Commit Graph
471 Commits
Author SHA1 Message Date
subhamkrai 0fddfcf307 ceph: handle golangci-lint linter errcheck error
this commit handle golangci-lint linter errcheck.

`errcheck` - Errcheck is a program for checking for
unchecked errors in go programs. These unchecked errors
can be critical bugs in some cases

To see only staticcheck linter output
`golangci-lint run --disable-all -E errcheck`

Signed-off-by: subhamkrai <srai@redhat.com>
2020-09-30 22:24:34 +05:30
Mudit Agarwal c547b36aa0 ceph: update csi sidecar images
This PR makes the changes in csi templates and
upgrade documentation required for updating
csi sidecar images.

Signed-off-by: Mudit Agarwal <muagarwa@redhat.com>
2020-09-28 18:58:52 +05:30
subhamkrai de8dbbcdcc ceph: handle golangci-lint linter staticcheck error
this commit handle golangci-lint linter staticcheck error.

`staticcheck` - Staticcheck is a go vet on steroids,
applying a ton of static analysis checks.

To see only `staticcheck` linter output

`golangci-lint run --disable-all -E staticcheck`

Signed-off-by: subhamkrai <srai@redhat.com>
2020-09-24 15:04:55 +05:30
subhamkrai 829778f251 ceph: handle golangci-lint linter ineffassign
this commit will enable one more linter ineffassign
in golangci-lint.

This linter throws an error when variable is assigned and never used.

`golangci-lint run --disable-all -E ineffassign` is used detects ineffassign
errors only.

Signed-off-by: subhamkrai <subhamkumarrai03@gmail.com>
2020-09-21 14:31:18 +05:30
Travis Nielsen 02fa0eb921 Merge pull request #6228 from Madhu-1/fix-ownerref
ceph: remove owner reference set by rook on csidriver
2020-09-18 10:09:36 -06:00
Sébastien Han d118bd38a6 Merge pull request #6278 from subhamkrai/golanci-lint-unused
ceph: handle golangci-lint linter unused
2020-09-18 12:44:37 +02:00
subhamkrai 4c11e45155 ceph: integration test on OpenShift
this commit enables the rook integration
testing capability on openshift. currently
this commit enable CephSmokeSuite testing
only.

Signed-off-by: subhamkrai <subhamkumarrai03@gmail.com>
2020-09-18 14:30:57 +05:30
Sébastien Han 204ffd4065 Merge pull request #6250 from leseb/mirroring-config
ceph: add rbd-mirror configuration
2020-09-18 09:16:08 +02:00
subhamkrai f9fafe62d4 ceph: handle golangci-lint linter unused
this commit will enable one more linter
in golangci-lint.

Signed-off-by: subhamkrai <subhamkumarrai03@gmail.com>
2020-09-17 22:53:24 +05:30
Sébastien Han 451622a955 ceph: add rbd-mirror configuration
Rook is now capable of configuring mirroring between sites. The
implementation works at different levels:

* CephBlockPool: which introduces a new `mirroring` configuration as well
as `statusCheck`. When turned on, Rook will enable mirroring on the
pool. It will also create a bootstrap peer token and store it in a
Kubernetes Secret. The name of that Secret can be found in the Status
field of the CephBlockPool CRD. This token can be fetched and used by
other clusters to configure the site as a peer. Mirroring can be
configured either at the pool or the image level.

* CephRBDMirror: which introduces a new `peers` configuration allowing
Rook to connect to peers by passing a Secret name. The administrator will
create a Kubernetes Secret with 2 keys: 'token' for the bootstrap peer
token and 'pool' for the name of pool. Once detected the rbd-mirror
controller will go ahead and import the peer configuration.

Pool mirroring status example:

```
status:
  info:
    rbdMirrorBootstrapPeerSecretName: pool-peer-token-test
  mirroringInfo:
    lastChanged: "2020-09-17T14:47:27Z"
    lastChecked: "2020-09-17T14:48:27Z"
    summary:
      summary:
        mode: image
        peers:
        - client_name: client.rbd-mirror-peer
          direction: rx-tx
          mirror_uuid: ""
          site_name: rhcs
          uuid: c50522a4-28a4-4bd3-ba68-e11780308882
        site_name: 91eae0dd-06b1-4d2c-91f3-1311c9df382b-rook-ceph
  mirroringStatus:
    lastChecked: "2020-09-17T14:48:27Z"
    summary:
      summary:
        daemon_health: OK
        health: OK
        image_health: OK
        states:
          replaying: 1
```

Signed-off-by: Sébastien Han <seb@redhat.com>
2020-09-17 19:05:04 +02:00
subhamkrai 25c116a4bd ceph: handle golangci-lint linter gosimple
this commit handles all the errors  check for
golangci-lint linter gosimple.

Signed-off-by: subhamkrai <subhamkumarrai03@gmail.com>
2020-09-17 15:10:27 +05:30
Madhu Rajanna a1024ebc75 ceph: remove owner reference set by rook on csidriver
currently, we are setting the rook operator as owner
on the csidriver objects,  as csidriver is cluster
scoped object we should not set namespaced object as
owner on cluster scoped object

fixes #6162

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2020-09-15 11:39:27 +05:30
Madhu Rajanna e864b8d42d ceph: add E2E testing for snapshot and clone
Added E2E testing to create,delete and restore
a snapshot, create a pvc-pvc clone, install
and uninstall snapshot controller and snapshot
CRD.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2020-09-10 22:05:15 +05:30
Sébastien Han 9a06d059f0 ci: change local disk path
With the recent aws instance type the disk naming changed too, so
replace xvdc with nvme0n1.

Closes: https://github.com/rook/rook/issues/6189
Signed-off-by: Sébastien Han <seb@redhat.com>
2020-08-31 22:04:46 +02:00
Travis Nielsen 34d40fee6e ceph: upgrade test uses rbac v1 instead of v1beta1
The upgrade tests can safely use the rbac.authorization.k8s.io/v1 instead of
rbac.authorization.k8s.io/v1beta1. In K8s 1.19, the upgrade test was failing
because v1beta1 has been deprecated.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-08-28 10:26:36 -06:00
Jared Watts 06ab07be8b Merge pull request #5863 from prksu/nfs-provisioner
nfs: nfs provisioner controlled by operator
2020-08-24 16:26:23 -07:00
Madhu Rajanna 0aa0957bf1 ceph: remove preStop from daemonset template
The lifecycle preStop hook fails on container stop / exit
because /bin/sh is not present in the driver registrar container
image.

the driver-registrar will remove the socket file
before stopping. we dont need to have any preStop hook
to remove the socket as it was not working as expected

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2020-08-24 19:25:44 +05:30
Ahmad Nurus S 5cc2ceda2d nfs: make provisioner as sidecar of nfs server
Signed-off-by: Ahmad Nurus S <prksu.sh@gmail.com>
2020-08-21 16:40:33 +07:00
Alexander Trost ed3c0eeff2 test: operator use rbac.authorization.k8s.io/v1 consistently
This replaces any K8S clientset usages of the
`rbac.authorization.k8s.io/v1beta1` APIs with
`rbac.authorization.k8s.io/v1` client.
This is done as some RBAC objects used the `v1beta1` and others already
using `v1`, for consistency.

Signed-off-by: Alexander Trost <galexrt@googlemail.com>
2020-08-20 12:08:32 +02:00
Alexander Trost be16bc455f docs: operator use rbac.authorization.k8s.io/v1
This replaces any uses of `rbac.authorization.k8s.io/v1beta1` with
`rbac.authorization.k8s.io/v1` affecting RBAC objects like ClusterRole
and ClusterRoleBindings, etc. to make it consistent.
This is done as some RBAC objects used the `v1beta1` and others already
using `v1`.

Signed-off-by: Alexander Trost <galexrt@googlemail.com>
2020-08-20 12:08:32 +02:00
Sébastien Han 45b8a0c88c Merge pull request #6035 from guni1192/ci-fix-remove-cluster-role-bindings
ci: skip the creation of already existing clusterrolebinding
2020-08-17 17:52:38 +02:00
Sébastien Han a5982b749f ceph: fix object store yaml example
The healthcheck for the bucket is called `bucket`.

Signed-off-by: Sébastien Han <seb@redhat.com>
2020-08-17 17:24:26 +02:00
Travis Nielsen 7481993959 Merge pull request #6017 from humblec/ceph-csi-snapshotter
Add/update ceph csi snapshotter rbac and sidecar deployments
2020-08-13 12:32:35 -06:00
Humble Chirammal 97a3283099 ceph: add snapshot create/delete and restore doc for cephfs
Signed-off-by: Humble Chirammal <hchiramm@redhat.com>
2020-08-13 22:17:01 +05:30
Takashi IIGUNI 39fae17fb1 ci: cleanup clusterrolebindings
`anon-user-access` clusterrolebinding is created when installing rook operator.
However each test suite does not delete the clusterrolebinding,
and cause errors.
This PR skip creating the clusterrolebinding in each suite if it already exists.

Signed-off-by: Takashi IIGUNI <iiguni.tks@gmail.com>
2020-08-13 03:02:14 +00:00
subhamkrai e21854145a ceph: disable object store port when secureport specified
currently, the object store schema requires the
port to be non-zero. This does not allow http
access to the object store to be disabled.
so setting the port minimum to 0 to from 1 in the cr.

Signed-off-by: subhamkrai <subhamkumarrai03@gmail.com>
2020-08-12 21:57:01 +05:30
Humble Chirammal 6613b3a9e9 ceph: update e2e manifest for cephfs snapshotter sidecar
Signed-off-by: Humble Chirammal <hchiramm@redhat.com>
2020-08-10 11:31:30 +05:30
mridulv 30cd786303 ceph: adding ability to specify crushroot in the CRD
Previously we did not supported defining crushRoot in some of the CRDs. With this fix, we plan to fix this behaviour.

Signed-off-by: mridulv <mridulv09@gmail.com>
2020-08-08 16:24:15 +05:30
Umanga Chapagain da1910840a ceph: add CRD changes and documentation
adds `enableRBDStats` to CRD manifets and updates documentation
on its usage.

Signed-off-by: Umanga Chapagain <chapagainumanga@gmail.com>
2020-08-06 12:11:55 +05:30
Sébastien Han 89b3225441 ceph: add encryption support for osd pvc
We can now encrypted OSD device that were provisioned via a storage
class using the PV interface.
The encryption works at the storageClassDeviceSets level, which means we
can have encrypted and non-encrypted sets.
Using the new key `encrypted` we can turn it on.

Signed-off-by: Sébastien Han <seb@redhat.com>
2020-08-05 10:06:11 +02:00
Travis Nielsen 772b7990db ceph: updated clusterroles applied in upgrade test
In the upgrade integration test we need to mirror what we expect
users to do during the upgrade by applying the new clusterroles.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-08-04 16:04:07 -06:00
Travis Nielsen 2365885653 ceph: remove unnecessary aggregate clusterroles
The aggregate clusterrole were designed for the scenario where
the rules are not completely owned by one component. Since Rook
owns all of the RBAC for its components, the aggregate rules can
be removed and simplify certain issues around upgrades.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-08-04 15:47:18 -06:00
Travis Nielsen 14495d1e5a ceph: upgrade documentation for v1.4
The upgrade guide is now updated for upgrades from v1.3 to v1.4.
The v1.2 upgrade yamls are removed and the docs are cleaned up from
1.3 upgrade steps that are no longer necessary.

Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
2020-08-04 15:47:18 -06:00
Travis Nielsen e0ea87a353 Merge pull request #5674 from thotz/quotaobc
ceph: adding support for quota in object bucket claims
2020-07-30 22:51:58 -06:00
Travis Nielsen 91a1f2dc9e Merge pull request #5921 from binoue/add-event-log-file
ci: create Kubernetes Event log file
2020-07-30 11:24:03 -06:00
binoue 937b77f8e6 ceph: revised according to the review comments
revised according to the review comments

Signed-off-by: binoue <banji-inoue@cybozu.co.jp>
2020-07-30 07:44:08 +09:00
binoue 9a44b95f68 ceph: create event log file
Currently, rook CI is not logging Kubernetes Events, but it sometimes gives hints
for bugs.
Therefore, this PR adds a function to collect and log Kubernetes Events.

Signed-off-by: binoue <banji-inoue@cybozu.co.jp>
2020-07-29 16:02:05 +09:00
Madhu Rajanna 28f0471106 ceph: update clusterrole of operator for csidrivers
updated the clusterrole of the rook operator
to delete the csidrivers object when csi-drivers
are disabled, without the required access rook operator
cannot delete the csidrivers object.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2020-07-29 09:41:26 +05:30
Jiffin Tony Thottan f4240cb31d ceph: add quota support for obc
Closes: #5274
Signed-off-by: Jiffin Tony Thottan <thottanjiffin@gmail.com>
2020-07-28 12:00:11 +05:30
Ahmad Nurus S 45f0debd00 nfs: nfs provisioner controlled by operator
Signed-off-by: Ahmad Nurus S <prksu.sh@gmail.com>
2020-07-27 12:24:32 +07:00
Alexander Trost 0795204b1d Merge pull request #5872 from cloudical-io/cassandra_update
cassandra: use latest 3.11.6 version in examples
2020-07-23 15:26:36 +02:00
Sébastien Han e517ac96aa ceph: fail if the pool fails to be deleted
Let's assert if the pool is still present.

Signed-off-by: Sébastien Han <seb@redhat.com>
2020-07-22 17:25:15 +02:00
Sébastien Han 39931b1edf ceph: fix conditions not being applied
Somehow, the client.Update was not updating the cluster object, using
client.Status().Update actually fixed it.

Signed-off-by: Sébastien Han <seb@redhat.com>
2020-07-22 17:25:15 +02:00
Travis Nielsen 66d81230ac Merge pull request #5870 from Madhu-1/remove-metaflag
ceph: remove unwanted metadatastore and mountcache flag
2020-07-22 09:00:23 -06:00
Alexander Trost 29e51cb1e9 cassandra: use latest 3.11.6 version in examples
This also updates the cassandra version in the tests.
This is to provide safe and secure defaults to users running Cassandra.

Signed-off-by: Alexander Trost <galexrt@googlemail.com>
2020-07-22 13:18:43 +02:00
Madhu Rajanna 73e1ee41c3 ceph: remove unwanted metadatastore and mountcache flag
metadatastore and mountcache are required for cephcsi v1.0.0

as rook doesnot used ceph-csi v1.+ version
we can remove this flag. Removing these flags doesnot
affect the functionality of anything.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2020-07-22 14:36:11 +05:30
Sébastien Han bc4875a5eb ci: only apply cleanup policy on converged cluster
There is no point of asking for a cleanup when the cluster is external,
also the cleanup pod will never exist and the CI will fail waiting for
it.

Signed-off-by: Sébastien Han <seb@redhat.com>
2020-07-21 17:10:28 +02:00
Sébastien Han 6444675d4d ci: debug cleanup job logs
Add logs of the cleanup jobs on success.

Signed-off-by: Sébastien Han <seb@redhat.com>
2020-07-21 17:10:26 +02:00
Sébastien Han 10ed662bdb ceph: enhancement disk sanitize options
Now, we can not only cleanup monitor data, logs and crashes but the
disks too. As part of the cleanupPolicy CR spec, we have a new setting
called sanitizeDisk which holds more details:

* method: indicates if the entire disk should be sanitized or simply ceph's metadata.
Possible choices are 'complete' or 'quick' (default)
* dataSource: indicate where to get random bytes from to write on the disk.
Possible choices are 'zero' (default) or 'random'
Using random sources will consume entropy from the system and will take much more time then the zero source
* iteration: overwrite N times instead of the default (1). Takes an integer value

See the documentation for more details.

Signed-off-by: Sébastien Han <seb@redhat.com>
2020-07-21 14:07:11 +02:00
Sébastien Han 97a029e691 Merge pull request #5844 from vbnrh/ci-issue-admission
ceph:  disables admission controller tests for k8 v1.14 and older.
2020-07-20 17:48:54 +02:00