in the existing node watcher, we'll check for node update
event and see if there are `out-of-service` taints are applied
and `ROOK_WATCH_FOR_NODE_FAILURE` is enabled in rook-ceph-operator-configmap,
if then we'll create the networkFence cr and delete the cr if nodes come back.
And, added the unit test too.
Signed-off-by: subhamkrai <srai@redhat.com>
adding drop `ALL` capabilities in rook operator container
as this is not required and will remove warning in ocp cluster.
Signed-off-by: subhamkrai <srai@redhat.com>
This commit removes code related to betav1CsiDriver
since minimum k8s version support by rook is now
k8s v1.22 which does not support betav1 csi driver crd.
Signed-off-by: Rakshith R <rar@redhat.com>
This commit removes k8s version check for oidc token
which required k8s v1.20 or above since minimum
k8s version that rook supports now is v1.22.
Signed-off-by: Rakshith R <rar@redhat.com>
Currently the holder daemonset is never updated
which will leaves the images the daemonset also
not updated. we should update the daemonset
template but not restart the csi holder pods
which causes the CSI volume access problem,
set the updateStrategy to OnDelete (already set in
yaml files) which allow us to update the holder
daemonset but not restart/update the pods, when a
pod is deleted or node is rebooted
the new changes will take effect.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
The bucket health checker was removed in 1.10. Now in 1.12
we no longer need this removal of the bucket health
checker since it will no longer exist to remove.
Signed-off-by: travisn <tnielsen@redhat.com>
If the ceph version does not suppport the exporter, the operator
will attempt to delete the service monitor related to the exporter
to ensure it does not exist for a node. If the expected rbac does
not exist, this will cause unnecessary errors since there would anyway
be no service monitor to delete. So we ignore the error of deleting
the service monitor for the exporter.
The context is also passed to the exporter so a new kubeconfig does
not need to be initiated and cause unnecessary logging about
invalid options for the config.
Signed-off-by: travisn <tnielsen@redhat.com>
When creating a CephObjectStoreUser with a value spec.store that refers to an
unexisting CephObjectStore, after the reconciliation loop the
CephObjectStoreUser is in the ReconcileFailed state. However, a
ReconcileSucceeded event is created with this message:
"successfully configured CephObjectStoreUser"
The success message results of the return value for the error which is currently
`nil`. Let's replace it with the error message.
Signed-off-by: Lucas Henry <polyedre@disroot.org>
This PR makes Rook operator to add a label on PVC that contains an image version of Ceph when creating an OSD.
Signed-off-by: YZ775 <yuzuki-mimura@cybozu.co.jp>
We add a new field domainName to the Kerberos section. The field is used
to setup /etc/idmapd.conf with the domain name. This allows idmapper to
map to kerberos credential to the correct uid/gid.
We add Spec.Security.Kerberos.DomainName to the CRD
Signed-off-by: Sachin Prabhu <sprabhu@redhat.com>
There is no reference for ssl in cephobjectstore Secret, so users won't
have much idea why tls secret need to used. Hence give reference
object stores tls secret ref in the Secret.
Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
Signed-off-by: avanthakkar <avanjohn@gmail.com>
Volume "ceph-daemons-sock-dir" is coming empty in case if dataDirHostPath,
which is the case for osd onPVC. Fix the volume creation by using the
ceph cluster spec dataDirHostPath, which allows to run socket commands
on osd containers.
Cleanup exporter daemon even if ceph version is not supported along with other resources like
metrics service and service monitor.
Signed-off-by: avanthakkar <avanjohn@gmail.com>
enable flags with --default prefix for --log-to-stderr, --mon-cluster-log-to-stderr, --err-to-stderr, and --log-stderr-prefix
Signed-off-by: Javier <sjavierlopez@gmail.com>
When deploying a cluster with Helm Chart, if the namespace is not the default value `rook-ceph`, and if the monitoring feature is enabled, then the generated ServiceMonitor's `rook_cluster` selector now follows the namespace, not the hard-coded value `rook-ceph`.
Signed-off-by: Ho Kim <ho.kim@ulagbulag.io>
The radosgw-admin command uses the network spec from ceph cluster spec
in object context but it is not filled properly in the object package.
But with PR 10898, network spec is available in clusterinfo which can
be used directly. Also removed cluserspec from object context.
Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
The rbd mirror reconcile was not re-queuing the reconcile
if the cephcluster was not initialized. All other controllers
waiting for the initialization are requeuing the event,
just not the rbd mirror controller.
Signed-off-by: travisn <tnielsen@redhat.com>
The exporter is enabled by default, but the service monitor
can only be enabled if prometheus CRDs are available. The
monitoring.enabled must be set to true as the flag that
prometheus is available and the service monitor should
be created.
Signed-off-by: travisn <tnielsen@redhat.com>
The prometheus mgr module and ceph exporter can now be optionally
disabled by the monitoring.metricsDisabled setting in the
CephCluster CR. These will not be disabled by default, rather
than the mgr module being disabled by default from v1.11.4.
Signed-off-by: travisn <tnielsen@redhat.com>
As we are not using the controller runtime
metrics we dont even need to start the server
as its just uses extra resouces and its not
much useful.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
if the configuration is already set in the ceph
database, using `ceph config assimilate-conf`
will add the key and value if its missing but
it wont update the value if the key is already
present, To fix this problem we can remove the
key and add all the configurations once again.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
Pare down the available volume sources for NFS config files so that the
CRD isn't unnecessarily huge. This allows us to recommend
`kubectl apply` again in the upgrade doc.
Size of the NFS CRD is reduced by approximately 60%.
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
Dashboard ac-user-create cmd was taking more time
then the usual ceph command to run,
So increased the timeout to run the cmd, and
now dashboard admin user is sucessfully created
Closes: https://github.com/rook/rook/issues/12113
Signed-off-by: parth-gr <paarora@redhat.com>
The journal size was only applicable to the filestore OSD
format which has not been supported by rook since v1.2.
Remove the remaining obsolete setting from the examples and
code.
Signed-off-by: travisn <tnielsen@redhat.com>
The active and standby labels are updated on the mgr pods
by the mgr sidecar. In the case of a single mgr, there is
not sidecar, so the dashboard and other mgr services were
not available when there was a single mgr. Now the mgr
pod will default to the active mgr status label so that
the single mgr case will succeed. In the case of two mgrs,
the sidecar will immediately update the standby mgr to
remove the active status label.
Signed-off-by: travisn <tnielsen@redhat.com>