forked from rook/rook
When the Ceph cluster runs on PVC and the OSDs are encrypted we can store LUKS's Key Encryption Key inside a Key Management System. Today, Rook only supports HashiCorp Vault: https://www.vaultproject.io/ The CephCluster has now a new "security" field which will plug onto the KMS. Here is an example: security: kms: tokenSecretName: <name of the secret containing a Vault token, used to authenticate> connectionDetails: < a map of strings containing connection information> Refer to the ceph-cluster-crd documentation to lear more. Closes: https://github.com/rook/rook/issues/6105 Signed-off-by: Sébastien Han <seb@redhat.com>
40 lines
707 B
Bash
Executable File
40 lines
707 B
Bash
Executable File
#!/bin/bash
|
|
set -ex
|
|
|
|
#############
|
|
# VARIABLES #
|
|
#############
|
|
MOD_FILE="mod"
|
|
CODEGEN_FILE="zz"
|
|
CODEGEN_ERR="found codegen files! please run 'make codegen' and update your PR"
|
|
MOD_ERR="changes found by mod.check. You may need to run make clean"
|
|
|
|
#############
|
|
# FUNCTIONS #
|
|
#############
|
|
function validate(){
|
|
for file in $(git status --porcelain); do
|
|
if [[ "$file" =~ $1 ]]; then
|
|
echo "$2"
|
|
exit 1
|
|
fi
|
|
done
|
|
}
|
|
|
|
########
|
|
# MAIN #
|
|
########
|
|
case "$1" in
|
|
codegen)
|
|
validate "$CODEGEN_FILE" "$CODEGEN_ERR"
|
|
;;
|
|
modcheck)
|
|
validate "$MOD_FILE" "$MOD_ERR"
|
|
;;
|
|
*)
|
|
echo $"Usage: $0 {codegen|modcheck}"
|
|
exit 1
|
|
esac
|
|
|
|
|