Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -39,7 +39,7 @@ spec:
namespace: network
cephImage:
repository: quay.io/ceph/ceph

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛑 Blocker: Ceph image bumped across a major version boundary (v20 → v21); Rook operator compatibility with Ceph v21.x has not been verified and the operator version was not updated in this PR.

Automated finding from AI PR review.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still open after this push; carried forward. (as of f0052cb)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Major: Major Ceph releases may require CSI driver updates; ensure the rook-csi components are compatible with Ceph v21 before deploying.

Automated finding from AI PR review.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still open after this push; carried forward. (as of f0052cb)

tag: v20.2.4@sha256:6bb1c8a42fbc0bf87938946990b65174466997bc11c31eb5a323225a779fd8f9
tag: v21.1.0@sha256:5ff3692d2f3f4bf47ca7717de6f8f8556440ce3e15efaa680b62cb924eec0541

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛑 Blocker (security): Major version upgrade (v20 -> v21) requires verification against the Talos Linux host platform compatibility matrix before merge.

Automated finding from AI PR review.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛑 Blocker: Ceph v21.1.0 (Reef) is a major version upgrade; compatibility with the currently deployed Rook operator version has not been verified against the official support matrix.

Automated finding from AI PR review.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still open after this push; carried forward. (as of 0b80f9d)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Major (question): Rook operator (v1.20.3 per git history) compatibility with Ceph v21 (Squid) has not been verified against Rook's published support matrix; this is a major version bump of the core storage backend and must be confirmed before merge.

Automated finding from AI PR review.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still open after this push; carried forward. (as of 582eaf8)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Info (docs): Ceph v21 (Squid) upstream release notes were not fetched; the PR body links to a non-allowlisted host and contains no release notes. Review upstream breaking changes before merging.

Automated finding from AI PR review.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still open after this push; carried forward. (as of 582eaf8)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛑 Blocker: Ceph major bump v20→v21 not verified against the pinned Rook operator (v1.20.3) supported-Ceph matrix; Rook 1.20.x may not support Ceph v21 — verify before merging.

Automated finding from AI PR review.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still open after this push; carried forward. (as of 8727c18)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛑 Blocker (bug): Ceph v21.1.0 is unsupported by the pinned Rook v1.20.3 chart, which only supports Squid and Tentacle and requires cephImage.allowUnsupported: true for newer versions; bump the Rook chart to a v21-supporting release first.

Automated finding from AI PR review.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still open after this push; carried forward. (as of ac036d9)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Major: Major Ceph bump (v20.2.3 → v21.1.0) has no verified compatibility matrix or release-notes evidence; confirm Rook chart support and data-format forward-compatibility before merging.

Automated finding from AI PR review.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still open after this push; carried forward. (as of 67a287f)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Info (docs): Ceph v21.1.0 release notes could not be fetched (docs.ceph.com not allowlisted); breaking/security changes remain unverified.

Automated finding from AI PR review.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still open after this push; carried forward. (as of 67a287f)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛑 Blocker: Ceph Quincy (v20.2.4) to Reef (v21.1.0) is a major-version jump; verify the deployed Rook operator supports Ceph Reef v21 before bumping the daemon image, since Rook only accepts a bounded set of Ceph majors.

Automated finding from AI PR review.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still open after this push; carried forward. (as of 21699dc)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Major: No backup/upgrade runbook or operator-first ordering accompanies this major Ceph upgrade; per upstream guidance the Rook operator must be upgraded to a Reef-supporting release before changing cephImage.

Automated finding from AI PR review.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still open after this push; carried forward. (as of 21699dc)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛑 Blocker: Ceph v21.1.0 (Umbrella) not listed as supported in Rook support matrix; matrix lists only Squid v19.2.0+ and Tentacle v20.2.1+ and Rook v1.21 Umbrella support is unreleased (404).

Automated finding from AI PR review.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still open after this push; carried forward. (as of f0d267e)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Major: Major Ceph 20→21 bump without a corresponding Rook operator/CSI chart version check; the rook-ceph-cluster OCIRepository pin is unchanged and may not support Ceph 21.

Automated finding from AI PR review.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Info (docs): Ceph v21.1.0 release notes and breaking changes could not be verified because docs.ceph.com and ceph.io are not on the allowed fetch list.

Automated finding from AI PR review.

cephClusterSpec:
# Ceph 20 rates cipher `aes` HEALTH_ERR, which blocks Rook's OSD upgrades. aes256k needs the
# in-kernel client from Linux 7.0. keyType does nothing unless keyRotationPolicy is set.
Expand Down