Commit Graph
164 Commits
Author SHA1 Message Date
subhamkrai a3e02e607d csi: update csi-operator version to v1.0.4
Updating csi-operator to latest v1.0.4 and
updating the required doc changes as well.

Signed-off-by: subhamkrai <srai@redhat.com>
2026-07-07 07:56:55 -06:00
subhamkrai 34b0a87c9e csi: csi-addons should be disabled by default
having csi-addons enabled by default is causing random
pod restart on non-openshift cluster. Let's disable
it by default.

Signed-off-by: subhamkrai <srai@redhat.com>
2026-06-05 13:42:17 -06:00
subhamkrai fbef1d755e docs: add few examples settings for new csi management
this command adds some examples on how users can add/update
the settings based on new way of managing CSI resources.

Signed-off-by: subhamkrai <srai@redhat.com>
2026-06-02 20:47:42 +05:30
Praveen M 449d1baeb7 csi: update ceph-csi image and sidecars
Update ceph-csi to v3.17.0 and CSI sidecars:
- csi-provisioner v6.1.1 -> v6.2.0
- csi-attacher v4.11.0 -> v4.12.0
- csi-node-driver-registrar v2.16.0 -> v2.17.0

Signed-off-by: Praveen M <m.praveen@ibm.com>
2026-05-27 13:25:22 +05:30
Travis Nielsen 45ec32e513 core: declare stable concurrent cluster reconciles
The ROOK_RECONCILE_CONCURRENT_CLUSTERS feature was implemented
in v1.19. This feature has been stable, with no related issues
reported. The feature is tested in the CI with no known
stability issues. Let's declare this feature as stable.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2026-05-01 14:18:35 -06:00
subhamkrai 4eefad42e8 csi: move csi management to admin
Going forward, admin will manage the csi operator
CR's and rook will only manage Ceph Connection cr
and client Profile cr.

The old csi driver is completely removed from Rook
and can no longer be used starting in Rook v1.20.

The upgrade guide will contain the needed transition steps
for managing the csi operator settings.

Signed-off-by: subhamkrai <srai@redhat.com>
2026-04-29 14:24:26 -06:00
Asish Kumar 24a35e4e74 pool: clean up unused crush rules
Clean up stale CRUSH rules after the Ceph mgr starts so rules left behind by pool failure-domain or device-class changes do not accumulate indefinitely.

The cleanup is guarded by a package-level RWMutex. Pool create and update paths hold the read lock while creating and assigning CRUSH rules, while cluster-wide cleanup holds the write lock before listing pools and deleting unused rules. This keeps pool reconciles parallel with each other while preventing cleanup from deleting a rule that another reconcile has just created but not yet attached to a pool.

Keep direct pool-delete cleanup for the pool's current CRUSH rule, make the cluster-wide cleanup best-effort across all unused rules, and add an operator-level ROOK_DELETE_UNUSED_CRUSH_RULES setting for clusters that need to leave unused custom rules in place.

Document the operator and Helm settings, regenerate the Helm chart docs, and add a pending release note for the default cleanup behavior.

Signed-off-by: Asish Kumar <officialasishkumar@gmail.com>
2026-04-24 23:57:40 +05:30
Niraj Yadav c5613a3320 csi: update ceph-csi image to v3.16.2
This patch updates the ceph-csi image version
to v3.16.2

Signed-off-by: Niraj Yadav <niryadav@redhat.com>
2026-03-13 15:35:34 +05:30
Praveen M 6b55092abf csi: update CSI sidecars to latest versions available
Updated the following csi sidecars to their latest available versions:
- csi-attacher: v4.11.0
- csi-snapshotter: v8.5.0
- csi-resizer: v2.1.0
- csi-provisioner: v6.1.1
- csi-node-driver-registrar: v2.16.0

Signed-off-by: Praveen M <m.praveen@ibm.com>
2026-02-26 10:25:49 +05:30
Praveen M 1ad4c04f14 csi: update ceph-csi image to 3.16.1
Signed-off-by: Praveen M <m.praveen@ibm.com>
2026-02-10 20:11:44 +05:30
subhamkrai 20f350a71a csi: remove automated node fencing code
since node fencing is disabled in rook for sometime
and this feature is implemented in csi. So, this
commits remove obsolete code related to node loss

Signed-off-by: subhamkrai <srai@redhat.com>
2026-01-22 15:19:12 +05:30
Praveen M 8ebf07bbfe csi: update csi-addons to v0.14.0
Signed-off-by: Praveen M <m.praveen@ibm.com>
2026-01-16 11:50:18 +05:30
Praveen M 31c7592d03 csi: update external sidecar images
Below sidecars are updated with latest available versions

csi-attacher: v4.10.0
csi-snapshotter: v8.4.0
csi-resizer: v2.0.0
csi-provisioner: v6.0.0
csi-node-driver-registrar: v2.15.0

Signed-off-by: Praveen M <m.praveen@ibm.com>
2026-01-14 14:47:11 +05:30
Praveen M e30d1f7649 csi: update ceph-csi image to 3.16.0
Signed-off-by: Praveen M <m.praveen@ibm.com>
2026-01-14 14:39:44 +05:30
Travis Nielsen b1ce9f226e operator: allow setting concurrent cluster reconciles
The cephcluster controller allows setting concurrent reconciles
with a setting in the operator configmap.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-11-17 11:46:33 -07:00
Praveen M 5fc4e15bb1 csi: update ceph-csi to v3.15.0
We have new release for Ceph-CSI v3.15.0 -
https://github.com/ceph/ceph-csi/releases/tag/v3.15.0

Signed-off-by: Praveen M <m.praveen@ibm.com>
2025-08-19 20:56:00 +05:30
subhamkrai 506ac2a3ff csi: make csi-operator default deployment
this commits enable the csi-operator by default,
moving it from experimental to stable.

Also, disable the csi-operator chart from generating
rbac in common.yaml

Signed-off-by: subhamkrai <srai@redhat.com>
2025-08-14 22:33:07 +05:30
Niels de Vos 17d53ed16b csi: update Kubernetes CSI-Addons sidecar to version 0.13.0
Signed-off-by: Niels de Vos <ndevos@ibm.com>
2025-08-12 17:56:37 +02:00
CL0Pinette b63c222d17 csi: add CrossNamespaceVolumeDataSource feature gate
This enables configuring the CrossNamespaceVolumeDataSource feature gate

Signed-off-by: CL0Pinette <me@cl0pinette.fr>
2025-08-07 14:28:33 +02:00
Madhu Rajanna 052fe4a9af csi: update ceph-csi to 3.14.2
Updating the ceph-csi image to 3.14.2
release.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2025-07-21 11:24:05 +02:00
Travis Nielsen a00c6fba64 Merge pull request #15846 from patrostkowski/fix/mon-run-as-root-15564
mon: allow running mon pods as root
2025-07-07 16:08:48 -06:00
Madhu Rajanna aa8fd61986 csi: update csi version to 3.14.1
Updating the cephcsi version to v3.14.1
release.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2025-06-24 11:46:14 +02:00
Patryk Rostkowski 7f3e6bd7fa mon: allow running mon pods as root
This change addresses a permission issue where mon pods crashloop
on some Kubernetes setups with SELinux enabled, even when
ROOK_HOSTPATH_REQUIRES_PRIVILEGED is set.

To resolve this, a new function makeMonSecurityContext() was introduced
to explicitly set runAsUser: 0 at the pod level for mon pods
when the environment variable ROOK_CEPH_MON_RUN_AS_ROOT is set to true.

Additionally, the function previously named PodSecurityContext() was renamed
to DefaultContainerSecurityContext() to avoid confusion between
container-level and pod-level security context configuration. All container
SecurityContext usages across Ceph daemons were updated to reflect this change.

This ensures the root user configuration is applied
automatically and consistently in environments where it is required
for mon pod startup, while preserving clear separation of container
and pod-level security logic.

Signed-off-by: Patryk Rostkowski <patrostkowski@gmail.com>
2025-06-16 18:29:31 +02:00
Niels de Vos a168c40008 csi: update Kubernetes CSI sidecar images to current versions
The Kubernetes CSI sidecars have had several releases that were not
included in deployments by Rook yet, update them to the versions that
are available today:

- csi-attacher:v4.8.1
- csi-provisioner:v5.2.0
- csi-resizer:v1.13.2
- csi-snapshotter:v8.2.1

This change is important, because Ceph-CSI will implement the new
Controller.GetSnapshot CSI procedure. A bug in csi-lib-utils causes a
panic when a ControllerCapability is provided, but not (yet) known to
the CSI sidecars. The updated sidecars consume a version of
csi-lib-utils with a fix for that panic.

See-also: kubernetes-csi/csi-lib-utils#188
Signed-off-by: Niels de Vos <ndevos@ibm.com>
2025-05-20 14:24:02 +02:00
Rakshith R a555885a5f csi: update cephcsi to latest release
This commit updates cephcsi version to 3.14.0
in rook.

Signed-off-by: Rakshith R <rar@redhat.com>
2025-04-11 18:05:44 +05:30
Travis Nielsen fe70248a13 operator: set dns policy for host network if needed
When host network is enabled, the operator needs to set the
dns policy to ClusterFirstWithHostNet so the request to the
rgw endpoint will resolve properly.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-03-20 14:01:26 -06:00
yati1998 762430ccb5 build: set ceph csi release version to v3.13.1
this commit sets the release version
for ceph-csi to v3.13.1

Signed-off-by: yati1998 <ypadia@redhat.com>
2025-03-10 11:08:07 +05:30
Niels de Vos 25d3b6d5fc csi: update csi-addons to v0.12.0
The csi-addons v0.12.0 release is now available.

See-also: https://github.com/csi-addons/kubernetes-csi-addons/releases/tag/v0.12.0
Signed-off-by: Niels de Vos <ndevos@ibm.com>
2025-03-05 09:35:41 +01:00
Travis NielsenandDmitry Mishin d109dc9029 core: implement operator settings as env vars
The operator settings loaded from the configmap have proven
inefficient for load time and frequently checking the configmap.
To avoid this ineffenciency, the configmap is only loaded once
each time it is created or updated. The values in the configmap
are applied as environment variables, which then are very efficient
to query throughout the various controllers, without needing
to be concerned about loading the configmap again.

Co-authored-by: Dmitry Mishin <dmitry.mishin@gmail.com>
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-02-24 12:12:45 -07:00
Skala Networks d3c3d25c60 csi: bind cephfs and rbd provisionners on non-colliding ports for hostNetwork setups
Signed-off-by: Skala Networks <contact@skala.network>
2025-02-23 06:31:43 -05:00
Blaine Gardner 0e33536539 object: disallow unsafe OBC fields by default
Implement an allow list mechanism that disables potentially unsafe OBC
fields by default. OBC fields beyond `maxObjects` and `maxSize` don't
neatly fit into the OBC framework as it was originally envisioned and
implemented.

Some of the newly added configs could allow users to cause confusion for
themselves. Others might allow users to hijack others buckets. Some
might allow bricking the entire S3 store.

Out of an abundance of safety, allow-list the known-safe options by
default, and require administrators to enable potentially troublesome
options via the new operator-level config
`ROOK_OBC_ALLOW_ADDITIONAL_CONFIG_FIELDS`.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2025-02-12 14:18:01 -07:00
Artem Torubarov 25ee6b4f59 operator: custom hostname topology label
Signed-off-by: Artem Torubarov <artem.torubarov@clyso.com>
2025-01-24 15:59:07 +01:00
Niels de Vos 955fa9cae4 csi: update Kubernetes CSI sidecar images to current versions
The Kubernetes CSI sidecars have had several releases that were not
included in deployments by Rook yet, update them to the versions that
are available today:

- csi-node-driver-registrar:v2.13.0
- csi-provisioner:v5.1.0
- csi-attacher:v4.8.0
- csi-resizer:v1.13.1

Signed-off-by: Niels de Vos <ndevos@ibm.com>
2025-01-15 13:11:26 +01:00
Steven Kreitzer 463d9fb420 csi: csi-snapshotter flag typo; upgrade csi-snapshotter
Signed-off-by: Steven Kreitzer <skre@skre.me>
2024-12-18 09:09:29 -06:00
Madhu Rajanna 07f5700a87 csi: update cephcsi to latest release
cephcsi 3.13.0 is released today and
update the Rook to use the latest image

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-12-11 14:31:17 -07:00
Niels de Vos f1d448cc46 csi: update csi-addons to v0.11.0
The csi-addons v0.11.0 release is now available.

See-also: https://github.com/csi-addons/kubernetes-csi-addons/releases/tag/v0.11.0
Signed-off-by: Niels de Vos <ndevos@ibm.com>
2024-11-26 10:38:54 +01:00
Madhu Rajanna e599ef67ef csi: update to latest cephcsi release
cephcsi fixed a bug related to data loss
and its fixed in 3.12.3 release, This commit
updates the cephcsi to 3.12.3 release.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-11-25 19:02:25 +01:00
Travis Nielsen 2ff429e479 csi: remove version check for k8s and cephcsi
The version checks for the csi driver are removed now
since they are all obsolete. The K8s version and cephcsi
versions are no longer checked. Anyway, the move to the
csi operator would take ownership of version checks
needed in the future, so for now we simplify rook
deployment of the csi driver.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-10-30 14:03:51 -06:00
Blaine Gardner 5539eedd1b multus: finish deprecating holder pods
Finish the process of deprecating holder pods by removing Rook's ability
to deploy them. The intent of this change is to make the most
superficial changes possible to accomplish this. There are still
remnants of code in Rook (particularly the CSI controller) that helped
configure or deploy holder pods. Due to the risk of breaking some
features, cleanup work of hose remnants will be deferred for future
work.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-10-23 16:29:02 -06:00
Madhu Rajanna 55441ee408 csi: fix typo in image version
add missing `v` in the cephcsi
image version

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-10-21 10:53:55 +02:00
Travis Nielsen 810de394e7 helm: add enforce host network setting
The ROOK_ENFORCE_HOST_NETWORK option was implemented recently
and now we add the helm setting to expose this new setting
in the rook chart.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-10-02 15:14:46 -06:00
Michael Adam ab8fd90aa6 core: add ROOK_REVISION_HISTORY_LIMIT operator setting
This adds an operator config setting ROOK_REVISION_HISTORY_LIMIT
defaulting to kubernetes'value for RevisionHistoryLimit.

If configured, the provided value will be used as RevisionHistoryLimit

for all Deployments rook creates.

Fixes: #12722

Signed-off-by: Michael Adam <obnox@samba.org>
2024-10-02 19:40:37 +02:00
Praveen M afad40e404 csi: update csi-addons to v0.10.0
The csi-addons v0.10.0 release is now available.
Ref: https://github.com/csi-addons/kubernetes-csi-addons/releases/tag/v0.10.0

Signed-off-by: Praveen M <m.praveen@ibm.com>
2024-09-18 12:19:46 +05:30
Madhu Rajanna d041be4bcf csi: update to new cephcsi release
we have 3.12.2 as the new cephcsi release
updating the rook to use the same.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-09-06 16:17:24 +02:00
Madhu Rajanna 05d579b607 csi: update csi-addons to v0.9.1
updating csi-addons to latest
v0.9.1 release.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-09-03 12:52:00 +02:00
Travis Nielsen 3d747f399e Merge pull request #14598 from jrcichra/configurable-metrics-bind-address
core: add configuration option for metrics bindAddress
2024-08-20 12:13:43 -06:00
Justin Cichra 74a79b24b3 core: add configuration option for metrics bindAddress
Alerting on controller-runtime's workqueue_depth can be useful for
debugging controllers. Also having a prometheus target for a pod gives
another data point that the system is working as expected. It is useful
for uptime alerts.

Make the bind address configurable via the configmap while still retaining the default
behavior that it is disabled.

Resolves: #14538

Signed-off-by: Justin Cichra <jcichra@cloudflare.com>
2024-08-20 13:38:38 -04:00
Zuhair AlSader 6714b86d3b manifest: add registry name to docker images
Signed-off-by: Zuhair AlSader <zuhair@devzero.io>
2024-08-20 13:35:08 -04:00
Praveen M a1ddf4535d csi: update csi sidecars' image version
Below csi sidecars are updated with latest available versions

csi-resizer: v1.11.1
csi-provisioner: v5.0.1
csi-attacher: v4.6.1
csi-snapshotter: v8.0.1
csi-node-driver-registrar: v2.11.1

Signed-off-by: Praveen M <m.praveen@ibm.com>
2024-08-20 22:08:19 +05:30
Madhu Rajanna 7c7e8a2b32 csi: update cephcsi to 3.12.0
updating cephcsi image to 3.12.0
release.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-08-16 10:47:44 +02:00