Commit Graph
113 Commits
Author SHA1 Message Date
Anas Khan 7f2a68fa91 object: return an error when reconciled rgw user has no keys
In createOrUpdateCephUser, when the desired user carries no explicit
keys the reconciler falls back to the live RGW user's keys. If that live
user also has zero keys the code intends to fail, but it built the error
with errors.Wrapf(err, ...) at a point where err is already nil (the
prior SetUserQuota error was handled and returned just above).
errors.Wrapf(nil, ...) returns nil, so the failure was swallowed and
createOrUpdateCephUser returned success on a user the operator itself
flagged as broken.

The reconcile then continued to generateCephUserSecret, which indexes
userConfig.Keys[0] to populate the Kubernetes secret and panicked on the
empty key slice. The reconciler's deferred RecoverAndLogException caught
and logged that panic, so the reconcile was abandoned before it reached
the Ready status update; and because the recovered Reconcile returns a
zero Result with a nil error, the request was not requeued either. The
user was left neither marked Ready nor retried.

Construct the error with errors.Errorf so the intended failure is
surfaced instead of being swallowed. Add a regression test that returns
a keyless live user and asserts a non-nil "no keys set" error.

Signed-off-by: Anas Khan <83116240+anxkhn@users.noreply.github.com>
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2026-07-20 17:41:21 -07:00
subhamkrai 392204c1f8 object: option to update rgw caps with account
this commit add support for updating rgw caps with
`user-info-without-key` and `accounts` to cephobjectstoreuser crd
Adding the check for min ceph version from which these caps
are available.

Co-Authoured-by:  Jiffin Tony Thottan <thottanjiffin@gmail.com>
Signed-off-by: subhamkrai <srai@redhat.com>
2026-07-15 16:45:49 +05:30
Travis Nielsen cc626020ba Merge pull request #17250 from sp98/implement-cosuser-accounts
rgw: add accountRef to CephObjectStoreUser CR
2026-04-02 15:56:30 -06:00
Joshua Hoblitt 0139637e34 test: add integration tests for CephObjectStoreUser capabilities
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2026-04-02 09:44:28 -07:00
Travis Nielsen e4b68e0a19 Merge pull request #17149 from hjk068/user-caps
object: call generateUserCaps after AdminOpsClient calls
2026-04-02 09:14:34 -06:00
hjk068 b113e37dae object: call generateUserCaps after AdminOpsClient calls
This prevents overwriting the user-specified capabilities
and correctly copies the Capabilities into UserCapabilities
after the AdminOpsClient calls.

Signed-off-by: hjk068 <hello.hyunjin@gmail.com>
2026-04-01 19:54:39 -04:00
Santosh 3798b00b39 rgw: add accountRef to CephObjectStoreUser CR
Adds AccountRef to the CephObjectStoreUser CR. This helps associate the
user with a RGW account

Signed-off-by: Santosh <sapillai@redhat.com>
2026-03-31 12:47:51 +05:30
Santosh c4ec7faee5 rgw: controller for account management
PR only focuses on account creation, deletion and update.

Signed-off-by: Santosh <sapillai@redhat.com>
2026-03-13 11:21:46 +05:30
Joshua Hoblitt 3ef0c90ef8 object: add ObjectStoreUserSpec.OpMask field
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2026-02-10 15:10:28 -07:00
subhamkrai 08344f39f6 build: update deprecated api GetEventRecorderFor
with controller runtime latest version vO.23.0, golangci lint
is complaining about deprecated api deprecated.
This commit updates the api and adds the requried rbacs

Signed-off-by: subhamkrai <srai@redhat.com>
2026-02-09 21:48:02 +05:30
Travis Nielsen 023608e6fd core: enhance logging with namespaced names
For all of the controllers besides the cluster controller,
the logging now includes the namespaced name of the resource
that is being reconciled. This will help with log troubleshooting
to help analyze logs consistently for the resource being
reconciled.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-12-04 12:00:42 -07:00
Travis Nielsen ac1fa3a4c3 core: shorten the logger names
The logger names are seen on each line of logging. As
long as they are unique, they really don't need to be
long and descriptive, so let's make them a bit more
concise, and independent from controller names.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-11-21 13:12:56 -07:00
cuiweixie 20b3b9deef operator: refactor to use reflect.TypeFor
Signed-off-by: cuiweixie <cuiweixie@gmail.com>
2025-08-28 23:02:19 +08:00
Joshua Hoblitt 1163133aec object: simplify CephObjectStoreUser deletion logic
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-08-01 12:41:10 -07:00
Oded Viner cf13deee6f core: log panics in controller reconcile functions
add RecoverAndLogException() helper to log panics with stack trace.
added defer call in all rook controller Reconcile() methods for
better error visibility in operator logs

Signed-off-by: Oded Viner <oviner@redhat.com>
2025-07-29 13:20:38 +03:00
Oded Viner 8249a28145 object: allow deletion of CephObjectStoreUser even if secret is missing
skip key generation during reconcile if CephObjectStoreUser is
being deleted to allow cleanup when referenced secret is missing

Signed-off-by: Oded Viner <oviner@redhat.com>
2025-06-22 09:14:50 +03:00
Joshua Hoblitt f1fad531eb object: change CephObjectStore "foo" found log level to debug
When multiple `CephObjectStoreUser` CRs are present, the operator logs a
high volume of `CephObjectStore "foo" found` messages during reconcile.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-05-08 09:28:19 -07:00
Travis Nielsen f7fb1bc0f2 core: skip reconcile when adding the finalizers
When finalizers are added to the CRs, a follow-up reconcile
will be triggered due to the increased generation on the CR.
Therefore, abort the initial reconcile when adding the finalizer,
and allow the follow-up reconcile to complete the configuration.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-04-08 13:42:58 -06:00
Joshua Hoblitt 9f1ed201db core: typed watch handlers and predicates
All existing controller runtime watches are converted to use "typed"
handlers and predicates instead of operating on `client.Object`.  The
intent is to be bug for bug equivalent with the existing logic while
replacing run time type assertions and switch statements with compile
time type constraints and type casts. In several cases, functions using
assertions were split up such that each function only handles a single
Kind at a time. It is hoped that this will improve readability and
maintainability while facilitating future refactoring such as migrating
some watches to using IndexFields.

Of particular note is that the massive switch statement in
`WatchControllerPredicate()`  from
`pkg/operator/ceph/controller/predicate.go` has been replaced with
generics, reflection, and splitting the obc logic into its own predicate
function. There are still many helper functions operating on
`client.Object`. These were not updated unless required by the compiler
in order to limit the size of this change. The type safety of these
funcs should be improved as followup work.

 It is strongly suggested that going forward, handlers and predicates
 only handle a single Kind (generic or not) and that switches / type
 assertions are heavily discouraged or forbidden. This PR removed all
 but a single switch statement in a predicate, which should be addressed
 in future work.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-04-04 09:40:56 -07:00
Joshua Hoblitt 6b2c357871 object: add CephObjectStoreUser.spec.keys
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-04-03 09:09:01 -07:00
Joshua Hoblitt 3cb343f62a core: run gofumpt on all files
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-03-26 10:41:48 -07:00
Joshua Hoblitt 01bbcf7857 object: all CephObjectStoreUser reconcile errors set .status.phase
objectuser.reconcile() had a number of error triggered return statements
which do not update the CR's status to reflect a reconcile failure.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-03-17 09:56:54 -07:00
Joshua Hoblitt 37b7930e13 object: rm ReconcileObjectStoreUser.userConfig field
This field held state for a single reconciliation request, which
should not have been retrained / reused across multiple, possibly concurrent,
reconciliations.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-02-07 14:37:14 -07:00
df511fb58f ci: update golangci-lint to the latest version (v1.62)
The ci was using a pretty old version og golangci-lint.
This updates to the latest version.

Additionally, it  silences some
gosec integer conversion overflow false positves
and fixes some real errors of this category
 and string format errors found by golangci-lint, while at it.

Co-authored-by: Blaine Gardner <b.blaine.gardner@gmail.com>
Co-authored-by: Travis Nielsen <tnielsen@redhat.com>
Signed-off-by: Michael Adam <obnox@samba.org>
2024-12-14 14:47:30 +01:00
Blaine Gardner fc08e87d44 Revert "object: create cosi user for each object store"
This reverts commit a941b3c33f.

Stop creating the 'cosi' user in the CephObjectStore reconcile. This
step often fails for some amount of time during initial object store
creation, causing frequent user concern. It has also been the source of
some reported failures that would otherwise be non-breaking for certain
users.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-11-21 16:03:32 -07:00
ee8bcad49d rgw: add support for keystone auth + swift/s3
For the specification see:
<https://github.com/rook/rook/blob/master/design/ceph/object/swift-and-keystone-integration.md>

* extend the API object specs for swift and keystone integration

* adapt rgw to the new go-ceph version

  - The parameter lists of the API call have changes, as parameters
    ignored by the RGW Admin Ops API are no longer serialized, therefore
    the mock has to be adapted.

  - There is now validation for the user keys that are passed to the
    User get API, therefore things failed when we had empty keys in our
    User proxy object.

* expand the reconcile loop for the swift and keystone integration

* fix minor mistakes in design document

* add env var to pass extra args to minikube

  Minikube decides CPU cores and memory automatically based on the
  available resources on the machine which may be insufficient to
  run rook. This commit adds an environment variable to add arbitrary
  arguments to the minikube command, so both can be specified if
  desired.

* integration tests for swift and keystone

  The new integration of swift or s3 and keystone support by rook
  does not have any integration tests yet.

  This commit introduces integration tests for swift and keystone. The
  tests are done against a minimal keystone setup (keystone container
  image from Yaook-project (https://yaook.cloud), sqlite as database
  backend, cert-manager and trust-manager for test certificate setup).

  To prevent hardcoded credentials, passwords are generated
  by the tests. The integration tests use the openstack client
  (keystone- and swift-functionality) (https://docs.openstack.org/
  python-openstackclient/ latest/). This was a concious design decision
  to use client tooling as close as possible to the end user instead of
  using other go-libraries (such as gophercloud).

* add documentation on swift and keystone

  Currently there is no documentation on the use of Swift to access
  an object store as well as the use of OpenStack keystone for
  authentication.

  This commit adds documentation on the use of Swift and OpenStack
  keystone, as well as CRD-related documentation and an example setup.

* add integration tests for S3 via keystone

  This commit introduces integration tests for s3 and keystone. The
  tests are run against the same minimal keystone setup that the tests
  for swift and keystone use.

  The integration tests use the aws s3 client to use client tooling as
  close as possible to the end user instead of using other go-libraries.

Co-authored-by: Jan Klippel <jan.klippel@uhurutec.com>
Co-authored-by: Silvio Ankermann <silvio.ankermann@cloudandheat.com>
Signed-off-by: Sebastian Riese <sebastian.riese@cloudandheat.com>
Signed-off-by: Jan Klippel <jan.klippel@uhurutec.com>
Signed-off-by: Silvio Ankermann <silvio.ankermann@cloudandheat.com>
2024-08-08 14:26:21 +02:00
Blaine Gardner a2b0b6449c object: add hosting.advertiseEndpoint config
Add CephObjectStore spec.hosting.advertiseEndpoint configuration. This
provides a clear documented default for which endpoint Rook "advertises"
to dependent resources like CephObjectStores, OBCs, and COSI
Buckets/Accesses and allows users to override the default behavior if
desired.

The current default is to round-robin an endpoint from
spec.hosting.dnsNames, which has proven to be troublesome for some
users' object store configurations. This change provides much-needed
disambiguation for users.

This may be a breaking change for some existing spec.hosting.dnsNames
users. This is unexpected but is documented.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-07-22 14:43:51 -06:00
subhamkrai d429ed8be4 build: update controller runtime to v0.18.4
this commit update cntrl runtime to v0.18.4 and other related deps/

Signed-off-by: subhamkrai <srai@redhat.com>
2024-07-05 09:05:12 +05:30
Blaine Gardner e74333ddcd Merge pull request #12633 from thotz/cosi-user-creation
object: create cosi user for each object store
2023-10-04 10:05:36 -06:00
Jiffin Tony Thottan a941b3c33f object: create cosi user for each object store
Create each cosi user for each object store and secret which holds
credentials.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2023-09-19 13:48:58 +05:30
guoguangwu 235ac293ff core: import packages only once
Signed-off-by: guoguangwu <guoguangwu@magic-shield.com>
2023-09-16 13:40:17 +08:00
travisn 2b1cc4c7b8 object: allow creating an object user in different namespace
The object user was previously required to be created in the
same namespace as the object store and the cluster. Now,
the object user can be reconciled even in a different namespace
from the cluster and object store. The namespace would be specified
in the object user CR.

Signed-off-by: travisn <tnielsen@redhat.com>
2023-08-25 11:54:57 -06:00
Travis Nielsen 2e7f9045ab Merge pull request #12460 from pgoron/admin-caps-spelling
object: align spelling of user admin capabilities with ceph
2023-07-18 13:23:15 -06:00
Peter Goron 40eed236cf object: align spelling of user admin capabilities with ceph
users & buckets admin capabilities aren't spelled the same
way between rook crd (singular) and ceph (plural). It's a bit
misleading when comparing ceph admin cap and rook users.

Signed-off-by: Peter Goron <peter.goron@gmail.com>
2023-07-01 19:05:26 +02:00
travisn 557a3e06cc core: api updates for controller runtime v0.15
For the controller runtime v0.15 there are some breaking
changes to the api that need to be updated.

Signed-off-by: travisn <tnielsen@redhat.com>
2023-06-22 10:33:28 -06:00
Travis Nielsen d7dcf58f7c Merge pull request #12406 from polyedre/confusing-message
Fix confusing successful message when reconciling CephObjectStoreUser
2023-06-20 13:12:55 -06:00
Lucas Henry 87bc3dfcdc operator: remove confusing successful message when reconciling CephObjectStoreUser
When creating a CephObjectStoreUser with a value spec.store that refers to an
unexisting CephObjectStore, after the reconciliation loop the
CephObjectStoreUser is in the ReconcileFailed state. However, a
ReconcileSucceeded event is created with this message:

"successfully configured CephObjectStoreUser"

The success message results of the return value for the error which is currently
`nil`. Let's replace it with the error message.

Signed-off-by: Lucas Henry <polyedre@disroot.org>
2023-06-20 11:02:04 +02:00
Jiffin Tony Thottan 6ea24cb11b object: add ssl ref in cephobjectstore user secret
There is no reference for ssl in cephobjectstore Secret, so users won't
have much idea why tls secret need to used. Hence give reference
object stores tls secret ref in the Secret.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2023-06-09 12:42:35 +05:30
Travis Nielsen 6417ed4047 Merge pull request #12256 from thotz/add-missing-caps-object-user
object: add missing caps for object store user
2023-05-30 16:37:18 -06:00
Jiffin Tony Thottan 1f45cfa581 object: use networkspec from clusterinfo spec while running radosgw-admin
The radosgw-admin command uses the network spec from ceph cluster spec
in object context but it is not filled properly in the object package.
But with PR 10898, network spec is available in clusterinfo which can
be used directly. Also removed cluserspec from object context.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2023-05-30 11:06:03 +05:30
Jiffin Tony Thottan ad0c000e6a object: add missing caps for object store user
Lot of new caps added to rgw users, reflecting same changes on the
object store user CRD.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2023-05-26 17:36:00 +05:30
Liang Zheng c81aa7f856 object: update os user caps
Removing user caps will be skipped as the UserCaps is empty, which will cause updating user caps to not take effect.

Signed-off-by: Liang Zheng <zhengliang0901@gmail.com>
2023-02-21 17:06:41 +08:00
parth-gr 26584fc6e5 core: update loadclusterInfo with multus check
if Multus is enabled the clusterinfo should be updated with
network as multus as to run the ceph cmds in remote
executor

Signed-off-by: parth-gr <paarora@redhat.com>
2022-09-22 14:46:51 +05:30
Jiffin Tony Thottan 6f4f10a3c5 object: add the external rgw server check properly
In object package code, external rgw server check is whether ceph cluster
is external instead of rgw. Correcting such scenarios in the code base.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2022-07-27 22:52:18 +05:30
Josh Soref 6e7b8767f3 core: fix spelling
* another
* are
* availability
* available
* bootstrap
* boundaries
* ceph
* certificate
* class
* codifies
* consuming
* corrupted
* createor
* csi
* deployments
* exceeded
* execute
* filesystem
* healthiness
* heuristics
* immediately
* insecure
* installed
* isolated
* maintained
* maximum
* minute
* monitor
* new
* nginx
* nonexistent
* not
* occurs
* omitempty
* operator
* orchestration
* persistentvolumes
* placement
* preexisting
* prometheus
* protecting
* provisioner
* purposes
* reconcile
* regex
* related
* requests
* returns
* rubbish
* running
* schedulable
* schedule
* serviceaccount
* simulating
* snapshots
* statement
* static
* tenants
* the
* unavailable
* volumeattachment
* waiting
* with
* wrapper
* zonegroup

Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>
2022-07-07 18:10:47 -04:00
Sébastien Han ed3121defd Merge pull request #9925 from leseb/multus-plugin-restart-fix
core: fix csi-cephfsplugin pod restart on non-hostnetworking env
2022-04-27 11:41:59 +02:00
Sébastien Han 583791c45c core: move clusterInfo code to the controller package
The CSI package needs to load clusterInfo, today this code is in the mon
package which makes the call of LoadClusterInfo impossible without
having a circular import.

Signed-off-by: Sébastien Han <seb@redhat.com>
2022-04-26 11:05:02 +02:00
Jiffin Tony Thottan 60da73a786 object: allocate keys for user after the creation
The access/secrets keys for the user struct need to allocate only if
ceph user creation succeeds.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2022-04-25 20:01:03 +05:30
parth-gr 2dfd64a97c core: add observedGeneration to CR status
adding observedGeneration field in the cephcluster cr
status for having better control on reconciling,
as observedGeneration field will be updated by the controller

Closes: https://github.com/rook/rook/issues/9673

Signed-off-by: parth-gr <paarora@redhat.com>
2022-03-16 19:58:35 +05:30
subhamkrai 6a9ff434d2 core: add k8s events in controller reconciler
adding k8s event in controller reconciler when
1. when reconciler starts
2. when deletion reconcile triggered.

Closes: https://github.com/rook/rook/issues/9462
Signed-off-by: subhamkrai <srai@redhat.com>
2022-03-14 18:55:26 +05:30