Commit Graph
38 Commits
Author SHA1 Message Date
Blaine Gardner c7dfe7837e Merge pull request #14884 from cobaltcore-dev/rgw-default-placement
rgw: support custom name for default pool placement
2024-10-25 10:30:58 -06:00
Artem Torubarov b47dff9770 rgw: support custom name for default pool placement
introduce Default flag to CRD

Signed-off-by: Artem Torubarov <artem.torubarov@clyso.com>
2024-10-25 12:52:06 +02:00
Joshua Hoblitt f51cfbdf6b object: add bucketMaxObjects & bucketMaxSize to obc
Two new keys are added to ObjectBucketClaim.spec.additionalConfig to
support the configuration of bucket scope quota(s). This differs from
the existing maxObjects & maxSize keys, which manage a user scope
quota(s) on the automatically generated rgw user.

Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
2024-10-23 14:39:38 -07:00
Travis Nielsen b665d7a7b7 core: remove support for ceph quincy
Given that Ceph Quincy (v17) is past end of life,
remove Quincy from the supported Ceph versions,
examples, and documentation.

Supported versions now include only Reef and Squid.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-10-03 11:12:55 -06:00
Artem Torubarov 59175f0b40 rgw: pool placement
Signed-off-by: Artem Torubarov <torubarov.a.a@gmail.com>
2024-09-06 16:02:53 +02:00
Vamsi Krishna Sethu a26565d922 docs: fix ceph object multisite and update source code layout
Signed-off-by: Vamsi Krishna Sethu <sethuvamsikrishna@gmail.com>
2024-08-23 20:55:32 +05:30
Blaine Gardner 5f98d2ea3e Merge pull request #13807 from jklippel/feature/swift-and-keystone
rgw: implement support for authentication using keystone for s3 and swift
2024-08-08 09:55:34 -06:00
ee8bcad49d rgw: add support for keystone auth + swift/s3
For the specification see:
<https://github.com/rook/rook/blob/master/design/ceph/object/swift-and-keystone-integration.md>

* extend the API object specs for swift and keystone integration

* adapt rgw to the new go-ceph version

  - The parameter lists of the API call have changes, as parameters
    ignored by the RGW Admin Ops API are no longer serialized, therefore
    the mock has to be adapted.

  - There is now validation for the user keys that are passed to the
    User get API, therefore things failed when we had empty keys in our
    User proxy object.

* expand the reconcile loop for the swift and keystone integration

* fix minor mistakes in design document

* add env var to pass extra args to minikube

  Minikube decides CPU cores and memory automatically based on the
  available resources on the machine which may be insufficient to
  run rook. This commit adds an environment variable to add arbitrary
  arguments to the minikube command, so both can be specified if
  desired.

* integration tests for swift and keystone

  The new integration of swift or s3 and keystone support by rook
  does not have any integration tests yet.

  This commit introduces integration tests for swift and keystone. The
  tests are done against a minimal keystone setup (keystone container
  image from Yaook-project (https://yaook.cloud), sqlite as database
  backend, cert-manager and trust-manager for test certificate setup).

  To prevent hardcoded credentials, passwords are generated
  by the tests. The integration tests use the openstack client
  (keystone- and swift-functionality) (https://docs.openstack.org/
  python-openstackclient/ latest/). This was a concious design decision
  to use client tooling as close as possible to the end user instead of
  using other go-libraries (such as gophercloud).

* add documentation on swift and keystone

  Currently there is no documentation on the use of Swift to access
  an object store as well as the use of OpenStack keystone for
  authentication.

  This commit adds documentation on the use of Swift and OpenStack
  keystone, as well as CRD-related documentation and an example setup.

* add integration tests for S3 via keystone

  This commit introduces integration tests for s3 and keystone. The
  tests are run against the same minimal keystone setup that the tests
  for swift and keystone use.

  The integration tests use the aws s3 client to use client tooling as
  close as possible to the end user instead of using other go-libraries.

Co-authored-by: Jan Klippel <jan.klippel@uhurutec.com>
Co-authored-by: Silvio Ankermann <silvio.ankermann@cloudandheat.com>
Signed-off-by: Sebastian Riese <sebastian.riese@cloudandheat.com>
Signed-off-by: Jan Klippel <jan.klippel@uhurutec.com>
Signed-off-by: Silvio Ankermann <silvio.ankermann@cloudandheat.com>
2024-08-08 14:26:21 +02:00
Blaine Gardner b4a2285aa6 object: use advertise endpoint for admin ops
RGW can only serve a single certificate. This limitation means that the
prior behavior of using the default service for admin ops when TLS is
enabled may mean it requires additional complex certificate management
to make sure the object store uses a certificate valid for Rook internal
admin ops and user connections.

This is needlessly complex for users. Instead, change Rook's behavior
and documentation to clarify that it will use the same endpoint intended
for S3 client applications. This means that users have a more
straightforward path to enabling both Rook and consuming applications.

More info: https://github.com/rook/rook/issues/14530

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-08-05 14:32:59 -06:00
Blaine Gardner a2b0b6449c object: add hosting.advertiseEndpoint config
Add CephObjectStore spec.hosting.advertiseEndpoint configuration. This
provides a clear documented default for which endpoint Rook "advertises"
to dependent resources like CephObjectStores, OBCs, and COSI
Buckets/Accesses and allows users to override the default behavior if
desired.

The current default is to round-robin an endpoint from
spec.hosting.dnsNames, which has proven to be troublesome for some
users' object store configurations. This change provides much-needed
disambiguation for users.

This may be a breaking change for some existing spec.hosting.dnsNames
users. This is unexpected but is documented.

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-07-22 14:43:51 -06:00
Jiffin Tony Thottan ba40f84123 object: update cosi images
Updating images for ceph cosi driver and side car.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2024-06-04 19:32:45 +05:30
Blaine Gardner c9d99e01a0 ci: use markdownlint to enforce mkdocs compatibility
mkdocs uses a markdown renderer that is hardcoded to 4 spaces per tab
for detecting indentation levels, including ordered- and
unordered-lists. Since we cannot easily change the renderer, begin using
a markdown linter in CI that will fail if official docs do not adhere to
the spacing rules.

As a starting point, the markdownlint config does not begin with the
default set of checks, which might overwhelm attempts to fix them.
Instead, focus on list-tab-spacing rules and a few other highly useful
checks.

markdownlint also has some gaps in its abilities that allow common Rook
doc issues to pass acceptance. However, it allows creating custom
linting plugins. Create 2 such linting plugins to check 2 things:

- all doc lines (except code blocks) must be aligned to a 4-space
  boundary, without exception. This ensures that markdown will render
  correctly with mkdocs. This unfortunately makes it possible to create
  lists that are internally aligned strangely.
- admonitions must all follow the same format of
  ```
  !!! header
      body
  ```

For the strange lists, this is allowed and renders correctly, but it
looks strange:

```md
- first bullet
- second bullet
    still second bullet
- third bullet

    has a paragraph
    of text inside

- last bullet

Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
2024-04-29 17:25:11 -06:00
Travis Nielsen 15f92a175d Merge pull request #13703 from thotz/prefix-provisioner-obc
object: provisoner prefix support
2024-03-12 12:16:45 -06:00
Travis Nielsen 9e55d0e02d doc: add space for object store formatting
The description of the object store types was improperly
formatted due to a missing newline before the bullet points.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-03-12 07:59:05 -06:00
Travis Nielsen fdacfd51c5 object: create an object store based on shared pools
Until now, an object store would create all the necessary
metadata pools and the data pool that were exclusively
for its own object store. When isolation between object
stores is necessary, this would cause many pools and
PGs to be created in the cluster, which was not
manageable.

Now one set of pools can be created to be shared
by any number of object stores. The metadata and data
between each object store is isolated by
RADOS namespaces, which by design will keep the
data safe for multi-tenancy.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2024-03-11 11:20:57 -06:00
Jiffin Tony Thottan e0768f5e5f object: provisoner prefix support
add an option to set prefix for the name of obc provisioner instead of
ceph cluster namespace.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2024-03-11 13:42:11 +05:30
Jiffin Tony Thottan b0989ee1d2 object: add rgw dns names
The virtual hosting for bucket is provided with help of `rgw_dns_name`

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2024-03-08 13:43:25 +05:30
Madhu Rajanna a2e0b0c46b cosi: fix problem in cosi document
Fixed a wording problem and moved the
app pod to default namespace where secret
was created and also removed the init container
from the sample as the busybox doesnt
have setup-aws-credentials CLI pre-installed.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2023-10-12 09:13:12 +02:00
Blaine Gardner e74333ddcd Merge pull request #12633 from thotz/cosi-user-creation
object: create cosi user for each object store
2023-10-04 10:05:36 -06:00
Redouane Kachach b3dd74ea20 docs: fixing some spelling issues
closes: https://github.com/rook/rook/issues/12987

Signed-off-by: Redouane Kachach <rkachach@redhat.com>
2023-10-03 13:50:17 +02:00
Jiffin Tony Thottan a941b3c33f object: create cosi user for each object store
Create each cosi user for each object store and secret which holds
credentials.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2023-09-19 13:48:58 +05:30
parth-gr 8a3f058329 object: fix s5cmd for s3 endpoint verification
add a new toolbox yaml manifest which will use the
rook image instead of ceph image
for running s5 cmd container needs to run with rook image

closes: https://github.com/rook/rook/issues/12227

Signed-off-by: parth-gr <paarora@redhat.com>
2023-08-04 18:29:05 +05:30
travisn 4145ecec37 cosi: document enabling the cosi driver
Add steps for enabling the cosi driver that is disabled
by default. Also add an introduction to the COSI driver
and a section for prerequisites.

Signed-off-by: travisn <tnielsen@redhat.com>
2023-07-18 14:35:54 -06:00
Travis Nielsen 91fea5395e Merge pull request #12415 from thotz/ceph-cosi-driver
object: adding ceph cosi driver
2023-07-18 12:12:12 -06:00
Jiffin Tony Thottan b48dc8a335 object: intial cosi driver controller design
Adding CephCOSIDriver CRD and controller. The controller will bring up
the ceph cosi driver when first object store is created in the rook
operator namespace. Then admin can defined COSI CRDs like BucketClass
and BucketAccessClass for different object stores deployed via Rook.
Using the BucketClass and BucketAccessClass, user can define
BucketAccess for backend bucket in the RGW. The CephCOSIDriver CRD
defines configuration options for ceph cosi driver. In the first version
its usability is minimal. Even if it is not defined Rook will bring up
the ceph cosi driver with default values.

Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2023-07-18 22:49:41 +05:30
Lucas Henry 393d09347e rgw: add option to disable synchronization traffic
Some users want to deploy two CephObjectStores for a single Zone. The first
configures RGWs to process the synchronization of the data, while the second
CephObjectStore configures the client RGWs.

Currently, this can be implemented by setting the RGW option
'rgw_run_sync_thread' in the 'rook-config-override' ConfigMap, though it is not
really user friendly.

Ref: https://docs.ceph.com/en/latest/radosgw/config-ref/#confval-rgw_run_sync_thread

This commit adds a new option in the CephObjectStore CRD as defined in issue
https://github.com/rook/rook/issues/12272. The new option
'disableMultisiteSyncTraffic' determine whether the operator should disable the
multisite sync threads for the RGWs.

If the option is set to 'false', or if the option is not specified, the operator
does nothing. This ensures that the multisite sync threads will not be enabled
for users that disabled explicitely the multisite sync threads either manually
or with the 'rook-config-override' ConfigMap.

This commit also recommends to use two objectstore when scaling Ceph Objectstore
Multisite replication, with one objectstore configured with disabled replication
traffic.

Signed-off-by: Lucas Henry <polyedre@disroot.org>
2023-07-17 09:27:20 +02:00
Travis Nielsen f6da90d539 Merge pull request #12264 from parth-gr/rgw-external-tls
external: fqdn should be persisted
2023-05-31 14:00:59 -06:00
parth-gr f66de7b9df external: fqdn should be persisted
1) donot change rgw fqdn to ip if provided,
As now the bucket class supports the
entry of fqdn

2) update crds with new description in EndpointAddress

Signed-off-by: parth-gr <paarora@redhat.com>
2023-05-31 17:36:29 +05:30
Jiffin Tony Thottan 2a96967ed0 docs: update the documentation for external rgw servers
The StorageConfiguration docs for external needs to update with Rook
design

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2023-05-17 14:17:30 +05:30
Travis Nielsen 7c9ef07659 object: move bucket notifications to stable
Bucket notifications and topics have been implemented since
v1.8 and have been stable. Therefore, with v1.11 we move
the feature to stable.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2023-01-04 10:30:14 -07:00
xiaobaowen 8f23c1ba9e docs: fix notes in CephBucketTopic docs
Signed-off-by: xiaobaowen <xiaobaowen@deeproute.ai>
2022-12-09 10:41:14 +08:00
Travis Nielsen 05590dfc9b docs: set crd page titles to crd name
The name of the CRD is more clear for finding the CRD specs
instead of a modified form of the name that was intended
to be more human readable. When someone is looking for the
CRD settings, they more naturally expect the CRD name
in the title

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2022-11-09 16:12:58 -07:00
Tarun Gupta Akirala a2b0871d08 docs: fix typo in numbering
Signed-off-by: Tarun Gupta Akirala <takirala@users.noreply.github.com>
2022-10-24 23:46:21 -07:00
Blaine Gardner a7c0c7ee93 object: remove health checker
Remove the health checker for CephObjectStore. The liveness and
readiness probes go through the same code paths in RGW as creating
buckets without as much affect on the storage backend.

Full discussion: https://github.com/rook/rook/issues/11031

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2022-10-18 13:41:46 -06:00
Jiffin Tony Thottan d05bcc61f8 docs: add steps to convert existing cephobjectstore into multisite
Most of the users starts with single site, provide the steps to convert
existing cephobjectstore into multisite configurations.

Signed-off-by: Jiffin Tony Thottan <jthottan@redhat.com>
2022-08-24 12:20:49 +05:30
Alexander Trost fe2000e6d8 docs: rename Rook-Ceph to Rook Ceph
Signed-off-by: Alexander Trost <galexrt@googlemail.com>
2022-08-11 14:58:57 +02:00
Josh Soref 6e7b8767f3 core: fix spelling
* another
* are
* availability
* available
* bootstrap
* boundaries
* ceph
* certificate
* class
* codifies
* consuming
* corrupted
* createor
* csi
* deployments
* exceeded
* execute
* filesystem
* healthiness
* heuristics
* immediately
* insecure
* installed
* isolated
* maintained
* maximum
* minute
* monitor
* new
* nginx
* nonexistent
* not
* occurs
* omitempty
* operator
* orchestration
* persistentvolumes
* placement
* preexisting
* prometheus
* protecting
* provisioner
* purposes
* reconcile
* regex
* related
* requests
* returns
* rubbish
* running
* schedulable
* schedule
* serviceaccount
* simulating
* snapshots
* statement
* static
* tenants
* the
* unavailable
* volumeattachment
* waiting
* with
* wrapper
* zonegroup

Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>
2022-07-07 18:10:47 -04:00
Alexander Trost 74431443e3 docs: use mkdocs and restructure docs
Signed-off-by: Alexander Trost <galexrt@googlemail.com>
2022-05-18 16:06:22 +02:00