github truenas/truenas-csi v1.4.0

2 hours ago

Fixes iSCSI CHAP, adds private CA and outbound proxy support, stops clones from
leaking snapshots, and keeps the operator's workloads in sync.

Changes

  • iSCSI CHAP works end to end, including mutual CHAP. Retried and cloned volumes
    keep their StorageClass's access control, and auth entries and initiator
    groups are deleted with their volumes (#66).
  • Trust a private CA with TRUENAS_CA_BUNDLE, the operator's trustedCA, or
    the chart's truenas.caBundle. See
    docs/tls.md (#67).
  • The driver now honors HTTP_PROXY, HTTPS_PROXY and NO_PROXY for the TrueNAS
    API. Operator: useClusterProxy; chart: proxy.*. See
    docs/proxy.md (#68).
  • Snapshot deletes are deferred, so a snapshot a clone depends on is destroyed
    when the clone goes instead of being left behind. See
    docs/snapshots.md (#69).
  • iSCSI login allows 30 seconds instead of 3 (#74).
  • Hostname iSCSI portals now work, matched to a TrueNAS portal bound to the
    address they resolve to (#77).
  • The operator restarts the CSI pods when the ConfigMap, API key or trusted CA
    changes (#63), puts back anything it deploys that is deleted or changed, and
    implements managementState: Removed (#64). The chart restarts them when its
    ConfigMap changes.
  • README: turning on discovery authentication on TrueNAS stops initiators from
    listing targets (#73).

Upgrading

  • With the operator, the controller and node pods restart once.
  • A second TrueNASCSI CR now fails with "already owned"; the first keeps running.
  • A TrueNAS certificate the driver cannot verify now stops the pod with an error
    naming the fix, instead of leaving it un-Ready with no visible error.
  • trustedCA and useClusterProxy are off unless set, so a cluster-wide proxy
    does not start carrying TrueNAS traffic on upgrade.
  • iSCSI nodes no longer use SendTargets discovery; they log in directly.
  • A failed snapshot delete is now returned to the snapshotter and retried,
    instead of being reported as done.

Leftovers from earlier versions:

  • csi-clone-* snapshots, one per cloned PVC, are deleted by the controller
    when it starts. Orphaned snapshot-* snapshots need a manual check; see
    docs/snapshots.md.
  • iSCSI targets created for cloned volumes, or while retrying a volume create,
    have no CHAP or initiator group even if the StorageClass asked for one.
    Existing targets are not changed; check them in TrueNAS.
  • Auth entries and initiator groups of volumes deleted before the upgrade were
    never removed. Mutual CHAP entries were also created with discovery
    authentication, which blocks unauthenticated discovery for every initiator on
    the appliance. Delete unused entries in TrueNAS (it refuses to delete one a
    target still uses), or set their discovery authentication to None.

Images

  • quay.io/truenas_solutions/truenas-csi:v1.4.0
  • quay.io/truenas_solutions/truenas-csi-operator:v1.4.0
  • quay.io/truenas_solutions/truenas-csi-operator-bundle:v1.4.0
  • ghcr.io/truenas/truenas-csi:v1.4.0
  • Helm chart 1.4.0

This release is not yet Red Hat certified. v1.1.2 remains the certified release
in the OpenShift catalog.

Don't miss a new truenas-csi release

NewReleases is sending notifications on new releases.