Commit Graph
814 Commits
Author SHA1 Message Date
parth-gr 9a0490982e nfs: fix nfs short name
nfs short name and crd name was same
which was conflicting,
remove the short name cephnfs as it can
be already called by the crd name

Signed-off-by: parth-gr <partharora1010@gmail.com>
2025-06-02 13:27:24 +05:30
Patryk Rostkowski ae6e1e0863 core: add short names to rook CRDs
This commit Assigns short names to all Rook CRDs
to improve kubectl usability.

Signed-off-by: Patryk Rostkowski <patrostkowski@gmail.com>
2025-05-22 18:29:06 +02:00
Niels de Vos a168c40008 csi: update Kubernetes CSI sidecar images to current versions
The Kubernetes CSI sidecars have had several releases that were not
included in deployments by Rook yet, update them to the versions that
are available today:

- csi-attacher:v4.8.1
- csi-provisioner:v5.2.0
- csi-resizer:v1.13.2
- csi-snapshotter:v8.2.1

This change is important, because Ceph-CSI will implement the new
Controller.GetSnapshot CSI procedure. A bug in csi-lib-utils causes a
panic when a ControllerCapability is provided, but not (yet) known to
the CSI sidecars. The updated sidecars consume a version of
csi-lib-utils with a fix for that panic.

See-also: kubernetes-csi/csi-lib-utils#188
Signed-off-by: Niels de Vos <ndevos@ibm.com>
2025-05-20 14:24:02 +02:00
parth-gr aa326a9419 rbdmirror: fix mirroring status on pool and rn
there is a change  from ceph on how the status
of the mirroring will look like,
Adopting with new fields so the status is correctly synced,
And other components might rely on the status too

Signed-off-by: parth-gr <partharora1010@gmail.com>
2025-05-14 13:07:24 +05:30
Yifeng Zhang 93ccf4c9c2 network: fix validation rule on provider field update
Provider validation is failing on updating from empty string to non-empty ones
which is expected to be supported. Fix the validation rule by adding one missing
condition.

Signed-off-by: Yifeng Zhang <Yifeng.Zhang@cerebras.net>
2025-05-09 13:34:22 -04:00
Travis Nielsen 530223c5b4 namespace: add conditions blocking deletion for rados namespace
When a rados namespace is deleted, it cannot be purged
until its images and snapshots are deleted. Now a condition
is being added to the rados namespace CR status so the user
does not need to read the operator log to discover the cause.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-05-07 15:42:17 -06:00
Joshua Hoblitt 300a22398e object: fix uppercase serialization of fields in KafkaEndpointSpec
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-05-02 10:29:29 -07:00
Patryk Rostkowski 45b0ef2104 operator: specify ceph config via secret
Adds .spec.cephConfigFromSecret to CephCluster for loading
Ceph config parameters from a Kubernetes Secret.

Signed-off-by: Patryk Rostkowski <patrostkowski@gmail.com>
2025-04-23 07:51:22 +02:00
Joshua Hoblitt 7887f03c5c object: add CephBucketTopic .spec.endpoint.kafka.{user,password}SecretRef
userSecretRef and passwordSecretRef fields are added to allow the Kafka
endpoint username and password to be supplied from a Kubernetes Secret,
rather than exposed as plaintext as part of the endpoint URI. If the
endpoint URI has HTTP basic auth user-id and user-pass components, they
are overridden by userSecretRef and passwordSecretRef.

Squid added bucket topic attributes for configuring the user-name and
password for pushing notifications to Kafka as an alternative to
encoding credentials into the URI. However, these attributes are not
supported under Reef. Thus, this initial implementation relies on URI
mangling for compatible with both Reef and Squid. Future work could
using Ceph version detection and switch to the new attributes to be used
with Squid and/or the implementation could be converted exclusively to
use the new attributes once Rook has dropped support for Reef.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-04-16 10:53:11 -07:00
Travis Nielsen f62e6d9cc2 core: set default ceph version to v19.2.2
Update the examples and docs and operator base image to
the latest ceph release v19.2.2.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-04-14 12:59:39 -06:00
Rakshith R a555885a5f csi: update cephcsi to latest release
This commit updates cephcsi version to 3.14.0
in rook.

Signed-off-by: Rakshith R <rar@redhat.com>
2025-04-11 18:05:44 +05:30
Santosh Pillai 2dab3d3832 Merge pull request #15645 from parth-gr/fix-mon
mon: fix mon rbac for endpoint slice
2025-04-04 12:37:32 +05:30
parth-gr e7dbab3513 mon: fix mon rbac for endpoint slice
a newly dynamic dns resolution code
was added by https://github.com/rook/rook/pull/15522
Fixing rbac of it, as current rbac needs
a sub resource `restricted`

Signed-off-by: parth-gr <partharora1010@gmail.com>
2025-04-04 11:59:08 +05:30
Joshua Hoblitt 6b2c357871 object: add CephObjectStoreUser.spec.keys
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-04-03 09:09:01 -07:00
Blaine Gardner e349a81a17 Merge pull request #15624 from parth-gr/rgw-ex
object: updated cephobjectstore zone spec
2025-04-02 09:47:31 -06:00
parth-gr c47c6c5072 object: updated cephobjectstore zone api
if no multisite is used, rook creates the zone,
in the same name as cephobjectstore cr,

But cephobjectstore zone spec
shows name as empty string("")

Which is confusing for the end user, so
to remove the confusion by updating the
api defination

Signed-off-by: parth-gr <partharora1010@gmail.com>
2025-04-02 16:50:57 +05:30
Blaine Gardner 2348ff689c Merge pull request #15459 from subhamkrai/implicit-ns
rbdmirror: mirroring b/w implicit and defined ns
2025-04-01 12:56:06 -06:00
Blaine Gardner 85440169dd Merge pull request #15554 from ragnard/kafka-topic-params
rgw: Support Kafka auth mechanism parameter
2025-04-01 10:44:36 -06:00
subhamkrai 420178fe3e rbdmirror: mirroring b/w implicit and defined ns
this commit add support for mirroring b/w implicit rados namespace and
defined rados namespace. To support this, rook will treat `<implicit>`
name on cephblockpool as `""` empty string. This will allow mirroring
b/w implicit and defined radosnamespace.

Signed-off-by: subhamkrai <srai@redhat.com>
2025-04-01 10:46:06 +05:30
Travis Nielsen 9e1c78dfd5 Merge pull request #15522 from patrostkowski/feature/mon-active-ep-14986
mon: manage endpoints containing set of mon ip addresses
2025-03-31 10:42:29 -06:00
Patryk Rostkowski 08199b27c9 mon: manage endpoints containing set of mon ip addresses
The change creates and manages an Endpoints resource
with the current Ceph monitor (mon) IPs, allowing
clients to resolve mon IPs via DNS without relying
on the rook-ceph-mon-endpoints ConfigMap.

Signed-off-by: Patryk Rostkowski <patrostkowski@gmail.com>
2025-03-31 18:05:37 +02:00
Blaine Gardner e783264652 Merge pull request #15588 from sp98/rgw-client-location
rgw: RGW read affinity for localized reads
2025-03-31 09:26:20 -06:00
Santosh Pillai deb010c32e rgw: support read affinty for localized reads
allows selecting Read Affinity policy from the ObjectStore API
aets `--crush-location=host` for RGW daemons.

Signed-off-by: Santosh Pillai <sapillai@redhat.com>
2025-03-31 18:24:32 +05:30
Travis Nielsen 721fe4ff7d test: include rgw zone flags for endpoint validation
The rgw endpoint validation requires the zone flags to be passed
when the admin user is in a non-default zone.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-03-27 17:41:20 -06:00
Santosh Pillai daa0dc1327 Merge pull request #15408 from sp98/redo-pdbs
osd: handle OSD PDBs when OSDs fail without affecting the cluster health
2025-03-26 21:34:17 +05:30
Santosh Pillai a816b4a971 osd: allow one healthy OSD to be drained
One ore more OSDs can be down and PGs can still be active+clean (data
was rebalanced to other available OSDs). This PR sets
maxunavailable=1+downOSDs to allow one healthy to be drained.

Signed-off-by: Santosh Pillai <sapillai@redhat.com>
2025-03-26 10:40:46 +05:30
Ragnar Dahlén 8bf7c679bb rgw: support kafka auth mechanism parameter
Ceph has support [1,2] for configuring which authentication
mechanism to use for bucket notifications using Kafka topics.

This commit adds the corresponding support to rook.

[1]: https://github.com/ceph/ceph/pull/48181/commits/d5dce601f65974a21c83c4b1add036030a75c3c4
[2]: https://tracker.ceph.com/issues/57608

Signed-off-by: Ragnar Dahlén <r.dahlen@gmail.com>
2025-03-24 21:53:49 +01:00
Travis Nielsen fe70248a13 operator: set dns policy for host network if needed
When host network is enabled, the operator needs to set the
dns policy to ClusterFirstWithHostNet so the request to the
rgw endpoint will resolve properly.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-03-20 14:01:26 -06:00
yati1998 762430ccb5 build: set ceph csi release version to v3.13.1
this commit sets the release version
for ceph-csi to v3.13.1

Signed-off-by: yati1998 <ypadia@redhat.com>
2025-03-10 11:08:07 +05:30
Niels de Vos 25d3b6d5fc csi: update csi-addons to v0.12.0
The csi-addons v0.12.0 release is now available.

See-also: https://github.com/csi-addons/kubernetes-csi-addons/releases/tag/v0.12.0
Signed-off-by: Niels de Vos <ndevos@ibm.com>
2025-03-05 09:35:41 +01:00
Travis Nielsen 9a5bf16247 Merge pull request #15400 from cobaltcore-dev/ext-mon-2
Implement external arbiter mon
2025-03-03 12:01:12 -07:00
Travis Nielsen 3399b712da Merge pull request #15426 from cobaltcore-dev/rgw-config-from-secret
object: allow overriding rgw config value from secret
2025-03-03 07:53:13 -07:00
Travis Nielsen 98a3d20c43 Merge pull request #15486 from parth-gr/fix-black
ci: update the python black package
2025-03-03 07:42:33 -07:00
Artem Torubarov 0b2e830111 mon: support external mons in local rook cluster
Implements #14733. Allows to set IDs of external mons to
Cluster CRD. Rook will not remove external mons from quorum
and will add external mon addresses to mon endpoints.
Use-case for external mon is to maintain quorum for 2-AZ
k8s cluster in case of zone outage.

Signed-off-by: Artem Torubarov <artem.torubarov@clyso.com>
2025-03-03 14:49:39 +01:00
Artem Torubarov 3b2e6f5bf6 object: allow overriding rgw config value from secret
Implements #15422
Extends existing ObjectStore configuration options with
rgwConfigFromSecret allowing to refer config value from
kubernetes secret.

Signed-off-by: Artem Torubarov <artem.torubarov@clyso.com>
2025-03-03 14:48:55 +01:00
parth-gr a3bde46ad3 ci: update the python black package
in the ci lint file, we use a dependency
from a 3rd party lint, which updates
the black package, The underlined python script
file was not updated to the latest formatting,
so re-format the file and update the
3rd party dependency version

Signed-off-by: parth-gr <partharora1010@gmail.com>
2025-03-03 18:48:39 +05:30
Travis NielsenandDmitry Mishin d109dc9029 core: implement operator settings as env vars
The operator settings loaded from the configmap have proven
inefficient for load time and frequently checking the configmap.
To avoid this ineffenciency, the configmap is only loaded once
each time it is created or updated. The values in the configmap
are applied as environment variables, which then are very efficient
to query throughout the various controllers, without needing
to be concerned about loading the configmap again.

Co-authored-by: Dmitry Mishin <dmitry.mishin@gmail.com>
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-02-24 12:12:45 -07:00
Travis Nielsen 4eed2a644f Merge pull request #15433 from SkalaNetworks/master
fix(csi-addons): bind cephfs and rbd provisionners on non-colliding p…
2025-02-24 12:06:57 -07:00
Skala Networks d3c3d25c60 csi: bind cephfs and rbd provisionners on non-colliding ports for hostNetwork setups
Signed-off-by: Skala Networks <contact@skala.network>
2025-02-23 06:31:43 -05:00
Travis Nielsen 2181170811 Merge pull request #15370 from travisn/osd-upgrade-checks
osd: Enable osd ok-to-stop checks on single node where there are at least three OSDs
2025-02-20 12:52:03 -07:00
Travis Nielsen 8f79b58edc Merge pull request #15392 from subhamkrai/update-ceph-v19.2.1
manifest: Update default ceph version to v19.2.1
2025-02-20 11:41:06 -07:00
subhamkrai 0e395f0a67 manifest: update default ceph version to v19.2.1
with ceph release v19.2.1 updating it to be dafult version
in rook.

Signed-off-by: subhamkrai <srai@redhat.com>
2025-02-20 23:24:54 +05:30
Blaine Gardner 73c931fc0a Merge pull request #15376 from BlaineEXE/obc-allow-list-obc-fields
object: disallow unsafe OBC fields by default
2025-02-19 12:00:54 -07:00
Niraj Yadav ece302f35b manifest: add list and watch capabilities to provisioners
This patch adds `list` and `watch` verbs to cephfs and rbd
provisioner roles for CSIAddonNode objects.

Signed-off-by: Niraj Yadav <niryadav@redhat.com>
2025-02-17 15:32:21 +05:30
Bipul Adhikari d25b26e890 csi: moves rbac for Tokenreview API from role to cluster role
CSI addons sidecar requires clusterrole permission for Tokenreview
Tokenreview is a cluster scoped API

Signed-off-by: Bipul Adhikari <badhikar@redhat.com>
2025-02-13 14:44:48 +05:45
Blaine Gardner 0e33536539 object: disallow unsafe OBC fields by default
Implement an allow list mechanism that disables potentially unsafe OBC
fields by default. OBC fields beyond `maxObjects` and `maxSize` don't
neatly fit into the OBC framework as it was originally envisioned and
implemented.

Some of the newly added configs could allow users to cause confusion for
themselves. Others might allow users to hijack others buckets. Some
might allow bricking the entire S3 store.

Out of an abundance of safety, allow-list the known-safe options by
default, and require administrators to enable potentially troublesome
options via the new operator-level config
`ROOK_OBC_ALLOW_ADDITIONAL_CONFIG_FIELDS`.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2025-02-12 14:18:01 -07:00
Travis Nielsen e068e156ce osd: enable osd ok-to-stop checks on single node for three osds
If there are at least three OSDs on a single node, we should
treat it as a potential production cluster and perform
the ok-to-stop checks during reconcile. Otherwise,
it may cause instability during upgrades on
single-node clusters.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-02-05 12:08:48 -07:00
Travis Nielsen 8ca9186038 Merge pull request #15326 from bipuladh/support-sidecar
csi: updates RBAC allow tokenreview creation
2025-02-05 07:39:41 -07:00
Bipul Adhikari 7ccd0cba13 csi: updates RBAC allow tokenreview creation
CSI addons sidecar requires tokenreview api access to verify authorization

Signed-off-by: Bipul Adhikari <badhikar@redhat.com>
2025-02-05 11:51:25 +05:45
parth 6cf97fd32b external: allow cephfs or rgw only deployments
currently there was a restriction to always create rbd pool
with this change only cephfs or rgw volumes created

Signed-off-by: parth-gr <partharora1010@gmail.com>
2025-02-04 14:27:36 +05:30