From 1e01cd670d7d29c75223e98429856e90efca2231 Mon Sep 17 00:00:00 2001 From: Ben Vincent Date: Fri, 24 Jul 2026 23:06:44 +1000 Subject: [PATCH] Roll cephrgw-operator to v0.2.0 (radosgw-native) cephrgw-operator v0.2.0 rebuilds the Ceph integration to talk directly to radosgw via go-ceph (Admin Ops API) and aws-sdk-go-v2 (S3), replacing the manager dashboard client, and adds fine-grained bucket-access policies. The operator now authenticates with an RGW admin user's access/secret key instead of a dashboard login. - bump the operator image to v0.2.0 - update the envFrom / VaultStaticSecret comments to the CEPH_RGW_* credential keys the new image consumes (the KV seed must be re-put with these keys) Claude-Session: https://claude.ai/code/session_016CEncETbf8cvy1PhsHfFHM --- apps/base/cephrgw-system/deployment.yaml | 9 +++++---- apps/base/cephrgw-system/vaultstaticsecret.yaml | 11 +++++++---- 2 files changed, 12 insertions(+), 8 deletions(-) diff --git a/apps/base/cephrgw-system/deployment.yaml b/apps/base/cephrgw-system/deployment.yaml index 0a27938..3ccfbfa 100644 --- a/apps/base/cephrgw-system/deployment.yaml +++ b/apps/base/cephrgw-system/deployment.yaml @@ -24,15 +24,16 @@ spec: runAsNonRoot: true containers: - name: operator - image: git.unkin.net/unkin/cephrgw-operator:v0.1.0 + image: git.unkin.net/unkin/cephrgw-operator:v0.2.0 args: - --metrics-bind-address=:8080 - --health-probe-bind-address=:8081 - --leader-elect envFrom: - # Provides CEPH_DASHBOARD_URL/USERNAME/PASSWORD and, optionally, - # CEPH_RGW_ENDPOINT / CEPH_DASHBOARD_CA. Create this Secret per - # docs/ceph-setup.md; it is intentionally not managed in GitOps. + # Provides CEPH_RGW_ACCESS_KEY/SECRET_KEY and the endpoints + # (CEPH_RGW_ENDPOINT / CEPH_RGW_ADMIN_ENDPOINT), plus optional + # CEPH_RGW_REGION / CEPH_RGW_CA / CEPH_RGW_INSECURE. Rendered from + # Vault per docs/ceph-setup.md; not managed in GitOps. - secretRef: name: cephrgw-credentials ports: diff --git a/apps/base/cephrgw-system/vaultstaticsecret.yaml b/apps/base/cephrgw-system/vaultstaticsecret.yaml index 142cc74..11009df 100644 --- a/apps/base/cephrgw-system/vaultstaticsecret.yaml +++ b/apps/base/cephrgw-system/vaultstaticsecret.yaml @@ -1,14 +1,17 @@ --- -# Renders the Ceph dashboard credentials from Vault into the cephrgw-credentials +# Renders the radosgw credentials from Vault into the cephrgw-credentials # Secret the operator Deployment consumes via envFrom. The KV secret's keys -# (CEPH_DASHBOARD_URL/USERNAME/PASSWORD, optional CEPH_RGW_ENDPOINT/CA) are -# copied verbatim, so they land as the matching env vars. +# (CEPH_RGW_ACCESS_KEY/SECRET_KEY, CEPH_RGW_ENDPOINT, optional +# CEPH_RGW_ADMIN_ENDPOINT/REGION/CA) are copied verbatim, so they land as the +# matching env vars. # # The path sits under the templated default policy # (kv/data/kubernetes/namespace///*), so it needs no dedicated Vault # role or policy. Seed the values with: # vault kv put kv/kubernetes/namespace/cephrgw-system/default/cephrgw-credentials \ -# CEPH_DASHBOARD_URL=... CEPH_DASHBOARD_USERNAME=... CEPH_DASHBOARD_PASSWORD=... +# CEPH_RGW_ENDPOINT=https://s3.ceph.unkin.net \ +# CEPH_RGW_ADMIN_ENDPOINT=https://radosgw.service.consul:443 \ +# CEPH_RGW_ACCESS_KEY=... CEPH_RGW_SECRET_KEY=... apiVersion: secrets.hashicorp.com/v1beta1 kind: VaultStaticSecret metadata: -- 2.47.3