artifacthub helm/rook/rook-ceph 1.21.0
v1.21.0

3 hours ago

Upgrade Guide

To upgrade from previous versions of Rook, see the Rook upgrade guide.

Breaking Changes

  • Helm OCI chart tags no longer include the v prefix (e.g., 1.21.0 instead of v1.21.0). Update any scripts or tooling that reference the chart by tag.
  • Ceph msgrv2 is required by default. Msgrv2 requires the 5.11 kernel. If you still cannot use msgrv2 due to an older kernel, disable the msgrv2 protocol with the CephCluster CR setting network.connections.requireMsgr2: false. If using the helm chart, this same value is applied under the cephClusterSpec of the values.
  • New installs of NFS must define a CephBlockPool for the .nfs pool. Rook no longer automatically creates the .nfs pool. A sample CephBlockPool spec is included in deploy/examples/nfs.yaml. Upgraded clusters are not impacted, as the .nfspool was already previously created.

Features

  • Ceph Umbrella (v21) is now a supported version of Ceph, once v21.2.0 is released by the Ceph team soon.
  • RBD Quality of Service (QoS) support is configured via the VolumeAttributesClass using the krbd mounter with cgroup v2 io.max enforcement. See the RBD QoS documentation for details.
  • Automated OSD replacement: An OSD deployment can be annotated to mark it for replacement. Rook will drain and destroy it by preserving its CRUSH position to later reuse it when new device will be available on the same node. All types of OSDs supported for host-based clusters, including OSDs sharing a metadata device. PVC-based OSDs are not supported for this new replacement design. See OSD replacement design document for details.
  • The rook-ceph-cluster Helm chart can create CephObjectStoreUser resources via the new cephObjectStoreUsers value.
  • The toolbox deployments from the Helm chart and the example manifests now reload the keyring and ceph.conf automatically after CephX key rotation, mon failover, or a config override change.
  • CephCluster dashboard TLS certificates can now be configured from a same-namespace Kubernetes TLS Secret with spec.dashboard.sslCertificateRef when the dashboard SSL is enabled. Rook reconciles updates to the referenced Secret and restores the default self-signed certificate when the reference is removed.
  • CephObjectStoreUser gained settings spec.defaultPlacement and spec.defaultStorageClass, which set the RGW user's default bucket placement target and default storage class. Both are optional and validated by RGW. The effective values are reported in status.info. Removing either field stops Rook from managing it and leaves the last applied value in place on the RGW user, except that changing defaultPlacement without a defaultStorageClass resets the storage class to the new placement target's default.
  • Default CSI driver container images are no longer set by Rook. The configmap rook-csi-operator-image-set-configmap is now configured with empty values, allowing the ceph-csi-operator to use its built-in defaults. Users with custom CSI images should ensure their overrides are present in the configmap after upgrade.

Don't miss a new rook-ceph release

NewReleases is sending notifications on new releases.