cephcsi fixed a bug related to data loss
and its fixed in 3.12.3 release, This commit
updates the cephcsi to 3.12.3 release.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
openshift cluster need to have access to
finalizers when we set the blockOwnerDeletion
if an ownerReference refers to a resource
we can't set finalizers on, This adds the extra
required permission
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
enable and disable the status of rados namespace
mirroring by looking at statusCheck spec of blockpool
Signed-off-by: parth-gr <partharora1010@gmail.com>
csiaddons required new RBAC in the next
release to create/update the csiaddonsnode
object based on the owner deployment/daemonset
names of the pods its running with.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
If there are multiple clusters, `dataDirHostPath` must be unique
for each cluster. However, it's not documented yet.
In addition, `ceph-teardown.md` was also updated because
the original document assumes that `dataDirHostPath` is
`/var/lib/rook` and the files for a cluster `rook-ceph` is
under `/var/lib/rook/rook-ceph`.
related issue:
https://github.com/rook/rook/issues/14790
Signed-off-by: Satoru Takeuchi <satoru.takeuchi@gmail.com>
If the cmd-reporter key is set under the resources
element in the CephCluster CR, the memory and cpu request
and limits will be set on the ceph detect version job
and network job accordingly.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
For nodes that are explicitly requested for deploying
OSDs, they will be skipped temporarily if not
schedulable or not ready. A future reconcile is
expected to schedule them. Allow the OSDs to be
scheduled even on these nodes that are temporarily
down, even if it blocks the reconcile from completing.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
The version checks for the csi driver are removed now
since they are all obsolete. The K8s version and cephcsi
versions are no longer checked. Anyway, the move to the
csi operator would take ownership of version checks
needed in the future, so for now we simplify rook
deployment of the csi driver.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
When generating the HTTP client used for RGW admin ops, use both system
certs as well as the user-given cert.
As a real world example, admins may use ACME to rotate Letsencrypt certs
every 2 months. For an external CephObjectStore, the cert used by Rook
and RGW may not be rotated at the same time. This can cause the Rook
operator to fail CephObjectStore reconciliation until both certs agree.
When Rook also relies on system certs in the container, Rook's
reconciliation will not have reconciliation failures because
Letsencrypt's well-known and trusted root certificates can be loaded
from the system to validate the RGW's newly-rotated cert.
Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
Finish the process of deprecating holder pods by removing Rook's ability
to deploy them. The intent of this change is to make the most
superficial changes possible to accomplish this. There are still
remnants of code in Rook (particularly the CSI controller) that helped
configure or deploy holder pods. Due to the risk of breaking some
features, cleanup work of hose remnants will be deferred for future
work.
Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
This acceptance test demonstrates the creation of two CephObjectStore(s)
that share the same pool(s) manually managed by CephBlockPool(s).
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
Modify the CR to allow mirroring of an rados namespace
to a differently named namespace on the remote cluster
1) enable rados namesapce mirroring only
if the blockpool mirrroing is enabled
2) disable blockpool mirroing only if
all the namesapce mirroing is disabled
if the rbd mirroring fails and ceph version is not supported
provide a error message with supported version details
and reason of failing
Signed-off-by: parth-gr <partharora1010@gmail.com>
These fields must be optional in order to allow usage of pre-existing
pools managed by CephBlockPool CR(s).
Signed-off-by: Joshua Hoblitt <josh@hoblitt.com>
Given that Ceph Quincy (v17) is past end of life,
remove Quincy from the supported Ceph versions,
examples, and documentation.
Supported versions now include only Reef and Squid.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
The ROOK_ENFORCE_HOST_NETWORK option was implemented recently
and now we add the helm setting to expose this new setting
in the rook chart.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
This adds an operator config setting ROOK_REVISION_HISTORY_LIMIT
defaulting to kubernetes'value for RevisionHistoryLimit.
If configured, the provided value will be used as RevisionHistoryLimit
for all Deployments rook creates.
Fixes: #12722
Signed-off-by: Michael Adam <obnox@samba.org>
for cephfs fencing in external mode, we run command `ceph tell mds ***`
which requires user user to include cap mds allow * in permission. So,
we need to add this in healthchercker and cephfs provisioner user
Signed-off-by: subhamkrai <srai@redhat.com>