Support adopting existing radosgw buckets and users
The operator previously assumed it created every user and bucket it managed: reconciling an existing resource could overwrite its user attributes or wipe its bucket policy, and deleting a CRD always deleted the underlying RGW object (only Bucket had retainOnDelete). That made taking over pre-existing radosgw state unsafe. Make adoption first-class. - add retainOnDelete to ObjectStoreUser and BucketAccess (dedicated users), so deleting the CRD orphans the RGW user instead of deleting it (symmetric with Bucket) - merge bucket policy instead of replacing it: the operator marks its own statements with a cephrgwop* Sid and preserves any statement it does not own, so adopting a bucket with a hand-written policy keeps it; add Bucket managePolicy (default true) to opt out of policy management entirely - only reconcile user attributes the spec sets: DisplayName when non-empty and Suspended is now an optional *bool, so adopting a user does not reset them - record adoption: ObjectStoreUser/Bucket status.adopted (+ printcolumn) is true when the RGW object already existed on first reconcile - add GetBucketPolicy + MergeBucketPolicy; keyed adoption detection off the status identity field so a Pending owner wait does not mislabel it - regenerate CRDs/deepcopy; add docs/adoption.md and config/samples/05-adoption.yaml; cover the merge in policy_test.go Claude-Session: https://claude.ai/code/session_016CEncETbf8cvy1PhsHfFHM
This commit is contained in:
@@ -60,6 +60,17 @@ refine it (see `config/samples/04-access-fine-grained.yaml`):
|
||||
RGW honours S3 bucket policy on **Reef 18.2+ / Squid**; condition-key support is
|
||||
a subset of AWS, so validate exotic conditions against your cluster.
|
||||
|
||||
### Adopting existing buckets and users
|
||||
|
||||
The operator can take over buckets/users that already exist in radosgw and hand
|
||||
them back without deleting them. In short: matching CRDs manage the resource in
|
||||
place (no recreation, keys reused, `status.adopted: true`), the bucket policy is
|
||||
**merged** so an existing hand-written policy is preserved (`spec.managePolicy:
|
||||
false` opts out entirely), and `spec.retainOnDelete` on `ObjectStoreUser` /
|
||||
`Bucket` / `BucketAccess` orphans the RGW object instead of deleting it. See
|
||||
**[docs/adoption.md](docs/adoption.md)** and
|
||||
`config/samples/05-adoption.yaml`.
|
||||
|
||||
The `Bucket` controller renders the policy as the **union of every ready
|
||||
`BucketAccess`** that targets it, so the result is convergent regardless of the
|
||||
order objects are created or deleted. It watches `BucketAccess` and
|
||||
|
||||
Reference in New Issue
Block a user