Commit Graph
42 Commits
Author SHA1 Message Date
Praveen MandClaude Opus 4.6 b2f2288032 csi: add v1 VolumeGroupSnapshot examples for RBD and NFS
Add VolumeGroupSnapshotClass and VolumeGroupSnapshot example manifests
for RBD and NFS, similar to the existing CephFS examples.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Signed-off-by: Praveen M <m.praveen@ibm.com>
2026-07-23 16:33:08 +05:30
Praveen M ad6f3c5b68 csi: update VolumeGroupSnapshot examples from beta to v1
ceph-csi has updated the VolumeGroupSnapshot API version to v1.
Update the example YAMLs to use groupsnapshot.storage.k8s.io/v1
instead of v1beta1.

Signed-off-by: Praveen M <m.praveen@ibm.com>
2026-07-20 12:48:40 +05:30
Madhu Rajanna fb71b7406e doc: update the documentation for QoS
Updated the required documentation and yamls
where we are adding support for the QoS for
the rbd pvc that uses the krbd mounter.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2026-07-10 12:27:12 +05:30
subhamkraiandTravis Nielsen 774054c45e docs: add rook compatible ceph csi driver values
adding rook compatible Ceph-Csi driver values.yaml
file making sure, upgrading to 1.20 doesn't break
when csi-driver is moved to admin.

Co-authored-by: Travis Nielsen <tnielsen@redhat.com>
Signed-off-by: subhamkrai <srai@redhat.com>
2026-06-05 14:48:21 -06:00
subhamkrai 4eefad42e8 csi: move csi management to admin
Going forward, admin will manage the csi operator
CR's and rook will only manage Ceph Connection cr
and client Profile cr.

The old csi driver is completely removed from Rook
and can no longer be used starting in Rook v1.20.

The upgrade guide will contain the needed transition steps
for managing the csi operator settings.

Signed-off-by: subhamkrai <srai@redhat.com>
2026-04-29 14:24:26 -06:00
Niels de Vos 02ed13afa0 nvmeof: update the ceph-csi-operator example to deploy Ceph-CSI/NVMe-oF
There is no need to manually deploy Ceph-CSI/NVMe-oF anymore, the YAMLs
can be removed as the example operator.yaml includes the options now.

Signed-off-by: Niels de Vos <ndevos@ibm.com>
2026-03-24 12:18:45 +01:00
Niraj Yadav c5613a3320 csi: update ceph-csi image to v3.16.2
This patch updates the ceph-csi image version
to v3.16.2

Signed-off-by: Niraj Yadav <niryadav@redhat.com>
2026-03-13 15:35:34 +05:30
Oded Viner 2ebb5d968a nvmeof: add nvmeof minikube canary test without csi operator
adds a new nvmeof minikube canary job for ceph v20.
the test deploys rook with csi operator disabled for nvmeof flow.
it validates pvc and pod io, gateway restart, and data persistence.

Signed-off-by: Oded Viner <oviner@redhat.com>
2026-02-18 13:22:50 +02:00
Praveen M 1ad4c04f14 csi: update ceph-csi image to 3.16.1
Signed-off-by: Praveen M <m.praveen@ibm.com>
2026-02-10 20:11:44 +05:30
subhamkrai 08344f39f6 build: update deprecated api GetEventRecorderFor
with controller runtime latest version vO.23.0, golangci lint
is complaining about deprecated api deprecated.
This commit updates the api and adds the requried rbacs

Signed-off-by: subhamkrai <srai@redhat.com>
2026-02-09 21:48:02 +05:30
Oded Viner 83c0b98418 nvmeof: update expansion fields and sidecar images
add expand secrets and set volume expansion in examples
update provisioner and resizer images to canary

Signed-off-by: Oded Viner <oviner@redhat.com>
2026-02-05 20:41:52 +02:00
Oded Viner 88a9bf5c7f nvmeof: add nvme-of gateway crd support
adds CephNVMeOFGateway crd for managing ceph nvme-of gateways.
supports configurable instances, placement, resources,
and networking options.

Signed-off-by: Oded Viner <oviner@redhat.com>
2026-01-20 13:19:18 +02:00
fullstackjam 8656bd493c helm: add missing labels to ConfigMap, SCC, and ServiceAccount resources
Add consistent metadata labels to resources that were missing them:
- configmap.yaml: Add labels to rook-ceph-operator-config ConfigMap
- securityContextConstraints.yaml: Add labels to both rook-ceph and rook-ceph-csi SCCs
- serviceaccount.yaml: Add labels to 6 CSI ServiceAccounts that were missing them

All new labels use the unified library.rook-ceph.labels template for consistency.
Regenerated deploy/examples/common.yaml and deploy/examples/csi/nfs/rbac.yaml
to reflect the updated label definitions.

This addresses reviewer feedback about missing labels in non-RBAC resources
and ensures consistent labeling across all Rook Ceph Helm chart resources.

Signed-off-by: fullstackjam <fullstackjam@outlook.com>
2025-10-01 14:43:29 +08:00
fullstackjam f635d96ae9 helm: add missing labels to RBAC resources to prevent ArgoCD drift
This PR addresses ArgoCD drift detection issues by adding consistent
metadata labels to RBAC resources in Rook Ceph Helm charts. The problem
occurs because many RBAC resources lack metadata labels, causing ArgoCD
to interpret them as 'labels: null' and report continuous drift.

Changes made:
- Added consistent labels to all RBAC templates in rook-ceph and library charts
- Created _recommended-labels.tpl template for standardized labeling
- Removed app.kubernetes.io/component label per consideRatio feedback to avoid scope creep
- Suppressed Helm-specific labels (version, instance, managed-by, created-by, chart) from static RBAC files
- Regenerated deploy/examples/common.yaml and deploy/examples/csi/nfs/rbac.yaml

Labels added to RBAC resources:
- operator: rook
- storage-backend: ceph
- app.kubernetes.io/name: rook-ceph
- app.kubernetes.io/part-of: rook-ceph-operator

Impact:
- Resolves ArgoCD 'OutOfSync' issues for Rook RBAC resources
- Improves resource identification and management
- Provides consistent labeling across all Rook Helm charts
- No functional changes to RBAC permissions
- Focuses on essential labels to avoid over-engineering

This addresses review feedback from travisn and consideRatio to maintain
scope and ensure static RBAC files only contain meaningful labels.

Signed-off-by: fullstackjam <fullstackjam@outlook.com>
2025-10-01 14:43:25 +08:00
Erik Sundell 039f158950 helm: refactoring to modernize templates
This touches a lot where a typo could cause issues for someone, so I have self-
reviewed it many times line-by-line already.

There are a few types of changes:
- All resources get tied to their own YAML document separator (`---`)
  before their definition, reducing the risk of not separating resources
  correctly when rendering multiple into a file. I think the changes
  will fix edge case bugs for people with mutiple items listed in
  `cephFileSystems` and similar configuration.
- `toYaml ...` is made into `... | toYaml` consistently.
- `default A B` is made into `B | default A` consistently.
- Consistent whitespace chomping, so instead of `{{ end }}` you would
  find `{{- end }}` typically. The system is that you should chomp left
  almost all the time, and almost all the time _not_ chomp right. You
  would chomp right in the beginning of a file or helper function in
  order to clear some initial whitespace, otherwise not.
- Multiline helm template comments `{{- /* ... */ }}` get their content
  indented 2 spaces.
- List items are consistently rendered with two spaces of indentation.
- `kind` is put before `apiVersion` consistently, to follow a practice
  observed partially in the repo.
- Calls to the helm `template` function have been replaced with
  `include` to be consistent and to stick with modern practices.
- Use of `indent` have been replaced with `nindent #` and a left
  whitespace chomp for a consistent easy to follow practice that gets
  good result.
- Several `if` statements like `if X -> render X` have been replaced
  with `with X -> render .` to avoid repetition. The `with` statement
  won't render if the provided context, making it function also like an
  `if` statement.
- Fixed a bug with `if .Values.revisionHistoryLimit`, which should
  really be `if not (typeIs "<nil>" .Values.revisionHistoryLimit)` to
  handle situations when its set to `0`.

Signed-off-by: Erik Sundell <erik@sundellopensource.se>
2025-09-16 09:55:10 +02:00
Madhu Rajanna 3d024ce3c7 csi: update the csi-operator API
updating the csi operator API version
to latest version.

Adding the cephFS and RBD controllerPublish
secret that are required for the fencing
operation that is supported by ceph-csi
with csi-operator.

Updated the storageclass to include the
secrets incase if user wants to override
the defaults in the clientProfile for
new PVC's.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2025-08-13 09:30:50 +02:00
Madhu Rajanna 610126c560 doc: update groupsnapshot to betav1
updating the groupsnapshot to betav1 api.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2025-01-02 16:06:16 +01:00
Niraj Yadav b040a02336 Revert "docs: add documentation for rbd volumegroupsnapshot"
This reverts commit 524b6071d2.

Signed-off-by: Niraj Yadav <niryadav@redhat.com>
2024-10-23 11:44:47 +05:30
Niraj Yadav 524b6071d2 docs: add documentation for rbd volumegroupsnapshot
This PR adds the sample YAMLs and documentation
for the RBD VolumeGroupSnapshot.

Signed-off-by: Niraj Yadav <niryadav@redhat.com>
2024-10-15 16:09:01 +05:30
Niraj Yadav 1e3d08f114 docs: add documentation for volumegroupsnapshot
This PR adds the sample YAMLs and documentation
for the VolumeGroupSnapshot feature.

Signed-off-by: Niraj Yadav <niryadav@redhat.com>
2024-09-17 16:55:14 +05:30
Rakshith R 53e2f8c67f csi: add pvc & pod yamls for block volume mode
This commit adds example yamls for block
volume mode.

Signed-off-by: Rakshith R <rar@redhat.com>
2024-08-07 12:50:50 +05:30
NymanRobin 05315ae64f csi: add cephfs encryption support
Ceph-CSI support for fscrypt encryption of cephfs.
To achieve this commit add capability of mounting the
required `rook-ceph-csi-kms-config` configmap into
csi-cephfsplugin-provisioner and nodeplugin pods.

Further it modifies the ClusterRoles `cephfs-csi-nodeplugin` and
`cephfs-external-provisioner-runner` to grant privileges
required for reading encryption configuration and fetching
encryption secrets from either kubernetes secrets or
from a Key Management System (KMS).

These privileges are essential for the proper functioning of
ceph-csi-cephfs with fscrypt encryption.

The following privileges have been added:
- `secrets/get`: Allows reading of secrets for encryption.
- `configmaps/get`: Grants access to configuration maps,
    this is used to read encryption configuration.
- `serviceaccounts/get`: Enables retrieval of service accounts for
    authentication to KMS and for retrieving encryption secrets
    stored there.
- `serviceaccounts/token/create`: Allows creation of service account tokens,
    which are required for authenticating requests to KMS
    when retrieving encryption secrets.

The commit also updated the csi documentation to include cephfs
in the encryption section, with examples updated accordingly.

Signed-off-by: NymanRobin <robin.nyman@est.tech>
2024-05-20 14:03:02 +03:00
travisn 27265ff279 helm: remove cpu limits from all pods
When CPU requests and limits are assigned to a pod,
the pod will be guaranteed the requests, up to the limits.
Even if there are spare CPU cycles, the pod cannot use
them. Thus, pods can be unnecessarily denied compute
when they need to burst if the limits are set.

Therefore, it is not recommended to set CPU limits
since the CPU requests are already guaranteeing that
no pod will be starved at least for its requests.

Signed-off-by: travisn <tnielsen@redhat.com>
2024-02-07 17:36:59 -07:00
Madhu Rajanna c35a8532aa csi: option to customize csi driver name prefix
For now we are using the operator namespace name
as the prefix for the csi driver, This PR provides
an option for the users if someone wants to have
their own prefix for the csi driver, if someone tries
to change the prefix for existing csi driver rook
operator will fail to reconcile the csi driver.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-01-29 10:54:25 +01:00
Praveen M a80396df1b csi: update cmdline args as used by ceph-csi
This commit adds cmdline args to enable
1. RecoverVolumeExpansionFailure
2. PreventVolumeModeConversion
3. HonorPVReclaimPolicy

Signed-off-by: Praveen M <m.praveen@ibm.com>
2024-01-12 15:24:07 +05:30
Mathieu Parent 1578d55b4d helm: drop snapshot.storage.k8s.io/v1beta1
v1 exists since k8s v1.20

Signed-off-by: Mathieu Parent <mathieu.parent@insee.fr>
2023-04-08 21:18:35 +02:00
Madhu Rajanna 4bdab21db0 nfs: add csi-attacher to NFS provisioner
Add attacher sidecar to NFS provisioner pod
to avoid mounting RWO volumes on two nodes

details: https://github.com/rook/rook/issues/10692

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2023-03-22 12:55:32 +01:00
Madhu Rajanna 61c533ba41 csi: add missing update rbac
when a PVC is cloned external-provisioner
still required update access or else a warning
will be logged in the pvc describe output

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2022-12-21 11:11:48 +01:00
Anthony D'Atri 10b398cc02 docs: add additional RBD image features to docs and YAML files
Signed-off-by: Anthony D'Atri <anthonyeleven@users.noreply.github.com>
2022-10-27 10:57:50 -06:00
Rakshith R 9c4592720c csi: add NFS expansion support
This commit adds resizer sidecar to
NFS driver and required storageclass
and rbac changes.

Signed-off-by: Rakshith R <rar@redhat.com>
2022-09-08 16:15:37 +05:30
Rakshith R f8eb2a2fbc csi: add NFS clone support
This commit reqired yaml and docs
changes too for NFS clone support.

Signed-off-by: Rakshith R <rar@redhat.com>
2022-09-08 16:15:37 +05:30
Rakshith R 73042c7531 csi: add NFS snapshot support
This commit adds snapshotter sidecar to
NFS driver and required yamls and docs too.

Signed-off-by: Rakshith R <rar@redhat.com>
2022-09-08 16:15:37 +05:30
Humble Chirammal 34e88776e7 csi: remove unwanted verbs for pv object
pv object patch verb is enough for the csi sidecar to function.

Signed-off-by: Humble Chirammal <hchiramm@redhat.com>
2022-05-16 14:35:34 +05:30
Rakshith R d0b67af23b build: fix csi nfs rbac csv generation
Added hack in generate-rook-csv for proper
generation of csi nfs rbac in csv.
Added placeholder clusterrole and binding for
nfs nodeplugin sa, since operator-sdk
does not include sa without rules.

Signed-off-by: Rakshith R <rar@redhat.com>
2022-04-28 19:42:24 +05:30
Travis Nielsen 6cd1de4776 Merge pull request #9940 from Rakshith-R/csi/add-kms-support
csi: add CSI encryption support
2022-04-19 09:26:52 -06:00
Rakshith R 2e18d5bbaa csi: add CSI encryption support
Ceph-CSI supports LUKS encryption for RBD volumes.
This commit adds support for the same by adding capability
of mounting required `rook-ceph-csi-kms-config` configmap
into csi-rbdplugin-provisioner and nodeplugin pods.
Required documentations, helm charts and examples yamls
are also updated.

Resolved: #7032

Signed-off-by: Rakshith R <rar@redhat.com>
2022-04-13 19:52:51 +05:30
Blaine Gardner bca2f128ab build: generate a separate NFS CSI RBAC manifest
Because the NFS CSI driver is optional and rarely deployed, make RBAC
for this driver an optional example that is generated by the helm chart.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2022-04-12 16:57:11 -06:00
Rakshith R f1953314d4 csi: add nfs example yamls
This commit adds example nfs storageclass,
pvc and pod yamls.

Signed-off-by: Rakshith R <rar@redhat.com>
2022-04-12 11:25:09 +05:30
subhamkrai 5b49d36167 csi: add comment after namespace
adding comment after namespace to identify if
it cluster namespace or operator namespace.

Signed-off-by: subhamkrai <srai@redhat.com>
2022-02-14 18:39:33 +05:30
Denis Egorenko 3ff681e81d file: allow to create CephFS data pools with predefined names
Add an ability to create data pools for CephFS with predefined
names.

Related-Issue: rook#9295
Signed-off-by: Denis Egorenko <degorenko@mirantis.com>
2021-12-14 12:52:19 +04:00
subhamkrai 5bb29f1a21 mds: create EC pool as secondary pool
When creating EC fs, create replicated pool as primary
pool and ec pool as secondary pool, creating ec pool
as primary is not encouraged and it will lead to failure.

Also, changing the pool name in storageclass-ec file.

Closes: https://github.com/rook/rook/issues/8210
Signed-off-by: subhamkrai <srai@redhat.com>
2021-12-07 07:44:54 +05:30
Sébastien Han c890710b63 core: change directory layout
As per discussion, proposing a new layout for the charts/yaml/olm files.

./deploy
├── charts
│   ├── rook-ceph
│   │   └── templates
│   └── rook-ceph-cluster
│       └── templates
├── examples
│   ├── csi
│   │   ├── cephfs
│   │   └── rbd
│   ├── flex
│   ├── monitoring
│   ├── pre-k8s-1.16
└── olm
    └── assemble

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-11-30 09:12:53 +01:00