Commit Graph
769 Commits
Author SHA1 Message Date
Travis Nielsen d252466f6f ci: test tentacle devel in daily builds
With the tentacle release approaching, let's start
running the Rook tests against the tentacle devel
images to catch if any issues.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-05-30 13:52:56 -06:00
Carlos Barria 030ada45b0 core: fix golangci-lint check QF1003 QF1002
Refactored multiple conditional if-else blocks into switch statements to improve readability and maintainability. Also removed outdated staticcheck rule comments (QF1002, QF1003) from .golangci.yaml.

Signed-off-by: Carlos Barria <cbarria@yahoo.com>
2025-05-27 13:49:49 -04:00
Carlos Barria c044ca9e77 core: fix golangci-lint check ST1008
Signed-off-by: Carlos Barria <cbarria@yahoo.com>
2025-05-22 15:39:30 -04:00
Carlos Barria 8afc4ee548 core: fix golangci-lint check QF1004
Signed-off-by: Carlos Barria <cbarria@yahoo.com>
2025-05-22 11:21:45 -04:00
Niels de Vos a168c40008 csi: update Kubernetes CSI sidecar images to current versions
The Kubernetes CSI sidecars have had several releases that were not
included in deployments by Rook yet, update them to the versions that
are available today:

- csi-attacher:v4.8.1
- csi-provisioner:v5.2.0
- csi-resizer:v1.13.2
- csi-snapshotter:v8.2.1

This change is important, because Ceph-CSI will implement the new
Controller.GetSnapshot CSI procedure. A bug in csi-lib-utils causes a
panic when a ControllerCapability is provided, but not (yet) known to
the CSI sidecars. The updated sidecars consume a version of
csi-lib-utils with a fix for that panic.

See-also: kubernetes-csi/csi-lib-utils#188
Signed-off-by: Niels de Vos <ndevos@ibm.com>
2025-05-20 14:24:02 +02:00
Carlos Barria 61494d1baf core: fix golangci-lint check ST1005
Signed-off-by: Carlos Barria <cbarria@yahoo.com>
2025-05-19 17:52:22 -04:00
Blaine Gardner 98bd03a420 ci: extend timeout for mons in upgrade test
When upgrading from one Ceph version to another, the new image to
upgrade to can take a long time to pull in some cases before the upgrade
can even begin. For example, some ceph-ci images regularly take 6+
minutes to pull, which exceeds the timeout waiting for mons to be ready.

Extend the timeout for mons to account for these cases.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2025-04-29 13:53:43 -06:00
Oded Viner 5d143d990c test: update Prometheus Operator to v0.82.0
this PR updates the Prometheus Operator URL references from
version v0.71.1 to the latest release v0.81.0 in documentation
and integration test scripts. This ensures we are aligned with
the latest features and improvements from
the Prometheus Operator project.

Signed-off-by: Oded Viner <oviner@redhat.com>
2025-04-22 15:37:56 +03:00
Joshua Hoblitt 7887f03c5c object: add CephBucketTopic .spec.endpoint.kafka.{user,password}SecretRef
userSecretRef and passwordSecretRef fields are added to allow the Kafka
endpoint username and password to be supplied from a Kubernetes Secret,
rather than exposed as plaintext as part of the endpoint URI. If the
endpoint URI has HTTP basic auth user-id and user-pass components, they
are overridden by userSecretRef and passwordSecretRef.

Squid added bucket topic attributes for configuring the user-name and
password for pushing notifications to Kafka as an alternative to
encoding credentials into the URI. However, these attributes are not
supported under Reef. Thus, this initial implementation relies on URI
mangling for compatible with both Reef and Squid. Future work could
using Ceph version detection and switch to the new attributes to be used
with Squid and/or the implementation could be converted exclusively to
use the new attributes once Rook has dropped support for Reef.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-04-16 10:53:11 -07:00
Travis Nielsen ca1d2ed3e3 tests: lower threshold for mon free space
The tests sometimes see that the mons run out of space
in the CI, therefore, we reduce the space required
from 30% down to 10%.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-04-14 16:06:03 -06:00
Travis Nielsen d3cb7271a7 tests: upgrade from rook 1.16 to master
The upgrade tests in master have been upgrading from 1.15 to
master. In anticipation of the v1.17 release, we change
the upgrade tests to start from v1.16 to test if there
are any regressions in the supported upgrades.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2025-03-27 13:06:55 -06:00
Joshua Hoblitt 3cb343f62a core: run gofumpt on all files
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2025-03-26 10:41:48 -07:00
Santosh Pillai a816b4a971 osd: allow one healthy OSD to be drained
One ore more OSDs can be down and PGs can still be active+clean (data
was rebalanced to other available OSDs). This PR sets
maxunavailable=1+downOSDs to allow one healthy to be drained.

Signed-off-by: Santosh Pillai <sapillai@redhat.com>
2025-03-26 10:40:46 +05:30
Travis Nielsen c7e5a4c236 tests: enable csi operator for go test suites
Create the CSI operator in the go integration test suites
to test the new CSI operator scenarios. For the upgrade
test suite, enable the CSI operator after the upgrade
to verify the working cluster after it is enabled.

Signed-off-by: subhamkrai <srai@redhat.com>
2025-03-19 21:02:05 +05:30
Blaine Gardner 0e33536539 object: disallow unsafe OBC fields by default
Implement an allow list mechanism that disables potentially unsafe OBC
fields by default. OBC fields beyond `maxObjects` and `maxSize` don't
neatly fit into the OBC framework as it was originally envisioned and
implemented.

Some of the newly added configs could allow users to cause confusion for
themselves. Others might allow users to hijack others buckets. Some
might allow bricking the entire S3 store.

Out of an abundance of safety, allow-list the known-safe options by
default, and require administrators to enable potentially troublesome
options via the new operator-level config
`ROOK_OBC_ALLOW_ADDITIONAL_CONFIG_FIELDS`.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2025-02-12 14:18:01 -07:00
Steven Kreitzer 463d9fb420 csi: csi-snapshotter flag typo; upgrade csi-snapshotter
Signed-off-by: Steven Kreitzer <skre@skre.me>
2024-12-18 09:09:29 -06:00
df511fb58f ci: update golangci-lint to the latest version (v1.62)
The ci was using a pretty old version og golangci-lint.
This updates to the latest version.

Additionally, it  silences some
gosec integer conversion overflow false positves
and fixes some real errors of this category
 and string format errors found by golangci-lint, while at it.

Co-authored-by: Blaine Gardner <b.blaine.gardner@gmail.com>
Co-authored-by: Travis Nielsen <tnielsen@redhat.com>
Signed-off-by: Michael Adam <obnox@samba.org>
2024-12-14 14:47:30 +01:00
Joshua Hoblitt 57b7eeec80 object: add httpClient param to object.NewS3Agent()
To allow the caller to pass in their own transport when testing.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-12-12 10:20:41 -07:00
Travis Nielsen 6db75b76b8 ci: use correct ceph-ci repo
The repo should be quay.ceph.io, instead of quay.io

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-12-11 15:24:08 -07:00
Travis Nielsen 85375bf073 ci: use ceph-ci instead of daemon-base images
Ceph has changed the image build process to only require a
dockerfile and stop using the ceph-container repo. The
daily images are pushed to the quay.io/ceph-ci/ceph repo,
so the Rook CI will now start using those images.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-12-11 14:04:46 -07:00
Travis Nielsen 506407b5ea tests: upgrade from rook 1.15 to master
The upgrade tests in master have been upgrading from 1.14 to
master. In anticipation of the v1.16 release, we change
the upgrade tests to start from v1.15 to test if there
are any regressions in the supported upgrades.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-11-22 10:40:02 -07:00
Travis Nielsen b229240faa ci: default to the latest stable squid instead of devel
The devel images have been fairly stable for Rook to test
against, but on occasion there are regressions from
Ceph development that affect the Rook CI. For stability during
Rook development, use the latest stable version of ceph for
PRs, master, and release tests. The daily CI will still use
the devel images from Ceph.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-11-04 14:10:36 -07:00
Travis Nielsen b52ba6baca test: wait for mon daemons rather than mon canaries
The mon canaries may be created even when the mon daemons
are not created thereafter during the integration tests.
Therefore, the integration tests need to also query a label
specific to the mon daemon so the canaries are not a distraction
to the test.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-10-25 09:17:02 -06:00
Travis Nielsen 7ed77ddd13 core: remove obsolete creation of v1beta1 pruner cron jobs
The v1beta1 cron jobs have been obsolete since K8s 1.21,
and Rook has not supported that version of K8s
for many moons, so we can remove the obsolete code
for the handling of v1beta1 cron jobs for crash pruning.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-10-14 17:13:06 -06:00
Travis Nielsen b665d7a7b7 core: remove support for ceph quincy
Given that Ceph Quincy (v17) is past end of life,
remove Quincy from the supported Ceph versions,
examples, and documentation.

Supported versions now include only Reef and Squid.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-10-03 11:12:55 -06:00
Travis Nielsen 810de394e7 helm: add enforce host network setting
The ROOK_ENFORCE_HOST_NETWORK option was implemented recently
and now we add the helm setting to expose this new setting
in the rook chart.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-10-02 15:14:46 -06:00
Travis Nielsen 8b60c52f31 build: generate the local build tag with docker io
The docker.io image prefix is expected to be prepended
to the image names in the test images. This was missed
in 14550 related to some CI tests, which was now causing
the CI failures in the 1.15 branch where the search and
replace was missing the new docker.io prefix.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
(cherry picked from commit 3045076db8)
2024-08-21 10:21:31 -06:00
Praveen M a1ddf4535d csi: update csi sidecars' image version
Below csi sidecars are updated with latest available versions

csi-resizer: v1.11.1
csi-provisioner: v5.0.1
csi-attacher: v4.6.1
csi-snapshotter: v8.0.1
csi-node-driver-registrar: v2.11.1

Signed-off-by: Praveen M <m.praveen@ibm.com>
2024-08-20 22:08:19 +05:30
ee8bcad49d rgw: add support for keystone auth + swift/s3
For the specification see:
<https://github.com/rook/rook/blob/master/design/ceph/object/swift-and-keystone-integration.md>

* extend the API object specs for swift and keystone integration

* adapt rgw to the new go-ceph version

  - The parameter lists of the API call have changes, as parameters
    ignored by the RGW Admin Ops API are no longer serialized, therefore
    the mock has to be adapted.

  - There is now validation for the user keys that are passed to the
    User get API, therefore things failed when we had empty keys in our
    User proxy object.

* expand the reconcile loop for the swift and keystone integration

* fix minor mistakes in design document

* add env var to pass extra args to minikube

  Minikube decides CPU cores and memory automatically based on the
  available resources on the machine which may be insufficient to
  run rook. This commit adds an environment variable to add arbitrary
  arguments to the minikube command, so both can be specified if
  desired.

* integration tests for swift and keystone

  The new integration of swift or s3 and keystone support by rook
  does not have any integration tests yet.

  This commit introduces integration tests for swift and keystone. The
  tests are done against a minimal keystone setup (keystone container
  image from Yaook-project (https://yaook.cloud), sqlite as database
  backend, cert-manager and trust-manager for test certificate setup).

  To prevent hardcoded credentials, passwords are generated
  by the tests. The integration tests use the openstack client
  (keystone- and swift-functionality) (https://docs.openstack.org/
  python-openstackclient/ latest/). This was a concious design decision
  to use client tooling as close as possible to the end user instead of
  using other go-libraries (such as gophercloud).

* add documentation on swift and keystone

  Currently there is no documentation on the use of Swift to access
  an object store as well as the use of OpenStack keystone for
  authentication.

  This commit adds documentation on the use of Swift and OpenStack
  keystone, as well as CRD-related documentation and an example setup.

* add integration tests for S3 via keystone

  This commit introduces integration tests for s3 and keystone. The
  tests are run against the same minimal keystone setup that the tests
  for swift and keystone use.

  The integration tests use the aws s3 client to use client tooling as
  close as possible to the end user instead of using other go-libraries.

Co-authored-by: Jan Klippel <jan.klippel@uhurutec.com>
Co-authored-by: Silvio Ankermann <silvio.ankermann@cloudandheat.com>
Signed-off-by: Sebastian Riese <sebastian.riese@cloudandheat.com>
Signed-off-by: Jan Klippel <jan.klippel@uhurutec.com>
Signed-off-by: Silvio Ankermann <silvio.ankermann@cloudandheat.com>
2024-08-08 14:26:21 +02:00
Travis Nielsen 6c36bc47b2 Merge pull request #14487 from travisn/upgrade-from-1.14
tests: Upgrade from rook 1.14 to master
2024-07-24 13:37:23 -06:00
Travis Nielsen 043b446675 tests: retry helm upgrade during upgrade tests
The helm upgrade tests have been failing frequently, but not
always, on the oldest version of K8s that is tested in the CI
for the past few months. Add a retry to attempt to get
the CI passing more consistently.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-07-24 08:14:21 -06:00
Travis Nielsen 099c603a43 tests: upgrade from rook 1.14 to master
The upgrade tests in master have been upgrading from 1.13 to
master. In anticipation of the v1.15 release, we change
the upgrade tests to start from v1.14 to test if there
are any regressions in the supported upgrades.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-07-24 08:12:31 -06:00
Travis Nielsen 1d8d55e1ad tests: daily ceph upgrade tests on rook master
The daily ceph upgrade tests were running on Rook v1.13.
This was causing the squid upgrade tests to fail since
1.13 does not support Squid. The purpose of the upgrade
tests is to test the ceph upgrades, therefore the daily
tests will just test them based on rook master.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-07-23 16:19:19 -06:00
Travis Nielsen 22d4139b74 core: add support for ceph squid
With the release of the first squid RC, we add squid
to the supported versions and add tests to run
Rook against the squid release.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-07-15 10:04:32 -06:00
Jiffin Tony Thottan ba40f84123 object: update cosi images
Updating images for ceph cosi driver and side car.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2024-06-04 19:32:45 +05:30
Travis Nielsen e479b051bc osd: configure cluster full settings when osds fill up
When the clusters reach full, nearfull, or backfill full thresholds
ceph will raise health warnings and stop allowing IO or backfill
depending on the threshold. These settings require special ceph
commands instead of being generic ceph config. Allow these settings
to be set from the CephCluster CR in the spec.storage
section.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-05-30 12:10:41 -06:00
Praveen M faf7837621 csi: update csi sidecars' image version
Below sidecars are updated with latest available versions

csi-node-driver-registrar: v2.10.1
csi-resizer: v1.10.1
csi-provisioner: v4.0.1
csi-attacher: v4.5.1
csi-snapshotter: v7.0.2

Signed-off-by: Praveen M <m.praveen@ibm.com>
2024-04-25 18:58:00 +05:30
Travis Nielsen 499a09ed72 Merge pull request #14052 from sp98/cleanup-radosnamespace
Cleanup RADOS namespace with forced deletion annotation
2024-04-12 11:11:47 -06:00
sp98 f6b1449faa core: cephblockpoolRadosNamespace cleanup
Clean up pool images and snapshots in the
radosnamespace

Signed-off-by: sp98 <sapillai@redhat.com>
2024-04-12 21:49:49 +05:30
Madhu Rajanna f57a8b6bbe subvolumegroup: add support for size and datapool
cephfs subvolumegroup supports creating svg
with quota and the datapool, This PR adds the
support for the same.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-04-10 16:40:56 +02:00
Travis Nielsen 2e8468a47c core: upgrade test from 1.13 to master
The upgrade test should always upgrade from the
previous minor release to the latest master. With 1.14
releasing soon, now we upgrade from 1.13 to master,
to confirm if there are any upgrade issues to 1.14.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-03-07 16:31:09 -07:00
Madhu Rajanna 0d5bd70194 csi: install vgs CRD in tests
update the snapshot controller to 7.0.1
and install new Volumegroup CRD's

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-03-01 09:15:17 +01:00
Travis Nielsen d77cee791c Merge pull request #13362 from parth-gr/service-account-deafult
core: Set default service account on all Ceph daemons
2024-02-28 10:52:12 -07:00
parth-gr f7a9d8ff7b core: added rook-ceph-default service account
When a private docker registry is used and an
image pull secret is specified in the chart,
the pods with default Service Account fail to pull
the image due to authentication issues.
Added rook-ceph-default service account and modify the pods
specifications by adding the serviceAccountName

closes: https://github.com/rook/rook/issues/12786

Closes: https://github.com/rook/rook/issues/6673
Co-authored-by: Tareq Sharafy <tareq.sha@gmail.com>
Signed-off-by: parth-gr <partharora1010@gmail.com>
(cherry picked from commit 737fb099fe)
Signed-off-by: parth-gr <partharora1010@gmail.com>
2024-02-28 13:32:55 +05:30
Sunnatillo 3ad456c6a2 build: uplift prometheus operator version to v0.71.1
This commit uplifts prometheus operator version to v0.71.1.

Signed-off-by: Sunnatillo <sunnat.samadov@est.tech>
2024-02-27 20:00:25 +02:00
travisn ef13dd3edc mgr: remove remaining pg_autoscaler examples
The pg_autoscaler is always enabled by ceph and cannot be disabled.
In a previous PR the pg_autoscaler config was removed from the main example.
Now the remaining config for the pg_autoscaler is removed as well.

Signed-off-by: travisn <tnielsen@redhat.com>
2024-02-14 11:13:29 -07:00
subhamkrai abc272c91c test: use mounter kernal instead of fuse
this kernal version is greater than 5.11 let's
use mounter kernal instead of fuse.

Signed-off-by: subhamkrai <srai@redhat.com>
2024-02-06 19:11:04 +05:30
Madhu Rajanna c35a8532aa csi: option to customize csi driver name prefix
For now we are using the operator namespace name
as the prefix for the csi driver, This PR provides
an option for the users if someone wants to have
their own prefix for the csi driver, if someone tries
to change the prefix for existing csi driver rook
operator will fail to reconcile the csi driver.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2024-01-29 10:54:25 +01:00
Praveen M a80396df1b csi: update cmdline args as used by ceph-csi
This commit adds cmdline args to enable
1. RecoverVolumeExpansionFailure
2. PreventVolumeModeConversion
3. HonorPVReclaimPolicy

Signed-off-by: Praveen M <m.praveen@ibm.com>
2024-01-12 15:24:07 +05:30
subhamkrai d8766ff871 ci: remove ceph SVGs in helm test
Both the helm tests are failing because,
```
2023-12-19 08:47:06.136640 E | ceph-file-controller: failed to reconcile CephFilesystem "helm-ns/ceph-filesystem-test". CephFilesystem "helm-ns/ceph-filesystem-test" will not be deleted until all dependents are removed: CephFilesystemSubVolumeGroups: [ceph-filesystem-test-csi]
```
So, let's remove the ceph SVGs before removing Ceph filesystem.

Signed-off-by: subhamkrai <srai@redhat.com>
2023-12-19 17:05:21 +05:30