Files
my-rook-config/pkg/operator/ceph/csi/secrets_test.go
T
Madhu Rajanna ece9efd978 ceph: add mgr caps for csi-rbd-node client
If the kernel doesnt support mapping of
rbd image with deep-flatten feature,cephcsi
need to flatten the rbd image first and than
map the image on the node.

cephcsi first tries to add a task to flatten
the rbd image if its receives any permission
error it will try to call rbd CLI command which
is a blocking call.
This commit adds mgr caps to the csi-rbd-node user
so that cephcsi will add flatten task and return
immediate error to the kubelet, let kubelet retry
again,If we go with blocking rbd CLI call we may
end up having stale maps on the node in corner cases.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
2020-12-08 17:09:18 +05:30

44 lines
1.5 KiB
Go

/*
Copyright 2019 The Rook Authors. All rights reserved.
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
*/
package csi
import (
"testing"
"github.com/stretchr/testify/assert"
)
func TestCephCSIKeyringRBDNodeCaps(t *testing.T) {
caps := cephCSIKeyringRBDNodeCaps()
assert.Equal(t, caps, []string{"mon", "profile rbd", "mgr", "allow rw", "osd", "profile rbd"})
}
func TestCephCSIKeyringRBDProvisionerCaps(t *testing.T) {
caps := cephCSIKeyringRBDProvisionerCaps()
assert.Equal(t, caps, []string{"mon", "profile rbd", "mgr", "allow rw", "osd", "profile rbd"})
}
func TestCephCSIKeyringCephFSNodeCaps(t *testing.T) {
caps := cephCSIKeyringCephFSNodeCaps()
assert.Equal(t, caps, []string{"mon", "allow r", "mgr", "allow rw", "osd", "allow rw tag cephfs *=*", "mds", "allow rw"})
}
func TestCephCSIKeyringCephFSProvisionerCaps(t *testing.T) {
caps := cephCSIKeyringCephFSProvisionerCaps()
assert.Equal(t, caps, []string{"mon", "allow r", "mgr", "allow rw", "osd", "allow rw tag cephfs metadata=*"})
}