Skip to content

Add support for Ceph RGW Object Store - #8389

Merged
yadvr merged 18 commits into
apache:mainfrom
wido:ceph-object-store
Sep 5, 2024
Merged

Add support for Ceph RGW Object Store#8389
yadvr merged 18 commits into
apache:mainfrom
wido:ceph-object-store

Conversation

@wido

@widowido commented Dec 20, 2023

Copy link
Copy Markdown
Contributor

Description

This PR adds support for the Ceph RGW as an Object Store Driver in CloudStack

Types of changes

  • New feature (non-breaking change which adds functionality)

Screenshots (if appropriate):

Screenshot from 2023-12-20 17-10-04

How Has This Been Tested?

I have a local Ceph environment (IPv6 only) running with the RADOS Gateway (S3 server) running against which I tested this PR.

It also has SSL enabled so it could verify that this works as expected.

How did you try to break this feature and the system with this change?

I manually tried to create and remove buckets and that worked as expected.

@codecov

codecovBot commented Dec 20, 2023

Copy link
Copy Markdown

Codecov Report

Attention: Patch coverage is 13.02083% with 334 lines in your changes missing coverage. Please review.

Project coverage is 15.64%. Comparing base (72d0546) to head (a448992).
Report is 2 commits behind head on main.

Files with missing linesPatch %Lines
...ge/datastore/driver/CephObjectStoreDriverImpl.java13.08%185 Missing and 1 partial ⚠️
...astore/lifecycle/CephObjectStoreLifeCycleImpl.java0.00%57 Missing ⚠️
...e/datastore/driver/MinIOObjectStoreDriverImpl.java11.11%16 Missing ⚠️
...loudstack/storage/object/BucketApiServiceImpl.java0.00%16 Missing ⚠️
...atastore/provider/CephObjectStoreProviderImpl.java40.00%15 Missing ⚠️
...src/main/java/com/cloud/agent/api/to/BucketTO.java22.22%14 Missing ⚠️
...oudstack/storage/object/store/ObjectStoreImpl.java0.00%14 Missing ⚠️
...tastore/driver/SimulatorObjectStoreDriverImpl.java0.00%11 Missing ⚠️
...hema/src/main/java/com/cloud/storage/BucketVO.java66.66%3 Missing ⚠️
...ain/java/com/cloud/storage/StorageManagerImpl.java0.00%2 Missing ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #8389 +/- ##
============================================
+ Coverage 15.57% 15.64% +0.06% - Complexity 12056 12118 +62 
============================================
Files 5506 5539 +33 Lines 482997 485358 +2361 Branches 59483 58983 -500 ============================================
+ Hits 75236 75941 +705 - Misses 399450 401043 +1593 - Partials 8311 8374 +63 
FlagCoverage Δ
uitests4.12% <ø> (-0.05%)⬇️
unittests16.44% <13.02%> (+0.08%)⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@github-actions

Copy link
Copy Markdown

This pull request has merge conflicts. Dear author, please fix the conflicts and sync your branch with the base branch.

@vishesh92vishesh92 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

clgtm

@DaanHoogland

Copy link
Copy Markdown
Contributor

@blueorangutan package

@blueorangutan

Copy link
Copy Markdown

@DaanHoogland a [SL] Jenkins job has been kicked to build packages. It will be bundled with KVM, XenServer and VMware SystemVM templates. I'll keep you posted as I make progress.

@blueorangutan

Copy link
Copy Markdown

Packaging result [SF]: ✖️ el7 ✖️ el8 ✖️ el9 ✖️ debian ✖️ suse15. SL-JID 8356

@yadvr

yadvr commented Feb 5, 2024

Copy link
Copy Markdown
Member

@wido I'll help kick tests again - can you check for build failures?

@blueorangutan package

@blueorangutan

Copy link
Copy Markdown

@rohityadavcloud a [SL] Jenkins job has been kicked to build packages. It will be bundled with KVM, XenServer and VMware SystemVM templates. I'll keep you posted as I make progress.

@blueorangutan

Copy link
Copy Markdown

Packaging result [SF]: ✖️ el7 ✖️ el8 ✖️ el9 ✖️ debian ✖️ suse15. SL-JID 8524

Comment threadplugins/storage/object/ceph/pom.xml Outdated
@weizhouapache

Copy link
Copy Markdown
Member

@blueorangutan package

@blueorangutan

Copy link
Copy Markdown

@weizhouapache a [SL] Jenkins job has been kicked to build packages. It will be bundled with KVM, XenServer and VMware SystemVM templates. I'll keep you posted as I make progress.

@blueorangutan

Copy link
Copy Markdown

Packaging result [SF]: ✖️ el7 ✖️ el8 ✖️ el9 ✖️ debian ✖️ suse15. SL-JID 8548

Signed-off-by: Rohit Yadav <rohit.yadav@shapeblue.com>
Signed-off-by: Rohit Yadav <rohit.yadav@shapeblue.com>
@yadvr

yadvr commented Sep 5, 2024

Copy link
Copy Markdown
Member

@blueorangutan package

@blueorangutan

Copy link
Copy Markdown

@rohityadavcloud a [SL] Jenkins job has been kicked to build packages. It will be bundled with KVM, XenServer and VMware SystemVM templates. I'll keep you posted as I make progress.

@blueorangutan

Copy link
Copy Markdown

Packaging result [SF]: ✖️ el8 ✖️ el9 ✖️ debian ✖️ suse15. SL-JID 10984

Signed-off-by: Rohit Yadav <rohit.yadav@shapeblue.com>
@DaanHoogland

Copy link
Copy Markdown
Contributor

@blueorangutan package

@blueorangutan

Copy link
Copy Markdown

@DaanHoogland a [SL] Jenkins job has been kicked to build packages. It will be bundled with KVM, XenServer and VMware SystemVM templates. I'll keep you posted as I make progress.

@blueorangutan

Copy link
Copy Markdown

Packaging result [SF]: ✖️ el8 ✖️ el9 ✖️ debian ✖️ suse15. SL-JID 10987

@blueorangutan

Copy link
Copy Markdown

Packaging result [SF]: ✔️ el8 ✔️ el9 ✖️ debian ✔️ suse15. SL-JID 10989

@DaanHoogland

Copy link
Copy Markdown
Contributor

@wido :

11:03:41 [ERROR] /jenkins/workspace/acs-deb-pkg-builder/plugins/storage/object/ceph/src/main/java/org/apache/cloudstack/storage/datastore/lifecycle/CephObjectStoreLifeCycleImpl.java:[30,23] error: package org.apache.log4j does not exist
11:03:41 [ERROR] /jenkins/workspace/acs-deb-pkg-builder/plugins/storage/object/ceph/src/main/java/org/apache/cloudstack/storage/datastore/lifecycle/CephObjectStoreLifeCycleImpl.java:[41,25] error: cannot find symbol
11:03:41 symbol: class Logger
11:03:41 location: class CephObjectStoreLifeCycleImpl

strange this error would only happen on the debian build and the el build is successful, but there you have it ???

Packaging result [SF]: ✔️ el8 ✔️ el9 ✖️ debian ✔️ suse15. SL-JID 10989

Signed-off-by: Rohit Yadav <rohit.yadav@shapeblue.com>
@yadvr

yadvr commented Sep 5, 2024

Copy link
Copy Markdown
Member

Fixed some issue, tested LGTM but some cases don't work will raise a separate issue for @wido to explore further:

  • Bucket creation fails when any of the options are specified or these options aren't supported: quota, versioning & encryption, bucket policy
  • During Bucket creation, locking feature/option is ignored
  • User quota not enforced/configured
  • Bucket policy fails and throws exception:
Error while updating bucket. Error while updating bucket: admin-test-bucket. SignatureDoesNotMatch (Service: Amazon S3; Status Code: 403; Error Code: SignatureDoesNotMatch; Request ID: tx00000c2e2357a96c47d4c-0066d97a79-42778b-default; S3 Extended Request ID: 42778b-default-default; Proxy: null)
  • UI browser doesn't work (due to cors issue, couldn't figure out how to configure radosgw for that)

@yadvr

yadvr commented Sep 5, 2024

Copy link
Copy Markdown
Member

@blueorangutan package

@blueorangutan

Copy link
Copy Markdown

@rohityadavcloud a [SL] Jenkins job has been kicked to build packages. It will be bundled with KVM, XenServer and VMware SystemVM templates. I'll keep you posted as I make progress.

@yadvryadvr left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, tested this plugins with Ceph Reef rgw, doesn't support all options but good to merge this.

@yadvr

yadvr commented Sep 5, 2024

Copy link
Copy Markdown
Member

Testing notes:

  1. Setup ceph cluster & rgw service:
Screenshot 2024-09-05 at 1 28 35 PM
  1. Next, was able to add this as object storage pool in cloudstack using url & api/secret credentials by creating a system 'admin' user in the rgw:
Screenshot 2024-09-05 at 1 29 31 PM

Following screenshots show, when cloudstack bucket is created, the relevant user is created in rgw & the bucket:

Screenshot 2024-09-05 at 3 15 12 PMScreenshot 2024-09-05 at 3 15 19 PM
  1. Was able to create bucket without any options or bucket policy, but then was able to use S3 client like Cyberduck to create/configure access permissions on the bucket & upload/download objects/files in it:
Screenshot 2024-09-05 at 2 04 52 PM
  1. Bucket policies don't work via cloudstack UI though and throw exception:
Screenshot 2024-09-05 at 3 01 42 PM

@yadvryadvr closed this Sep 5, 2024
@yadvryadvr reopened this Sep 5, 2024
@apacheapache deleted a comment from blueorangutanSep 5, 2024
@yadvr

yadvr commented Sep 5, 2024

Copy link
Copy Markdown
Member

@blueorangutan package

@blueorangutan

Copy link
Copy Markdown

@rohityadavcloud a [SL] Jenkins job has been kicked to build packages. It will be bundled with KVM, XenServer and VMware SystemVM templates. I'll keep you posted as I make progress.

Signed-off-by: Rohit Yadav <rohit.yadav@shapeblue.com>
@yadvr

yadvr commented Sep 5, 2024

Copy link
Copy Markdown
Member

Merging this based on manual QA with limitations and followup logged at #9641 (cc @wido), reviews, earlier smoketests & GH build/smoketests.

@yadvr
yadvr merged commit c3f0d14 into apache:mainSep 5, 2024
@blueorangutan

Copy link
Copy Markdown

Packaging result [SF]: ✔️ el8 ✔️ el9 ✔️ debian ✔️ suse15. SL-JID 11001

dhslove pushed a commit to ablecloud-team/ablestack-cloud that referenced this pull request Sep 6, 2024
This feature adds support for Ceph's RADOS Gateway (RGW) support for the
Object Store feature of CloudStack.
The RGW of Ceph is Amazon S3 compliant and is therefor an easy and straigforward
implementation of basic S3 features.
Existing Ceph environments can have the RGW added as an additional feature to a
cluster already providing RBD (Block Device) to a CloudStack environment.
Introduce the BucketTO to pass to the drivers. This replaces just passing the bucket's name.
Some upcoming drivers require more information then just the bucket name to perform their actions,
for example they require the access and secret key which belong to the account of this bucket.
This is leftover code from a long time ago and this validation test has nu influence
on the end result on how a URL will be used afterwards.
We should support hosts pointing to an IPv6(-only) address out of the box.
For the code it does not matter if it's IPv4 or IPv6. This is the admin's choice.
Signed-off-by: Rohit Yadav <rohit.yadav@shapeblue.com>
Co-authored-by: Rohit Yadav <rohit.yadav@shapeblue.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

9 participants

@wido@DaanHoogland@blueorangutan@yadvr@weizhouapache@shwstppr@vishesh92@piyushvijay@JoaoJandre