Commit Graph
761 Commits
Author SHA1 Message Date
Blaine Gardner 472c4f3f92 Merge pull request #18010 from jhoblitt/ss-17970
object: return an error when the multisite zone is not found
2026-07-30 13:50:40 -06:00
parth-gr d6a0e9fd87 rgw: force delete the rgw accounts by looking at the force annotation
if the account cr has a force delete annotation, forcefully
remove the account, even if it contatins data in it, using the
purge data flag

Signed-off-by: parth-gr <partharora1010@gmail.com>
2026-07-29 13:03:06 +05:30
Anas Khan 0bf6f84ff5 object: return an error when the multisite zone is not found
retrieveMultisiteZone is meant to gate the object-store reconcile on the
backing Ceph zone existing: it runs "radosgw-admin zone get" and, when
that fails, returns a non-nil error so the caller requeues. That gate is
dead code. The ENOENT check declares an inner err from exec.ExtractExitCode
that shadows the outer command error, and ExtractExitCode returns a nil
error for the ordinary exit failures radosgw-admin produces. Both the
ENOENT branch and the else branch then wrap that shadowed nil, and
errors.Wrapf(nil, ...) is nil, so the function returns
(waitForRequeueIfObjectStoreNotReady, nil). The caller only propagates the
requeue when the error is non-nil, so the requeue is dropped and reconcile
runs on.

The result is that a failed "zone get" no longer backs off. Reconcile
proceeds to stand up the object store anyway -- the RGW service, the
admin-ops endpoint, the deployment, and the pools radosgw scaffolds as it
comes up -- for a multisite store whose backing zone does not exist. This
is not the "normal multisite bootstrap" transient the original wording
suggested. getMultisiteResourceNames runs immediately before this and
already requeues until the CephObjectZone CR reports Ready, and the zone
controller marks it Ready only after it has created the Ceph zone, so a
healthy bootstrap never reaches this gate with a missing zone. That
CR-Ready gate, not this one, is what actually blocks bootstrap.

Where the dead gate does bite is the cases the CR status cannot cover:

- the Ceph zone deleted or renamed out of band while the CR still reads Ready
- a zone controller that reports Ready without leaving a usable zone behind
- any non-ENOENT "zone get" failure, e.g. a permission or connectivity
  error, which the else branch swallows the same way

The check was correct when fc579f4520 introduced it in 2020 with
exec.ExitStatus, which returns (code, ok) and leaves err unshadowed.
bd58790c31 ("ceph: proxy ceph commands when multus is configured", 2021)
swapped it to exec.ExtractExitCode as an unrelated drive-by, inverting the
contract and killing the gate. The sibling realm, zonegroup, and zone
controllers were left untouched and still use exec.ExitStatus today.

Restore exec.ExitStatus so the outer error is no longer shadowed, both
branches wrap the real command error, and the caller requeues until the
zone exists -- matching the sibling controllers.

Signed-off-by: Anas Khan <83116240+anxkhn@users.noreply.github.com>
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2026-07-21 12:40:25 -07:00
Anas Khan 7f2a68fa91 object: return an error when reconciled rgw user has no keys
In createOrUpdateCephUser, when the desired user carries no explicit
keys the reconciler falls back to the live RGW user's keys. If that live
user also has zero keys the code intends to fail, but it built the error
with errors.Wrapf(err, ...) at a point where err is already nil (the
prior SetUserQuota error was handled and returned just above).
errors.Wrapf(nil, ...) returns nil, so the failure was swallowed and
createOrUpdateCephUser returned success on a user the operator itself
flagged as broken.

The reconcile then continued to generateCephUserSecret, which indexes
userConfig.Keys[0] to populate the Kubernetes secret and panicked on the
empty key slice. The reconciler's deferred RecoverAndLogException caught
and logged that panic, so the reconcile was abandoned before it reached
the Ready status update; and because the recovered Reconcile returns a
zero Result with a nil error, the request was not requeued either. The
user was left neither marked Ready nor retried.

Construct the error with errors.Errorf so the intended failure is
surfaced instead of being swallowed. Add a regression test that returns
a keyless live user and asserts a non-nil "no keys set" error.

Signed-off-by: Anas Khan <83116240+anxkhn@users.noreply.github.com>
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2026-07-20 17:41:21 -07:00
Travis Nielsen 68853a50be Merge pull request #17962 from parth-gr/rgw-account-deletion
rgw: rgw account deletion should remove account from ceph
2026-07-20 14:11:52 -06:00
Blaine Gardner 75e64b00be Merge pull request #17940 from subhamkrai/add-caps-rgw-admin-user
object: option to update rgw caps with account
2026-07-15 14:12:24 -06:00
Michael Adam c90913051b rgw: fix a comment typo
This fixes a comment typo caught bt the codespell CI check.

Signed-off-by: Michael Adam <obnox@samba.org>
2026-07-15 18:25:53 +02:00
subhamkrai 392204c1f8 object: option to update rgw caps with account
this commit add support for updating rgw caps with
`user-info-without-key` and `accounts` to cephobjectstoreuser crd
Adding the check for min ceph version from which these caps
are available.

Co-Authoured-by:  Jiffin Tony Thottan <thottanjiffin@gmail.com>
Signed-off-by: subhamkrai <srai@redhat.com>
2026-07-15 16:45:49 +05:30
parth-gr cca7020f0b rgw: rgw account deletion should remove account from ceph
currently there was a bug in the code where it didnt removed
the account from the ceph cluster during intial intialize

Signed-off-by: parth-gr <partharora1010@gmail.com>
2026-07-14 16:01:09 +05:30
Joshua Hoblitt c0eb360041 docs: fix typos and grammar in code comments
Fix duplicate words, incorrect articles (a/an), it's/its, and other small
grammar mistakes in Go comments and user-facing messages across pkg/, cmd/,
and tests/.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2026-07-01 08:34:11 -07:00
Anas Khan 67bf4baab8 object: use passed context for S3 v2 API calls
The AWS SDK v1 to v2 migration in #17468 left the S3Agent wrapper methods
calling the SDK with context.TODO(), so S3 operations could not be cancelled
when the controller context is cancelled. Add a leading context.Context
parameter to CreateBucket, PutObjectInBucket, GetObjectInBucket,
DeleteObjectInBucket, PutBucketPolicy, and GetBucketPolicy, forward it to the
underlying client, and pass clusterInfo.Context from the bucket provisioner.

Resolves #17526

Signed-off-by: Anas Khan <83116240+anxkhn@users.noreply.github.com>
2026-07-01 13:15:40 +05:30
Joshua Hoblitt e5c6d75a73 core: narrow bare //nolint directives to specific linters
The //nolint directives at these sites omit the linter name, so each
suppresses every linter on its line rather than the one check it needs.
That hides any unrelated errcheck/gosec/govet finding later introduced
on the same line. Name the specific linter for each:

- staticcheck for the two operator sites: SA4004 (the intentional
  single-iteration loop in the OSD PVC host lookup) and SA1019 (the
  deliberate read of the deprecated S3.Enabled field in the RGW
  API-enable builder).
- errcheck for the rbd-mirror deferred token-file cleanup and the
  test-framework logging helpers (WriteString / writeHeader).

No behavior change.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2026-06-29 16:32:59 -07:00
Joshua Hoblitt 49612461a4 docs: fix function comments to match their declaration names
Several godoc comments led with a stale or incorrect identifier, left
over from renames, exported/unexported changes, copy-paste between
sibling declarations, or plain typos. As a result the documented name no
longer matched the function, method, type, or var it describes. Correct
each leading word to the name of the declaration it documents.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2026-06-26 12:52:39 -07:00
pengqima 240c431f42 docs: fix function comment to match actual function name
Signed-off-by: pengqima <pengqima@outlook.com>
2026-06-26 23:43:22 +08:00
Joshua Hoblitt 573e2f81e7 object: generate URL-safe realm access keys
The realm system user's access and secret keys are generated by
GeneratePassword() and then wrapped in base64. GeneratePassword()
deliberately excludes '/' from the access key character set, but the
base64.StdEncoding wrap reintroduces it: its alphabet contains '/' and
'+', and the 14-character input always produces trailing '='. The
encoded string is the literal key used in S3 requests.

An access key containing '/' breaks AWS SigV4 credential scope parsing
("<access-key>/<date>/<region>/<service>/aws4_request" is split on
'/'), so "radosgw-admin realm pull" against the realm endpoint fails
permanently with "request failed: (22) Invalid argument" (HTTP 400),
and a CephObjectRealm pulling that realm can never reconcile.

This is the dominant cause of the "deploy second cluster rook"
failures in the rgw-multisite-testing canary job: every sampled failure
had a generated access key containing '/' and looped on EINVAL for the
whole 600s wait window, while runs with slash-free keys pulled the
realm successfully.

Encode both keys with base64.RawURLEncoding instead, whose alphabet
(A-Za-z0-9-_, unpadded) is safe in credential scopes, URLs, and shell
arguments. Only newly created realm secrets are affected; existing
secrets are not modified by the reconciler.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2026-06-10 15:38:58 -07:00
Joshua Hoblitt d6d0fd8d89 Merge pull request #17648 from jhoblitt/maint-rm-dead-object-funcs
object: remove dead functions and ObjectBuckets sort type
2026-06-03 12:07:15 -07:00
Joshua Hoblitt 1c16afdbc9 Merge pull request #17647 from jhoblitt/maint-rm-dead-object-policy-funcs
object: remove dead EjectPrincipals methods and duplicate AllowedActi…
2026-06-03 11:06:18 -07:00
Joshua HoblittandClaude Sonnet 4.6 ae481f0f43 object: remove dead functions and ObjectBuckets sort type
Remove the following unreferenced symbols:
- (*S3Agent).CreateBucketNoInfoLogging
- (*S3Agent).DeleteBucket (wrapper; callers use the SDK client directly)
- GetBucketsStats
- ObjectBuckets type and its Len/Less/Swap sort.Interface methods

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2026-06-03 10:27:40 -07:00
Joshua HoblittandClaude Sonnet 4.6 df30bf66e8 object: remove dead EjectPrincipals methods and duplicate AllowedActions entry
Remove (*BucketPolicy).EjectPrincipals and (*PolicyStatement).EjectPrincipals,
which had no callers outside policy.go. Also drop the duplicate PutBucketVersioning
entry in AllowedActions.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2026-06-03 09:39:12 -07:00
Artem Muterko 321911b96c object: clobber bucket policy on modify instead of merging
ModifyBucketPolicy merged the caller's statement into the policy fetched
from the bucket, matching by SID. Besides a missing match flag that
appended a duplicate when a SID matched, this preserved any pre-existing
statements on the bucket and reapplied them on every reconcile.

Overwrite the policy with the provided statements instead, so a managed
bucket always ends up with exactly the intended policy and cannot retain
unexpected statements.

Signed-off-by: Artem Muterko <artem@sopho.tech>
2026-06-03 11:04:17 +02:00
Oded Viner 4b5fc9d16a object: add logger for AWS SDK v2 debug signing output
Wire a rookLogger adapter implementing smithy's Logger
interface so that aws.LogSigning output is emitted through
rook's capnslog when debug mode is enabled.

Signed-off-by: Oded Viner <oviner@redhat.com>
2026-05-27 20:08:14 +03:00
Blaine Gardner 469b04e1a9 Merge pull request #17572 from OdedViner/remove_asw_v1
object: remove AWS SDK v1 dependency
2026-05-27 10:30:31 -06:00
Travis Nielsen 9774d2de75 Merge pull request #17570 from subhamkrai/add-tls1.3-ciphers
object: add TLS 1.3 cipher suite support for RGW beast frontend
2026-05-27 09:51:33 -06:00
Oded Viner 254965fff1 object: remove AWS SDK v1 dependency
Remove the AWS SDK v1 (github.com/aws/aws-sdk-go)
dependency entirely. All S3 operations now use AWS SDK v2
exclusively.

- Remove the v1 Client field from S3Agent struct and
  rename ClientV2 to Client
- Remove v1 session/client initialization from NewS3Agent
- Update all call sites referencing ClientV2
- Convert integration tests to use v2 API calling
  conventions (context parameter) and smithy error handling
- Remove aws-sdk-go v1.55.8 from go.mod

Signed-off-by: Oded Viner <oviner@redhat.com>
2026-05-27 18:35:54 +03:00
Joshua Hoblitt 8dd1778655 Merge pull request #17561 from jhoblitt/maint-ref-all-containers-by-name-instead-of-index
core: reference all containers in a spec by name instead of index
2026-05-26 12:10:09 -07:00
Joshua Hoblitt d059c351fc core: reference all containers in a spec by name instead of index
This changeset excludes converting _test.go code as there may be a
legitimate reasons (E.g. convenience) for unit test to be sensitive to
ordering.

Related to:
- https://github.com/rook/rook/issues/15291
- https://github.com/rook/rook/pull/16969

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2026-05-26 10:09:23 -07:00
subhamkrai b70a0c9257 object: add TLS 1.3 cipher suite support for RGW beast frontend
adding new tls ssl_ciphersuites supporting tls 1.3 and the existing,
ssl_cipher supports tls 1.2 and below. Adding, the docs and unit-test
changs as well.

Signed-off-by: subhamkrai <srai@redhat.com>
2026-05-26 20:50:21 +05:30
Blaine Gardner 645aa741eb Merge pull request #17530 from rook/maint-rm-unused-consts-opus-4.7
core: rm unused consts
2026-05-20 09:01:05 -06:00
Travis Nielsen 5f398420fc Merge pull request #17527 from OdedViner/aws_sdk_2_topic
object: migrate sns topic provisioner to aws sdk v2
2026-05-20 07:54:56 -06:00
Oded Viner 81a2cd8833 object: migrate sns topic provisioner to aws sdk v2
migrate the sns-based topic provisioner from aws-sdk-go (v1)
to aws-sdk-go-v2. replace v1 session, credentials, and
request handlers with v2 aws.Config, static credentials
provider, and endpoint resolver. convert the custom ceph rgw
v2 signer hack from a v1 handler swap to a smithy finalize
middleware. update sns api calls to use context-first
signatures, map[string]string attributes, and typed
snstypes.NotFoundException error handling via errors.As.
update unit tests accordingly.

Signed-off-by: Oded Viner <oviner@redhat.com>
2026-05-20 13:02:00 +03:00
Sunnatillo 0bd299aa60 build: fix gosec and go vet lint errors for Go 1.26
Signed-off-by: Sunnatillo <sunnat.samadov@est.tech>
2026-05-15 21:45:06 +03:00
Joshua Hoblitt 9eec9c730e core: rm unused consts
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2026-05-14 09:34:52 -07:00
Oded Viner f5df592106 object: migrate notification package to aws sdk v2
migrate the notification provisioner and s3ext packages from
aws sdk v1 to v2. the custom DeleteBucketNotification call is
rewritten to manually build and sign the HTTP request using the
v2 v4 signer, since this ceph-specific API has no sdk equivalent.

also fix t.Skipped() -> t.Skip() in notification integration test.

Signed-off-by: Oded Viner <oviner@redhat.com>
2026-05-13 19:06:52 +03:00
subhamkrai 01ef98c1e3 rgw: add option for tls and cipher in objectstore
this commit add option in the ceph objecstore CR
to configure TLS profile and TLS ciphersuite for
rgw beast.

Signed-off-by: subhamkrai <srai@redhat.com>
2026-05-06 21:02:30 +05:30
Oded Viner 5ba3e1a2c0 object: migrate bucket provisioner to aws sdk v2
migrate bucket provisioner from aws sdk v1 to v2.

replace awserr.Error type assertions with smithy.APIError
using errors.As for v2-style error handling.

switch setBucketPolicy and setBucketLifecycle to use
the v2 s3 client (ClientV2) directly with context.

replace v1 s3 types (BucketLifecycleConfiguration,
GetBucketLifecycleConfigurationOutput) with v2 equivalents
from s3types and s3v2 packages.

add cmpopts.IgnoreUnexported to cmp.Diff calls to handle
unexported noSmithyDocumentSerde fields in v2 sdk types.

add nil guard on lifecycle output before accessing rules
to prevent nil dereference when get returns an error.

depends on #17414

Signed-off-by: Oded Viner <oviner@redhat.com>
2026-04-29 16:34:22 +03:00
Joshua Hoblitt 03789475f9 Merge pull request #17414 from OdedViner/policy_aws_sdk_v2
object: migrate bucket policy methods to aws sdk v2
2026-04-28 07:45:36 -04:00
Oded Viner 88e0047d9b object: migrate bucket policy methods to aws sdk v2
migrate PutBucketPolicy and GetBucketPolicy to use aws sdk v2
client.

Signed-off-by: Oded Viner <oviner@redhat.com>
2026-04-23 18:54:48 +03:00
Oded Viner 2cb714dabd object: migrate s3agent object methods to aws sdk v2
migrate PutObjectInBucket, GetObjectInBucket, and
DeleteObjectInBucket to use aws sdk v2 client.
replace v1 awserr error handling in DeleteObjectInBucket
with v2 typed errors (errors.As).
remove unused v1 awserr import.

Signed-off-by: Oded Viner <oviner@redhat.com>
2026-04-23 17:40:15 +03:00
Blaine Gardner bf3adcb464 Merge pull request #17319 from OdedViner/aws_v2_upgrade_delete_bucket
object: add support for aws sdk v2 in s3agent DeleteBucket
2026-04-07 11:52:32 -06:00
Oded Viner f5b73f12c6 object: add support for aws sdk v2 in s3agent DeleteBucket
update createbucket to use sdk v2 while keeping
all other methods on sdk v1.

Signed-off-by: Oded Viner <oviner@redhat.com>
2026-04-07 18:35:41 +03:00
Santosh c6836c474a rgw: support SSE-S3 with vault agent
Support using SSE-S3 encryption with RGW using vault Agent auth.
RGW sends requests to the agent instead of directly to Vault, and the agent transparently injects the authentication token. This eliminates using and managing a static token

Signed-off-by: Santosh <sapillai@redhat.com>
2026-04-07 12:18:29 +05:30
Travis Nielsen cc626020ba Merge pull request #17250 from sp98/implement-cosuser-accounts
rgw: add accountRef to CephObjectStoreUser CR
2026-04-02 15:56:30 -06:00
Joshua Hoblitt 0139637e34 test: add integration tests for CephObjectStoreUser capabilities
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2026-04-02 09:44:28 -07:00
Travis Nielsen e4b68e0a19 Merge pull request #17149 from hjk068/user-caps
object: call generateUserCaps after AdminOpsClient calls
2026-04-02 09:14:34 -06:00
hjk068 b113e37dae object: call generateUserCaps after AdminOpsClient calls
This prevents overwriting the user-specified capabilities
and correctly copies the Capabilities into UserCapabilities
after the AdminOpsClient calls.

Signed-off-by: hjk068 <hello.hyunjin@gmail.com>
2026-04-01 19:54:39 -04:00
Blaine Gardner 9a89a96cea Merge pull request #16875 from OdedViner/aws_v2_upgrade
object: add support for aws sdk v2 in s3agent createbucket
2026-04-01 11:42:50 -06:00
Tarun Gupta Akirala 9803964d03 cosi: update default sidecar image version
Encountered this bug in current image kubernetes-sigs/container-object-storage-interface#173
which is fixed in recent release via kubernetes-sigs/container-object-storage-interface#197

Signed-off-by: Tarun Gupta Akirala <tarun.akirala@nutanix.com>
2026-03-31 14:23:20 -07:00
Oded Viner 86c920fa79 object: add support for aws sdk v2 in s3agent createbucket
initialize both aws sdk v1 and v2 clients in s3agent.
update createbucket to use sdk v2 while keeping all
other methods on sdk v1.

Signed-off-by: Oded Viner <oviner@redhat.com>
2026-03-31 17:41:51 +03:00
Santosh 3798b00b39 rgw: add accountRef to CephObjectStoreUser CR
Adds AccountRef to the CephObjectStoreUser CR. This helps associate the
user with a RGW account

Signed-off-by: Santosh <sapillai@redhat.com>
2026-03-31 12:47:51 +05:30
majiayu000 ac6ec79865 object: add labels field to CephObjectStore RGW service spec
Allow users to configure custom labels on CephObjectStore RGW services
by adding a Labels field to the RGWServiceSpec, following the existing
pattern used for Annotations. This enables use cases such as service
mesh integration and monitoring discovery that require specific labels
on Kubernetes services.

Fixes: #17235
Signed-off-by: majiayu000 <1835304752@qq.com>
2026-03-28 17:46:28 +08:00