Fixes iSCSI CHAP, adds private CA and outbound proxy support, stops clones from
leaking snapshots, and keeps the operator's workloads in sync.
Changes
- iSCSI CHAP works end to end, including mutual CHAP. Retried and cloned volumes
keep their StorageClass's access control, and auth entries and initiator
groups are deleted with their volumes (#66). - Trust a private CA with
TRUENAS_CA_BUNDLE, the operator'strustedCA, or
the chart'struenas.caBundle. See
docs/tls.md (#67). - The driver now honors HTTP_PROXY, HTTPS_PROXY and NO_PROXY for the TrueNAS
API. Operator:useClusterProxy; chart:proxy.*. See
docs/proxy.md (#68). - Snapshot deletes are deferred, so a snapshot a clone depends on is destroyed
when the clone goes instead of being left behind. See
docs/snapshots.md (#69). - iSCSI login allows 30 seconds instead of 3 (#74).
- Hostname iSCSI portals now work, matched to a TrueNAS portal bound to the
address they resolve to (#77). - The operator restarts the CSI pods when the ConfigMap, API key or trusted CA
changes (#63), puts back anything it deploys that is deleted or changed, and
implementsmanagementState: Removed(#64). The chart restarts them when its
ConfigMap changes. - README: turning on discovery authentication on TrueNAS stops initiators from
listing targets (#73).
Upgrading
- With the operator, the controller and node pods restart once.
- A second TrueNASCSI CR now fails with "already owned"; the first keeps running.
- A TrueNAS certificate the driver cannot verify now stops the pod with an error
naming the fix, instead of leaving it un-Ready with no visible error. trustedCAanduseClusterProxyare off unless set, so a cluster-wide proxy
does not start carrying TrueNAS traffic on upgrade.- iSCSI nodes no longer use SendTargets discovery; they log in directly.
- A failed snapshot delete is now returned to the snapshotter and retried,
instead of being reported as done.
Leftovers from earlier versions:
csi-clone-*snapshots, one per cloned PVC, are deleted by the controller
when it starts. Orphanedsnapshot-*snapshots need a manual check; see
docs/snapshots.md.- iSCSI targets created for cloned volumes, or while retrying a volume create,
have no CHAP or initiator group even if the StorageClass asked for one.
Existing targets are not changed; check them in TrueNAS. - Auth entries and initiator groups of volumes deleted before the upgrade were
never removed. Mutual CHAP entries were also created with discovery
authentication, which blocks unauthenticated discovery for every initiator on
the appliance. Delete unused entries in TrueNAS (it refuses to delete one a
target still uses), or set their discovery authentication to None.
Images
quay.io/truenas_solutions/truenas-csi:v1.4.0quay.io/truenas_solutions/truenas-csi-operator:v1.4.0quay.io/truenas_solutions/truenas-csi-operator-bundle:v1.4.0ghcr.io/truenas/truenas-csi:v1.4.0- Helm chart 1.4.0
This release is not yet Red Hat certified. v1.1.2 remains the certified release
in the OpenShift catalog.