finally, admission controller will be enabled default
without any script/manual step. But it still requires cert-manager
to be installed which I believe is already installed in clusters.
**Note**
Code doesn't return error it just logs the error since
we don't want to stop reconciling if the admission controller fails.
We can work on this once the admission controller is stable.
Signed-off-by: subhamkrai <srai@redhat.com>
For supporting features like service account authentication for vault
KMS , a service account account need to attach with pod.
Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
The aws go lang sdk needs value for region, it is set differently in
various part of current code. With PR the value is always `us-east-1` so
that it will work RGW server without any issues.
This reverts commit 280c29f330.
Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
The prometheus rules had been previously created if the cephcluster CR
setting monitoring.enabled was set to true. The rules were not customizable
and therefore not flexible enough. Now the rules are installed by the helm
chart. To customize the rules, a post-processor can be applied to the helm
chart.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
The upgrade integration test had been testing from v1.7
to master. Now with the v1.8 release coming up we upgrade
from v1.8 to master.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
With Ceph Quincy v17 support added in Rook v1.9, Quincy
is now added as a target ceph version to test in the integration
tests. The smoke suite will test against Quincy, the upgrade
suite will upgrade from pacific to quincy, while other test
suites will run against octopus or pacific. The daily tests
will test other combinations as well.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
msgr2 allows for encryption and/or compression across the wire.
Settings for enabling the encryption and compression are now
available in the cluster CR to that ceph will be automatically
configured with these settings when desired.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
The encryption on the wire requires either the 5.11 kernel
or the nbd driver. Until the kernel update is available in minikube
we use the rbd-nbd.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
To ensure the mgr is not the single point of failure, the mgr
daemon count is now set to 2 by default in the cluster examples.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
Currently, the admin/user can configure the ceph.conf
for daemon pods using https://rook.io/docs/rook/v1.7/
ceph-advanced-configuration.html#custom-cephconf-settings.
This the above custom ceph.conf is only for ceph pods.
the support to provide constom ceph.conf for cephcsi
is added in cephcsi PR 2476
This PR adds the support to create/update
ceph.conf for csi pods.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
Currently, we sleep only if the snapshot is not ready
and try again, this covers only the happy path.
the checks might fail to get the snapshot object
or the `.status.readyToUse` might not be set yet.
First sleep and then try to check snapshot is
ready or not, if we do this we cover all the cases
when checking the snapshot ready status.
Changed sleep internal to do incremental sleep to
give more time for tests.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
in kubernetes 1.18 we are seeing CRD validation
errors when installing with kubectl, adding
validate=false to skip the validation and
to make tests works with kubernetes 1.18
closes: #9670
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
The external-snapshotter was deployed as statefulset
in 4.x and now its deployed as a deployment. updated
the check in CI to make sure deployment is created.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
updating the csi-snapshotter and dependencies
to v5.0.1 released version.
Co-authored-by: Mathieu Parent <mathieu.parent@insee.fr>
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
The certs for accessing TLS enabled RGW is saved as secrets and inject
them if controllers for notification and topics if request is sent to
TLS enabled RGW endpoint.
Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
Signed-off-by: Jiffin Tony Thottan <jthottan@redhat.com>
Some operator settings can be applied dynamically in a configmap
instead of requiring the operator to restart. While these settings
may be infrequently updated, applying these settings in the configmap
can avoid an unnecessary operator restart. This will also make the
operator deployment more consistent with the non-helm install.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
The helm tests were previously only for new installs, and did
not have an upgrade path. Now the upgrade path is tested
to give confidence in the helm upgrades.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
The test suites were triggered by Jenkins potentially
using different versions of K8s and environment variables.
There is no longer a need for these environment vars to
determine which test suites should be run. The test
suites to run can just be triggered directly.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
The built-in pools device_health_metrics and .nfs created by ceph
need to be configured for replicas, failure domain, etc.
To support this, we allow the pool to be created as a CR.
Since K8s does not support underscores in the resource names
the operator must translate this special pool name into
the name expected by ceph.
This also sets the basis for allowing filesystem data
pools to specify the desired pool name instead of requiring
a generated name.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
The generation of a long node name in the integration tests was
being done based on the k8s version. In the past, older K8s versions
did not support the changing name. Now it's more maintainable if
we generate the long name depending on the test suite.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
Added following test cases for bucket notification integration test
suite:
* different order: OBC - Topic - Notification
* different order: OBC - Notification - Topic
* adding a label to an existing OBC
* deleting a label from an existing OBC
Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
The upgrade integration test was from rook v1.6 to the latest master.
This was necessary until we are ready for the v1.8 release, from which
time we want to focus the upgrade testing from v1.7 to the latest
master.
The duplication in the test CRs and other resources is now reduced
by the upgrade calling a thin wrapper to forward a call to the
master version of the resource. When a new feature is added that
needs to be differentiated from the previous version, the method
then can be implemented instead of wrapping the master implementation.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
The ingress api version changed when it went to v1, and this has caused some upheaval
throughout the kubernetes ecosystem. This commit uses a common method of deciding which
ingress api to use, and allows the optional override of the kubernetes version
presented to helm using the helm build-in capabilities.
also add an ingress into the helm integration tests so any regressions to how ingresses
are handled in the future are caught easier.
Closes rook#9174
Signed-off-by: Tom Hellier <me@tomhellier.com>
The cluster info is important context for the cluster controller to
create the cluster, and all the fields must be properly set.
A test cluster name was being set temporarily, resulting in
mons incorrectly getting the wrong cluster CR name. There is no
known issue from the temporary value, it was just exposed by
https://github.com/rook/rook/pull/8678 setting the value to a label.
Now the functions are more clearly named so only unit and
integration tests should be using the test value for the cluster
name where it is not important.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
Using a default value for CompressionMode to none effectively overrides
any values for Parameters. It is deprecated but still takes precedence.
Which means that in its previous form, Parameters was always ignored
since CompressionMode was always set to none when empty.
Signed-off-by: Sébastien Han <seb@redhat.com>
The volume replication CRDs are an external component, not owned by Rook.
Therefore, they should be installed as any other independent component
in case the admin will install other consumers of the volumereplication CRDs
in the future in addition to Rook and the CSI driver.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
I've seen cases were the CI needs a few more seconds to delete and
object store. When logging in the runner, the object store is gone and
the timing matches too with the runner's logs (comparing with the
operator's logs).
Signed-off-by: Sébastien Han <seb@redhat.com>
We have new jobs now:
* one that runs both smoke and object on the next Pacific version
* one that runs both smoke and object on Ceph master
* one that tests the upgrade from the current pacific stable to the
pacific devel
* one that tests the upgrade from the current octopus stable to the
octopus devel
Signed-off-by: Sébastien Han <seb@redhat.com>
In Rook v1.8 the min version of K8s supported is updated to 1.16.
Users running on older versions of K8s are recommended to update
to 1.16 or newer before updating to Rook v1.8.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
The flex driver has been fully deprecated and thus removed from Rook.
Before upgrading to v1.8, users will need to convert existing flex volumes
from flex to csi volumes.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
The integration tests must always be run against the local
build of rook, and an image should never be pulled from dockerhub.
To prevent pulling a release or master tag, the local build
will use a tag specific to the build and not ever published
elsewhere.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
(cherry picked from commit a8a40428b0)