Add VolumeGroupSnapshotClass and VolumeGroupSnapshot example manifests
for RBD and NFS, similar to the existing CephFS examples.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Signed-off-by: Praveen M <m.praveen@ibm.com>
ceph-csi has updated the VolumeGroupSnapshot API version to v1.
Update the example YAMLs to use groupsnapshot.storage.k8s.io/v1
instead of v1beta1.
Signed-off-by: Praveen M <m.praveen@ibm.com>
Updated the required documentation and yamls
where we are adding support for the QoS for
the rbd pvc that uses the krbd mounter.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
adding rook compatible Ceph-Csi driver values.yaml
file making sure, upgrading to 1.20 doesn't break
when csi-driver is moved to admin.
Co-authored-by: Travis Nielsen <tnielsen@redhat.com>
Signed-off-by: subhamkrai <srai@redhat.com>
Going forward, admin will manage the csi operator
CR's and rook will only manage Ceph Connection cr
and client Profile cr.
The old csi driver is completely removed from Rook
and can no longer be used starting in Rook v1.20.
The upgrade guide will contain the needed transition steps
for managing the csi operator settings.
Signed-off-by: subhamkrai <srai@redhat.com>
There is no need to manually deploy Ceph-CSI/NVMe-oF anymore, the YAMLs
can be removed as the example operator.yaml includes the options now.
Signed-off-by: Niels de Vos <ndevos@ibm.com>
adds a new nvmeof minikube canary job for ceph v20.
the test deploys rook with csi operator disabled for nvmeof flow.
it validates pvc and pod io, gateway restart, and data persistence.
Signed-off-by: Oded Viner <oviner@redhat.com>
with controller runtime latest version vO.23.0, golangci lint
is complaining about deprecated api deprecated.
This commit updates the api and adds the requried rbacs
Signed-off-by: subhamkrai <srai@redhat.com>
Add consistent metadata labels to resources that were missing them:
- configmap.yaml: Add labels to rook-ceph-operator-config ConfigMap
- securityContextConstraints.yaml: Add labels to both rook-ceph and rook-ceph-csi SCCs
- serviceaccount.yaml: Add labels to 6 CSI ServiceAccounts that were missing them
All new labels use the unified library.rook-ceph.labels template for consistency.
Regenerated deploy/examples/common.yaml and deploy/examples/csi/nfs/rbac.yaml
to reflect the updated label definitions.
This addresses reviewer feedback about missing labels in non-RBAC resources
and ensures consistent labeling across all Rook Ceph Helm chart resources.
Signed-off-by: fullstackjam <fullstackjam@outlook.com>
This PR addresses ArgoCD drift detection issues by adding consistent
metadata labels to RBAC resources in Rook Ceph Helm charts. The problem
occurs because many RBAC resources lack metadata labels, causing ArgoCD
to interpret them as 'labels: null' and report continuous drift.
Changes made:
- Added consistent labels to all RBAC templates in rook-ceph and library charts
- Created _recommended-labels.tpl template for standardized labeling
- Removed app.kubernetes.io/component label per consideRatio feedback to avoid scope creep
- Suppressed Helm-specific labels (version, instance, managed-by, created-by, chart) from static RBAC files
- Regenerated deploy/examples/common.yaml and deploy/examples/csi/nfs/rbac.yaml
Labels added to RBAC resources:
- operator: rook
- storage-backend: ceph
- app.kubernetes.io/name: rook-ceph
- app.kubernetes.io/part-of: rook-ceph-operator
Impact:
- Resolves ArgoCD 'OutOfSync' issues for Rook RBAC resources
- Improves resource identification and management
- Provides consistent labeling across all Rook Helm charts
- No functional changes to RBAC permissions
- Focuses on essential labels to avoid over-engineering
This addresses review feedback from travisn and consideRatio to maintain
scope and ensure static RBAC files only contain meaningful labels.
Signed-off-by: fullstackjam <fullstackjam@outlook.com>
This touches a lot where a typo could cause issues for someone, so I have self-
reviewed it many times line-by-line already.
There are a few types of changes:
- All resources get tied to their own YAML document separator (`---`)
before their definition, reducing the risk of not separating resources
correctly when rendering multiple into a file. I think the changes
will fix edge case bugs for people with mutiple items listed in
`cephFileSystems` and similar configuration.
- `toYaml ...` is made into `... | toYaml` consistently.
- `default A B` is made into `B | default A` consistently.
- Consistent whitespace chomping, so instead of `{{ end }}` you would
find `{{- end }}` typically. The system is that you should chomp left
almost all the time, and almost all the time _not_ chomp right. You
would chomp right in the beginning of a file or helper function in
order to clear some initial whitespace, otherwise not.
- Multiline helm template comments `{{- /* ... */ }}` get their content
indented 2 spaces.
- List items are consistently rendered with two spaces of indentation.
- `kind` is put before `apiVersion` consistently, to follow a practice
observed partially in the repo.
- Calls to the helm `template` function have been replaced with
`include` to be consistent and to stick with modern practices.
- Use of `indent` have been replaced with `nindent #` and a left
whitespace chomp for a consistent easy to follow practice that gets
good result.
- Several `if` statements like `if X -> render X` have been replaced
with `with X -> render .` to avoid repetition. The `with` statement
won't render if the provided context, making it function also like an
`if` statement.
- Fixed a bug with `if .Values.revisionHistoryLimit`, which should
really be `if not (typeIs "<nil>" .Values.revisionHistoryLimit)` to
handle situations when its set to `0`.
Signed-off-by: Erik Sundell <erik@sundellopensource.se>
updating the csi operator API version
to latest version.
Adding the cephFS and RBD controllerPublish
secret that are required for the fencing
operation that is supported by ceph-csi
with csi-operator.
Updated the storageclass to include the
secrets incase if user wants to override
the defaults in the clientProfile for
new PVC's.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
Ceph-CSI support for fscrypt encryption of cephfs.
To achieve this commit add capability of mounting the
required `rook-ceph-csi-kms-config` configmap into
csi-cephfsplugin-provisioner and nodeplugin pods.
Further it modifies the ClusterRoles `cephfs-csi-nodeplugin` and
`cephfs-external-provisioner-runner` to grant privileges
required for reading encryption configuration and fetching
encryption secrets from either kubernetes secrets or
from a Key Management System (KMS).
These privileges are essential for the proper functioning of
ceph-csi-cephfs with fscrypt encryption.
The following privileges have been added:
- `secrets/get`: Allows reading of secrets for encryption.
- `configmaps/get`: Grants access to configuration maps,
this is used to read encryption configuration.
- `serviceaccounts/get`: Enables retrieval of service accounts for
authentication to KMS and for retrieving encryption secrets
stored there.
- `serviceaccounts/token/create`: Allows creation of service account tokens,
which are required for authenticating requests to KMS
when retrieving encryption secrets.
The commit also updated the csi documentation to include cephfs
in the encryption section, with examples updated accordingly.
Signed-off-by: NymanRobin <robin.nyman@est.tech>
When CPU requests and limits are assigned to a pod,
the pod will be guaranteed the requests, up to the limits.
Even if there are spare CPU cycles, the pod cannot use
them. Thus, pods can be unnecessarily denied compute
when they need to burst if the limits are set.
Therefore, it is not recommended to set CPU limits
since the CPU requests are already guaranteeing that
no pod will be starved at least for its requests.
Signed-off-by: travisn <tnielsen@redhat.com>
For now we are using the operator namespace name
as the prefix for the csi driver, This PR provides
an option for the users if someone wants to have
their own prefix for the csi driver, if someone tries
to change the prefix for existing csi driver rook
operator will fail to reconcile the csi driver.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
when a PVC is cloned external-provisioner
still required update access or else a warning
will be logged in the pvc describe output
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
Added hack in generate-rook-csv for proper
generation of csi nfs rbac in csv.
Added placeholder clusterrole and binding for
nfs nodeplugin sa, since operator-sdk
does not include sa without rules.
Signed-off-by: Rakshith R <rar@redhat.com>
Ceph-CSI supports LUKS encryption for RBD volumes.
This commit adds support for the same by adding capability
of mounting required `rook-ceph-csi-kms-config` configmap
into csi-rbdplugin-provisioner and nodeplugin pods.
Required documentations, helm charts and examples yamls
are also updated.
Resolved: #7032
Signed-off-by: Rakshith R <rar@redhat.com>
Because the NFS CSI driver is optional and rarely deployed, make RBAC
for this driver an optional example that is generated by the helm chart.
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
When creating EC fs, create replicated pool as primary
pool and ec pool as secondary pool, creating ec pool
as primary is not encouraged and it will lead to failure.
Also, changing the pool name in storageclass-ec file.
Closes: https://github.com/rook/rook/issues/8210
Signed-off-by: subhamkrai <srai@redhat.com>