Added failureDomains and osdsPerDomain fields to the
ErasureCodedSpec, which maps to the crush-num-failure-domains and
crush-osds-per-failure-domain Ceph EC profile parameters. This enables
creating EC pools that distribute chunks across fewer, larger hosts
without needing one host per data chunk.
Signed-off-by: Prabhala Tara Aasrita <taraprabhala@Prabhalas-MacBook-Pro.local>
(cherry picked from commit 715f38de91)
Document spec.server.port for host-network port conflicts, and describe
how user-managed LoadBalancer and NodePort Services must align port and
targetPort with the CR.
Signed-off-by: raaizik <raaizik@yahoo.com>
Co-Authored-By: Blaine Gardner <b.blaine.gardner@gmail.com>
(cherry picked from commit a400ae6fd5)
When NFS runs with host networking, port 2049 may already be in use.
Add CephNFS spec.server.port (default 2049), wire it through Ganesha
config, the operator Service, and probes, and regenerate CRDs.
Signed-off-by: raaizik <raaizik@yahoo.com>
(cherry picked from commit 5e36fa4bc3)
Aggregate pool usage by pool before predict_linear to avoid duplicate series after mgr pod replacement, and add a one-hour hold time to match the source rule update in ceph/ceph#68621.
Signed-off-by: Jeff Wallace <jeff@tjwallace.ca>
(cherry picked from commit 5119f3aeb4)
Updating csi-operator to latest v1.0.4 and
updating the required doc changes as well.
Signed-off-by: subhamkrai <srai@redhat.com>
(cherry picked from commit a3e02e607d)
Fix duplicate words, incorrect articles (a/an), it's/its, and other small
grammar mistakes in Go comments and user-facing messages across pkg/, cmd/,
and tests/.
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
(cherry picked from commit c0eb360041)
The MGR watch-active sidecar needs Kubernetes API access to
read configmaps and monitor active-standby state. The API
server is host-networked and cannot be targeted by
pod/namespace selectors, making egress restrictions
impractical.
Switch the rook-ceph-mgr NetworkPolicy from egress-only to
ingress-only:
- Allow MON/OSD/MDS/tools pods on ports 6800-7300
- Allow Prometheus scraping on port 9283
- Remove egress rules that blocked API server access and
caused CrashLoopBackOff in the watch-active container
Signed-off-by: Oded Viner <oviner@redhat.com>
(cherry picked from commit 9cec9780fd)
Several godoc comments led with a stale or incorrect identifier, left
over from renames, exported/unexported changes, copy-paste between
sibling declarations, or plain typos. As a result the documented name no
longer matched the function, method, type, or var it describes. Correct
each leading word to the name of the declaration it documents.
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
(cherry picked from commit 49612461a4)
this commit implement api to configure
ceph health warning mute/unmute.
Signed-off-by: subhamkrai <srai@redhat.com>
(cherry picked from commit 9a6c5842bc)
adding api changes to mute/unmute ceph warnings
based on user configuration. The field is map[string]string
key is ceph warning and value is duration how longs
the warnings will be muted.
Signed-off-by: subhamkrai <srai@redhat.com>
(cherry picked from commit ff5f3baa58)
The rgw endpoint validation issued an HTTP request to the admin ops
api without a timeout. If the RGW is accepting connections but slow to
respond, for example right after the object store was created, the
script hangs indefinitely instead of reporting a validation error that
the caller could retry on.
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
(cherry picked from commit 459c4bebe9)
before the csi op, the unblish grpc call was not present,
and it has no op
But with csi op, the unpublish grpc is called before the
volumeattachment get remove, and the unpublish call need a
unpublish secret, currently it is getting the secret from the
client profile, but the client profile secret is hardcoded to default
So to override this secret we are adding the secret name in the
storageclass parameter
Signed-off-by: parth-gr <partharora1010@gmail.com>
(cherry picked from commit 88e31185dc)
Add a single example YAML with NetworkPolicy definitions
for all Ceph operand pods (mon, osd, mgr, mds, exporter,
osd-prepare, crashcollector, tools).
Users can apply these policies to restrict egress/ingress
traffic for Rook-Ceph daemon pods.
Signed-off-by: Oded Viner <oviner@redhat.com>
(cherry picked from commit 9dc70051a8)
Make the NVMe-oF gateway image optional in the CR spec.
When not specified, the operator fetches the image from
the Ceph mon config store using the key
mgr/cephadm/container_image_nvmeof. Falls back to the
hardcoded default if the config is unavailable.
Signed-off-by: Oded Viner <oviner@redhat.com>
(cherry picked from commit 8b4fd67e17)
updated the external cluster doc, and helm and manifest
install to make use of csi operator as it is the default
offering now
Signed-off-by: parth-gr <partharora1010@gmail.com>
(cherry picked from commit dbc8d2a541)
adding rook compatible Ceph-Csi driver values.yaml
file making sure, upgrading to 1.20 doesn't break
when csi-driver is moved to admin.
Co-authored-by: Travis Nielsen <tnielsen@redhat.com>
Signed-off-by: subhamkrai <srai@redhat.com>
(cherry picked from commit 774054c45e)
having csi-addons enabled by default is causing random
pod restart on non-openshift cluster. Let's disable
it by default.
Signed-off-by: subhamkrai <srai@redhat.com>
(cherry picked from commit 34b0a87c9e)
this command adds some examples on how users can add/update
the settings based on new way of managing CSI resources.
Signed-off-by: subhamkrai <srai@redhat.com>
(cherry picked from commit fbef1d755e)
adding new tls ssl_ciphersuites supporting tls 1.3 and the existing,
ssl_cipher supports tls 1.2 and below. Adding, the docs and unit-test
changs as well.
Signed-off-by: subhamkrai <srai@redhat.com>
(cherry picked from commit b70a0c9257)
Updating csi-operator to latest v1.0.1 and
updating the required doc changes as well.
Signed-off-by: subhamkrai <srai@redhat.com>
(cherry picked from commit 34c5ad7049)
This commit update the csi-operator to latest v1.0.0.
we need to manually patch the csi drivers with the new serviceAccount
name that are being creating based on the latest ceph-csi-operator
release v1.0.0 where serviceAccount are being separate from csi-operator
chart.
co-authored-by: Travis Nielsen <tnielsen@redhat.com>
Signed-off-by: subhamkrai <srai@redhat.com>
(cherry picked from commit 06452991bf)
net_raw is listed in the rook-ceph scc allowedcapabilities
but no daemon uses it — all pods explicitly drop net_raw.
remove it to align with the go scc helper and helm charts.
Signed-off-by: Oded Viner <oviner@redhat.com>
(cherry picked from commit 572527d476)
this commit adds flag stripe_unit for the command
ceph osd erasure-code-profile set [flags]. This key
increase perfomance for ec pool. The default value
is 4kib/4096 bytes.
Signed-off-by: subhamkrai <srai@redhat.com>
(cherry picked from commit 9fb0582dd6)
Going forward, admin will manage the csi operator
CR's and rook will only manage Ceph Connection cr
and client Profile cr.
The old csi driver is completely removed from Rook
and can no longer be used starting in Rook v1.20.
The upgrade guide will contain the needed transition steps
for managing the csi operator settings.
Signed-off-by: subhamkrai <srai@redhat.com>
(cherry picked from commit 4eefad42e8)
The ROOK_RECONCILE_CONCURRENT_CLUSTERS feature was implemented
in v1.19. This feature has been stable, with no related issues
reported. The feature is tested in the CI with no known
stability issues. Let's declare this feature as stable.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
(cherry picked from commit 45ec32e513)
this commit add option in the ceph objecstore CR
to configure TLS profile and TLS ciphersuite for
rgw beast.
Signed-off-by: subhamkrai <srai@redhat.com>
(cherry picked from commit 01ef98c1e3)
With the default version now being v20.2.1, also update
all of the examples, documentation, and default CI to run
with that version
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
(cherry picked from commit 62a9debceb)
Clean up stale CRUSH rules after the Ceph mgr starts so rules left behind by pool failure-domain or device-class changes do not accumulate indefinitely.
The cleanup is guarded by a package-level RWMutex. Pool create and update paths hold the read lock while creating and assigning CRUSH rules, while cluster-wide cleanup holds the write lock before listing pools and deleting unused rules. This keeps pool reconciles parallel with each other while preventing cleanup from deleting a rule that another reconcile has just created but not yet attached to a pool.
Keep direct pool-delete cleanup for the pool's current CRUSH rule, make the cluster-wide cleanup best-effort across all unused rules, and add an operator-level ROOK_DELETE_UNUSED_CRUSH_RULES setting for clusters that need to leave unused custom rules in place.
Document the operator and Helm settings, regenerate the Helm chart docs, and add a pending release note for the default cleanup behavior.
Signed-off-by: Asish Kumar <officialasishkumar@gmail.com>
(cherry picked from commit 24a35e4e74)
This parameter is written to .spec.cephFS.radosNamespace of the generated
ClientProfile.
The parameter is called 'CSIMetadataRadosNamespace' to clarify that it is used
for CSI metadata and unrelated to the actual CephFS (meta)data.
Context:
The ceph-csi CephFS plugin stores additional metadata related to PV(C)s
in RADOS objects in the metadata pool of the CephFS.
By default those objects are stored in the 'csi' RADOS namespace.
For a multi-tenant CephFS setup (that is used by multiple K8s Clusters/
ceph-csi drivers) segregating those additional objects into separate RADOS
namespaces is desireable so the clusters can not modify the metadata of other
clusters (enforced by appropriate ceph client capabilities).
'ceph-csi' implemented this via the `cephFS.radosNamespace` config option for
cluster entries in the `ceph-csi-config` ConfigMap with https://github.com/ceph/ceph-csi/pull/4661.
The `ceph-csi-operator` added support for that config entry by adding
'radosNamespace' to the 'CephFsConfigSpec' of the 'ClientProfile' with
https://github.com/ceph/ceph-csi-operator/pull/165.
Signed-off-by: Alexander Degenhart <degenhart@fim.uni-passau.de>
Add a standalone Job manifest mirroring the cleanup logic the operator
executes via cleanUpJobTemplateSpec when a CephCluster is deleted with
cleanupPolicy enabled.
Useful when the operator-managed cleanup did not run (e.g. force-deleted
cluster) or a node needs manual cleanup outside normal operator flow.
Secrets (ROOK_MON_SECRET, ROOK_CLUSTER_FSID) are sourced from the
rook-ceph-mon secret via secretKeyRef. Namespace is injected via the
Downward API. Only dataDirHostPath and node hostname need manual input.
Closes#17255
Signed-off-by: Mateen Anjum <mateenali66@gmail.com>