forked from rook/rook
External CephObjectStores already have endpoints defined by spec.gateway.externalRgwEndpoints, and if the external store is configured with TLS (HTTPS), the store's certificates will likely not accept connections intended for the Service endpoint Rook creates. Some users might not be able to easily add the service endpoint to their certificates. Therefore, don't even bother creating a Service for external clusters. This does introduce a few issues. The Service seems to have been initially created to allow multiple external RGW endpoints to be addressable via a single address in Rook. For all connections to an external CephObjectStore with multiple endpoints, simply choose an endpoint at random. Random selection will prevent Rook from failing to create buckets or users on an external store if one of the external store's endpoints fails. The latest OBC library (lib-bucket-provisioner) allows updating the endpoints on ObjectBuckets after they are created. This allows Rook users to change endpoints on external CephObjectStores without breaking all existing OBCs. It requires implementation of the new GetUserID() library call, requires updating Provision() and Grant() calls to be idempotent, and it requires removing the Update() call. Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
106 lines
4.2 KiB
Go
106 lines
4.2 KiB
Go
/*
|
|
Copyright 2020 The Rook Authors. All rights reserved.
|
|
|
|
Licensed under the Apache License, Version 2.0 (the "License");
|
|
you may not use this file except in compliance with the License.
|
|
You may obtain a copy of the License at
|
|
|
|
http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
Unless required by applicable law or agreed to in writing, software
|
|
distributed under the License is distributed on an "AS IS" BASIS,
|
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
See the License for the specific language governing permissions and
|
|
limitations under the License.
|
|
*/
|
|
|
|
package object
|
|
|
|
import (
|
|
"context"
|
|
|
|
"github.com/pkg/errors"
|
|
cephv1 "github.com/rook/rook/pkg/apis/ceph.rook.io/v1"
|
|
"github.com/rook/rook/pkg/operator/ceph/reporting"
|
|
"github.com/rook/rook/pkg/operator/k8sutil"
|
|
kerrors "k8s.io/apimachinery/pkg/api/errors"
|
|
"k8s.io/apimachinery/pkg/types"
|
|
"k8s.io/client-go/util/retry"
|
|
"sigs.k8s.io/controller-runtime/pkg/client"
|
|
"sigs.k8s.io/controller-runtime/pkg/reconcile"
|
|
)
|
|
|
|
func (r *ReconcileCephObjectStore) setFailedStatus(observedGeneration int64, name types.NamespacedName, errMessage string, err error) (reconcile.Result, error) {
|
|
updateStatus(r.opManagerContext, observedGeneration, r.client, name, cephv1.ConditionFailure, map[string]string{})
|
|
return reconcile.Result{}, errors.Wrapf(err, "%s", errMessage)
|
|
}
|
|
|
|
// updateStatus updates an object with a given status
|
|
func updateStatus(ctx context.Context, observedGeneration int64, client client.Client, namespacedName types.NamespacedName, status cephv1.ConditionType, info map[string]string) {
|
|
// Updating the status is important to users, but we can still keep operating if there is a
|
|
// failure. Retry a few times to give it our best effort attempt.
|
|
err := retry.RetryOnConflict(retry.DefaultRetry, func() error {
|
|
objectStore := &cephv1.CephObjectStore{}
|
|
if err := client.Get(ctx, namespacedName, objectStore); err != nil {
|
|
if kerrors.IsNotFound(err) {
|
|
logger.Debug("CephObjectStore resource not found. Ignoring since object must be deleted.")
|
|
return nil
|
|
}
|
|
return errors.Wrapf(err, "failed to retrieve object store %q to update status to %q", namespacedName.String(), status)
|
|
}
|
|
if objectStore.Status == nil {
|
|
objectStore.Status = &cephv1.ObjectStoreStatus{
|
|
Endpoints: cephv1.ObjectEndpoints{
|
|
Insecure: []string{},
|
|
Secure: []string{},
|
|
},
|
|
}
|
|
}
|
|
|
|
if objectStore.Status.Phase == cephv1.ConditionDeleting {
|
|
logger.Debugf("object store %q status not updated to %q because it is deleting", namespacedName.String(), status)
|
|
return nil // do not transition to other statuses once deletion begins
|
|
}
|
|
|
|
objectStore.Status.Phase = status
|
|
objectStore.Status.Info = info
|
|
if observedGeneration != k8sutil.ObservedGenerationNotAvailable {
|
|
objectStore.Status.ObservedGeneration = observedGeneration
|
|
}
|
|
|
|
insecurePort := objectStore.Spec.Gateway.Port
|
|
if insecurePort > 0 {
|
|
objectStore.Status.Endpoints.Insecure = getAllDNSEndpoints(objectStore, insecurePort, false)
|
|
}
|
|
securePort := objectStore.Spec.Gateway.SecurePort
|
|
if securePort > 0 {
|
|
objectStore.Status.Endpoints.Secure = getAllDNSEndpoints(objectStore, securePort, true)
|
|
}
|
|
|
|
if err := reporting.UpdateStatus(client, objectStore); err != nil {
|
|
return errors.Wrapf(err, "failed to set object store %q status to %q", namespacedName.String(), status)
|
|
}
|
|
return nil
|
|
})
|
|
if err != nil {
|
|
logger.Error(err)
|
|
}
|
|
|
|
logger.Debugf("object store %q status updated to %q", namespacedName.String(), status)
|
|
}
|
|
|
|
func buildStatusInfo(cephObjectStore *cephv1.CephObjectStore) map[string]string {
|
|
m := make(map[string]string)
|
|
|
|
if cephObjectStore.Spec.Gateway.SecurePort != 0 && cephObjectStore.Spec.Gateway.Port != 0 {
|
|
m["secureEndpoint"] = BuildDNSEndpoint(GetStableDomainName(cephObjectStore), cephObjectStore.Spec.Gateway.SecurePort, true)
|
|
m["endpoint"] = BuildDNSEndpoint(GetStableDomainName(cephObjectStore), cephObjectStore.Spec.Gateway.Port, false)
|
|
} else if cephObjectStore.Spec.Gateway.SecurePort != 0 {
|
|
m["endpoint"] = BuildDNSEndpoint(GetStableDomainName(cephObjectStore), cephObjectStore.Spec.Gateway.SecurePort, true)
|
|
} else {
|
|
m["endpoint"] = BuildDNSEndpoint(GetStableDomainName(cephObjectStore), cephObjectStore.Spec.Gateway.Port, false)
|
|
}
|
|
|
|
return m
|
|
}
|