Files
my-rook-config/pkg/operator/ceph/object/status.go
T
Blaine Gardner a777b1d7d1 object: do not create service for external object stores
External CephObjectStores already have endpoints defined by
spec.gateway.externalRgwEndpoints, and if the external store is
configured with TLS (HTTPS), the store's certificates will likely not
accept connections intended for the Service endpoint Rook creates. Some
users might not be able to easily add the service endpoint to their
certificates. Therefore, don't even bother creating a Service for
external clusters.

This does introduce a few issues. The Service seems to have been
initially created to allow multiple external RGW endpoints to be
addressable via a single address in Rook. For all connections to an
external CephObjectStore with multiple endpoints, simply choose an
endpoint at random. Random selection will prevent Rook from failing to
create buckets or users on an external store if one of the external
store's endpoints fails.

The latest OBC library (lib-bucket-provisioner) allows updating the
endpoints on ObjectBuckets after they are created. This allows Rook
users to change endpoints on external CephObjectStores without breaking
all existing OBCs. It requires implementation of the new GetUserID()
library call, requires updating Provision() and Grant() calls to be
idempotent, and it requires removing the Update() call.

Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
2022-11-04 17:30:30 -06:00

106 lines
4.2 KiB
Go

/*
Copyright 2020 The Rook Authors. All rights reserved.
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
*/
package object
import (
"context"
"github.com/pkg/errors"
cephv1 "github.com/rook/rook/pkg/apis/ceph.rook.io/v1"
"github.com/rook/rook/pkg/operator/ceph/reporting"
"github.com/rook/rook/pkg/operator/k8sutil"
kerrors "k8s.io/apimachinery/pkg/api/errors"
"k8s.io/apimachinery/pkg/types"
"k8s.io/client-go/util/retry"
"sigs.k8s.io/controller-runtime/pkg/client"
"sigs.k8s.io/controller-runtime/pkg/reconcile"
)
func (r *ReconcileCephObjectStore) setFailedStatus(observedGeneration int64, name types.NamespacedName, errMessage string, err error) (reconcile.Result, error) {
updateStatus(r.opManagerContext, observedGeneration, r.client, name, cephv1.ConditionFailure, map[string]string{})
return reconcile.Result{}, errors.Wrapf(err, "%s", errMessage)
}
// updateStatus updates an object with a given status
func updateStatus(ctx context.Context, observedGeneration int64, client client.Client, namespacedName types.NamespacedName, status cephv1.ConditionType, info map[string]string) {
// Updating the status is important to users, but we can still keep operating if there is a
// failure. Retry a few times to give it our best effort attempt.
err := retry.RetryOnConflict(retry.DefaultRetry, func() error {
objectStore := &cephv1.CephObjectStore{}
if err := client.Get(ctx, namespacedName, objectStore); err != nil {
if kerrors.IsNotFound(err) {
logger.Debug("CephObjectStore resource not found. Ignoring since object must be deleted.")
return nil
}
return errors.Wrapf(err, "failed to retrieve object store %q to update status to %q", namespacedName.String(), status)
}
if objectStore.Status == nil {
objectStore.Status = &cephv1.ObjectStoreStatus{
Endpoints: cephv1.ObjectEndpoints{
Insecure: []string{},
Secure: []string{},
},
}
}
if objectStore.Status.Phase == cephv1.ConditionDeleting {
logger.Debugf("object store %q status not updated to %q because it is deleting", namespacedName.String(), status)
return nil // do not transition to other statuses once deletion begins
}
objectStore.Status.Phase = status
objectStore.Status.Info = info
if observedGeneration != k8sutil.ObservedGenerationNotAvailable {
objectStore.Status.ObservedGeneration = observedGeneration
}
insecurePort := objectStore.Spec.Gateway.Port
if insecurePort > 0 {
objectStore.Status.Endpoints.Insecure = getAllDNSEndpoints(objectStore, insecurePort, false)
}
securePort := objectStore.Spec.Gateway.SecurePort
if securePort > 0 {
objectStore.Status.Endpoints.Secure = getAllDNSEndpoints(objectStore, securePort, true)
}
if err := reporting.UpdateStatus(client, objectStore); err != nil {
return errors.Wrapf(err, "failed to set object store %q status to %q", namespacedName.String(), status)
}
return nil
})
if err != nil {
logger.Error(err)
}
logger.Debugf("object store %q status updated to %q", namespacedName.String(), status)
}
func buildStatusInfo(cephObjectStore *cephv1.CephObjectStore) map[string]string {
m := make(map[string]string)
if cephObjectStore.Spec.Gateway.SecurePort != 0 && cephObjectStore.Spec.Gateway.Port != 0 {
m["secureEndpoint"] = BuildDNSEndpoint(GetStableDomainName(cephObjectStore), cephObjectStore.Spec.Gateway.SecurePort, true)
m["endpoint"] = BuildDNSEndpoint(GetStableDomainName(cephObjectStore), cephObjectStore.Spec.Gateway.Port, false)
} else if cephObjectStore.Spec.Gateway.SecurePort != 0 {
m["endpoint"] = BuildDNSEndpoint(GetStableDomainName(cephObjectStore), cephObjectStore.Spec.Gateway.SecurePort, true)
} else {
m["endpoint"] = BuildDNSEndpoint(GetStableDomainName(cephObjectStore), cephObjectStore.Spec.Gateway.Port, false)
}
return m
}