Add the following scenario:
* simple osd on pvc
* osd on pvc with db device
* osd on pvc with wal device
* encrypted simple osd on pvc
* encrypted osd on pvc with db device
* encrypted osd on pvc with wal device
Signed-off-by: Sébastien Han <seb@redhat.com>
When the Ceph cluster runs on PVC and the OSDs are encrypted we can
store LUKS's Key Encryption Key inside a Key Management System. Today,
Rook only supports HashiCorp Vault: https://www.vaultproject.io/
The CephCluster has now a new "security" field which will plug onto the
KMS. Here is an example:
security:
kms:
tokenSecretName: <name of the secret containing a Vault token, used
to authenticate>
connectionDetails: < a map of strings containing connection
information>
Refer to the ceph-cluster-crd documentation to lear more.
Closes: https://github.com/rook/rook/issues/6105
Signed-off-by: Sébastien Han <seb@redhat.com>
To be able to switch to helm v3, helm itself needs to be downloaded from
get.helm.sh. The old location from googleapis.com will only contain
helm v2 binaries. See [1].
[1] https://helm.sh/blog/get-helm-sh/
Signed-off-by: Thomas Bechtold <tbechtold@suse.com>
We can't use vm-drivers other than "docker" or "none" in minikube
scripts. It's because there is no device for OSD.
Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
Download the pre-defined helm by default to make the integration test simpler.
As a result, we can make PATH/TEST_HELM_PATH environment variable optional.
In addition, the default helm path can be simplified that doesn't include arch and os.
Signed-off-by: Takashi IIGUNI <iiguni.tks@gmail.com>
Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
It's messy to answer `y` everytime in `tests/script/kubeadm.sh clean.`
Since the cluster only exists for testing, it's safe to reset without prompting.
Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
This commit will remove "sudo rm /usr/local/bin/kube*" and "sudo rm kubectl" in "tests/scripts/kubeadm.sh".
I think that CI-test doesn't make those files.
Signed-off-by: tenzen-y <toyonomajyutushi@yahoo.co.jp>
It's not necessary to use random string for mon directory.
In addition, current implementation leaves garbage under /var/lib/rook.
Signed-off-by: Takashi IIGUNI <iiguni.tks@gmail.com>
moves the admission-controller server to use controller-runtime library for better support, maintainibility of code.
Signed-off-by: Vineet Badrinath <vbadrina@redhat.com>
Update the base operator image and cluster examples to use the latest
octopus release v15.2.4. Also cleanup some old examples and unit tests
that were still based on mimic.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
adds deploy.sh script to deploy validatingwebhookconfiguration and create secrets.
adds new command ceph admission-controller to start webhook servers.
adds validation for various rook custom resources
Signed-off-by: Vineet Badrinath <vbadrina@redhat.com>
The device name for OSD is fixed to /dev/xvdc. It works fine in the CI.
However, the name would be different in the developer's local environment.
Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
kubeadm installer tries to install the fixed versions of some packages.
So if the newer versions are already installed, this script fails.
Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
After running `swapoff -a`, systemd re-enable swap soon.
We should stop the corresponding unit to avoid this problem.
Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
- `helm_read` is not a command, but a variable
- If `helm` was installed in `helm.sh up`, the following `heml.sh clean`
fails since `helm_rest` can't find the installed `helm`.
Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
Only kubectl for amd64 is currently available.This modification adds
arm64 version of kubectl that can successfully deploy kubernetes on
arm64 machine.
Signed-off-by: Haichao Li <haichao.li@arm.com>
This commit adds a shell script to provision localPath PVs over the
disks in the nodes for OSDs and random host directoris for mons.
Note: currently it is hardcoded to select disk of `/dev/xvdb`.
Signed-off-by: Ashish Ranjan <ashishranjan738@gmail.com>
The minio operator has not had community support nor
any updates since being added to Rook. Support is being
removed from Rook due to this lack of community interest.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
The helper script to start minikube has dead code that is
no longer used. Specifically, the flex driver config isn't needed
anymore and the RBAC rules are all configured in the manifests.
Neither is there a need to have a restart option on minikube.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
Helm requires some changes to be compatible with k8s 1.16.
The deployment needs to use v1 apiVersion and a selector
needs to be added. A tiller service account is also required.
Signed-off-by: travisn <tnielsen@redhat.com>
There is generally not a need to launch a specific version
of k8s, so just let minikube pick the latest version
to launch.
Signed-off-by: travisn <tnielsen@redhat.com>
The ceph image isn't needed every time the rook image is updated.
Thus, make it optional to copy the ceph image into the cluster.
Pushing the ceph image can be done by uncommenting in the script
when needed.
Signed-off-by: travisn <tnielsen@redhat.com>
Default to virtualbox driver. `minikube config get vm-driver` does not
work when default is used.
Fixes#3208.
Signed-off-by: Kaushal M <kshlmster@gmail.com>
This fixs that the `git describe` is run with the `-C REPO_PATH` flag to
correctly get the latest tag of the k8s-vagrant-multi-node repo and not
the Rook repository.
Signed-off-by: Alexander Trost <galexrt@googlemail.com>
The minikube script now uses the proper disk path (vda) when minikube is
configured to run with the libvirt driver.
Signed-off-by: Kaushal M <kshlmster@gmail.com>
To simplify the deployment of Rook, both the operator and cluster crd are now created in the
same namespace in the examples. By default the operator will only manage a cluster crd
in the same namespace instead of watching for clusters in all namespaces. To manage a cluster
in another namespace, the roles in latter half of operator-common.yaml need to point to the new
namespace and the operator env var ROOK_CURRENT_NAMESPACE_ONLY should be set to false.
Signed-off-by: travisn <tnielsen@redhat.com>