This code path is no longer necessary, and removing it allows removing
the `replicasets` RBAC permission for the operator.
Signed-off-by: Blaine Gardner <blaine.gardner@suse.com>
All usages of k8s go client are now also using the versioned `AppsV1() `
call for the client.
Updated MySQL and Wordpress, and Kube Registy examples to use apps/v1
Deployments.
Signed-off-by: Alexander Trost <galexrt@googlemail.com>
Make the Ceph operator more cautious about when it decides to remove
nodes from the Rook-Ceph cluster which are acting as osd hosts.
When `useAllNodes` is set to `true` we assume that the user wants to
have the most hands-off experience. Node removals are allowed when a
node is delted from Kubernetes and when a node has its taints/affinities
modified by the user (but not by automatic k8s modification as much as
possible).
When `useAllnodes` is set to `false` the only time a node is removed is
if it is removed from the Ceph cluster definition.
Signed-off-by: Blaine Gardner <blaine.gardner@suse.com>
socket directory name need not follow
the driver name format,renamed socket directory
to simple names.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
The Ceph upgrade test is the only one which uses the
`WaitForDeploymentImage` method, and it has to be configured to wait
longer after upgrade at this point. Since the wait time is still
hard-coded, this method is moved to the operator's test dir to make
it clear that the method is suitable only for tests currently.
Signed-off-by: Blaine Gardner <blaine.gardner@suse.com>
When deleting a CephObjectStoreUser the deleteUser function
attempts to delete the stored secret using the wrong name. This
patch updates deleteUser to use the same fmt.Sprintf call used in
the createUser function.
Updated CI to delete the correct CRD and check the secret is deleted.
Signed-off-by: Keith Schincke <keith.schincke@gmail.com>
Nautilus has an issue targeting Luminous when running the rbd info command.
Rook already has the info it needs for the call and can return it
after the rbd create command succeeds.
Signed-off-by: travisn <tnielsen@redhat.com>
Configure the Ceph rgw daemon completely from the operator a la the
recent changes to the Ceph mon, mgr, and mds operators.
Create the rgw deployment or daemonset first, and then create the
keyring secret for the object store with its owner reference as the
corresponding deployment or daemonset. When the replication controller
is deleted, the secret is also deleted.
The RGW's mime.types file is now stored in a configmap with a different
file created for each object store. This is primarily just a means to
get the mime.types file into the rgw pod, but the added benefit is that
the administrator can modify the configmap, which could reduce
susceptibility to file type execution vulnerabilities (worst case).
Signed-off-by: Blaine Gardner <blaine.gardner@suse.com>
Various kubectl helper methods return strings from calls to
create, delete, or apply resources. There is no need for this.
It is sufficient and complete to check the err from these calls to determine failure.
Signed-off-by: travisn <tnielsen@redhat.com>
The integration tests check for the return of substrings from calls to kubectl
in a number of places. On occasion these return something slightly different
and cause an unnecessary failure in the integration tests.
Signed-off-by: travisn <tnielsen@redhat.com>
I had some trouble with RBAC under minikube when testing some
ceph-mgr functionality. This patch tweaks rook-ceph-mgr-system to
be a ClusterRole, and rook-ceph-mgr-cluster to use a
ClusterRoleBinding.
While we're in there, remove the namespace fields from the
ClusterRoleBindings since they just get ignored.
Finally, also fix up the upgrade test to remove the objects that have
changed and reinstantiate them properly.
Suggested-by: Travis Nielsen <tnielsen@redhat.com>
Signed-off-by: Jeff Layton <jlayton@redhat.com>
Introduce mount security mode for basic multi tenancy
Fixes#2164.
This adds three new parameters/options to StorageClass/flexvolume entry:
* `mountUser`
* `mountSecret`
* `mountSecretNamespace`
Signed-off-by: Alexander Trost <galexrt@googlemail.com>