Commit Graph
1252 Commits
Author SHA1 Message Date
Joshua Hoblitt fa89038264 helm: add helm-unittest harness for the charts
The charts have no unit tests. CI runs ct lint plus a helm template and
kustomize build, which prove the charts render but never assert what
they render, so conditional template logic goes unverified.

Add helm-unittest, pinned and installed as a standalone binary, a
test.helm make target, and a Helm Unittests workflow that runs it. The
first suite covers the toolbox deployment: the image composed from the
toolbox and cephImage settings, the precedence of both over the older
toolbox.image setting, the hostNetwork branch driven by the cluster
network provider, and the revisionHistoryLimit guard.

The new job is a required check in .mergify.yml, alongside the existing
chart linting.

Suites live under tests/ in a chart and are excluded from the packaged
chart via .helmignore. The runner is invoked with --strict so that a
misspelled key fails the suite instead of silently rendering defaults.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2026-07-29 10:40:43 -07:00
Travis Nielsen 6ed8f3efcd Merge pull request #18028 from taraasrita10/support_EC_with_MSR
pool: support CRUSH MSR rules for EC pools
2026-07-28 13:45:02 -06:00
Travis Nielsen c40d428ffb Merge pull request #18042 from jhoblitt/helm-toolbox-repository-tag
helm: add toolbox repository and tag settings
2026-07-28 11:12:48 -06:00
Prabhala Tara Aasrita 715f38de91 pool: support CRUSH MSR rules for EC pools
Added failureDomains and osdsPerDomain fields to the
ErasureCodedSpec, which maps to the crush-num-failure-domains and
crush-osds-per-failure-domain Ceph EC profile parameters. This enables
creating EC pools that distribute chunks across fewer, larger hosts
without needing one host per data chunk.

Signed-off-by: Prabhala Tara Aasrita <taraprabhala@Prabhalas-MacBook-Pro.local>
2026-07-28 20:23:51 +05:30
Blaine Gardner d01d770a04 Merge pull request #18029 from raaizik/nfs-custom-port
nfs: support custom NFS server port
2026-07-28 08:49:20 -06:00
raaizikandBlaine Gardner a400ae6fd5 doc: document CephNFS custom port and exposure examples
Document spec.server.port for host-network port conflicts, and describe
how user-managed LoadBalancer and NodePort Services must align port and
targetPort with the CR.

Signed-off-by: raaizik <raaizik@yahoo.com>
Co-Authored-By: Blaine Gardner <b.blaine.gardner@gmail.com>
2026-07-27 13:54:57 +03:00
raaizik 5e36fa4bc3 nfs: support custom NFS server port
When NFS runs with host networking, port 2049 may already be in use.
Add CephNFS spec.server.port (default 2049), wire it through Ganesha
config, the operator Service, and probes, and regenerate CRDs.

Signed-off-by: raaizik <raaizik@yahoo.com>
2026-07-27 13:54:57 +03:00
Joshua Hoblitt faf2bffe5a helm: add toolbox repository and tag settings
The operator image in the rook-ceph chart and the Ceph image in the
rook-ceph-cluster chart are both configured as a repository and tag
pair. The toolbox was the exception, taking a single toolbox.image
string.

Add toolbox.repository and toolbox.tag, so the toolbox image can be
configured the same way as the others. Either setting may be applied on
its own; whichever is left unset falls back to cephImage.repository or
cephImage.tag.

The new settings take precedence over toolbox.image, which continues to
apply when neither is set, so existing values files are unaffected.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2026-07-24 15:16:35 -07:00
Praveen MandClaude Opus 4.6 b2f2288032 csi: add v1 VolumeGroupSnapshot examples for RBD and NFS
Add VolumeGroupSnapshotClass and VolumeGroupSnapshot example manifests
for RBD and NFS, similar to the existing CephFS examples.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Signed-off-by: Praveen M <m.praveen@ibm.com>
2026-07-23 16:33:08 +05:30
Parth Arora 65af8e4f1b Merge pull request #17960 from parth-gr/external-update
external: import script should create mon secret before rns
2026-07-22 13:37:57 +05:30
Oded Viner ec502c3f80 nvmeof: use .nvmeof pool for gateway and remove pool field from CRD
Changes:
- Use a dedicated .nvmeof pool (via CephBlockPool CR named
  builtin-nvmeof) for the NVMe-oF gateway internal state.
- Use a separate nvmeof pool for the StorageClass data.
- Remove the pool field from the CephNVMeOFGateway CRD.
  The gateway now always uses the .nvmeof pool, hardcoded
  in the operator.
- Add .nvmeof to the allowed CephBlockPool name overrides.
- Create a production example nvmeof.yaml (instances: 2,
  replicas: 3) and a CI-only nvmeof-test.yaml (instances: 1,
  replicas: 1).
- Update documentation and CI test script accordingly.

Signed-off-by: Oded Viner <oviner@redhat.com>
2026-07-21 20:19:44 +03:00
parth-gr ce3a2c77ae external: update the csi secrets ordering
create the csi secret before creating the mon cm
as the cluster controller will look for the csi
secrets for creating client profile

Signed-off-by: parth-gr <partharora1010@gmail.com>
2026-07-21 19:52:38 +05:30
parth-gr 56153b344f external: import script should create mon secret before rns
the order of creating the svg and rns is important,
the svg and rns controller is dependent on the ceph health,
so first we should create the mon secret to get the cephcluster `health ok`

Signed-off-by: parth-gr <partharora1010@gmail.com>
2026-07-21 19:52:38 +05:30
subham rai 02428dc8ac Merge pull request #17979 from Madhu-1/resolve-node-publish-secret
external: resolve node secret names via annotations for external cluster
2026-07-20 14:20:41 +05:30
Praveen M ad6f3c5b68 csi: update VolumeGroupSnapshot examples from beta to v1
ceph-csi has updated the VolumeGroupSnapshot API version to v1.
Update the example YAMLs to use groupsnapshot.storage.k8s.io/v1
instead of v1beta1.

Signed-off-by: Praveen M <m.praveen@ibm.com>
2026-07-20 12:48:40 +05:30
Blaine Gardner 75e64b00be Merge pull request #17940 from subhamkrai/add-caps-rgw-admin-user
object: option to update rgw caps with account
2026-07-15 14:12:24 -06:00
subhamkrai 392204c1f8 object: option to update rgw caps with account
this commit add support for updating rgw caps with
`user-info-without-key` and `accounts` to cephobjectstoreuser crd
Adding the check for min ceph version from which these caps
are available.

Co-Authoured-by:  Jiffin Tony Thottan <thottanjiffin@gmail.com>
Signed-off-by: subhamkrai <srai@redhat.com>
2026-07-15 16:45:49 +05:30
Madhu Rajanna 14a146c045 external: resolve node secret names via annotations for external clusters
Add annotations to RBD node secrets in
import-external-cluster.sh so that externally
created secrets with
custom names can be discovered at runtime.
Update CreateUpdateClientProfileRadosNamespace to
look up secrets by annotation
instead of using hardcoded names.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2026-07-15 10:37:18 +05:30
Travis Nielsen 72403b99d7 Merge pull request #17969 from parth-gr/external-fix-ec
external: add the controller publish secret for the ec sc
2026-07-14 11:44:41 -06:00
Parth Arora 0679f843bc Merge pull request #17896 from parth-gr/vsi-volume-attach
external: resolve provisioner secret names via annotations for extern…
2026-07-14 18:10:16 +05:30
parth-gr 53b00ccca4 external: add the controller publish secret for the ec sc
ec sc has the controller publish secret missing
add that to the import script

Signed-off-by: parth-gr <partharora1010@gmail.com>
2026-07-14 18:07:44 +05:30
Joshua Hoblitt 452fb31d95 Merge pull request #17917 from jhoblitt/chart-object-multisite
helm: add multisite CR support to rook-ceph-cluster chart
2026-07-13 13:10:05 -07:00
Travis Nielsen 46a1b0d19b Merge pull request #17887 from Madhu-1/add-node-publish-volume
csi: Add supported files for krbd QoS
2026-07-13 11:55:16 -06:00
Jeff Wallace 5119f3aeb4 monitoring: align pool growth alert with ceph mixin
Aggregate pool usage by pool before predict_linear to avoid duplicate series after mgr pod replacement, and add a one-hour hold time to match the source rule update in ceph/ceph#68621.

Signed-off-by: Jeff Wallace <jeff@tjwallace.ca>
2026-07-10 15:49:48 -07:00
parth-gr ac14ce76c9 external: resolve provisioner secret names via annotations for external clusters
Add annotations to CephFS and RBD provisioner secrets in
import-external-cluster.sh so that externally created secrets with
custom names can be discovered at runtime.
Update CreateUpdateClientProfileRadosNamespace and
generateProfileSubVolumeGroupSpec to look up secrets by annotation
instead of using hardcoded names.

closes: https://github.com/rook/rook/issues/16956
Signed-off-by: parth-gr <partharora1010@gmail.com>
2026-07-10 17:15:01 +05:30
Madhu Rajanna fb71b7406e doc: update the documentation for QoS
Updated the required documentation and yamls
where we are adding support for the QoS for
the rbd pvc that uses the krbd mounter.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2026-07-10 12:27:12 +05:30
Joshua Hoblitt 8989bff653 helm: add multisite CR support to rook-ceph-cluster chart
Add optional CephObjectRealm, CephObjectZoneGroup, and CephObjectZone
resources to the rook-ceph-cluster chart so an RGW multisite topology can
be deployed from the chart alongside CephObjectStore.

Each resource type follows the existing per-list template idiom: a new
template ranges over a values list and renders name, namespace, and spec.
The realm template renders spec only when set, supporting both a new realm
(no spec) and a pulled realm (spec.pull.endpoint).

The three lists ship commented out in values.yaml with a multisite
example, matching the opt-in cephECBlockPools precedent, so a default
install creates no multisite resources.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2026-07-08 14:18:25 -07:00
Madhu Rajanna dfe108d33a csi: update external script for secrets
Update the external script to add the controller
modify and the node publish secrets.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2026-07-08 10:17:52 +05:30
subhamkrai a3e02e607d csi: update csi-operator version to v1.0.4
Updating csi-operator to latest v1.0.4 and
updating the required doc changes as well.

Signed-off-by: subhamkrai <srai@redhat.com>
2026-07-07 07:56:55 -06:00
Joshua Hoblitt c0eb360041 docs: fix typos and grammar in code comments
Fix duplicate words, incorrect articles (a/an), it's/its, and other small
grammar mistakes in Go comments and user-facing messages across pkg/, cmd/,
and tests/.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2026-07-01 08:34:11 -07:00
Travis Nielsen 915c2ade02 Merge pull request #17827 from OdedViner/fix_mg_netpolicy
security: restrict mgr NetworkPolicy to ingress-only
2026-06-30 11:40:57 -06:00
Joshua Hoblitt 993be34a24 Merge pull request #17834 from jhoblitt/docs/fix-stale-doc-comment-names
docs: fix function comments to match their declaration names
2026-06-29 12:04:25 -07:00
Blaine Gardner 485529056d Merge pull request #17764 from subhamkrai/mute-ceph-errors
core: add api changes to mute ceph warnings
2026-06-29 09:50:13 -06:00
Oded Viner 9cec9780fd security: restrict mgr NetworkPolicy to ingress-only
The MGR watch-active sidecar needs Kubernetes API access to
read configmaps and monitor active-standby state. The API
server is host-networked and cannot be targeted by
pod/namespace selectors, making egress restrictions
impractical.

Switch the rook-ceph-mgr NetworkPolicy from egress-only to
ingress-only:
- Allow MON/OSD/MDS/tools pods on ports 6800-7300
- Allow Prometheus scraping on port 9283
- Remove egress rules that blocked API server access and
  caused CrashLoopBackOff in the watch-active container

Signed-off-by: Oded Viner <oviner@redhat.com>
2026-06-28 17:54:39 +03:00
Joshua Hoblitt 49612461a4 docs: fix function comments to match their declaration names
Several godoc comments led with a stale or incorrect identifier, left
over from renames, exported/unexported changes, copy-paste between
sibling declarations, or plain typos. As a result the documented name no
longer matched the function, method, type, or var it describes. Correct
each leading word to the name of the declaration it documents.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2026-06-26 12:52:39 -07:00
Joshua Hoblitt f44af173c4 Merge pull request #17734 from jhoblitt/ci-rgw-endpoint-timeout
ci: make canary rgw endpoint validation retry until clean
2026-06-26 12:31:01 -07:00
Parth Arora 8ff563664d Merge pull request #17826 from parth-gr/external-mounts
external: volumeattachment should be deleted during unmount
2026-06-26 20:38:13 +05:30
parth-gr 88e31185dc external: volumeattachment should be deleted during unmount
before the csi op, the unblish grpc call was not present,
and it has no op
But with csi op, the unpublish grpc is called before the
volumeattachment get remove, and the unpublish call need a
unpublish secret, currently it is getting the secret from the
client profile, but the client profile secret is hardcoded to default
So to override this secret we are adding the secret name in the
storageclass parameter

Signed-off-by: parth-gr <partharora1010@gmail.com>
2026-06-26 17:55:22 +05:30
subhamkrai 9a6c5842bc core: implement ceph health warning mute
this commit implement api to configure
ceph health warning mute/unmute.

Signed-off-by: subhamkrai <srai@redhat.com>
2026-06-24 21:10:54 +05:30
kavirakesh14 619b800b67 operator: fail reconcile if rook-config-override lacks trailing newline
Signed-off-by: kavirakesh14 <kavirakesh007@gmail.com>
2026-06-24 09:56:41 +00:00
Joshua Hoblitt 459c4bebe9 external: add timeout to rgw admin ops api request
The rgw endpoint validation issued an HTTP request to the admin ops
api without a timeout. If the RGW is accepting connections but slow to
respond, for example right after the object store was created, the
script hangs indefinitely instead of reporting a validation error that
the caller could retry on.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2026-06-22 16:41:32 -07:00
Travis Nielsen dc50bce4e6 Merge pull request #17559 from OdedViner/network_policy_upstream
security: add example NetworkPolicy CRs for Ceph operand pods
2026-06-17 12:54:24 -06:00
subhamkrai ad26ebdab0 build: update ceph version to latest v20.2.2
updating the ceph version from v20.2.1 to v20.2.2

Signed-off-by: subhamkrai <srai@redhat.com>
2026-06-17 22:00:11 +05:30
Oded Viner 9dc70051a8 security: add example NetworkPolicy CRs for Ceph operand pods
Add a single example YAML with NetworkPolicy definitions
for all Ceph operand pods (mon, osd, mgr, mds, exporter,
osd-prepare, crashcollector, tools).
Users can apply these policies to restrict egress/ingress
traffic for Rook-Ceph daemon pods.

Signed-off-by: Oded Viner <oviner@redhat.com>
2026-06-16 17:44:34 +03:00
subhamkrai ff5f3baa58 core: add api changes to mute ceph warnings
adding api changes to mute/unmute ceph warnings
based on user configuration. The field is map[string]string
key is ceph warning and value is duration how longs
the warnings will be muted.

Signed-off-by: subhamkrai <srai@redhat.com>
2026-06-16 17:16:04 +05:30
Parth Arora 31236a51e5 Merge pull request #17628 from parth-gr/drbd-upstream
core: add a install guide for tnf
2026-06-15 15:42:09 +05:30
parth-gr 8171c3ed3b core: add a install guide for tnf
add a install guide for tnf
1) Add a drbd install script
2) add a drbd instal doc

assisted-by: anthropic-ai/claude-code

Signed-off-by: parth-gr <partharora1010@gmail.com>
2026-06-12 17:22:43 +05:30
Travis Nielsen d8dd41a623 Merge pull request #17701 from OdedViner/nvme_image
nvmeof: fetch gateway image from ceph config when not in CR
2026-06-11 12:02:45 -06:00
Oded Viner 8b4fd67e17 nvmeof: fetch gateway image from ceph config when not in CR
Make the NVMe-oF gateway image optional in the CR spec.
When not specified, the operator fetches the image from
the Ceph mon config store using the key
mgr/cephadm/container_image_nvmeof. Falls back to the
hardcoded default if the config is unavailable.

Signed-off-by: Oded Viner <oviner@redhat.com>
2026-06-11 19:55:16 +03:00
parth-gr dbc8d2a541 external: update the external cluster to make use of csi op
updated the external cluster doc, and helm and manifest
install to make use of csi operator as it is the default
offering now

Signed-off-by: parth-gr <partharora1010@gmail.com>
2026-06-11 19:10:30 +05:30