Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 1844360

Summary: Incorrect capabilities are recommended in "INTEGRATING AN OVERCLOUD WITH AN EXISTING RED HAT CEPH CLUSTER" guide for openstack.client
Product: Red Hat OpenStack Reporter: Alex Stupnikov <astupnik>
Component: documentationAssignee: RHOS Documentation Team <rhos-docs>
Status: CLOSED NOTABUG QA Contact: RHOS Documentation Team <rhos-docs>
Severity: medium Docs Contact:
Priority: unspecified    
Version: 16.1 (Train)CC: amoralej, fsoppels, lmarsh
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: All   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2020-07-17 18:16:05 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Alex Stupnikov 2020-06-05 08:15:37 UTC
Description of problem:

This issue was originally reported and discussed in bug #1838145 . The problem is that recommended mon_cap ('allow r') are too restrictive and could cause various issues; one of those issues was reported in bug #1838145 : it is impossible to delete cinder volume that once belonged to an instance hosted on compute node that was brutally shutdown.

This issue is known and its workaround is documented in the following KCS: https://access.redhat.com/solutions/3391211 . Basically, mon_cap should be defined in the following way:

ceph auth caps client.openstack mon 'allow r, allow command "osd blacklist"' osd 'allow class-read object_prefix rbd_children, allow rwx pool=volumes, allow rwx pool=vms, allow rwx pool=images, allow rwx pool=backups, allow rwx pool=metrics'

It would also be great to add a URL to KCS for customer with existing Ceph clusters to documentation.

Documentation for all supported RHOSP releases is affected and should be fixed.

Comment 1 Fabrizio Soppelsa 2020-06-08 08:53:37 UTC
Include this change into RHOSP 13 docs too.

Comment 2 Alex Stupnikov 2020-06-11 07:36:29 UTC
In bug #1838145 Jason Dillaman confirmed that "osd blacklist" is granted as a part of "profile rbd", so it could be a Ceph bug. Will keep you posted.

Comment 3 Alex Stupnikov 2020-06-12 07:02:39 UTC
Please check correct capabilities in comment https://bugzilla.redhat.com/show_bug.cgi?id=1838145#c30

Comment 4 Alex Stupnikov 2020-06-29 08:54:50 UTC
This issue was fixed in bug #1838145 (please check latest comments). IMO this bug can be closed.