New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
csi: default to ReadWriteOnceWithFSType for cephfs #9729
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Need change at below places
https://github.com/rook/rook/blob/master/deploy/examples/operator.yaml#L71
https://github.com/rook/rook/blob/master/deploy/examples/operator-openshift.yaml#L153
Do we need documentation to change this value in upgraded clusters?
``` ReadWriteOnceWithFSType: Indicates that volumes will be examined to determine if volume ownership and permissions should be modified to match the pod's security policy. Changes will only occur if the fsType is defined and the persistent volume's accessModes contains ReadWriteOnce. ``` In between considering we are giving 0777 permission on nodestage of cephfs shares, we defaulted to NONE. However giving worldwide permission to the volume is not the right thing and it has been fixed in cephfs via ceph/ceph-csi#2847 This commit brings it back to the value which is also in parity with RBD driver. Signed-off-by: Humble Chirammal <hchiramm@redhat.com>
9ab79fc
to
6561bda
Compare
Considering the changes are opt in and out as always, we dont need to ask the users I believe. |
|
@Madhu-1 can you revisit the PR? |
|
Yeah, afaict, it should be fine to pick the change even in absence of CSI fix @travisn |
csi: default to ReadWriteOnceWithFSType for cephfs (backport #9729)
In between considering we are giving 0777 permission on nodestage
of cephfs shares, we defaulted to NONE. However giving worldwide
permission to the volume is not the right thing and it has been
fixed in cephfs via ceph/ceph-csi#2847
This commit brings it back to the value which is also in parity
with RBD driver.
Signed-off-by: Humble Chirammal hchiramm@redhat.com
Description of your changes:
Which issue is resolved by this Pull Request:
Resolves #
Checklist:
make codegen) has been run to update object specifications, if necessary.