this commit handle golangci-lint linter errcheck.
`errcheck` - Errcheck is a program for checking for
unchecked errors in go programs. These unchecked errors
can be critical bugs in some cases
To see only staticcheck linter output
`golangci-lint run --disable-all -E errcheck`
Signed-off-by: subhamkrai <srai@redhat.com>
This PR makes the changes in csi templates and
upgrade documentation required for updating
csi sidecar images.
Signed-off-by: Mudit Agarwal <muagarwa@redhat.com>
this commit handle golangci-lint linter staticcheck error.
`staticcheck` - Staticcheck is a go vet on steroids,
applying a ton of static analysis checks.
To see only `staticcheck` linter output
`golangci-lint run --disable-all -E staticcheck`
Signed-off-by: subhamkrai <srai@redhat.com>
this commit will enable one more linter ineffassign
in golangci-lint.
This linter throws an error when variable is assigned and never used.
`golangci-lint run --disable-all -E ineffassign` is used detects ineffassign
errors only.
Signed-off-by: subhamkrai <subhamkumarrai03@gmail.com>
this commit enables the rook integration
testing capability on openshift. currently
this commit enable CephSmokeSuite testing
only.
Signed-off-by: subhamkrai <subhamkumarrai03@gmail.com>
Rook is now capable of configuring mirroring between sites. The
implementation works at different levels:
* CephBlockPool: which introduces a new `mirroring` configuration as well
as `statusCheck`. When turned on, Rook will enable mirroring on the
pool. It will also create a bootstrap peer token and store it in a
Kubernetes Secret. The name of that Secret can be found in the Status
field of the CephBlockPool CRD. This token can be fetched and used by
other clusters to configure the site as a peer. Mirroring can be
configured either at the pool or the image level.
* CephRBDMirror: which introduces a new `peers` configuration allowing
Rook to connect to peers by passing a Secret name. The administrator will
create a Kubernetes Secret with 2 keys: 'token' for the bootstrap peer
token and 'pool' for the name of pool. Once detected the rbd-mirror
controller will go ahead and import the peer configuration.
Pool mirroring status example:
```
status:
info:
rbdMirrorBootstrapPeerSecretName: pool-peer-token-test
mirroringInfo:
lastChanged: "2020-09-17T14:47:27Z"
lastChecked: "2020-09-17T14:48:27Z"
summary:
summary:
mode: image
peers:
- client_name: client.rbd-mirror-peer
direction: rx-tx
mirror_uuid: ""
site_name: rhcs
uuid: c50522a4-28a4-4bd3-ba68-e11780308882
site_name: 91eae0dd-06b1-4d2c-91f3-1311c9df382b-rook-ceph
mirroringStatus:
lastChecked: "2020-09-17T14:48:27Z"
summary:
summary:
daemon_health: OK
health: OK
image_health: OK
states:
replaying: 1
```
Signed-off-by: Sébastien Han <seb@redhat.com>
currently, we are setting the rook operator as owner
on the csidriver objects, as csidriver is cluster
scoped object we should not set namespaced object as
owner on cluster scoped object
fixes#6162
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
Added E2E testing to create,delete and restore
a snapshot, create a pvc-pvc clone, install
and uninstall snapshot controller and snapshot
CRD.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
The upgrade tests can safely use the rbac.authorization.k8s.io/v1 instead of
rbac.authorization.k8s.io/v1beta1. In K8s 1.19, the upgrade test was failing
because v1beta1 has been deprecated.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
The lifecycle preStop hook fails on container stop / exit
because /bin/sh is not present in the driver registrar container
image.
the driver-registrar will remove the socket file
before stopping. we dont need to have any preStop hook
to remove the socket as it was not working as expected
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
This replaces any K8S clientset usages of the
`rbac.authorization.k8s.io/v1beta1` APIs with
`rbac.authorization.k8s.io/v1` client.
This is done as some RBAC objects used the `v1beta1` and others already
using `v1`, for consistency.
Signed-off-by: Alexander Trost <galexrt@googlemail.com>
This replaces any uses of `rbac.authorization.k8s.io/v1beta1` with
`rbac.authorization.k8s.io/v1` affecting RBAC objects like ClusterRole
and ClusterRoleBindings, etc. to make it consistent.
This is done as some RBAC objects used the `v1beta1` and others already
using `v1`.
Signed-off-by: Alexander Trost <galexrt@googlemail.com>
`anon-user-access` clusterrolebinding is created when installing rook operator.
However each test suite does not delete the clusterrolebinding,
and cause errors.
This PR skip creating the clusterrolebinding in each suite if it already exists.
Signed-off-by: Takashi IIGUNI <iiguni.tks@gmail.com>
currently, the object store schema requires the
port to be non-zero. This does not allow http
access to the object store to be disabled.
so setting the port minimum to 0 to from 1 in the cr.
Signed-off-by: subhamkrai <subhamkumarrai03@gmail.com>
Previously we did not supported defining crushRoot in some of the CRDs. With this fix, we plan to fix this behaviour.
Signed-off-by: mridulv <mridulv09@gmail.com>
We can now encrypted OSD device that were provisioned via a storage
class using the PV interface.
The encryption works at the storageClassDeviceSets level, which means we
can have encrypted and non-encrypted sets.
Using the new key `encrypted` we can turn it on.
Signed-off-by: Sébastien Han <seb@redhat.com>
In the upgrade integration test we need to mirror what we expect
users to do during the upgrade by applying the new clusterroles.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
The aggregate clusterrole were designed for the scenario where
the rules are not completely owned by one component. Since Rook
owns all of the RBAC for its components, the aggregate rules can
be removed and simplify certain issues around upgrades.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
The upgrade guide is now updated for upgrades from v1.3 to v1.4.
The v1.2 upgrade yamls are removed and the docs are cleaned up from
1.3 upgrade steps that are no longer necessary.
Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
Currently, rook CI is not logging Kubernetes Events, but it sometimes gives hints
for bugs.
Therefore, this PR adds a function to collect and log Kubernetes Events.
Signed-off-by: binoue <banji-inoue@cybozu.co.jp>
updated the clusterrole of the rook operator
to delete the csidrivers object when csi-drivers
are disabled, without the required access rook operator
cannot delete the csidrivers object.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
Somehow, the client.Update was not updating the cluster object, using
client.Status().Update actually fixed it.
Signed-off-by: Sébastien Han <seb@redhat.com>
This also updates the cassandra version in the tests.
This is to provide safe and secure defaults to users running Cassandra.
Signed-off-by: Alexander Trost <galexrt@googlemail.com>
metadatastore and mountcache are required for cephcsi v1.0.0
as rook doesnot used ceph-csi v1.+ version
we can remove this flag. Removing these flags doesnot
affect the functionality of anything.
Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
There is no point of asking for a cleanup when the cluster is external,
also the cleanup pod will never exist and the CI will fail waiting for
it.
Signed-off-by: Sébastien Han <seb@redhat.com>
Now, we can not only cleanup monitor data, logs and crashes but the
disks too. As part of the cleanupPolicy CR spec, we have a new setting
called sanitizeDisk which holds more details:
* method: indicates if the entire disk should be sanitized or simply ceph's metadata.
Possible choices are 'complete' or 'quick' (default)
* dataSource: indicate where to get random bytes from to write on the disk.
Possible choices are 'zero' (default) or 'random'
Using random sources will consume entropy from the system and will take much more time then the zero source
* iteration: overwrite N times instead of the default (1). Takes an integer value
See the documentation for more details.
Signed-off-by: Sébastien Han <seb@redhat.com>