Commit Graph
651 Commits
Author SHA1 Message Date
subhamkrai f6f03d272b core: start admission controller without any script
finally, admission controller will be enabled default
without any script/manual step. But it still requires cert-manager
to be installed which I believe is already installed in clusters.

**Note**
Code doesn't return error it just logs the error since
we don't want to stop reconciling if the admission controller fails.
We can work on this once the admission controller is stable.

Signed-off-by: subhamkrai <srai@redhat.com>
2022-04-11 19:44:54 +05:30
subhamkrai 24802c559e core: fix golangci linter
fix golangci linter

Signed-off-by: subhamkrai <srai@redhat.com>
2022-04-04 20:59:31 +05:30
Jiffin Tony Thottan 5e72b26948 object: add service account for RGW pod
For supporting features like service account authentication for vault
KMS , a service account account need to attach with pod.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2022-04-04 11:24:50 +05:30
Travis Nielsen 6c50530737 Merge pull request #9685 from weirdwiz/context-remove
Remove context.TODO and add context parameter
2022-03-30 12:20:30 -05:00
Jiffin Tony Thottan fc2b8012c6 object: use us-east-1 for aws go lang sdk
The aws go lang sdk needs value for region, it is set differently in
various part of current code. With PR the value is always `us-east-1` so
that it will work RGW server without any issues.

This reverts commit 280c29f330.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2022-03-24 14:37:39 +05:30
Divyansh Kamboj 9008409f87 core: add context parameter to functions
This commit adds context parameter to various functions, and remove the
usage of context.TODO.

Closes: https://github.com/rook/rook/issues/8701
Signed-off-by: Divyansh Kamboj <dkamboj@redhat.com>
2022-03-22 08:19:07 +05:30
Travis Nielsen 4edcff04f7 monitoring: create prometheus rules with helm chart
The prometheus rules had been previously created if the cephcluster CR
setting monitoring.enabled was set to true. The rules were not customizable
and therefore not flexible enough. Now the rules are installed by the helm
chart. To customize the rules, a post-processor can be applied to the helm
chart.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-03-21 14:47:52 -06:00
Travis Nielsen 4f9a72c1db Merge pull request #9894 from yuvalman/resources
helm: enable resource defaults on rook components
2022-03-21 13:58:17 -06:00
Yuval Manor ff7a5c2d2d helm: enable resource defaults on rook components
This PR assign default values to the resources of all Rook and Ceph components

Closes: https://github.com/rook/rook/issues/9858
Signed-off-by: Yuval Manor <yuvalman958@gmail.com>
2022-03-21 21:23:35 +02:00
Travis Nielsen ee1e17518d test: upgrade from 1.8 to master
The upgrade integration test had been testing from v1.7
to master. Now with the v1.8 release coming up we upgrade
from v1.8 to master.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-03-16 14:19:08 -06:00
Travis Nielsen 8ed9c5d480 test: add quincy to the integration test matrix
With Ceph Quincy v17 support added in Rook v1.9, Quincy
is now added as a target ceph version to test in the integration
tests. The smoke suite will test against Quincy, the upgrade
suite will upgrade from pacific to quincy, while other test
suites will run against octopus or pacific. The daily tests
will test other combinations as well.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-03-16 14:19:08 -06:00
Travis Nielsen 03c7164b15 mon: options for enabling msgr2 encryption and compression
msgr2 allows for encryption and/or compression across the wire.
Settings for enabling the encryption and compression are now
available in the cluster CR to that ceph will be automatically
configured with these settings when desired.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-03-10 11:50:42 -07:00
Travis Nielsen cec3942d72 test: run encrypted tests with nbd driver
The encryption on the wire requires either the 5.11 kernel
or the nbd driver. Until the kernel update is available in minikube
we use the rbd-nbd.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-03-10 11:48:48 -07:00
Travis Nielsen 75a385e187 csi: update volume replication to v0.3.0
Update to the latest volume replication crd version of
v0.3.0

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-03-09 15:53:45 -07:00
Travis Nielsen bc9914e99d mgr: set the default count of mgr daemons to 2
To ensure the mgr is not the single point of failure, the mgr
daemon count is now set to 2 by default in the cluster examples.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-03-02 13:35:05 -07:00
Madhu Rajanna 2076a3c788 csi: add custom ceph.conf for csi pods
Currently, the admin/user can configure the ceph.conf
for daemon pods using https://rook.io/docs/rook/v1.7/
ceph-advanced-configuration.html#custom-cephconf-settings.
This the above custom ceph.conf is only for ceph pods.
the support to provide constom ceph.conf for cephcsi
is added in cephcsi PR 2476

This PR adds the support to create/update
ceph.conf for csi pods.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2022-03-01 12:42:59 +05:30
bootjp / Yoshiaki Ueda 294b6854f6 test: fix typo
GitHub is officially known as GitHub. https://github.com/logos

Signed-off-by: bootjp / Yoshiaki Ueda <contact@bootjp.me>
2022-02-19 20:32:23 +09:00
Jiffin Tony Thottan 438cf6abf1 test: update bucket notification integration test with http server
Add test cases to check notification is received by http server. For
this a sample http server https://github.com/thotz/pythonwebserver is
used.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2022-02-15 12:59:58 +05:30
Madhu Rajanna 97e5b78c11 csi: cover error cases in snapshot ready check
Currently, we sleep only if the snapshot is not ready
and try again, this covers only the happy path.
the checks might fail to get the snapshot object
or the `.status.readyToUse` might not be set yet.
First sleep and then try to check snapshot is
ready or not, if we do this we cover all the cases
when checking the snapshot ready status.
Changed sleep internal to do incremental sleep to
give more time for tests.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2022-01-31 13:07:37 +05:30
Madhu Rajanna c40ff24410 csi: skip validation when installing snapshotter
in kubernetes 1.18 we are seeing CRD validation
errors when installing with kubectl, adding
validate=false to skip the validation and
to make tests works with kubernetes 1.18

closes: #9670

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2022-01-28 08:25:07 +05:30
Madhu Rajanna 53e12d687f csi: check deployment for snapshot controller
The external-snapshotter was deployed as statefulset
in 4.x and now its deployed as a deployment. updated
the check in CI to make sure deployment is created.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2022-01-27 23:06:16 +05:30
Madhu RajannaandMathieu Parent cf46615688 csi: bump csi snapshotter image to v5
updating the csi-snapshotter and dependencies
to v5.0.1 released version.

Co-authored-by: Mathieu Parent <mathieu.parent@insee.fr>
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2022-01-27 21:17:51 +05:30
Blaine Gardner 18c1397bcc Merge pull request #9565 from thotz/rgw-tls-cert-fix-bucket-notifications
rgw: inject tls certs for bucket notification and topic operations
2022-01-24 11:56:09 -07:00
Jiffin Tony Thottan a97747cece rgw: inject tls certs for bucket notification and topic operations
The certs for accessing TLS enabled RGW is saved as secrets and inject
them if controllers for notification and topics if request is sent to
TLS enabled RGW endpoint.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
Signed-off-by: Jiffin Tony Thottan <jthottan@redhat.com>
2022-01-24 22:39:57 +05:30
Travis Nielsen 741f211a13 helm: apply operator settings in configmap instead of deployment
Some operator settings can be applied dynamically in a configmap
instead of requiring the operator to restart. While these settings
may be infrequently updated, applying these settings in the configmap
can avoid an unnecessary operator restart. This will also make the
operator deployment more consistent with the non-helm install.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-01-20 14:41:28 -07:00
Blaine Gardner 3b415ea15a Merge pull request #9482 from yuvalif/ceph-cloudevent-topic
rgw: add HTTP CloudEvent endpoints to CephBucketNotification CR
2022-01-13 08:40:07 -07:00
Yuval Lifshitz c99e2a37fd rgw: add HTTP CloudEvent endpoints to CephBucketNotification CR
this add a configuration parameter that allows an RGW, from
Ceph Quincy (v17) and on, to send bucket notifications to an HTTP CloudEvents
endpoint.
Header format:
https://github.com/cloudevents/spec/blob/main/cloudevents/adapters/aws-s3.md

Signed-off-by: Yuval Lifshitz <ylifshit@redhat.com>
2022-01-13 12:08:40 +02:00
Travis Nielsen 8fb758fee9 test: implement helm upgrade integration test
The helm tests were previously only for new installs, and did
not have an upgrade path. Now the upgrade path is tested
to give confidence in the helm upgrades.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-01-12 07:19:42 -07:00
Travis Nielsen 52c938b7f9 test: remove obsolete check for test suites to run
The test suites were triggered by Jenkins potentially
using different versions of K8s and environment variables.
There is no longer a need for these environment vars to
determine which test suites should be run. The test
suites to run can just be triggered directly.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-01-11 11:10:50 -07:00
Travis Nielsen d1f3e3b9ad test: upgrade from v1.7.10
The upgrade test is best if run from the latest v1.7 patch release.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-01-11 11:10:48 -07:00
Travis Nielsen 7ee9cc9d56 pool: allow configuration of built-in pools with non-k8s names
The built-in pools device_health_metrics and .nfs created by ceph
need to be configured for replicas, failure domain, etc.
To support this, we allow the pool to be created as a CR.
Since K8s does not support underscores in the resource names
the operator must translate this special pool name into
the name expected by ceph.

This also sets the basis for allowing filesystem data
pools to specify the desired pool name instead of requiring
a generated name.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-12-15 15:32:02 -07:00
Blaine Gardner 2467daa406 Merge pull request #9169 from thotz/addtestcasesbucketnotification
test: add more test cases for bucket notfication
2021-12-09 08:54:21 -07:00
Sébastien Han 0a918814ea core: bump to ceph 16.2.7
ceph 16.2.7 is out so let's use it in our manifests.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-12-08 17:24:56 +01:00
Travis Nielsen 9d2aa1f6bd test: generate long node name depending on test suite
The generation of a long node name in the integration tests was
being done based on the k8s version. In the past, older K8s versions
did not support the changing name. Now it's more maintainable if
we generate the long name depending on the test suite.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-12-06 08:03:56 -07:00
Jiffin Tony Thottan 7a9a7123a0 test: add more test cases for bucket notfication
Added following test cases for bucket notification integration test
suite:

* different order: OBC - Topic - Notification
* different order: OBC - Notification - Topic
* adding a label to an existing OBC
* deleting a label from an existing OBC

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2021-12-02 23:02:45 +05:30
Travis Nielsen d9ac8ce490 test: upgrade integration test from 1.7 to master
The upgrade integration test was from rook v1.6 to the latest master.
This was necessary until we are ready for the v1.8 release, from which
time we want to focus the upgrade testing from v1.7 to the latest
master.

The duplication in the test CRs and other resources is now reduced
by the upgrade calling a thin wrapper to forward a call to the
master version of the resource. When a new feature is added that
needs to be differentiated from the previous version, the method
then can be implemented instead of wrapping the master implementation.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-11-30 08:07:42 -07:00
Sébastien Han c890710b63 core: change directory layout
As per discussion, proposing a new layout for the charts/yaml/olm files.

./deploy
├── charts
│   ├── rook-ceph
│   │   └── templates
│   └── rook-ceph-cluster
│       └── templates
├── examples
│   ├── csi
│   │   ├── cephfs
│   │   └── rbd
│   ├── flex
│   ├── monitoring
│   ├── pre-k8s-1.16
└── olm
    └── assemble

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-11-30 09:12:53 +01:00
Travis Nielsen ba54567e8f Merge pull request #9176 from TomHellier/9174-ingress-support-more-k8s-versions
helm: Allow further configurability of the ingress version
2021-11-23 13:47:33 -07:00
Tom Hellier ba44602477 helm: allow further configurability of ingress version
The ingress api version changed when it went to v1, and this has caused some upheaval
throughout the kubernetes ecosystem. This commit uses a common method of deciding which
ingress api to use, and allows the optional override of the kubernetes version
presented to helm using the helm build-in capabilities.
also add an ingress into the helm integration tests so any regressions to how ingresses
are handled in the future are caught easier.

Closes rook#9174

Signed-off-by: Tom Hellier <me@tomhellier.com>
2021-11-22 10:03:02 +00:00
Travis Nielsen 1afd322650 core: ensure cluster name is available on cluster info
The cluster info is important context for the cluster controller to
create the cluster, and all the fields must be properly set.
A test cluster name was being set temporarily, resulting in
mons incorrectly getting the wrong cluster CR name. There is no
known issue from the temporary value, it was just exposed by
https://github.com/rook/rook/pull/8678 setting the value to a label.

Now the functions are more clearly named so only unit and
integration tests should be using the test value for the cluster
name where it is not important.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-11-18 15:30:26 -07:00
Yuval Lifshitz 71ed45b69b rgw: implement bucket notifications for object storage
following the design from here:
https://github.com/rook/rook/blob/master/design/ceph/object/ceph-bucket-notification-crd.md

Closes: https://github.com/rook/rook/issues/5313
Signed-off-by: Yuval Lifshitz <ylifshit@redhat.com>
2021-11-04 11:20:40 +02:00
subhamkrai 0150966024 ceph: remove ceph nautilus, ceph octopus to default
since rook 1.8, ceph nautilus no longer supported,
ceph octopus will be the minimum ceph version.

Closes: https://github.com/rook/rook/issues/7908
Signed-off-by: subhamkrai <srai@redhat.com>
2021-10-20 14:45:12 +05:30
Sébastien Han 28cc6f5514 ceph: remove default value for pool compression
Using a default value for CompressionMode to none effectively overrides
any values for Parameters. It is deprecated but still takes precedence.
Which means that in its previous form, Parameters was always ignored
since CompressionMode was always set to none when empty.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-10-13 17:06:22 +02:00
Travis Nielsen c420f2309c csi: no longer install the volumereplication crds from rook
The volume replication CRDs are an external component, not owned by Rook.
Therefore, they should be installed as any other independent component
in case the admin will install other consumers of the volumereplication CRDs
in the future in addition to Rook and the CSI driver.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-10-06 16:27:44 +00:00
Sébastien Han b4a36e9967 ci: wait longer for pod label to be deleted
I've seen cases were the CI needs a few more seconds to delete and
object store. When logging in the runner, the object store is gone and
the timing matches too with the runner's logs (comparing with the
operator's logs).

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-09-28 15:24:39 +02:00
Sébastien Han 33dbaba38b ci: add daily jobs
We have new jobs now:

* one that runs both smoke and object on the next Pacific version
* one that runs both smoke and object on Ceph master
* one that tests the upgrade from the current pacific stable to the
  pacific devel
* one that tests the upgrade from the current octopus stable to the
  octopus devel

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-09-27 11:59:04 +02:00
Travis Nielsen f5c1543ddf build: update min k8s version to 1.16
In Rook v1.8 the min version of K8s supported is updated to 1.16.
Users running on older versions of K8s are recommended to update
to 1.16 or newer before updating to Rook v1.8.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-09-23 16:17:56 -06:00
Travis Nielsen 0a0b9c98bd build: remove obsolete flex driver
The flex driver has been fully deprecated and thus removed from Rook.
Before upgrading to v1.8, users will need to convert existing flex volumes
from flex to csi volumes.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2021-09-23 16:17:20 -06:00
Travis Nielsen 9ff0753514 test: run all integration tests against the local build
The integration tests must always be run against the local
build of rook, and an image should never be pulled from dockerhub.
To prevent pulling a release or master tag, the local build
will use a tag specific to the build and not ever published
elsewhere.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
(cherry picked from commit a8a40428b0)
2021-09-22 07:39:42 -06:00
Sébastien Han 0c33493f27 ceph: bump manifests to ceph pacific 16.2.6
New version is out so let's use it.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-09-21 09:16:32 +02:00