forked from rook/rook
The toolbox is really only used for ceph commands. The main reason the rook image was being used in the toolbox pod was for the script that generates the ceph.conf and updates it whenever the mons are updated during mon failover. Now the ceph image can be specified directly by moving the script inline with the container definition instead of being required in the image. The rook image will still contain the script for backward compatibility and for scenarios where the rook binary may still be needed Signed-off-by: Travis Nielsen <tnielsen@redhat.com>
118 lines
3.7 KiB
YAML
118 lines
3.7 KiB
YAML
apiVersion: apps/v1
|
|
kind: Deployment
|
|
metadata:
|
|
name: rook-ceph-tools
|
|
namespace: rook-ceph # namespace:cluster
|
|
labels:
|
|
app: rook-ceph-tools
|
|
spec:
|
|
replicas: 1
|
|
selector:
|
|
matchLabels:
|
|
app: rook-ceph-tools
|
|
template:
|
|
metadata:
|
|
labels:
|
|
app: rook-ceph-tools
|
|
spec:
|
|
dnsPolicy: ClusterFirstWithHostNet
|
|
containers:
|
|
- name: rook-ceph-tools
|
|
image: quay.io/ceph/ceph:v17.2.1
|
|
command:
|
|
- /bin/bash
|
|
- -c
|
|
- |
|
|
# Replicate the script from toolbox.sh inline so the ceph image
|
|
# can be run directly, instead of requiring the rook toolbox
|
|
CEPH_CONFIG="/etc/ceph/ceph.conf"
|
|
MON_CONFIG="/etc/rook/mon-endpoints"
|
|
KEYRING_FILE="/etc/ceph/keyring"
|
|
|
|
# create a ceph config file in its default location so ceph/rados tools can be used
|
|
# without specifying any arguments
|
|
write_endpoints() {
|
|
endpoints=$(cat ${MON_CONFIG})
|
|
|
|
# filter out the mon names
|
|
# external cluster can have numbers or hyphens in mon names, handling them in regex
|
|
# shellcheck disable=SC2001
|
|
mon_endpoints=$(echo "${endpoints}"| sed 's/[a-z0-9_-]\+=//g')
|
|
|
|
DATE=$(date)
|
|
echo "$DATE writing mon endpoints to ${CEPH_CONFIG}: ${endpoints}"
|
|
cat <<EOF > ${CEPH_CONFIG}
|
|
[global]
|
|
mon_host = ${mon_endpoints}
|
|
|
|
[client.admin]
|
|
keyring = ${KEYRING_FILE}
|
|
EOF
|
|
}
|
|
|
|
# watch the endpoints config file and update if the mon endpoints ever change
|
|
watch_endpoints() {
|
|
# get the timestamp for the target of the soft link
|
|
real_path=$(realpath ${MON_CONFIG})
|
|
initial_time=$(stat -c %Z "${real_path}")
|
|
while true; do
|
|
real_path=$(realpath ${MON_CONFIG})
|
|
latest_time=$(stat -c %Z "${real_path}")
|
|
|
|
if [[ "${latest_time}" != "${initial_time}" ]]; then
|
|
write_endpoints
|
|
initial_time=${latest_time}
|
|
fi
|
|
|
|
sleep 10
|
|
done
|
|
}
|
|
|
|
# create the keyring file
|
|
cat <<EOF > ${KEYRING_FILE}
|
|
[${ROOK_CEPH_USERNAME}]
|
|
key = ${ROOK_CEPH_SECRET}
|
|
EOF
|
|
|
|
# write the initial config file
|
|
write_endpoints
|
|
|
|
# continuously update the mon endpoints if they fail over
|
|
watch_endpoints
|
|
imagePullPolicy: IfNotPresent
|
|
tty: true
|
|
securityContext:
|
|
runAsNonRoot: true
|
|
runAsUser: 2016
|
|
runAsGroup: 2016
|
|
env:
|
|
- name: ROOK_CEPH_USERNAME
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: rook-ceph-mon
|
|
key: ceph-username
|
|
- name: ROOK_CEPH_SECRET
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: rook-ceph-mon
|
|
key: ceph-secret
|
|
volumeMounts:
|
|
- mountPath: /etc/ceph
|
|
name: ceph-config
|
|
- name: mon-endpoint-volume
|
|
mountPath: /etc/rook
|
|
volumes:
|
|
- name: mon-endpoint-volume
|
|
configMap:
|
|
name: rook-ceph-mon-endpoints
|
|
items:
|
|
- key: data
|
|
path: mon-endpoints
|
|
- name: ceph-config
|
|
emptyDir: {}
|
|
tolerations:
|
|
- key: "node.kubernetes.io/unreachable"
|
|
operator: "Exists"
|
|
effect: "NoExecute"
|
|
tolerationSeconds: 5
|