Because the NFS CSI driver is optional and rarely deployed, make RBAC
for this driver an optional example that is generated by the helm chart.
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
Create the ".nfs" config pool by default so that users aren't required
to create it via CephBlockPool.
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
Adds support for valid arbitrary NodeAffinity JSON input by the user while
maintaining backward compatibility with the older parsing code.
Signed-off-by: Pranshu Srivastava <rexagod@gmail.com>
This new integration test will deploy a cluster with multus enabled. It
will be comprised of two network interfaces for ceph public and cluster
communications.
For now, it only deploys a Ceph cluster up to the OSDs.
Closes: https://github.com/rook/rook/issues/9784
Signed-off-by: Sébastien Han <seb@redhat.com>
finally, admission controller will be enabled default
without any script/manual step. But it still requires cert-manager
to be installed which I believe is already installed in clusters.
**Note**
Code doesn't return error it just logs the error since
we don't want to stop reconciling if the admission controller fails.
We can work on this once the admission controller is stable.
Signed-off-by: subhamkrai <srai@redhat.com>
The default replica count for test clusters should be 1.
This was causing the rgw-multisite integration test to
fail because the PGs were attempting to use the default
replication instead of the replication of 1 expected
for test clusters.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
The CSI driver pods dont need to update the node objects for
its operations. This commit remove the unwanted access to node
object update in the RBAC of CSI pods.
Signed-off-by: Humble Chirammal <hchiramm@redhat.com>
Update upgrade and supporting docs for release of Rook v1.9.
Include pending release notes as part of this update.
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
Removed v3.4.0 as its deprecated in cephcsi
and updated the templates to point to latest
v3.6.0 release.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
In the `object-openshift.yaml` details about exposing `Routes` for RGW
service, currently it exposes both ports if they are available. This is
very difficult to manage via same route like adding termination policy
etc.
Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
Corrected RGW_ADMIN_OPS_USER_ACCESS_KEY and
RGW_ADMIN_OPS_USER_SECRET_KEY so it should be
output correctely when called script with
bash format output
Signed-off-by: parth-gr <paarora@redhat.com>
This introduces a new CRD to add the ability
to create rados namespace for a given
ceph block pool. Typically the name of the pool
is the name of the blockpool created by rook.
Closes: #7035
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
For supporting features like service account authentication for vault
KMS , a service account account need to attach with pod.
Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
Corrected CSI_RBD_NODE_SECRET name so it should be
output correctely when called script with
bash format output
Signed-off-by: parth-gr <paarora@redhat.com>
pylint was failing with used-before-assignment error
fixed it by making the variables assignmet before it was used
Also backward compatibility is removed from the ModuleNotFoundError import,
as we auto installed python3 version on ceph standalone
Signed-off-by: parth-gr <paarora@redhat.com>
The aws go lang sdk needs value for region, it is set differently in
various part of current code. With PR the value is always `us-east-1` so
that it will work RGW server without any issues.
This reverts commit 280c29f330.
Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
The prometheus rules had been previously created if the cephcluster CR
setting monitoring.enabled was set to true. The rules were not customizable
and therefore not flexible enough. Now the rules are installed by the helm
chart. To customize the rules, a post-processor can be applied to the helm
chart.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
this commit adding `Phase` in `additionalPrinterColumns` for
all the CRs.
this is how it looks now, example:
```
$ kc get cephfilesystem
NAME ACTIVEMDS AGE PHASE
myfs 1 4m57s Ready
srai@ ~
$ kc get cephblockpool
NAME PHASE
device-health-metrics Ready
replicapool Progressing
srai@ ~
$ kc get cephclient
NAME PHASE
cinder Ready
glance Ready
```
Closes: https://github.com/rook/rook/issues/9883
Signed-off-by: subhamkrai <srai@redhat.com>
In Quincy, the device_health_metrics pool is renamed to .mgr.
In the example cluster-test.yaml, we therefore update the
example to create the pool with the new name.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
adding observedGeneration field in the cephcluster cr
status for having better control on reconciling,
as observedGeneration field will be updated by the controller
Closes: https://github.com/rook/rook/issues/9673
Signed-off-by: parth-gr <paarora@redhat.com>
msgr2 allows for encryption and/or compression across the wire.
Settings for enabling the encryption and compression are now
available in the cluster CR to that ceph will be automatically
configured with these settings when desired.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
When using dry-run option with external script, out_map dictionary
doesn't contain keys ( ACCESS_KEY and SECRET_KEY ) which leads to KeyError.
This fix to avoid creating json_out incase of dry-run since we will not use
json_out for dry-run.
Signed-off-by: vavuthu <vavuthu@redhat.com>
When using dry-run option with external script, function create_rgw_admin_ops_user
is not returning expected values which leads to TypeError. This fix is to append
values to out_map dictionary only in case of actual run.
Signed-off-by: vavuthu <vavuthu@redhat.com>
To ensure the mgr is not the single point of failure, the mgr
daemon count is now set to 2 by default in the cluster examples.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
Currently, the admin/user can configure the ceph.conf
for daemon pods using https://rook.io/docs/rook/v1.7/
ceph-advanced-configuration.html#custom-cephconf-settings.
This the above custom ceph.conf is only for ceph pods.
the support to provide constom ceph.conf for cephcsi
is added in cephcsi PR 2476
This PR adds the support to create/update
ceph.conf for csi pods.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
The latest ceph image should be used for the base of
the rook image to pick up the latest security releases.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>