Commit Graph
426 Commits
Author SHA1 Message Date
Artem Torubarov 7ea3480d5e docs: osd replacement user guide
Signed-off-by: Artem Torubarov <artem.torubarov@sap.com>
2026-07-27 18:43:58 +02:00
Madhu Rajanna fb71b7406e doc: update the documentation for QoS
Updated the required documentation and yamls
where we are adding support for the QoS for
the rbd pvc that uses the krbd mounter.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2026-07-10 12:27:12 +05:30
Prabhala Tara Aasrita f699960a31 build: remove v prefix from helm chart version tag
Removed the leading v from the Helm OCI chart version tag so that helm pull can auto-resolve the latest version without specifying the tag explicitly.

Signed-off-by: Prabhala Tara Aasrita <taraasrita@ibm.com>
2026-06-29 11:25:14 +05:30
Travis Nielsen d8c30cbf3e docs: reset pending release notes for v1.21
For the next minor release v1.21 reset the pending
release notes

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2026-06-04 13:47:52 -06:00
Santosh 3e49c9f4cf osd: add cryptsetup resize for encrypted host based osds
when using encryptedDevice:true with host based (non pvc) osds, resizing
the underlying disk and restarting the OSD didn't expand the OSD because
the LUKS encryption layer was not resized.

This PR adds resize capabilities inside the activate container. Full
device stack must be resized: PV → LV → LUKS

Steps:
1. Run pvresize and lvextend to grow the LVM layers.
2. Retrieve the LUKS key from the Ceph config-key store using the
lockbox crednetials already available in the activate container
3. Pass the key explicitly to cryptsetup resize via --key-file.

Signed-off-by: Santosh <sapillai@redhat.com>
2026-05-29 12:09:17 +05:30
Michael AdamandTravis Nielsen df57b77b6b docs: update supported kubernetes version range to 1.31 through 1.36
So far, the latest supported kubernetes version was documented as 1.35

This change documents 1.36 (I. e. the latest available) as
the latest supported version.

It also updates the minimun supported kubernetes version
from 1.30 to 1.31

Signed-off-by: Michael Adam <obnox@samba.org>
Co-authored-by: Travis Nielsen <tnielsen@redhat.com>
2026-05-27 15:35:44 +02:00
Joshua Hoblitt d059c351fc core: reference all containers in a spec by name instead of index
This changeset excludes converting _test.go code as there may be a
legitimate reasons (E.g. convenience) for unit test to be sensitive to
ordering.

Related to:
- https://github.com/rook/rook/issues/15291
- https://github.com/rook/rook/pull/16969

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2026-05-26 10:09:23 -07:00
Travis Nielsen 45ec32e513 core: declare stable concurrent cluster reconciles
The ROOK_RECONCILE_CONCURRENT_CLUSTERS feature was implemented
in v1.19. This feature has been stable, with no related issues
reported. The feature is tested in the CI with no known
stability issues. Let's declare this feature as stable.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2026-05-01 14:18:35 -06:00
subhamkrai 4eefad42e8 csi: move csi management to admin
Going forward, admin will manage the csi operator
CR's and rook will only manage Ceph Connection cr
and client Profile cr.

The old csi driver is completely removed from Rook
and can no longer be used starting in Rook v1.20.

The upgrade guide will contain the needed transition steps
for managing the csi operator settings.

Signed-off-by: subhamkrai <srai@redhat.com>
2026-04-29 14:24:26 -06:00
Asish Kumar 24a35e4e74 pool: clean up unused crush rules
Clean up stale CRUSH rules after the Ceph mgr starts so rules left behind by pool failure-domain or device-class changes do not accumulate indefinitely.

The cleanup is guarded by a package-level RWMutex. Pool create and update paths hold the read lock while creating and assigning CRUSH rules, while cluster-wide cleanup holds the write lock before listing pools and deleting unused rules. This keeps pool reconciles parallel with each other while preventing cleanup from deleting a rule that another reconcile has just created but not yet attached to a pool.

Keep direct pool-delete cleanup for the pool's current CRUSH rule, make the cluster-wide cleanup best-effort across all unused rules, and add an operator-level ROOK_DELETE_UNUSED_CRUSH_RULES setting for clusters that need to leave unused custom rules in place.

Document the operator and Helm settings, regenerate the Helm chart docs, and add a pending release note for the default cleanup behavior.

Signed-off-by: Asish Kumar <officialasishkumar@gmail.com>
2026-04-24 23:57:40 +05:30
Santosh c6836c474a rgw: support SSE-S3 with vault agent
Support using SSE-S3 encryption with RGW using vault Agent auth.
RGW sends requests to the agent instead of directly to Vault, and the agent transparently injects the authentication token. This eliminates using and managing a static token

Signed-off-by: Santosh <sapillai@redhat.com>
2026-04-07 12:18:29 +05:30
Santosh bcc070738c doc: rgw accounts
adds pending release notes and documentation for the experimental Ceph
RGW accounts feature.

Signed-off-by: Santosh <sapillai@redhat.com>
2026-04-06 21:16:12 +05:30
Travis Nielsen d996f7fed9 docs: reset pending release notes
With the release of v1.19, the pending release notes doc
is reset for v1.20.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2026-01-21 15:46:36 -07:00
Blaine Gardner a81fc5b0a4 Merge pull request #16885 from BlaineEXE/upgrade-docs-1.19
docs: update upgrade docs for v1.19
2026-01-12 10:41:19 -07:00
Blaine Gardner 48e353b934 docs: update upgrade docs for v1.19
Update the upgrade docs for the upcoming Rook v1.19 release.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2026-01-12 09:12:31 -07:00
parth-gr 3b07adcd1f external: if admin creds is provided dont stop creating csi secret
if admin secret is created stop creating csi secret from
the rook operator

the csi creds and secret will still be created by the python and
the import script

Signed-off-by: parth-gr <partharora1010@gmail.com>
2026-01-12 19:43:26 +05:30
Travis Nielsen 023608e6fd core: enhance logging with namespaced names
For all of the controllers besides the cluster controller,
the logging now includes the namespaced name of the resource
that is being reconciled. This will help with log troubleshooting
to help analyze logs consistently for the resource being
reconciled.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-12-04 12:00:42 -07:00
Travis Nielsen 8782e9183d Merge pull request #16719 from travisn/concurrent-reconcile
cluster: Support concurrent reconcile when there are multiple cephcluster CRs
2025-11-19 11:34:00 -07:00
Travis Nielsen a1c87c6188 mds: remove mds standby if disabled
The activeStandby property was being ignored when deciding
how many mds daemons to start. 2x the active count of mds
daemons were always being created. If the standby is not
desired, the standby can be removed, and it was unexpected
that it was not removed.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-11-19 10:55:12 -07:00
Travis Nielsen b1ce9f226e operator: allow setting concurrent cluster reconciles
The cephcluster controller allows setting concurrent reconciles
with a setting in the operator configmap.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-11-17 11:46:33 -07:00
Travis Nielsen 7b9d208dc2 docs: reset pending release notes for 1.19
Now that core feature development is completed for 1.18,
reset the pending release notes such that changes in
master will go out with 1.19

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-08-29 14:36:43 -06:00
Travis Nielsen 8b4d3b19cf mon: failover mon immediately if node not exist
During mon failover, if a mon is assigned to a node
but the node does not exist, the mon should be failed
over immediately instead of waiting for a 10 or 20
minute timeout. If the node does not exist, the mon pod
will be in a pending state until the failover is finally
triggered, and no point in waiting that long if the
node is gone.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-08-07 10:06:57 -06:00
Oded Viner 973f8a3a35 osd: validate node topology to prevent invalid crush map hierarchy
add a validation check to fail osd deployment when topology labels
like rack or chassis are duplicated across parent domains
(e.g., zones). this prevents invalid crush map hierarchies
(dfbugs-2610).

Signed-off-by: Oded Viner <oviner@redhat.com>
2025-08-05 12:47:11 +03:00
Madhu Rajanna 21220ea81f core: add clusterID to subvolume group CRD
Providing an option for user to specify the clusterID
they want to use in the storageclass while creating
the subvolume group.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2025-07-28 08:29:51 +02:00
synthe102 25a7a910b5 helm(rook-ceph-cluster): add HTTPRoute for dashboard and objectstore
Signed-off-by: synthe102 <leonard@suslian.engineer>
2025-07-15 19:00:00 +00:00
Michael AdamandTravis Nielsen 42d0531be2 helm: support the six most recent minor helm versions
Now rook supports the six most recent minor versions of helm along with
their patch updates. I. e. helm 3.13 and newer is supported.

Fixes: #15980

Co-authored-by: Travis Nielsen <tnielsen@redhat.com>
Signed-off-by: Michael Adam <obnox@samba.org>
2025-06-25 20:22:41 +02:00
Travis Nielsen 75307a4f1b docs: reset pending release notes
For the upcoming 1.18 release in a few months, reset
the pending release notes for that release.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-04-21 11:57:32 -06:00
Joshua Hoblitt 02c65b832e doc: add CephBucketTopic kafka mechanism field to upgrade docs
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-04-14 16:08:58 -07:00
Blaine Gardner deb9838324 doc: update release notes and upgrade docs
Update pending release notes and upgrade docs for v1.17.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2025-04-07 09:57:20 -06:00
Joshua Hoblitt 6b2c357871 object: add CephObjectStoreUser.spec.keys
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-04-03 09:09:01 -07:00
Patryk Rostkowski 08199b27c9 mon: manage endpoints containing set of mon ip addresses
The change creates and manages an Endpoints resource
with the current Ceph monitor (mon) IPs, allowing
clients to resolve mon IPs via DNS without relying
on the rook-ceph-mon-endpoints ConfigMap.

Signed-off-by: Patryk Rostkowski <patrostkowski@gmail.com>
2025-03-31 18:05:37 +02:00
Artem Torubarov c79d28669b ci: add external mon to pending release notes
Signed-off-by: Artem Torubarov <artem.torubarov@clyso.com>
2025-03-03 18:53:58 +01:00
Blaine Gardner 88bf8dd475 doc: add obc allow list to pending release notes
Add a note about the upcoming potentially-breaking change to OBCs to the
v1.17 release notes. This covers usage of
`ROOK_OBC_ALLOW_ADDITIONAL_CONFIG_FIELDS` for OBC fields that some
admins might not want exposed to users.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2025-02-19 12:10:06 -07:00
Travis Nielsen 86a287030c docs: reset pending release notes
For the upcoming 4.17 release, we reset the pending release
notes so we can add new features to the list.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-01-14 09:57:27 -07:00
Blaine Gardner 80903df984 Merge pull request #15138 from jhoblitt/feature/obc-bucket-policy-alt1
object: add bucketPolicy to obc
2024-12-12 14:36:16 -07:00
Joshua Hoblitt 97b904c717 object: add obc bucketPolicy
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-12-12 13:36:26 -07:00
Travis Nielsen 7c2f41e72e build: add support for k8s 1.32
With the release of K8s 1.32, we update the CI and docs
to support this new release, to maintain the most recent
six releases of K8s.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-12-12 09:48:42 -07:00
Artem Torubarov 83c8ec8160 rgw: add rgw_enable_apis config option
Signed-off-by: Artem Torubarov <artem.torubarov@clyso.com>
2024-12-10 11:53:27 +01:00
Santosh Pillai 85c81946ce osd: enable encryption as day-2 operation
Migrate OSDs to enable encryption as day-2 operation.

Signed-off-by: Santosh Pillai <sapillai@redhat.com>
2024-12-06 09:33:03 +05:30
parth-gr 9785ef5c8d rbdmirror: enable periodic monitoring for rados namespace
enable monitoring for rados namespace

Signed-off-by: parth-gr <partharora1010@gmail.com>
2024-11-05 13:45:02 +05:30
Travis Nielsen 0fa21969df Merge pull request #14701 from parth-gr/rbd-mirror-rados
rbdmirror: enable rbd rados namespace mirroring
2024-10-10 09:35:22 -06:00
parth-gr 2cef47a9b7 rbdmirror: enable rbd rados namespace mirroring
Modify the CR to allow mirroring of an rados namespace
to a differently named namespace on the remote cluster

1) enable rados namesapce mirroring only
if the blockpool mirrroing is enabled

2) disable blockpool mirroing only if
all the namesapce mirroing is disabled

if the rbd mirroring fails and ceph version is not supported
provide a error message with supported version details
and reason of failing

Signed-off-by: parth-gr <partharora1010@gmail.com>
2024-10-10 14:23:11 +05:30
Travis Nielsen b665d7a7b7 core: remove support for ceph quincy
Given that Ceph Quincy (v17) is past end of life,
remove Quincy from the supported Ceph versions,
examples, and documentation.

Supported versions now include only Reef and Squid.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-10-03 11:12:55 -06:00
Travis Nielsen ceee04b671 docs: reset pending release notes
Since 1.15 is released, we reset the pending release notes
for the 1.16 release

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-08-28 15:22:46 -06:00
Zuhair AlSader 6714b86d3b manifest: add registry name to docker images
Signed-off-by: Zuhair AlSader <zuhair@devzero.io>
2024-08-20 13:35:08 -04:00
Travis Nielsen e157bb5a56 core: support k8s versions 1.26 through 1.31
With the release of K8s v1.31.0, we update the minimum
supported version to v1.26, and add v1.31 to the CI
so we can test the most recent six versions of K8s.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-08-13 16:54:52 -06:00
Blaine Gardner 6026fb1c36 docs: update upgrade docs for v1.15
Update Rook and Ceph upgrade docs for upcoming v1.15 release.
Tidy up pending release notes in the working text as well as official
doc texts.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-08-13 10:47:58 -06:00
ee8bcad49d rgw: add support for keystone auth + swift/s3
For the specification see:
<https://github.com/rook/rook/blob/master/design/ceph/object/swift-and-keystone-integration.md>

* extend the API object specs for swift and keystone integration

* adapt rgw to the new go-ceph version

  - The parameter lists of the API call have changes, as parameters
    ignored by the RGW Admin Ops API are no longer serialized, therefore
    the mock has to be adapted.

  - There is now validation for the user keys that are passed to the
    User get API, therefore things failed when we had empty keys in our
    User proxy object.

* expand the reconcile loop for the swift and keystone integration

* fix minor mistakes in design document

* add env var to pass extra args to minikube

  Minikube decides CPU cores and memory automatically based on the
  available resources on the machine which may be insufficient to
  run rook. This commit adds an environment variable to add arbitrary
  arguments to the minikube command, so both can be specified if
  desired.

* integration tests for swift and keystone

  The new integration of swift or s3 and keystone support by rook
  does not have any integration tests yet.

  This commit introduces integration tests for swift and keystone. The
  tests are done against a minimal keystone setup (keystone container
  image from Yaook-project (https://yaook.cloud), sqlite as database
  backend, cert-manager and trust-manager for test certificate setup).

  To prevent hardcoded credentials, passwords are generated
  by the tests. The integration tests use the openstack client
  (keystone- and swift-functionality) (https://docs.openstack.org/
  python-openstackclient/ latest/). This was a concious design decision
  to use client tooling as close as possible to the end user instead of
  using other go-libraries (such as gophercloud).

* add documentation on swift and keystone

  Currently there is no documentation on the use of Swift to access
  an object store as well as the use of OpenStack keystone for
  authentication.

  This commit adds documentation on the use of Swift and OpenStack
  keystone, as well as CRD-related documentation and an example setup.

* add integration tests for S3 via keystone

  This commit introduces integration tests for s3 and keystone. The
  tests are run against the same minimal keystone setup that the tests
  for swift and keystone use.

  The integration tests use the aws s3 client to use client tooling as
  close as possible to the end user instead of using other go-libraries.

Co-authored-by: Jan Klippel <jan.klippel@uhurutec.com>
Co-authored-by: Silvio Ankermann <silvio.ankermann@cloudandheat.com>
Signed-off-by: Sebastian Riese <sebastian.riese@cloudandheat.com>
Signed-off-by: Jan Klippel <jan.klippel@uhurutec.com>
Signed-off-by: Silvio Ankermann <silvio.ankermann@cloudandheat.com>
2024-08-08 14:26:21 +02:00
Blaine Gardner b76631ace9 Merge pull request #14467 from BlaineEXE/object-advertise-endpoint
object: add hosting.advertiseEndpoint config
2024-07-31 16:17:24 -06:00
Blaine Gardner a2b0b6449c object: add hosting.advertiseEndpoint config
Add CephObjectStore spec.hosting.advertiseEndpoint configuration. This
provides a clear documented default for which endpoint Rook "advertises"
to dependent resources like CephObjectStores, OBCs, and COSI
Buckets/Accesses and allows users to override the default behavior if
desired.

The current default is to round-robin an endpoint from
spec.hosting.dnsNames, which has proven to be troublesome for some
users' object store configurations. This change provides much-needed
disambiguation for users.

This may be a breaking change for some existing spec.hosting.dnsNames
users. This is unexpected but is documented.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-07-22 14:43:51 -06:00