Commit Graph
1018 Commits
Author SHA1 Message Date
Prabhala Tara Aasrita ebf90170bc pool: support CRUSH MSR rules for EC pools
Added failureDomains and osdsPerDomain fields to the
ErasureCodedSpec, which maps to the crush-num-failure-domains and
crush-osds-per-failure-domain Ceph EC profile parameters. This enables
creating EC pools that distribute chunks across fewer, larger hosts
without needing one host per data chunk.

Signed-off-by: Prabhala Tara Aasrita <taraprabhala@Prabhalas-MacBook-Pro.local>
(cherry picked from commit 715f38de91)
2026-07-28 19:46:04 +00:00
Travis Nielsen 8c5ca91584 build: update the version to v1.20.3
For the patch release update the docs and examples
to v1.20.3

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2026-07-28 11:55:57 -06:00
raaizik ec9028a9f8 doc: document CephNFS custom port and exposure examples
Document spec.server.port for host-network port conflicts, and describe
how user-managed LoadBalancer and NodePort Services must align port and
targetPort with the CR.

Signed-off-by: raaizik <raaizik@yahoo.com>
Co-Authored-By: Blaine Gardner <b.blaine.gardner@gmail.com>
(cherry picked from commit a400ae6fd5)
2026-07-28 14:50:05 +00:00
raaizik 7c4787691d nfs: support custom NFS server port
When NFS runs with host networking, port 2049 may already be in use.
Add CephNFS spec.server.port (default 2049), wire it through Ganesha
config, the operator Service, and probes, and regenerate CRDs.

Signed-off-by: raaizik <raaizik@yahoo.com>
(cherry picked from commit 5e36fa4bc3)
2026-07-28 14:50:04 +00:00
Jeff Wallace cf1acb42c7 monitoring: align pool growth alert with ceph mixin
Aggregate pool usage by pool before predict_linear to avoid duplicate series after mgr pod replacement, and add a one-hour hold time to match the source rule update in ceph/ceph#68621.

Signed-off-by: Jeff Wallace <jeff@tjwallace.ca>
(cherry picked from commit 5119f3aeb4)
2026-07-13 17:44:49 +00:00
Michael Adam 4457429406 build: set the release version to v1.20.2
For the patch release update the docs and images to
v1.20.2.

Signed-off-by: Michael Adam <obnox@samba.org>
2026-07-07 12:33:29 -06:00
subhamkrai 6b106fc03f csi: update csi-operator version to v1.0.4
Updating csi-operator to latest v1.0.4 and
updating the required doc changes as well.

Signed-off-by: subhamkrai <srai@redhat.com>
(cherry picked from commit a3e02e607d)
2026-07-07 11:15:12 -06:00
Joshua Hoblitt ac686a02c8 docs: fix typos and grammar in code comments
Fix duplicate words, incorrect articles (a/an), it's/its, and other small
grammar mistakes in Go comments and user-facing messages across pkg/, cmd/,
and tests/.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
(cherry picked from commit c0eb360041)
2026-07-01 09:23:27 -07:00
Oded Viner 8ae7637750 security: restrict mgr NetworkPolicy to ingress-only
The MGR watch-active sidecar needs Kubernetes API access to
read configmaps and monitor active-standby state. The API
server is host-networked and cannot be targeted by
pod/namespace selectors, making egress restrictions
impractical.

Switch the rook-ceph-mgr NetworkPolicy from egress-only to
ingress-only:
- Allow MON/OSD/MDS/tools pods on ports 6800-7300
- Allow Prometheus scraping on port 9283
- Remove egress rules that blocked API server access and
  caused CrashLoopBackOff in the watch-active container

Signed-off-by: Oded Viner <oviner@redhat.com>
(cherry picked from commit 9cec9780fd)
2026-06-30 17:41:34 +00:00
Joshua Hoblitt dcd4dfb2bd docs: fix function comments to match their declaration names
Several godoc comments led with a stale or incorrect identifier, left
over from renames, exported/unexported changes, copy-paste between
sibling declarations, or plain typos. As a result the documented name no
longer matched the function, method, type, or var it describes. Correct
each leading word to the name of the declaration it documents.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
(cherry picked from commit 49612461a4)
2026-06-29 19:04:45 +00:00
subhamkrai 87e7082d48 core: implement ceph health warning mute
this commit implement api to configure
ceph health warning mute/unmute.

Signed-off-by: subhamkrai <srai@redhat.com>
(cherry picked from commit 9a6c5842bc)
2026-06-29 15:50:37 +00:00
subhamkrai 789876785e core: add api changes to mute ceph warnings
adding api changes to mute/unmute ceph warnings
based on user configuration. The field is map[string]string
key is ceph warning and value is duration how longs
the warnings will be muted.

Signed-off-by: subhamkrai <srai@redhat.com>
(cherry picked from commit ff5f3baa58)
2026-06-29 15:50:37 +00:00
Joshua Hoblitt cfec82af69 external: add timeout to rgw admin ops api request
The rgw endpoint validation issued an HTTP request to the admin ops
api without a timeout. If the RGW is accepting connections but slow to
respond, for example right after the object store was created, the
script hangs indefinitely instead of reporting a validation error that
the caller could retry on.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
(cherry picked from commit 459c4bebe9)
2026-06-26 19:31:16 +00:00
parth-gr bf85ab04b9 external: volumeattachment should be deleted during unmount
before the csi op, the unblish grpc call was not present,
and it has no op
But with csi op, the unpublish grpc is called before the
volumeattachment get remove, and the unpublish call need a
unpublish secret, currently it is getting the secret from the
client profile, but the client profile secret is hardcoded to default
So to override this secret we are adding the secret name in the
storageclass parameter

Signed-off-by: parth-gr <partharora1010@gmail.com>
(cherry picked from commit 88e31185dc)
2026-06-26 15:08:41 +00:00
kavirakesh14 8e0e66d324 operator: fail reconcile if rook-config-override lacks trailing newline
Signed-off-by: kavirakesh14 <kavirakesh007@gmail.com>
(cherry picked from commit 619b800b67)
2026-06-24 16:49:17 +00:00
Oded Viner 448154e0d3 security: add example NetworkPolicy CRs for Ceph operand pods
Add a single example YAML with NetworkPolicy definitions
for all Ceph operand pods (mon, osd, mgr, mds, exporter,
osd-prepare, crashcollector, tools).
Users can apply these policies to restrict egress/ingress
traffic for Rook-Ceph daemon pods.

Signed-off-by: Oded Viner <oviner@redhat.com>
(cherry picked from commit 9dc70051a8)
2026-06-17 18:54:41 +00:00
subhamkrai e2600812e5 build: update ceph version to latest v20.2.2
updating the ceph version from v20.2.1 to v20.2.2

Signed-off-by: subhamkrai <srai@redhat.com>
(cherry picked from commit ad26ebdab0)
2026-06-17 17:01:15 +00:00
Michael Adam efe29fae94 build: set the release version to v1.20.1
For the patch release update the docs and images to
v1.20.1.

Signed-off-by: Michael Adam <obnox@samba.org>
2026-06-16 13:08:01 -06:00
parth-gr adcb56ee70 core: add a install guide for tnf
add a install guide for tnf
1) Add a drbd install script
2) add a drbd instal doc

assisted-by: anthropic-ai/claude-code

Signed-off-by: parth-gr <partharora1010@gmail.com>
(cherry picked from commit 8171c3ed3b)
2026-06-15 10:12:36 +00:00
subham rai 3afc8f2adb Merge pull request #17721 from rook/mergify/bp/release-1.20/pr-17701
nvmeof: fetch gateway image from ceph config when not in CR (backport #17701)
2026-06-12 12:29:57 +05:30
Oded Viner 2a2dc44cb7 nvmeof: fetch gateway image from ceph config when not in CR
Make the NVMe-oF gateway image optional in the CR spec.
When not specified, the operator fetches the image from
the Ceph mon config store using the key
mgr/cephadm/container_image_nvmeof. Falls back to the
hardcoded default if the config is unavailable.

Signed-off-by: Oded Viner <oviner@redhat.com>
(cherry picked from commit 8b4fd67e17)
2026-06-11 18:03:36 +00:00
parth-gr ba65c926c6 external: update the external cluster to make use of csi op
updated the external cluster doc, and helm and manifest
install to make use of csi operator as it is the default
offering now

Signed-off-by: parth-gr <partharora1010@gmail.com>
(cherry picked from commit dbc8d2a541)
2026-06-11 15:40:26 +00:00
subhamkrai 07a1a68b1f docs: add rook compatible ceph csi driver values
adding rook compatible Ceph-Csi driver values.yaml
file making sure, upgrading to 1.20 doesn't break
when csi-driver is moved to admin.

Co-authored-by: Travis Nielsen <tnielsen@redhat.com>
Signed-off-by: subhamkrai <srai@redhat.com>
(cherry picked from commit 774054c45e)
2026-06-05 21:25:59 +00:00
subhamkrai 426225a60a csi: csi-addons should be disabled by default
having csi-addons enabled by default is causing random
pod restart on non-openshift cluster. Let's disable
it by default.

Signed-off-by: subhamkrai <srai@redhat.com>
(cherry picked from commit 34b0a87c9e)
2026-06-05 20:54:38 +00:00
Michael Adam 764715b92c build: update release version to v1.20.0
For the minor release v1.20, update the examples and docs

Signed-off-by: Michael Adam <obnox@samba.org>
2026-06-02 19:19:14 +02:00
subhamkrai 92b50220d6 docs: add few examples settings for new csi management
this command adds some examples on how users can add/update
the settings based on new way of managing CSI resources.

Signed-off-by: subhamkrai <srai@redhat.com>
(cherry picked from commit fbef1d755e)
2026-06-02 16:32:36 +00:00
subhamkrai 51868449e9 operator: add csi operator cr default in openshift example
adding csi operator CR default values to operator-openshift
file for cluster running on openshift.

Signed-off-by: subhamkrai <srai@redhat.com>
(cherry picked from commit e4e6d3958a)
2026-05-27 23:18:37 +00:00
subhamkrai e10393f5a2 object: add TLS 1.3 cipher suite support for RGW beast frontend
adding new tls ssl_ciphersuites supporting tls 1.3 and the existing,
ssl_cipher supports tls 1.2 and below. Adding, the docs and unit-test
changs as well.

Signed-off-by: subhamkrai <srai@redhat.com>
(cherry picked from commit b70a0c9257)
2026-05-27 15:52:52 +00:00
subhamkrai 1ad231b355 build: update csi-operator to v1.0.1
Updating csi-operator to latest v1.0.1 and
updating the required doc changes as well.

Signed-off-by: subhamkrai <srai@redhat.com>
(cherry picked from commit 34c5ad7049)
2026-05-27 13:50:27 +00:00
Praveen M c616cb918f csi: update ceph-csi image and sidecars
Update ceph-csi to v3.17.0 and CSI sidecars:
- csi-provisioner v6.1.1 -> v6.2.0
- csi-attacher v4.11.0 -> v4.12.0
- csi-node-driver-registrar v2.16.0 -> v2.17.0

Signed-off-by: Praveen M <m.praveen@ibm.com>
(cherry picked from commit 449d1baeb7)
2026-05-27 11:25:18 +00:00
Joshua Hoblitt 69eddeaa27 helm: add cluster label to prom persistent-volume-alert.rules
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
(cherry picked from commit ec75182dad)
2026-05-26 19:09:17 +00:00
subhamkrai ec3953ea34 csi: update csi-operator to v1.0.0
This commit update the csi-operator to latest v1.0.0.
we need to manually patch the csi drivers with the new serviceAccount
name that are being creating based on the latest ceph-csi-operator
release v1.0.0 where serviceAccount are being separate from csi-operator
chart.

co-authored-by: Travis Nielsen <tnielsen@redhat.com>
Signed-off-by: subhamkrai <srai@redhat.com>
(cherry picked from commit 06452991bf)
2026-05-21 15:22:41 -06:00
Oded Viner 81e10ad5bf security: remove net_raw from operator-openshift.yaml scc
net_raw is listed in the rook-ceph scc allowedcapabilities
but no daemon uses it — all pods explicitly drop net_raw.
remove it to align with the go scc helper and helm charts.

Signed-off-by: Oded Viner <oviner@redhat.com>
(cherry picked from commit 572527d476)
2026-05-14 17:09:43 +00:00
subhamkrai 536909a58b pool: add stripe_unit with erasure-code-profile set
this commit adds flag stripe_unit for the command
ceph osd erasure-code-profile set [flags]. This key
increase perfomance for ec pool. The default value
is 4kib/4096 bytes.

Signed-off-by: subhamkrai <srai@redhat.com>
(cherry picked from commit 9fb0582dd6)
2026-05-14 16:38:55 +00:00
subhamkrai a9d29bdec6 csi: move csi management to admin
Going forward, admin will manage the csi operator
CR's and rook will only manage Ceph Connection cr
and client Profile cr.

The old csi driver is completely removed from Rook
and can no longer be used starting in Rook v1.20.

The upgrade guide will contain the needed transition steps
for managing the csi operator settings.

Signed-off-by: subhamkrai <srai@redhat.com>
(cherry picked from commit 4eefad42e8)
2026-05-12 12:49:21 -10:00
Travis Nielsen 4182fe67a1 core: declare stable concurrent cluster reconciles
The ROOK_RECONCILE_CONCURRENT_CLUSTERS feature was implemented
in v1.19. This feature has been stable, with no related issues
reported. The feature is tested in the CI with no known
stability issues. Let's declare this feature as stable.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
(cherry picked from commit 45ec32e513)
2026-05-11 22:50:18 +00:00
subhamkrai 3445e2be3a rgw: add option for tls and cipher in objectstore
this commit add option in the ceph objecstore CR
to configure TLS profile and TLS ciphersuite for
rgw beast.

Signed-off-by: subhamkrai <srai@redhat.com>
(cherry picked from commit 01ef98c1e3)
2026-05-06 17:13:59 +00:00
Travis Nielsen 82e9c4de51 core: update all docs and examples to v20.2.1
With the default version now being v20.2.1, also update
all of the examples, documentation, and default CI to run
with that version

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
(cherry picked from commit 62a9debceb)
2026-04-28 22:24:53 +00:00
Asish Kumar 0b3605dd84 pool: clean up unused crush rules
Clean up stale CRUSH rules after the Ceph mgr starts so rules left behind by pool failure-domain or device-class changes do not accumulate indefinitely.

The cleanup is guarded by a package-level RWMutex. Pool create and update paths hold the read lock while creating and assigning CRUSH rules, while cluster-wide cleanup holds the write lock before listing pools and deleting unused rules. This keeps pool reconciles parallel with each other while preventing cleanup from deleting a rule that another reconcile has just created but not yet attached to a pool.

Keep direct pool-delete cleanup for the pool's current CRUSH rule, make the cluster-wide cleanup best-effort across all unused rules, and add an operator-level ROOK_DELETE_UNUSED_CRUSH_RULES setting for clusters that need to leave unused custom rules in place.

Document the operator and Helm settings, regenerate the Helm chart docs, and add a pending release note for the default cleanup behavior.

Signed-off-by: Asish Kumar <officialasishkumar@gmail.com>
(cherry picked from commit 24a35e4e74)
2026-04-24 22:32:15 +00:00
Elias Carter 6e978043d7 doc: fix out of date references to default PgHealthyRegex
Signed-off-by: Elias Carter <elias@dropbox.com>
(cherry picked from commit 5a065948e2)
2026-04-20 17:53:03 +00:00
Michael Adam 407d152879 build: set the release version to v1.20.0-beta.0
For the new 1.20 branch, update the examples and docs
to the v1.20.0-beta.0 tag.

Signed-off-by: Michael Adam <obnox@samba.org>
2026-04-17 17:21:34 +02:00
Alexander Degenhart 17b98da89e csi: add 'CSIMetadataRadosNamespace' parameter to CephFilesystemSubVolumeGroup
This parameter is written to .spec.cephFS.radosNamespace of the generated
ClientProfile.

The parameter is called 'CSIMetadataRadosNamespace' to clarify that it is used
for CSI metadata and unrelated to the actual CephFS (meta)data.

Context:

The ceph-csi CephFS plugin stores additional metadata related to PV(C)s
in RADOS objects in the metadata pool of the CephFS.
By default those objects are stored in the 'csi' RADOS namespace.

For a multi-tenant CephFS setup (that is used by multiple K8s Clusters/
ceph-csi drivers) segregating those additional objects into separate RADOS
namespaces is desireable so the clusters can not modify the metadata of other
clusters (enforced by appropriate ceph client capabilities).

'ceph-csi' implemented this via the `cephFS.radosNamespace` config option for
cluster entries in the `ceph-csi-config` ConfigMap with https://github.com/ceph/ceph-csi/pull/4661.

The `ceph-csi-operator` added support for that config entry by adding
'radosNamespace' to the 'CephFsConfigSpec' of the 'ClientProfile' with
https://github.com/ceph/ceph-csi-operator/pull/165.

Signed-off-by: Alexander Degenhart <degenhart@fim.uni-passau.de>
2026-04-16 00:31:29 +02:00
Travis Nielsen 8dabe11973 Merge pull request #17324 from gonzolino/rook-ceph-mgr-role-secondary
mgr: Add missing RBAC role for ceph-mgr in secondary clusters
2026-04-08 11:43:21 -06:00
Travis Nielsen abacf2e367 Merge pull request #16836 from subhamkrai/update-use-tentacnle
build: use ceph tentacle v20 as default version
2026-04-08 11:20:11 -06:00
Santosh Pillai 700220bfed Merge pull request #17262 from mateenali66/add-cleanup-job-example
deploy/examples: add standalone cleanup-job.yaml
2026-04-08 22:44:47 +05:30
Daniel Gonzalez 6e8bb63705 manifest: add missing rook-ceph-mgr role to secondary cluster
Fixes: https://github.com/rook/rook/issues/17323

Signed-off-by: Daniel Gonzalez <daniel@gonzalez-nothnagel.de>
2026-04-08 15:43:11 +02:00
subhamkrai 6285afc0a4 build: use ceph tentacle v20 as default version
let's use ceph tentacle as default version in deployment

Signed-off-by: subhamkrai <srai@redhat.com>
2026-04-08 15:39:17 +05:30
Travis Nielsen cc626020ba Merge pull request #17250 from sp98/implement-cosuser-accounts
rgw: add accountRef to CephObjectStoreUser CR
2026-04-02 15:56:30 -06:00
Mateen Anjum e3b4217458 manifest: add standalone cleanup-job.yaml example
Add a standalone Job manifest mirroring the cleanup logic the operator
executes via cleanUpJobTemplateSpec when a CephCluster is deleted with
cleanupPolicy enabled.

Useful when the operator-managed cleanup did not run (e.g. force-deleted
cluster) or a node needs manual cleanup outside normal operator flow.

Secrets (ROOK_MON_SECRET, ROOK_CLUSTER_FSID) are sourced from the
rook-ceph-mon secret via secretKeyRef. Namespace is injected via the
Downward API. Only dataDirHostPath and node hostname need manual input.

Closes #17255

Signed-off-by: Mateen Anjum <mateenali66@gmail.com>
2026-04-02 09:50:11 -04:00
Tarun Gupta Akirala 9803964d03 cosi: update default sidecar image version
Encountered this bug in current image kubernetes-sigs/container-object-storage-interface#173
which is fixed in recent release via kubernetes-sigs/container-object-storage-interface#197

Signed-off-by: Tarun Gupta Akirala <tarun.akirala@nutanix.com>
2026-03-31 14:23:20 -07:00