Upgrade Guide
To upgrade from previous versions of Rook, see the Rook upgrade guide.
Breaking Changes
- Helm OCI chart tags no longer include the
vprefix (e.g.,1.21.0instead ofv1.21.0). Update any scripts or tooling that reference the chart by tag. - Ceph msgrv2 is required by default. Msgrv2 requires the 5.11 kernel. If you still cannot use msgrv2 due to an older kernel, disable the msgrv2 protocol with the CephCluster CR setting
network.connections.requireMsgr2: false. If using the helm chart, this same value is applied under thecephClusterSpecof the values. - New installs of NFS must define a CephBlockPool for the
.nfspool. Rook no longer automatically creates the.nfspool. A sample CephBlockPool spec is included indeploy/examples/nfs.yaml. Upgraded clusters are not impacted, as the.nfspool was already previously created.
Features
- Ceph Umbrella (v21) is now a supported version of Ceph, once v21.2.0 is released by the Ceph team soon.
- RBD Quality of Service (QoS) support is configured via the
VolumeAttributesClassusing the krbd mounter with cgroup v2io.maxenforcement. See the RBD QoS documentation for details. - Automated OSD replacement: An OSD deployment can be annotated to mark it for replacement. Rook will drain and destroy it by preserving its CRUSH position to later reuse it when new device will be available on the same node. All types of OSDs supported for host-based clusters, including OSDs sharing a metadata device. PVC-based OSDs are not supported for this new replacement design. See OSD replacement design document for details.
- The rook-ceph-cluster Helm chart can create
CephObjectStoreUserresources via the newcephObjectStoreUsersvalue. - The toolbox deployments from the Helm chart and the example manifests now reload the keyring and
ceph.confautomatically after CephX key rotation, mon failover, or a config override change. - CephCluster dashboard TLS certificates can now be configured from a same-namespace Kubernetes TLS Secret with
spec.dashboard.sslCertificateRefwhen the dashboard SSL is enabled. Rook reconciles updates to the referenced Secret and restores the default self-signed certificate when the reference is removed. CephObjectStoreUsergained settingsspec.defaultPlacementandspec.defaultStorageClass, which set the RGW user's default bucket placement target and default storage class. Both are optional and validated by RGW. The effective values are reported instatus.info. Removing either field stops Rook from managing it and leaves the last applied value in place on the RGW user, except that changingdefaultPlacementwithout adefaultStorageClassresets the storage class to the new placement target's default.- Default CSI driver container images are no longer set by Rook. The configmap
rook-csi-operator-image-set-configmapis now configured with empty values, allowing the ceph-csi-operator to use its built-in defaults. Users with custom CSI images should ensure their overrides are present in the configmap after upgrade.