Roll cephrgw-operator to v0.2.0 (radosgw-native) (#273)
## Why cephrgw-operator **v0.2.0** rebuilds the Ceph integration to talk directly to radosgw via **go-ceph** (Admin Ops API) + **aws-sdk-go-v2** (S3), replacing the manager-dashboard client, and adds **fine-grained bucket-access policies** (paths / actions / conditions / rawStatements). The operator now authenticates with an **RGW admin user's access/secret key** instead of a dashboard login. Operator repo PRs: unkin/cephrgw-operator #3 (rebuild) and #4 (fine-grained), both merged; tag `v0.2.0`. ## Changes - bump the operator image `git.unkin.net/unkin/cephrgw-operator` → `v0.2.0` - update the `envFrom` / `VaultStaticSecret` comments to the `CEPH_RGW_*` credential keys the new image consumes ## Required manual step (runtime) The VaultStaticSecret copies the KV secret's keys **verbatim**, so the seed must be re-put with the new keys before/with rollout — otherwise the operator fails auth: ``` vault kv put kv/kubernetes/namespace/cephrgw-system/default/cephrgw-credentials \ CEPH_RGW_ENDPOINT=https://s3.ceph.unkin.net \ CEPH_RGW_ADMIN_ENDPOINT=https://radosgw.service.consul:443 \ CEPH_RGW_ACCESS_KEY=<key> CEPH_RGW_SECRET_KEY=<secret> ``` (The old `CEPH_DASHBOARD_*` keys are ignored by v0.2.0.) VSO refreshes within 5m and the `reloader` annotation restarts the operator. https://claude.ai/code/session_016CEncETbf8cvy1PhsHfFHM Reviewed-on: #273 Co-authored-by: Ben Vincent <ben@unkin.net> Co-committed-by: Ben Vincent <ben@unkin.net>
This commit was merged in pull request #273.
This commit is contained in:
@@ -24,15 +24,16 @@ spec:
|
|||||||
runAsNonRoot: true
|
runAsNonRoot: true
|
||||||
containers:
|
containers:
|
||||||
- name: operator
|
- name: operator
|
||||||
image: git.unkin.net/unkin/cephrgw-operator:v0.1.0
|
image: git.unkin.net/unkin/cephrgw-operator:v0.2.0
|
||||||
args:
|
args:
|
||||||
- --metrics-bind-address=:8080
|
- --metrics-bind-address=:8080
|
||||||
- --health-probe-bind-address=:8081
|
- --health-probe-bind-address=:8081
|
||||||
- --leader-elect
|
- --leader-elect
|
||||||
envFrom:
|
envFrom:
|
||||||
# Provides CEPH_DASHBOARD_URL/USERNAME/PASSWORD and, optionally,
|
# Provides CEPH_RGW_ACCESS_KEY/SECRET_KEY and the endpoints
|
||||||
# CEPH_RGW_ENDPOINT / CEPH_DASHBOARD_CA. Create this Secret per
|
# (CEPH_RGW_ENDPOINT / CEPH_RGW_ADMIN_ENDPOINT), plus optional
|
||||||
# docs/ceph-setup.md; it is intentionally not managed in GitOps.
|
# CEPH_RGW_REGION / CEPH_RGW_CA / CEPH_RGW_INSECURE. Rendered from
|
||||||
|
# Vault per docs/ceph-setup.md; not managed in GitOps.
|
||||||
- secretRef:
|
- secretRef:
|
||||||
name: cephrgw-credentials
|
name: cephrgw-credentials
|
||||||
ports:
|
ports:
|
||||||
|
|||||||
@@ -1,14 +1,17 @@
|
|||||||
---
|
---
|
||||||
# Renders the Ceph dashboard credentials from Vault into the cephrgw-credentials
|
# Renders the radosgw credentials from Vault into the cephrgw-credentials
|
||||||
# Secret the operator Deployment consumes via envFrom. The KV secret's keys
|
# Secret the operator Deployment consumes via envFrom. The KV secret's keys
|
||||||
# (CEPH_DASHBOARD_URL/USERNAME/PASSWORD, optional CEPH_RGW_ENDPOINT/CA) are
|
# (CEPH_RGW_ACCESS_KEY/SECRET_KEY, CEPH_RGW_ENDPOINT, optional
|
||||||
# copied verbatim, so they land as the matching env vars.
|
# CEPH_RGW_ADMIN_ENDPOINT/REGION/CA) are copied verbatim, so they land as the
|
||||||
|
# matching env vars.
|
||||||
#
|
#
|
||||||
# The path sits under the templated default policy
|
# The path sits under the templated default policy
|
||||||
# (kv/data/kubernetes/namespace/<ns>/<sa>/*), so it needs no dedicated Vault
|
# (kv/data/kubernetes/namespace/<ns>/<sa>/*), so it needs no dedicated Vault
|
||||||
# role or policy. Seed the values with:
|
# role or policy. Seed the values with:
|
||||||
# vault kv put kv/kubernetes/namespace/cephrgw-system/default/cephrgw-credentials \
|
# vault kv put kv/kubernetes/namespace/cephrgw-system/default/cephrgw-credentials \
|
||||||
# CEPH_DASHBOARD_URL=... CEPH_DASHBOARD_USERNAME=... CEPH_DASHBOARD_PASSWORD=...
|
# CEPH_RGW_ENDPOINT=https://s3.ceph.unkin.net \
|
||||||
|
# CEPH_RGW_ADMIN_ENDPOINT=https://radosgw.service.consul:443 \
|
||||||
|
# CEPH_RGW_ACCESS_KEY=... CEPH_RGW_SECRET_KEY=...
|
||||||
apiVersion: secrets.hashicorp.com/v1beta1
|
apiVersion: secrets.hashicorp.com/v1beta1
|
||||||
kind: VaultStaticSecret
|
kind: VaultStaticSecret
|
||||||
metadata:
|
metadata:
|
||||||
|
|||||||
Reference in New Issue
Block a user