Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
35 changes: 35 additions & 0 deletions deploy/charts/ceph-csi-drivers/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -93,6 +93,8 @@ operatorConfig:
verbosity: 0
rotation:
# -- Enable log rotation (default: true)
# On SELinux-enforcing hosts, combine with controllerPlugin.privileged:true
# when using hostPath log storage; the operator does not auto-escalate.
enabled: true
# -- Maximum number of log files to keep (default: 7)
maxFiles: 7
Expand All @@ -101,6 +103,9 @@ operatorConfig:
# -- Periodicity for log rotation (options: hourly, daily, weekly, monthly) (default: "daily")
periodicity: "daily"
# -- Default log directory path (default: "")
# HostPath prefix for rotated CSI log files. Kubernetes does not relabel
# hostPath volumes for SELinux, so unprivileged containers cannot write
# there on SELinux-enforcing hosts.
logHostPath: ""
imageSet:
# -- ConfigMap reference to the image set for the driver (default: "")
Expand Down Expand Up @@ -164,6 +169,8 @@ operatorConfig:
# -- Deployment strategy for the controller plugin (default: {})
deploymentStrategy: {}
# -- Flag to indicate if the container should be privileged (default: false)
# Set to true on SELinux-enforcing hosts (e.g. OpenShift) when log rotation
# writes to a hostPath volume (see log.rotation.enabled/logHostPath).
privileged: false
# -- List of tolerations for the controller plugin (default: [])
tolerations: []
Expand All @@ -186,6 +193,8 @@ drivers:
verbosity: 0
rotation:
# -- Enable log rotation (default: true)
# On SELinux-enforcing hosts, combine with controllerPlugin.privileged:true
# when using hostPath log storage; the operator does not auto-escalate.
enabled: true
# -- Maximum number of log files to keep (default: 7)
maxFiles: 7
Expand All @@ -194,6 +203,9 @@ drivers:
# -- Periodicity for log rotation (options: hourly, daily, weekly, monthly) (default: "daily")
periodicity: "daily"
# -- Default log directory path (default: "")
# HostPath prefix for rotated CSI log files. Kubernetes does not relabel
# hostPath volumes for SELinux, so unprivileged containers cannot write
# there on SELinux-enforcing hosts.
logHostPath: ""
imageSet:
# -- ConfigMap reference to the image set for the driver (default: "")
Expand Down Expand Up @@ -253,6 +265,8 @@ drivers:
# -- Deployment strategy for the controller plugin (default: {})
deploymentStrategy: {}
# -- Flag to indicate if the container should be privileged (default: false)
# Set to true on SELinux-enforcing hosts (e.g. OpenShift) when log rotation
# writes to a hostPath volume (see log.rotation.enabled/logHostPath).
privileged: false
# -- List of tolerations for the controller plugin (default: [])
tolerations: []
Expand Down Expand Up @@ -326,6 +340,8 @@ drivers:
verbosity: 0
rotation:
# -- Enable log rotation (default: true)
# On SELinux-enforcing hosts, combine with controllerPlugin.privileged:true
# when using hostPath log storage; the operator does not auto-escalate.
enabled: true
# -- Maximum number of log files to keep (default: 7)
maxFiles: 7
Expand All @@ -334,6 +350,9 @@ drivers:
# -- Periodicity for log rotation (options: hourly, daily, weekly, monthly) (default: "daily")
periodicity: "daily"
# -- Default log directory path (default: "")
# HostPath prefix for rotated CSI log files. Kubernetes does not relabel
# hostPath volumes for SELinux, so unprivileged containers cannot write
# there on SELinux-enforcing hosts.
logHostPath: ""
imageSet:
# -- ConfigMap reference to the image set for the driver (default: "")
Expand Down Expand Up @@ -393,6 +412,8 @@ drivers:
# -- Deployment strategy for the controller plugin (default: {})
deploymentStrategy: {}
# -- Flag to indicate if the container should be privileged (default: false)
# Set to true on SELinux-enforcing hosts (e.g. OpenShift) when log rotation
# writes to a hostPath volume (see log.rotation.enabled/logHostPath).
privileged: false
# -- List of tolerations for the controller plugin (default: [])
tolerations: []
Expand Down Expand Up @@ -466,6 +487,8 @@ drivers:
verbosity: 0
rotation:
# -- Enable log rotation (default: true)
# On SELinux-enforcing hosts, combine with controllerPlugin.privileged:true
# when using hostPath log storage; the operator does not auto-escalate.
enabled: true
# -- Maximum number of log files to keep (default: 7)
maxFiles: 7
Expand All @@ -474,6 +497,9 @@ drivers:
# -- Periodicity for log rotation (options: hourly, daily, weekly, monthly) (default: "daily")
periodicity: "daily"
# -- Default log directory path (default: "")
# HostPath prefix for rotated CSI log files. Kubernetes does not relabel
# hostPath volumes for SELinux, so unprivileged containers cannot write
# there on SELinux-enforcing hosts.
logHostPath: ""
imageSet:
# -- ConfigMap reference to the image set for the driver (default: "")
Expand Down Expand Up @@ -533,6 +559,8 @@ drivers:
# -- Deployment strategy for the controller plugin (default: {})
deploymentStrategy: {}
# -- Flag to indicate if the container should be privileged (default: false)
# Set to true on SELinux-enforcing hosts (e.g. OpenShift) when log rotation
# writes to a hostPath volume (see log.rotation.enabled/logHostPath).
privileged: false
# -- List of tolerations for the controller plugin (default: [])
tolerations: []
Expand Down Expand Up @@ -603,6 +631,8 @@ drivers:
verbosity: 0
rotation:
# -- Enable log rotation (default: true)
# On SELinux-enforcing hosts, combine with controllerPlugin.privileged:true
# when using hostPath log storage; the operator does not auto-escalate.
enabled: true
# -- Maximum number of log files to keep (default: 7)
maxFiles: 7
Expand All @@ -611,6 +641,9 @@ drivers:
# -- Periodicity for log rotation (options: hourly, daily, weekly, monthly) (default: "daily")
periodicity: "daily"
# -- Default log directory path (default: "")
# HostPath prefix for rotated CSI log files. Kubernetes does not relabel
# hostPath volumes for SELinux, so unprivileged containers cannot write
# there on SELinux-enforcing hosts.
logHostPath: ""
imageSet:
# -- ConfigMap reference to the image set for the driver (default: "")
Expand Down Expand Up @@ -672,6 +705,8 @@ drivers:
# -- Deployment strategy for the controller plugin (default: {})
deploymentStrategy: {}
# -- Flag to indicate if the container should be privileged (default: false)
# Set to true on SELinux-enforcing hosts (e.g. OpenShift) when log rotation
# writes to a hostPath volume (see log.rotation.enabled/logHostPath).
privileged: false
# -- List of tolerations for the controller plugin (default: [])
tolerations: []
Expand Down
17 changes: 17 additions & 0 deletions docs/helm-charts/drivers-chart.gotmpl.md
Original file line number Diff line number Diff line change
Expand Up @@ -69,6 +69,23 @@ The following table lists the configurable parameters of the ceph-csi-drivers ch

{{ template "chart.valuesTable" . }}

### Troubleshooting log rotation on SELinux-enforcing hosts

If log rotation (`log.rotation.enabled`) uses a hostPath volume (`log.rotation.logHostPath`)
on hosts with SELinux in enforcing mode (for example, OpenShift), the controller plugin
containers need `controllerPlugin.privileged:true` to write the rotated log files, as
Kubernetes does not relabel hostPath volumes for SELinux. See [docs/design/logrotate.md](https://github.com/ceph/ceph-csi-operator/blob/main/docs/design/logrotate.md).

The operator does not automatically make the controller plugin privileged; set the field
explicitly per driver or via `operatorConfig.driverSpecDefaults`. The default
`controllerPlugin.privileged:false` is unchanged for non-SELinux clusters.

In mixed clusters with both SELinux-enforcing and non-SELinux nodes, note that
`controllerPlugin.privileged:true` applies to the controller plugin Deployment as a whole.
Use node affinity and tolerations (`controllerPlugin.affinity`,
`controllerPlugin.tolerations`) to place controller plugin pods on the intended nodes
if you need to restrict where privileged pods run.

### **Development Build**

To deploy from a local build from your development environment:
Expand Down
Loading
Loading