Add the ability to specify node profiles in the multus validation test.
This addresses a few points of early feedback on the validation tool.
Statements below critique the tool's behavior before this patch.
1. The tool assumes all daemons are on public and cluster network, which
means users who have a significantly smaller cluster net (a
design choice) cannot run a single test to determine if Rook is
likely to install correctly.
2. The tool does not have placement options to select only a subset of
Kubernetes nodes to run validation on.
3. Users of multus seem to have a dedicated pool of storage nodes more
often than the average Rook install. This makes sense for security-
and perforance-minded users. The tool cannot run a single test to
verify storage-only and general-workload nodes at one time.
These points are addressed by allowing users to specify configurations
for different "NodeTypes."
Each NodeType config has options for selecting the number of OSDs as
well as the number of other (non-OSD) Ceph daemons. This limits the
unnecessary exhaustion of cluster network addresses from critique 1.
Each NodeType config has its own placement (critique 2).
Users can define as many NodeTypes as needed to test the network for
their planned CephCluster. Specifically, this allows the tool to test
storage-only nodes and generalized-workload nodes at the same time. An
arbitrary number of NodeTypes are allowed to support even more highly
specialized cluster setups, such as multiple tiers of storage nodes
where some storage-only nodes may run more OSDs than others.
Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
The issues are fixed from the clean disk action
repo and we shouldn't require any workaround. Also,
I'm not using git revert to revert the commit is earlier
clean disk action was mentioned in every CI which was
duplicate and now we have placed the action to composite yaml
Signed-off-by: subhamkrai <srai@redhat.com>
Since `google-cloud-sdk` is renamed with `google-cloud-cli`,
the github action is failing to remove the older name and this
is causing ci issues. Applying changes suggested by community to
manually remove some packages to resolve the issue.
Signed-off-by: subhamkrai <srai@redhat.com>
Update the multus canary test to reflect modern knowledge about how it
should be configured.
No longer test for the network device in OSD pods. Pods will utterly
fail to start if Multus is unable to attach interfaces.
Instead, look to the OSD map to test the connections more wholistically.
OSDs must have map IPs that include both public and cluster network.
This implicitly tests that the interfaces exist in the Pod, and it
additionally verifies other details, like Ceph `*_network` configs are
set propertly.
Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
using `rook/ceph:master` tags take longer time
to pull and also, we should be using `rook/ceph:local-build`
tag for our ci. This will help canary raw test to be more stable.
Signed-off-by: subhamkrai <srai@redhat.com>
add a new toolbox yaml manifest which will use the
rook image instead of ceph image
for running s5 cmd container needs to run with rook image
closes: https://github.com/rook/rook/issues/12227
Signed-off-by: parth-gr <paarora@redhat.com>
Let's use same ceph version(latest Reef) in both
cluster-test and toolbox.yaml so that we don't need
to pull image twice. Alos, github action helper script
was calling `deploy_manifest_with_local_build` which
is required for operator.yaml and not for toolbox.yaml.
Signed-off-by: subhamkrai <srai@redhat.com>
Adding CephCOSIDriver CRD and controller. The controller will bring up
the ceph cosi driver when first object store is created in the rook
operator namespace. Then admin can defined COSI CRDs like BucketClass
and BucketAccessClass for different object stores deployed via Rook.
Using the BucketClass and BucketAccessClass, user can define
BucketAccess for backend bucket in the RGW. The CephCOSIDriver CRD
defines configuration options for ceph cosi driver. In the first version
its usability is minimal. Even if it is not defined Rook will bring up
the ceph cosi driver with default values.
Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
we need to wait for the rgw pod to be delete and not
only the cephobjectsore, sometime the pod could be in
terminating state. Also, in some place it require proper
command to wait for pod to be ready/delete and get the
pod name only.
Signed-off-by: subhamkrai <srai@redhat.com>
currently we just print the error is anything fails in
script for rgw, So by that there is no panic or
failiure of script if something wrong happened,
Added Explicittly forcing to catch the error from
the error message that is thrown
Closes: https://github.com/rook/rook/issues/12244
Signed-off-by: parth-gr <paarora@redhat.com>
Add a CI e2e test for the multus validation routine that runs whenever
the multus validation test is modified and on master/releases.
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
Add a tmate manifest that can be added to CI tests to allow manually
debugging them in real-time while the test is ongoing.
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
Add a more involved multus validation test to the Rook binary. Because
this is intended to be end-user runnable, make sure operator-only
commands are hidden.
Build this into the rook binary instead of creating a separate binary
for ease, and because any binary built with the kube api becomes 40+
megabytes. We save quite a bit of space by including this in the Rook
binary, which is good for keeping container layers as small as possible.
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
For the RGW daemon validation please check whether pod is Running than
the exisitng checks
Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
The `DOCS_GIT_REPO` var needs to be exported when not set through a `.env`
file, as otherwise it is not propagated to commands run in the
`build-release.sh` script.
Signed-off-by: Alexander Trost <galexrt@googlemail.com>
The canary test is waiting for the prometheus module,
which is now disabled by default. For the canary test,
we need to enable the prometheus module for the external
cluster test.
Signed-off-by: travisn <tnielsen@redhat.com>
This helps forks build custom rook releases more easily by allowing
certain Makefile vars to be overwriten using a `.env` file.
In addition this introduces the `DOCKERCMD` var to the
`build/release/Makefile`.
Signed-off-by: Alexander Trost <galexrt@googlemail.com>
Signed-off-by: Deepika Upadhyay <deepika@koor.tech>
Signed-off-by: Zuhair AlSader <zuhair@koor.tech>
The canary tests sometimes have an intermittent failure
when processing the return value of a grep for the osds
to be running. Print some debug info to help track it
down.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
The test scripts were only waiting for a timeout of three
seconds for ceph commands, which was causing intermittent
failures in the CI. Now the timeout is increased to
ten seconds.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
this commit bump minmum k8s version to 1.21.14 and
max k8s version to latest 1.26.0. Keeping support for
most recent 6 versions.
Signed-off-by: subhamkrai <srai@redhat.com>
The PSPs have long since been deprected. In K8s 1.21 the PSPs
were first deprecated, and support was completely removed
for them in 1.25. With Rook v1.11, the min supported version of
K8s is now 1.21. To reduce confusion in the documentation,
mention of the PSPs is now removed from the 1.11 docs.
For the corner case that users still require the PSPs,
the helm chart still contains the option for creating PSPs
or other users can still create the psp.yaml.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
A new variable is added to rook-ceph-operator-config
ConfigMap to allow using loop devices for osd.
This feature is intended to be used for testing purposes only.
Signed-off-by: Shinya Hayashi <shinya-hayashi@cybozu.co.jp>
Run the ganesha-rados-grace command in a remote pod when multus
networking is enabled.
Signed-off-by: parth-gr <paarora@redhat.com>
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
The service account generated a secret that is required for
configuration automatically in Kubernetes 1.23. In Kubernetes
1.24+, you need to create the secret explicitly.
Signed-off-by: subhamkrai <srai@redhat.com>
The build process sometimes fails with intermittent problems. Some of them
are known problems and then we retry build process. However, there still
are unknown problems. In this case, it's hard to find the reason because
the build process exits immediately.
ref.
https://github.com/rook/rook/runs/8225144002?check_suite_focus=true#step:3:926
```
+ case "$o" in
+ exit 1
Error: Process completed with exit code 1.
```
To make debugging easier, let's print the output of `make`. This log won't be
too long since `make` prints most messages to stderr.
Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
these indenation where added by vscode extentions.
for yaml I have extention ` YAML` by Red Hat
for bash I have `shell-format` and `shellCheck`.
Signed-off-by: subhamkrai <srai@redhat.com>