nfs short name and crd name was same
which was conflicting,
remove the short name cephnfs as it can
be already called by the crd name
Signed-off-by: parth-gr <partharora1010@gmail.com>
The Kubernetes CSI sidecars have had several releases that were not
included in deployments by Rook yet, update them to the versions that
are available today:
- csi-attacher:v4.8.1
- csi-provisioner:v5.2.0
- csi-resizer:v1.13.2
- csi-snapshotter:v8.2.1
This change is important, because Ceph-CSI will implement the new
Controller.GetSnapshot CSI procedure. A bug in csi-lib-utils causes a
panic when a ControllerCapability is provided, but not (yet) known to
the CSI sidecars. The updated sidecars consume a version of
csi-lib-utils with a fix for that panic.
See-also: kubernetes-csi/csi-lib-utils#188
Signed-off-by: Niels de Vos <ndevos@ibm.com>
there is a change from ceph on how the status
of the mirroring will look like,
Adopting with new fields so the status is correctly synced,
And other components might rely on the status too
Signed-off-by: parth-gr <partharora1010@gmail.com>
Provider validation is failing on updating from empty string to non-empty ones
which is expected to be supported. Fix the validation rule by adding one missing
condition.
Signed-off-by: Yifeng Zhang <Yifeng.Zhang@cerebras.net>
When a rados namespace is deleted, it cannot be purged
until its images and snapshots are deleted. Now a condition
is being added to the rados namespace CR status so the user
does not need to read the operator log to discover the cause.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
Adds .spec.cephConfigFromSecret to CephCluster for loading
Ceph config parameters from a Kubernetes Secret.
Signed-off-by: Patryk Rostkowski <patrostkowski@gmail.com>
userSecretRef and passwordSecretRef fields are added to allow the Kafka
endpoint username and password to be supplied from a Kubernetes Secret,
rather than exposed as plaintext as part of the endpoint URI. If the
endpoint URI has HTTP basic auth user-id and user-pass components, they
are overridden by userSecretRef and passwordSecretRef.
Squid added bucket topic attributes for configuring the user-name and
password for pushing notifications to Kafka as an alternative to
encoding credentials into the URI. However, these attributes are not
supported under Reef. Thus, this initial implementation relies on URI
mangling for compatible with both Reef and Squid. Future work could
using Ceph version detection and switch to the new attributes to be used
with Squid and/or the implementation could be converted exclusively to
use the new attributes once Rook has dropped support for Reef.
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
if no multisite is used, rook creates the zone,
in the same name as cephobjectstore cr,
But cephobjectstore zone spec
shows name as empty string("")
Which is confusing for the end user, so
to remove the confusion by updating the
api defination
Signed-off-by: parth-gr <partharora1010@gmail.com>
this commit add support for mirroring b/w implicit rados namespace and
defined rados namespace. To support this, rook will treat `<implicit>`
name on cephblockpool as `""` empty string. This will allow mirroring
b/w implicit and defined radosnamespace.
Signed-off-by: subhamkrai <srai@redhat.com>
The change creates and manages an Endpoints resource
with the current Ceph monitor (mon) IPs, allowing
clients to resolve mon IPs via DNS without relying
on the rook-ceph-mon-endpoints ConfigMap.
Signed-off-by: Patryk Rostkowski <patrostkowski@gmail.com>
allows selecting Read Affinity policy from the ObjectStore API
aets `--crush-location=host` for RGW daemons.
Signed-off-by: Santosh Pillai <sapillai@redhat.com>
The rgw endpoint validation requires the zone flags to be passed
when the admin user is in a non-default zone.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
One ore more OSDs can be down and PGs can still be active+clean (data
was rebalanced to other available OSDs). This PR sets
maxunavailable=1+downOSDs to allow one healthy to be drained.
Signed-off-by: Santosh Pillai <sapillai@redhat.com>
When host network is enabled, the operator needs to set the
dns policy to ClusterFirstWithHostNet so the request to the
rgw endpoint will resolve properly.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
Implements #14733. Allows to set IDs of external mons to
Cluster CRD. Rook will not remove external mons from quorum
and will add external mon addresses to mon endpoints.
Use-case for external mon is to maintain quorum for 2-AZ
k8s cluster in case of zone outage.
Signed-off-by: Artem Torubarov <artem.torubarov@clyso.com>
in the ci lint file, we use a dependency
from a 3rd party lint, which updates
the black package, The underlined python script
file was not updated to the latest formatting,
so re-format the file and update the
3rd party dependency version
Signed-off-by: parth-gr <partharora1010@gmail.com>
The operator settings loaded from the configmap have proven
inefficient for load time and frequently checking the configmap.
To avoid this ineffenciency, the configmap is only loaded once
each time it is created or updated. The values in the configmap
are applied as environment variables, which then are very efficient
to query throughout the various controllers, without needing
to be concerned about loading the configmap again.
Co-authored-by: Dmitry Mishin <dmitry.mishin@gmail.com>
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
This patch adds `list` and `watch` verbs to cephfs and rbd
provisioner roles for CSIAddonNode objects.
Signed-off-by: Niraj Yadav <niryadav@redhat.com>
CSI addons sidecar requires clusterrole permission for Tokenreview
Tokenreview is a cluster scoped API
Signed-off-by: Bipul Adhikari <badhikar@redhat.com>
Implement an allow list mechanism that disables potentially unsafe OBC
fields by default. OBC fields beyond `maxObjects` and `maxSize` don't
neatly fit into the OBC framework as it was originally envisioned and
implemented.
Some of the newly added configs could allow users to cause confusion for
themselves. Others might allow users to hijack others buckets. Some
might allow bricking the entire S3 store.
Out of an abundance of safety, allow-list the known-safe options by
default, and require administrators to enable potentially troublesome
options via the new operator-level config
`ROOK_OBC_ALLOW_ADDITIONAL_CONFIG_FIELDS`.
Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
If there are at least three OSDs on a single node, we should
treat it as a potential production cluster and perform
the ok-to-stop checks during reconcile. Otherwise,
it may cause instability during upgrades on
single-node clusters.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
currently there was a restriction to always create rbd pool
with this change only cephfs or rgw volumes created
Signed-off-by: parth-gr <partharora1010@gmail.com>