-09 17:24:56 +02:00
subhamkrai ebe21c8f68 ci: add action for shellcheck linter
we are adding new linter for shellcheck.
As we are writing more shell scripts this
will help maintain quality.

Also, doing all the changes required in
bash files to pass this shellcheck.

Closes: https://github.com/rook/rook/issues/8431
Signed-off-by: subhamkrai <srai@redhat.com>
2021-08-26 10:03:32 +05:30
parth-gr 33bf21ba69 ceph: update CSR from v1beta1 to v1
This commit update the certificates.k8s.io to use version v1
Updated to v1 as v1beta1 certificates.k8s.io is deprecated in v1.19+

Closes: https://github.com/rook/rook/issues/8308
Signed-off-by: parth-gr <paarora@redhat.com>
2021-08-12 20:27:05 +05:30
Ali Maredia b6404ae2ab ceph: rgw multisite intgration testing
This test:
- starts up 2 minikube clusters
- create 2 ceph clusters
- creates object multisite CRDs on each cluster and
syncs the clusters
- writes an object to cluster 1 and reads it on
cluster 2

This commit also adds new functions in
github-action-helper.sh that aid in the multisite
test and the multi cluster mirroring test.

Signed-off-by: Ali Maredia <amaredia@redhat.com>
2021-08-11 13:25:43 -04:00
Sébastien Han 6582fdce97 ci: break if no errors on build
No wonder why the build has been taking longer... We were building 3
times.
We just got at least 2 minutes back of build time thanks to this fix.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-08-05 15:40:48 +02:00
Travis Nielsen 87596c6f8e build: detect git version instead of setting to 0
The build version should be detected with the git describe
command, but if the VERSION var is already set, it will be
used instead of being detected from git. During the official
builds or even local builds, we just want to let the makefile
detect the git version.

The full git history is added to enable proper detection of the
version. Without the full history only a hash is returned for
the version, which then results in an invalid semantic version
error for the helm chart.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-07-28 07:25:10 -06:00
Sébastien Han db40a31bb2 ci: change yq path to /usr/local/bin/yq
So it will override any existing installation.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-07-21 14:15:07 +02:00
Sébastien Han 741dd25efb Merge pull request #8278 from leseb/retry-ci
ci: retry on network errors
2021-07-08 08:52:28 +02:00
Sébastien Han ff8d24a296 ci: retry on network errors
Seen today in https://github.com/rook/rook/pull/8272/checks?check_run_id=3010477951

```
github.com/rook/rook/pkg/apis/ceph.rook.io/v1 imports
	github.com/hashicorp/vault/api: github.com/hashicorp/vault@v1.4.2: reading https://proxy.golang.org/github.com/hashicorp/vault/@v/v1.4.2.zip: 503 Service Unavailable
	server response: Service Unavailable
github.com/rook/rook/pkg/daemon/ceph/osd/kms imports
	github.com/libopenstorage/secrets/vault imports
	github.com/hashicorp/vault/command/agent/auth: github.com/hashicorp/vault@v1.4.2: reading https://proxy.golang.org/github.com/hashicorp/vault/@v/v1.4.2.zip: 503 Service Unavailable
	server response: Service Unavailable
github.com/rook/rook/pkg/daemon/ceph/osd/kms imports
	github.com/libopenstorage/secrets/vault imports
	github.com/hashicorp/vault/command/agent/auth/kubernetes: github.com/hashicorp/vault@v1.4.2: reading https://proxy.golang.org/github.com/hashicorp/vault/@v/v1.4.2.zip: 503 Service Unavailable
	server response: Service Unavailable
make: *** [go.mod.check] Error 1
```

Also https://github.com/rook/rook/pull/8272/checks?check_run_id=3010482113

```
go get: sigs.k8s.io/controller-tools@v0.4.1 updating to
	sigs.k8s.io/controller-tools@v0.5.1-0.20210420220833-f284e2e8098c requires
	k8s.io/apimachinery@v0.20.2 requires
	github.com/json-iterator/go@v1.1.10: verifying go.mod: github.com/json-iterator/go@v1.1.10/go.mod: reading https://sum.golang.org/tile/8/0/x005/043: stream error: stream ID 1099; INTERNAL_ERROR
make[3]: *** [/home/runner/work/rook/rook/.cache/tools/linux_amd64/controller-gen-f284e2e8098cb0193c2b0c7c1c651ae75496539b] Error 1
make[2]: *** [generate-csv-ceph-templates] Error 1
```

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-07-07 18:00:01 +02:00
Sébastien Han 830b36c039 Merge pull request #7920 from thotz/tlscitest
test: ci test for TLS objectstore
2021-07-05 11:23:40 +02:00
Sébastien Han b578f916e7 ceph: add fs mirror config
Similarly to block volume replication, Ceph is capable of replicating the
content of a Ceph Filesystem from one cluster to another.
For this, during the 1.6 cycle, we introduced a new CRD called
CephFilesystemMirror which effectively deploys a cephfs-mirror daemon.
However, configuring peers to enable replication between two clusters
had to be done manually.
Also various bug fix made it in Ceph eventually and the minimum required
version for this to work is to run on Ceph Pacific 16.2.5 at least.

So the automatic configuration of Ceph Filesystem peers is now possible.

By editing the CephFilesystem CRD, you can now turn on mirroring:

```yaml
  mirroring:
    enabled: false
    # list of Kubernetes Secrets containing the peer token
    # for more details see: https://docs.ceph.com/en/latest/dev/cephfs-mirroring/#bootstrap-peers
    peers:
      secretNames:
        - secondary-cluster-peer
```

Also, the mirroring status is displayed in the CR status:

```
status:
  info:
    fsMirrorBootstrapPeerSecretName: fs-peer-token-myfs
  mirroringStatus:
    daemonsStatus:
    - daemon_id: 4186
      filesystems:
      - filesystem_id: 2
        name: myfs
    lastChecked: "2021-07-01T14:16:29Z"
  phase: Ready
  snapshotScheduleStatus:
    lastChecked: "2021-07-01T14:16:29Z"
    snapshotSchedules:
    - fs: myfs
      path: /
      rel_path: /
      retention: {}
      schedule: 24h
```

Closes: https://github.com/rook/rook/issues/7063
Signed-off-by: Sébastien Han <seb@redhat.com>
2021-07-01 17:35:19 +02:00
Jiffin Tony Thottan 9e3cf68d04 test: ci test for TLS objectstore
Extend the object store smoke test to include TLS configurations.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2021-07-01 18:50:27 +05:30
Sébastien Han 9738131010 ci: retry on network build failures
We have seen cases where the build might fail due to a small network
hiccup so let's retry up to 3 times if this is the case.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-06-29 09:18:56 +02:00
Sébastien Han e6734304cd ci: format helper using standard 2 spaces indent
Bash common indent is 2 spaces so let's use it.
See: https://google.github.io/styleguide/shellguide.html

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-06-29 09:18:56 +02:00
Travis Nielsen 054004ba76 Merge pull request #7946 from leseb/ci-arm64-run
ci: add arm64 runner
2021-06-02 10:13:31 -06:00
Sébastien Han b178c8ae2c ci: add arm64 hosted runner
Thanks to @xin3liang we now have 2 hosted runners on ARM64. So let's add
a small integration test for it.
The action will run every day at midnight.

Successful run: https://github.com/rook/rook/pull/7946/checks?check_run_id=2726403458

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-06-02 11:54:43 +02:00
Sébastien Han 0004869f66 ceph: add ceph cluster fsid to LUKS header
When configuring encrypted on-pvc clusters we now set the cluster fsid
in the LUKS header. If needed we can then determine if the encrypted
block is part of our cluster or not. We also attach the pvc_name in case
it might become useful.

Closes: https://github.com/rook/rook/issues/7991
Signed-off-by: Sébastien Han <seb@redhat.com>
2021-05-31 15:01:52 +02:00
Sébastien Han 0c806588d2 Merge pull request #7790 from leseb/retry-vg
ci: retry vgcreate on failure
2021-04-29 19:01:35 +02:00
Sébastien Han c63a42a661 ci: retry vgcreate on failure
Try to mitigate the following error from the CI:

```
+ sudo vgcreate test-rook-vg /dev/sdb
  Can't open /dev/sdb exclusively.  Mounted filesystem?
Error: Process completed with exit code 5.

```

Now we retry up to 3 times to create the volume group.

Closes: https://github.com/rook/rook/issues/7487
Signed-off-by: Sébastien Han <seb@redhat.com>
2021-04-29 18:24:48 +02:00
Sébastien Han 0f7128ece9 build: fix parallel build
We now the generate the CRDs as well as the CSV on a single GOARCH only:
amd64. This helps us avoiding builds colliding with each others.

Closes: https://github.com/rook/rook/issues/7655
Signed-off-by: Sébastien Han <seb@redhat.com>
2021-04-29 17:31:22 +02:00
subhamkrai 7974d46b20 ci: improve github action writing
we have lots of duplicate codes for
github action. this commit refactor
them to a bash script which will minimize
duplicate codes.

Signed-off-by: subhamkrai <srai@redhat.com>
2021-04-27 20:15:52 +05:30