Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
5c0bf7c293 | ||
|
|
2e03568225 | ||
|
|
7dabef4851 | ||
|
|
29c3841eaa | ||
|
|
45204da444 | ||
|
|
c18ddbf255 | ||
|
|
76410df0e8 | ||
|
|
6a0f3a38d0 | ||
|
|
265e99ccd0 | ||
|
|
aa71a1968f | ||
|
|
5382f1c7bb | ||
|
|
a5dbf74123 | ||
|
|
784fd7d233 | ||
|
|
13b7c0e73d | ||
|
|
d747ec8c41 | ||
|
|
cabe5d1543 | ||
|
|
38da624930 | ||
|
|
e0ff8a014f | ||
|
|
8721f21874 | ||
|
|
9eb858fb5f | ||
|
|
9f084f48f6 | ||
|
|
c998325448 | ||
|
|
a243ff6459 | ||
|
|
47b3294666 | ||
|
|
3afed2473e | ||
|
|
fdeacdcf30 | ||
|
|
d7ddd7752c | ||
|
|
2b2c7d5e39 | ||
|
|
e26478c2e7 | ||
|
|
c7b9d30fd3 | ||
|
|
5803655840 | ||
|
|
61ce26ba29 | ||
|
|
32e651ec96 | ||
|
|
dbed0e94cb | ||
|
|
8b39a268b9 | ||
|
|
d40ba7c5ce | ||
|
|
985257f2d7 | ||
|
|
a4f3383f21 | ||
|
|
b2d828ec84 | ||
|
|
b2a74de715 | ||
|
|
430761ad2e | ||
|
|
38a1f6937d | ||
|
|
8b46914999 | ||
|
|
1b81e60187 | ||
|
|
526c597cd0 | ||
|
|
7a97783ead | ||
|
|
b4425d8e65 | ||
|
|
1afda35bd3 | ||
|
|
0953f5ebdd | ||
|
|
1b03615e50 | ||
|
|
8f208c53df | ||
|
|
c0d2dabe66 | ||
|
|
6da4aaf176 | ||
|
|
5b6a6fce9a | ||
|
|
79fb2def57 | ||
|
|
7f5c24144b | ||
|
|
3cf876fafa | ||
|
|
771aa83282 | ||
|
|
03404ac95d | ||
|
|
decf314238 | ||
|
|
ab1849ff07 | ||
|
|
33b18c7229 | ||
|
|
4a2efb29ec | ||
|
|
00a432193a | ||
|
|
d83eb599a0 | ||
|
|
c1c9b1975d | ||
|
|
ba0d9ad9f2 | ||
|
|
4feabc4ab6 | ||
|
|
1a14301c50 | ||
|
|
5dc52a7c06 | ||
|
|
4d45b27696 | ||
|
|
5995c4a00f | ||
|
|
906388adaa | ||
|
|
5dbc679e16 | ||
|
|
d48864a6be | ||
|
|
462482d319 | ||
|
|
5ef9d78461 | ||
|
|
1b20010a69 | ||
|
|
d750d00c6f | ||
|
|
66cb564e2c | ||
|
|
f782decbd6 | ||
|
|
717582c4ba | ||
|
|
cd62c0755f | ||
|
|
c6f5ab7d79 | ||
|
|
09607ddcbe | ||
|
|
278852b4d5 | ||
|
|
7b11c6e90d | ||
|
|
6251ce8b9a | ||
|
|
d4a42f61cf | ||
|
|
6b003bcc34 | ||
|
|
1c945bcb41 | ||
|
|
716527b184 | ||
|
|
8c0486bd76 | ||
|
|
d2cf271f64 | ||
|
|
d93b488e32 | ||
|
|
fbffec5abb | ||
|
|
b6eb8f2055 | ||
|
|
e373ea2163 | ||
|
|
5e12b4a1a5 | ||
|
|
78b067566f | ||
|
|
cf3abdb9e3 | ||
|
|
826b35b369 | ||
|
|
cdc730314b | ||
|
|
5248d7f324 | ||
|
|
4161f0bd01 | ||
|
|
5627977a9b | ||
|
|
ec9cfa76c1 | ||
|
|
0c88884576 | ||
|
|
ba7637d9ad | ||
|
|
ac1025c7a5 | ||
|
|
2a81cef78a | ||
|
|
bcf6a7c7d1 | ||
|
|
85c4be3957 | ||
|
|
cf2ba05e4b | ||
|
|
04c2f8d408 | ||
|
|
0e528ca8f3 | ||
|
|
c6f733b96a | ||
|
|
938ac09248 | ||
|
|
3becdbf5b9 | ||
|
|
9c49315fdf | ||
|
|
430d3cfb6f | ||
|
|
c491db699c | ||
|
|
e9d053e30f | ||
|
|
1be51f903c | ||
|
|
cd51f14a90 | ||
|
|
9b8107875f | ||
|
|
ca606570f7 | ||
|
|
22d094ccc6 | ||
|
|
fd84d84279 | ||
|
|
af2b1e28e3 | ||
|
|
9dda449f48 | ||
|
|
e6d4b32629 | ||
|
|
4de22a08e2 | ||
|
|
a403de46b3 | ||
|
|
ac20f605f6 | ||
|
|
51ecbadb12 | ||
|
|
6a4627b625 | ||
|
|
fd2b8b8792 | ||
|
|
f3d662bac7 | ||
|
|
553cc8ef87 | ||
|
|
67fdf1142b | ||
|
|
02f6e564a6 | ||
|
|
33d14061d6 | ||
|
|
677e755e4e | ||
|
|
11a972cbfb | ||
|
|
1834743a0e | ||
|
|
213f76c66c | ||
|
|
91698404a7 | ||
|
|
27bd38d95e | ||
|
|
ef0e61be1b | ||
|
|
26fb08d7da | ||
|
|
80fa3094b3 | ||
|
|
df931b1e17 | ||
|
|
906294ae9a | ||
|
|
15f69719e4 | ||
|
|
43aa4cfff6 | ||
|
|
6901227390 | ||
|
|
7f718feaf6 | ||
|
|
236ffbb24e | ||
|
|
0e300f4c50 | ||
|
|
6d82a3daa3 | ||
|
|
c0c01a8e57 | ||
|
|
334755e912 | ||
|
|
c16f955a51 | ||
|
|
c1dc14f5ee | ||
|
|
ec6a70bbd3 | ||
|
|
f236ed895a | ||
|
|
7d70c90196 | ||
|
|
0a04490043 | ||
|
|
dce7ffde6f | ||
|
|
f6bd1ff0e5 | ||
|
|
ac00a06757 | ||
|
|
155cfb3c73 | ||
|
|
126891126a | ||
|
|
547a394be6 | ||
|
|
1a511acead | ||
|
|
5576a0d9ff | ||
|
|
879e9a32d1 | ||
|
|
747fd5c121 | ||
|
|
b4aab7a78e | ||
|
|
de26a995fc | ||
|
|
8418a9ad7b | ||
|
|
27be4ee2fa | ||
|
|
00517e2bac | ||
|
|
e0a2615cbc | ||
|
|
63fe3c323a | ||
|
|
a88465df05 | ||
|
|
ad24be717a | ||
|
|
648e3b12f0 | ||
|
|
a675993c74 | ||
|
|
c9dfd0f67d | ||
|
|
84919a10a9 | ||
|
|
51ae4d6e24 | ||
|
|
572b20fedc | ||
|
|
4e2724b28f | ||
|
|
768b1675f8 | ||
|
|
38fa722725 | ||
|
|
e56d83fb7f | ||
|
|
ff95a85875 | ||
|
|
98203568a8 | ||
|
|
89df98ee08 | ||
|
|
0007a831b6 | ||
|
|
40517c335f | ||
|
|
c9f7308b6a | ||
|
|
85c7e3bde0 | ||
|
|
4fb55b3535 | ||
|
|
912aca11a3 | ||
|
|
7b454bd16c | ||
|
|
a0c8be46a4 | ||
|
|
53b4329fac | ||
|
|
a7f41c4a12 | ||
|
|
5d78057ac3 | ||
|
|
8efc5a353f | ||
|
|
603b26b896 | ||
|
|
a3b0fe0deb | ||
|
|
f504e356d5 | ||
|
|
4ed17b7070 | ||
|
|
1fd2819724 | ||
|
|
dcdabbc1ec | ||
|
|
625d5b7b9e | ||
|
|
9e507fd333 | ||
|
|
c2b5118127 | ||
|
|
4b926e2223 | ||
|
|
a5d9a6996a | ||
|
|
0ee03e7172 | ||
|
|
88b7d9afcd | ||
|
|
f271c8450c | ||
|
|
f78d7d4efc | ||
|
|
fdaf7c88ff | ||
|
|
2fb6eb0c30 | ||
|
|
36d2b56208 | ||
|
|
14b22f2ba9 | ||
|
|
fe8b1fe0cc | ||
|
|
1ec963e468 | ||
|
|
5100f822d8 | ||
|
|
7432494e88 | ||
|
|
d0c0f3ea39 | ||
|
|
f61190f31d | ||
|
|
3dc0ab5c33 | ||
|
|
de96efed2f | ||
|
|
87a5230798 | ||
|
|
0c5e6d4346 | ||
|
|
b278087410 | ||
|
|
a8e821b13b | ||
|
|
caa70317fa | ||
|
|
b8eaaabfe4 | ||
|
|
e4d80c415e | ||
|
|
553191c3ff | ||
|
|
ab385252b5 | ||
|
|
041185c673 | ||
|
|
b03ac80a57 | ||
|
|
2ba56074f9 | ||
|
|
4acfe149cb | ||
|
|
008ed5b269 | ||
|
|
4fffe0f032 | ||
|
|
a76d5ccc0d | ||
|
|
8ed1e180e0 | ||
|
|
8832fc3b14 | ||
|
|
0134934c99 | ||
|
|
2e36f292bd | ||
|
|
bcc6419760 | ||
|
|
dd5941b9a4 | ||
|
|
4005b88865 | ||
|
|
280b5cd675 | ||
|
|
e5c505eaf4 | ||
|
|
c1d244d4f0 | ||
|
|
9b264a212f | ||
|
|
ff7f5cb4f4 | ||
|
|
25ecca7625 | ||
|
|
99c4244004 | ||
|
|
9949b9fb4e | ||
|
|
e6881ad1d5 | ||
|
|
b30635b932 | ||
|
|
0c1154833c | ||
|
|
c227bb05b6 | ||
|
|
dd85315f22 | ||
|
|
47d2f4e0be | ||
|
|
2a5028d17f | ||
|
|
07915c2881 | ||
|
|
79141eb383 | ||
|
|
f7cbb6ed56 | ||
|
|
8f8172db99 | ||
|
|
94be147e80 | ||
|
|
538620b400 | ||
|
|
4c34a47179 | ||
|
|
df16ab627a | ||
|
|
44c895dc30 | ||
|
|
fdea595913 | ||
|
|
ef4c91ecc8 | ||
|
|
5192c6cf50 | ||
|
|
cb639a130d | ||
|
|
892e3a8b6d | ||
|
|
0bd9c26620 | ||
|
|
ae2b1f7802 | ||
|
|
883b2e45da | ||
|
|
09df74cfac | ||
|
|
2ef3f012c9 | ||
|
|
7175d99c64 | ||
|
|
230a26772e | ||
|
|
637684c579 | ||
|
|
c541dd422f | ||
|
|
22c39561cf | ||
|
|
d4c67b4879 | ||
|
|
d1b7167861 | ||
|
|
33b561b73a | ||
|
|
a95a60c600 | ||
|
|
b3bc815354 | ||
|
|
42fc45d6da | ||
|
|
3fbe2e7f8a | ||
|
|
310c512b43 | ||
|
|
fd3e3b4ef0 | ||
|
|
93cf69f89f | ||
|
|
a8dd8bf06c | ||
|
|
7e23b57014 | ||
|
|
b2427836a1 | ||
|
|
2ed6760447 | ||
|
|
a1d215ea2f | ||
|
|
4fa442a5de | ||
|
|
3a057ed5af | ||
|
|
0ad042b28b | ||
|
|
4d75c6c8f9 | ||
|
|
9ec18f0aa1 | ||
|
|
facaa2cc6a | ||
|
|
d2ac8e3827 | ||
|
|
d6dacc67db | ||
|
|
cbe51595cb | ||
|
|
6bd0830ab8 | ||
|
|
796e82f34d | ||
|
|
db39283970 | ||
|
|
9f8c686321 | ||
|
|
2618e559d1 | ||
|
|
037d2bc162 | ||
|
|
f0b64adb32 | ||
|
|
f06d64d879 | ||
|
|
d164499a1c | ||
|
|
725e9aa8ae | ||
|
|
0715feffa1 | ||
|
|
e9f37e8dc3 | ||
|
|
4fbe4b5654 | ||
|
|
9fb645693b | ||
|
|
9e47828383 | ||
|
|
ac2ce48cb2 | ||
|
|
9cc2beed95 | ||
|
|
fb1c870f5c | ||
|
|
2d616d8058 | ||
|
|
3f7f6f442b | ||
|
|
7e7b95eeb4 | ||
|
|
dd588a0783 | ||
|
|
028a6cab68 | ||
|
|
d75334ddf0 | ||
|
|
bf0875128e | ||
|
|
9a6a7b7f75 | ||
|
|
c4c17ee6fb | ||
|
|
2b801a7ffa | ||
|
|
233d2b2a09 | ||
|
|
8380d4c6a6 | ||
|
|
73f9c7293f | ||
|
|
1c66c3e5ba | ||
|
|
eddfa93c18 | ||
|
|
ddd755a0e6 | ||
|
|
819f5b7ec9 | ||
|
|
34d0a6d9b1 | ||
|
|
fe83825ead | ||
|
|
8ec7faa675 | ||
|
|
21cf5c8815 | ||
|
|
44eeb1ed13 | ||
|
|
cc6c445cf0 | ||
|
|
bd6af0db09 | ||
|
|
8860101e99 | ||
|
|
c92661b364 | ||
|
|
9a02a592e3 | ||
|
|
8b7fa3d3bc | ||
|
|
db5eaa2eee | ||
|
|
d35727dbb7 | ||
|
|
b78f526696 | ||
|
|
a23df12260 | ||
|
|
166e16102e | ||
|
|
06c602110c | ||
|
|
1de68c30af | ||
|
|
2a0aca6e94 | ||
|
|
e808332e12 | ||
|
|
fc5a183959 | ||
|
|
55de37e58a | ||
|
|
aacfdf0dec | ||
|
|
a67c415e0f | ||
|
|
495f3fb4cd | ||
|
|
934752d617 | ||
|
|
1e6e233426 | ||
|
|
a5768a8ef6 | ||
|
|
216707f101 | ||
|
|
8ffdb93ed3 | ||
|
|
2fb7022c78 | ||
|
|
2633978fec | ||
|
|
615d4825c0 | ||
|
|
e55ca26ff6 | ||
|
|
abe093b9a3 | ||
|
|
07e6eb0b16 | ||
|
|
0eacce1e1d | ||
|
|
3df410acc7 | ||
|
|
e55927076c | ||
|
|
60fcb168fe | ||
|
|
b17691ba02 | ||
|
|
f2cbe793e2 | ||
|
|
0053546f8b | ||
|
|
959f792f82 | ||
|
|
eaff4509ca | ||
|
|
04eefce30b | ||
|
|
746844d301 | ||
|
|
c8f5b6cb19 | ||
|
|
0f4837e9bb | ||
|
|
25ce82a729 | ||
|
|
944499135f | ||
|
|
08f21edaf7 | ||
|
|
e9f0639e62 | ||
|
|
4e0b203552 | ||
|
|
b772a3cd04 | ||
|
|
856ad79a02 | ||
|
|
39a8772d7f | ||
|
|
993f40de37 | ||
|
|
5607222921 | ||
|
|
378fff6f67 | ||
|
|
daf2cc3fb1 | ||
|
|
17d61c5868 | ||
|
|
e709657de4 | ||
|
|
3eecf9048c | ||
|
|
1852caaeec | ||
|
|
7b40561141 | ||
|
|
d80c12ced2 | ||
|
|
b9713deecd | ||
|
|
852734270e | ||
|
|
8f92979a18 | ||
|
|
b720af74c2 | ||
|
|
96df2966cc | ||
|
|
d3b171e047 | ||
|
|
7287b7fc25 | ||
|
|
e1bb670491 | ||
|
|
1e5a01def8 | ||
|
|
371e630f52 | ||
|
|
0a7ae616f3 | ||
|
|
82f5fb7edd | ||
|
|
ec8527c89d | ||
|
|
5afef7ca6d | ||
|
|
e512e1eeb1 | ||
|
|
7ab60c00ab | ||
|
|
ac8e0ef231 | ||
|
|
94f3634602 | ||
|
|
2b8a9e3f90 | ||
|
|
ef792608b0 | ||
|
|
04531bcfbb | ||
|
|
1b40fa1cee | ||
|
|
3ea9230ed0 | ||
|
|
97dfbfad75 | ||
|
|
c148f97ee4 | ||
|
|
b1f61eb5c8 | ||
|
|
9db8748647 | ||
|
|
e747319c1e | ||
|
|
0cb0e31ceb | ||
|
|
0703efd8b9 | ||
|
|
4a0720a231 | ||
|
|
57d83ecf7c | ||
|
|
d4f7bbb412 | ||
|
|
e5e71fc21a | ||
|
|
0ec4f1608a | ||
|
|
232e416658 | ||
|
|
23d5fec580 | ||
|
|
16881a3d6b | ||
|
|
7cde5c75b9 | ||
|
|
4c32244409 | ||
|
|
30c5a79772 | ||
|
|
6e856c2719 | ||
|
|
af710d3c65 | ||
|
|
8189c3a4ef | ||
|
|
552ba5d885 | ||
|
|
14bbf18ede | ||
|
|
c3eaaa4b94 | ||
|
|
8b35c09e12 | ||
|
|
74b8ea1303 | ||
|
|
6a30e6653a | ||
|
|
2d7da127ad | ||
|
|
4143d56db7 | ||
|
|
5067554e46 | ||
|
|
bc48eb1ff8 | ||
|
|
b0809b33aa | ||
|
|
d61cf2303f | ||
|
|
712f22d6f8 | ||
|
|
4340082315 | ||
|
|
a1a449686a | ||
|
|
fb87870734 | ||
|
|
99bddb976a | ||
|
|
4f997791b8 | ||
|
|
c980168d10 | ||
|
|
dce4a6c37a | ||
|
|
38d5175f66 | ||
|
|
7569fb959b | ||
|
|
aa1e62a502 | ||
|
|
dcbdb0ae33 | ||
|
|
6e5f990801 | ||
|
|
845e76a0ec | ||
|
|
a98aee7906 | ||
|
|
064a94166c | ||
|
|
38112e9012 | ||
|
|
353460cc83 | ||
|
|
92631bb6b3 | ||
|
|
ce050e7eda | ||
|
|
556fc9a876 | ||
|
|
274f9ecda5 | ||
|
|
e0d2705294 | ||
|
|
57d2f30303 | ||
|
|
7f4c541a6f | ||
|
|
b0b495a991 | ||
|
|
da8bf2b73b | ||
|
|
615e9d1274 | ||
|
|
ec5e93307d | ||
|
|
b599334c4a | ||
|
|
bcde273ca1 | ||
|
|
87fe1bc00f | ||
|
|
d4c465f786 | ||
|
|
62995243f3 | ||
|
|
7ea4884ef6 | ||
|
|
8823ddf48e | ||
|
|
db14037ac8 | ||
|
|
64db505357 | ||
|
|
8992eb57df | ||
|
|
f3048d0858 | ||
|
|
714b0783bf | ||
|
|
e8e2aa5dba | ||
|
|
9063bcaa41 | ||
|
|
c392e914e2 | ||
|
|
249e04ac0d | ||
|
|
16dee7c136 | ||
|
|
adddf9b3b1 | ||
|
|
6a5044ae36 | ||
|
|
49407afa17 | ||
|
|
a00fc1bc24 | ||
|
|
3a96d41c93 | ||
|
|
2e4d5ae5bb | ||
|
|
db458fc999 | ||
|
|
574520be0f | ||
|
|
715e7df51f | ||
|
|
ea5ee0c46f | ||
|
|
47bec8af47 | ||
|
|
ec3bf4ae6c | ||
|
|
cb45b1865d | ||
|
|
f656545f4a | ||
|
|
0241a61412 | ||
|
|
0bc81f5320 | ||
|
|
84961f6d0a | ||
|
|
cb085f9c8f | ||
|
|
a9773b1908 | ||
|
|
11783a2d7a | ||
|
|
7915605609 | ||
|
|
3ba3eed0cf | ||
|
|
5dc0b42146 | ||
|
|
b44c3a7971 | ||
|
|
59b7b2e0c3 | ||
|
|
7f0c78113b | ||
|
|
20bbeb4095 | ||
|
|
3c687a2993 | ||
|
|
7530bdbec7 | ||
|
|
c78b4d184d | ||
|
|
c7a6b77c21 | ||
|
|
3cb7ec69bc | ||
|
|
954e7b658d | ||
|
|
2c6ea8a521 | ||
|
|
bfd5575425 | ||
|
|
85e61c9c31 | ||
|
|
f580cee936 | ||
|
|
6d0460500a | ||
|
|
01ae800d34 | ||
|
|
dbb885a6b1 | ||
|
|
8ff2c268f7 | ||
|
|
8430104c19 | ||
|
|
4c11e3ad3d | ||
|
|
d88b49872b | ||
|
|
ca27b91919 | ||
|
|
94f31b96b8 | ||
|
|
76c7c26d32 | ||
|
|
8aa2c49202 | ||
|
|
0f330b10f1 | ||
|
|
477b54a0d8 | ||
|
|
5823a7de66 | ||
|
|
eb0deaa3f5 | ||
|
|
59e6527303 | ||
|
|
67ba9f9b7c | ||
|
|
3ad83e8d13 | ||
|
|
5d3f3f47a7 | ||
|
|
8ee7058ec8 | ||
|
|
1badc6ad13 | ||
|
|
be1858848e | ||
|
|
d75b1cb2d2 | ||
|
|
a1c17d90a3 | ||
|
|
f0112050ce | ||
|
|
d6b8d921d6 | ||
|
|
65872f5d0e | ||
|
|
15eef27d44 | ||
|
|
aa1e51de5f | ||
|
|
c164adb43c | ||
|
|
622631c146 | ||
|
|
4ab93d8481 | ||
|
|
bd64770317 | ||
|
|
34cb48d553 | ||
|
|
724d2ffa04 | ||
|
|
b6bfe1435d | ||
|
|
74a23dcb63 | ||
|
|
93fd23b2bb | ||
|
|
eedc700b83 | ||
|
|
c8cc17dbe9 | ||
|
|
b55d406386 | ||
|
|
0c46dbd333 | ||
|
|
ed94aa52cf | ||
|
|
555ae613c2 | ||
|
|
cad6ea0360 | ||
|
|
d60709dce1 | ||
|
|
a03ffd0d73 | ||
|
|
89b76a87b6 | ||
|
|
ceba343ac0 | ||
|
|
3bc04d8250 | ||
|
|
d228fbfb68 | ||
|
|
e3c8fd28b4 | ||
|
|
d87e7d1a37 | ||
|
|
59f87c3e30 | ||
|
|
eba383f66f | ||
|
|
4e5e8822c0 | ||
|
|
60933c1d00 | ||
|
|
1ad6933953 | ||
|
|
8a250f4fca | ||
|
|
94ddf20667 | ||
|
|
5f18496c04 | ||
|
|
08a3dcd587 | ||
|
|
3c5b9d2744 | ||
|
|
cff08d2c72 | ||
|
|
1e1f395947 | ||
|
|
e6c2628960 | ||
|
|
887f7c1530 | ||
|
|
2c6bddd831 | ||
|
|
e1715c33bb | ||
|
|
2ef80bf0b8 | ||
|
|
85ba710718 | ||
|
|
c16b0e7f92 | ||
|
|
b3d388228a | ||
|
|
bcde9de7da | ||
|
|
52bc3261e9 | ||
|
|
2d42f29385 | ||
|
|
17240c6144 | ||
|
|
9e627a4414 | ||
|
|
90b1019636 | ||
|
|
df604afbd5 | ||
|
|
47c7aa62de | ||
|
|
9f2dc48d0f | ||
|
|
6d951b21fb | ||
|
|
552f28cb3e | ||
|
|
e87b6e26f7 | ||
|
|
0c89886374 | ||
|
|
e79bef8751 | ||
|
|
ad76f84e1c | ||
|
|
db827cb34c | ||
|
|
e5c6d85ea1 | ||
|
|
6cc44c1f54 | ||
|
|
c20450c1f1 | ||
|
|
db63e58b3d | ||
|
|
31b7021330 | ||
|
|
2ebe3a468c | ||
|
|
9892fccfb0 | ||
|
|
0be86a306d | ||
|
|
d77a775948 | ||
|
|
8cc82bab39 | ||
|
|
f9d5e33ddd | ||
|
|
f83418d93e | ||
|
|
fbf14fb0cb | ||
|
|
fb1c3e00f4 | ||
|
|
d8332171e9 | ||
|
|
c24cc9bf0b | ||
|
|
9f57c75acf | ||
|
|
53b12641d1 | ||
|
|
5c5c8825dc | ||
|
|
3a261ac3fc | ||
|
|
04514435de | ||
|
|
07303020fc | ||
|
|
feaf7a15cf | ||
|
|
29dda5066f | ||
|
|
1de53ef7e6 | ||
|
|
4793dbe9c3 | ||
|
|
918ea34af2 | ||
|
|
2db8184cd8 | ||
|
|
0e964b3c8c | ||
|
|
1b9296ff6c | ||
|
|
6bf136c199 | ||
|
|
b529f77264 | ||
|
|
bf9519dcdc | ||
|
|
4ba687738b | ||
|
|
8427f6fe46 | ||
|
|
efa6bc3e70 | ||
|
|
da33e9b12d | ||
|
|
265127c1a7 | ||
|
|
2b30acfc1d | ||
|
|
7fbc38ef29 | ||
|
|
e5070e991a | ||
|
|
625552c441 | ||
|
|
78c95c94f6 | ||
|
|
488e20bf55 | ||
|
|
25d6281b3e | ||
|
|
1676e50b3a | ||
|
|
8049e3c14a | ||
|
|
93a30efd86 | ||
|
|
83fb121f36 | ||
|
|
afc97b757b | ||
|
|
68905cbf41 | ||
|
|
3fff667f13 | ||
|
|
980aec1d9b | ||
|
|
f515fcce62 |
@@ -1,28 +1,29 @@
|
|||||||
FROM node:16-bullseye
|
FROM node:16-bookworm
|
||||||
|
|
||||||
WORKDIR /root
|
WORKDIR /root
|
||||||
|
|
||||||
ADD ./docker/vitastor.gpg /etc/apt/trusted.gpg.d
|
ADD ./docker/etc/apt/trusted.gpg.d /etc/apt/trusted.gpg.d
|
||||||
|
|
||||||
RUN echo 'deb http://deb.debian.org/debian bullseye-backports main' >> /etc/apt/sources.list; \
|
RUN echo 'deb http://deb.debian.org/debian bookworm-backports main' >> /etc/apt/sources.list; \
|
||||||
echo 'deb http://vitastor.io/debian bullseye main' >> /etc/apt/sources.list; \
|
echo 'deb http://vitastor.io/debian bookworm main' >> /etc/apt/sources.list; \
|
||||||
echo >> /etc/apt/preferences; \
|
echo >> /etc/apt/preferences; \
|
||||||
echo 'Package: *' >> /etc/apt/preferences; \
|
echo 'Package: *' >> /etc/apt/preferences; \
|
||||||
echo 'Pin: release a=bullseye-backports' >> /etc/apt/preferences; \
|
echo 'Pin: release n=bookworm-backports' >> /etc/apt/preferences; \
|
||||||
echo 'Pin-Priority: 500' >> /etc/apt/preferences; \
|
echo 'Pin-Priority: 500' >> /etc/apt/preferences; \
|
||||||
echo >> /etc/apt/preferences; \
|
echo >> /etc/apt/preferences; \
|
||||||
echo 'Package: *' >> /etc/apt/preferences; \
|
echo 'Package: *' >> /etc/apt/preferences; \
|
||||||
echo 'Pin: origin "vitastor.io"' >> /etc/apt/preferences; \
|
echo 'Pin: origin "vitastor.io"' >> /etc/apt/preferences; \
|
||||||
echo 'Pin-Priority: 1000' >> /etc/apt/preferences; \
|
echo 'Pin-Priority: 1000' >> /etc/apt/preferences; \
|
||||||
|
perl -i -pe 's/Types: deb$/Types: deb deb-src/' /etc/apt/sources.list.d/debian.sources; \
|
||||||
grep '^deb ' /etc/apt/sources.list | perl -pe 's/^deb/deb-src/' >> /etc/apt/sources.list; \
|
grep '^deb ' /etc/apt/sources.list | perl -pe 's/^deb/deb-src/' >> /etc/apt/sources.list; \
|
||||||
echo 'APT::Install-Recommends false;' >> /etc/apt/apt.conf; \
|
echo 'APT::Install-Recommends false;' >> /etc/apt/apt.conf; \
|
||||||
echo 'APT::Install-Suggests false;' >> /etc/apt/apt.conf
|
echo 'APT::Install-Suggests false;' >> /etc/apt/apt.conf
|
||||||
|
|
||||||
RUN apt-get update
|
RUN apt-get update
|
||||||
RUN apt-get -y install etcd qemu-system-x86 qemu-block-extra qemu-utils fio libasan5 \
|
RUN apt-get -y install etcd qemu-system-x86 qemu-block-extra qemu-utils fio libasan8 \
|
||||||
liburing1 liburing-dev libgoogle-perftools-dev devscripts libjerasure-dev cmake libibverbs-dev libisal-dev
|
libgoogle-perftools-dev devscripts libjerasure-dev cmake libibverbs-dev libisal-dev
|
||||||
RUN apt-get -y build-dep fio qemu=`dpkg -s qemu-system-x86|grep ^Version:|awk '{print $2}'`
|
RUN apt-get -y build-dep fio qemu=`dpkg -s qemu-system-x86|grep ^Version:|awk '{print $2}'`
|
||||||
RUN apt-get update && apt-get -y install jq lp-solve sudo nfs-common fdisk parted
|
RUN apt-get update && apt-get -y install jq lp-solve sudo nfs-common fdisk parted libc-ares-dev udev
|
||||||
RUN apt-get --download-only source fio qemu=`dpkg -s qemu-system-x86|grep ^Version:|awk '{print $2}'`
|
RUN apt-get --download-only source fio qemu=`dpkg -s qemu-system-x86|grep ^Version:|awk '{print $2}'`
|
||||||
|
|
||||||
RUN set -ex; \
|
RUN set -ex; \
|
||||||
|
|||||||
+1157
-5
File diff suppressed because it is too large
Load Diff
@@ -38,6 +38,18 @@ for my $line (<>)
|
|||||||
{
|
{
|
||||||
$test_name .= '_antietcd';
|
$test_name .= '_antietcd';
|
||||||
}
|
}
|
||||||
|
elsif ($1 eq 'ETCD_SCHEME' && $2 eq 'https')
|
||||||
|
{
|
||||||
|
$test_name .= '_https';
|
||||||
|
}
|
||||||
|
elsif ($1 eq 'ENCRYPTED')
|
||||||
|
{
|
||||||
|
$test_name .= '_encrypted';
|
||||||
|
}
|
||||||
|
elsif ($1 eq 'OLD')
|
||||||
|
{
|
||||||
|
$test_name =~ s/^test_/test_old_/s;
|
||||||
|
}
|
||||||
else
|
else
|
||||||
{
|
{
|
||||||
$test_name .= '_'.lc($1).'_'.$2;
|
$test_name .= '_'.lc($1).'_'.$2;
|
||||||
|
|||||||
@@ -3,3 +3,4 @@
|
|||||||
package-lock.json
|
package-lock.json
|
||||||
fio
|
fio
|
||||||
qemu
|
qemu
|
||||||
|
node_modules
|
||||||
|
|||||||
+15
-2
@@ -1,7 +1,20 @@
|
|||||||
cmake_minimum_required(VERSION 2.8.12)
|
cmake_minimum_required(VERSION 2.8...3.30)
|
||||||
|
|
||||||
project(vitastor)
|
project(vitastor)
|
||||||
|
|
||||||
set(VITASTOR_VERSION "2.2.2")
|
set(VITASTOR_VERSION "3.0.15")
|
||||||
|
|
||||||
|
include(CTest)
|
||||||
|
|
||||||
|
add_custom_target(build_tests)
|
||||||
|
set_property(TEST PROPERTY ENVIRONMENT LSAN_OPTIONS=suppressions=${CMAKE_CURRENT_BINARY_DIR}/lsan-suppress.txt)
|
||||||
|
add_test(gen_lsan_suppress
|
||||||
|
${CMAKE_COMMAND} -E echo leak:tcmalloc > "${CMAKE_CURRENT_BINARY_DIR}/lsan-suppress.txt"
|
||||||
|
)
|
||||||
|
set_tests_properties(gen_lsan_suppress PROPERTIES FIXTURES_SETUP f_lsan_suppress)
|
||||||
|
set_property(TEST PROPERTY FIXTURES_REQUIRED f_lsan_suppress)
|
||||||
|
# make -j16 -C ../../build test_heap && ../../build/src/test/test_heap
|
||||||
|
# make -j16 -C ../../build test_heap && rm -f $(find ../../build -name '*.gcda') && ctest -V -T test -T coverage -R heap --test-dir ../../build && (cd ../../build; gcovr -f ../src --html --html-nested -o coverage/index.html; cd ../src/test)
|
||||||
|
# make -j16 -C ../../build test_blockstore && rm -f $(find ../../build -name '*.gcda') && ctest -V -T test -T coverage -R blockstore --test-dir ../../build && (cd ../../build; gcovr -f ../src --html --html-nested -o coverage/index.html; cd ../src/test)
|
||||||
|
# kcov --include-path=../../../src ../../kcov ./test_blockstore
|
||||||
add_subdirectory(src)
|
add_subdirectory(src)
|
||||||
|
|||||||
+11
-5
@@ -19,18 +19,22 @@ Vitastor нацелен в первую очередь на SSD и SSD+HDD кл
|
|||||||
TCP и RDMA и на хорошем железе может достигать задержки 4 КБ чтения и записи на уровне ~0.1 мс,
|
TCP и RDMA и на хорошем железе может достигать задержки 4 КБ чтения и записи на уровне ~0.1 мс,
|
||||||
что примерно в 10 раз быстрее, чем Ceph и другие популярные программные СХД.
|
что примерно в 10 раз быстрее, чем Ceph и другие популярные программные СХД.
|
||||||
|
|
||||||
Vitastor поддерживает QEMU-драйвер, протоколы NBD и NFS, драйверы OpenStack, OpenNebula, Proxmox, Kubernetes.
|
Vitastor поддерживает QEMU-драйвер, протоколы UBLK, NBD и NFS, драйверы OpenStack, OpenNebula, Proxmox, Kubernetes.
|
||||||
Другие драйверы могут также быть легко реализованы.
|
Другие драйверы могут также быть легко реализованы.
|
||||||
|
|
||||||
Подробности смотрите в документации по ссылкам. Можете начать отсюда: [Быстрый старт](docs/intro/quickstart.ru.md).
|
Подробности смотрите в документации по ссылкам. Можете начать отсюда: [Быстрый старт](docs/intro/quickstart.ru.md).
|
||||||
|
|
||||||
## Презентации и записи докладов
|
## Презентации и записи докладов
|
||||||
|
|
||||||
|
- KuberConf'2025: [видео](https://vitastor.io/presentation/kuberconf.webm)
|
||||||
|
- Highload'2025: [видео](https://vitastor.io/presentation/hl2025/hl2025.webm),
|
||||||
|
[на youtube](https://www.youtube.com/watch?v=0R8MLjFtz7g), презентация
|
||||||
|
([на русском](https://vitastor.io/presentation/hl2025/), [на английском](https://vitastor.io/presentation/hl2025/en.html))
|
||||||
|
- Highload'2022: презентация ([на русском](https://vitastor.io/presentation/highload/highload.html)),
|
||||||
|
[видео](https://vitastor.io/presentation/highload/talk.webm)
|
||||||
- DevOpsConf'2021: презентация ([на русском](https://vitastor.io/presentation/devopsconf/devopsconf.html),
|
- DevOpsConf'2021: презентация ([на русском](https://vitastor.io/presentation/devopsconf/devopsconf.html),
|
||||||
[на английском](https://vitastor.io/presentation/devopsconf/devopsconf_en.html)),
|
[на английском](https://vitastor.io/presentation/devopsconf/devopsconf_en.html)),
|
||||||
[видео](https://vitastor.io/presentation/devopsconf/talk.webm)
|
[видео](https://vitastor.io/presentation/devopsconf/talk.webm)
|
||||||
- Highload'2022: презентация ([на русском](https://vitastor.io/presentation/highload/highload.html)),
|
|
||||||
[видео](https://vitastor.io/presentation/highload/talk.webm)
|
|
||||||
|
|
||||||
## Документация
|
## Документация
|
||||||
|
|
||||||
@@ -58,14 +62,16 @@ Vitastor поддерживает QEMU-драйвер, протоколы NBD и
|
|||||||
- [Дисковые параметры OSD](docs/config/layout-osd.ru.md)
|
- [Дисковые параметры OSD](docs/config/layout-osd.ru.md)
|
||||||
- [Прочие параметры OSD](docs/config/osd.ru.md)
|
- [Прочие параметры OSD](docs/config/osd.ru.md)
|
||||||
- [Параметры мониторов](docs/config/monitor.ru.md)
|
- [Параметры мониторов](docs/config/monitor.ru.md)
|
||||||
|
- [Безопасность](docs/config/security.ru.md)
|
||||||
- [Настройки пулов](docs/config/pool.ru.md)
|
- [Настройки пулов](docs/config/pool.ru.md)
|
||||||
- [Метаданные образов в etcd](docs/config/inode.ru.md)
|
- [Метаданные образов в etcd](docs/config/inode.ru.md)
|
||||||
- Использование
|
- Использование
|
||||||
- [vitastor-cli](docs/usage/cli.ru.md) (консольный интерфейс)
|
- [vitastor-cli](docs/usage/cli.ru.md) (консольный интерфейс)
|
||||||
- [vitastor-disk](docs/usage/disk.ru.md) (управление дисками)
|
- [vitastor-disk](docs/usage/disk.ru.md) (управление дисками)
|
||||||
- [fio](docs/usage/fio.ru.md) для тестов производительности
|
- [fio](docs/usage/fio.ru.md) для тестов производительности
|
||||||
- [NBD](docs/usage/nbd.ru.md) для монтирования ядром
|
- [UBLK](docs/usage/ublk.ru.md) для монтирования ядром
|
||||||
- [QEMU и qemu-img](docs/usage/qemu.ru.md)
|
- [NBD](docs/usage/nbd.ru.md) - старый интерфейс для монтирования ядром
|
||||||
|
- [QEMU, qemu-img и VDUSE](docs/usage/qemu.ru.md)
|
||||||
- [NFS](docs/usage/nfs.ru.md) кластерная файловая система и псевдо-ФС прокси
|
- [NFS](docs/usage/nfs.ru.md) кластерная файловая система и псевдо-ФС прокси
|
||||||
- [Администрирование](docs/usage/admin.ru.md)
|
- [Администрирование](docs/usage/admin.ru.md)
|
||||||
- Производительность
|
- Производительность
|
||||||
|
|||||||
@@ -19,18 +19,22 @@ supports TCP and RDMA and may achieve 4 KB read and write latency as low as ~0.1
|
|||||||
with proper hardware which is ~10 times faster than other popular SDS's like Ceph
|
with proper hardware which is ~10 times faster than other popular SDS's like Ceph
|
||||||
or internal systems of public clouds.
|
or internal systems of public clouds.
|
||||||
|
|
||||||
Vitastor supports QEMU, NBD, NFS protocols, OpenStack, OpenNebula, Proxmox, Kubernetes drivers.
|
Vitastor supports QEMU, UBLK, NBD, NFS protocols, OpenStack, OpenNebula, Proxmox, Kubernetes drivers.
|
||||||
More drivers may be created easily.
|
More drivers may be created easily.
|
||||||
|
|
||||||
Read more details in the documentation. You can start from here: [Quick Start](docs/intro/quickstart.en.md).
|
Read more details in the documentation. You can start from here: [Quick Start](docs/intro/quickstart.en.md).
|
||||||
|
|
||||||
## Talks and presentations
|
## Talks and presentations
|
||||||
|
|
||||||
|
- KuberConf'2025: [video](https://vitastor.io/presentation/kuberconf.webm)
|
||||||
|
- Highload'2025: [video](https://vitastor.io/presentation/hl2025/hl2025.webm),
|
||||||
|
[youtube](https://www.youtube.com/watch?v=0R8MLjFtz7g), presentation
|
||||||
|
([in Russian](https://vitastor.io/presentation/hl2025/), [in English](https://vitastor.io/presentation/hl2025/en.html))
|
||||||
|
- Highload'2022: presentation ([in Russian](https://vitastor.io/presentation/highload/highload.html)),
|
||||||
|
[video](https://vitastor.io/presentation/highload/talk.webm)
|
||||||
- DevOpsConf'2021: presentation ([in Russian](https://vitastor.io/presentation/devopsconf/devopsconf.html),
|
- DevOpsConf'2021: presentation ([in Russian](https://vitastor.io/presentation/devopsconf/devopsconf.html),
|
||||||
[in English](https://vitastor.io/presentation/devopsconf/devopsconf_en.html)),
|
[in English](https://vitastor.io/presentation/devopsconf/devopsconf_en.html)),
|
||||||
[video](https://vitastor.io/presentation/devopsconf/talk.webm)
|
[video](https://vitastor.io/presentation/devopsconf/talk.webm)
|
||||||
- Highload'2022: presentation ([in Russian](https://vitastor.io/presentation/highload/highload.html)),
|
|
||||||
[video](https://vitastor.io/presentation/highload/talk.webm)
|
|
||||||
|
|
||||||
## Documentation
|
## Documentation
|
||||||
|
|
||||||
@@ -58,14 +62,16 @@ Read more details in the documentation. You can start from here: [Quick Start](d
|
|||||||
- [OSD Disk Layout](docs/config/layout-osd.en.md)
|
- [OSD Disk Layout](docs/config/layout-osd.en.md)
|
||||||
- [OSD Runtime Parameters](docs/config/osd.en.md)
|
- [OSD Runtime Parameters](docs/config/osd.en.md)
|
||||||
- [Monitor](docs/config/monitor.en.md)
|
- [Monitor](docs/config/monitor.en.md)
|
||||||
|
- [Security](docs/config/security.en.md)
|
||||||
- [Pool configuration](docs/config/pool.en.md)
|
- [Pool configuration](docs/config/pool.en.md)
|
||||||
- [Image metadata in etcd](docs/config/inode.en.md)
|
- [Image metadata in etcd](docs/config/inode.en.md)
|
||||||
- Usage
|
- Usage
|
||||||
- [vitastor-cli](docs/usage/cli.en.md) (command-line interface)
|
- [vitastor-cli](docs/usage/cli.en.md) (command-line interface)
|
||||||
- [vitastor-disk](docs/usage/disk.en.md) (disk management tool)
|
- [vitastor-disk](docs/usage/disk.en.md) (disk management tool)
|
||||||
- [fio](docs/usage/fio.en.md) for benchmarks
|
- [fio](docs/usage/fio.en.md) for benchmarks
|
||||||
- [NBD](docs/usage/nbd.en.md) for kernel mounts
|
- [UBLK](docs/usage/ublk.en.md) for kernel mounts
|
||||||
- [QEMU and qemu-img](docs/usage/qemu.en.md)
|
- [NBD](docs/usage/nbd.en.md) - old interface for kernel mounts
|
||||||
|
- [QEMU, qemu-img and VDUSE](docs/usage/qemu.en.md)
|
||||||
- [NFS](docs/usage/nfs.en.md) clustered file system and pseudo-FS proxy
|
- [NFS](docs/usage/nfs.en.md) clustered file system and pseudo-FS proxy
|
||||||
- [Administration](docs/usage/admin.en.md)
|
- [Administration](docs/usage/admin.en.md)
|
||||||
- Performance
|
- Performance
|
||||||
|
|||||||
+1
-1
Submodule cpp-btree updated: 8de8b467ac...431d2e1d35
+8
-8
@@ -1,5 +1,5 @@
|
|||||||
# Compile stage
|
# Compile stage
|
||||||
FROM golang:bookworm AS build
|
FROM golang:trixie AS build
|
||||||
|
|
||||||
ADD go.sum go.mod /app/
|
ADD go.sum go.mod /app/
|
||||||
RUN cd /app; CGO_ENABLED=1 GOOS=linux GOARCH=amd64 go mod download -x
|
RUN cd /app; CGO_ENABLED=1 GOOS=linux GOARCH=amd64 go mod download -x
|
||||||
@@ -9,7 +9,7 @@ RUN perl -i -e '$/ = undef; while(<>) { s/\n\s*(\{\s*\n)/$1\n/g; s/\}(\s*\n\s*)e
|
|||||||
CGO_ENABLED=1 GOOS=linux GOARCH=amd64 go build -o vitastor-csi
|
CGO_ENABLED=1 GOOS=linux GOARCH=amd64 go build -o vitastor-csi
|
||||||
|
|
||||||
# Final stage
|
# Final stage
|
||||||
FROM debian:bookworm
|
FROM debian:trixie
|
||||||
|
|
||||||
LABEL maintainers="Vitaliy Filippov <vitalif@yourcmc.ru>"
|
LABEL maintainers="Vitaliy Filippov <vitalif@yourcmc.ru>"
|
||||||
LABEL description="Vitastor CSI Driver"
|
LABEL description="Vitastor CSI Driver"
|
||||||
@@ -25,20 +25,20 @@ RUN apt-get update && \
|
|||||||
# NFS mount dependencies
|
# NFS mount dependencies
|
||||||
nfs-common netbase \
|
nfs-common netbase \
|
||||||
# dependencies of qemu-storage-daemon
|
# dependencies of qemu-storage-daemon
|
||||||
libnuma1 liburing2 libglib2.0-0 libfuse3-3 libaio1 libzstd1 libnettle8 \
|
libaio1t64 libc6 libfuse3-4 libglib2.0-0t64 libgmp10 libgnutls30t64 \
|
||||||
libgmp10 libhogweed6 libp11-kit0 libidn2-0 libunistring2 libtasn1-6 libpcre2-8-0 libffi8 && \
|
libhogweed6t64 libnettle8t64 libnuma1 libselinux1 liburing2 libzstd1 zlib1g && \
|
||||||
apt-get clean && \
|
apt-get clean && \
|
||||||
(echo options nbd nbds_max=128 > /etc/modprobe.d/nbd.conf)
|
(echo options nbd nbds_max=128 > /etc/modprobe.d/nbd.conf)
|
||||||
|
|
||||||
COPY --from=build /app/vitastor-csi /bin/
|
COPY --from=build /app/vitastor-csi /bin/
|
||||||
|
|
||||||
RUN (echo deb http://vitastor.io/debian bookworm main > /etc/apt/sources.list.d/vitastor.list) && \
|
RUN (echo deb http://vitastor.io/debian trixie main > /etc/apt/sources.list.d/vitastor.list) && \
|
||||||
((echo 'Package: *'; echo 'Pin: origin "vitastor.io"'; echo 'Pin-Priority: 1000') > /etc/apt/preferences.d/vitastor.pref) && \
|
((echo 'Package: *'; echo 'Pin: origin "vitastor.io"'; echo 'Pin-Priority: 1000') > /etc/apt/preferences.d/vitastor.pref) && \
|
||||||
wget -q -O /etc/apt/trusted.gpg.d/vitastor.gpg https://vitastor.io/debian/pubkey.gpg && \
|
wget -q -O /etc/apt/trusted.gpg.d/vitastor.gpg https://vitastor.io/debian/pubkey.gpg && \
|
||||||
apt-get update && \
|
apt-get update && \
|
||||||
apt-get install -y vitastor-client && \
|
apt-get install -y vitastor-client ibverbs-providers && \
|
||||||
wget https://vitastor.io/archive/qemu/qemu-bookworm-9.2.2%2Bds-1%2Bvitastor4/qemu-utils_9.2.2%2Bds-1%2Bvitastor4_amd64.deb && \
|
wget https://vitastor.io/archive/qemu/qemu-trixie-10.0.2%2Bds-2%2Bvitastor1/qemu-utils_10.0.2%2Bds-2%2Bvitastor1_amd64.deb && \
|
||||||
wget https://vitastor.io/archive/qemu/qemu-bookworm-9.2.2%2Bds-1%2Bvitastor4/qemu-block-extra_9.2.2%2Bds-1%2Bvitastor4_amd64.deb && \
|
wget https://vitastor.io/archive/qemu/qemu-trixie-10.0.2%2Bds-2%2Bvitastor1/qemu-block-extra_10.0.2%2Bds-2%2Bvitastor1_amd64.deb && \
|
||||||
dpkg -x qemu-utils*.deb tmp1 && \
|
dpkg -x qemu-utils*.deb tmp1 && \
|
||||||
dpkg -x qemu-block-extra*.deb tmp1 && \
|
dpkg -x qemu-block-extra*.deb tmp1 && \
|
||||||
cp -a tmp1/usr/bin/qemu-storage-daemon /usr/bin/ && \
|
cp -a tmp1/usr/bin/qemu-storage-daemon /usr/bin/ && \
|
||||||
|
|||||||
@@ -0,0 +1,49 @@
|
|||||||
|
# Compile stage
|
||||||
|
FROM golang:trixie AS build
|
||||||
|
|
||||||
|
ADD go.sum go.mod /app/
|
||||||
|
RUN cd /app; CGO_ENABLED=1 GOOS=linux GOARCH=amd64 go mod download -x
|
||||||
|
ADD . /app
|
||||||
|
RUN perl -i -e '$/ = undef; while(<>) { s/\n\s*(\{\s*\n)/$1\n/g; s/\}(\s*\n\s*)else\b/$1} else/g; print; }' `find /app -name '*.go'` && \
|
||||||
|
cd /app && \
|
||||||
|
CGO_ENABLED=1 GOOS=linux GOARCH=amd64 go build -o vitastor-csi
|
||||||
|
|
||||||
|
# Final stage
|
||||||
|
FROM debian:trixie
|
||||||
|
|
||||||
|
LABEL maintainers="Vitaliy Filippov <vitalif@yourcmc.ru>"
|
||||||
|
LABEL description="Vitastor CSI Driver"
|
||||||
|
|
||||||
|
ENV NODE_ID=""
|
||||||
|
ENV CSI_ENDPOINT=""
|
||||||
|
|
||||||
|
RUN apt-get update && \
|
||||||
|
apt-get install -y wget && \
|
||||||
|
(echo "APT::Install-Recommends false;" > /etc/apt/apt.conf) && \
|
||||||
|
apt-get update && \
|
||||||
|
apt-get install -y e2fsprogs xfsprogs kmod iproute2 \
|
||||||
|
# NFS mount dependencies
|
||||||
|
nfs-common netbase \
|
||||||
|
# dependencies of qemu-storage-daemon
|
||||||
|
libnuma1 liburing2 libglib2.0-0 libfuse3-3 libaio1 libzstd1 libnettle8 \
|
||||||
|
libgmp10 libhogweed6 libp11-kit0 libidn2-0 libunistring2 libtasn1-6 libpcre2-8-0 libffi8 && \
|
||||||
|
apt-get clean && \
|
||||||
|
(echo options nbd nbds_max=128 > /etc/modprobe.d/nbd.conf)
|
||||||
|
|
||||||
|
COPY --from=build /app/vitastor-csi /bin/
|
||||||
|
|
||||||
|
ADD deb /deb
|
||||||
|
|
||||||
|
RUN apt-get update && \
|
||||||
|
apt-get -y install /deb/vitastor-client_*.deb && \
|
||||||
|
wget https://vitastor.io/archive/qemu/qemu-trixie-9.2.2%2Bds-1%2Bvitastor4/qemu-utils_9.2.2%2Bds-1%2Bvitastor4_amd64.deb && \
|
||||||
|
wget https://vitastor.io/archive/qemu/qemu-trixie-9.2.2%2Bds-1%2Bvitastor4/qemu-block-extra_9.2.2%2Bds-1%2Bvitastor4_amd64.deb && \
|
||||||
|
dpkg -x qemu-utils*.deb tmp1 && \
|
||||||
|
dpkg -x qemu-block-extra*.deb tmp1 && \
|
||||||
|
cp -a tmp1/usr/bin/qemu-storage-daemon /usr/bin/ && \
|
||||||
|
mkdir -p /usr/lib/x86_64-linux-gnu/qemu && \
|
||||||
|
cp -a tmp1/usr/lib/x86_64-linux-gnu/qemu/block-vitastor.so /usr/lib/x86_64-linux-gnu/qemu/ && \
|
||||||
|
rm -rf tmp1 *.deb && \
|
||||||
|
apt-get clean
|
||||||
|
|
||||||
|
ENTRYPOINT ["/bin/vitastor-csi"]
|
||||||
+1
-1
@@ -1,4 +1,4 @@
|
|||||||
VITASTOR_VERSION ?= v2.2.2
|
VITASTOR_VERSION ?= v3.0.15
|
||||||
|
|
||||||
all: build push
|
all: build push
|
||||||
|
|
||||||
|
|||||||
@@ -49,7 +49,7 @@ spec:
|
|||||||
capabilities:
|
capabilities:
|
||||||
add: ["SYS_ADMIN"]
|
add: ["SYS_ADMIN"]
|
||||||
allowPrivilegeEscalation: true
|
allowPrivilegeEscalation: true
|
||||||
image: vitalif/vitastor-csi:v2.2.2
|
image: vitalif/vitastor-csi:v3.0.15
|
||||||
args:
|
args:
|
||||||
- "--node=$(NODE_ID)"
|
- "--node=$(NODE_ID)"
|
||||||
- "--endpoint=$(CSI_ENDPOINT)"
|
- "--endpoint=$(CSI_ENDPOINT)"
|
||||||
|
|||||||
@@ -121,7 +121,7 @@ spec:
|
|||||||
privileged: true
|
privileged: true
|
||||||
capabilities:
|
capabilities:
|
||||||
add: ["SYS_ADMIN"]
|
add: ["SYS_ADMIN"]
|
||||||
image: vitalif/vitastor-csi:v2.2.2
|
image: vitalif/vitastor-csi:v3.0.15
|
||||||
args:
|
args:
|
||||||
- "--node=$(NODE_ID)"
|
- "--node=$(NODE_ID)"
|
||||||
- "--endpoint=$(CSI_ENDPOINT)"
|
- "--endpoint=$(CSI_ENDPOINT)"
|
||||||
|
|||||||
+1
-1
@@ -5,7 +5,7 @@ package vitastor
|
|||||||
|
|
||||||
const (
|
const (
|
||||||
vitastorCSIDriverName = "csi.vitastor.io"
|
vitastorCSIDriverName = "csi.vitastor.io"
|
||||||
vitastorCSIDriverVersion = "2.2.2"
|
vitastorCSIDriverVersion = "3.0.15"
|
||||||
)
|
)
|
||||||
|
|
||||||
// Config struct fills the parameters of request or user input
|
// Config struct fills the parameters of request or user input
|
||||||
|
|||||||
+115
-20
@@ -33,7 +33,7 @@ import (
|
|||||||
type NodeServer struct
|
type NodeServer struct
|
||||||
{
|
{
|
||||||
*Driver
|
*Driver
|
||||||
useVduse bool
|
method MountMethod
|
||||||
stateDir string
|
stateDir string
|
||||||
nfsStageDir string
|
nfsStageDir string
|
||||||
mounter mount.Interface
|
mounter mount.Interface
|
||||||
@@ -81,16 +81,23 @@ func NewNodeServer(driver *Driver) *NodeServer
|
|||||||
}
|
}
|
||||||
ns := &NodeServer{
|
ns := &NodeServer{
|
||||||
Driver: driver,
|
Driver: driver,
|
||||||
useVduse: checkVduseSupport(),
|
method: selectMountMethod(),
|
||||||
stateDir: stateDir,
|
stateDir: stateDir,
|
||||||
nfsStageDir: nfsStageDir,
|
nfsStageDir: nfsStageDir,
|
||||||
mounter: mount.New(""),
|
mounter: mount.New(""),
|
||||||
volumeLocks: make(map[string]bool),
|
volumeLocks: make(map[string]bool),
|
||||||
}
|
}
|
||||||
ns.cond = sync.NewCond(&ns.mu)
|
ns.cond = sync.NewCond(&ns.mu)
|
||||||
if (ns.useVduse)
|
if (ns.method == MOUNT_VDUSE)
|
||||||
{
|
{
|
||||||
ns.restoreVduseDaemons()
|
ns.restoreVduseDaemons()
|
||||||
|
}
|
||||||
|
else if (ns.method == MOUNT_UBLK)
|
||||||
|
{
|
||||||
|
ns.restoreUblkDaemons()
|
||||||
|
}
|
||||||
|
if (ns.method == MOUNT_VDUSE || ns.method == MOUNT_UBLK)
|
||||||
|
{
|
||||||
dur, err := time.ParseDuration(os.Getenv("RESTART_INTERVAL"))
|
dur, err := time.ParseDuration(os.Getenv("RESTART_INTERVAL"))
|
||||||
if (err != nil)
|
if (err != nil)
|
||||||
{
|
{
|
||||||
@@ -136,7 +143,14 @@ func (ns *NodeServer) restarter()
|
|||||||
for
|
for
|
||||||
{
|
{
|
||||||
<-ticker.C
|
<-ticker.C
|
||||||
ns.restoreVduseDaemons()
|
if (ns.method == MOUNT_VDUSE)
|
||||||
|
{
|
||||||
|
ns.restoreVduseDaemons()
|
||||||
|
}
|
||||||
|
else if (ns.method == MOUNT_UBLK)
|
||||||
|
{
|
||||||
|
ns.restoreUblkDaemons()
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -231,6 +245,78 @@ func (ns *NodeServer) checkVduseState(stateFile string, devs map[string]interfac
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func (ns *NodeServer) restoreUblkDaemons()
|
||||||
|
{
|
||||||
|
pattern := ns.stateDir+"vitastor-ublk-*.json"
|
||||||
|
stateFiles, err := filepath.Glob(pattern)
|
||||||
|
if (err != nil)
|
||||||
|
{
|
||||||
|
klog.Errorf("failed to list %s: %v", pattern, err)
|
||||||
|
}
|
||||||
|
if (len(stateFiles) == 0)
|
||||||
|
{
|
||||||
|
return
|
||||||
|
}
|
||||||
|
for _, stateFile := range stateFiles
|
||||||
|
{
|
||||||
|
deviceNum := stateFile[len(ns.stateDir) + len("vitastor-ublk-") :]
|
||||||
|
deviceNum = deviceNum[0:len(deviceNum)-5]
|
||||||
|
ns.checkUblkState(deviceNum)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func (ns *NodeServer) checkUblkState(deviceNum string)
|
||||||
|
{
|
||||||
|
// Check if the ublk daemon is still active
|
||||||
|
|
||||||
|
// Read state file
|
||||||
|
stateFile := ns.stateDir + "vitastor-ublk-" + deviceNum + ".json"
|
||||||
|
stateJSON, err := os.ReadFile(stateFile)
|
||||||
|
if (err != nil)
|
||||||
|
{
|
||||||
|
klog.Warningf("error reading state file %v: %v", stateFile, err)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
var state DeviceState
|
||||||
|
err = json.Unmarshal(stateJSON, &state)
|
||||||
|
if (err != nil)
|
||||||
|
{
|
||||||
|
klog.Warningf("state file %v contains invalid JSON (error %v): %v", stateFile, err, string(stateJSON))
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
// Lock volume
|
||||||
|
ns.lockVolume(state.ConfigPath+":block:"+state.Image)
|
||||||
|
defer ns.unlockVolume(state.ConfigPath+":block:"+state.Image)
|
||||||
|
|
||||||
|
// Recheck state file after locking
|
||||||
|
_, err = os.ReadFile(stateFile)
|
||||||
|
if (err != nil)
|
||||||
|
{
|
||||||
|
klog.Warningf("state file %v disappeared, skipping volume", stateFile)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
// Check if the vitastor-ublk process is still active
|
||||||
|
pidFile := ns.stateDir + "vitastor-ublk-" + deviceNum + ".pid"
|
||||||
|
exists := false
|
||||||
|
proc, err := findByPidFile(pidFile)
|
||||||
|
if (err == nil)
|
||||||
|
{
|
||||||
|
exists = proc.Signal(syscall.Signal(0)) == nil
|
||||||
|
}
|
||||||
|
if (!exists)
|
||||||
|
{
|
||||||
|
// Restart daemon
|
||||||
|
klog.Warningf("recovering UBLK device /dev/ublkb%v for volume %v", deviceNum, state.Image)
|
||||||
|
_, err = mapUblk(ns.stateDir, state.Image, state.ConfigPath, state.Readonly, "/dev/ublkb"+deviceNum)
|
||||||
|
if (err != nil)
|
||||||
|
{
|
||||||
|
klog.Warningf("failed to recover ublk device for volume %v: %v", state.Image, err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
func (ns *NodeServer) restoreNfsDaemons()
|
func (ns *NodeServer) restoreNfsDaemons()
|
||||||
{
|
{
|
||||||
pattern := ns.stateDir+"vitastor-nfs-*.json"
|
pattern := ns.stateDir+"vitastor-nfs-*.json"
|
||||||
@@ -417,14 +503,18 @@ func (ns *NodeServer) NodeStageVolume(ctx context.Context, req *csi.NodeStageVol
|
|||||||
}
|
}
|
||||||
|
|
||||||
var devicePath, vdpaId string
|
var devicePath, vdpaId string
|
||||||
if (!ns.useVduse)
|
if (ns.method == MOUNT_UBLK)
|
||||||
{
|
{
|
||||||
devicePath, err = mapNbd(volName, ctxVars, false)
|
devicePath, err = mapUblk(ns.stateDir, volName, ctxVars["configPath"], false, "")
|
||||||
}
|
}
|
||||||
else
|
else if (ns.method == MOUNT_VDUSE)
|
||||||
{
|
{
|
||||||
devicePath, vdpaId, err = mapVduse(ns.stateDir, volName, ctxVars, false)
|
devicePath, vdpaId, err = mapVduse(ns.stateDir, volName, ctxVars, false)
|
||||||
}
|
}
|
||||||
|
else /* if (ns.method == MOUNT_NBD) */
|
||||||
|
{
|
||||||
|
devicePath, err = mapNbd(volName, ctxVars, false)
|
||||||
|
}
|
||||||
if (err != nil)
|
if (err != nil)
|
||||||
{
|
{
|
||||||
return nil, err
|
return nil, err
|
||||||
@@ -439,7 +529,8 @@ func (ns *NodeServer) NodeStageVolume(ctx context.Context, req *csi.NodeStageVol
|
|||||||
else
|
else
|
||||||
{
|
{
|
||||||
// Check existing format
|
// Check existing format
|
||||||
existingFormat, err := diskMounter.GetDiskFormat(devicePath)
|
var existingFormat string
|
||||||
|
existingFormat, err = diskMounter.GetDiskFormat(devicePath)
|
||||||
if (err != nil)
|
if (err != nil)
|
||||||
{
|
{
|
||||||
klog.Errorf("failed to get disk format for path %s, error: %v", err)
|
klog.Errorf("failed to get disk format for path %s, error: %v", err)
|
||||||
@@ -495,10 +586,6 @@ func (ns *NodeServer) NodeStageVolume(ctx context.Context, req *csi.NodeStageVol
|
|||||||
case "xfs":
|
case "xfs":
|
||||||
_, err = systemCombined("xfs_growfs", devicePath)
|
_, err = systemCombined("xfs_growfs", devicePath)
|
||||||
}
|
}
|
||||||
if (err != nil)
|
|
||||||
{
|
|
||||||
goto unmap
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
if (err != nil)
|
if (err != nil)
|
||||||
@@ -512,14 +599,18 @@ func (ns *NodeServer) NodeStageVolume(ctx context.Context, req *csi.NodeStageVol
|
|||||||
return &csi.NodeStageVolumeResponse{}, nil
|
return &csi.NodeStageVolumeResponse{}, nil
|
||||||
|
|
||||||
unmap:
|
unmap:
|
||||||
if (!ns.useVduse || len(devicePath) >= 8 && devicePath[0:8] == "/dev/nbd")
|
if (ns.method == MOUNT_UBLK)
|
||||||
{
|
{
|
||||||
unmapNbd(devicePath)
|
unmapUblk(ns.stateDir, devicePath)
|
||||||
}
|
}
|
||||||
else
|
else if (ns.method == MOUNT_VDUSE)
|
||||||
{
|
{
|
||||||
unmapVduseById(ns.stateDir, vdpaId)
|
unmapVduseById(ns.stateDir, vdpaId)
|
||||||
}
|
}
|
||||||
|
else /* if (ns.method == MOUNT_NBD) */
|
||||||
|
{
|
||||||
|
unmapNbd(devicePath)
|
||||||
|
}
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -545,7 +636,7 @@ func (ns *NodeServer) NodeUnstageVolume(ctx context.Context, req *csi.NodeUnstag
|
|||||||
defer ns.unlockVolume(ctxVars["configPath"]+":block:"+volName)
|
defer ns.unlockVolume(ctxVars["configPath"]+":block:"+volName)
|
||||||
|
|
||||||
targetPath := req.GetStagingTargetPath()
|
targetPath := req.GetStagingTargetPath()
|
||||||
devicePath, _, err := mount.GetDeviceNameFromMount(ns.mounter, targetPath)
|
devicePath, err := GetDeviceNameFromMount(targetPath)
|
||||||
if (err != nil)
|
if (err != nil)
|
||||||
{
|
{
|
||||||
if (os.IsNotExist(err))
|
if (os.IsNotExist(err))
|
||||||
@@ -582,14 +673,18 @@ func (ns *NodeServer) NodeUnstageVolume(ctx context.Context, req *csi.NodeUnstag
|
|||||||
// unmap device
|
// unmap device
|
||||||
if (len(refList) == 0)
|
if (len(refList) == 0)
|
||||||
{
|
{
|
||||||
if (!ns.useVduse)
|
if (ns.method == MOUNT_UBLK)
|
||||||
{
|
{
|
||||||
unmapNbd(devicePath)
|
unmapUblk(ns.stateDir, devicePath)
|
||||||
}
|
}
|
||||||
else
|
else if (ns.method == MOUNT_VDUSE)
|
||||||
{
|
{
|
||||||
unmapVduse(ns.stateDir, devicePath)
|
unmapVduse(ns.stateDir, devicePath)
|
||||||
}
|
}
|
||||||
|
else /* if (ns.method == MOUNT_NBD) */
|
||||||
|
{
|
||||||
|
unmapNbd(devicePath)
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
return &csi.NodeUnstageVolumeResponse{}, nil
|
return &csi.NodeUnstageVolumeResponse{}, nil
|
||||||
@@ -897,7 +992,7 @@ func (ns *NodeServer) NodeUnpublishVolume(ctx context.Context, req *csi.NodeUnpu
|
|||||||
}
|
}
|
||||||
|
|
||||||
targetPath := req.GetTargetPath()
|
targetPath := req.GetTargetPath()
|
||||||
devicePath, _, err := mount.GetDeviceNameFromMount(ns.mounter, targetPath)
|
devicePath, err := GetDeviceNameFromMount(targetPath)
|
||||||
if (err != nil)
|
if (err != nil)
|
||||||
{
|
{
|
||||||
if (os.IsNotExist(err))
|
if (os.IsNotExist(err))
|
||||||
|
|||||||
+205
-26
@@ -16,10 +16,20 @@ import (
|
|||||||
"syscall"
|
"syscall"
|
||||||
|
|
||||||
"k8s.io/klog"
|
"k8s.io/klog"
|
||||||
|
"k8s.io/utils/mount"
|
||||||
|
|
||||||
"google.golang.org/grpc/codes"
|
"google.golang.org/grpc/codes"
|
||||||
"google.golang.org/grpc/status"
|
"google.golang.org/grpc/status"
|
||||||
)
|
)
|
||||||
|
|
||||||
|
type MountMethod int
|
||||||
|
|
||||||
|
const (
|
||||||
|
MOUNT_NBD MountMethod = 0
|
||||||
|
MOUNT_VDUSE MountMethod = 1
|
||||||
|
MOUNT_UBLK MountMethod = 2
|
||||||
|
)
|
||||||
|
|
||||||
func Contains(list []string, s string) bool
|
func Contains(list []string, s string) bool
|
||||||
{
|
{
|
||||||
for i := 0; i < len(list); i++
|
for i := 0; i < len(list); i++
|
||||||
@@ -32,29 +42,26 @@ func Contains(list []string, s string) bool
|
|||||||
return false
|
return false
|
||||||
}
|
}
|
||||||
|
|
||||||
func checkVduseSupport() bool
|
func selectMountMethod() MountMethod
|
||||||
{
|
{
|
||||||
|
// Check UBLK support (ublk_drv kernel module)
|
||||||
|
if (checkModule("ublk_drv"))
|
||||||
|
{
|
||||||
|
klog.Infof("UBLK support enabled successfully")
|
||||||
|
return MOUNT_UBLK
|
||||||
|
}
|
||||||
|
klog.Errorf(
|
||||||
|
"Your host apparently has no UBLK support. UBLK support disabled."+
|
||||||
|
" For UBLK you need at least Linux 6.0 and the ublk_drv kernel module.",
|
||||||
|
)
|
||||||
// Check VDUSE support (vdpa, vduse, virtio-vdpa kernel modules)
|
// Check VDUSE support (vdpa, vduse, virtio-vdpa kernel modules)
|
||||||
vduse := true
|
vduse := true
|
||||||
for _, mod := range []string{"vdpa", "vduse", "virtio-vdpa"}
|
for _, mod := range []string{"vdpa", "vduse", "virtio-vdpa"}
|
||||||
{
|
{
|
||||||
_, err := os.Stat("/sys/module/"+mod)
|
if (!checkModule(mod))
|
||||||
if (err != nil)
|
|
||||||
{
|
{
|
||||||
if (!errors.Is(err, os.ErrNotExist))
|
vduse = false
|
||||||
{
|
break
|
||||||
klog.Errorf("failed to check /sys/module/%s: %v", mod, err)
|
|
||||||
}
|
|
||||||
c := exec.Command("/sbin/modprobe", mod)
|
|
||||||
c.Stdout = os.Stderr
|
|
||||||
c.Stderr = os.Stderr
|
|
||||||
err := c.Run()
|
|
||||||
if (err != nil)
|
|
||||||
{
|
|
||||||
klog.Errorf("/sbin/modprobe %s failed: %v", mod, err)
|
|
||||||
vduse = false
|
|
||||||
break
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
// Check that vdpa tool functions
|
// Check that vdpa tool functions
|
||||||
@@ -69,18 +76,38 @@ func checkVduseSupport() bool
|
|||||||
vduse = false
|
vduse = false
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
if (!vduse)
|
if (vduse)
|
||||||
{
|
|
||||||
klog.Errorf(
|
|
||||||
"Your host apparently has no VDUSE support. VDUSE support disabled, NBD will be used to map devices."+
|
|
||||||
" For VDUSE you need at least Linux 5.15 and the following kernel modules: vdpa, virtio-vdpa, vduse.",
|
|
||||||
)
|
|
||||||
}
|
|
||||||
else
|
|
||||||
{
|
{
|
||||||
klog.Infof("VDUSE support enabled successfully")
|
klog.Infof("VDUSE support enabled successfully")
|
||||||
|
return MOUNT_VDUSE
|
||||||
}
|
}
|
||||||
return vduse
|
klog.Errorf(
|
||||||
|
"Your host apparently has no VDUSE support. VDUSE support disabled, NBD will be used to map devices."+
|
||||||
|
" For VDUSE you need at least Linux 5.15 and the following kernel modules: vdpa, virtio-vdpa, vduse.",
|
||||||
|
)
|
||||||
|
return MOUNT_NBD
|
||||||
|
}
|
||||||
|
|
||||||
|
func checkModule(mod string) bool
|
||||||
|
{
|
||||||
|
_, err := os.Stat("/sys/module/"+mod)
|
||||||
|
if (err != nil)
|
||||||
|
{
|
||||||
|
if (!errors.Is(err, os.ErrNotExist))
|
||||||
|
{
|
||||||
|
klog.Errorf("failed to check /sys/module/%s: %v", mod, err)
|
||||||
|
}
|
||||||
|
c := exec.Command("/sbin/modprobe", mod)
|
||||||
|
c.Stdout = os.Stderr
|
||||||
|
c.Stderr = os.Stderr
|
||||||
|
err := c.Run()
|
||||||
|
if (err != nil)
|
||||||
|
{
|
||||||
|
klog.Errorf("/sbin/modprobe %s failed: %v", mod, err)
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return true
|
||||||
}
|
}
|
||||||
|
|
||||||
func mapNbd(volName string, ctxVars map[string]string, readonly bool) (string, error)
|
func mapNbd(volName string, ctxVars map[string]string, readonly bool) (string, error)
|
||||||
@@ -217,6 +244,7 @@ func mapVduse(stateDir string, volName string, ctxVars map[string]string, readon
|
|||||||
stateJSON, _ := json.Marshal(&DeviceState{
|
stateJSON, _ := json.Marshal(&DeviceState{
|
||||||
ConfigPath: ctxVars["configPath"],
|
ConfigPath: ctxVars["configPath"],
|
||||||
VdpaId: vdpaId,
|
VdpaId: vdpaId,
|
||||||
|
|
||||||
Image: volName,
|
Image: volName,
|
||||||
Blockdev: blockdev,
|
Blockdev: blockdev,
|
||||||
Readonly: readonly,
|
Readonly: readonly,
|
||||||
@@ -309,6 +337,117 @@ func unmapVduseById(stateDir, vdpaId string)
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func mapUblk(stateDir string, volName string, configPath string, readonly bool, recoverDev string) (string, error)
|
||||||
|
{
|
||||||
|
pidFile := ""
|
||||||
|
if (recoverDev != "")
|
||||||
|
{
|
||||||
|
if (len(recoverDev) < 10 || recoverDev[0:10] != "/dev/ublkb")
|
||||||
|
{
|
||||||
|
return "", fmt.Errorf("recover: %s does not start with /dev/ublkb", recoverDev)
|
||||||
|
}
|
||||||
|
pidFile = stateDir + "vitastor-ublk-" + recoverDev[10:] + ".pid"
|
||||||
|
}
|
||||||
|
else
|
||||||
|
{
|
||||||
|
pidFd, err := os.CreateTemp(stateDir, "vitastor-tmp-*.pid")
|
||||||
|
if (err != nil)
|
||||||
|
{
|
||||||
|
return "", err
|
||||||
|
}
|
||||||
|
pidFile = pidFd.Name()
|
||||||
|
pidFd.Close()
|
||||||
|
}
|
||||||
|
// Map device via vitastor-ublk
|
||||||
|
args := []string{
|
||||||
|
"map", "--image", volName, "--pidfile", pidFile,
|
||||||
|
}
|
||||||
|
if (configPath != "")
|
||||||
|
{
|
||||||
|
args = append(args, "--config_path", configPath)
|
||||||
|
}
|
||||||
|
if (readonly)
|
||||||
|
{
|
||||||
|
args = append(args, "--readonly")
|
||||||
|
}
|
||||||
|
if (recoverDev != "")
|
||||||
|
{
|
||||||
|
args = append(args, "--recover", recoverDev)
|
||||||
|
}
|
||||||
|
stdout, stderr, err := system("/usr/bin/vitastor-ublk", args...)
|
||||||
|
if (err != nil)
|
||||||
|
{
|
||||||
|
return "", err
|
||||||
|
}
|
||||||
|
devicePath := strings.TrimSpace(string(stdout))
|
||||||
|
if (devicePath == "")
|
||||||
|
{
|
||||||
|
return "", fmt.Errorf("vitastor-ublk did not return the name of the device. output: %s", stderr)
|
||||||
|
}
|
||||||
|
if (len(devicePath) >= 10 && devicePath[0:10] == "/dev/ublkb")
|
||||||
|
{
|
||||||
|
// Generate state file
|
||||||
|
devNum := devicePath[10:]
|
||||||
|
pidNew := stateDir + "vitastor-ublk-" + devNum + ".pid"
|
||||||
|
if (pidFile != pidNew)
|
||||||
|
{
|
||||||
|
err := os.Rename(pidFile, pidNew)
|
||||||
|
if (err != nil)
|
||||||
|
{
|
||||||
|
klog.Errorf("Failed to rename PID file %s to %s: %v", pidFile, pidNew, err)
|
||||||
|
}
|
||||||
|
else
|
||||||
|
{
|
||||||
|
pidFile = pidNew
|
||||||
|
}
|
||||||
|
}
|
||||||
|
stateFile := stateDir + "vitastor-ublk-" + devNum + ".json"
|
||||||
|
stateJSON, _ := json.Marshal(&DeviceState{
|
||||||
|
ConfigPath: configPath,
|
||||||
|
Image: volName,
|
||||||
|
Readonly: readonly,
|
||||||
|
PidFile: pidFile,
|
||||||
|
})
|
||||||
|
err = os.WriteFile(stateFile, stateJSON, 0600)
|
||||||
|
if (err == nil)
|
||||||
|
{
|
||||||
|
klog.Infof("Attached volume %s via UBLK as %s", volName, devicePath)
|
||||||
|
return devicePath, nil
|
||||||
|
}
|
||||||
|
os.Remove(stateFile)
|
||||||
|
}
|
||||||
|
killErr := killByPidFile(pidFile)
|
||||||
|
if (killErr != nil)
|
||||||
|
{
|
||||||
|
klog.Errorf("Failed to kill started vitastor-ublk: %v", killErr)
|
||||||
|
}
|
||||||
|
os.Remove(pidFile)
|
||||||
|
return "", err
|
||||||
|
}
|
||||||
|
|
||||||
|
func unmapUblk(stateDir, devicePath string)
|
||||||
|
{
|
||||||
|
if (len(devicePath) < 10 || devicePath[0:10] != "/dev/ublkb")
|
||||||
|
{
|
||||||
|
klog.Errorf("%s does not start with /dev/ublkb", devicePath)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
unmapOut, unmapErr := exec.Command("/usr/bin/vitastor-ublk", "unmap", devicePath).CombinedOutput()
|
||||||
|
if (unmapErr != nil)
|
||||||
|
{
|
||||||
|
klog.Errorf("failed to unmap UBLK device %s: %s, error: %v", devicePath, unmapOut, unmapErr)
|
||||||
|
}
|
||||||
|
for _, ext := range []string{"json", "pid"}
|
||||||
|
{
|
||||||
|
fn := stateDir + "vitastor-ublk-" + devicePath[10:] + "." + ext
|
||||||
|
err := os.Remove(fn)
|
||||||
|
if (err != nil)
|
||||||
|
{
|
||||||
|
klog.Errorf("failed to remove %s: %v", fn, err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
func system(program string, args ...string) ([]byte, []byte, error)
|
func system(program string, args ...string) ([]byte, []byte, error)
|
||||||
{
|
{
|
||||||
klog.Infof("Running "+program+" "+strings.Join(args, " "))
|
klog.Infof("Running "+program+" "+strings.Join(args, " "))
|
||||||
@@ -340,3 +479,43 @@ func systemCombined(program string, args ...string) ([]byte, error)
|
|||||||
}
|
}
|
||||||
return out.Bytes(), nil
|
return out.Bytes(), nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func GetDeviceNameFromMount(mountPath string) (string, error)
|
||||||
|
{
|
||||||
|
// Use /proc/self/mountinfo to correctly parse bind mounts for block device files
|
||||||
|
mps, err := mount.ParseMountInfo("/proc/self/mountinfo")
|
||||||
|
if (err != nil)
|
||||||
|
{
|
||||||
|
return "", err
|
||||||
|
}
|
||||||
|
|
||||||
|
slTarget, err := filepath.EvalSymlinks(mountPath)
|
||||||
|
if (err != nil)
|
||||||
|
{
|
||||||
|
slTarget = mountPath
|
||||||
|
}
|
||||||
|
|
||||||
|
device := ""
|
||||||
|
for _, mp := range mps
|
||||||
|
{
|
||||||
|
if (mp.MountPoint == slTarget)
|
||||||
|
{
|
||||||
|
device = mp.Source
|
||||||
|
if (device[0] != '/' && mp.Root != "/")
|
||||||
|
{
|
||||||
|
// Handle {Source=udev Root=/vdb MountPoint=/var/lib/kubelet/tralaleylo/tralala}
|
||||||
|
for _, other := range mps
|
||||||
|
{
|
||||||
|
if (other.Root == "/" && other.Source == mp.Source)
|
||||||
|
{
|
||||||
|
device = other.MountPoint + mp.Root
|
||||||
|
break
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
break
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return device, nil
|
||||||
|
}
|
||||||
|
|||||||
Vendored
+2
-5
@@ -1,7 +1,4 @@
|
|||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
|
|
||||||
cat < vitastor.Dockerfile > ../Dockerfile
|
docker build --build-arg DISTRO=debian --build-arg REL=bookworm -t vitastor-buildenv:bookworm -f vitastor-buildenv.Dockerfile .
|
||||||
cd ..
|
docker run -it --rm -e REL=bookworm -v `dirname $0`/../:/root/vitastor vitastor-buildenv:bookworm /root/vitastor/debian/vitastor-build.sh
|
||||||
mkdir -p packages
|
|
||||||
sudo podman build --build-arg DISTRO=debian --build-arg REL=bookworm -v `pwd`/packages:/root/packages -f Dockerfile .
|
|
||||||
rm Dockerfile
|
|
||||||
|
|||||||
Vendored
+2
-5
@@ -1,7 +1,4 @@
|
|||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
|
|
||||||
cat < vitastor.Dockerfile > ../Dockerfile
|
docker build --build-arg DISTRO=debian --build-arg REL=bullseye -t vitastor-buildenv:bullseye -f vitastor-buildenv.Dockerfile .
|
||||||
cd ..
|
docker run -it --rm -e REL=bullseye -v `dirname $0`/../:/root/vitastor vitastor-buildenv:bullseye /root/vitastor/debian/vitastor-build.sh
|
||||||
mkdir -p packages
|
|
||||||
sudo podman build --build-arg DISTRO=debian --build-arg REL=bullseye -v `pwd`/packages:/root/packages -f Dockerfile .
|
|
||||||
rm Dockerfile
|
|
||||||
|
|||||||
Vendored
+2
-5
@@ -1,7 +1,4 @@
|
|||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
|
|
||||||
cat < vitastor.Dockerfile > ../Dockerfile
|
docker build --build-arg DISTRO=debian --build-arg REL=buster -t vitastor-buildenv:buster -f vitastor-buildenv.Dockerfile .
|
||||||
cd ..
|
docker run -it --rm -e REL=buster -v `dirname $0`/../:/root/vitastor vitastor-buildenv:buster /root/vitastor/debian/vitastor-build.sh
|
||||||
mkdir -p packages
|
|
||||||
sudo podman build --build-arg DISTRO=debian --build-arg REL=buster -v `pwd`/packages:/root/packages -f Dockerfile .
|
|
||||||
rm Dockerfile
|
|
||||||
|
|||||||
+4
@@ -0,0 +1,4 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
docker build --build-arg DISTRO=debian --build-arg REL=trixie -t vitastor-buildenv:trixie -f vitastor-buildenv.Dockerfile .
|
||||||
|
docker run -it --rm -e REL=trixie -v `dirname $0`/../:/root/vitastor vitastor-buildenv:trixie /root/vitastor/debian/vitastor-build.sh
|
||||||
+3
-5
@@ -1,7 +1,5 @@
|
|||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
|
# Ubuntu 22.04 Jammy Jellyfish
|
||||||
|
|
||||||
cat < vitastor.Dockerfile > ../Dockerfile
|
docker build --build-arg DISTRO=ubuntu --build-arg REL=jammy -t vitastor-buildenv:jammy -f vitastor-buildenv.Dockerfile .
|
||||||
cd ..
|
docker run -it --rm -e REL=jammy -v `dirname $0`/../:/root/vitastor vitastor-buildenv:jammy /root/vitastor/debian/vitastor-build.sh
|
||||||
mkdir -p packages
|
|
||||||
sudo podman build --build-arg DISTRO=ubuntu --build-arg REL=jammy -v `pwd`/packages:/root/packages -f Dockerfile .
|
|
||||||
rm Dockerfile
|
|
||||||
|
|||||||
+5
@@ -0,0 +1,5 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
# 24.04 Noble Numbat
|
||||||
|
|
||||||
|
docker build --build-arg DISTRO=ubuntu --build-arg REL=noble -t vitastor-buildenv:noble -f vitastor-buildenv.Dockerfile .
|
||||||
|
docker run -it --rm -e REL=noble -v `dirname $0`/../:/root/vitastor vitastor-buildenv:noble /root/vitastor/debian/vitastor-build.sh
|
||||||
+5
@@ -0,0 +1,5 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
# 25.10 Questing quokka
|
||||||
|
|
||||||
|
docker build --build-arg DISTRO=ubuntu --build-arg REL=questing -t vitastor-buildenv:questing -f vitastor-buildenv.Dockerfile .
|
||||||
|
docker run -it --rm -e REL=questing -v `dirname $0`/../:/root/vitastor vitastor-buildenv:questing /root/vitastor/debian/vitastor-build.sh
|
||||||
+5
@@ -0,0 +1,5 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
# 26.04 Resolute Raccoon
|
||||||
|
|
||||||
|
docker build --build-arg DISTRO=ubuntu --build-arg REL=resolute -t vitastor-buildenv:resolute -f vitastor-buildenv.Dockerfile .
|
||||||
|
docker run -it --rm -e REL=resolute -v `dirname $0`/../:/root/vitastor vitastor-buildenv:resolute /root/vitastor/debian/vitastor-build.sh
|
||||||
Vendored
+1
-1
@@ -1,4 +1,4 @@
|
|||||||
vitastor (2.2.2-1) unstable; urgency=medium
|
vitastor (3.0.15-1) unstable; urgency=medium
|
||||||
|
|
||||||
* Bugfixes
|
* Bugfixes
|
||||||
|
|
||||||
|
|||||||
Vendored
+3
-3
@@ -2,9 +2,9 @@ Source: vitastor
|
|||||||
Section: admin
|
Section: admin
|
||||||
Priority: optional
|
Priority: optional
|
||||||
Maintainer: Vitaliy Filippov <vitalif@yourcmc.ru>
|
Maintainer: Vitaliy Filippov <vitalif@yourcmc.ru>
|
||||||
Build-Depends: debhelper, liburing-dev (>= 0.6), g++ (>= 8), libstdc++6 (>= 8),
|
Build-Depends: debhelper, g++ (>= 8), libstdc++6 (>= 8),
|
||||||
linux-libc-dev, libgoogle-perftools-dev, libjerasure-dev, libgf-complete-dev,
|
linux-libc-dev, libgoogle-perftools-dev, libjerasure-dev, libgf-complete-dev, libc-ares-dev,
|
||||||
libibverbs-dev, libisal-dev, cmake, pkg-config, libnl-3-dev, libnl-genl-3-dev,
|
libibverbs-dev, librdmacm-dev, libisal-dev, cmake, pkg-config, libnl-3-dev, libnl-genl-3-dev,
|
||||||
node-bindings <!nocheck>, node-gyp, node-nan
|
node-bindings <!nocheck>, node-gyp, node-nan
|
||||||
Standards-Version: 4.5.0
|
Standards-Version: 4.5.0
|
||||||
Homepage: https://vitastor.io/
|
Homepage: https://vitastor.io/
|
||||||
|
|||||||
Vendored
+1
-1
@@ -26,7 +26,7 @@ RUN if [ "$REL" = "buster" -o "$REL" = "bullseye" -o "$REL" = "bookworm" ]; then
|
|||||||
echo 'APT::Install-Suggests false;' >> /etc/apt/apt.conf
|
echo 'APT::Install-Suggests false;' >> /etc/apt/apt.conf
|
||||||
|
|
||||||
RUN apt-get update
|
RUN apt-get update
|
||||||
RUN DEBIAN_FRONTEND=noninteractive TZ=Europe/Moscow apt-get -y install fio liburing-dev libgoogle-perftools-dev devscripts
|
RUN DEBIAN_FRONTEND=noninteractive TZ=Europe/Moscow apt-get -y install fio libgoogle-perftools-dev devscripts
|
||||||
RUN DEBIAN_FRONTEND=noninteractive TZ=Europe/Moscow apt-get -y build-dep qemu
|
RUN DEBIAN_FRONTEND=noninteractive TZ=Europe/Moscow apt-get -y build-dep qemu
|
||||||
# To build a custom version
|
# To build a custom version
|
||||||
#RUN cp /root/packages/qemu-orig/* /root
|
#RUN cp /root/packages/qemu-orig/* /root
|
||||||
|
|||||||
Vendored
+1
@@ -11,6 +11,7 @@ override_dh_install:
|
|||||||
cp -v node-binding/package.json node-binding/index.js node-binding/addon.cc node-binding/addon.h node-binding/client.cc node-binding/client.h debian/tmp/usr/lib/x86_64-linux-gnu/nodejs/vitastor
|
cp -v node-binding/package.json node-binding/index.js node-binding/addon.cc node-binding/addon.h node-binding/client.cc node-binding/client.h debian/tmp/usr/lib/x86_64-linux-gnu/nodejs/vitastor
|
||||||
cp -v node-binding/build/Release/addon.node debian/tmp/usr/lib/x86_64-linux-gnu/nodejs/vitastor/build/Release
|
cp -v node-binding/build/Release/addon.node debian/tmp/usr/lib/x86_64-linux-gnu/nodejs/vitastor/build/Release
|
||||||
dh_install
|
dh_install
|
||||||
|
cd debian/vitastor-mon/usr/lib/vitastor/mon && npm install --production
|
||||||
|
|
||||||
override_dh_installdeb:
|
override_dh_installdeb:
|
||||||
cat debian/fio_version >> debian/vitastor-fio.substvars
|
cat debian/fio_version >> debian/vitastor-fio.substvars
|
||||||
|
|||||||
+59
@@ -0,0 +1,59 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
# To be ran inside buildenv docker
|
||||||
|
|
||||||
|
set -e -x
|
||||||
|
|
||||||
|
[ -e /usr/lib/x86_64-linux-gnu/pkgconfig/libisal.pc ] || cp /root/vitastor/debian/libisal.pc /usr/lib/x86_64-linux-gnu/pkgconfig
|
||||||
|
|
||||||
|
mkdir -p /root/fio-build/
|
||||||
|
cd /root/fio-build/
|
||||||
|
rm -rf /root/fio-build/*
|
||||||
|
dpkg-source -x /root/fio*.dsc
|
||||||
|
|
||||||
|
FULLVER=`head -n1 /root/vitastor/debian/changelog | perl -pe 's/^.*\((.*?)\).*$/$1/'`
|
||||||
|
VER=${FULLVER%%-*}
|
||||||
|
rm -rf /root/vitastor-$VER
|
||||||
|
mkdir /root/vitastor-$VER
|
||||||
|
cd /root/vitastor
|
||||||
|
cp -a $(ls | grep -v packages) /root/vitastor-$VER
|
||||||
|
|
||||||
|
rm -rf /root/vitastor/packages/vitastor-$REL
|
||||||
|
mkdir -p /root/vitastor/packages/vitastor-$REL
|
||||||
|
mv /root/vitastor-$VER /root/vitastor/packages/vitastor-$REL/
|
||||||
|
|
||||||
|
cd /root/vitastor/packages/vitastor-$REL/vitastor-$VER
|
||||||
|
|
||||||
|
rm -rf fio
|
||||||
|
ln -s /root/fio-build/fio-*/ ./fio
|
||||||
|
FIO=`head -n1 fio/debian/changelog | perl -pe 's/^.*\((.*?)\).*$/$1/'`
|
||||||
|
ls /usr/include/linux/raw.h || cp ./debian/raw.h /usr/include/linux/raw.h
|
||||||
|
sh copy-fio-includes.sh
|
||||||
|
rm fio
|
||||||
|
mkdir -p a b debian/patches
|
||||||
|
mv fio-copy b/fio
|
||||||
|
diff -NaurpbB a b > debian/patches/fio-headers.patch || true
|
||||||
|
echo fio-headers.patch >> debian/patches/series
|
||||||
|
rm -rf a b
|
||||||
|
|
||||||
|
echo "dep:fio=$FIO" > debian/fio_version
|
||||||
|
|
||||||
|
cd /root/vitastor/packages/vitastor-$REL
|
||||||
|
if [[ ( "$REL" = "trixie" || "$REL" = "resolute" ) && -e ../vitastor-bookworm/vitastor_$VER.orig.tar.xz ]]; then
|
||||||
|
# Fucking shit, archives differ between bookworm (xz 5.4.1) and trixie (xz 5.8.1)
|
||||||
|
cp ../vitastor-bookworm/vitastor_$VER.orig.tar.xz .
|
||||||
|
else
|
||||||
|
tar --sort=name --mtime='2020-01-01' --owner=0 --group=0 --exclude=debian -cJf vitastor_$VER.orig.tar.xz vitastor-$VER
|
||||||
|
fi
|
||||||
|
cd vitastor-$VER
|
||||||
|
DEBEMAIL="Vitaliy Filippov <vitalif@yourcmc.ru>" dch -D $REL -v "$FULLVER""$REL" "Rebuild for $REL"
|
||||||
|
DEB_BUILD_OPTIONS=nocheck dpkg-buildpackage --jobs=auto -sa
|
||||||
|
rm -rf /root/vitastor/packages/vitastor-$REL/vitastor-*/
|
||||||
|
|
||||||
|
# Why does ubuntu rename debug packages to *.ddeb?
|
||||||
|
cd /root/vitastor/packages/vitastor-$REL
|
||||||
|
if ls *.ddeb >/dev/null; then
|
||||||
|
perl -i -pe 's/\.ddeb/.deb/' *.buildinfo *.changes
|
||||||
|
for i in *.ddeb; do
|
||||||
|
mv $i ${i%%.ddeb}.deb
|
||||||
|
done
|
||||||
|
fi
|
||||||
Vendored
+29
@@ -0,0 +1,29 @@
|
|||||||
|
# Build environment for building Vitastor packages for Debian inside a container
|
||||||
|
# cd ..
|
||||||
|
# docker build --build-arg DISTRO=debian --build-arg REL=bullseye -f debian/vitastor.Dockerfile -t vitastor-buildenv:bullseye .
|
||||||
|
# docker run --rm -e REL=bullseye -v ./:/root/vitastor /root/vitastor/debian/vitastor-build.sh
|
||||||
|
|
||||||
|
ARG DISTRO=debian
|
||||||
|
ARG REL=
|
||||||
|
FROM $DISTRO:$REL
|
||||||
|
ARG DISTRO=debian
|
||||||
|
ARG REL=
|
||||||
|
|
||||||
|
WORKDIR /root
|
||||||
|
|
||||||
|
RUN set -e -x; \
|
||||||
|
perl -i -pe 's/deb.debian.org/archive.debian.org/' /etc/apt/sources.list; \
|
||||||
|
apt-get update; \
|
||||||
|
apt-get -y install wget; \
|
||||||
|
wget https://vitastor.io/debian/pubkey.gpg -O /etc/apt/trusted.gpg.d/vitastor.gpg; \
|
||||||
|
echo "deb https://vitastor.io/debian $REL main" >> /etc/apt/sources.list; \
|
||||||
|
grep '^deb ' /etc/apt/sources.list | perl -pe 's/^deb/deb-src/' >> /etc/apt/sources.list; \
|
||||||
|
perl -i -pe 's/Types: deb$/Types: deb deb-src/' /etc/apt/sources.list.d/*.sources || true; \
|
||||||
|
echo 'APT::Install-Recommends false;' >> /etc/apt/apt.conf; \
|
||||||
|
echo 'APT::Install-Suggests false;' >> /etc/apt/apt.conf
|
||||||
|
|
||||||
|
RUN apt-get update && \
|
||||||
|
apt-get -y install fio libgoogle-perftools-dev devscripts libjerasure-dev cmake libc-ares-dev libisal-crypto-dev \
|
||||||
|
libibverbs-dev librdmacm-dev libisal-dev libnl-3-dev libnl-genl-3-dev curl nodejs npm node-nan node-bindings && \
|
||||||
|
apt-get -y build-dep fio && \
|
||||||
|
apt-get --download-only source fio
|
||||||
Vendored
+1
@@ -2,6 +2,7 @@ usr/bin/vita
|
|||||||
usr/bin/vitastor-cli
|
usr/bin/vitastor-cli
|
||||||
usr/bin/vitastor-rm
|
usr/bin/vitastor-rm
|
||||||
usr/bin/vitastor-nbd
|
usr/bin/vitastor-nbd
|
||||||
|
usr/bin/vitastor-ublk
|
||||||
usr/bin/vitastor-nfs
|
usr/bin/vitastor-nfs
|
||||||
usr/bin/vitastor-kv
|
usr/bin/vitastor-kv
|
||||||
usr/bin/vitastor-kv-stress
|
usr/bin/vitastor-kv-stress
|
||||||
|
|||||||
Vendored
-65
@@ -1,65 +0,0 @@
|
|||||||
# Build Vitastor packages for Debian inside a container
|
|
||||||
# cd ..; podman build --build-arg DISTRO=debian --build-arg REL=bullseye -v `pwd`/packages:/root/packages -f debian/vitastor.Dockerfile .
|
|
||||||
|
|
||||||
ARG DISTRO=debian
|
|
||||||
ARG REL=
|
|
||||||
FROM $DISTRO:$REL
|
|
||||||
ARG DISTRO=debian
|
|
||||||
ARG REL=
|
|
||||||
|
|
||||||
WORKDIR /root
|
|
||||||
|
|
||||||
RUN set -e -x; \
|
|
||||||
if [ "$REL" = "buster" ]; then \
|
|
||||||
apt-get update; \
|
|
||||||
apt-get -y install wget; \
|
|
||||||
wget https://vitastor.io/debian/pubkey.gpg -O /etc/apt/trusted.gpg.d/vitastor.gpg; \
|
|
||||||
echo "deb https://vitastor.io/debian $REL main" >> /etc/apt/sources.list; \
|
|
||||||
fi; \
|
|
||||||
grep '^deb ' /etc/apt/sources.list | perl -pe 's/^deb/deb-src/' >> /etc/apt/sources.list; \
|
|
||||||
perl -i -pe 's/Types: deb$/Types: deb deb-src/' /etc/apt/sources.list.d/debian.sources || true; \
|
|
||||||
echo 'APT::Install-Recommends false;' >> /etc/apt/apt.conf; \
|
|
||||||
echo 'APT::Install-Suggests false;' >> /etc/apt/apt.conf
|
|
||||||
|
|
||||||
RUN apt-get update && \
|
|
||||||
apt-get -y install fio liburing-dev libgoogle-perftools-dev devscripts libjerasure-dev cmake \
|
|
||||||
libibverbs-dev librdmacm-dev libisal-dev libnl-3-dev libnl-genl-3-dev curl nodejs npm node-nan node-bindings && \
|
|
||||||
apt-get -y build-dep fio && \
|
|
||||||
apt-get --download-only source fio
|
|
||||||
|
|
||||||
ADD . /root/vitastor
|
|
||||||
RUN set -e -x; \
|
|
||||||
[ -e /usr/lib/x86_64-linux-gnu/pkgconfig/libisal.pc ] || cp /root/vitastor/debian/libisal.pc /usr/lib/x86_64-linux-gnu/pkgconfig; \
|
|
||||||
mkdir -p /root/fio-build/; \
|
|
||||||
cd /root/fio-build/; \
|
|
||||||
rm -rf /root/fio-build/*; \
|
|
||||||
dpkg-source -x /root/fio*.dsc; \
|
|
||||||
mkdir -p /root/packages/vitastor-$REL; \
|
|
||||||
rm -rf /root/packages/vitastor-$REL/*; \
|
|
||||||
cd /root/packages/vitastor-$REL; \
|
|
||||||
FULLVER=$(head -n1 /root/vitastor/debian/changelog | perl -pe 's/^.*\((.*?)\).*$/$1/'); \
|
|
||||||
VER=${FULLVER%%-*}; \
|
|
||||||
cp -r /root/vitastor vitastor-$VER; \
|
|
||||||
cd vitastor-$VER; \
|
|
||||||
ln -s /root/fio-build/fio-*/ ./fio; \
|
|
||||||
FIO=$(head -n1 fio/debian/changelog | perl -pe 's/^.*\((.*?)\).*$/$1/'); \
|
|
||||||
ls /usr/include/linux/raw.h || cp ./debian/raw.h /usr/include/linux/raw.h; \
|
|
||||||
sh copy-fio-includes.sh; \
|
|
||||||
rm fio; \
|
|
||||||
mkdir -p a b debian/patches; \
|
|
||||||
mv fio-copy b/fio; \
|
|
||||||
diff -NaurpbB a b > debian/patches/fio-headers.patch || true; \
|
|
||||||
echo fio-headers.patch >> debian/patches/series; \
|
|
||||||
rm -rf a b; \
|
|
||||||
echo "dep:fio=$FIO" > debian/fio_version; \
|
|
||||||
cd /root/packages/vitastor-$REL/vitastor-$VER; \
|
|
||||||
mkdir mon/node_modules; \
|
|
||||||
cd mon/node_modules; \
|
|
||||||
curl -s https://git.yourcmc.ru/vitalif/antietcd/archive/master.tar.gz | tar -zx; \
|
|
||||||
curl -s https://git.yourcmc.ru/vitalif/tinyraft/archive/master.tar.gz | tar -zx; \
|
|
||||||
cd /root/packages/vitastor-$REL; \
|
|
||||||
tar --sort=name --mtime='2020-01-01' --owner=0 --group=0 --exclude=debian -cJf vitastor_$VER.orig.tar.xz vitastor-$VER; \
|
|
||||||
cd vitastor-$VER; \
|
|
||||||
DEBFULLNAME="Vitaliy Filippov <vitalif@yourcmc.ru>" dch -D $REL -v "$FULLVER""$REL" "Rebuild for $REL"; \
|
|
||||||
DEB_BUILD_OPTIONS=nocheck dpkg-buildpackage --jobs=auto -sa; \
|
|
||||||
rm -rf /root/packages/vitastor-$REL/vitastor-*/
|
|
||||||
+2
-2
@@ -1,9 +1,9 @@
|
|||||||
# Build Docker image with Vitastor packages
|
# Build Docker image with Vitastor packages
|
||||||
|
|
||||||
FROM debian:bookworm
|
FROM debian:trixie
|
||||||
|
|
||||||
ADD etc/apt /etc/apt/
|
ADD etc/apt /etc/apt/
|
||||||
RUN apt-get update && apt-get -y install vitastor udev systemd qemu-system-x86 qemu-system-common qemu-block-extra qemu-utils jq nfs-common && apt-get clean
|
RUN apt-get update && apt-get -y install vitastor ibverbs-providers udev systemd qemu-system-x86 qemu-system-common qemu-block-extra qemu-utils jq nfs-common && apt-get clean
|
||||||
ADD sleep.sh /usr/bin/
|
ADD sleep.sh /usr/bin/
|
||||||
ADD install.sh /usr/bin/
|
ADD install.sh /usr/bin/
|
||||||
ADD scripts /opt/scripts/
|
ADD scripts /opt/scripts/
|
||||||
|
|||||||
+1
-1
@@ -1,4 +1,4 @@
|
|||||||
VITASTOR_VERSION ?= v2.2.2
|
VITASTOR_VERSION ?= v3.0.15
|
||||||
|
|
||||||
all: build push
|
all: build push
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,3 @@
|
|||||||
|
Package: *
|
||||||
|
Pin: release n=trixie-backports
|
||||||
|
Pin-Priority: 500
|
||||||
@@ -1,2 +1,2 @@
|
|||||||
deb http://vitastor.io/debian bookworm main
|
deb http://vitastor.io/debian trixie main
|
||||||
deb http://http.debian.net/debian/ bookworm-backports main
|
#deb http://http.debian.net/debian/ trixie-backports main
|
||||||
|
|||||||
@@ -12,12 +12,7 @@ EnvironmentFile=/etc/vitastor/etcd.conf
|
|||||||
SyslogIdentifier=etcd
|
SyslogIdentifier=etcd
|
||||||
ExecStart=bash -c 'docker run --rm -i -v /var/lib/vitastor/etcd:/data \
|
ExecStart=bash -c 'docker run --rm -i -v /var/lib/vitastor/etcd:/data \
|
||||||
--log-driver none --network host $CONTAINER_OPTIONS --name vitastor-etcd \
|
--log-driver none --network host $CONTAINER_OPTIONS --name vitastor-etcd \
|
||||||
$ETCD_IMAGE /usr/local/bin/etcd --name "$ETCD_NAME" --data-dir /data \
|
$ETCD_IMAGE /usr/local/bin/etcd --data-dir /data
|
||||||
--snapshot-count 10000 --advertise-client-urls http://$ETCD_IP:2379 --listen-client-urls http://$ETCD_IP:2379 \
|
|
||||||
--initial-advertise-peer-urls http://$ETCD_IP:2380 --listen-peer-urls http://$ETCD_IP:2380 \
|
|
||||||
--initial-cluster-token vitastor-etcd-1 --initial-cluster "$ETCD_INITIAL_CLUSTER" \
|
|
||||||
--initial-cluster-state new --max-txn-ops=100000 --max-request-bytes=104857600 \
|
|
||||||
--auto-compaction-retention=10 --auto-compaction-mode=revision'
|
|
||||||
ExecStop=docker stop vitastor-etcd
|
ExecStop=docker stop vitastor-etcd
|
||||||
Restart=always
|
Restart=always
|
||||||
StartLimitInterval=0
|
StartLimitInterval=0
|
||||||
|
|||||||
@@ -7,7 +7,7 @@ PartOf=vitastor.target
|
|||||||
[Service]
|
[Service]
|
||||||
Restart=always
|
Restart=always
|
||||||
EnvironmentFile=/etc/vitastor/docker.conf
|
EnvironmentFile=/etc/vitastor/docker.conf
|
||||||
ExecStart=bash -c 'docker run --rm -i -v /etc/vitastor:/etc/vitastor -v /dev:/dev -v /run:/run \
|
ExecStart=bash -c 'docker run --rm -i -v /etc/vitastor:/etc/vitastor -v /dev:/dev -v /run:/run -e SYSTEMD_IN_CHROOT=0 \
|
||||||
--security-opt seccomp=unconfined --privileged --pid=host --log-driver none --network host --name vitastor vitastor:$VITASTOR_VERSION \
|
--security-opt seccomp=unconfined --privileged --pid=host --log-driver none --network host --name vitastor vitastor:$VITASTOR_VERSION \
|
||||||
sleep.sh'
|
sleep.sh'
|
||||||
ExecStartPost=udevadm trigger
|
ExecStartPost=udevadm trigger
|
||||||
|
|||||||
@@ -4,7 +4,7 @@
|
|||||||
#
|
#
|
||||||
|
|
||||||
# Desired Vitastor version
|
# Desired Vitastor version
|
||||||
VITASTOR_VERSION=v2.2.2
|
VITASTOR_VERSION=v3.0.15
|
||||||
|
|
||||||
# Additional arguments for all containers
|
# Additional arguments for all containers
|
||||||
# For example, you may want to specify a custom logging driver here
|
# For example, you may want to specify a custom logging driver here
|
||||||
|
|||||||
@@ -1,4 +1 @@
|
|||||||
ETCD_IMAGE=quay.io/coreos/etcd:v3.5.18
|
ETCD_IMAGE=quay.io/coreos/etcd:v3.5.18
|
||||||
ETCD_NAME=""
|
|
||||||
ETCD_IP=""
|
|
||||||
ETCD_INITIAL_CLUSTER=""
|
|
||||||
|
|||||||
+2
-3
@@ -2,8 +2,7 @@
|
|||||||
|
|
||||||
set -e
|
set -e
|
||||||
|
|
||||||
cp -urv /etc/default /host-etc/
|
cp -urv /etc/systemd/system/vitastor* /host-etc/systemd/system/
|
||||||
cp -urv /etc/systemd /host-etc/
|
cp -urv /etc/udev/rules.d /host-etc/udev/
|
||||||
cp -urv /etc/udev /host-etc/
|
|
||||||
cp -urnv /etc/vitastor /host-etc/
|
cp -urnv /etc/vitastor /host-etc/
|
||||||
cp -urnv /opt/scripts/* /host-bin/
|
cp -urnv /opt/scripts/* /host-bin/
|
||||||
|
|||||||
@@ -38,3 +38,4 @@ In the future, additional configuration methods may be added:
|
|||||||
- [OSD Disk Layout](config/layout-osd.en.md)
|
- [OSD Disk Layout](config/layout-osd.en.md)
|
||||||
- [OSD Runtime Parameters](config/osd.en.md)
|
- [OSD Runtime Parameters](config/osd.en.md)
|
||||||
- [Monitor](config/monitor.en.md)
|
- [Monitor](config/monitor.en.md)
|
||||||
|
- [Security Parameters](config/security.en.md)
|
||||||
|
|||||||
@@ -41,3 +41,4 @@
|
|||||||
- [Дисковые параметры OSD](config/layout-osd.ru.md)
|
- [Дисковые параметры OSD](config/layout-osd.ru.md)
|
||||||
- [Прочие параметры OSD](config/osd.ru.md)
|
- [Прочие параметры OSD](config/osd.ru.md)
|
||||||
- [Параметры мониторов](config/monitor.ru.md)
|
- [Параметры мониторов](config/monitor.ru.md)
|
||||||
|
- [Параметры безопасности](config/security.ru.md)
|
||||||
|
|||||||
@@ -25,6 +25,9 @@ affect their interaction with the cluster.
|
|||||||
- [nbd_max_part](#nbd_max_part)
|
- [nbd_max_part](#nbd_max_part)
|
||||||
- [osd_nearfull_ratio](#osd_nearfull_ratio)
|
- [osd_nearfull_ratio](#osd_nearfull_ratio)
|
||||||
- [hostname](#hostname)
|
- [hostname](#hostname)
|
||||||
|
- [ublk_queue_depth](#ublk_queue_depth)
|
||||||
|
- [ublk_max_io_size](#ublk_max_io_size)
|
||||||
|
- [qemu_file_mirror_path](#qemu_file_mirror_path)
|
||||||
|
|
||||||
## client_iothread_count
|
## client_iothread_count
|
||||||
|
|
||||||
@@ -225,3 +228,28 @@ without destroying and recreating OSDs.
|
|||||||
Clients use host name to find their distance to OSDs when [localized reads](pool.en.md#local_reads)
|
Clients use host name to find their distance to OSDs when [localized reads](pool.en.md#local_reads)
|
||||||
are enabled. By default, standard [gethostname](https://man7.org/linux/man-pages/man2/gethostname.2.html)
|
are enabled. By default, standard [gethostname](https://man7.org/linux/man-pages/man2/gethostname.2.html)
|
||||||
function is used to determine host name, but you can also override it with this parameter.
|
function is used to determine host name, but you can also override it with this parameter.
|
||||||
|
|
||||||
|
## ublk_queue_depth
|
||||||
|
|
||||||
|
- Type: integer
|
||||||
|
- Default: 256
|
||||||
|
|
||||||
|
Default queue depth for [Vitastor ublk servers](../usage/ublk.en.md).
|
||||||
|
|
||||||
|
## ublk_max_io_size
|
||||||
|
|
||||||
|
- Type: integer
|
||||||
|
|
||||||
|
Default maximum I/O size for Vitastor [ublk servers](../usage/ublk.en.md).
|
||||||
|
The largest of 1 MB and pool block size multiplied by EC data chunk count is used if not specified.
|
||||||
|
|
||||||
|
## qemu_file_mirror_path
|
||||||
|
|
||||||
|
- Type: string
|
||||||
|
|
||||||
|
When set to an FS directory path (for example, `/mnt/vitastor/`), `qemu-img info` and similar
|
||||||
|
QAPI commands return the name of the image inside this directory instead of normal
|
||||||
|
`vitastor://?image=abc` URI as `filename`.
|
||||||
|
|
||||||
|
This allows to then mount this path using [vitastor-nfs](../usage/nfs.en.md) and trick
|
||||||
|
third-party systems like Veeam which rely on `filename` in the image info but don't support Vitastor.
|
||||||
|
|||||||
@@ -25,6 +25,9 @@
|
|||||||
- [nbd_max_part](#nbd_max_part)
|
- [nbd_max_part](#nbd_max_part)
|
||||||
- [osd_nearfull_ratio](#osd_nearfull_ratio)
|
- [osd_nearfull_ratio](#osd_nearfull_ratio)
|
||||||
- [hostname](#hostname)
|
- [hostname](#hostname)
|
||||||
|
- [ublk_queue_depth](#ublk_queue_depth)
|
||||||
|
- [ublk_max_io_size](#ublk_max_io_size)
|
||||||
|
- [qemu_file_mirror_path](#qemu_file_mirror_path)
|
||||||
|
|
||||||
## client_iothread_count
|
## client_iothread_count
|
||||||
|
|
||||||
@@ -230,3 +233,30 @@ RDMA и хотите повысить пиковую производитель
|
|||||||
[локальные чтения](pool.ru.md#local_reads). По умолчанию для определения имени
|
[локальные чтения](pool.ru.md#local_reads). По умолчанию для определения имени
|
||||||
хоста используется стандартная функция [gethostname](https://man7.org/linux/man-pages/man2/gethostname.2.html),
|
хоста используется стандартная функция [gethostname](https://man7.org/linux/man-pages/man2/gethostname.2.html),
|
||||||
но вы также можете задать имя хоста вручную данным параметром.
|
но вы также можете задать имя хоста вручную данным параметром.
|
||||||
|
|
||||||
|
## ublk_queue_depth
|
||||||
|
|
||||||
|
- Тип: целое число
|
||||||
|
- Значение по умолчанию: 256
|
||||||
|
|
||||||
|
Глубина очереди по умолчанию для [ublk-серверов Vitastor](../usage/ublk.ru.md).
|
||||||
|
|
||||||
|
## ublk_max_io_size
|
||||||
|
|
||||||
|
- Тип: целое число
|
||||||
|
|
||||||
|
Максимальный размер запроса ввода-вывода для [ublk-серверов Vitastor](../usage/ublk.ru.md).
|
||||||
|
Если не задан, используется максимум из 1 МБ и размера блока пула, умноженного на число частей
|
||||||
|
данных EC-пула.
|
||||||
|
|
||||||
|
## qemu_file_mirror_path
|
||||||
|
|
||||||
|
- Тип: строка
|
||||||
|
|
||||||
|
Если установить эту опцию равной пути к каталогу в ФС, команда `qemu-img info` и подобные
|
||||||
|
команды QAPI будут возвращать в поле `filename` имя образа внутри заданного каталога вместо
|
||||||
|
обычного адреса типа `vitastor://?image=abc`.
|
||||||
|
|
||||||
|
Это позволяет смонтировать этот путь с помощью [vitastor-nfs](../usage/nfs.ru.md) и обмануть
|
||||||
|
сторонние системы типа Veeam, которые полагаются на поле `filename` в информации об образе QEMU,
|
||||||
|
но не поддерживают Vitastor.
|
||||||
|
|||||||
@@ -9,6 +9,7 @@
|
|||||||
These parameters apply to OSDs, are fixed at the moment of OSD drive
|
These parameters apply to OSDs, are fixed at the moment of OSD drive
|
||||||
initialization and can't be changed after it without losing data.
|
initialization and can't be changed after it without losing data.
|
||||||
|
|
||||||
|
- [meta_format](#meta_format)
|
||||||
- [data_device](#data_device)
|
- [data_device](#data_device)
|
||||||
- [meta_device](#meta_device)
|
- [meta_device](#meta_device)
|
||||||
- [journal_device](#journal_device)
|
- [journal_device](#journal_device)
|
||||||
@@ -27,6 +28,21 @@ initialization and can't be changed after it without losing data.
|
|||||||
- [data_csum_type](#data_csum_type)
|
- [data_csum_type](#data_csum_type)
|
||||||
- [csum_block_size](#csum_block_size)
|
- [csum_block_size](#csum_block_size)
|
||||||
|
|
||||||
|
## meta_format
|
||||||
|
|
||||||
|
- Type: integer
|
||||||
|
- Default: 3
|
||||||
|
|
||||||
|
OSD store implementation version and on-disk metadata format.
|
||||||
|
|
||||||
|
Three versions are currently supported: 3, 2 and 1.
|
||||||
|
- 3 the new log-structured store, it's overall faster, has lower Write
|
||||||
|
Amplification, which may be even close to 1 (i.e. almost no extra writes)
|
||||||
|
if your SSDs support atomic writes (see [atomic_write_size](osd.en.md#atomic_write_size)).
|
||||||
|
- 2 is the old stable store from Vitastor 0.9-2.x.
|
||||||
|
- 1 is the same old store but with a legacy metadata format from Vitastor
|
||||||
|
versions to up 0.8.x, without any support for checksums.
|
||||||
|
|
||||||
## data_device
|
## data_device
|
||||||
|
|
||||||
- Type: string
|
- Type: string
|
||||||
@@ -182,8 +198,14 @@ put a modified value into etcd key /vitastor/config/global.
|
|||||||
- Type: string
|
- Type: string
|
||||||
- Default: none
|
- Default: none
|
||||||
|
|
||||||
Data checksum type to use. May be "crc32c" or "none". Set to "crc32c" to
|
Data and metadata checksum type to use. May be "crc32c", "xxh3_32" or "none".
|
||||||
enable data checksums.
|
Select crc32c or xxh3_32 and set csum_block_size to enable data checksums.
|
||||||
|
|
||||||
|
Both crc32c and xxh3_32 are almost equally fast, xxh3_32 is safer. xxh3_32 is
|
||||||
|
the xxhash3 algorithm truncated from 64 to 32 bits (which is still a good hash).
|
||||||
|
|
||||||
|
Note that enabled data checksums either increase memory usage or reduce
|
||||||
|
performance. Check details in [csum_block_size](#csum_block_size) description.
|
||||||
|
|
||||||
## csum_block_size
|
## csum_block_size
|
||||||
|
|
||||||
|
|||||||
@@ -10,6 +10,7 @@
|
|||||||
дисковые параметры, задаются в момент инициализации дисков OSD и не могут быть
|
дисковые параметры, задаются в момент инициализации дисков OSD и не могут быть
|
||||||
изменены после этого без потери данных.
|
изменены после этого без потери данных.
|
||||||
|
|
||||||
|
- [meta_format](#meta_format)
|
||||||
- [data_device](#data_device)
|
- [data_device](#data_device)
|
||||||
- [meta_device](#meta_device)
|
- [meta_device](#meta_device)
|
||||||
- [journal_device](#journal_device)
|
- [journal_device](#journal_device)
|
||||||
@@ -28,6 +29,23 @@
|
|||||||
- [data_csum_type](#data_csum_type)
|
- [data_csum_type](#data_csum_type)
|
||||||
- [csum_block_size](#csum_block_size)
|
- [csum_block_size](#csum_block_size)
|
||||||
|
|
||||||
|
## meta_format
|
||||||
|
|
||||||
|
- Тип: целое число
|
||||||
|
- Значение по умолчанию: 3
|
||||||
|
|
||||||
|
Версия реализации дискового хранилища OSD и дискового формата метаданных.
|
||||||
|
|
||||||
|
Поддерживаются три версии: 3, 2 и 1.
|
||||||
|
- 3 - новое лог-структурированное хранилище, в целом более быстрое, со
|
||||||
|
сниженным фактором амплификации записи, который может составлять около 1
|
||||||
|
(то есть, практически без лишней служебной записи), если ваши SSD
|
||||||
|
поддерживают атомарную запись (см. [atomic_write_size](osd.ru.md#atomic_write_size)).
|
||||||
|
- 2 - старое стабильное хранилище из версий Vitastor 0.9-2.x.
|
||||||
|
- 1 - то же самое стабильное хранилище, но с ещё более старым форматом
|
||||||
|
метаданных из версий Vitastor до 0.8.x, без какой-либо поддержки
|
||||||
|
контрольных сумм.
|
||||||
|
|
||||||
## data_device
|
## data_device
|
||||||
|
|
||||||
- Тип: строка
|
- Тип: строка
|
||||||
@@ -191,8 +209,12 @@ journal_block_size и meta_block_size. Однако на данный момен
|
|||||||
- Тип: строка
|
- Тип: строка
|
||||||
- Значение по умолчанию: none
|
- Значение по умолчанию: none
|
||||||
|
|
||||||
Тип используемых OSD контрольных сумм данных. Может быть "crc32c" или "none".
|
Тип используемых OSD контрольных сумм данных и метаданных. Может быть "crc32c",
|
||||||
Установите в "crc32c", чтобы включить расчёт и проверку контрольных сумм данных.
|
"xxh3_32" или "none". Выберите crc32c или xxh3_32 и установите csum_block_size,
|
||||||
|
чтобы включить контрольные суммы данных.
|
||||||
|
|
||||||
|
И crc32c, и xxh3_32 примерно одинаково быстры, xxh3_32 надёжней. xxh3_32 - это
|
||||||
|
алгоритм xxhash3, обрезанный с 64 до 32 бит (это всё равно хороший хеш).
|
||||||
|
|
||||||
Следует понимать, что контрольные суммы в зависимости от размера блока их
|
Следует понимать, что контрольные суммы в зависимости от размера блока их
|
||||||
расчёта либо увеличивают потребление памяти, либо снижают производительность.
|
расчёта либо увеличивают потребление памяти, либо снижают производительность.
|
||||||
|
|||||||
@@ -50,6 +50,9 @@ or antietcd_data_dir options). All other antietcd parameters
|
|||||||
cluster, cluster_key, persist_filter, stale_read can also be set in
|
cluster, cluster_key, persist_filter, stale_read can also be set in
|
||||||
Vitastor configuration with `antietcd_` prefix.
|
Vitastor configuration with `antietcd_` prefix.
|
||||||
|
|
||||||
|
See also: [antietcd_cert](security.en.md#antietcd_cert),
|
||||||
|
[antietcd_key](security.en.md#antietcd_key) and [etcd_proxy](security.en.md#etcd_proxyurls).
|
||||||
|
|
||||||
You can dump/load data to or from antietcd using Antietcd `anticli` tool:
|
You can dump/load data to or from antietcd using Antietcd `anticli` tool:
|
||||||
|
|
||||||
```
|
```
|
||||||
|
|||||||
@@ -50,6 +50,9 @@ antietcd_data_file или antietcd_data_dir). Все остальные пара
|
|||||||
node_id, cluster, cluster_key, persist_filter, stale_read также можно задавать
|
node_id, cluster, cluster_key, persist_filter, stale_read также можно задавать
|
||||||
в конфигурации Vitastor с префиксом `antietcd_`.
|
в конфигурации Vitastor с префиксом `antietcd_`.
|
||||||
|
|
||||||
|
Смотрите также настройки [antietcd_cert](security.ru.md#antietcd_cert),
|
||||||
|
[antietcd_key](security.ru.md#antietcd_key) и [etcd_proxy](security.ru.md#etcd_proxyurls).
|
||||||
|
|
||||||
Вы можете выгружать/загружать данные в или из antietcd с помощью его инструмента
|
Вы можете выгружать/загружать данные в или из antietcd с помощью его инструмента
|
||||||
`anticli`:
|
`anticli`:
|
||||||
|
|
||||||
|
|||||||
+18
-29
@@ -22,7 +22,6 @@ between clients, OSDs and etcd.
|
|||||||
- [rdma_max_msg](#rdma_max_msg)
|
- [rdma_max_msg](#rdma_max_msg)
|
||||||
- [rdma_max_recv](#rdma_max_recv)
|
- [rdma_max_recv](#rdma_max_recv)
|
||||||
- [rdma_max_send](#rdma_max_send)
|
- [rdma_max_send](#rdma_max_send)
|
||||||
- [rdma_odp](#rdma_odp)
|
|
||||||
- [peer_connect_interval](#peer_connect_interval)
|
- [peer_connect_interval](#peer_connect_interval)
|
||||||
- [peer_connect_timeout](#peer_connect_timeout)
|
- [peer_connect_timeout](#peer_connect_timeout)
|
||||||
- [osd_idle_timeout](#osd_idle_timeout)
|
- [osd_idle_timeout](#osd_idle_timeout)
|
||||||
@@ -74,7 +73,7 @@ Consider `use_rdmacm` for such networks.
|
|||||||
## use_rdmacm
|
## use_rdmacm
|
||||||
|
|
||||||
- Type: boolean
|
- Type: boolean
|
||||||
- Default: true
|
- Default: false
|
||||||
|
|
||||||
Use an alternative implementation of RDMA through RDMA-CM (Connection
|
Use an alternative implementation of RDMA through RDMA-CM (Connection
|
||||||
Manager). Works with all RDMA networks: Infiniband, iWARP and
|
Manager). Works with all RDMA networks: Infiniband, iWARP and
|
||||||
@@ -102,11 +101,6 @@ found or if `osd_network` is not specified. Auto-selection is also
|
|||||||
unsupported with old libibverbs < v32, like in Debian 10 Buster or
|
unsupported with old libibverbs < v32, like in Debian 10 Buster or
|
||||||
CentOS 7.
|
CentOS 7.
|
||||||
|
|
||||||
Vitastor supports all adapters, even ones without ODP support, like
|
|
||||||
Mellanox ConnectX-3 and non-Mellanox cards. Versions up to Vitastor
|
|
||||||
1.2.0 required ODP which is only present in Mellanox ConnectX >= 4.
|
|
||||||
See also [rdma_odp](#rdma_odp).
|
|
||||||
|
|
||||||
Run `ibv_devinfo -v` as root to list available RDMA devices and their
|
Run `ibv_devinfo -v` as root to list available RDMA devices and their
|
||||||
features.
|
features.
|
||||||
|
|
||||||
@@ -116,6 +110,23 @@ the manual of your network vendor for details about setting up the switch
|
|||||||
for RoCEv2 correctly. Usually it means setting up Lossless Ethernet with
|
for RoCEv2 correctly. Usually it means setting up Lossless Ethernet with
|
||||||
PFC (Priority Flow Control) and ECN (Explicit Congestion Notification).
|
PFC (Priority Flow Control) and ECN (Explicit Congestion Notification).
|
||||||
|
|
||||||
|
Vitastor supports all adapters, even ones without ODP (On-Demand Paging)
|
||||||
|
support, like Mellanox ConnectX-3 and non-Mellanox cards. ODP is only present
|
||||||
|
in Mellanox ConnectX >= 4 adapters and allows to skip memory registration
|
||||||
|
for RDMA and thus, in theory, avoid memory copying.
|
||||||
|
|
||||||
|
Versions up to Vitastor 1.2.0 required ODP, then it was disabled by default,
|
||||||
|
but it was still supported up to 3.0.3. Now ODP support is removed because it
|
||||||
|
actually only hurts performance: an example 3-node cluster with 8 NVMe in each
|
||||||
|
node and 2*25 GBit/s ConnectX-6 RDMA network pushed 3950000 read iops without
|
||||||
|
ODP, but only 239000 iops with ODP.
|
||||||
|
|
||||||
|
This happens because Mellanox ODP implementation seems to be based on
|
||||||
|
message retransmissions when the adapter doesn't know about the buffer yet -
|
||||||
|
it likely uses standard "RNR retransmissions" (RNR = receiver not ready)
|
||||||
|
which is generally slow in RDMA/RoCE networks. Here's a presentation about
|
||||||
|
it from ISPASS-2021 conference: https://tkygtr6.github.io/pub/ISPASS21_slides.pdf
|
||||||
|
|
||||||
## rdma_port_num
|
## rdma_port_num
|
||||||
|
|
||||||
- Type: integer
|
- Type: integer
|
||||||
@@ -187,28 +198,6 @@ less than `rdma_max_recv` so the receiving side doesn't run out of buffers.
|
|||||||
Doesn't affect memory usage - additional memory isn't allocated for send
|
Doesn't affect memory usage - additional memory isn't allocated for send
|
||||||
operations.
|
operations.
|
||||||
|
|
||||||
## rdma_odp
|
|
||||||
|
|
||||||
- Type: boolean
|
|
||||||
- Default: false
|
|
||||||
|
|
||||||
Use RDMA with On-Demand Paging. ODP is currently only available on Mellanox
|
|
||||||
ConnectX-4 and newer adapters. ODP allows to not register memory explicitly
|
|
||||||
for RDMA adapter to be able to use it. This, in turn, allows to skip memory
|
|
||||||
copying during sending. One would think this should improve performance, but
|
|
||||||
**in reality** RDMA performance with ODP is **drastically** worse. Example
|
|
||||||
3-node cluster with 8 NVMe in each node and 2*25 GBit/s ConnectX-6 RDMA network
|
|
||||||
without ODP pushes 3950000 read iops, but only 239000 iops with ODP...
|
|
||||||
|
|
||||||
This happens because Mellanox ODP implementation seems to be based on
|
|
||||||
message retransmissions when the adapter doesn't know about the buffer yet -
|
|
||||||
it likely uses standard "RNR retransmissions" (RNR = receiver not ready)
|
|
||||||
which is generally slow in RDMA/RoCE networks. Here's a presentation about
|
|
||||||
it from ISPASS-2021 conference: https://tkygtr6.github.io/pub/ISPASS21_slides.pdf
|
|
||||||
|
|
||||||
ODP support is retained in the code just in case a good ODP implementation
|
|
||||||
appears one day.
|
|
||||||
|
|
||||||
## peer_connect_interval
|
## peer_connect_interval
|
||||||
|
|
||||||
- Type: seconds
|
- Type: seconds
|
||||||
|
|||||||
+19
-31
@@ -22,7 +22,6 @@
|
|||||||
- [rdma_max_msg](#rdma_max_msg)
|
- [rdma_max_msg](#rdma_max_msg)
|
||||||
- [rdma_max_recv](#rdma_max_recv)
|
- [rdma_max_recv](#rdma_max_recv)
|
||||||
- [rdma_max_send](#rdma_max_send)
|
- [rdma_max_send](#rdma_max_send)
|
||||||
- [rdma_odp](#rdma_odp)
|
|
||||||
- [peer_connect_interval](#peer_connect_interval)
|
- [peer_connect_interval](#peer_connect_interval)
|
||||||
- [peer_connect_timeout](#peer_connect_timeout)
|
- [peer_connect_timeout](#peer_connect_timeout)
|
||||||
- [osd_idle_timeout](#osd_idle_timeout)
|
- [osd_idle_timeout](#osd_idle_timeout)
|
||||||
@@ -74,7 +73,7 @@ RDMA-устройства, но они не имеют соединения с
|
|||||||
## use_rdmacm
|
## use_rdmacm
|
||||||
|
|
||||||
- Тип: булево (да/нет)
|
- Тип: булево (да/нет)
|
||||||
- Значение по умолчанию: true
|
- Значение по умолчанию: false
|
||||||
|
|
||||||
Использовать альтернативную реализацию RDMA на основе RDMA-CM (Connection
|
Использовать альтернативную реализацию RDMA на основе RDMA-CM (Connection
|
||||||
Manager). Работает со всеми типами RDMA-сетей: Infiniband, iWARP и
|
Manager). Работает со всеми типами RDMA-сетей: Infiniband, iWARP и
|
||||||
@@ -101,12 +100,6 @@ RoCEv1/RoCEv2, и даже позволяет полностью отключи
|
|||||||
не задана. Также автовыбор не поддерживается со старыми версиями библиотеки
|
не задана. Также автовыбор не поддерживается со старыми версиями библиотеки
|
||||||
libibverbs < v32, например в Debian 10 Buster или CentOS 7.
|
libibverbs < v32, например в Debian 10 Buster или CentOS 7.
|
||||||
|
|
||||||
Vitastor поддерживает все модели адаптеров, включая те, у которых
|
|
||||||
нет поддержки ODP, то есть вы можете использовать RDMA с ConnectX-3 и
|
|
||||||
картами производства не Mellanox. Версии Vitastor до 1.2.0 включительно
|
|
||||||
требовали ODP, который есть только на Mellanox ConnectX 4 и более новых.
|
|
||||||
См. также [rdma_odp](#rdma_odp).
|
|
||||||
|
|
||||||
Запустите `ibv_devinfo -v` от имени суперпользователя, чтобы посмотреть
|
Запустите `ibv_devinfo -v` от имени суперпользователя, чтобы посмотреть
|
||||||
список доступных RDMA-устройств, их параметры и возможности.
|
список доступных RDMA-устройств, их параметры и возможности.
|
||||||
|
|
||||||
@@ -117,6 +110,24 @@ Vitastor поддерживает все модели адаптеров, вкл
|
|||||||
подразумевает настройку сети без потерь на основе PFC (Priority Flow
|
подразумевает настройку сети без потерь на основе PFC (Priority Flow
|
||||||
Control) и ECN (Explicit Congestion Notification).
|
Control) и ECN (Explicit Congestion Notification).
|
||||||
|
|
||||||
|
Vitastor поддерживает все модели адаптеров, включая те, у которых нет
|
||||||
|
поддержки ODP (On-Demand Paging), например, ConnectX-3 и карты производства
|
||||||
|
не Mellanox. Функция ODP доступна только на адаптерах Mellanox ConnectX-4 и
|
||||||
|
более новых и позволяет не регистрировать память для её использования RDMA-картой,
|
||||||
|
благодаря чему в теории можно избежать лишних копирований памяти.
|
||||||
|
|
||||||
|
Версии Vitastor до 1.2.0 включительно требовали ODP, потом функция был отключена
|
||||||
|
по умолчанию, но поддерживалась вплоть до версии 3.0.3. Сейчас поддержка ODP
|
||||||
|
полностью удалена, так как на самом деле она только портит производительность:
|
||||||
|
например, на 3-узловом кластере с 8 NVMe в каждом узле и сетью 2*25 Гбит/с на
|
||||||
|
чтение с RDMA без ODP удаётся снять 3950000 iops, а с ODP - всего 239000 iops.
|
||||||
|
|
||||||
|
Это происходит из-за того, что реализация ODP у Mellanox неоптимальная и
|
||||||
|
основана на повторной передаче сообщений, когда карте не известен буфер -
|
||||||
|
вероятно, на стандартных "RNR retransmission" (RNR = receiver not ready).
|
||||||
|
А данные повторные передачи в RDMA/RoCE - всегда очень медленная штука.
|
||||||
|
Презентация на эту тему с конференции ISPASS-2021: https://tkygtr6.github.io/pub/ISPASS21_slides.pdf
|
||||||
|
|
||||||
## rdma_port_num
|
## rdma_port_num
|
||||||
|
|
||||||
- Тип: целое число
|
- Тип: целое число
|
||||||
@@ -192,29 +203,6 @@ OSD в любом случае согласовывают реальное зн
|
|||||||
Не влияет на потребление памяти - дополнительная память на операции отправки
|
Не влияет на потребление памяти - дополнительная память на операции отправки
|
||||||
не выделяется.
|
не выделяется.
|
||||||
|
|
||||||
## rdma_odp
|
|
||||||
|
|
||||||
- Тип: булево (да/нет)
|
|
||||||
- Значение по умолчанию: false
|
|
||||||
|
|
||||||
Использовать RDMA с On-Demand Paging. ODP - функция, доступная пока что
|
|
||||||
исключительно на адаптерах Mellanox ConnectX-4 и более новых. ODP позволяет
|
|
||||||
не регистрировать память для её использования RDMA-картой. Благодаря этому
|
|
||||||
можно не копировать данные при отправке их в сеть и, казалось бы, это должно
|
|
||||||
улучшать производительность - но **по факту** получается так, что
|
|
||||||
производительность только ухудшается, причём сильно. Пример - на 3-узловом
|
|
||||||
кластере с 8 NVMe в каждом узле и сетью 2*25 Гбит/с на чтение с RDMA без ODP
|
|
||||||
удаётся снять 3950000 iops, а с ODP - всего 239000 iops...
|
|
||||||
|
|
||||||
Это происходит из-за того, что реализация ODP у Mellanox неоптимальная и
|
|
||||||
основана на повторной передаче сообщений, когда карте не известен буфер -
|
|
||||||
вероятно, на стандартных "RNR retransmission" (RNR = receiver not ready).
|
|
||||||
А данные повторные передачи в RDMA/RoCE - всегда очень медленная штука.
|
|
||||||
Презентация на эту тему с конференции ISPASS-2021: https://tkygtr6.github.io/pub/ISPASS21_slides.pdf
|
|
||||||
|
|
||||||
Возможность использования ODP сохранена в коде на случай, если вдруг в один
|
|
||||||
прекрасный день появится хорошая реализация ODP.
|
|
||||||
|
|
||||||
## peer_connect_interval
|
## peer_connect_interval
|
||||||
|
|
||||||
- Тип: секунды
|
- Тип: секунды
|
||||||
|
|||||||
+102
-8
@@ -38,6 +38,7 @@ with an OSD restart or, for some of them, even without restarting by updating co
|
|||||||
- [journal_io](#journal_io)
|
- [journal_io](#journal_io)
|
||||||
- [journal_sector_buffer_count](#journal_sector_buffer_count)
|
- [journal_sector_buffer_count](#journal_sector_buffer_count)
|
||||||
- [journal_no_same_sector_overwrites](#journal_no_same_sector_overwrites)
|
- [journal_no_same_sector_overwrites](#journal_no_same_sector_overwrites)
|
||||||
|
- [skip_corrupted_meta_entries](#skip_corrupted_meta_entries)
|
||||||
- [throttle_small_writes](#throttle_small_writes)
|
- [throttle_small_writes](#throttle_small_writes)
|
||||||
- [throttle_target_iops](#throttle_target_iops)
|
- [throttle_target_iops](#throttle_target_iops)
|
||||||
- [throttle_target_mbs](#throttle_target_mbs)
|
- [throttle_target_mbs](#throttle_target_mbs)
|
||||||
@@ -65,6 +66,11 @@ with an OSD restart or, for some of them, even without restarting by updating co
|
|||||||
- [allow_net_split](#allow_net_split)
|
- [allow_net_split](#allow_net_split)
|
||||||
- [enable_pg_locks](#enable_pg_locks)
|
- [enable_pg_locks](#enable_pg_locks)
|
||||||
- [pg_lock_retry_interval_ms](#pg_lock_retry_interval_ms)
|
- [pg_lock_retry_interval_ms](#pg_lock_retry_interval_ms)
|
||||||
|
- [atomic_write_size](#atomic_write_size)
|
||||||
|
- [use_atomic_flag](#use_atomic_flag)
|
||||||
|
- [pg_reshard_chunk_size](#pg_reshard_chunk_size)
|
||||||
|
- [pg_reshard_chunk_pause_ms](#pg_reshard_chunk_pause_ms)
|
||||||
|
- [gc_on_start](#gc_on_start)
|
||||||
|
|
||||||
## bind_address
|
## bind_address
|
||||||
|
|
||||||
@@ -275,13 +281,19 @@ Maximum number of journal flushers (see above min_flusher_count).
|
|||||||
- Type: boolean
|
- Type: boolean
|
||||||
- Default: true
|
- Default: true
|
||||||
|
|
||||||
This parameter makes Vitastor always keep metadata area of the block device
|
Only for the old store ([meta_format](layout-osd.en.md#meta_format) 2).
|
||||||
in memory. It's required for good performance because it allows to avoid
|
|
||||||
additional read-modify-write cycles during metadata modifications. Metadata
|
This parameter makes Vitastor keep a copy of metadata area in memory as it is
|
||||||
area size is currently roughly 224 MB per 1 TB of data. You can turn it off
|
on disk, in addition to the metadata database. When the option is enabled, every
|
||||||
to reduce memory usage by this value, but it will hurt performance. This
|
metadata entry is effectively stored in RAM twice. It's required for good performance
|
||||||
restriction is likely to be removed in the future along with the upgrade
|
because it allows to avoid additional read-modify-write cycles during metadata
|
||||||
of the metadata storage scheme.
|
modifications. Metadata area size with the old store is roughly 224 MB per 1 TB
|
||||||
|
of data. You can turn the option off to reduce memory usage by this value, but
|
||||||
|
it will reduce performance.
|
||||||
|
|
||||||
|
For the new store ([meta_format](layout-osd.en.md#meta_format) 3), the option
|
||||||
|
may be changed in the future to support operation without loading full metadata
|
||||||
|
database in memory.
|
||||||
|
|
||||||
## inmemory_journal
|
## inmemory_journal
|
||||||
|
|
||||||
@@ -360,6 +372,8 @@ blocks. The only situation when you should increase it to a larger value
|
|||||||
is when you enable journal_no_same_sector_overwrites. In this case set
|
is when you enable journal_no_same_sector_overwrites. In this case set
|
||||||
it to, for example, 1024.
|
it to, for example, 1024.
|
||||||
|
|
||||||
|
Not applicable to the new store ([meta_format](layout-osd.en.md#meta_format) 3).
|
||||||
|
|
||||||
## journal_no_same_sector_overwrites
|
## journal_no_same_sector_overwrites
|
||||||
|
|
||||||
- Type: boolean
|
- Type: boolean
|
||||||
@@ -373,6 +387,17 @@ journal after writing it instead of possibly overwriting it the second time.
|
|||||||
|
|
||||||
Most (99%) other SSDs don't need this option.
|
Most (99%) other SSDs don't need this option.
|
||||||
|
|
||||||
|
Not applicable to the new store ([meta_format](layout-osd.en.md#meta_format) 3).
|
||||||
|
|
||||||
|
## skip_corrupted_meta_entries
|
||||||
|
|
||||||
|
- Type: boolean
|
||||||
|
- Default: false
|
||||||
|
|
||||||
|
Only for the new store ([meta_format](layout-osd.en.md#meta_format) 3).
|
||||||
|
Allow OSD to start when some metadata entries or blocks are corrupted by
|
||||||
|
skipping them. Should be only used as an emergency measure.
|
||||||
|
|
||||||
## throttle_small_writes
|
## throttle_small_writes
|
||||||
|
|
||||||
- Type: boolean
|
- Type: boolean
|
||||||
@@ -491,7 +516,7 @@ Can be used to slow down scrubbing if it affects user load too much.
|
|||||||
## scrub_list_limit
|
## scrub_list_limit
|
||||||
|
|
||||||
- Type: integer
|
- Type: integer
|
||||||
- Default: 1000
|
- Default: 262144
|
||||||
- Can be changed online: yes
|
- Can be changed online: yes
|
||||||
|
|
||||||
Number of objects to list in one listing operation during scrub.
|
Number of objects to list in one listing operation during scrub.
|
||||||
@@ -666,3 +691,72 @@ Use this parameter to enable or disable this function for all pools.
|
|||||||
- Default: 100
|
- Default: 100
|
||||||
|
|
||||||
Retry interval for failed PG lock attempts.
|
Retry interval for failed PG lock attempts.
|
||||||
|
|
||||||
|
## atomic_write_size
|
||||||
|
|
||||||
|
- Type: integer
|
||||||
|
- Default: 4096
|
||||||
|
|
||||||
|
Maximum data device atomic write size allowed for OSD to use.
|
||||||
|
|
||||||
|
Atomic writes allow to reduce the Write Amplification factor with the new store
|
||||||
|
([meta_format](layout-osd.en.md#meta_format)=3) to almost 1 (i.e. almost no extra writes)
|
||||||
|
with replicated pools and reach the best possible write performance.
|
||||||
|
|
||||||
|
Default value is auto-detected during OSD initialization from
|
||||||
|
`/sys/block/xx/queue/atomic_write_max_bytes` or assumed to be 4096 bytes
|
||||||
|
because all known disks support 4 KB atomic writes. Auto-detection is only used for
|
||||||
|
NVMe disks because SAS disks require the explicit WRITE ATOMIC command which requires
|
||||||
|
RWF_ATOMIC (see below [#use_atomic_flag]) but that flag works incorrectly in current
|
||||||
|
Linux versions.
|
||||||
|
|
||||||
|
You can also check if your NVMe drives support atomic writes by running
|
||||||
|
the command `nvme id-ctrl /dev/nvme0n1 | grep awupf`. If the reported value,
|
||||||
|
plus 1, multiplied by the currently selected block size of the NVMe,
|
||||||
|
is more than 4 KB, then the new store can utilize it for better performance.
|
||||||
|
The only drives known to support it currently are [Micron and Kioxia](../intro/quickstart.en.md).
|
||||||
|
|
||||||
|
Atomic writes allow to skip double data writes in replicated pools, thus
|
||||||
|
reducing Write Amplification and improving write performance up to 2 times.
|
||||||
|
|
||||||
|
## use_atomic_flag
|
||||||
|
|
||||||
|
- Type: boolean
|
||||||
|
|
||||||
|
This option controls whether Vitastor OSDs use RWF_ATOMIC write flag with atomic writes.
|
||||||
|
This flag is supported since Linux 6.11 and adds some safety to atomic writes - the kernel
|
||||||
|
guarantees to not fragment write requests with it and also to check them against the actual
|
||||||
|
device atomic write capabilities.
|
||||||
|
|
||||||
|
However, the option is disabled by default because the flag is currently UNUSABLE - Linux
|
||||||
|
incorrectly requires writes with that flag to be of power-of-2 length and length-aligned.
|
||||||
|
I.e., for example, 12 KB writes and not-8-KB aligned 8 KB writes are forbidden by the kernel,
|
||||||
|
even though the NVMe specification allows them.
|
||||||
|
|
||||||
|
For NVMe disks with `scheduler=none` writes aren't fragmented anyway so it's not a big deal.
|
||||||
|
However, you can rebuild your kernel with [this patch](../../patches/linux-fix-atomic-write-checks.diff)
|
||||||
|
and turn this option on. It will make your atomic writes a bit safer.
|
||||||
|
|
||||||
|
## pg_reshard_chunk_size
|
||||||
|
|
||||||
|
- Type: integer
|
||||||
|
- Default: 100000
|
||||||
|
|
||||||
|
Pool PG count change is a CPU-intensive operation because OSDs store the full object database
|
||||||
|
in memory and have to move all entries between old and new PGs. Thus it's performed in chunks,
|
||||||
|
with pauses between chunks to prevent blocking OSD's event loop and other clients' operations.
|
||||||
|
This option sets the maximum number of object is a chunk. Moving 100k objects usually takes
|
||||||
|
50-100ms. Chunk size equal to 0 means unlimited.
|
||||||
|
|
||||||
|
## pg_reshard_chunk_pause_ms
|
||||||
|
|
||||||
|
- Type: milliseconds
|
||||||
|
- Default: 100
|
||||||
|
|
||||||
|
This option sets the interval between handling two PG count change chunks.
|
||||||
|
|
||||||
|
## gc_on_start
|
||||||
|
|
||||||
|
- Type: boolean
|
||||||
|
|
||||||
|
Forcibly clean all garbage entries in the new store on every OSD restart.
|
||||||
|
|||||||
+109
-8
@@ -39,6 +39,7 @@
|
|||||||
- [journal_io](#journal_io)
|
- [journal_io](#journal_io)
|
||||||
- [journal_sector_buffer_count](#journal_sector_buffer_count)
|
- [journal_sector_buffer_count](#journal_sector_buffer_count)
|
||||||
- [journal_no_same_sector_overwrites](#journal_no_same_sector_overwrites)
|
- [journal_no_same_sector_overwrites](#journal_no_same_sector_overwrites)
|
||||||
|
- [skip_corrupted_meta_entries](#skip_corrupted_meta_entries)
|
||||||
- [throttle_small_writes](#throttle_small_writes)
|
- [throttle_small_writes](#throttle_small_writes)
|
||||||
- [throttle_target_iops](#throttle_target_iops)
|
- [throttle_target_iops](#throttle_target_iops)
|
||||||
- [throttle_target_mbs](#throttle_target_mbs)
|
- [throttle_target_mbs](#throttle_target_mbs)
|
||||||
@@ -66,6 +67,11 @@
|
|||||||
- [allow_net_split](#allow_net_split)
|
- [allow_net_split](#allow_net_split)
|
||||||
- [enable_pg_locks](#enable_pg_locks)
|
- [enable_pg_locks](#enable_pg_locks)
|
||||||
- [pg_lock_retry_interval_ms](#pg_lock_retry_interval_ms)
|
- [pg_lock_retry_interval_ms](#pg_lock_retry_interval_ms)
|
||||||
|
- [atomic_write_size](#atomic_write_size)
|
||||||
|
- [use_atomic_flag](#use_atomic_flag)
|
||||||
|
- [pg_reshard_chunk_size](#pg_reshard_chunk_size)
|
||||||
|
- [pg_reshard_chunk_pause_ms](#pg_reshard_chunk_pause_ms)
|
||||||
|
- [gc_on_start](#gc_on_start)
|
||||||
|
|
||||||
## bind_address
|
## bind_address
|
||||||
|
|
||||||
@@ -283,13 +289,19 @@ Flusher - это микро-поток (корутина), которая коп
|
|||||||
- Тип: булево (да/нет)
|
- Тип: булево (да/нет)
|
||||||
- Значение по умолчанию: true
|
- Значение по умолчанию: true
|
||||||
|
|
||||||
Данный параметр заставляет Vitastor всегда держать область метаданных диска
|
Только для старого хранилища ([meta_format](layout-osd.en.md#meta_format) 2).
|
||||||
в памяти. Это нужно, чтобы избегать дополнительных операций чтения с диска
|
|
||||||
при записи. Размер области метаданных на данный момент составляет примерно
|
Данный параметр заставляет Vitastor всегда держать копию области метаданных
|
||||||
224 МБ на 1 ТБ данных. При включении потребление памяти снизится примерно
|
в памяти в том же виде, как она лежит на диске, в дополнение к БД метаданных.
|
||||||
на эту величину, но при этом также снизится и производительность. В будущем,
|
То есть, с включённой опцией каждая запись метаданных хранится в памяти дважды.
|
||||||
после обновления схемы хранения метаданных, это ограничение, скорее всего,
|
Это нужно, чтобы избегать дополнительных операций чтения с диска при записи.
|
||||||
будет ликвидировано.
|
Размер области метаданных в старом хранилище составляет примерно 224 МБ на
|
||||||
|
1 ТБ данных. Вы можете отключить опцию, чтобы снизить потребление памяти
|
||||||
|
примерно на эту величину, но при этом также снизится и производительность.
|
||||||
|
|
||||||
|
Для нового хранилища ([meta_format](layout-osd.en.md#meta_format) 3) опция,
|
||||||
|
возможно, будет переработана в будущем для поддержки работы без полной
|
||||||
|
загрузки метаданных в памяти.
|
||||||
|
|
||||||
## inmemory_journal
|
## inmemory_journal
|
||||||
|
|
||||||
@@ -372,6 +384,8 @@ fsync небезопасным даже с режимом "directsync".
|
|||||||
нужно менять - это если вы включаете journal_no_same_sector_overwrites. В
|
нужно менять - это если вы включаете journal_no_same_sector_overwrites. В
|
||||||
этом случае установите данный параметр, например, в 1024.
|
этом случае установите данный параметр, например, в 1024.
|
||||||
|
|
||||||
|
Неприменимо к новому хранилищу ([meta_format](layout-osd.en.md#meta_format) 3).
|
||||||
|
|
||||||
## journal_no_same_sector_overwrites
|
## journal_no_same_sector_overwrites
|
||||||
|
|
||||||
- Тип: булево (да/нет)
|
- Тип: булево (да/нет)
|
||||||
@@ -387,6 +401,18 @@ fsync небезопасным даже с режимом "directsync".
|
|||||||
|
|
||||||
Почти все другие SSD (99% моделей) не требуют данной опции.
|
Почти все другие SSD (99% моделей) не требуют данной опции.
|
||||||
|
|
||||||
|
Неприменимо к новому хранилищу ([meta_format](layout-osd.en.md#meta_format) 3).
|
||||||
|
|
||||||
|
## skip_corrupted_meta_entries
|
||||||
|
|
||||||
|
- Тип: булево (да/нет)
|
||||||
|
- Значение по умолчанию: false
|
||||||
|
|
||||||
|
Только для нового хранилища ([meta_format](layout-osd.en.md#meta_format) 3).
|
||||||
|
Разрешить OSD запускаться, даже если часть блоков или записей метаданных
|
||||||
|
повреждена, пропуская их. Опция предназначена для использования только в
|
||||||
|
целях аварийного восстановления.
|
||||||
|
|
||||||
## throttle_small_writes
|
## throttle_small_writes
|
||||||
|
|
||||||
- Тип: булево (да/нет)
|
- Тип: булево (да/нет)
|
||||||
@@ -514,7 +540,7 @@ fsync небезопасным даже с режимом "directsync".
|
|||||||
## scrub_list_limit
|
## scrub_list_limit
|
||||||
|
|
||||||
- Тип: целое число
|
- Тип: целое число
|
||||||
- Значение по умолчанию: 1000
|
- Значение по умолчанию: 262144
|
||||||
- Можно менять на лету: да
|
- Можно менять на лету: да
|
||||||
|
|
||||||
Размер загружаемых за одну операцию списков объектов в процессе фоновой
|
Размер загружаемых за одну операцию списков объектов в процессе фоновой
|
||||||
@@ -699,3 +725,78 @@ pg_minsize OSD во время переключений, что может по
|
|||||||
- Значение по умолчанию: 100
|
- Значение по умолчанию: 100
|
||||||
|
|
||||||
Интервал повтора неудачных попыток блокировки PG.
|
Интервал повтора неудачных попыток блокировки PG.
|
||||||
|
|
||||||
|
## atomic_write_size
|
||||||
|
|
||||||
|
- Тип: целое число
|
||||||
|
- Значение по умолчанию: 4096
|
||||||
|
|
||||||
|
Максимальный размер атомарной записи на диск данных, который OSD разрешено использовать.
|
||||||
|
|
||||||
|
Поддержка атомарной записи позволяет снизить мультипликатор записи (Write Amplification)
|
||||||
|
на диск с новым хранилищем ([meta_format](layout-osd.ru.md#meta_format)=3)
|
||||||
|
практически до 1 (то есть, почти до нулевого объёма лишней записи) в реплицированных
|
||||||
|
пулах и достигнуть наилучшей возможной производительности записи.
|
||||||
|
|
||||||
|
Значение по умолчанию авто-определяется во время инициализации OSD из
|
||||||
|
`/sys/block/xx/queue/atomic_write_max_bytes` либо принимается равным 4096,
|
||||||
|
так как все известные диски поддерживают атомарную запись 4 КБ блоков.
|
||||||
|
Автоопределение применяется только для NVMe-дисков, так как SAS диски требуют
|
||||||
|
использования отдельной команды WRITE ATOMIC, а для неё нужен флаг RWF_ATOMIC
|
||||||
|
(см. ниже [#use_atomic_flag]), а он в текущих версиях Linux работает некорректно.
|
||||||
|
|
||||||
|
Вы также можете проверить, поддерживают ли ваши NVMe-диски атомарную запись,
|
||||||
|
с помощью команды `nvme id-ctrl /dev/nvme0n1 | grep awupf`. Если значение awupf
|
||||||
|
плюс 1, умноженное на текущий выбранный размер блока NVMe-диска, больше 4 КБ,
|
||||||
|
то новое хранилище может использовать атомарные записи для достижения лучшей
|
||||||
|
производительности. Единственные известные диски, которые поддерживают это сейчас -
|
||||||
|
[Micron и Kioxia](../intro/quickstart.ru.md).
|
||||||
|
|
||||||
|
Атомарная запись позволяет не использовать двойную запись данных (в журнал и на
|
||||||
|
устройство данных) в реплицированных пулах и таким образом снижает амплификацию
|
||||||
|
записи (объём служебной записи на диск) и улучшает производительность записи
|
||||||
|
вплоть до 2-х кратного прироста.
|
||||||
|
|
||||||
|
## use_atomic_flag
|
||||||
|
|
||||||
|
- Тип: булево (да/нет)
|
||||||
|
|
||||||
|
Данная опция контролирует использование Vitastor OSD флага RWF_ATOMIC при атомарной записи
|
||||||
|
блоков. Этот флаг поддерживается, начиная с версии ядра Linux 6.11 и добавляет немного корректности
|
||||||
|
атомарным записям - ядро гарантирует отсутствие фрагментации запросов записи с этим флагом и
|
||||||
|
проверяет их на соответствие реальным возможностям устройства.
|
||||||
|
|
||||||
|
Однако, данная опция по умолчанию отключена, так как флаг в текущих версиях Linux работает
|
||||||
|
абсолютно НЕКОРРЕКТНО - при нём Linux требует, чтобы запросы записи имели длину, равную
|
||||||
|
степени двойки и были выровнены на эту длину. То есть, например, 12 КБ запросы записи, а также
|
||||||
|
8 КБ запросы записи по не-кратному 8 КБ смещению запрещаются ядром, хотя спецификация NVMe их
|
||||||
|
разрешает.
|
||||||
|
|
||||||
|
Для NVMe-дисков с `scheduler=none` запросы записи и так не фрагментируются, так что это не так
|
||||||
|
уж и важно, однако вы можете пересобрать своё ядро с [этим патчем](../../patches/linux-fix-atomic-write-checks.diff)
|
||||||
|
и включить данную опцию. Это сделает вашу атомарную запись капельку безопаснее.
|
||||||
|
|
||||||
|
## pg_reshard_chunk_size
|
||||||
|
|
||||||
|
- Тип: целое число
|
||||||
|
- Значение по умолчанию: 100000
|
||||||
|
|
||||||
|
Изменение числа PG в пуле заметно загружает процессор, так как OSD хранят полную базу данных
|
||||||
|
объектов в памяти и им приходится перемещать все записи объектов между старыми и новыми PG.
|
||||||
|
Поэтому изменение применяется порциями, с паузами между порциями, чтобы не блокировать обработку
|
||||||
|
событий OSD и операции остальных клиентов. Данная опция задаёт максимальное число объектов
|
||||||
|
в порции. Перемещение 100 тысяч объектов (значение по умолчанию) обычно занимает порядка
|
||||||
|
50-100 миллисекунд. Значение опции 0 отключает лимит размера порции.
|
||||||
|
|
||||||
|
## pg_reshard_chunk_pause_ms
|
||||||
|
|
||||||
|
- Тип: миллисекунды
|
||||||
|
- Значение по умолчанию: 100
|
||||||
|
|
||||||
|
Данная опция задаёт интервал между обработкой двух порций изменения числа PG пулов.
|
||||||
|
|
||||||
|
## gc_on_start
|
||||||
|
|
||||||
|
- Тип: булево (да/нет)
|
||||||
|
|
||||||
|
Принудительно очищать все мусорные записи в новом хранилище при каждом запуске OSD.
|
||||||
|
|||||||
@@ -0,0 +1,306 @@
|
|||||||
|
[Documentation](../../README.md#documentation) → [Configuration](../config.en.md) → Security Parameters
|
||||||
|
|
||||||
|
-----
|
||||||
|
|
||||||
|
[Читать на русском](security.ru.md)
|
||||||
|
|
||||||
|
# Security Parameters
|
||||||
|
|
||||||
|
These parameters affect your Vitastor installation security and apply to OSDs, monitors and clients.
|
||||||
|
|
||||||
|
Most of them can be set in /etc/vitastor/vitastor.conf and in etcd, but don't support online modification.
|
||||||
|
|
||||||
|
All certificate and private key parameters mentioned may contain a path to a PEM file or just
|
||||||
|
a PEM string with certificate or a private key. In the latter case, the string must begin with
|
||||||
|
"-----BEGIN CERTIFICATE-----" or "-----BEGIN PRIVATE KEY-----".
|
||||||
|
|
||||||
|
- [use_perms](#use_perms)
|
||||||
|
- [cert](#cert)
|
||||||
|
- [pkey](#pkey)
|
||||||
|
- [etcd_ca](#etcd_ca)
|
||||||
|
- [client_ca](#client_ca)
|
||||||
|
- [osd_ca](#osd_ca)
|
||||||
|
- [mon_ca](#mon_ca)
|
||||||
|
- [antietcd_cert](#antietcd_cert)
|
||||||
|
- [antietcd_key](#antietcd_key)
|
||||||
|
- [etcd_proxy.urls](#etcd_proxyurls)
|
||||||
|
- [etcd_proxy.cert](#etcd_proxycert)
|
||||||
|
- [etcd_proxy.key](#etcd_proxykey)
|
||||||
|
- [etcd_proxy.ca](#etcd_proxyca)
|
||||||
|
- [osd_cert](#osd_cert)
|
||||||
|
- [osd_pkey](#osd_pkey)
|
||||||
|
- [api_cert](#api_cert)
|
||||||
|
- [api_pkey](#api_pkey)
|
||||||
|
- [etcd_client_cert](#etcd_client_cert)
|
||||||
|
- [etcd_client_key](#etcd_client_key)
|
||||||
|
- [osd_etcd_client_cert](#osd_etcd_client_cert)
|
||||||
|
- [osd_etcd_client_key](#osd_etcd_client_key)
|
||||||
|
- [mon_etcd_client_cert](#mon_etcd_client_cert)
|
||||||
|
- [mon_etcd_client_key](#mon_etcd_client_key)
|
||||||
|
- [proto_checksums](#proto_checksums)
|
||||||
|
- [force_proto_checksums](#force_proto_checksums)
|
||||||
|
- [max_cipher_pool_size](#max_cipher_pool_size)
|
||||||
|
- [vault_url](#vault_url)
|
||||||
|
- [vault_secret_api_path](#vault_secret_api_path)
|
||||||
|
- [vault_client_cert](#vault_client_cert)
|
||||||
|
- [vault_client_key](#vault_client_key)
|
||||||
|
- [vault_ca](#vault_ca)
|
||||||
|
- [vault_timeout_ms](#vault_timeout_ms)
|
||||||
|
- [vault_error_timeout_sec](#vault_error_timeout_sec)
|
||||||
|
- [vault_refresh_leeway_sec](#vault_refresh_leeway_sec)
|
||||||
|
|
||||||
|
## use_perms
|
||||||
|
|
||||||
|
- Type: boolean
|
||||||
|
- Default: false
|
||||||
|
|
||||||
|
Enable client permissions in a Vitastor cluster, including Antietcd built into the Monitor.
|
||||||
|
Requires configured encryption. Also note that separate Antietcd requires separate configuration
|
||||||
|
to use permissions (see [security documentation](../intro/security.en.md) for details).
|
||||||
|
|
||||||
|
## cert
|
||||||
|
|
||||||
|
- Type: string
|
||||||
|
|
||||||
|
Client certificate of the current Vitastor user. Required for Vitastor protocol encryption.
|
||||||
|
Must be signed with [client_ca](#client_ca). Also used as the client certificate for etcd/Antietcd
|
||||||
|
connections by default.
|
||||||
|
|
||||||
|
## pkey
|
||||||
|
|
||||||
|
- Type: string
|
||||||
|
|
||||||
|
Private key of the current Vitastor user.
|
||||||
|
|
||||||
|
## etcd_ca
|
||||||
|
|
||||||
|
- Type: string
|
||||||
|
|
||||||
|
Trusted TLS CA to verify etcd server certificate. Or just the etcd server's
|
||||||
|
certificate itself - it's fine to use it for etcd_ca.
|
||||||
|
|
||||||
|
## client_ca
|
||||||
|
|
||||||
|
- Type: string
|
||||||
|
|
||||||
|
Trusted TLS CA to verify Vitastor client certificates.
|
||||||
|
Mandatory for Vitastor protocol encryption.
|
||||||
|
|
||||||
|
## osd_ca
|
||||||
|
|
||||||
|
- Type: string
|
||||||
|
|
||||||
|
Trusted TLS CA to verify Vitastor OSD certificates. Also mandatory for Vitastor protocol
|
||||||
|
encryption. Must be different from client_ca. May be equal to osd_cert - different OSDs
|
||||||
|
don't require separate certificates at the moment because their permissions don't differ.
|
||||||
|
|
||||||
|
## mon_ca
|
||||||
|
|
||||||
|
- Type: string
|
||||||
|
|
||||||
|
Trusted TLS CA to verify Vitastor Monitor certificates. Used only for separate Antietcd,
|
||||||
|
not required when a monitor built-in Antietcd is used. May be equal to mon_client_etcd_cert.
|
||||||
|
|
||||||
|
## antietcd_cert
|
||||||
|
|
||||||
|
- Type: string
|
||||||
|
|
||||||
|
Server TLS certificate for Antietcd built into the Monitor.
|
||||||
|
|
||||||
|
## antietcd_key
|
||||||
|
|
||||||
|
- Type: string
|
||||||
|
|
||||||
|
Private key for antietcd_cert.
|
||||||
|
|
||||||
|
## etcd_proxy.urls
|
||||||
|
|
||||||
|
- Type: string or array of strings
|
||||||
|
|
||||||
|
etcd URLs for Antietcd etcd proxy mode.
|
||||||
|
See [Mon as Etcd proxy](../intro/security.en.md#mon-as-etcd-proxy) for details.
|
||||||
|
|
||||||
|
## etcd_proxy.cert
|
||||||
|
|
||||||
|
- Type: string
|
||||||
|
|
||||||
|
Client certificate for Antietcd connections to etcd in proxy mode.
|
||||||
|
|
||||||
|
## etcd_proxy.key
|
||||||
|
|
||||||
|
- Type: string
|
||||||
|
|
||||||
|
Private key for etcd_proxy.cert.
|
||||||
|
|
||||||
|
## etcd_proxy.ca
|
||||||
|
|
||||||
|
- Type: string
|
||||||
|
|
||||||
|
Trusted TLS CA to verify etcd server certificate when connecting to it from Antietcd.
|
||||||
|
|
||||||
|
## osd_cert
|
||||||
|
|
||||||
|
- Type: string
|
||||||
|
|
||||||
|
Vitastor OSD server certificate. Required for Vitastor protocol encryption. May be equal
|
||||||
|
to [osd_ca](#osd_ca) - all OSDs share the same permission set for now. Also used as the client
|
||||||
|
certificate for connections from OSD to etcd/Antietcd by default.
|
||||||
|
|
||||||
|
## osd_pkey
|
||||||
|
|
||||||
|
- Type: string
|
||||||
|
|
||||||
|
Private key for osd_cert.
|
||||||
|
|
||||||
|
## api_cert
|
||||||
|
|
||||||
|
- Type: string
|
||||||
|
|
||||||
|
Server TLS certificate for [vitastor-cli serve](../usage/cli.en.md#serve) API server.
|
||||||
|
|
||||||
|
## api_pkey
|
||||||
|
|
||||||
|
- Type: string
|
||||||
|
|
||||||
|
Private key for api_cert.
|
||||||
|
|
||||||
|
## etcd_client_cert
|
||||||
|
|
||||||
|
- Type: string
|
||||||
|
|
||||||
|
Client TLS certificate to use for connections from Vitastor clients to etcd/Antietcd if you don't want
|
||||||
|
to use the common client certificate [cert](#cert).
|
||||||
|
|
||||||
|
## etcd_client_key
|
||||||
|
|
||||||
|
- Type: string
|
||||||
|
|
||||||
|
Private key for etcd_client_cert.
|
||||||
|
|
||||||
|
## osd_etcd_client_cert
|
||||||
|
|
||||||
|
- Type: string
|
||||||
|
|
||||||
|
Client TLS certificate to use for connections from Vitastor OSDs to etcd/Antietcd if you don't want
|
||||||
|
to use the common OSD certificate [osd_cert](#osd_cert).
|
||||||
|
|
||||||
|
## osd_etcd_client_key
|
||||||
|
|
||||||
|
- Type: string
|
||||||
|
|
||||||
|
Private key for osd_etcd_client_cert.
|
||||||
|
|
||||||
|
## mon_etcd_client_cert
|
||||||
|
|
||||||
|
- Type: string
|
||||||
|
|
||||||
|
Client TLS certificate to use for connections from Vitastor Monitors to etcd/Antietcd - required
|
||||||
|
if you don't use the built-in Antietcd. In case you use it Monitor has direct access to Antietcd data
|
||||||
|
and doesn't require any connection.
|
||||||
|
|
||||||
|
## mon_etcd_client_key
|
||||||
|
|
||||||
|
- Type: string
|
||||||
|
|
||||||
|
Private key for mon_etcd_client_cert.
|
||||||
|
|
||||||
|
## proto_checksums
|
||||||
|
|
||||||
|
- Type: string
|
||||||
|
- Default: payload
|
||||||
|
|
||||||
|
One of "full", "payload", "gcm", "none":
|
||||||
|
- "full" means calculate and verify transport level checksums from the full message data
|
||||||
|
including the header - recommended for unencrypted setups.
|
||||||
|
- "payload" enables checksums only for the actual read/write data, but skips them for message
|
||||||
|
headers - recommended for encrypted setups because headers are already protected by AES-GCM.
|
||||||
|
- "gcm" disables checksums and enables AES-GCM encryption of the whole messages including headers
|
||||||
|
and data - AES-GCM already includes MAC which is actually a stronger checksum. This option is
|
||||||
|
slower and is only recommended for untrusted networks.
|
||||||
|
- "none" disables transport level checksums at all.
|
||||||
|
|
||||||
|
## force_proto_checksums
|
||||||
|
|
||||||
|
- Type: string
|
||||||
|
|
||||||
|
To allow older clients to connect to a Vitastor cluster with enabled checksums, Vitastor OSDs
|
||||||
|
allow clients to downgrade their proto_checksums by default. force_proto_checksums sets the
|
||||||
|
minimum security level allowed for connecting clients. When encryption is disabled, default
|
||||||
|
force_proto_checksums is none and clients without checksums are allowed. With enabled
|
||||||
|
encryption, force_proto_checksums becomes "payload" by default to block unauthenticated data
|
||||||
|
on the transport level.
|
||||||
|
|
||||||
|
## max_cipher_pool_size
|
||||||
|
|
||||||
|
- Type: integer
|
||||||
|
- Default: 256
|
||||||
|
|
||||||
|
Maximum number of OpenSSL cipher contexts cached in OSD memory, counted separately
|
||||||
|
for each cipher and for encryption/decryption. Probably doesn't require modification.
|
||||||
|
|
||||||
|
## vault_url
|
||||||
|
|
||||||
|
- Type: string
|
||||||
|
|
||||||
|
Vault base URL.
|
||||||
|
|
||||||
|
Vitastor clients support AES-256-XTS image data encryption with different per-image keys.
|
||||||
|
Encryption is performed by the client, OSDs don't have access to decrypted data.
|
||||||
|
|
||||||
|
Encryption keys may be stored in etcd or, for the increased security level, in an external
|
||||||
|
[HashiCorp Vault](https://developer.hashicorp.com/vault/) or [OpenBao](https://openbao.org/)
|
||||||
|
instance.
|
||||||
|
|
||||||
|
Vitastor clients use [v1 k/v secrets engine](https://openbao.org/api-docs/secret/kv/kv-v1/)
|
||||||
|
and [TLS authentication engine](https://openbao.org/api-docs/auth/cert/) in Vault.
|
||||||
|
|
||||||
|
In that case, only key IDs are stored in etcd.
|
||||||
|
|
||||||
|
## vault_secret_api_path
|
||||||
|
|
||||||
|
- Type: string
|
||||||
|
- Default: /v1/secret/
|
||||||
|
|
||||||
|
Vault v1 secret API mount path to use.
|
||||||
|
|
||||||
|
## vault_client_cert
|
||||||
|
|
||||||
|
- Type: string
|
||||||
|
|
||||||
|
Client TLS certificate to use for Vault connections if you don't want to use the common Vitastor
|
||||||
|
client certificate [cert](#cert) which is also used for Vault connections by default.
|
||||||
|
|
||||||
|
## vault_client_key
|
||||||
|
|
||||||
|
- Type: string
|
||||||
|
|
||||||
|
Private key for the vault_client_cert certificate.
|
||||||
|
|
||||||
|
## vault_ca
|
||||||
|
|
||||||
|
- Type: string
|
||||||
|
|
||||||
|
Trusted TLS CA to verify Vault server certificate. May be path to a file,
|
||||||
|
directory or just a PEM string with certificate.
|
||||||
|
|
||||||
|
## vault_timeout_ms
|
||||||
|
|
||||||
|
- Type: integer
|
||||||
|
- Default: 5000
|
||||||
|
|
||||||
|
Timeout for Vault requests in milliseconds.
|
||||||
|
|
||||||
|
## vault_error_timeout_sec
|
||||||
|
|
||||||
|
- Type: integer
|
||||||
|
- Default: 60
|
||||||
|
|
||||||
|
Time (in seconds) to wait before retrying after receiving an error from Vault.
|
||||||
|
|
||||||
|
## vault_refresh_leeway_sec
|
||||||
|
|
||||||
|
- Type: integer
|
||||||
|
- Default: 60
|
||||||
|
|
||||||
|
Extra time (in seconds) before real Vault token lease_timeout to refresh it, just
|
||||||
|
in case of system clock drift.
|
||||||
@@ -0,0 +1,312 @@
|
|||||||
|
[Документация](../../README-ru.md#документация) → [Конфигурация](../config.ru.md) → Параметры безопасности
|
||||||
|
|
||||||
|
-----
|
||||||
|
|
||||||
|
[Read in English](security.en.md)
|
||||||
|
|
||||||
|
# Параметры безопасности
|
||||||
|
|
||||||
|
Данные параметры затрагивают безопасность инсталляций Vitastor и используются
|
||||||
|
OSD, мониторами и клиентами.
|
||||||
|
|
||||||
|
Большая их часть может задаваться в /etc/vitastor/vitastor.conf и в etcd, но не
|
||||||
|
поддерживает онлайн-изменение.
|
||||||
|
|
||||||
|
Все параметры сертификатов и закрытых ключей могут быть путём к файлу или просто
|
||||||
|
строкой с сертификатом в формате PEM. В последнем случае строка должна начинаться с
|
||||||
|
"-----BEGIN CERTIFICATE-----" или "-----BEGIN PRIVATE KEY-----".
|
||||||
|
|
||||||
|
- [use_perms](#use_perms)
|
||||||
|
- [cert](#cert)
|
||||||
|
- [pkey](#pkey)
|
||||||
|
- [etcd_ca](#etcd_ca)
|
||||||
|
- [client_ca](#client_ca)
|
||||||
|
- [osd_ca](#osd_ca)
|
||||||
|
- [mon_ca](#mon_ca)
|
||||||
|
- [antietcd_cert](#antietcd_cert)
|
||||||
|
- [antietcd_key](#antietcd_key)
|
||||||
|
- [etcd_proxy.urls](#etcd_proxyurls)
|
||||||
|
- [etcd_proxy.cert](#etcd_proxycert)
|
||||||
|
- [etcd_proxy.key](#etcd_proxykey)
|
||||||
|
- [etcd_proxy.ca](#etcd_proxyca)
|
||||||
|
- [osd_cert](#osd_cert)
|
||||||
|
- [osd_pkey](#osd_pkey)
|
||||||
|
- [api_cert](#api_cert)
|
||||||
|
- [api_pkey](#api_pkey)
|
||||||
|
- [etcd_client_cert](#etcd_client_cert)
|
||||||
|
- [etcd_client_key](#etcd_client_key)
|
||||||
|
- [osd_etcd_client_cert](#osd_etcd_client_cert)
|
||||||
|
- [osd_etcd_client_key](#osd_etcd_client_key)
|
||||||
|
- [mon_etcd_client_cert](#mon_etcd_client_cert)
|
||||||
|
- [mon_etcd_client_key](#mon_etcd_client_key)
|
||||||
|
- [proto_checksums](#proto_checksums)
|
||||||
|
- [force_proto_checksums](#force_proto_checksums)
|
||||||
|
- [max_cipher_pool_size](#max_cipher_pool_size)
|
||||||
|
- [vault_url](#vault_url)
|
||||||
|
- [vault_secret_api_path](#vault_secret_api_path)
|
||||||
|
- [vault_client_cert](#vault_client_cert)
|
||||||
|
- [vault_client_key](#vault_client_key)
|
||||||
|
- [vault_ca](#vault_ca)
|
||||||
|
- [vault_timeout_ms](#vault_timeout_ms)
|
||||||
|
- [vault_error_timeout_sec](#vault_error_timeout_sec)
|
||||||
|
- [vault_refresh_leeway_sec](#vault_refresh_leeway_sec)
|
||||||
|
|
||||||
|
## use_perms
|
||||||
|
|
||||||
|
- Тип: булево (да/нет)
|
||||||
|
- Значение по умолчанию: false
|
||||||
|
|
||||||
|
Включает клиентские привилегии в кластере Vitastor, в том числе во встроенном в мониторе Antietcd.
|
||||||
|
Требует настроенного шифрования протокола. Также обратите внимание, что отдельно установленный Antietcd
|
||||||
|
требует отдельной настройки привилегий (подробности смотрите в [документации безопасности](../intro/security.ru.md)).
|
||||||
|
|
||||||
|
## cert
|
||||||
|
|
||||||
|
- Тип: строка
|
||||||
|
|
||||||
|
Клиентский сертификат текущего пользователя Vitastor. Требуется для шифрования протокола Vitastor.
|
||||||
|
Должен быть подписан [client_ca](#client_ca). Также по умолчанию используется как клиентский
|
||||||
|
сертификат для подключения к etcd/Antietcd и Vault.
|
||||||
|
|
||||||
|
## pkey
|
||||||
|
|
||||||
|
- Тип: строка
|
||||||
|
|
||||||
|
Закрытый ключ текущего пользователя Vitastor.
|
||||||
|
|
||||||
|
## etcd_ca
|
||||||
|
|
||||||
|
- Тип: строка
|
||||||
|
|
||||||
|
Доверенный корневой TLS-сертификат для проверки сертификата сервера etcd.
|
||||||
|
Либо же просто сам сертификат сервера etcd - его можно использовать как etcd_ca.
|
||||||
|
|
||||||
|
## client_ca
|
||||||
|
|
||||||
|
- Тип: строка
|
||||||
|
|
||||||
|
Доверенный TLS-сертификат для проверки сертификатов клиентов Vitastor.
|
||||||
|
Требуется для шифрования протокола Vitastor.
|
||||||
|
|
||||||
|
## osd_ca
|
||||||
|
|
||||||
|
- Тип: строка
|
||||||
|
|
||||||
|
Доверенный TLS-сертификат для проверки сертификатов OSD Vitastor. Также обязателен
|
||||||
|
для шифрования протокола Vitastor. Должен отличаться от client_ca. Может быть равен
|
||||||
|
osd_cert - разные OSD не требуют разных сертификатов, потому что на данный момент
|
||||||
|
привилегии разных OSD никак не отличаются.
|
||||||
|
|
||||||
|
## mon_ca
|
||||||
|
|
||||||
|
- Тип: строка
|
||||||
|
|
||||||
|
Доверенный TLS-сертификат для проверки сертификатов мониторов Vitastor. Используется
|
||||||
|
только отдельно установленным Antietcd, не требуется при использовании встроенного в монитор
|
||||||
|
Antietcd. Может быть равен mon_client_etcd_cert.
|
||||||
|
|
||||||
|
## antietcd_cert
|
||||||
|
|
||||||
|
- Тип: строка
|
||||||
|
|
||||||
|
Серверный TLS-сертификат для Antietcd, встроенного в монитор.
|
||||||
|
|
||||||
|
## antietcd_key
|
||||||
|
|
||||||
|
- Тип: строка
|
||||||
|
|
||||||
|
Закрытый ключ для сертификата antietcd_cert.
|
||||||
|
|
||||||
|
## etcd_proxy.urls
|
||||||
|
|
||||||
|
- Тип: строка или массив строк
|
||||||
|
|
||||||
|
Адреса etcd для режима Antietcd etcd-прокси.
|
||||||
|
Смотрите подробности в разделе [Mon в роли Etcd proxy](../intro/security.ru.md#mon-в-роли-etcd-proxy).
|
||||||
|
|
||||||
|
## etcd_proxy.cert
|
||||||
|
|
||||||
|
- Тип: строка
|
||||||
|
|
||||||
|
Клиентский сертификат для подключений от Antietcd к etcd в режиме прокси.
|
||||||
|
|
||||||
|
## etcd_proxy.key
|
||||||
|
|
||||||
|
- Тип: строка
|
||||||
|
|
||||||
|
Закрытый ключ для сертификата etcd_proxy.cert.
|
||||||
|
|
||||||
|
## etcd_proxy.ca
|
||||||
|
|
||||||
|
- Тип: строка
|
||||||
|
|
||||||
|
Доверенный TLS-сертификат для проверки сертификата сервера etcd при подключениях от Antietcd.
|
||||||
|
|
||||||
|
## osd_cert
|
||||||
|
|
||||||
|
- Тип: строка
|
||||||
|
|
||||||
|
Сертификат сервера Vitastor OSD. Требуется для шифрования протокола Vitastor. Может быть равен
|
||||||
|
[osd_ca](#osd_ca) - все OSD на данный момент имеют одинаковые привилегии. Также по умолчанию
|
||||||
|
используется как клиентский сертификат для подключения от OSD к etcd/Antietcd.
|
||||||
|
|
||||||
|
## osd_pkey
|
||||||
|
|
||||||
|
- Тип: строка
|
||||||
|
|
||||||
|
Закрытый ключ для сертификата osd_cert.
|
||||||
|
|
||||||
|
## api_cert
|
||||||
|
|
||||||
|
- Тип: строка
|
||||||
|
|
||||||
|
Серверный TLS-сертификат для API-сервера [vitastor-cli serve](../usage/cli.ru.md#serve).
|
||||||
|
|
||||||
|
## api_pkey
|
||||||
|
|
||||||
|
- Тип: строка
|
||||||
|
|
||||||
|
Закрытый ключ для сертификата api_cert.
|
||||||
|
|
||||||
|
## etcd_client_cert
|
||||||
|
|
||||||
|
- Тип: строка
|
||||||
|
|
||||||
|
Клиентский TLS сертификат для подключений от клиентов Vitastor к etcd/Antietcd, если вы не хотите
|
||||||
|
использовать общий клиентский сертификат [cert](#cert).
|
||||||
|
|
||||||
|
## etcd_client_key
|
||||||
|
|
||||||
|
- Тип: строка
|
||||||
|
|
||||||
|
Закрытый ключ для сертификата etcd_client_cert.
|
||||||
|
|
||||||
|
## osd_etcd_client_cert
|
||||||
|
|
||||||
|
- Тип: строка
|
||||||
|
|
||||||
|
Клиентский TLS сертификат для подключений от Vitastor OSD к etcd/Antietcd, если вы не хотите
|
||||||
|
использовать общий сертификат OSD [osd_cert](#osd_cert).
|
||||||
|
|
||||||
|
## osd_etcd_client_key
|
||||||
|
|
||||||
|
- Тип: строка
|
||||||
|
|
||||||
|
Закрытый ключ для сертификата osd_etcd_client_cert.
|
||||||
|
|
||||||
|
## mon_etcd_client_cert
|
||||||
|
|
||||||
|
- Тип: строка
|
||||||
|
|
||||||
|
Клиентский TLS сертификат для подключений от мониторов Vitastor к etcd/Antietcd - требуется, если
|
||||||
|
вы не используете встроенный в монитор Antietcd. Если вы используете его, то монитор и так имеет
|
||||||
|
прямой доступ к данным Antietcd и не требует никаких соединений.
|
||||||
|
|
||||||
|
## mon_etcd_client_key
|
||||||
|
|
||||||
|
- Тип: строка
|
||||||
|
|
||||||
|
Закрытый ключ для сертификата mon_etcd_client_cert.
|
||||||
|
|
||||||
|
## proto_checksums
|
||||||
|
|
||||||
|
- Тип: строка
|
||||||
|
- Значение по умолчанию: payload
|
||||||
|
|
||||||
|
Одно из значений "full", "payload", "gcm" и "none":
|
||||||
|
- "full" означает расчёт и проверку контрольных сумм на транспортном уровне от полных сообщений,
|
||||||
|
включая их заголовки и данные - рекомендуется для кластеров без шифрования.
|
||||||
|
- "payload" включает контрольные суммы только для данных сообщений, но пропускает заголовки -
|
||||||
|
такая настройка рекомендуется для кластеров с включённым шифрованием, потому что в них заголовки
|
||||||
|
и так защищены шифрованием AES-GCM.
|
||||||
|
- "gcm" отключает контрольные суммы и включает шифрование полных сообщений включая заголовки и
|
||||||
|
данные - AES-GCM уже включает в себя MAC, который по сути является криптостойкой контрольной
|
||||||
|
суммой. Такая настройка медленнее и рекомендуется только для недоверенных сетей.
|
||||||
|
- "none" полностью отключает контрольные суммы на транспортном уровне.
|
||||||
|
|
||||||
|
## force_proto_checksums
|
||||||
|
|
||||||
|
- Тип: строка
|
||||||
|
|
||||||
|
Чтобы старые клиенты Vitastor могли подключаться к кластеру с включёнными контрольными
|
||||||
|
суммами, Vitastor OSD по умолчанию разрешают клиентам отключать контрольные суммы
|
||||||
|
данных (proto_checksums). Настройка force_proto_checksums задаёт минимальный уровень
|
||||||
|
безопасности, разрешённый для подключающихся клиентов. Когда шифрование отключено,
|
||||||
|
force_proto_checksums по умолчанию равно none и подключения клиентов без контрольных
|
||||||
|
сумм разрешаются. При включённом шифровании значение по умолчанию force_proto_checksums
|
||||||
|
становится "payload", чтобы блокировать подключения с неаутентифицированными данными.
|
||||||
|
|
||||||
|
## max_cipher_pool_size
|
||||||
|
|
||||||
|
- Тип: целое число
|
||||||
|
- Значение по умолчанию: 256
|
||||||
|
|
||||||
|
Максимальное количество кэшируемых в памяти OSD контекстов шифра OpenSSL, учитываемое
|
||||||
|
отдельно для каждого шифра и для шифрования и расшифровки. Вряд ли требует изменения.
|
||||||
|
|
||||||
|
## vault_url
|
||||||
|
|
||||||
|
- Тип: строка
|
||||||
|
|
||||||
|
Базовый адрес Vault.
|
||||||
|
|
||||||
|
Клиенты Vitastor поддерживают AES-256-XTS шифрование данных образов с отдельными ключами на
|
||||||
|
каждый образ. Данные шифруются клиентами, OSD не имеют доступа к незашифрованным данным.
|
||||||
|
|
||||||
|
Ключи шифрования могут храниться в etcd или, для повышенного уровня безопасности, во внешнем
|
||||||
|
[HashiCorp Vault](https://developer.hashicorp.com/vault/) или [OpenBao](https://openbao.org/).
|
||||||
|
|
||||||
|
Клиенты Vitastor используют [движок секретов v1](https://openbao.org/api-docs/secret/kv/kv-v1/)
|
||||||
|
и [TLS-аутентификацию](https://openbao.org/api-docs/auth/cert/) в Vault.
|
||||||
|
|
||||||
|
В этом случае, только ID ключей хранятся в etcd.
|
||||||
|
|
||||||
|
## vault_secret_api_path
|
||||||
|
|
||||||
|
- Тип: строка
|
||||||
|
- Значение по умолчанию: /v1/secret/
|
||||||
|
|
||||||
|
Путь к API секретов v1 для использования клиентами.
|
||||||
|
|
||||||
|
## vault_client_cert
|
||||||
|
|
||||||
|
- Тип: строка
|
||||||
|
|
||||||
|
Клиентский TLS сертификат для подключений к Vault на тот случай, если вы не хотите использовать
|
||||||
|
общий сертификат клиента Vitastor [cert](#cert), используемый для подключений к Vault по умолчанию.
|
||||||
|
|
||||||
|
## vault_client_key
|
||||||
|
|
||||||
|
- Тип: строка
|
||||||
|
|
||||||
|
Закрытый ключ для сертификата vault_client_cert.
|
||||||
|
|
||||||
|
## vault_ca
|
||||||
|
|
||||||
|
- Тип: строка
|
||||||
|
|
||||||
|
Доверенный корневой TLS-сертификат для проверки сертификата сервера Vault.
|
||||||
|
Может быть путём к файлу, директории или просто строкой с сертификатом в
|
||||||
|
формате PEM.
|
||||||
|
|
||||||
|
## vault_timeout_ms
|
||||||
|
|
||||||
|
- Тип: целое число
|
||||||
|
- Значение по умолчанию: 5000
|
||||||
|
|
||||||
|
Максимально время выполнения Vault-запросов в миллисекундах.
|
||||||
|
|
||||||
|
## vault_error_timeout_sec
|
||||||
|
|
||||||
|
- Тип: целое число
|
||||||
|
- Значение по умолчанию: 60
|
||||||
|
|
||||||
|
Время (в секундах) для ожидания перед повторной попыткой при получении ошибки от Vault.
|
||||||
|
|
||||||
|
## vault_refresh_leeway_sec
|
||||||
|
|
||||||
|
- Тип: целое число
|
||||||
|
- Значение по умолчанию: 60
|
||||||
|
|
||||||
|
Зазор времени (в секундах), чтобы обновлять токены Vault чуть раньше их реального
|
||||||
|
lease_timeout, на случай "ухода" системных часов.
|
||||||
@@ -283,3 +283,36 @@
|
|||||||
[локальные чтения](pool.ru.md#local_reads). По умолчанию для определения имени
|
[локальные чтения](pool.ru.md#local_reads). По умолчанию для определения имени
|
||||||
хоста используется стандартная функция [gethostname](https://man7.org/linux/man-pages/man2/gethostname.2.html),
|
хоста используется стандартная функция [gethostname](https://man7.org/linux/man-pages/man2/gethostname.2.html),
|
||||||
но вы также можете задать имя хоста вручную данным параметром.
|
но вы также можете задать имя хоста вручную данным параметром.
|
||||||
|
- name: ublk_queue_depth
|
||||||
|
type: int
|
||||||
|
default: 256
|
||||||
|
online: false
|
||||||
|
info: Default queue depth for [Vitastor ublk servers](../usage/ublk.en.md).
|
||||||
|
info_ru: Глубина очереди по умолчанию для [ublk-серверов Vitastor](../usage/ublk.ru.md).
|
||||||
|
- name: ublk_max_io_size
|
||||||
|
type: int
|
||||||
|
online: false
|
||||||
|
info: |
|
||||||
|
Default maximum I/O size for Vitastor [ublk servers](../usage/ublk.en.md).
|
||||||
|
The largest of 1 MB and pool block size multiplied by EC data chunk count is used if not specified.
|
||||||
|
info_ru: |
|
||||||
|
Максимальный размер запроса ввода-вывода для [ublk-серверов Vitastor](../usage/ublk.ru.md).
|
||||||
|
Если не задан, используется максимум из 1 МБ и размера блока пула, умноженного на число частей
|
||||||
|
данных EC-пула.
|
||||||
|
- name: qemu_file_mirror_path
|
||||||
|
type: string
|
||||||
|
info: |
|
||||||
|
When set to an FS directory path (for example, `/mnt/vitastor/`), `qemu-img info` and similar
|
||||||
|
QAPI commands return the name of the image inside this directory instead of normal
|
||||||
|
`vitastor://?image=abc` URI as `filename`.
|
||||||
|
|
||||||
|
This allows to then mount this path using [vitastor-nfs](../usage/nfs.en.md) and trick
|
||||||
|
third-party systems like Veeam which rely on `filename` in the image info but don't support Vitastor.
|
||||||
|
info_ru: |
|
||||||
|
Если установить эту опцию равной пути к каталогу в ФС, команда `qemu-img info` и подобные
|
||||||
|
команды QAPI будут возвращать в поле `filename` имя образа внутри заданного каталога вместо
|
||||||
|
обычного адреса типа `vitastor://?image=abc`.
|
||||||
|
|
||||||
|
Это позволяет смонтировать этот путь с помощью [vitastor-nfs](../usage/nfs.ru.md) и обмануть
|
||||||
|
сторонние системы типа Veeam, которые полагаются на поле `filename` в информации об образе QEMU,
|
||||||
|
но не поддерживают Vitastor.
|
||||||
|
|||||||
@@ -24,6 +24,8 @@
|
|||||||
|
|
||||||
{{../../installation/kubernetes.en.md}}
|
{{../../installation/kubernetes.en.md}}
|
||||||
|
|
||||||
|
{{../../installation/s3.en.md}}
|
||||||
|
|
||||||
{{../../installation/source.en.md}}
|
{{../../installation/source.en.md}}
|
||||||
|
|
||||||
{{../../config.en.md|indent=1}}
|
{{../../config.en.md|indent=1}}
|
||||||
@@ -42,6 +44,8 @@
|
|||||||
|
|
||||||
{{../../config/monitor.en.md|indent=2}}
|
{{../../config/monitor.en.md|indent=2}}
|
||||||
|
|
||||||
|
{{../../config/security.en.md|indent=2}}
|
||||||
|
|
||||||
{{../../config/pool.en.md|indent=2}}
|
{{../../config/pool.en.md|indent=2}}
|
||||||
|
|
||||||
{{../../config/inode.en.md|indent=2}}
|
{{../../config/inode.en.md|indent=2}}
|
||||||
@@ -54,6 +58,8 @@
|
|||||||
|
|
||||||
{{../../usage/fio.en.md}}
|
{{../../usage/fio.en.md}}
|
||||||
|
|
||||||
|
{{../../usage/ublk.en.md}}
|
||||||
|
|
||||||
{{../../usage/nbd.en.md}}
|
{{../../usage/nbd.en.md}}
|
||||||
|
|
||||||
{{../../usage/qemu.en.md}}
|
{{../../usage/qemu.en.md}}
|
||||||
|
|||||||
@@ -26,6 +26,8 @@
|
|||||||
|
|
||||||
{{../../installation/source.ru.md}}
|
{{../../installation/source.ru.md}}
|
||||||
|
|
||||||
|
{{../../installation/s3.ru.md}}
|
||||||
|
|
||||||
{{../../config.ru.md|indent=1}}
|
{{../../config.ru.md|indent=1}}
|
||||||
|
|
||||||
{{../../config/common.ru.md|indent=2}}
|
{{../../config/common.ru.md|indent=2}}
|
||||||
@@ -42,6 +44,8 @@
|
|||||||
|
|
||||||
{{../../config/monitor.ru.md|indent=2}}
|
{{../../config/monitor.ru.md|indent=2}}
|
||||||
|
|
||||||
|
{{../../config/security.ru.md|indent=2}}
|
||||||
|
|
||||||
{{../../config/pool.ru.md|indent=2}}
|
{{../../config/pool.ru.md|indent=2}}
|
||||||
|
|
||||||
{{../../config/inode.ru.md|indent=2}}
|
{{../../config/inode.ru.md|indent=2}}
|
||||||
@@ -54,6 +58,8 @@
|
|||||||
|
|
||||||
{{../../usage/fio.ru.md}}
|
{{../../usage/fio.ru.md}}
|
||||||
|
|
||||||
|
{{../../usage/ublk.ru.md}}
|
||||||
|
|
||||||
{{../../usage/nbd.ru.md}}
|
{{../../usage/nbd.ru.md}}
|
||||||
|
|
||||||
{{../../usage/qemu.ru.md}}
|
{{../../usage/qemu.ru.md}}
|
||||||
|
|||||||
@@ -1,3 +1,28 @@
|
|||||||
|
- name: meta_format
|
||||||
|
type: int
|
||||||
|
default: 3
|
||||||
|
info: |
|
||||||
|
OSD store implementation version and on-disk metadata format.
|
||||||
|
|
||||||
|
Three versions are currently supported: 3, 2 and 1.
|
||||||
|
- 3 the new log-structured store, it's overall faster, has lower Write
|
||||||
|
Amplification, which may be even close to 1 (i.e. almost no extra writes)
|
||||||
|
if your SSDs support atomic writes (see [atomic_write_size](osd.en.md#atomic_write_size)).
|
||||||
|
- 2 is the old stable store from Vitastor 0.9-2.x.
|
||||||
|
- 1 is the same old store but with a legacy metadata format from Vitastor
|
||||||
|
versions to up 0.8.x, without any support for checksums.
|
||||||
|
info_ru: |
|
||||||
|
Версия реализации дискового хранилища OSD и дискового формата метаданных.
|
||||||
|
|
||||||
|
Поддерживаются три версии: 3, 2 и 1.
|
||||||
|
- 3 - новое лог-структурированное хранилище, в целом более быстрое, со
|
||||||
|
сниженным фактором амплификации записи, который может составлять около 1
|
||||||
|
(то есть, практически без лишней служебной записи), если ваши SSD
|
||||||
|
поддерживают атомарную запись (см. [atomic_write_size](osd.ru.md#atomic_write_size)).
|
||||||
|
- 2 - старое стабильное хранилище из версий Vitastor 0.9-2.x.
|
||||||
|
- 1 - то же самое стабильное хранилище, но с ещё более старым форматом
|
||||||
|
метаданных из версий Vitastor до 0.8.x, без какой-либо поддержки
|
||||||
|
контрольных сумм.
|
||||||
- name: data_device
|
- name: data_device
|
||||||
type: string
|
type: string
|
||||||
info: |
|
info: |
|
||||||
@@ -208,11 +233,21 @@
|
|||||||
type: string
|
type: string
|
||||||
default: none
|
default: none
|
||||||
info: |
|
info: |
|
||||||
Data checksum type to use. May be "crc32c" or "none". Set to "crc32c" to
|
Data and metadata checksum type to use. May be "crc32c", "xxh3_32" or "none".
|
||||||
enable data checksums.
|
Select crc32c or xxh3_32 and set csum_block_size to enable data checksums.
|
||||||
|
|
||||||
|
Both crc32c and xxh3_32 are almost equally fast, xxh3_32 is safer. xxh3_32 is
|
||||||
|
the xxhash3 algorithm truncated from 64 to 32 bits (which is still a good hash).
|
||||||
|
|
||||||
|
Note that enabled data checksums either increase memory usage or reduce
|
||||||
|
performance. Check details in [csum_block_size](#csum_block_size) description.
|
||||||
info_ru: |
|
info_ru: |
|
||||||
Тип используемых OSD контрольных сумм данных. Может быть "crc32c" или "none".
|
Тип используемых OSD контрольных сумм данных и метаданных. Может быть "crc32c",
|
||||||
Установите в "crc32c", чтобы включить расчёт и проверку контрольных сумм данных.
|
"xxh3_32" или "none". Выберите crc32c или xxh3_32 и установите csum_block_size,
|
||||||
|
чтобы включить контрольные суммы данных.
|
||||||
|
|
||||||
|
И crc32c, и xxh3_32 примерно одинаково быстры, xxh3_32 надёжней. xxh3_32 - это
|
||||||
|
алгоритм xxhash3, обрезанный с 64 до 32 бит (это всё равно хороший хеш).
|
||||||
|
|
||||||
Следует понимать, что контрольные суммы в зависимости от размера блока их
|
Следует понимать, что контрольные суммы в зависимости от размера блока их
|
||||||
расчёта либо увеличивают потребление памяти, либо снижают производительность.
|
расчёта либо увеличивают потребление памяти, либо снижают производительность.
|
||||||
|
|||||||
@@ -64,7 +64,7 @@ for (const file of params_files)
|
|||||||
let out = '\n';
|
let out = '\n';
|
||||||
for (const c of cfg)
|
for (const c of cfg)
|
||||||
{
|
{
|
||||||
out += `\n- [${c.name}](#${c.name})`;
|
out += `\n- [${c.name}](#${c.name.replace(/\./g, '')})`;
|
||||||
}
|
}
|
||||||
for (const c of cfg)
|
for (const c of cfg)
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -21,6 +21,9 @@
|
|||||||
cluster, cluster_key, persist_filter, stale_read can also be set in
|
cluster, cluster_key, persist_filter, stale_read can also be set in
|
||||||
Vitastor configuration with `antietcd_` prefix.
|
Vitastor configuration with `antietcd_` prefix.
|
||||||
|
|
||||||
|
See also: [antietcd_cert](security.en.md#antietcd_cert),
|
||||||
|
[antietcd_key](security.en.md#antietcd_key) and [etcd_proxy](security.en.md#etcd_proxyurls).
|
||||||
|
|
||||||
You can dump/load data to or from antietcd using Antietcd `anticli` tool:
|
You can dump/load data to or from antietcd using Antietcd `anticli` tool:
|
||||||
|
|
||||||
```
|
```
|
||||||
@@ -47,6 +50,9 @@
|
|||||||
node_id, cluster, cluster_key, persist_filter, stale_read также можно задавать
|
node_id, cluster, cluster_key, persist_filter, stale_read также можно задавать
|
||||||
в конфигурации Vitastor с префиксом `antietcd_`.
|
в конфигурации Vitastor с префиксом `antietcd_`.
|
||||||
|
|
||||||
|
Смотрите также настройки [antietcd_cert](security.ru.md#antietcd_cert),
|
||||||
|
[antietcd_key](security.ru.md#antietcd_key) и [etcd_proxy](security.ru.md#etcd_proxyurls).
|
||||||
|
|
||||||
Вы можете выгружать/загружать данные в или из antietcd с помощью его инструмента
|
Вы можете выгружать/загружать данные в или из antietcd с помощью его инструмента
|
||||||
`anticli`:
|
`anticli`:
|
||||||
|
|
||||||
|
|||||||
+36
-51
@@ -51,7 +51,7 @@
|
|||||||
Рассмотрите включение `use_rdmacm` для таких сетей.
|
Рассмотрите включение `use_rdmacm` для таких сетей.
|
||||||
- name: use_rdmacm
|
- name: use_rdmacm
|
||||||
type: bool
|
type: bool
|
||||||
default: true
|
default: false
|
||||||
info: |
|
info: |
|
||||||
Use an alternative implementation of RDMA through RDMA-CM (Connection
|
Use an alternative implementation of RDMA through RDMA-CM (Connection
|
||||||
Manager). Works with all RDMA networks: Infiniband, iWARP and
|
Manager). Works with all RDMA networks: Infiniband, iWARP and
|
||||||
@@ -84,11 +84,6 @@
|
|||||||
unsupported with old libibverbs < v32, like in Debian 10 Buster or
|
unsupported with old libibverbs < v32, like in Debian 10 Buster or
|
||||||
CentOS 7.
|
CentOS 7.
|
||||||
|
|
||||||
Vitastor supports all adapters, even ones without ODP support, like
|
|
||||||
Mellanox ConnectX-3 and non-Mellanox cards. Versions up to Vitastor
|
|
||||||
1.2.0 required ODP which is only present in Mellanox ConnectX >= 4.
|
|
||||||
See also [rdma_odp](#rdma_odp).
|
|
||||||
|
|
||||||
Run `ibv_devinfo -v` as root to list available RDMA devices and their
|
Run `ibv_devinfo -v` as root to list available RDMA devices and their
|
||||||
features.
|
features.
|
||||||
|
|
||||||
@@ -97,6 +92,23 @@
|
|||||||
the manual of your network vendor for details about setting up the switch
|
the manual of your network vendor for details about setting up the switch
|
||||||
for RoCEv2 correctly. Usually it means setting up Lossless Ethernet with
|
for RoCEv2 correctly. Usually it means setting up Lossless Ethernet with
|
||||||
PFC (Priority Flow Control) and ECN (Explicit Congestion Notification).
|
PFC (Priority Flow Control) and ECN (Explicit Congestion Notification).
|
||||||
|
|
||||||
|
Vitastor supports all adapters, even ones without ODP (On-Demand Paging)
|
||||||
|
support, like Mellanox ConnectX-3 and non-Mellanox cards. ODP is only present
|
||||||
|
in Mellanox ConnectX >= 4 adapters and allows to skip memory registration
|
||||||
|
for RDMA and thus, in theory, avoid memory copying.
|
||||||
|
|
||||||
|
Versions up to Vitastor 1.2.0 required ODP, then it was disabled by default,
|
||||||
|
but it was still supported up to 3.0.3. Now ODP support is removed because it
|
||||||
|
actually only hurts performance: an example 3-node cluster with 8 NVMe in each
|
||||||
|
node and 2*25 GBit/s ConnectX-6 RDMA network pushed 3950000 read iops without
|
||||||
|
ODP, but only 239000 iops with ODP.
|
||||||
|
|
||||||
|
This happens because Mellanox ODP implementation seems to be based on
|
||||||
|
message retransmissions when the adapter doesn't know about the buffer yet -
|
||||||
|
it likely uses standard "RNR retransmissions" (RNR = receiver not ready)
|
||||||
|
which is generally slow in RDMA/RoCE networks. Here's a presentation about
|
||||||
|
it from ISPASS-2021 conference: https://tkygtr6.github.io/pub/ISPASS21_slides.pdf
|
||||||
info_ru: |
|
info_ru: |
|
||||||
Название RDMA-устройства для связи с Vitastor OSD (например, "rocep5s0f0").
|
Название RDMA-устройства для связи с Vitastor OSD (например, "rocep5s0f0").
|
||||||
Если не указано, Vitastor попробует найти RoCE-устройство, соответствующее
|
Если не указано, Vitastor попробует найти RoCE-устройство, соответствующее
|
||||||
@@ -105,12 +117,6 @@
|
|||||||
не задана. Также автовыбор не поддерживается со старыми версиями библиотеки
|
не задана. Также автовыбор не поддерживается со старыми версиями библиотеки
|
||||||
libibverbs < v32, например в Debian 10 Buster или CentOS 7.
|
libibverbs < v32, например в Debian 10 Buster или CentOS 7.
|
||||||
|
|
||||||
Vitastor поддерживает все модели адаптеров, включая те, у которых
|
|
||||||
нет поддержки ODP, то есть вы можете использовать RDMA с ConnectX-3 и
|
|
||||||
картами производства не Mellanox. Версии Vitastor до 1.2.0 включительно
|
|
||||||
требовали ODP, который есть только на Mellanox ConnectX 4 и более новых.
|
|
||||||
См. также [rdma_odp](#rdma_odp).
|
|
||||||
|
|
||||||
Запустите `ibv_devinfo -v` от имени суперпользователя, чтобы посмотреть
|
Запустите `ibv_devinfo -v` от имени суперпользователя, чтобы посмотреть
|
||||||
список доступных RDMA-устройств, их параметры и возможности.
|
список доступных RDMA-устройств, их параметры и возможности.
|
||||||
|
|
||||||
@@ -120,6 +126,24 @@
|
|||||||
коммутатора для RoCEv2 ищите в документации производителя. Обычно это
|
коммутатора для RoCEv2 ищите в документации производителя. Обычно это
|
||||||
подразумевает настройку сети без потерь на основе PFC (Priority Flow
|
подразумевает настройку сети без потерь на основе PFC (Priority Flow
|
||||||
Control) и ECN (Explicit Congestion Notification).
|
Control) и ECN (Explicit Congestion Notification).
|
||||||
|
|
||||||
|
Vitastor поддерживает все модели адаптеров, включая те, у которых нет
|
||||||
|
поддержки ODP (On-Demand Paging), например, ConnectX-3 и карты производства
|
||||||
|
не Mellanox. Функция ODP доступна только на адаптерах Mellanox ConnectX-4 и
|
||||||
|
более новых и позволяет не регистрировать память для её использования RDMA-картой,
|
||||||
|
благодаря чему в теории можно избежать лишних копирований памяти.
|
||||||
|
|
||||||
|
Версии Vitastor до 1.2.0 включительно требовали ODP, потом функция был отключена
|
||||||
|
по умолчанию, но поддерживалась вплоть до версии 3.0.3. Сейчас поддержка ODP
|
||||||
|
полностью удалена, так как на самом деле она только портит производительность:
|
||||||
|
например, на 3-узловом кластере с 8 NVMe в каждом узле и сетью 2*25 Гбит/с на
|
||||||
|
чтение с RDMA без ODP удаётся снять 3950000 iops, а с ODP - всего 239000 iops.
|
||||||
|
|
||||||
|
Это происходит из-за того, что реализация ODP у Mellanox неоптимальная и
|
||||||
|
основана на повторной передаче сообщений, когда карте не известен буфер -
|
||||||
|
вероятно, на стандартных "RNR retransmission" (RNR = receiver not ready).
|
||||||
|
А данные повторные передачи в RDMA/RoCE - всегда очень медленная штука.
|
||||||
|
Презентация на эту тему с конференции ISPASS-2021: https://tkygtr6.github.io/pub/ISPASS21_slides.pdf
|
||||||
- name: rdma_port_num
|
- name: rdma_port_num
|
||||||
type: int
|
type: int
|
||||||
info: |
|
info: |
|
||||||
@@ -218,45 +242,6 @@
|
|||||||
у принимающей стороны в процессе работы не заканчивались буферы на приём.
|
у принимающей стороны в процессе работы не заканчивались буферы на приём.
|
||||||
Не влияет на потребление памяти - дополнительная память на операции отправки
|
Не влияет на потребление памяти - дополнительная память на операции отправки
|
||||||
не выделяется.
|
не выделяется.
|
||||||
- name: rdma_odp
|
|
||||||
type: bool
|
|
||||||
default: false
|
|
||||||
online: false
|
|
||||||
info: |
|
|
||||||
Use RDMA with On-Demand Paging. ODP is currently only available on Mellanox
|
|
||||||
ConnectX-4 and newer adapters. ODP allows to not register memory explicitly
|
|
||||||
for RDMA adapter to be able to use it. This, in turn, allows to skip memory
|
|
||||||
copying during sending. One would think this should improve performance, but
|
|
||||||
**in reality** RDMA performance with ODP is **drastically** worse. Example
|
|
||||||
3-node cluster with 8 NVMe in each node and 2*25 GBit/s ConnectX-6 RDMA network
|
|
||||||
without ODP pushes 3950000 read iops, but only 239000 iops with ODP...
|
|
||||||
|
|
||||||
This happens because Mellanox ODP implementation seems to be based on
|
|
||||||
message retransmissions when the adapter doesn't know about the buffer yet -
|
|
||||||
it likely uses standard "RNR retransmissions" (RNR = receiver not ready)
|
|
||||||
which is generally slow in RDMA/RoCE networks. Here's a presentation about
|
|
||||||
it from ISPASS-2021 conference: https://tkygtr6.github.io/pub/ISPASS21_slides.pdf
|
|
||||||
|
|
||||||
ODP support is retained in the code just in case a good ODP implementation
|
|
||||||
appears one day.
|
|
||||||
info_ru: |
|
|
||||||
Использовать RDMA с On-Demand Paging. ODP - функция, доступная пока что
|
|
||||||
исключительно на адаптерах Mellanox ConnectX-4 и более новых. ODP позволяет
|
|
||||||
не регистрировать память для её использования RDMA-картой. Благодаря этому
|
|
||||||
можно не копировать данные при отправке их в сеть и, казалось бы, это должно
|
|
||||||
улучшать производительность - но **по факту** получается так, что
|
|
||||||
производительность только ухудшается, причём сильно. Пример - на 3-узловом
|
|
||||||
кластере с 8 NVMe в каждом узле и сетью 2*25 Гбит/с на чтение с RDMA без ODP
|
|
||||||
удаётся снять 3950000 iops, а с ODP - всего 239000 iops...
|
|
||||||
|
|
||||||
Это происходит из-за того, что реализация ODP у Mellanox неоптимальная и
|
|
||||||
основана на повторной передаче сообщений, когда карте не известен буфер -
|
|
||||||
вероятно, на стандартных "RNR retransmission" (RNR = receiver not ready).
|
|
||||||
А данные повторные передачи в RDMA/RoCE - всегда очень медленная штука.
|
|
||||||
Презентация на эту тему с конференции ISPASS-2021: https://tkygtr6.github.io/pub/ISPASS21_slides.pdf
|
|
||||||
|
|
||||||
Возможность использования ODP сохранена в коде на случай, если вдруг в один
|
|
||||||
прекрасный день появится хорошая реализация ODP.
|
|
||||||
- name: peer_connect_interval
|
- name: peer_connect_interval
|
||||||
type: sec
|
type: sec
|
||||||
min: 1
|
min: 1
|
||||||
|
|||||||
+156
-15
@@ -253,21 +253,33 @@
|
|||||||
type: bool
|
type: bool
|
||||||
default: true
|
default: true
|
||||||
info: |
|
info: |
|
||||||
This parameter makes Vitastor always keep metadata area of the block device
|
Only for the old store ([meta_format](layout-osd.en.md#meta_format) 2).
|
||||||
in memory. It's required for good performance because it allows to avoid
|
|
||||||
additional read-modify-write cycles during metadata modifications. Metadata
|
This parameter makes Vitastor keep a copy of metadata area in memory as it is
|
||||||
area size is currently roughly 224 MB per 1 TB of data. You can turn it off
|
on disk, in addition to the metadata database. When the option is enabled, every
|
||||||
to reduce memory usage by this value, but it will hurt performance. This
|
metadata entry is effectively stored in RAM twice. It's required for good performance
|
||||||
restriction is likely to be removed in the future along with the upgrade
|
because it allows to avoid additional read-modify-write cycles during metadata
|
||||||
of the metadata storage scheme.
|
modifications. Metadata area size with the old store is roughly 224 MB per 1 TB
|
||||||
|
of data. You can turn the option off to reduce memory usage by this value, but
|
||||||
|
it will reduce performance.
|
||||||
|
|
||||||
|
For the new store ([meta_format](layout-osd.en.md#meta_format) 3), the option
|
||||||
|
may be changed in the future to support operation without loading full metadata
|
||||||
|
database in memory.
|
||||||
info_ru: |
|
info_ru: |
|
||||||
Данный параметр заставляет Vitastor всегда держать область метаданных диска
|
Только для старого хранилища ([meta_format](layout-osd.en.md#meta_format) 2).
|
||||||
в памяти. Это нужно, чтобы избегать дополнительных операций чтения с диска
|
|
||||||
при записи. Размер области метаданных на данный момент составляет примерно
|
Данный параметр заставляет Vitastor всегда держать копию области метаданных
|
||||||
224 МБ на 1 ТБ данных. При включении потребление памяти снизится примерно
|
в памяти в том же виде, как она лежит на диске, в дополнение к БД метаданных.
|
||||||
на эту величину, но при этом также снизится и производительность. В будущем,
|
То есть, с включённой опцией каждая запись метаданных хранится в памяти дважды.
|
||||||
после обновления схемы хранения метаданных, это ограничение, скорее всего,
|
Это нужно, чтобы избегать дополнительных операций чтения с диска при записи.
|
||||||
будет ликвидировано.
|
Размер области метаданных в старом хранилище составляет примерно 224 МБ на
|
||||||
|
1 ТБ данных. Вы можете отключить опцию, чтобы снизить потребление памяти
|
||||||
|
примерно на эту величину, но при этом также снизится и производительность.
|
||||||
|
|
||||||
|
Для нового хранилища ([meta_format](layout-osd.en.md#meta_format) 3) опция,
|
||||||
|
возможно, будет переработана в будущем для поддержки работы без полной
|
||||||
|
загрузки метаданных в памяти.
|
||||||
- name: inmemory_journal
|
- name: inmemory_journal
|
||||||
type: bool
|
type: bool
|
||||||
default: true
|
default: true
|
||||||
@@ -386,11 +398,15 @@
|
|||||||
blocks. The only situation when you should increase it to a larger value
|
blocks. The only situation when you should increase it to a larger value
|
||||||
is when you enable journal_no_same_sector_overwrites. In this case set
|
is when you enable journal_no_same_sector_overwrites. In this case set
|
||||||
it to, for example, 1024.
|
it to, for example, 1024.
|
||||||
|
|
||||||
|
Not applicable to the new store ([meta_format](layout-osd.en.md#meta_format) 3).
|
||||||
info_ru: |
|
info_ru: |
|
||||||
Максимальное число буферов, разрешённых для использования под записываемые
|
Максимальное число буферов, разрешённых для использования под записываемые
|
||||||
в журнал блоки метаданных. Единственная ситуация, в которой этот параметр
|
в журнал блоки метаданных. Единственная ситуация, в которой этот параметр
|
||||||
нужно менять - это если вы включаете journal_no_same_sector_overwrites. В
|
нужно менять - это если вы включаете journal_no_same_sector_overwrites. В
|
||||||
этом случае установите данный параметр, например, в 1024.
|
этом случае установите данный параметр, например, в 1024.
|
||||||
|
|
||||||
|
Неприменимо к новому хранилищу ([meta_format](layout-osd.en.md#meta_format) 3).
|
||||||
- name: journal_no_same_sector_overwrites
|
- name: journal_no_same_sector_overwrites
|
||||||
type: bool
|
type: bool
|
||||||
default: false
|
default: false
|
||||||
@@ -402,6 +418,8 @@
|
|||||||
journal after writing it instead of possibly overwriting it the second time.
|
journal after writing it instead of possibly overwriting it the second time.
|
||||||
|
|
||||||
Most (99%) other SSDs don't need this option.
|
Most (99%) other SSDs don't need this option.
|
||||||
|
|
||||||
|
Not applicable to the new store ([meta_format](layout-osd.en.md#meta_format) 3).
|
||||||
info_ru: |
|
info_ru: |
|
||||||
Включайте данную опцию для SSD вроде Intel D3-S4510 и D3-S4610, которые
|
Включайте данную опцию для SSD вроде Intel D3-S4510 и D3-S4610, которые
|
||||||
ОЧЕНЬ не любят, когда ПО перезаписывает один и тот же сектор несколько раз
|
ОЧЕНЬ не любят, когда ПО перезаписывает один и тот же сектор несколько раз
|
||||||
@@ -412,6 +430,20 @@
|
|||||||
самого сектора.
|
самого сектора.
|
||||||
|
|
||||||
Почти все другие SSD (99% моделей) не требуют данной опции.
|
Почти все другие SSD (99% моделей) не требуют данной опции.
|
||||||
|
|
||||||
|
Неприменимо к новому хранилищу ([meta_format](layout-osd.en.md#meta_format) 3).
|
||||||
|
- name: skip_corrupted_meta_entries
|
||||||
|
type: bool
|
||||||
|
default: false
|
||||||
|
info: |
|
||||||
|
Only for the new store ([meta_format](layout-osd.en.md#meta_format) 3).
|
||||||
|
Allow OSD to start when some metadata entries or blocks are corrupted by
|
||||||
|
skipping them. Should be only used as an emergency measure.
|
||||||
|
info_ru: |
|
||||||
|
Только для нового хранилища ([meta_format](layout-osd.en.md#meta_format) 3).
|
||||||
|
Разрешить OSD запускаться, даже если часть блоков или записей метаданных
|
||||||
|
повреждена, пропуская их. Опция предназначена для использования только в
|
||||||
|
целях аварийного восстановления.
|
||||||
- name: throttle_small_writes
|
- name: throttle_small_writes
|
||||||
type: bool
|
type: bool
|
||||||
default: false
|
default: false
|
||||||
@@ -566,7 +598,7 @@
|
|||||||
сильно влияет на пользовательскую нагрузку.
|
сильно влияет на пользовательскую нагрузку.
|
||||||
- name: scrub_list_limit
|
- name: scrub_list_limit
|
||||||
type: int
|
type: int
|
||||||
default: 1000
|
default: 262144
|
||||||
online: true
|
online: true
|
||||||
info: |
|
info: |
|
||||||
Number of objects to list in one listing operation during scrub.
|
Number of objects to list in one listing operation during scrub.
|
||||||
@@ -801,3 +833,112 @@
|
|||||||
default: 100
|
default: 100
|
||||||
info: Retry interval for failed PG lock attempts.
|
info: Retry interval for failed PG lock attempts.
|
||||||
info_ru: Интервал повтора неудачных попыток блокировки PG.
|
info_ru: Интервал повтора неудачных попыток блокировки PG.
|
||||||
|
- name: atomic_write_size
|
||||||
|
type: int
|
||||||
|
default: 4096
|
||||||
|
info: |
|
||||||
|
Maximum data device atomic write size allowed for OSD to use.
|
||||||
|
|
||||||
|
Atomic writes allow to reduce the Write Amplification factor with the new store
|
||||||
|
([meta_format](layout-osd.en.md#meta_format)=3) to almost 1 (i.e. almost no extra writes)
|
||||||
|
with replicated pools and reach the best possible write performance.
|
||||||
|
|
||||||
|
Default value is auto-detected during OSD initialization from
|
||||||
|
`/sys/block/xx/queue/atomic_write_max_bytes` or assumed to be 4096 bytes
|
||||||
|
because all known disks support 4 KB atomic writes. Auto-detection is only used for
|
||||||
|
NVMe disks because SAS disks require the explicit WRITE ATOMIC command which requires
|
||||||
|
RWF_ATOMIC (see below [#use_atomic_flag]) but that flag works incorrectly in current
|
||||||
|
Linux versions.
|
||||||
|
|
||||||
|
You can also check if your NVMe drives support atomic writes by running
|
||||||
|
the command `nvme id-ctrl /dev/nvme0n1 | grep awupf`. If the reported value,
|
||||||
|
plus 1, multiplied by the currently selected block size of the NVMe,
|
||||||
|
is more than 4 KB, then the new store can utilize it for better performance.
|
||||||
|
The only drives known to support it currently are [Micron and Kioxia](../intro/quickstart.en.md).
|
||||||
|
|
||||||
|
Atomic writes allow to skip double data writes in replicated pools, thus
|
||||||
|
reducing Write Amplification and improving write performance up to 2 times.
|
||||||
|
info_ru: |
|
||||||
|
Максимальный размер атомарной записи на диск данных, который OSD разрешено использовать.
|
||||||
|
|
||||||
|
Поддержка атомарной записи позволяет снизить мультипликатор записи (Write Amplification)
|
||||||
|
на диск с новым хранилищем ([meta_format](layout-osd.ru.md#meta_format)=3)
|
||||||
|
практически до 1 (то есть, почти до нулевого объёма лишней записи) в реплицированных
|
||||||
|
пулах и достигнуть наилучшей возможной производительности записи.
|
||||||
|
|
||||||
|
Значение по умолчанию авто-определяется во время инициализации OSD из
|
||||||
|
`/sys/block/xx/queue/atomic_write_max_bytes` либо принимается равным 4096,
|
||||||
|
так как все известные диски поддерживают атомарную запись 4 КБ блоков.
|
||||||
|
Автоопределение применяется только для NVMe-дисков, так как SAS диски требуют
|
||||||
|
использования отдельной команды WRITE ATOMIC, а для неё нужен флаг RWF_ATOMIC
|
||||||
|
(см. ниже [#use_atomic_flag]), а он в текущих версиях Linux работает некорректно.
|
||||||
|
|
||||||
|
Вы также можете проверить, поддерживают ли ваши NVMe-диски атомарную запись,
|
||||||
|
с помощью команды `nvme id-ctrl /dev/nvme0n1 | grep awupf`. Если значение awupf
|
||||||
|
плюс 1, умноженное на текущий выбранный размер блока NVMe-диска, больше 4 КБ,
|
||||||
|
то новое хранилище может использовать атомарные записи для достижения лучшей
|
||||||
|
производительности. Единственные известные диски, которые поддерживают это сейчас -
|
||||||
|
[Micron и Kioxia](../intro/quickstart.ru.md).
|
||||||
|
|
||||||
|
Атомарная запись позволяет не использовать двойную запись данных (в журнал и на
|
||||||
|
устройство данных) в реплицированных пулах и таким образом снижает амплификацию
|
||||||
|
записи (объём служебной записи на диск) и улучшает производительность записи
|
||||||
|
вплоть до 2-х кратного прироста.
|
||||||
|
- name: use_atomic_flag
|
||||||
|
type: bool
|
||||||
|
info: |
|
||||||
|
This option controls whether Vitastor OSDs use RWF_ATOMIC write flag with atomic writes.
|
||||||
|
This flag is supported since Linux 6.11 and adds some safety to atomic writes - the kernel
|
||||||
|
guarantees to not fragment write requests with it and also to check them against the actual
|
||||||
|
device atomic write capabilities.
|
||||||
|
|
||||||
|
However, the option is disabled by default because the flag is currently UNUSABLE - Linux
|
||||||
|
incorrectly requires writes with that flag to be of power-of-2 length and length-aligned.
|
||||||
|
I.e., for example, 12 KB writes and not-8-KB aligned 8 KB writes are forbidden by the kernel,
|
||||||
|
even though the NVMe specification allows them.
|
||||||
|
|
||||||
|
For NVMe disks with `scheduler=none` writes aren't fragmented anyway so it's not a big deal.
|
||||||
|
However, you can rebuild your kernel with [this patch](../../patches/linux-fix-atomic-write-checks.diff)
|
||||||
|
and turn this option on. It will make your atomic writes a bit safer.
|
||||||
|
info_ru: |
|
||||||
|
Данная опция контролирует использование Vitastor OSD флага RWF_ATOMIC при атомарной записи
|
||||||
|
блоков. Этот флаг поддерживается, начиная с версии ядра Linux 6.11 и добавляет немного корректности
|
||||||
|
атомарным записям - ядро гарантирует отсутствие фрагментации запросов записи с этим флагом и
|
||||||
|
проверяет их на соответствие реальным возможностям устройства.
|
||||||
|
|
||||||
|
Однако, данная опция по умолчанию отключена, так как флаг в текущих версиях Linux работает
|
||||||
|
абсолютно НЕКОРРЕКТНО - при нём Linux требует, чтобы запросы записи имели длину, равную
|
||||||
|
степени двойки и были выровнены на эту длину. То есть, например, 12 КБ запросы записи, а также
|
||||||
|
8 КБ запросы записи по не-кратному 8 КБ смещению запрещаются ядром, хотя спецификация NVMe их
|
||||||
|
разрешает.
|
||||||
|
|
||||||
|
Для NVMe-дисков с `scheduler=none` запросы записи и так не фрагментируются, так что это не так
|
||||||
|
уж и важно, однако вы можете пересобрать своё ядро с [этим патчем](../../patches/linux-fix-atomic-write-checks.diff)
|
||||||
|
и включить данную опцию. Это сделает вашу атомарную запись капельку безопаснее.
|
||||||
|
- name: pg_reshard_chunk_size
|
||||||
|
type: int
|
||||||
|
default: 100000
|
||||||
|
info: |
|
||||||
|
Pool PG count change is a CPU-intensive operation because OSDs store the full object database
|
||||||
|
in memory and have to move all entries between old and new PGs. Thus it's performed in chunks,
|
||||||
|
with pauses between chunks to prevent blocking OSD's event loop and other clients' operations.
|
||||||
|
This option sets the maximum number of object is a chunk. Moving 100k objects usually takes
|
||||||
|
50-100ms. Chunk size equal to 0 means unlimited.
|
||||||
|
info_ru: |
|
||||||
|
Изменение числа PG в пуле заметно загружает процессор, так как OSD хранят полную базу данных
|
||||||
|
объектов в памяти и им приходится перемещать все записи объектов между старыми и новыми PG.
|
||||||
|
Поэтому изменение применяется порциями, с паузами между порциями, чтобы не блокировать обработку
|
||||||
|
событий OSD и операции остальных клиентов. Данная опция задаёт максимальное число объектов
|
||||||
|
в порции. Перемещение 100 тысяч объектов (значение по умолчанию) обычно занимает порядка
|
||||||
|
50-100 миллисекунд. Значение опции 0 отключает лимит размера порции.
|
||||||
|
- name: pg_reshard_chunk_pause_ms
|
||||||
|
type: ms
|
||||||
|
default: 100
|
||||||
|
info: |
|
||||||
|
This option sets the interval between handling two PG count change chunks.
|
||||||
|
info_ru: |
|
||||||
|
Данная опция задаёт интервал между обработкой двух порций изменения числа PG пулов.
|
||||||
|
- name: gc_on_start
|
||||||
|
type: bool
|
||||||
|
info: Forcibly clean all garbage entries in the new store on every OSD restart.
|
||||||
|
info_ru: Принудительно очищать все мусорные записи в новом хранилище при каждом запуске OSD.
|
||||||
|
|||||||
@@ -0,0 +1,5 @@
|
|||||||
|
{
|
||||||
|
"dependencies": {
|
||||||
|
"yaml": "^2.8.2"
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
# Security Parameters
|
||||||
|
|
||||||
|
These parameters affect your Vitastor installation security and apply to OSDs, monitors and clients.
|
||||||
|
|
||||||
|
Most of them can be set in /etc/vitastor/vitastor.conf and in etcd, but don't support online modification.
|
||||||
|
|
||||||
|
All certificate and private key parameters mentioned may contain a path to a PEM file or just
|
||||||
|
a PEM string with certificate or a private key. In the latter case, the string must begin with
|
||||||
|
"-----BEGIN CERTIFICATE-----" or "-----BEGIN PRIVATE KEY-----".
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
# Параметры безопасности
|
||||||
|
|
||||||
|
Данные параметры затрагивают безопасность инсталляций Vitastor и используются
|
||||||
|
OSD, мониторами и клиентами.
|
||||||
|
|
||||||
|
Большая их часть может задаваться в /etc/vitastor/vitastor.conf и в etcd, но не
|
||||||
|
поддерживает онлайн-изменение.
|
||||||
|
|
||||||
|
Все параметры сертификатов и закрытых ключей могут быть путём к файлу или просто
|
||||||
|
строкой с сертификатом в формате PEM. В последнем случае строка должна начинаться с
|
||||||
|
"-----BEGIN CERTIFICATE-----" или "-----BEGIN PRIVATE KEY-----".
|
||||||
@@ -0,0 +1,276 @@
|
|||||||
|
- name: use_perms
|
||||||
|
type: bool
|
||||||
|
default: false
|
||||||
|
info: |
|
||||||
|
Enable client permissions in a Vitastor cluster, including Antietcd built into the Monitor.
|
||||||
|
Requires configured encryption. Also note that separate Antietcd requires separate configuration
|
||||||
|
to use permissions (see [security documentation](../intro/security.en.md) for details).
|
||||||
|
info_ru: |
|
||||||
|
Включает клиентские привилегии в кластере Vitastor, в том числе во встроенном в мониторе Antietcd.
|
||||||
|
Требует настроенного шифрования протокола. Также обратите внимание, что отдельно установленный Antietcd
|
||||||
|
требует отдельной настройки привилегий (подробности смотрите в [документации безопасности](../intro/security.ru.md)).
|
||||||
|
- name: cert
|
||||||
|
type: string
|
||||||
|
info: |
|
||||||
|
Client certificate of the current Vitastor user. Required for Vitastor protocol encryption.
|
||||||
|
Must be signed with [client_ca](#client_ca). Also used as the client certificate for etcd/Antietcd
|
||||||
|
connections by default.
|
||||||
|
info_ru: |
|
||||||
|
Клиентский сертификат текущего пользователя Vitastor. Требуется для шифрования протокола Vitastor.
|
||||||
|
Должен быть подписан [client_ca](#client_ca). Также по умолчанию используется как клиентский
|
||||||
|
сертификат для подключения к etcd/Antietcd и Vault.
|
||||||
|
- name: pkey
|
||||||
|
type: string
|
||||||
|
info: Private key of the current Vitastor user.
|
||||||
|
info_ru: Закрытый ключ текущего пользователя Vitastor.
|
||||||
|
- name: etcd_ca
|
||||||
|
type: string
|
||||||
|
info: |
|
||||||
|
Trusted TLS CA to verify etcd server certificate. Or just the etcd server's
|
||||||
|
certificate itself - it's fine to use it for etcd_ca.
|
||||||
|
info_ru: |
|
||||||
|
Доверенный корневой TLS-сертификат для проверки сертификата сервера etcd.
|
||||||
|
Либо же просто сам сертификат сервера etcd - его можно использовать как etcd_ca.
|
||||||
|
- name: client_ca
|
||||||
|
type: string
|
||||||
|
info: |
|
||||||
|
Trusted TLS CA to verify Vitastor client certificates.
|
||||||
|
Mandatory for Vitastor protocol encryption.
|
||||||
|
info_ru: |
|
||||||
|
Доверенный TLS-сертификат для проверки сертификатов клиентов Vitastor.
|
||||||
|
Требуется для шифрования протокола Vitastor.
|
||||||
|
- name: osd_ca
|
||||||
|
type: string
|
||||||
|
info: |
|
||||||
|
Trusted TLS CA to verify Vitastor OSD certificates. Also mandatory for Vitastor protocol
|
||||||
|
encryption. Must be different from client_ca. May be equal to osd_cert - different OSDs
|
||||||
|
don't require separate certificates at the moment because their permissions don't differ.
|
||||||
|
info_ru: |
|
||||||
|
Доверенный TLS-сертификат для проверки сертификатов OSD Vitastor. Также обязателен
|
||||||
|
для шифрования протокола Vitastor. Должен отличаться от client_ca. Может быть равен
|
||||||
|
osd_cert - разные OSD не требуют разных сертификатов, потому что на данный момент
|
||||||
|
привилегии разных OSD никак не отличаются.
|
||||||
|
- name: mon_ca
|
||||||
|
type: string
|
||||||
|
info: |
|
||||||
|
Trusted TLS CA to verify Vitastor Monitor certificates. Used only for separate Antietcd,
|
||||||
|
not required when a monitor built-in Antietcd is used. May be equal to mon_client_etcd_cert.
|
||||||
|
info_ru: |
|
||||||
|
Доверенный TLS-сертификат для проверки сертификатов мониторов Vitastor. Используется
|
||||||
|
только отдельно установленным Antietcd, не требуется при использовании встроенного в монитор
|
||||||
|
Antietcd. Может быть равен mon_client_etcd_cert.
|
||||||
|
- name: antietcd_cert
|
||||||
|
type: string
|
||||||
|
info: Server TLS certificate for Antietcd built into the Monitor.
|
||||||
|
info_ru: Серверный TLS-сертификат для Antietcd, встроенного в монитор.
|
||||||
|
- name: antietcd_key
|
||||||
|
type: string
|
||||||
|
info: Private key for antietcd_cert.
|
||||||
|
info_ru: Закрытый ключ для сертификата antietcd_cert.
|
||||||
|
- name: etcd_proxy.urls
|
||||||
|
type: string or array of strings
|
||||||
|
type_ru: строка или массив строк
|
||||||
|
info: |
|
||||||
|
etcd URLs for Antietcd etcd proxy mode.
|
||||||
|
See [Mon as Etcd proxy](../intro/security.en.md#mon-as-etcd-proxy) for details.
|
||||||
|
info_ru: |
|
||||||
|
Адреса etcd для режима Antietcd etcd-прокси.
|
||||||
|
Смотрите подробности в разделе [Mon в роли Etcd proxy](../intro/security.ru.md#mon-в-роли-etcd-proxy).
|
||||||
|
- name: etcd_proxy.cert
|
||||||
|
type: string
|
||||||
|
info: Client certificate for Antietcd connections to etcd in proxy mode.
|
||||||
|
info_ru: Клиентский сертификат для подключений от Antietcd к etcd в режиме прокси.
|
||||||
|
- name: etcd_proxy.key
|
||||||
|
type: string
|
||||||
|
info: Private key for etcd_proxy.cert.
|
||||||
|
info_ru: Закрытый ключ для сертификата etcd_proxy.cert.
|
||||||
|
- name: etcd_proxy.ca
|
||||||
|
type: string
|
||||||
|
info: Trusted TLS CA to verify etcd server certificate when connecting to it from Antietcd.
|
||||||
|
info_ru: Доверенный TLS-сертификат для проверки сертификата сервера etcd при подключениях от Antietcd.
|
||||||
|
- name: osd_cert
|
||||||
|
type: string
|
||||||
|
info: |
|
||||||
|
Vitastor OSD server certificate. Required for Vitastor protocol encryption. May be equal
|
||||||
|
to [osd_ca](#osd_ca) - all OSDs share the same permission set for now. Also used as the client
|
||||||
|
certificate for connections from OSD to etcd/Antietcd by default.
|
||||||
|
info_ru: |
|
||||||
|
Сертификат сервера Vitastor OSD. Требуется для шифрования протокола Vitastor. Может быть равен
|
||||||
|
[osd_ca](#osd_ca) - все OSD на данный момент имеют одинаковые привилегии. Также по умолчанию
|
||||||
|
используется как клиентский сертификат для подключения от OSD к etcd/Antietcd.
|
||||||
|
- name: osd_pkey
|
||||||
|
type: string
|
||||||
|
info: Private key for osd_cert.
|
||||||
|
info_ru: Закрытый ключ для сертификата osd_cert.
|
||||||
|
- name: api_cert
|
||||||
|
type: string
|
||||||
|
info: Server TLS certificate for [vitastor-cli serve](../usage/cli.en.md#serve) API server.
|
||||||
|
info_ru: Серверный TLS-сертификат для API-сервера [vitastor-cli serve](../usage/cli.ru.md#serve).
|
||||||
|
- name: api_pkey
|
||||||
|
type: string
|
||||||
|
info: Private key for api_cert.
|
||||||
|
info_ru: Закрытый ключ для сертификата api_cert.
|
||||||
|
- name: etcd_client_cert
|
||||||
|
type: string
|
||||||
|
info: |
|
||||||
|
Client TLS certificate to use for connections from Vitastor clients to etcd/Antietcd if you don't want
|
||||||
|
to use the common client certificate [cert](#cert).
|
||||||
|
info_ru: |
|
||||||
|
Клиентский TLS сертификат для подключений от клиентов Vitastor к etcd/Antietcd, если вы не хотите
|
||||||
|
использовать общий клиентский сертификат [cert](#cert).
|
||||||
|
- name: etcd_client_key
|
||||||
|
type: string
|
||||||
|
info: Private key for etcd_client_cert.
|
||||||
|
info_ru: Закрытый ключ для сертификата etcd_client_cert.
|
||||||
|
- name: osd_etcd_client_cert
|
||||||
|
type: string
|
||||||
|
info: |
|
||||||
|
Client TLS certificate to use for connections from Vitastor OSDs to etcd/Antietcd if you don't want
|
||||||
|
to use the common OSD certificate [osd_cert](#osd_cert).
|
||||||
|
info_ru: |
|
||||||
|
Клиентский TLS сертификат для подключений от Vitastor OSD к etcd/Antietcd, если вы не хотите
|
||||||
|
использовать общий сертификат OSD [osd_cert](#osd_cert).
|
||||||
|
- name: osd_etcd_client_key
|
||||||
|
type: string
|
||||||
|
info: Private key for osd_etcd_client_cert.
|
||||||
|
info_ru: Закрытый ключ для сертификата osd_etcd_client_cert.
|
||||||
|
- name: mon_etcd_client_cert
|
||||||
|
type: string
|
||||||
|
info: |
|
||||||
|
Client TLS certificate to use for connections from Vitastor Monitors to etcd/Antietcd - required
|
||||||
|
if you don't use the built-in Antietcd. In case you use it Monitor has direct access to Antietcd data
|
||||||
|
and doesn't require any connection.
|
||||||
|
info_ru: |
|
||||||
|
Клиентский TLS сертификат для подключений от мониторов Vitastor к etcd/Antietcd - требуется, если
|
||||||
|
вы не используете встроенный в монитор Antietcd. Если вы используете его, то монитор и так имеет
|
||||||
|
прямой доступ к данным Antietcd и не требует никаких соединений.
|
||||||
|
- name: mon_etcd_client_key
|
||||||
|
type: string
|
||||||
|
info: Private key for mon_etcd_client_cert.
|
||||||
|
info_ru: Закрытый ключ для сертификата mon_etcd_client_cert.
|
||||||
|
- name: proto_checksums
|
||||||
|
type: string
|
||||||
|
default: payload
|
||||||
|
info: |
|
||||||
|
One of "full", "payload", "gcm", "none":
|
||||||
|
- "full" means calculate and verify transport level checksums from the full message data
|
||||||
|
including the header - recommended for unencrypted setups.
|
||||||
|
- "payload" enables checksums only for the actual read/write data, but skips them for message
|
||||||
|
headers - recommended for encrypted setups because headers are already protected by AES-GCM.
|
||||||
|
- "gcm" disables checksums and enables AES-GCM encryption of the whole messages including headers
|
||||||
|
and data - AES-GCM already includes MAC which is actually a stronger checksum. This option is
|
||||||
|
slower and is only recommended for untrusted networks.
|
||||||
|
- "none" disables transport level checksums at all.
|
||||||
|
info_ru: |
|
||||||
|
Одно из значений "full", "payload", "gcm" и "none":
|
||||||
|
- "full" означает расчёт и проверку контрольных сумм на транспортном уровне от полных сообщений,
|
||||||
|
включая их заголовки и данные - рекомендуется для кластеров без шифрования.
|
||||||
|
- "payload" включает контрольные суммы только для данных сообщений, но пропускает заголовки -
|
||||||
|
такая настройка рекомендуется для кластеров с включённым шифрованием, потому что в них заголовки
|
||||||
|
и так защищены шифрованием AES-GCM.
|
||||||
|
- "gcm" отключает контрольные суммы и включает шифрование полных сообщений включая заголовки и
|
||||||
|
данные - AES-GCM уже включает в себя MAC, который по сути является криптостойкой контрольной
|
||||||
|
суммой. Такая настройка медленнее и рекомендуется только для недоверенных сетей.
|
||||||
|
- "none" полностью отключает контрольные суммы на транспортном уровне.
|
||||||
|
- name: force_proto_checksums
|
||||||
|
type: string
|
||||||
|
info: |
|
||||||
|
To allow older clients to connect to a Vitastor cluster with enabled checksums, Vitastor OSDs
|
||||||
|
allow clients to downgrade their proto_checksums by default. force_proto_checksums sets the
|
||||||
|
minimum security level allowed for connecting clients. When encryption is disabled, default
|
||||||
|
force_proto_checksums is none and clients without checksums are allowed. With enabled
|
||||||
|
encryption, force_proto_checksums becomes "payload" by default to block unauthenticated data
|
||||||
|
on the transport level.
|
||||||
|
info_ru: |
|
||||||
|
Чтобы старые клиенты Vitastor могли подключаться к кластеру с включёнными контрольными
|
||||||
|
суммами, Vitastor OSD по умолчанию разрешают клиентам отключать контрольные суммы
|
||||||
|
данных (proto_checksums). Настройка force_proto_checksums задаёт минимальный уровень
|
||||||
|
безопасности, разрешённый для подключающихся клиентов. Когда шифрование отключено,
|
||||||
|
force_proto_checksums по умолчанию равно none и подключения клиентов без контрольных
|
||||||
|
сумм разрешаются. При включённом шифровании значение по умолчанию force_proto_checksums
|
||||||
|
становится "payload", чтобы блокировать подключения с неаутентифицированными данными.
|
||||||
|
- name: max_cipher_pool_size
|
||||||
|
type: int
|
||||||
|
default: 256
|
||||||
|
info: |
|
||||||
|
Maximum number of OpenSSL cipher contexts cached in OSD memory, counted separately
|
||||||
|
for each cipher and for encryption/decryption. Probably doesn't require modification.
|
||||||
|
info_ru: |
|
||||||
|
Максимальное количество кэшируемых в памяти OSD контекстов шифра OpenSSL, учитываемое
|
||||||
|
отдельно для каждого шифра и для шифрования и расшифровки. Вряд ли требует изменения.
|
||||||
|
- name: vault_url
|
||||||
|
type: string
|
||||||
|
info: |
|
||||||
|
Vault base URL.
|
||||||
|
|
||||||
|
Vitastor clients support AES-256-XTS image data encryption with different per-image keys.
|
||||||
|
Encryption is performed by the client, OSDs don't have access to decrypted data.
|
||||||
|
|
||||||
|
Encryption keys may be stored in etcd or, for the increased security level, in an external
|
||||||
|
[HashiCorp Vault](https://developer.hashicorp.com/vault/) or [OpenBao](https://openbao.org/)
|
||||||
|
instance.
|
||||||
|
|
||||||
|
Vitastor clients use [v1 k/v secrets engine](https://openbao.org/api-docs/secret/kv/kv-v1/)
|
||||||
|
and [TLS authentication engine](https://openbao.org/api-docs/auth/cert/) in Vault.
|
||||||
|
|
||||||
|
In that case, only key IDs are stored in etcd.
|
||||||
|
info_ru: |
|
||||||
|
Базовый адрес Vault.
|
||||||
|
|
||||||
|
Клиенты Vitastor поддерживают AES-256-XTS шифрование данных образов с отдельными ключами на
|
||||||
|
каждый образ. Данные шифруются клиентами, OSD не имеют доступа к незашифрованным данным.
|
||||||
|
|
||||||
|
Ключи шифрования могут храниться в etcd или, для повышенного уровня безопасности, во внешнем
|
||||||
|
[HashiCorp Vault](https://developer.hashicorp.com/vault/) или [OpenBao](https://openbao.org/).
|
||||||
|
|
||||||
|
Клиенты Vitastor используют [движок секретов v1](https://openbao.org/api-docs/secret/kv/kv-v1/)
|
||||||
|
и [TLS-аутентификацию](https://openbao.org/api-docs/auth/cert/) в Vault.
|
||||||
|
|
||||||
|
В этом случае, только ID ключей хранятся в etcd.
|
||||||
|
- name: vault_secret_api_path
|
||||||
|
type: string
|
||||||
|
default: /v1/secret/
|
||||||
|
info: Vault v1 secret API mount path to use.
|
||||||
|
info_ru: Путь к API секретов v1 для использования клиентами.
|
||||||
|
- name: vault_client_cert
|
||||||
|
type: string
|
||||||
|
info: |
|
||||||
|
Client TLS certificate to use for Vault connections if you don't want to use the common Vitastor
|
||||||
|
client certificate [cert](#cert) which is also used for Vault connections by default.
|
||||||
|
info_ru: |
|
||||||
|
Клиентский TLS сертификат для подключений к Vault на тот случай, если вы не хотите использовать
|
||||||
|
общий сертификат клиента Vitastor [cert](#cert), используемый для подключений к Vault по умолчанию.
|
||||||
|
- name: vault_client_key
|
||||||
|
type: string
|
||||||
|
info: Private key for the vault_client_cert certificate.
|
||||||
|
info_ru: Закрытый ключ для сертификата vault_client_cert.
|
||||||
|
- name: vault_ca
|
||||||
|
type: string
|
||||||
|
info: |
|
||||||
|
Trusted TLS CA to verify Vault server certificate. May be path to a file,
|
||||||
|
directory or just a PEM string with certificate.
|
||||||
|
info_ru: |
|
||||||
|
Доверенный корневой TLS-сертификат для проверки сертификата сервера Vault.
|
||||||
|
Может быть путём к файлу, директории или просто строкой с сертификатом в
|
||||||
|
формате PEM.
|
||||||
|
- name: vault_timeout_ms
|
||||||
|
type: int
|
||||||
|
default: 5000
|
||||||
|
info: Timeout for Vault requests in milliseconds.
|
||||||
|
info_ru: Максимально время выполнения Vault-запросов в миллисекундах.
|
||||||
|
- name: vault_error_timeout_sec
|
||||||
|
type: int
|
||||||
|
default: 60
|
||||||
|
info: |
|
||||||
|
Time (in seconds) to wait before retrying after receiving an error from Vault.
|
||||||
|
info_ru: |
|
||||||
|
Время (в секундах) для ожидания перед повторной попыткой при получении ошибки от Vault.
|
||||||
|
- name: vault_refresh_leeway_sec
|
||||||
|
type: int
|
||||||
|
default: 60
|
||||||
|
info: |
|
||||||
|
Extra time (in seconds) before real Vault token lease_timeout to refresh it, just
|
||||||
|
in case of system clock drift.
|
||||||
|
info_ru: |
|
||||||
|
Зазор времени (в секундах), чтобы обновлять токены Vault чуть раньше их реального
|
||||||
|
lease_timeout, на случай "ухода" системных часов.
|
||||||
@@ -26,13 +26,37 @@ at Vitastor Kubernetes operator: https://github.com/Antilles7227/vitastor-operat
|
|||||||
The instruction is very simple.
|
The instruction is very simple.
|
||||||
|
|
||||||
1. Download a Docker image of the desired version: \
|
1. Download a Docker image of the desired version: \
|
||||||
`docker pull vitastor:v2.2.2`
|
`docker pull vitalif/vitastor:v3.0.15`
|
||||||
2. Install scripts to the host system: \
|
2. Install scripts to the host system: \
|
||||||
`docker run --rm -it -v /etc:/host-etc -v /usr/bin:/host-bin vitastor:v2.2.2 install.sh`
|
`docker run --rm -it -v /etc:/host-etc -v /usr/bin:/host-bin vitalif/vitastor:v3.0.15 install.sh`
|
||||||
3. Reload udev rules: \
|
3. Reload udev rules: \
|
||||||
`udevadm control --reload-rules`
|
`udevadm control --reload-rules`
|
||||||
|
4. Enable the vitastor-host service: \
|
||||||
|
`systemctl enable --now vitastor-host`
|
||||||
|
|
||||||
And you can return to [Quick Start](../intro/quickstart.en.md).
|
After these steps, you can return to [Quick Start](../intro/quickstart.en.md).
|
||||||
|
|
||||||
|
## Podman
|
||||||
|
|
||||||
|
If you use Podman, run the following commands as root before installing Vitastor containers:
|
||||||
|
|
||||||
|
```
|
||||||
|
ln -s podman /usr/bin/docker
|
||||||
|
|
||||||
|
mkdir -p /etc/systemd/system/systemd-udevd.service.d
|
||||||
|
|
||||||
|
cat >/etc/systemd/system/systemd-udevd.service.d/override.conf <<EOF
|
||||||
|
[Service]
|
||||||
|
CapabilityBoundingSet=~
|
||||||
|
SystemCallFilter=@mount capset
|
||||||
|
EOF
|
||||||
|
|
||||||
|
systemctl daemon-reload
|
||||||
|
|
||||||
|
systemctl restart systemd-udevd
|
||||||
|
```
|
||||||
|
|
||||||
|
Without it, udev fails to do calls into a Podman container and Vitastor disk detection doesn't work.
|
||||||
|
|
||||||
## Upgrading Containers
|
## Upgrading Containers
|
||||||
|
|
||||||
|
|||||||
@@ -25,14 +25,39 @@ Vitastor можно установить в Docker/Podman. При этом etcd,
|
|||||||
Инструкция по установке максимально простая.
|
Инструкция по установке максимально простая.
|
||||||
|
|
||||||
1. Скачайте Docker-образ желаемой версии: \
|
1. Скачайте Docker-образ желаемой версии: \
|
||||||
`docker pull vitastor:v2.2.2`
|
`docker pull vitalif/vitastor:v3.0.15`
|
||||||
2. Установите скрипты в хост-систему командой: \
|
2. Установите скрипты в хост-систему командой: \
|
||||||
`docker run --rm -it -v /etc:/host-etc -v /usr/bin:/host-bin vitastor:v2.2.2 install.sh`
|
`docker run --rm -it -v /etc:/host-etc -v /usr/bin:/host-bin vitalif/vitastor:v3.0.15 install.sh`
|
||||||
3. Перезагрузите правила udev: \
|
3. Перезагрузите правила udev: \
|
||||||
`udevadm control --reload-rules`
|
`udevadm control --reload-rules`
|
||||||
|
4. Включите сервис vitastor-host: \
|
||||||
|
`systemctl enable --now vitastor-host`
|
||||||
|
|
||||||
После этого вы можете возвращаться к разделу [Быстрый старт](../intro/quickstart.ru.md).
|
После этого вы можете возвращаться к разделу [Быстрый старт](../intro/quickstart.ru.md).
|
||||||
|
|
||||||
|
## Podman
|
||||||
|
|
||||||
|
Если вы используете Podman, перед установкой контейнеров Vitastor выполните следующие
|
||||||
|
команды от имени суперпользователя:
|
||||||
|
|
||||||
|
```
|
||||||
|
ln -s podman /usr/bin/docker
|
||||||
|
|
||||||
|
mkdir -p /etc/systemd/system/systemd-udevd.service.d
|
||||||
|
|
||||||
|
cat >/etc/systemd/system/systemd-udevd.service.d/override.conf <<EOF
|
||||||
|
[Service]
|
||||||
|
CapabilityBoundingSet=~
|
||||||
|
SystemCallFilter=@mount capset
|
||||||
|
EOF
|
||||||
|
|
||||||
|
systemctl daemon-reload
|
||||||
|
|
||||||
|
systemctl restart systemd-udevd
|
||||||
|
```
|
||||||
|
|
||||||
|
Без этих настроек udev не может делать вызовы внутрь Podman-контейнеров и определение дисков Vitastor не работает.
|
||||||
|
|
||||||
## Обновление контейнеров
|
## Обновление контейнеров
|
||||||
|
|
||||||
Сначала обязательно проверьте раздел [Обновление Vitastor](../usage/admin.ru.md#обновление-vitastor),
|
Сначала обязательно проверьте раздел [Обновление Vitastor](../usage/admin.ru.md#обновление-vitastor),
|
||||||
|
|||||||
@@ -30,7 +30,7 @@ volume_backend_name = vitastor-testcluster
|
|||||||
image_volume_cache_enabled = True
|
image_volume_cache_enabled = True
|
||||||
volume_clear = none
|
volume_clear = none
|
||||||
vitastor_etcd_address = 192.168.7.2:2379
|
vitastor_etcd_address = 192.168.7.2:2379
|
||||||
vitastor_etcd_prefix =
|
vitastor_etcd_prefix = /vitastor
|
||||||
vitastor_config_path = /etc/vitastor/vitastor.conf
|
vitastor_config_path = /etc/vitastor/vitastor.conf
|
||||||
vitastor_pool_id = 1
|
vitastor_pool_id = 1
|
||||||
image_upload_use_cinder_backend = True
|
image_upload_use_cinder_backend = True
|
||||||
|
|||||||
@@ -29,7 +29,7 @@ volume_backend_name = vitastor-testcluster
|
|||||||
image_volume_cache_enabled = True
|
image_volume_cache_enabled = True
|
||||||
volume_clear = none
|
volume_clear = none
|
||||||
vitastor_etcd_address = 192.168.7.2:2379
|
vitastor_etcd_address = 192.168.7.2:2379
|
||||||
vitastor_etcd_prefix =
|
vitastor_etcd_prefix = /vitastor
|
||||||
vitastor_config_path = /etc/vitastor/vitastor.conf
|
vitastor_config_path = /etc/vitastor/vitastor.conf
|
||||||
vitastor_pool_id = 1
|
vitastor_pool_id = 1
|
||||||
image_upload_use_cinder_backend = True
|
image_upload_use_cinder_backend = True
|
||||||
|
|||||||
@@ -11,12 +11,21 @@
|
|||||||
- Trust Vitastor package signing key:
|
- Trust Vitastor package signing key:
|
||||||
`wget https://vitastor.io/debian/pubkey.gpg -O /etc/apt/trusted.gpg.d/vitastor.gpg`
|
`wget https://vitastor.io/debian/pubkey.gpg -O /etc/apt/trusted.gpg.d/vitastor.gpg`
|
||||||
- Add Vitastor package repository to your /etc/apt/sources.list:
|
- Add Vitastor package repository to your /etc/apt/sources.list:
|
||||||
- Debian 12 (Bookworm/Sid): `deb https://vitastor.io/debian bookworm main`
|
- Debian 13 (Trixie/Sid): `deb https://vitastor.io/debian trixie main`
|
||||||
|
- Debian 12 (Bookworm): `deb https://vitastor.io/debian bookworm main`
|
||||||
- Debian 11 (Bullseye): `deb https://vitastor.io/debian bullseye main`
|
- Debian 11 (Bullseye): `deb https://vitastor.io/debian bullseye main`
|
||||||
- Debian 10 (Buster): `deb https://vitastor.io/debian buster main`
|
- Debian 10 (Buster): `deb https://vitastor.io/debian buster main`
|
||||||
- Ubuntu 22.04 (Jammy): `deb https://vitastor.io/debian jammy main`
|
- Ubuntu 22.04 (Jammy): `deb https://vitastor.io/debian jammy main`
|
||||||
|
- Ubuntu 24.04 (Noble): `deb https://vitastor.io/debian noble main`
|
||||||
|
- Ubuntu 26.04 (Resolute): `deb https://vitastor.io/debian resolute main`
|
||||||
- Add `-oldstable` to bookworm/bullseye/buster in this line to install the last
|
- Add `-oldstable` to bookworm/bullseye/buster in this line to install the last
|
||||||
stable version from 0.9.x branch instead of 1.x
|
stable version from 0.9.x branch instead of 1.x
|
||||||
|
- To always prefer vitastor-patched QEMU and Libvirt versions, add the following to `/etc/apt/preferences`:
|
||||||
|
```
|
||||||
|
Package: *
|
||||||
|
Pin: origin "vitastor.io"
|
||||||
|
Pin-Priority: 501
|
||||||
|
```
|
||||||
- Install packages: `apt update; apt install vitastor lp-solve etcd linux-image-amd64 qemu-system-x86`
|
- Install packages: `apt update; apt install vitastor lp-solve etcd linux-image-amd64 qemu-system-x86`
|
||||||
|
|
||||||
## CentOS
|
## CentOS
|
||||||
@@ -25,15 +34,17 @@
|
|||||||
- CentOS 7: `yum install https://vitastor.io/rpms/centos/7/vitastor-release.rpm`
|
- CentOS 7: `yum install https://vitastor.io/rpms/centos/7/vitastor-release.rpm`
|
||||||
- CentOS 8: `dnf install https://vitastor.io/rpms/centos/8/vitastor-release.rpm`
|
- CentOS 8: `dnf install https://vitastor.io/rpms/centos/8/vitastor-release.rpm`
|
||||||
- AlmaLinux 9 and other RHEL 9 clones (Rocky, Oracle...): `dnf install https://vitastor.io/rpms/centos/9/vitastor-release.rpm`
|
- AlmaLinux 9 and other RHEL 9 clones (Rocky, Oracle...): `dnf install https://vitastor.io/rpms/centos/9/vitastor-release.rpm`
|
||||||
|
- AlmaLinux 10 and other RHEL 10 clones: `dnf install https://vitastor.io/rpms/centos/10/vitastor-release.rpm`
|
||||||
- Enable EPEL: `yum/dnf install epel-release`
|
- Enable EPEL: `yum/dnf install epel-release`
|
||||||
- Enable additional CentOS repositories:
|
- Enable additional CentOS repositories:
|
||||||
- CentOS 7: `yum install centos-release-scl`
|
- CentOS 7: `yum install centos-release-scl`
|
||||||
- CentOS 8: `dnf install centos-release-advanced-virtualization`
|
- CentOS 8: `dnf install centos-release-advanced-virtualization`
|
||||||
- RHEL 9 clones: not required
|
- RHEL 9/10 clones: not required
|
||||||
- Enable elrepo-kernel:
|
- Enable elrepo-kernel:
|
||||||
- CentOS 7: `yum install https://www.elrepo.org/elrepo-release-7.el7.elrepo.noarch.rpm`
|
- CentOS 7: `yum install https://www.elrepo.org/elrepo-release-7.el7.elrepo.noarch.rpm`
|
||||||
- CentOS 8: `dnf install https://www.elrepo.org/elrepo-release-8.el8.elrepo.noarch.rpm`
|
- CentOS 8: `dnf install https://www.elrepo.org/elrepo-release-8.el8.elrepo.noarch.rpm`
|
||||||
- RHEL 9 clones: `dnf install https://www.elrepo.org/elrepo-release-9.el9.elrepo.noarch.rpm`
|
- RHEL 9 clones: `dnf install https://www.elrepo.org/elrepo-release-9.el9.elrepo.noarch.rpm`
|
||||||
|
- RHEL 10 clones: not required
|
||||||
- Install packages: `yum/dnf install vitastor lpsolve etcd kernel-ml qemu-kvm`
|
- Install packages: `yum/dnf install vitastor lpsolve etcd kernel-ml qemu-kvm`
|
||||||
|
|
||||||
## Installation requirements
|
## Installation requirements
|
||||||
@@ -42,7 +53,6 @@
|
|||||||
recommended because io_uring is a relatively new technology and there is
|
recommended because io_uring is a relatively new technology and there is
|
||||||
at least one bug which reproduces with io_uring and HP SmartArray
|
at least one bug which reproduces with io_uring and HP SmartArray
|
||||||
controllers in 5.4
|
controllers in 5.4
|
||||||
- liburing 0.4 or newer
|
|
||||||
- lp_solve
|
- lp_solve
|
||||||
- etcd 3.4.15 or newer. Earlier versions won't work because of various bugs,
|
- etcd 3.4.15 or newer. Earlier versions won't work because of various bugs,
|
||||||
for example [#12402](https://github.com/etcd-io/etcd/pull/12402).
|
for example [#12402](https://github.com/etcd-io/etcd/pull/12402).
|
||||||
|
|||||||
@@ -11,12 +11,21 @@
|
|||||||
- Добавьте ключ репозитория Vitastor:
|
- Добавьте ключ репозитория Vitastor:
|
||||||
`wget https://vitastor.io/debian/pubkey.gpg -O /etc/apt/trusted.gpg.d/vitastor.gpg`
|
`wget https://vitastor.io/debian/pubkey.gpg -O /etc/apt/trusted.gpg.d/vitastor.gpg`
|
||||||
- Добавьте репозиторий Vitastor в /etc/apt/sources.list:
|
- Добавьте репозиторий Vitastor в /etc/apt/sources.list:
|
||||||
- Debian 12 (Bookworm/Sid): `deb https://vitastor.io/debian bookworm main`
|
- Debian 13 (Trixie/Sid): `deb https://vitastor.io/debian trixie main`
|
||||||
|
- Debian 12 (Bookworm): `deb https://vitastor.io/debian bookworm main`
|
||||||
- Debian 11 (Bullseye): `deb https://vitastor.io/debian bullseye main`
|
- Debian 11 (Bullseye): `deb https://vitastor.io/debian bullseye main`
|
||||||
- Debian 10 (Buster): `deb https://vitastor.io/debian buster main`
|
- Debian 10 (Buster): `deb https://vitastor.io/debian buster main`
|
||||||
- Ubuntu 22.04 (Jammy): `deb https://vitastor.io/debian jammy main`
|
- Ubuntu 22.04 (Jammy): `deb https://vitastor.io/debian jammy main`
|
||||||
|
- Ubuntu 24.04 (Noble): `deb https://vitastor.io/debian noble main`
|
||||||
|
- Ubuntu 26.04 (Resolute): `deb https://vitastor.io/debian resolute main`
|
||||||
- Добавьте `-oldstable` к слову bookworm/bullseye/buster в этой строке, чтобы
|
- Добавьте `-oldstable` к слову bookworm/bullseye/buster в этой строке, чтобы
|
||||||
установить последнюю стабильную версию из ветки 0.9.x вместо 1.x
|
установить последнюю стабильную версию из ветки 0.9.x вместо 1.x
|
||||||
|
- Чтобы всегда предпочитались версии пакетов QEMU и Libvirt с патчами Vitastor, добавьте в `/etc/apt/preferences`:
|
||||||
|
```
|
||||||
|
Package: *
|
||||||
|
Pin: origin "vitastor.io"
|
||||||
|
Pin-Priority: 501
|
||||||
|
```
|
||||||
- Установите пакеты: `apt update; apt install vitastor lp-solve etcd linux-image-amd64 qemu-system-x86`
|
- Установите пакеты: `apt update; apt install vitastor lp-solve etcd linux-image-amd64 qemu-system-x86`
|
||||||
|
|
||||||
## CentOS
|
## CentOS
|
||||||
@@ -25,15 +34,17 @@
|
|||||||
- CentOS 7: `yum install https://vitastor.io/rpms/centos/7/vitastor-release.rpm`
|
- CentOS 7: `yum install https://vitastor.io/rpms/centos/7/vitastor-release.rpm`
|
||||||
- CentOS 8: `dnf install https://vitastor.io/rpms/centos/8/vitastor-release.rpm`
|
- CentOS 8: `dnf install https://vitastor.io/rpms/centos/8/vitastor-release.rpm`
|
||||||
- AlmaLinux 9 и другие клоны RHEL 9 (Rocky, Oracle...): `dnf install https://vitastor.io/rpms/centos/9/vitastor-release.rpm`
|
- AlmaLinux 9 и другие клоны RHEL 9 (Rocky, Oracle...): `dnf install https://vitastor.io/rpms/centos/9/vitastor-release.rpm`
|
||||||
|
- AlmaLinux 10 и другие клоны RHEL 10: `dnf install https://vitastor.io/rpms/centos/10/vitastor-release.rpm`
|
||||||
- Включите EPEL: `yum/dnf install epel-release`
|
- Включите EPEL: `yum/dnf install epel-release`
|
||||||
- Включите дополнительные репозитории CentOS:
|
- Включите дополнительные репозитории CentOS:
|
||||||
- CentOS 7: `yum install centos-release-scl`
|
- CentOS 7: `yum install centos-release-scl`
|
||||||
- CentOS 8: `dnf install centos-release-advanced-virtualization`
|
- CentOS 8: `dnf install centos-release-advanced-virtualization`
|
||||||
- Клоны RHEL 9: не нужно
|
- Клоны RHEL 9/10: не нужно
|
||||||
- Включите elrepo-kernel:
|
- Включите elrepo-kernel:
|
||||||
- CentOS 7: `yum install https://www.elrepo.org/elrepo-release-7.el7.elrepo.noarch.rpm`
|
- CentOS 7: `yum install https://www.elrepo.org/elrepo-release-7.el7.elrepo.noarch.rpm`
|
||||||
- CentOS 8: `dnf install https://www.elrepo.org/elrepo-release-8.el8.elrepo.noarch.rpm`
|
- CentOS 8: `dnf install https://www.elrepo.org/elrepo-release-8.el8.elrepo.noarch.rpm`
|
||||||
- Клоны RHEL 9: `dnf install https://www.elrepo.org/elrepo-release-9.el9.elrepo.noarch.rpm`
|
- Клоны RHEL 9: `dnf install https://www.elrepo.org/elrepo-release-9.el9.elrepo.noarch.rpm`
|
||||||
|
- Клоны RHEL 10: не нужно
|
||||||
- Установите пакеты: `yum/dnf install vitastor lpsolve etcd kernel-ml qemu-kvm`
|
- Установите пакеты: `yum/dnf install vitastor lpsolve etcd kernel-ml qemu-kvm`
|
||||||
|
|
||||||
## Установочные требования
|
## Установочные требования
|
||||||
@@ -41,7 +52,6 @@
|
|||||||
- Ядро Linux 5.4 или новее, для поддержки io_uring. Рекомендуется даже 5.8,
|
- Ядро Linux 5.4 или новее, для поддержки io_uring. Рекомендуется даже 5.8,
|
||||||
так как io_uring - относительно новый интерфейс и в версиях до 5.8 встречались
|
так как io_uring - относительно новый интерфейс и в версиях до 5.8 встречались
|
||||||
некоторые баги, например, зависание с io_uring и контроллером HP SmartArray
|
некоторые баги, например, зависание с io_uring и контроллером HP SmartArray
|
||||||
- liburing 0.4 или новее
|
|
||||||
- lp_solve
|
- lp_solve
|
||||||
- etcd 3.4.15 или новее. Более старые версии не будут работать из-за разных багов,
|
- etcd 3.4.15 или новее. Более старые версии не будут работать из-за разных багов,
|
||||||
например, [#12402](https://github.com/etcd-io/etcd/pull/12402).
|
например, [#12402](https://github.com/etcd-io/etcd/pull/12402).
|
||||||
|
|||||||
@@ -6,10 +6,10 @@
|
|||||||
|
|
||||||
# Proxmox VE
|
# Proxmox VE
|
||||||
|
|
||||||
To enable Vitastor support in Proxmox Virtual Environment (6.4-8.x are supported):
|
To enable Vitastor support in Proxmox Virtual Environment (6.4-9.x are supported):
|
||||||
|
|
||||||
- Add the corresponding Vitastor Debian repository into sources.list on Proxmox hosts:
|
- Add the corresponding Vitastor Debian repository into sources.list on Proxmox hosts:
|
||||||
bookworm for 8.1+, pve8.0 for 8.0, bullseye for 7.4, pve7.3 for 7.3, pve7.2 for 7.2, pve7.1 for 7.1, buster for 6.4
|
trixie for 9.0+, bookworm for 8.1+, pve8.0 for 8.0, bullseye for 7.4, pve7.3 for 7.3, pve7.2 for 7.2, pve7.1 for 7.1, buster for 6.4
|
||||||
- Install vitastor-client, pve-qemu-kvm, pve-storage-vitastor (* or see note) packages from Vitastor repository
|
- Install vitastor-client, pve-qemu-kvm, pve-storage-vitastor (* or see note) packages from Vitastor repository
|
||||||
- Define storage in `/etc/pve/storage.cfg` (see below)
|
- Define storage in `/etc/pve/storage.cfg` (see below)
|
||||||
- Block network access from VMs to Vitastor network (to OSDs and etcd),
|
- Block network access from VMs to Vitastor network (to OSDs and etcd),
|
||||||
|
|||||||
@@ -6,10 +6,10 @@
|
|||||||
|
|
||||||
# Proxmox VE
|
# Proxmox VE
|
||||||
|
|
||||||
Чтобы подключить Vitastor к Proxmox Virtual Environment (поддерживаются версии 6.4-8.x):
|
Чтобы подключить Vitastor к Proxmox Virtual Environment (поддерживаются версии 6.4-9.x):
|
||||||
|
|
||||||
- Добавьте соответствующий Debian-репозиторий Vitastor в sources.list на хостах Proxmox:
|
- Добавьте соответствующий Debian-репозиторий Vitastor в sources.list на хостах Proxmox:
|
||||||
bookworm для 8.1+, pve8.0 для 8.0, bullseye для 7.4, pve7.3 для 7.3, pve7.2 для 7.2, pve7.1 для 7.1, buster для 6.4
|
trixie для 9.0+, bookworm для 8.1+, pve8.0 для 8.0, bullseye для 7.4, pve7.3 для 7.3, pve7.2 для 7.2, pve7.1 для 7.1, buster для 6.4
|
||||||
- Установите пакеты vitastor-client, pve-qemu-kvm, pve-storage-vitastor (* или см. сноску) из репозитория Vitastor
|
- Установите пакеты vitastor-client, pve-qemu-kvm, pve-storage-vitastor (* или см. сноску) из репозитория Vitastor
|
||||||
- Определите тип хранилища в `/etc/pve/storage.cfg` (см. ниже)
|
- Определите тип хранилища в `/etc/pve/storage.cfg` (см. ниже)
|
||||||
- Обязательно заблокируйте доступ от виртуальных машин к сети Vitastor (OSD и etcd), т.к. Vitastor (пока) не поддерживает аутентификацию
|
- Обязательно заблокируйте доступ от виртуальных машин к сети Vitastor (OSD и etcd), т.к. Vitastor (пока) не поддерживает аутентификацию
|
||||||
|
|||||||
@@ -15,9 +15,8 @@
|
|||||||
- gcc and g++ 8 or newer, clang 10 or newer, or other compiler with C++11 plus
|
- gcc and g++ 8 or newer, clang 10 or newer, or other compiler with C++11 plus
|
||||||
designated initializers support from C++20
|
designated initializers support from C++20
|
||||||
- CMake
|
- CMake
|
||||||
- liburing, jerasure headers and libraries
|
- jerasure, c-ares headers and libraries
|
||||||
- ISA-L, libibverbs and librdmacm headers and libraries (optional)
|
- ISA-L, libibverbs, librdmacm, libnl3 headers and libraries (optional)
|
||||||
- tcmalloc (google-perftools-dev)
|
|
||||||
|
|
||||||
## Basic instructions
|
## Basic instructions
|
||||||
|
|
||||||
|
|||||||
@@ -15,9 +15,8 @@
|
|||||||
- gcc и g++ >= 8, либо clang >= 10, либо другой компилятор с поддержкой C++11 плюс
|
- gcc и g++ >= 8, либо clang >= 10, либо другой компилятор с поддержкой C++11 плюс
|
||||||
назначенных инициализаторов (designated initializers) из C++20
|
назначенных инициализаторов (designated initializers) из C++20
|
||||||
- CMake
|
- CMake
|
||||||
- Заголовки и библиотеки liburing, jerasure
|
- Заголовки и библиотеки jerasure, c-ares
|
||||||
- Опционально - заголовки и библиотеки ISA-L, libibverbs, librdmacm
|
- Опционально - заголовки и библиотеки ISA-L, libibverbs, librdmacm, libnl3
|
||||||
- tcmalloc (google-perftools-dev)
|
|
||||||
|
|
||||||
## Базовая инструкция
|
## Базовая инструкция
|
||||||
|
|
||||||
|
|||||||
@@ -14,6 +14,8 @@
|
|||||||
|
|
||||||
- Basic part: highly-available block storage with symmetric clustering and no SPOF
|
- Basic part: highly-available block storage with symmetric clustering and no SPOF
|
||||||
- [Performance](../performance/bench2.en.md) ;-D
|
- [Performance](../performance/bench2.en.md) ;-D
|
||||||
|
- [NVMe atomic write support](../config/osd.en.md#atomic_write_size) for reducing the amount
|
||||||
|
of "extra" disk writes to almost zero (Write Amplification = 1)
|
||||||
- [Multiple redundancy schemes](../config/pool.en.md#scheme): Replication, XOR n+1, Reed-Solomon erasure codes
|
- [Multiple redundancy schemes](../config/pool.en.md#scheme): Replication, XOR n+1, Reed-Solomon erasure codes
|
||||||
based on jerasure and ISA-L libraries with any number of data and parity drives in a group
|
based on jerasure and ISA-L libraries with any number of data and parity drives in a group
|
||||||
- Configuration via simple JSON data structures in etcd (parameters, pools and images)
|
- Configuration via simple JSON data structures in etcd (parameters, pools and images)
|
||||||
@@ -39,6 +41,8 @@
|
|||||||
- [Built-in Prometheus metric exporter](../config/monitor.en.md#enable_prometheus)
|
- [Built-in Prometheus metric exporter](../config/monitor.en.md#enable_prometheus)
|
||||||
- [NFS RDMA support](../usage/nfs.en.md#rdma) (probably also usable for GPUDirect)
|
- [NFS RDMA support](../usage/nfs.en.md#rdma) (probably also usable for GPUDirect)
|
||||||
- [S3](../installation/s3.en.md)
|
- [S3](../installation/s3.en.md)
|
||||||
|
- [TLS support for etcd connections](../config/security.en.md)
|
||||||
|
- [AES-256-XTS image encryption](../usage/cli.en.md#create) and [Vault support](../config/security.en.md#vault_url) for key storage
|
||||||
|
|
||||||
## Plugins and tools
|
## Plugins and tools
|
||||||
|
|
||||||
@@ -52,7 +56,7 @@
|
|||||||
- Generic user-space client library
|
- Generic user-space client library
|
||||||
- [Native QEMU driver](../usage/qemu.en.md)
|
- [Native QEMU driver](../usage/qemu.en.md)
|
||||||
- [Loadable fio engine for benchmarks](../usage/fio.en.md)
|
- [Loadable fio engine for benchmarks](../usage/fio.en.md)
|
||||||
- [NBD proxy for kernel mounts](../usage/nbd.en.md)
|
- [UBLK](../usage/ublk.en.md) and [NBD](../usage/nbd.en.md) servers for kernel mounts
|
||||||
- [Simplified NFS proxy for file-based image access emulation (suitable for VMWare)](../usage/nfs.en.md#pseudo-fs)
|
- [Simplified NFS proxy for file-based image access emulation (suitable for VMWare)](../usage/nfs.en.md#pseudo-fs)
|
||||||
|
|
||||||
## Roadmap
|
## Roadmap
|
||||||
|
|||||||
@@ -14,6 +14,8 @@
|
|||||||
|
|
||||||
- Базовая часть - надёжное кластерное блочное хранилище без единой точки отказа
|
- Базовая часть - надёжное кластерное блочное хранилище без единой точки отказа
|
||||||
- [Производительность](../performance/bench2.ru.md) ;-D
|
- [Производительность](../performance/bench2.ru.md) ;-D
|
||||||
|
- [Поддержка атомарной записи NVMe](../config/osd.ru.md#atomic_write_size) для снижения объёма
|
||||||
|
служебной записи практически до нуля (Write Amplification = 1)
|
||||||
- [Несколько схем отказоустойчивости](../config/pool.ru.md#scheme): репликация, XOR n+1 (1 диск чётности), коды коррекции ошибок
|
- [Несколько схем отказоустойчивости](../config/pool.ru.md#scheme): репликация, XOR n+1 (1 диск чётности), коды коррекции ошибок
|
||||||
Рида-Соломона на основе библиотек jerasure и ISA-L с любым числом дисков данных и чётности в группе
|
Рида-Соломона на основе библиотек jerasure и ISA-L с любым числом дисков данных и чётности в группе
|
||||||
- Конфигурация через простые человекочитаемые JSON-структуры в etcd
|
- Конфигурация через простые человекочитаемые JSON-структуры в etcd
|
||||||
@@ -41,6 +43,8 @@
|
|||||||
- [Встроенный Prometheus-экспортер метрик](../config/monitor.ru.md#enable_prometheus)
|
- [Встроенный Prometheus-экспортер метрик](../config/monitor.ru.md#enable_prometheus)
|
||||||
- [Поддержка NFS RDMA](../usage/nfs.ru.md#rdma) (вероятно, также подходящая для GPUDirect)
|
- [Поддержка NFS RDMA](../usage/nfs.ru.md#rdma) (вероятно, также подходящая для GPUDirect)
|
||||||
- [S3](../installation/s3.ru.md)
|
- [S3](../installation/s3.ru.md)
|
||||||
|
- [Поддержка TLS-соединений с etcd](../config/security.ru.md)
|
||||||
|
- [AES-256-XTS шифрование данных](../usage/cli.ru.md#create) и [поддержка Vault](../config/security.ru.md#vault_url) для хранения ключей
|
||||||
|
|
||||||
## Драйверы и инструменты
|
## Драйверы и инструменты
|
||||||
|
|
||||||
@@ -54,7 +58,7 @@
|
|||||||
- Общая пользовательская клиентская библиотека для работы с кластером
|
- Общая пользовательская клиентская библиотека для работы с кластером
|
||||||
- [Драйвер диска для QEMU](../usage/qemu.ru.md)
|
- [Драйвер диска для QEMU](../usage/qemu.ru.md)
|
||||||
- [Драйвер диска для утилиты тестирования производительности fio](../usage/fio.ru.md)
|
- [Драйвер диска для утилиты тестирования производительности fio](../usage/fio.ru.md)
|
||||||
- [NBD-прокси для монтирования образов ядром](../usage/nbd.ru.md) ("блочное устройство в режиме пользователя")
|
- [UBLK](../usage/ublk.ru.md) и [NBD](../usage/nbd.ru.md) серверы для монтирования образов ядром ("блочное устройство в режиме пользователя")
|
||||||
- [Упрощённая NFS-прокси для эмуляции файлового доступа к образам (подходит для VMWare)](../usage/nfs.ru.md#псевдо-фс)
|
- [Упрощённая NFS-прокси для эмуляции файлового доступа к образам (подходит для VMWare)](../usage/nfs.ru.md#псевдо-фс)
|
||||||
|
|
||||||
## Планы развития
|
## Планы развития
|
||||||
|
|||||||
@@ -18,9 +18,10 @@
|
|||||||
|
|
||||||
## Preparation
|
## Preparation
|
||||||
|
|
||||||
- Get some SATA or NVMe SSDs with capacitors (server-grade drives). You can use desktop SSDs
|
- Get some SATA or NVMe SSDs with capacitors (server-grade drives). The best performance
|
||||||
with lazy fsync, but prepare for inferior single-thread latency. Read more about capacitors
|
is achieved with Micron or Kioxia NVMes with atomic write support (see below). You can use desktop
|
||||||
[here](../config/layout-cluster.en.md#immediate_commit).
|
SSDs with lazy fsync, but prepare for inferior single-thread latency. Read more about
|
||||||
|
capacitors [here](../config/layout-cluster.en.md#immediate_commit).
|
||||||
- If you want to use HDDs, get modern HDDs with Media Cache or SSD Cache: HGST Ultrastar,
|
- If you want to use HDDs, get modern HDDs with Media Cache or SSD Cache: HGST Ultrastar,
|
||||||
Toshiba MG, Seagate EXOS or something similar. If your drives don't have such cache then
|
Toshiba MG, Seagate EXOS or something similar. If your drives don't have such cache then
|
||||||
you also need small SSDs for journal and metadata (even 2 GB per 1 TB of HDD space is enough).
|
you also need small SSDs for journal and metadata (even 2 GB per 1 TB of HDD space is enough).
|
||||||
@@ -30,20 +31,26 @@
|
|||||||
|
|
||||||
## Recommended drives
|
## Recommended drives
|
||||||
|
|
||||||
- SATA SSD: Micron 5100/5200/5300/5400, Samsung PM863/PM883/PM893, Intel D3-S4510/4520/4610/4620, Kingston DC500M
|
- NVMe with atomic write support (ideal!): Micron 7450/7500/7550, Kioxia CD6/CD7/CD8/CD9
|
||||||
- NVMe: Micron 9100/9200/9300/9400, Micron 7300/7450, Samsung PM983/PM9A3, Samsung PM1723/1735/1743,
|
- Other NVMe: Micron 9100/9200/9300/9400/9550, Micron 7300, Samsung PM983/PM9A3, Samsung PM1723/1735/1743,
|
||||||
Intel DC-P3700/P4500/P4600, Intel D5-P4320/P5530, Intel D7-P5500/P5600, Intel Optane, Kingston DC1000B/DC1500M
|
Intel DC-P3700/P4500/P4600, Intel/Solidigm D5-P4320/P5530, Intel/Solidigm D7-P5500/P5600, Solidigm D7-PS1010/PS1030/P5810,
|
||||||
|
Intel Optane, Kingston DC1000B/DC1500M, Kioxia CD6/CD7/CD8/CD9
|
||||||
|
- SATA SSD: Micron 5100/5200/5300/5400, Samsung PM863/PM883/PM893, Intel/Solidigm D3-S4510/4520/4610/4620, Kingston DC500M
|
||||||
- HDD: HGST Ultrastar, Toshiba MG, Seagate EXOS
|
- HDD: HGST Ultrastar, Toshiba MG, Seagate EXOS
|
||||||
|
|
||||||
## Configure monitors
|
## Configure monitors
|
||||||
|
|
||||||
On the monitor hosts:
|
On the monitor hosts:
|
||||||
- Put identical etcd_address into `/etc/vitastor/vitastor.conf`. Example:
|
- Create minimal configuration in `/etc/vitastor/vitastor.conf`:
|
||||||
```
|
```
|
||||||
{
|
{
|
||||||
"etcd_address": ["10.200.1.10:2379","10.200.1.11:2379","10.200.1.12:2379"]
|
"etcd_address": ["http://10.200.1.10:2379","http://10.200.1.11:2379","http://10.200.1.12:2379"],
|
||||||
|
"osd_network": "10.200.1.0/24",
|
||||||
|
"use_perms": false
|
||||||
}
|
}
|
||||||
```
|
```
|
||||||
|
- Note that you can enable encryption by using `https://` and `use_perms` option.
|
||||||
|
[Details](security.en.md#quick-setup) about encryption setup with make-etcd.
|
||||||
- Create systemd units for etcd by running: `/usr/lib/vitastor/mon/make-etcd`
|
- Create systemd units for etcd by running: `/usr/lib/vitastor/mon/make-etcd`
|
||||||
Or, if you installed Vitastor in Docker, run `systemctl start vitastor-host; docker exec vitastor make-etcd`.
|
Or, if you installed Vitastor in Docker, run `systemctl start vitastor-host; docker exec vitastor make-etcd`.
|
||||||
- Start etcd and monitors: `systemctl enable --now vitastor-etcd vitastor-mon`
|
- Start etcd and monitors: `systemctl enable --now vitastor-etcd vitastor-mon`
|
||||||
|
|||||||
+15
-14
@@ -18,8 +18,9 @@
|
|||||||
|
|
||||||
## Подготовка
|
## Подготовка
|
||||||
|
|
||||||
- Возьмите серверы с SSD (SATA или NVMe), желательно с конденсаторами (серверные SSD). Можно
|
- Возьмите серверы с SSD (SATA или NVMe), желательно с конденсаторами (серверные SSD). Наилучшая
|
||||||
использовать и десктопные SSD, включив режим отложенного fsync, но производительность будет хуже.
|
производительность достигается на дисках Micron и Kioxia с поддержкой атомарной записи (см. ниже).
|
||||||
|
Можно использовать и десктопные SSD, включив режим отложенного fsync, но производительность будет хуже.
|
||||||
О конденсаторах читайте [здесь](../config/layout-cluster.ru.md#immediate_commit).
|
О конденсаторах читайте [здесь](../config/layout-cluster.ru.md#immediate_commit).
|
||||||
- Если хотите использовать HDD, берите современные модели с Media или SSD кэшем - HGST Ultrastar,
|
- Если хотите использовать HDD, берите современные модели с Media или SSD кэшем - HGST Ultrastar,
|
||||||
Toshiba MG, Seagate EXOS или что-то похожее. Если такого кэша у ваших дисков нет,
|
Toshiba MG, Seagate EXOS или что-то похожее. Если такого кэша у ваших дисков нет,
|
||||||
@@ -30,33 +31,33 @@
|
|||||||
|
|
||||||
## Рекомендуемые диски
|
## Рекомендуемые диски
|
||||||
|
|
||||||
- SATA SSD: Micron 5100/5200/5300/5400, Samsung PM863/PM883/PM893, Intel D3-S4510/4520/4610/4620, Kingston DC500M
|
- NVMe с поддержкой атомарной записи (идеально!): Micron 7450/7500/7550, Kioxia CD6/CD7/CD8/CD9
|
||||||
- NVMe: Micron 9100/9200/9300/9400, Micron 7300/7450, Samsung PM983/PM9A3, Samsung PM1723/1735/1743,
|
- Другие NVMe: Micron 9100/9200/9300/9400/9550, Micron 7300, Samsung PM983/PM9A3, Samsung PM1723/1735/1743,
|
||||||
Intel DC-P3700/P4500/P4600, Intel D5-P4320/P5530, Intel D7-P5500/P5600, Intel Optane, Kingston DC1000B/DC1500M
|
Intel DC-P3700/P4500/P4600, Intel/Solidigm D5-P4320/P5530, Intel/Solidigm D7-P5500/P5600, Solidigm D7-PS1010/PS1030/P5810,
|
||||||
|
Intel Optane, Kingston DC1000B/DC1500M, Kioxia CD6/CD7/CD8/CD9
|
||||||
|
- SATA SSD: Micron 5100/5200/5300/5400, Samsung PM863/PM883/PM893, Intel/Solidigm D3-S4510/4520/4610/4620, Kingston DC500M
|
||||||
- HDD: HGST Ultrastar, Toshiba MG, Seagate EXOS
|
- HDD: HGST Ultrastar, Toshiba MG, Seagate EXOS
|
||||||
|
|
||||||
## Настройте мониторы
|
## Настройте мониторы
|
||||||
|
|
||||||
На хостах, выделенных под мониторы:
|
На хостах, выделенных под мониторы:
|
||||||
- Пропишите одинаковые etcd_address в `/etc/vitastor/vitastor.conf`. Например:
|
- Создайте минимальную конфигурацию в `/etc/vitastor/vitastor.conf`:
|
||||||
```
|
```
|
||||||
{
|
{
|
||||||
"etcd_address": ["10.200.1.10:2379","10.200.1.11:2379","10.200.1.12:2379"]
|
"etcd_address": ["http://10.200.1.10:2379","http://10.200.1.11:2379","http://10.200.1.12:2379"],
|
||||||
|
"osd_network": "10.200.1.0/24",
|
||||||
|
"use_perms": false
|
||||||
}
|
}
|
||||||
```
|
```
|
||||||
|
- Обратите внимание, что с помощью схемы `https://` и опции `use_perms` можно включить шифрование.
|
||||||
|
[Подробно](security.ru.md#быстрая-настройка) о настройке шифрования через make-etcd.
|
||||||
- Инициализируйте сервисы etcd, запустив `/usr/lib/vitastor/mon/make-etcd`.\
|
- Инициализируйте сервисы etcd, запустив `/usr/lib/vitastor/mon/make-etcd`.\
|
||||||
Либо, если вы установили Vitastor в Docker, запустите `systemctl start vitastor-host; docker exec vitastor make-etcd`.
|
Либо, если вы установили Vitastor в Docker, запустите `systemctl start vitastor-host; docker exec vitastor make-etcd`.
|
||||||
- Запустите etcd и мониторы: `systemctl enable --now vitastor-etcd vitastor-mon`
|
- Запустите etcd и мониторы: `systemctl enable --now vitastor-etcd vitastor-mon`
|
||||||
|
|
||||||
## Настройте OSD
|
## Настройте OSD
|
||||||
|
|
||||||
- Пропишите etcd_address и [osd_network](../config/network.ru.md#osd_network) в `/etc/vitastor/vitastor.conf`. Например:
|
- Создайте/скопируйте с узлов с мониторами файл конфигурации `/etc/vitastor/vitastor.conf`.
|
||||||
```
|
|
||||||
{
|
|
||||||
"etcd_address": ["10.200.1.10:2379","10.200.1.11:2379","10.200.1.12:2379"],
|
|
||||||
"osd_network": "10.200.1.0/24"
|
|
||||||
}
|
|
||||||
```
|
|
||||||
- Инициализуйте OSD:
|
- Инициализуйте OSD:
|
||||||
- Только SSD или только HDD: `vitastor-disk prepare /dev/sdXXX [/dev/sdYYY ...]`.
|
- Только SSD или только HDD: `vitastor-disk prepare /dev/sdXXX [/dev/sdYYY ...]`.
|
||||||
Если вы используете десктопные SSD без конденсаторов, добавьте опцию `--disable_data_fsync off`,
|
Если вы используете десктопные SSD без конденсаторов, добавьте опцию `--disable_data_fsync off`,
|
||||||
|
|||||||
@@ -0,0 +1,657 @@
|
|||||||
|
[Documentation](../../README.md#documentation) → Introduction → Security in Vitastor
|
||||||
|
|
||||||
|
-----
|
||||||
|
|
||||||
|
[Читать на русском](security.ru.md)
|
||||||
|
|
||||||
|
# Security in Vitastor
|
||||||
|
|
||||||
|
- [Overview](#overview)
|
||||||
|
- [Quick setup](#quick-setup)
|
||||||
|
- Principles of operation
|
||||||
|
- [etcd transport encryption (TLS)](#etcd-transport-encryption-tls)
|
||||||
|
- [OSD transport encryption (AES-GCM)](#osd-transport-encryption-aes-gcm)
|
||||||
|
- [End-to-end image data encryption (AES-XTS)](#end-to-end-image-data-encryption-aes-xts)
|
||||||
|
- [Certificate-based authentication](#certificate-based-authentication)
|
||||||
|
- [Users and access rights](#users-and-access-rights)
|
||||||
|
- [etcd privileges](#etcd-privileges)
|
||||||
|
- Manual setup
|
||||||
|
- [Configuring OSD transport encryption](#configuring-osd-transport-encryption)
|
||||||
|
- etcd/Antietcd setup options
|
||||||
|
- [Mon with embedded Antietcd](#mon-with-embedded-antietcd)
|
||||||
|
- [Mon as an Etcd proxy](#mon-as-an-etcd-proxy)
|
||||||
|
- [Mon with a separate Antietcd Proxy](#mon-with-a-separate-antietcd-proxy)
|
||||||
|
- [Standalone Antietcd without etcd](#standalone-antietcd-without-etcd)
|
||||||
|
- [Vault/OpenBao setup](#vaultopenbao-setup)
|
||||||
|
- [Vault setup example](#vault-setup-example)
|
||||||
|
- Lists of allowed operations
|
||||||
|
- [etcd data access rights](#etcd-data-access-rights)
|
||||||
|
- [OSD data access rights](#osd-data-access-rights)
|
||||||
|
- [API access rights](#api-access-rights)
|
||||||
|
- [Encryption performance](#encryption-performance)
|
||||||
|
|
||||||
|
## Overview
|
||||||
|
|
||||||
|
Starting from version 3.1.0, Vitastor provides full data protection:
|
||||||
|
control plane protection (etcd), data plane protection (OSDs), and end-to-end data encryption.
|
||||||
|
|
||||||
|
- Control plane protection:
|
||||||
|
- etcd transport encryption (TLS)
|
||||||
|
- Authentication via client TLS (X.509) certificates
|
||||||
|
- Access control of clients to etcd data
|
||||||
|
- Data plane protection:
|
||||||
|
- Full AES-GCM encryption of OSD transport (similar to TLS, but faster)
|
||||||
|
- Alternatively, AES-GCM encryption of just operation headers with data checksums using a secret "salt"
|
||||||
|
- Authentication via client TLS (X.509) certificates
|
||||||
|
- Access control of clients on the OSD side
|
||||||
|
- End-to-end encryption:
|
||||||
|
- Data is encrypted using AES-XTS on the client side, the Vitastor cluster has no access to plaintext data
|
||||||
|
- AES-XTS keys can be stored in etcd or in an external Vault/OpenBao
|
||||||
|
|
||||||
|
All features are optional and disabled in the simplest configuration. By default, only
|
||||||
|
transport-level data checksums ([proto_checksums](../config/security.en.md#proto_checksums)=payload)
|
||||||
|
are enabled for clients that support them (>= 3.1.0). For older clients, connections
|
||||||
|
without data checksums are allowed by default ([force_proto_checksums](../config/security.en.md#force_proto_checksums) is empty).
|
||||||
|
|
||||||
|
For a quick setup, jump to the [Quick setup](#quick-setup) section.
|
||||||
|
|
||||||
|
Descriptions of all security-related parameters can be found [here](../config/security.en.md).
|
||||||
|
|
||||||
|
## Quick setup
|
||||||
|
|
||||||
|
For a quick setup, use the `/usr/lib/vitastor/mon/make-etcd` script:
|
||||||
|
|
||||||
|
1. Log in to the node where the first monitor and etcd will be located.
|
||||||
|
2. Create `/etc/vitastor/vitastor.conf` with minimal parameters: etcd_address,
|
||||||
|
osd_network and, if you want to enable privileges, use_perms (note `https://`
|
||||||
|
in etcd addresses):
|
||||||
|
```
|
||||||
|
{
|
||||||
|
"etcd_address": ["https://10.0.0.10:2379","https://10.0.0.11:2379","https://10.0.0.12:2379"],
|
||||||
|
"osd_network": "10.0.0.0/24",
|
||||||
|
"use_perms": true
|
||||||
|
}
|
||||||
|
```
|
||||||
|
3. Run `/usr/lib/vitastor/mon/make-etcd` without parameters or with the `--antietcd-only`
|
||||||
|
parameter if you want to initialize the cluster with Antietcd only, without etcd.
|
||||||
|
4. The script will generate all necessary certificates and offer to copy them to the other
|
||||||
|
monitor nodes (agree!).
|
||||||
|
5. Log in to all other monitor nodes and repeat the `/usr/lib/vitastor/mon/make-etcd` call there.
|
||||||
|
6. If you also have nodes with OSDs only (without monitors), run the following command to
|
||||||
|
copy only the required configuration to these nodes:
|
||||||
|
```
|
||||||
|
/usr/lib/vitastor/mon/make-etcd --copy-to-osd osdnode1,osdnode2,...
|
||||||
|
```
|
||||||
|
|
||||||
|
After that, you can proceed with OSD initialization.
|
||||||
|
|
||||||
|
If you want to understand the setup in more detail, read the [Principles of operation](#principles-of-operation)
|
||||||
|
and [Manual setup](#manual-setup) sections below.
|
||||||
|
|
||||||
|
## Principles of operation
|
||||||
|
|
||||||
|
### etcd transport encryption (TLS)
|
||||||
|
|
||||||
|
Possible setups:
|
||||||
|
- Without encryption (http)
|
||||||
|
- With encryption (https)
|
||||||
|
- With encryption and client certificate authentication. Either the same certificate
|
||||||
|
used for authentication on the OSD side (`cert`+`pkey` / `osd_cert`+`osd_pkey`)
|
||||||
|
is used, or a separately specified certificate (`etcd_client_cert`+`etcd_client_key`).
|
||||||
|
|
||||||
|
### OSD transport encryption (AES-GCM)
|
||||||
|
|
||||||
|
Possible setups:
|
||||||
|
- Unencrypted transport without checksums: `proto_checksums=none`.
|
||||||
|
- Unencrypted transport with data checksums: `proto_checksums=payload` (may be omitted,
|
||||||
|
this is the default value). It's allowed to disable checksums on the client side, or
|
||||||
|
use an older client that does not support checksums. If you want to block connections
|
||||||
|
from clients without checksums, use the option `force_proto_checksums=payload`.
|
||||||
|
- Header-only encryption with data checksums: activated when the options
|
||||||
|
`cert`, `pkey`, `osd_ca` are set on the client side and `osd_cert`, `osd_pkey`, `osd_ca`, `client_ca`
|
||||||
|
on the OSD side, with `proto_checksums=payload`. In this mode, disabling checksums on the client
|
||||||
|
side is forbidden by default, i.e. `force_proto_checksums=payload` is used.
|
||||||
|
- Full transport encryption of all traffic: same as the previous option, but with `proto_checksums=gcm`.
|
||||||
|
In this case, clients are by default allowed to downgrade to checksums only, but this
|
||||||
|
can also be forbidden via `force_proto_checksums=gcm`. This is the slowest setup and
|
||||||
|
it's only recommended for insecure (public) networks. In particular, full traffic
|
||||||
|
encryption together with end-to-end AES-XTS image encryption encrypts data twice.
|
||||||
|
|
||||||
|
Encryption uses the AES-256-GCM algorithm and a custom simplified key exchange protocol,
|
||||||
|
fully analogous to TLS 1.3 ECDHE.
|
||||||
|
|
||||||
|
### End-to-end image data encryption (AES-XTS)
|
||||||
|
|
||||||
|
The Vitastor client supports encrypting each image's data with its own key. In this case,
|
||||||
|
data is encrypted by the client before sending it to OSDs and OSDs can't see it in plain.
|
||||||
|
The encryption key can be changed when cloning/creating image snapshots. For example,
|
||||||
|
you can make a base VM image (say, Debian Linux) unencrypted, but have encrypted client VM
|
||||||
|
images inheriting from it.
|
||||||
|
|
||||||
|
Image encryption keys can be stored in etcd or in an external Vault. In the latter case,
|
||||||
|
etcd only stores key IDs and Vitastor cluster can't decrypt the data at all. To use
|
||||||
|
Vault, create an image with the `--enc_key vault:ID` option, specify vault_url and vault_ca
|
||||||
|
options in the configuration, create accounts for all clients in Vault, and grant them access
|
||||||
|
to the required v1 secrets.
|
||||||
|
|
||||||
|
Once again, if AES-XTS is used together with full traffic encryption (`proto_checksums=gcm`),
|
||||||
|
image data is encrypted twice — first with AES-XTS, and then with AES-GCM. Use it only if
|
||||||
|
you are completely paranoid :-).
|
||||||
|
|
||||||
|
### Certificate-based authentication
|
||||||
|
|
||||||
|
When encryption is enabled, Vitastor clients, OSDs, and monitors authenticate via certificates
|
||||||
|
for both etcd (Antietcd) and OSD connections.
|
||||||
|
|
||||||
|
Separate certificates must be used for OSDs and monitors — either self-signed, or signed
|
||||||
|
by separate CAs (`osd_ca` and `mon_ca`). All OSDs can use the same certificate, and all
|
||||||
|
monitors can also use the same certificate, since the privileges of different OSDs or
|
||||||
|
different monitors do not differ (theoretically, one could differentiate OSD certificates
|
||||||
|
by pool, but there has been no need for this so far).
|
||||||
|
|
||||||
|
Also, a monitor certificate may not be needed at all if Antietcd is embedded into the monitor
|
||||||
|
itself. In this case, the monitor already has access to all etcd data directly in memory.
|
||||||
|
|
||||||
|
### Users and access rights
|
||||||
|
|
||||||
|
When transport encryption is disabled, Vitastor operates without access control, i.e.,
|
||||||
|
any cluster client has full access to both the management layer and the data layer. This
|
||||||
|
option is suitable for dedicated trusted storage networks.
|
||||||
|
|
||||||
|
When OSD transport encryption is enabled (at least for headers), you can enable access
|
||||||
|
rights by turning on the `use_perms=true` option. When this option is enabled, each user
|
||||||
|
can perform only the operations that they are permitted, and even OSDs and monitors are
|
||||||
|
also forbidden from performing "unnecessary" operations.
|
||||||
|
|
||||||
|
Each user (or administrator) must have their own certificate signed by a common root
|
||||||
|
certificate for clients (`client_ca`), with a Common Name equal to the user name.
|
||||||
|
Privilege settings are stored in etcd. OSDs and monitors don't need user accounts;
|
||||||
|
they authenticate via separate certificates.
|
||||||
|
|
||||||
|
User privileges are stored in etcd data under the keys `/vitastor/config/user/<name>`.
|
||||||
|
The following is defined per user in this key:
|
||||||
|
- Type:
|
||||||
|
- Client (`type=client` or omitted) — can only read and modify explicitly permitted images.
|
||||||
|
- Administrator (`type=admin`) — can read and modify all images, and also administer the
|
||||||
|
cluster: view overall statistics and status, create and delete OSDs, etc.
|
||||||
|
- List of group names the user is a member of.
|
||||||
|
|
||||||
|
Images have the following properties:
|
||||||
|
- Owner (owner) — the user name that is allowed to both read and modify the image
|
||||||
|
- Owner group (owner_group) — the owner group name
|
||||||
|
- Reader group (reader_group) — the name of the group of users allowed to read the image
|
||||||
|
|
||||||
|
And there is also a property on the pool:
|
||||||
|
- Creator group (creator_group) — the name of the group of users allowed to create images in the pool
|
||||||
|
|
||||||
|
For the list of allowed operations on image data on the OSD side, see the
|
||||||
|
[OSD data access rights](#osd-data-access-rights) section.
|
||||||
|
|
||||||
|
### etcd privileges
|
||||||
|
|
||||||
|
etcd privileges are implemented through Antietcd in all modes of operation.
|
||||||
|
|
||||||
|
Built-in etcd privileges are not supported due to numerous inconveniences:
|
||||||
|
- Certificate-based authentication does not work at all in etcd's REST interface,
|
||||||
|
- Privileges are stored separately from k/v data and cannot participate in transactions,
|
||||||
|
- Only the administrator (root) can change privileges,
|
||||||
|
- There is no support for filtering range read responses by privileges.
|
||||||
|
|
||||||
|
If etcd is used, Antietcd acts as a filtering proxy and can be embedded in the Vitastor
|
||||||
|
monitor or run separately. In this case, etcd must allow incoming connections only from
|
||||||
|
Antietcd, and all other components must connect to Antietcd.
|
||||||
|
|
||||||
|
If Antietcd runs as a part of the Vitastor monitor, it is sufficient to enable the option
|
||||||
|
`use_perms=true` and set the required certificates. If Antietcd is run separately, privileges
|
||||||
|
have to be enabled separately using Antietcd options. For more details on the setup, see
|
||||||
|
the [etcd/Antietcd setup options](#etcdantietcd-setup-options) section.
|
||||||
|
|
||||||
|
For the list of allowed operations with etcd data, see the
|
||||||
|
[etcd data access rights](#etcd-data-access-rights) section.
|
||||||
|
|
||||||
|
## Manual setup
|
||||||
|
|
||||||
|
### Configuring OSD transport encryption
|
||||||
|
|
||||||
|
You need 2 certificates: one for OSDs and one for signing all client certificates.
|
||||||
|
For OSDs, you can use a self-signed certificate (osd_ca.crt) or a separate certificate (osd.crt)
|
||||||
|
signed by a trusted osd_ca.crt certificate. For clients, you must use separate certificates
|
||||||
|
signed by a common trusted (client_ca.crt).
|
||||||
|
|
||||||
|
Add to the Vitastor configuration on OSD servers:
|
||||||
|
- use_perms: true
|
||||||
|
- osd_ca: osd_ca.crt
|
||||||
|
- client_ca: client_ca.crt
|
||||||
|
- osd_cert: osd_ca.crt
|
||||||
|
- osd_pkey: osd_ca.key
|
||||||
|
|
||||||
|
On the client side:
|
||||||
|
- use_perms: true
|
||||||
|
- cert: client.crt
|
||||||
|
- pkey: client.key
|
||||||
|
|
||||||
|
### etcd/Antietcd setup options
|
||||||
|
|
||||||
|
The following configuration options are available:
|
||||||
|
|
||||||
|
#### Mon with embedded Antietcd
|
||||||
|
|
||||||
|
The simplest option. You need 1 certificate for Antietcd (antietcd.crt), plus root
|
||||||
|
certificates for OSDs and clients.
|
||||||
|
|
||||||
|
Vitastor settings (`/etc/vitastor/vitastor.conf`):
|
||||||
|
- etcd_address: [ "http://mon1:2379", ... ] (addresses of your monitors with port 2379)
|
||||||
|
- use_perms: true
|
||||||
|
- use_antietcd: true
|
||||||
|
- antietcd_cert: antietcd.crt
|
||||||
|
- antietcd_key: antietcd.key
|
||||||
|
- etcd_ca: antietcd.crt
|
||||||
|
- osd_ca: osd_ca.crt
|
||||||
|
- client_ca: client_ca.crt
|
||||||
|
|
||||||
|
#### Mon as an Etcd proxy
|
||||||
|
|
||||||
|
If you want to enable privileges, but stay on etcd, you can use etcd proxy mode.
|
||||||
|
|
||||||
|
You will need 2 separate certificates: one for etcd (etcd.crt) and one for antietcd (antietcd.crt).
|
||||||
|
The etcd client port must be different from the standard 2379 — for example, you can pick 2381.
|
||||||
|
OSD and client certificates are also needed.
|
||||||
|
|
||||||
|
Vitastor settings:
|
||||||
|
- etcd_address: [ "http://mon1:2379", ... ] (addresses of your monitors with port 2379)
|
||||||
|
- use_perms: true
|
||||||
|
- use_antietcd: true
|
||||||
|
- etcd_proxy:
|
||||||
|
```
|
||||||
|
{
|
||||||
|
"urls": [ "http://mon1:2381", ... ], // addresses of your etcd with port 2381
|
||||||
|
"cert": "antietcd.crt",
|
||||||
|
"key": "antietcd.key",
|
||||||
|
"ca": "etcd.crt"
|
||||||
|
}
|
||||||
|
```
|
||||||
|
- antietcd_cert: antietcd.crt
|
||||||
|
- antietcd_key: antietcd.key
|
||||||
|
- etcd_ca: antietcd.crt
|
||||||
|
- osd_ca: osd_ca.crt
|
||||||
|
- client_ca: client_ca.crt
|
||||||
|
|
||||||
|
etcd command-line options:
|
||||||
|
```
|
||||||
|
--advertise-client-urls=https://<ADDRESS>:2381 --listen-client-urls=https://<ADDRESS>:2381 \
|
||||||
|
--client-cert-auth --cert-file=etcd.crt --key-file=etcd.key --trusted-ca-file=antietcd.crt \
|
||||||
|
--peer-client-cert-auth --peer-cert-file=etcd.crt --peer-key-file=etcd.key --peer-trusted-ca-file=etcd.crt
|
||||||
|
```
|
||||||
|
|
||||||
|
#### Mon with a separate Antietcd Proxy
|
||||||
|
|
||||||
|
If in addition to the previous option you want to offload Antietcd from the Vitastor monitor's
|
||||||
|
tasks, you can run it separately.
|
||||||
|
|
||||||
|
Similar to the previous option, 2 certificates are needed: one for etcd and one for antietcd,
|
||||||
|
plus separate certificates for clients, OSDs, and monitors will be needed.
|
||||||
|
|
||||||
|
Vitastor settings:
|
||||||
|
- etcd_address: [ "http://mon1:2379", ... ] (addresses of your monitors with port 2379)
|
||||||
|
- use_perms: true
|
||||||
|
- use_antietcd: false
|
||||||
|
- etcd_ca: antietcd.crt
|
||||||
|
- osd_ca: osd_ca.crt
|
||||||
|
- client_ca: client_ca.crt
|
||||||
|
- mon_etcd_client_cert: mon_ca.crt
|
||||||
|
- mon_etcd_client_key: mon_ca.key
|
||||||
|
|
||||||
|
Antietcd command-line options:
|
||||||
|
```
|
||||||
|
--port 2379 \
|
||||||
|
--client_cert_auth 1 --auth_filter vitastor_auth_filter.js --etcd_proxy url1,url2,... \
|
||||||
|
--cert antietcd.crt --key antietcd.key --ca client_ca.crt --osd_ca osd_ca.crt --mon_ca mon_ca.crt \
|
||||||
|
--etcd_cert antietcd.crt --etcd_key antietcd.key --etcd_ca etcd.crt
|
||||||
|
```
|
||||||
|
|
||||||
|
etcd command-line options (same as in the previous option):
|
||||||
|
```
|
||||||
|
--advertise-client-urls=https://<ADDRESS>:2381 --listen-client-urls=https://<ADDRESS>:2381 \
|
||||||
|
--client-cert-auth --cert-file=etcd.crt --key-file=etcd.key --trusted-ca-file=antietcd.crt \
|
||||||
|
--peer-client-cert-auth --peer-cert-file=etcd.crt --peer-key-file=etcd.key --peer-trusted-ca-file=etcd.crt
|
||||||
|
```
|
||||||
|
|
||||||
|
#### Standalone Antietcd without etcd
|
||||||
|
|
||||||
|
Same as the previous option, but etcd and its certificate are not needed:
|
||||||
|
|
||||||
|
Vitastor settings (same as in the previous option):
|
||||||
|
- etcd_address: [ "http://mon1:2379", ... ] (addresses of your monitors with port 2379)
|
||||||
|
- use_perms: true
|
||||||
|
- use_antietcd: false
|
||||||
|
- etcd_ca: antietcd.crt
|
||||||
|
- osd_ca: osd_ca.crt
|
||||||
|
- client_ca: client_ca.crt
|
||||||
|
- mon_etcd_client_cert: mon_ca.crt
|
||||||
|
- mon_etcd_client_key: mon_ca.key
|
||||||
|
|
||||||
|
Antietcd command-line options:
|
||||||
|
```
|
||||||
|
--port 2379 \
|
||||||
|
--client_cert_auth 1 --auth_filter vitastor_auth_filter.js \
|
||||||
|
--persist_filter vitastor_persist_filter.js \
|
||||||
|
--cert antietcd.crt --key antietcd.key --ca client_ca.crt --osd_ca osd_ca.crt --mon_ca mon_ca.crt
|
||||||
|
```
|
||||||
|
|
||||||
|
### Vault/OpenBao setup
|
||||||
|
|
||||||
|
To use Vault, each client that needs to get image keys from Vault needs a Vault account.
|
||||||
|
Vitastor only supports client certificate-based authentication, so all client certificates
|
||||||
|
(`cert`+`pkey`) must be registered in Vault, and they must be granted access to the
|
||||||
|
corresponding secrets (v1 secrets API is supported).
|
||||||
|
|
||||||
|
The required format of a Vault secret is a single `key` field as a hexadecimal string.
|
||||||
|
The AES-256-XTS algorithm is used, so the key length is 64 bytes, i.e., the string must
|
||||||
|
consist of 128 hexadecimal digits.
|
||||||
|
|
||||||
|
To connect to Vault, set the following settings in Vitastor.conf:
|
||||||
|
- `vault_url` — Vault address (e.g., `https://vault:8200`)
|
||||||
|
- `vault_ca` — Vault's own certificate
|
||||||
|
|
||||||
|
After that, if you create an image (`vitastor-cli create`) with the option `--enc_key vault:<ID>`,
|
||||||
|
Vitastor clients will first contact Vault to obtain a token at `/v1/auth/cert/login`,
|
||||||
|
and then request the actual secret from Vault at `/v1/secret/<ID>`.
|
||||||
|
|
||||||
|
#### Vault setup example
|
||||||
|
|
||||||
|
Step-by-step instructions for setting up a test Vault using OpenBao as an example:
|
||||||
|
|
||||||
|
1. If TLS is not yet configured, generate a self-signed TLS certificate for Vault:
|
||||||
|
```
|
||||||
|
openssl req -days 3650 -x509 -addext basicConstraints=critical,CA:TRUE,pathlen:1 --addext subjectAltName=DNS:vault \
|
||||||
|
-new -newkey rsa:4096 -nodes -keyout /etc/openbao/vault.key -out /etc/openbao/vault.crt
|
||||||
|
```
|
||||||
|
Configure it in `/etc/openbao/openbao.hcl`:
|
||||||
|
```
|
||||||
|
listener "tcp" {
|
||||||
|
address = "0.0.0.0:8200"
|
||||||
|
tls_cert_file = "/etc/openbao/vault.crt"
|
||||||
|
tls_key_file = "/etc/openbao/vault.key"
|
||||||
|
}
|
||||||
|
```
|
||||||
|
And restart OpenBao (`systemctl restart openbao`).
|
||||||
|
2. Copy Vault's TLS certificate for Vitastor:
|
||||||
|
```
|
||||||
|
cp /etc/openbao/vault.crt /etc/vitastor/vault.crt
|
||||||
|
```
|
||||||
|
Transfer it to all client nodes and specify it in `/etc/vitastor/vitastor.conf`:
|
||||||
|
```
|
||||||
|
{
|
||||||
|
...
|
||||||
|
"vault_url": "http://vault:8200",
|
||||||
|
"vault_ca": "/etc/vitastor/vault.crt"
|
||||||
|
}
|
||||||
|
```
|
||||||
|
3. Check Vault status:
|
||||||
|
```
|
||||||
|
bao status -ca-cert /etc/openbao/vault.crt -address=https://vault:8200
|
||||||
|
```
|
||||||
|
4. Initialize Vault in test mode from 1 node (with 1 key share):
|
||||||
|
```
|
||||||
|
bao operator init -n 1 -t 1 -ca-cert /etc/openbao/vault.crt -address=https://vault:8200
|
||||||
|
```
|
||||||
|
5. Unseal Vault:
|
||||||
|
```
|
||||||
|
bao operator unseal -ca-cert /etc/openbao/vault.crt -address=https://vault:8200
|
||||||
|
```
|
||||||
|
6. Enable certificate-based authentication:
|
||||||
|
```
|
||||||
|
bao auth enable -ca-cert /etc/openbao/vault.crt -address=https://vault:8200 cert
|
||||||
|
```
|
||||||
|
7. Enable v1 secrets:
|
||||||
|
```
|
||||||
|
bao secrets enable -ca-cert /etc/openbao/vault.crt -address=https://vault:8200 -path=secret kv-v1
|
||||||
|
```
|
||||||
|
8. Create a test secret:
|
||||||
|
```
|
||||||
|
bao kv put -ca-cert /etc/openbao/vault.crt -address=https://vault:8200 secret/vitastor/testimg3 key=$(openssl rand -hex 64)
|
||||||
|
```
|
||||||
|
9. Generate a signed certificate for a Vitastor user (on a machine where you have `client_ca.crt` and `client_ca.key`):
|
||||||
|
```
|
||||||
|
openssl req -subj '/CN=testimg3' -nodes -new -keyout testimg3.key -out testimg3.csr
|
||||||
|
openssl x509 -req -days 3650 -CA client_ca.crt -CAkey client_ca.key -CAcreateserial -in testimg3.csr -out testimg3.crt
|
||||||
|
rm testimg3.csr
|
||||||
|
```
|
||||||
|
10. Create a user in Vault and grant it access to the secret:
|
||||||
|
```
|
||||||
|
cat >testimg3.policy <<EOF
|
||||||
|
path "/secret/vitastor/testimg3" {
|
||||||
|
capabilities = ["read"]
|
||||||
|
}
|
||||||
|
EOF
|
||||||
|
|
||||||
|
bao policy write -ca-cert /etc/openbao/vault.crt -address=https://vault:8200 testimg3 testimg3.policy
|
||||||
|
|
||||||
|
bao write -ca-cert /etc/openbao/vault.crt -address=https://vault:8200 auth/cert/certs/testimg3 \
|
||||||
|
certificate=@testimg3.crt display_name=testimg3 token_ttl=24h token_policies=testimg3
|
||||||
|
```
|
||||||
|
11. Test access to the secret:
|
||||||
|
```
|
||||||
|
curl --cacert /etc/vitastor/vault.crt --cert testimg3.crt --key testimg3.key \
|
||||||
|
--json '{}' https://vault:8200/v1/auth/cert/login
|
||||||
|
```
|
||||||
|
A token will be printed, substitute it into the following request:
|
||||||
|
```
|
||||||
|
curl --cacert /etc/vitastor/vault.crt --cert testimg3.crt --key testimg3.key \
|
||||||
|
-H 'X-Vault-Token: <RECEIVED TOKEN>' https://vault:8200/v1/secret/vitastor/testimg3
|
||||||
|
```
|
||||||
|
12. Create an image in Vitastor with the given secret (as an administrator or someone who
|
||||||
|
has the right to create images in your pool):
|
||||||
|
```
|
||||||
|
vitastor-cli create -s 100G --enc_key vault:vitastor/testimg3 --owner testimg3 testimg3
|
||||||
|
```
|
||||||
|
13. Test access to the image as user testimg3:
|
||||||
|
```
|
||||||
|
vitastor-cli --cert testimg3.crt --pkey testimg3.key dd if=/dev/urandom oimg=testimg3 bs=1M count=100
|
||||||
|
```
|
||||||
|
|
||||||
|
## Lists of allowed operations
|
||||||
|
|
||||||
|
### etcd data access rights
|
||||||
|
|
||||||
|
Below, all key names are given without the common prefix `/vitastor`.
|
||||||
|
|
||||||
|
Allowed operations with keys in Antietcd for clients (`type=client`):
|
||||||
|
- Read-only:
|
||||||
|
- Always allowed:
|
||||||
|
- `/config/global`
|
||||||
|
- `/config/node_placement`
|
||||||
|
- `/config/pools`
|
||||||
|
- `/pg/config`
|
||||||
|
- `/osd/state/*`
|
||||||
|
- `/pg/state/*`
|
||||||
|
- `/index/maxid/*`
|
||||||
|
- For images [readable by the user](#users-and-access-rights):
|
||||||
|
- `/config/inode/*`
|
||||||
|
- `/index/image/*`
|
||||||
|
- `/inode/stats/*`
|
||||||
|
- Read and write:
|
||||||
|
- For pools in which the user can create images:
|
||||||
|
- `/index/maxid/*`
|
||||||
|
- For images owned by the user:
|
||||||
|
- `/config/inode/*`
|
||||||
|
- `/index/image/*`
|
||||||
|
|
||||||
|
Allowed operations with keys in Antietcd for administrators (`type=admin`):
|
||||||
|
- Read:
|
||||||
|
- `/stats`
|
||||||
|
- `/mon/*`
|
||||||
|
- `/pg/*`
|
||||||
|
- `/pgstats/*`
|
||||||
|
- `/inode/stats/*`
|
||||||
|
- `/pool/stats/*`
|
||||||
|
- Read and write:
|
||||||
|
- `/config/*`
|
||||||
|
- `/osd/*`
|
||||||
|
- `/index/*`
|
||||||
|
- `/pg/history/*`
|
||||||
|
|
||||||
|
Allowed operations with keys in etcd for OSDs:
|
||||||
|
- Read:
|
||||||
|
- `/pg/config`
|
||||||
|
- `/config/*`
|
||||||
|
- Read and write:
|
||||||
|
- `/osd/*`
|
||||||
|
- `/pg/state/*`
|
||||||
|
- `/pg/history/*`
|
||||||
|
- `/pgstats/*`
|
||||||
|
|
||||||
|
Allowed operations with keys in etcd for monitors:
|
||||||
|
- Read:
|
||||||
|
- `/config/*`
|
||||||
|
- `/osd/*`
|
||||||
|
- `/pgstats/*`
|
||||||
|
- Read and write:
|
||||||
|
- `/pg/config`
|
||||||
|
- `/stats`
|
||||||
|
- `/history/last_clean_pgs`
|
||||||
|
- `/mon/*`
|
||||||
|
- `/pg/history/*`
|
||||||
|
- `/inode/stats/*`
|
||||||
|
- `/pool/stats/*`
|
||||||
|
|
||||||
|
### OSD data access rights
|
||||||
|
|
||||||
|
When the `use_perms` option and encryption are enabled, OSDs authenticate clients via
|
||||||
|
certificates and allow each client only what is allowed by the access control model.
|
||||||
|
|
||||||
|
Client operations:
|
||||||
|
- READ — allowed for images the user has read access to.
|
||||||
|
- WRITE, DELETE, SCRUB — allowed for images the user has write access to.
|
||||||
|
- SYNC — the operation is not tied to an image and is always allowed.
|
||||||
|
- DESCRIBE — the operation is allowed only for administrators (used by the commands
|
||||||
|
`vitastor-cli describe` and `fix`).
|
||||||
|
- PING — the operation is always allowed.
|
||||||
|
- SHOW_CONFIG — the operation is always allowed, however, if the client presents
|
||||||
|
itself as an OSD in it, then it is verified that it uses a certificate signed by `osd_ca`.
|
||||||
|
- SEC_LIST (listing) — allowed for other OSDs and administrators with any parameters,
|
||||||
|
and for regular clients only allowed for requests limited to an image the user has
|
||||||
|
read access to.
|
||||||
|
|
||||||
|
Cluster operations — allowed only for other OSDs:
|
||||||
|
- SEC_READ
|
||||||
|
- SEC_WRITE
|
||||||
|
- SEC_WRITE_STABLE
|
||||||
|
- SEC_SYNC
|
||||||
|
- SEC_STABILIZE
|
||||||
|
- SEC_ROLLBACK
|
||||||
|
- SEC_DELETE
|
||||||
|
- SEC_READ_BMP
|
||||||
|
- SEC_LOCK
|
||||||
|
|
||||||
|
### API access rights
|
||||||
|
|
||||||
|
[vitastor-cli serve](../usage/cli.en.md#serve) also supports client authentication
|
||||||
|
via certificates. Only certificates signed by `client_ca` are accepted. A separate
|
||||||
|
certificate `server_cert` with the key `server_pkey` is used as the server certificate.
|
||||||
|
|
||||||
|
For `vitastor-cli serve` to work correctly, it itself must use a certificate
|
||||||
|
(`cert`+`pkey`) of a user with administrator rights (`type=admin`) to access Vitastor.
|
||||||
|
|
||||||
|
Regular clients, when accessing the API, are only allowed API operations on images
|
||||||
|
available to them either for reading (for reads) or for writing (for modification).
|
||||||
|
All other API calls are allowed only for administrators.
|
||||||
|
|
||||||
|
List of allowed API operations:
|
||||||
|
|
||||||
|
Clients (users with `type=client`) are allowed the following operations:
|
||||||
|
- image/list — for images the user can read.
|
||||||
|
- image/create — for pools in which the user is allowed to create images, or for
|
||||||
|
creating snapshots of images owned by the user.
|
||||||
|
- image/delete, image/flatten, image/modify — for images owned by the user.
|
||||||
|
|
||||||
|
All other operations are allowed only for administrators (`type=admin`).
|
||||||
|
|
||||||
|
## Encryption performance
|
||||||
|
|
||||||
|
You may wonder — how fast is all this wonderful encryption?
|
||||||
|
|
||||||
|
The answer is — it depends heavily on the CPU. On modern processors (with AVX512 with VAES
|
||||||
|
support) it is very fast — AES encryption speed can reach 10-20 GB/s and above. This
|
||||||
|
primarily concerns the CPU of client machines, because end-to-end encryption is performed
|
||||||
|
entirely on the client, and client uses its signle thread for transport encryption too,
|
||||||
|
while there are many OSDs on the server side, and it is easier to add resources there.
|
||||||
|
|
||||||
|
On older processors, the speed is noticeably worse — for example, on a Xeon E5 v4 it is
|
||||||
|
only 3 GB/s.
|
||||||
|
|
||||||
|
You can evaluate the performance of your processors using the `vitastor-cli cpubench` command.
|
||||||
|
|
||||||
|
Example output (💪 AMD EPYC 9575F):
|
||||||
|
|
||||||
|
```
|
||||||
|
$ vitastor-cli cpubench
|
||||||
|
Vitastor transport encryption benchmark (AES-256-GCM, AES-256-XTS and xxhash3)
|
||||||
|
|
||||||
|
Warmup...
|
||||||
|
|
||||||
|
No transport encryption, data checksums enabled, e2e unencrypted image
|
||||||
|
xxhash3 1 M block... 209000 iterations in 2001 ms = 104447.78 MB/s
|
||||||
|
xxhash3 4 K block... 37000000 iterations in 2022 ms = 71479.35 MB/s
|
||||||
|
|
||||||
|
Header encryption with payload checksums, e2e unencrypted image
|
||||||
|
AES-256-GCM encrypt header + xxhash3 1 M block... 210000 iterations in 2015 ms = 104218.36 MB/s
|
||||||
|
AES-256-GCM encrypt header + xxhash3 4 K block... 26000000 iterations in 2073 ms = 48993.01 MB/s
|
||||||
|
|
||||||
|
Full transport encryption, e2e unencrypted image
|
||||||
|
AES-256-GCM encrypt header and 1 M block... 54000 iterations in 2000 ms = 27000.00 MB/s
|
||||||
|
AES-256-GCM encrypt header and 4 K block... 11700000 iterations in 2014 ms = 22692.71 MB/s
|
||||||
|
|
||||||
|
No transport encryption, no checksums, e2e encrypted image
|
||||||
|
AES-256-XTS encrypt 1 M block... 50000 iterations in 2039 ms = 24521.82 MB/s
|
||||||
|
AES-256-XTS encrypt 4 K block... 12600000 iterations in 2009 ms = 24499.13 MB/s
|
||||||
|
|
||||||
|
No transport encryption, e2e encrypted image, data checksums enabled
|
||||||
|
AES-256-XTS encrypt + xxhash3 1 M block... 40000 iterations in 2013 ms = 19870.84 MB/s
|
||||||
|
AES-256-XTS encrypt + xxhash3 4 K block... 10200000 iterations in 2011 ms = 19812.90 MB/s
|
||||||
|
|
||||||
|
Header encryption with payload checksums, e2e encrypted image
|
||||||
|
AES-256-GCM encrypt header + AES-256-XTS encrypt + xxhash3 1 M block... 40000 iterations in 2014 ms = 19860.97 MB/s
|
||||||
|
AES-256-GCM encrypt header + AES-256-XTS encrypt + xxhash3 4 K block... 8700000 iterations in 2011 ms = 16899.24 MB/s
|
||||||
|
|
||||||
|
Full transport encryption, e2e encrypted image
|
||||||
|
AES-256-XTS + AES-256-GCM encrypt 1 M block... 26000 iterations in 2062 ms = 12609.12 MB/s
|
||||||
|
AES-256-XTS + AES-256-GCM encrypt 4 K block... 6300000 iterations in 2006 ms = 12267.88 MB/s
|
||||||
|
```
|
||||||
|
|
||||||
|
And here is Xeon E5-2680v4:
|
||||||
|
|
||||||
|
```
|
||||||
|
$ vitastor-cli cpubench
|
||||||
|
Vitastor transport encryption benchmark (AES-256-GCM, AES-256-XTS and xxhash3)
|
||||||
|
|
||||||
|
Warmup...
|
||||||
|
|
||||||
|
No transport encryption, data checksums enabled, e2e unencrypted image
|
||||||
|
xxhash3 1 M block... 62000 iterations in 2021 ms = 30677.88 MB/s
|
||||||
|
xxhash3 4 K block... 12400000 iterations in 2006 ms = 24146.31 MB/s
|
||||||
|
|
||||||
|
Header encryption with payload checksums, e2e unencrypted image
|
||||||
|
AES-256-GCM encrypt header + xxhash3 1 M block... 62000 iterations in 2027 ms = 30587.07 MB/s
|
||||||
|
AES-256-GCM encrypt header + xxhash3 4 K block... 6800000 iterations in 2011 ms = 13208.60 MB/s
|
||||||
|
|
||||||
|
Full transport encryption, e2e unencrypted image
|
||||||
|
AES-256-GCM encrypt header and 1 M block... 7000 iterations in 2317 ms = 3021.15 MB/s
|
||||||
|
AES-256-GCM encrypt header and 4 K block... 1500000 iterations in 2102 ms = 2787.52 MB/s
|
||||||
|
|
||||||
|
No transport encryption, no checksums, e2e encrypted image
|
||||||
|
AES-256-XTS encrypt 1 M block... 7000 iterations in 2317 ms = 3021.15 MB/s
|
||||||
|
AES-256-XTS encrypt 4 K block... 1600000 iterations in 2088 ms = 2993.30 MB/s
|
||||||
|
|
||||||
|
No transport encryption, e2e encrypted image, data checksums enabled
|
||||||
|
AES-256-XTS encrypt + xxhash3 1 M block... 6000 iterations in 2188 ms = 2742.23 MB/s
|
||||||
|
AES-256-XTS encrypt + xxhash3 4 K block... 1400000 iterations in 2053 ms = 2663.78 MB/s
|
||||||
|
|
||||||
|
Header encryption with payload checksums, e2e encrypted image
|
||||||
|
AES-256-GCM encrypt header + AES-256-XTS encrypt + xxhash3 1 M block... 6000 iterations in 2190 ms = 2739.73 MB/s
|
||||||
|
AES-256-GCM encrypt header + AES-256-XTS encrypt + xxhash3 4 K block... 1300000 iterations in 2101 ms = 2417.00 MB/s
|
||||||
|
|
||||||
|
Full transport encryption, e2e encrypted image
|
||||||
|
AES-256-XTS + AES-256-GCM encrypt 1 M block... 4000 iterations in 2666 ms = 1500.38 MB/s
|
||||||
|
AES-256-XTS + AES-256-GCM encrypt 4 K block... 800000 iterations in 2113 ms = 1478.94 MB/s
|
||||||
|
```
|
||||||
@@ -0,0 +1,662 @@
|
|||||||
|
[Документация](../../README-ru.md#документация) → Введение → Безопасность в Vitastor
|
||||||
|
|
||||||
|
-----
|
||||||
|
|
||||||
|
[Read in English](security.en.md)
|
||||||
|
|
||||||
|
# Безопасность в Vitastor
|
||||||
|
|
||||||
|
- [Обзор](#обзор)
|
||||||
|
- [Быстрая настройка](#быстрая-настройка)
|
||||||
|
- Принципы работы
|
||||||
|
- [Шифрование соединений с etcd (TLS)](#шифрование-соединений-с-etcd-tls)
|
||||||
|
- [Шифрование соединений с OSD (AES-GCM)](#шифрование-соединений-с-osd-aes-gcm)
|
||||||
|
- [Сквозное шифрование данных образов (AES-XTS)](#сквозное-шифрование-данных-образов-aes-xts)
|
||||||
|
- [Аутентификация по сертификатам](#аутентификация-по-сертификатам)
|
||||||
|
- [Пользователи и права доступа](#пользователи-и-права-доступа)
|
||||||
|
- [Привилегии etcd](#привилегии-etcd)
|
||||||
|
- Ручная настройка
|
||||||
|
- [Настройка шифрования соединений OSD](#настройка-шифрования-соединений-osd)
|
||||||
|
- Варианты настройки etcd/Antietcd
|
||||||
|
- [Mon со встроенным Antietcd](#mon-со-встроенным-antietcd)
|
||||||
|
- [Mon в роли Etcd proxy](#mon-в-роли-etcd-proxy)
|
||||||
|
- [Mon с отдельным Antietcd Proxy](#mon-с-отдельным-antietcd-proxy)
|
||||||
|
- [Отдельный Antietcd без etcd](#отдельный-antietcd-без-etcd)
|
||||||
|
- [Настройка Vault/OpenBao](#настройка-vaultopenbao)
|
||||||
|
- [Пример настройки Vault](#пример-настройки-vault)
|
||||||
|
- Списки разрешённых операций
|
||||||
|
- [Права доступа к данным etcd](#права-доступа-к-данным-etcd)
|
||||||
|
- [Права доступа к данным OSD](#права-доступа-к-данным-osd)
|
||||||
|
- [Права доступа к API](#права-доступа-к-api)
|
||||||
|
- [Производительность шифрования](#производительность-шифрования)
|
||||||
|
|
||||||
|
## Обзор
|
||||||
|
|
||||||
|
Начиная с версии 3.1.0, Vitastor предоставляет полную защиту данных: защиту слоя
|
||||||
|
управления (etcd), защиту слоя данных (OSD) и сквозное шифрование данных.
|
||||||
|
|
||||||
|
- Защита слоя управления:
|
||||||
|
- Шифрование соединений с etcd (TLS)
|
||||||
|
- Аутентификация по клиентским TLS (X.509) сертификатам
|
||||||
|
- Разграничение прав доступа клиентов к данным etcd
|
||||||
|
- Защита слоя данных:
|
||||||
|
- Либо полное AES-GCM шифрование соединений с OSD (аналогично TLS, но быстрее)
|
||||||
|
- Либо шифрование AES-GCM только заголовков команд с контрольными суммами данных с секретной "солью"
|
||||||
|
- Аутентификация по клиентским TLS (X.509) сертификатам
|
||||||
|
- Разграничение прав доступа клиентов на стороне OSD
|
||||||
|
- Сквозное шифрование:
|
||||||
|
- Данные шифруются AES-XTS на стороне клиента, кластер Vitastor не имеет доступа к открытым данным
|
||||||
|
- Ключи AES-XTS могут храниться в etcd или во внешнем Vault/OpenBao
|
||||||
|
|
||||||
|
Все функции опциональны и в простейшем варианте настройки выключены. По умолчанию включены
|
||||||
|
только контрольные суммы данных на транспортном уровне ([proto_checksums](../config/security.ru.md#proto_checksums)=payload) для
|
||||||
|
поддерживающих их клиентов (>= 3.1.0). Для более старых клиентов по умолчанию разрешены
|
||||||
|
соединения без контрольных сумм данных ([force_proto_checksums](../config/security.ru.md#force_proto_checksums) пусто).
|
||||||
|
|
||||||
|
Для быстрой настройки перейдите к разделу [Быстрая настройка](#быстрая-настройка).
|
||||||
|
|
||||||
|
Описания всех параметров, связанных с безопасностью, читайте [здесь](../config/security.ru.md).
|
||||||
|
|
||||||
|
## Быстрая настройка
|
||||||
|
|
||||||
|
Для быстрой настройки используйте скрипт `/usr/lib/vitastor/mon/make-etcd`:
|
||||||
|
|
||||||
|
1. Зайдите на узел, на котором будет располагаться первый монитор и etcd.
|
||||||
|
2. Создайте там минимальный `/etc/vitastor/vitastor.conf` с параметрами etcd_address,
|
||||||
|
osd_network и, если хотите включить привилегии - use_perms (обратите внимание на `https://`
|
||||||
|
в адресах etcd):
|
||||||
|
```
|
||||||
|
{
|
||||||
|
"etcd_address": ["https://10.0.0.10:2379","https://10.0.0.11:2379","https://10.0.0.12:2379"],
|
||||||
|
"osd_network": "10.0.0.0/24",
|
||||||
|
"use_perms": true
|
||||||
|
}
|
||||||
|
```
|
||||||
|
3. Запустите `/usr/lib/vitastor/mon/make-etcd` без параметров или с параметром `--antietcd-only`,
|
||||||
|
если хотите инициализировать кластер только с Antietcd без etcd.
|
||||||
|
4. Скрипт сгенерирует все необходимые сертификаты и предложит скопировать их на остальные узлы
|
||||||
|
мониторов (соглашайтесь!).
|
||||||
|
5. Зайдите на все остальные узлы мониторов и повторите там вызов `/usr/lib/vitastor/mon/make-etcd`.
|
||||||
|
6. Если у вас будут узлы только с OSD без мониторов, выполните следующую команду, чтобы скопировать
|
||||||
|
только нужную конфигурацию на эти узлы:
|
||||||
|
```
|
||||||
|
/usr/lib/vitastor/mon/make-etcd --copy-to-osd osdnode1,osdnode2,...
|
||||||
|
```
|
||||||
|
|
||||||
|
После этого можете переходить к инициализации OSD.
|
||||||
|
|
||||||
|
Если хотите разобраться в настройке подробнее, читайте далее разделы [Принципы работы](#принципы-работы)
|
||||||
|
и [Ручная настройка](#ручная-настройка).
|
||||||
|
|
||||||
|
## Принципы работы
|
||||||
|
|
||||||
|
### Шифрование соединений с etcd (TLS)
|
||||||
|
|
||||||
|
Варианты настройки:
|
||||||
|
- Без шифрования (http)
|
||||||
|
- С шифрованием (https)
|
||||||
|
- С шифрованием и аутентификацией по клиентским сертификатам. Используется либо тот
|
||||||
|
же сертификат, что используется для аутентификации на стороне OSD (`cert`+`pkey` / `osd_cert`+`osd_pkey`),
|
||||||
|
либо отдельно указанный сертификат (`etcd_client_cert`+`etcd_client_key`)
|
||||||
|
|
||||||
|
### Шифрование соединений с OSD (AES-GCM)
|
||||||
|
|
||||||
|
Варианты настройки:
|
||||||
|
- Без шифрования и без контрольных сумм: `proto_checksums=none`.
|
||||||
|
- Без шифрования, с контрольными суммами данных: `proto_checksums=payload` (можно не указывать,
|
||||||
|
т.к. это значение по умолчанию). При этом контрольные суммы можно отключить на стороне
|
||||||
|
клиента либо использовать более старые версии клиента, не поддерживающие контрольные суммы.
|
||||||
|
Если нужно запретить подключение клиентов без контрольных сумм, можно использовать опцию
|
||||||
|
`force_proto_checksums=payload`.
|
||||||
|
- С шифрованием заголовков и контрольными суммами данных: активируется при установленных опциях
|
||||||
|
`cert`, `pkey`, `osd_ca` на стороне клиента и `osd_cert`, `osd_pkey`, `osd_ca`, `client_ca`
|
||||||
|
на стороне OSD, при `proto_checksums=payload`. При этом по умолчанию запрещается
|
||||||
|
отключение контрольных сумм на уровне клиента, то есть используется `force_proto_checksums=payload`.
|
||||||
|
- С полным шифрованием всего трафика: аналогично прошлому варианту, но с `proto_checksums=gcm`.
|
||||||
|
Клиенту при этом по умолчанию разрешается понизить уровень защиты до контрольных сумм, но
|
||||||
|
это тоже можно запретить через `force_proto_checksums=gcm`. Данный вариант самый медленный и
|
||||||
|
рекомендуется только для небезопасных (публичных) сетей. В том числе потому, что при использовании
|
||||||
|
и полного шифрования трафика, и сквозного шифрования образов AES-XTS, данные шифруются дважды.
|
||||||
|
|
||||||
|
Для шифрования используется алгоритм AES-256-GCM и собственный упрощённый протокол согласования
|
||||||
|
ключей, полностью аналогичный TLS 1.3 ECDHE.
|
||||||
|
|
||||||
|
### Сквозное шифрование данных образов (AES-XTS)
|
||||||
|
|
||||||
|
Клиент Vitastor поддерживает шифрование данных каждого образа своим ключом. В этом случае на OSD
|
||||||
|
уходят уже зашифрованные данные и сами OSD не видят исходные данные клиента. При этом ключ можно
|
||||||
|
менять при клонировании/создании снимков образов. Например, можно сделать базовый образ ВМ
|
||||||
|
(условный Debian Linux) нешифрованным, но наследовать от него шифрованные образы клиентских ВМ.
|
||||||
|
|
||||||
|
Ключи шифрования образов могут храниться либо в etcd, либо во внешнем Vault. Во втором случае
|
||||||
|
в etcd хранятся только ID ключей, а Vitastor вообще не имеет доступа к данным образов. Для
|
||||||
|
использования Vault нужно создать образ с опцией `--enc_key vault:ID`, в конфигурации указать
|
||||||
|
опции vault_url, и vault_ca, создать всем клиентам учётные записи в Vault и дать им доступ
|
||||||
|
к требуемым секретам v1.
|
||||||
|
|
||||||
|
Ещё раз повторимся, что если AES-XTS используется с полным шифрованием трафика (`proto_checksums=gcm`),
|
||||||
|
то данные образов шифруются дважды - сначала AES-XTS, а потом AES-GCM. Можете использовать,
|
||||||
|
только если вы совсем параноик :-).
|
||||||
|
|
||||||
|
### Аутентификация по сертификатам
|
||||||
|
|
||||||
|
При включённом шифровании клиенты, OSD и мониторы Vitastor аутентифицируются по сертификатам
|
||||||
|
как при соединениях с etcd (Antietcd), так и с OSD.
|
||||||
|
|
||||||
|
Для OSD и мониторов должны использоваться отдельные сертификаты - либо самоподписанные, либо
|
||||||
|
подписанные отдельными CA (`osd_ca` и `mon_ca`). При этом все OSD могут использовать один и
|
||||||
|
тот же сертификат и все мониторы тоже могут использовать один и тот же сертификат, так как
|
||||||
|
привилегии разных OSD или разных мониторов ничем не отличаются (теоретически можно было бы
|
||||||
|
сделать разграничение сертификатов OSD по пулам, но пока что такой необходимости не было).
|
||||||
|
|
||||||
|
Также сертификат монитора может быть вообще не нужен, если Antietcd встраивается в сам монитор.
|
||||||
|
В этом случае монитор и так имеет доступ ко всем данным etcd прямо в памяти.
|
||||||
|
|
||||||
|
### Пользователи и права доступа
|
||||||
|
|
||||||
|
При отключённом шифровании трафика Vitastor работает без разграничения прав доступа, то есть,
|
||||||
|
любой клиент кластера имеет полный доступ как к слою управлению, так и к слою данных. Такой
|
||||||
|
вариант подходит для выделенных доверенных сетей хранения.
|
||||||
|
|
||||||
|
При включённом шифровании трафика OSD (хотя бы заголовков) есть возможность задействовать
|
||||||
|
права доступа, включив опцию `use_perms=true`. При включённой опции каждый пользователь может
|
||||||
|
выполнять только те операции, которые ему разрешены, и даже OSD и мониторам также запрещены
|
||||||
|
"лишние" операции.
|
||||||
|
|
||||||
|
Каждый пользователь (или администратор) должен иметь свой сертификат, подписанный общим
|
||||||
|
корневым сертификатом для клиентов (`client_ca`), с Common Name, равным имени пользователя.
|
||||||
|
Настройки привилегий же хранятся в etcd. Для OSD и мониторов учётные записи не нужны,
|
||||||
|
они аутентифицируются по отдельным сертификатам.
|
||||||
|
|
||||||
|
Привилегии пользователей хранятся в данных etcd в ключах `/vitastor/config/user/<имя>`.
|
||||||
|
В этом ключе для каждого пользователя задаётся:
|
||||||
|
- Тип:
|
||||||
|
- Клиент (`type=client` или не указано) - может читать и модифицировать только явным образом
|
||||||
|
разрешённые образы.
|
||||||
|
- Администратор (`type=admin`) - может читать и модифицировать все образы, а также администрировать
|
||||||
|
кластер: смотреть общую статистику и состояние, создавать и удалять OSD и так далее.
|
||||||
|
- Список имён групп, членом которых пользователь является.
|
||||||
|
|
||||||
|
У образов есть следующие свойства:
|
||||||
|
- Владелец (owner) - имя пользователя, которому разрешено и читать, и менять образ
|
||||||
|
- Группа владельцев (owner_group) - имя группы владельцев
|
||||||
|
- Группа читателей (reader_group) - имя группы пользователей, которым разрешено читать образ
|
||||||
|
|
||||||
|
И также есть свойство у пула:
|
||||||
|
- Группа создателей (creator_group) - имя группы пользователей, которым разрешено создавать образы в пуле
|
||||||
|
|
||||||
|
Перечень разрешённых операций с данными образов на стороне OSD смотрите в разделе
|
||||||
|
[Права доступа к данным OSD](#права-доступа-к-данным-osd).
|
||||||
|
|
||||||
|
### Привилегии etcd
|
||||||
|
|
||||||
|
Привилегии etcd реализуются через Antietcd во всех режимах работы.
|
||||||
|
|
||||||
|
Встроенные привилегии etcd не поддерживаются по причине их многочисленных неудобств:
|
||||||
|
- Аутентификация по сертификатам вообще не работает в REST интерфейсе etcd,
|
||||||
|
- Привилегии хранятся отдельно от k/v данных и не могут участвовать в транзакциях,
|
||||||
|
- Менять привилегии может только администратор (root),
|
||||||
|
- Нет поддержки фильтрации диапазонных ответов чтения по привилегиям.
|
||||||
|
|
||||||
|
Если используется etcd, то Antietcd выступает в роли фильтрующего прокси, при этом он
|
||||||
|
может быть встроен в монитор Vitastor или запущен отдельно. В этом случае etcd должен
|
||||||
|
разрешать входящие подключения только от Antietcd, а все остальные компоненты должны
|
||||||
|
соединяться с Antietcd.
|
||||||
|
|
||||||
|
Если Antietcd запускается в составе монитора Vitastor, то достаточно включить опцию
|
||||||
|
`use_perms=true` и задать нужные сертификаты. Если Antietcd запускается отдельно, то
|
||||||
|
привилегии нужно включать отдельно опциями Antietcd. Подробнее о настройке смотрите
|
||||||
|
раздел [Варианты настройки etcd/Antietcd](#варианты-настройки-etcdantietcd).
|
||||||
|
|
||||||
|
Перечень разрешённых операций с данными etcd смотрите в разделе
|
||||||
|
[Права доступа к данным etcd](#права-доступа-к-данным-etcd).
|
||||||
|
|
||||||
|
## Ручная настройка
|
||||||
|
|
||||||
|
### Настройка шифрования соединений OSD
|
||||||
|
|
||||||
|
Вам нужно 2 сертификата: один для OSD и один для подписи сертификатов всех клиентов.
|
||||||
|
Для OSD можно использовать самоподписанный сертификат (osd_ca.crt) или отдельный сертификат (osd.crt),
|
||||||
|
подписанный доверенным сертификатом osd_ca.crt. Для клиентов нужно использовать отдельные
|
||||||
|
сертификаты, подписанные общим доверенным (client_ca.crt).
|
||||||
|
|
||||||
|
В конфигурацию Vitastor на серверах OSD нужно добавить:
|
||||||
|
- use_perms: true
|
||||||
|
- osd_ca: osd_ca.crt
|
||||||
|
- client_ca: client_ca.crt
|
||||||
|
- osd_cert: osd_ca.crt
|
||||||
|
- osd_pkey: osd_ca.key
|
||||||
|
|
||||||
|
На стороне клиентов:
|
||||||
|
- use_perms: true
|
||||||
|
- cert: client.crt
|
||||||
|
- pkey: client.key
|
||||||
|
|
||||||
|
### Варианты настройки etcd/Antietcd
|
||||||
|
|
||||||
|
Доступны следующие варианты настройки:
|
||||||
|
|
||||||
|
#### Mon со встроенным Antietcd
|
||||||
|
|
||||||
|
Самый простой вариант. Вам нужен 1 сертификат для Antietcd (antietcd.crt), плюс
|
||||||
|
корневые сертификаты для OSD и клиентов.
|
||||||
|
|
||||||
|
Настройки Vitastor (`/etc/vitastor/vitastor.conf`):
|
||||||
|
- etcd_address: [ "http://mon1:2379", ... ] (адреса ваших мониторов с портом 2379)
|
||||||
|
- use_perms: true
|
||||||
|
- use_antietcd: true
|
||||||
|
- antietcd_cert: antietcd.crt
|
||||||
|
- antietcd_key: antietcd.key
|
||||||
|
- etcd_ca: antietcd.crt
|
||||||
|
- osd_ca: osd_ca.crt
|
||||||
|
- client_ca: client_ca.crt
|
||||||
|
|
||||||
|
#### Mon в роли Etcd proxy
|
||||||
|
|
||||||
|
Если вы хотите включить привилегии, но остаться на etcd, можно задействовать режим etcd proxy.
|
||||||
|
|
||||||
|
Вам понадобится 2 отдельных сертификата: один для etcd (etcd.crt) и один для antietcd (antietcd.crt).
|
||||||
|
Клиентский порт etcd должен отличаться от стандартного 2379, например, можно выбрать 2381.
|
||||||
|
Также нужны сертификаты OSD и клиентов.
|
||||||
|
|
||||||
|
Настройки Vitastor:
|
||||||
|
- etcd_address: [ "http://mon1:2379", ... ] (адреса ваших мониторов с портом 2379)
|
||||||
|
- use_perms: true
|
||||||
|
- use_antietcd: true
|
||||||
|
- etcd_proxy:
|
||||||
|
```
|
||||||
|
{
|
||||||
|
"urls": [ "http://mon1:2381", ... ], // адреса ваших etcd с портом 2381
|
||||||
|
"cert": "antietcd.crt",
|
||||||
|
"key": "antietcd.key",
|
||||||
|
"ca": "etcd.crt"
|
||||||
|
}
|
||||||
|
```
|
||||||
|
- antietcd_cert: antietcd.crt
|
||||||
|
- antietcd_key: antietcd.key
|
||||||
|
- etcd_ca: antietcd.crt
|
||||||
|
- osd_ca: osd_ca.crt
|
||||||
|
- client_ca: client_ca.crt
|
||||||
|
|
||||||
|
Опции командной строки etcd:
|
||||||
|
```
|
||||||
|
--advertise-client-urls=https://<АДРЕС>:2381 --listen-client-urls=https://<АДРЕС>:2381 \
|
||||||
|
--client-cert-auth --cert-file=etcd.crt --key-file=etcd.key --trusted-ca-file=antietcd.crt \
|
||||||
|
--peer-client-cert-auth --peer-cert-file=etcd.crt --peer-key-file=etcd.key --peer-trusted-ca-file=etcd.crt
|
||||||
|
```
|
||||||
|
|
||||||
|
#### Mon с отдельным Antietcd Proxy
|
||||||
|
|
||||||
|
Если в дополнение к предыдущему варианту вы хотите разгрузить Antietcd от задач монитора Vitastor,
|
||||||
|
можно запустить его отдельно.
|
||||||
|
|
||||||
|
Аналогично предыдущему варианту нужно 2 сертификата: один для etcd и один для antietcd, плюс понадобятся
|
||||||
|
отдельные сертификаты для клиентов, OSD и монитора.
|
||||||
|
|
||||||
|
Настройки Vitastor:
|
||||||
|
- etcd_address: [ "http://mon1:2379", ... ] (адреса ваших мониторов с портом 2379)
|
||||||
|
- use_perms: true
|
||||||
|
- use_antietcd: false
|
||||||
|
- etcd_ca: antietcd.crt
|
||||||
|
- osd_ca: osd_ca.crt
|
||||||
|
- client_ca: client_ca.crt
|
||||||
|
- mon_etcd_client_cert: mon_ca.crt
|
||||||
|
- mon_etcd_client_key: mon_ca.key
|
||||||
|
|
||||||
|
Опции командной строки Antietcd:
|
||||||
|
```
|
||||||
|
--port 2379 \
|
||||||
|
--client_cert_auth 1 --auth_filter vitastor_auth_filter.js --etcd_proxy url1,url2,... \
|
||||||
|
--cert antietcd.crt --key antietcd.key --ca client_ca.crt --osd_ca osd_ca.crt --mon_ca mon_ca.crt \
|
||||||
|
--etcd_cert antietcd.crt --etcd_key antietcd.key --etcd_ca etcd.crt
|
||||||
|
```
|
||||||
|
|
||||||
|
Опции командной строки etcd (не отличаются от предыдущего варианта):
|
||||||
|
```
|
||||||
|
--advertise-client-urls=https://<АДРЕС>:2381 --listen-client-urls=https://<АДРЕС>:2381 \
|
||||||
|
--client-cert-auth --cert-file=etcd.crt --key-file=etcd.key --trusted-ca-file=antietcd.crt \
|
||||||
|
--peer-client-cert-auth --peer-cert-file=etcd.crt --peer-key-file=etcd.key --peer-trusted-ca-file=etcd.crt
|
||||||
|
```
|
||||||
|
|
||||||
|
#### Отдельный Antietcd без etcd
|
||||||
|
|
||||||
|
Аналогично предыдущему варианту, но etcd и его сертификат не нужны:
|
||||||
|
|
||||||
|
Настройки Vitastor (не отличаются от предыдущего варианта):
|
||||||
|
- etcd_address: [ "http://mon1:2379", ... ] (адреса ваших мониторов с портом 2379)
|
||||||
|
- use_perms: true
|
||||||
|
- use_antietcd: false
|
||||||
|
- etcd_ca: antietcd.crt
|
||||||
|
- osd_ca: osd_ca.crt
|
||||||
|
- client_ca: client_ca.crt
|
||||||
|
- mon_etcd_client_cert: mon_ca.crt
|
||||||
|
- mon_etcd_client_key: mon_ca.key
|
||||||
|
|
||||||
|
Опции командной строки Antietcd:
|
||||||
|
```
|
||||||
|
--port 2379 \
|
||||||
|
--client_cert_auth 1 --auth_filter vitastor_auth_filter.js \
|
||||||
|
--persist_filter vitastor_persist_filter.js \
|
||||||
|
--cert antietcd.crt --key antietcd.key --ca client_ca.crt --osd_ca osd_ca.crt --mon_ca mon_ca.crt
|
||||||
|
```
|
||||||
|
|
||||||
|
### Настройка Vault/OpenBao
|
||||||
|
|
||||||
|
Для использования Vault каждому клиенту, который будет получать из Vault ключи
|
||||||
|
образов, нужна учётная запись в Vault. Vitastor поддерживает только аутентификацию
|
||||||
|
по клиентским сертификатам, так что все сертификаты клиентов (`cert`+`pkey`) должны
|
||||||
|
быть зарегистрированы в Vault и им должен быть дан доступ к соответствующим секретам
|
||||||
|
(поддерживается API секретов v1).
|
||||||
|
|
||||||
|
Требуемый формат секрета Vault - одно поле `key` в формате шестнадцатеричной строки.
|
||||||
|
Используется алгоритм AES-256-XTS, так что длина ключа - 64 байта, то есть строка
|
||||||
|
должна состоять из 128 шестнадцатеричных цифр.
|
||||||
|
|
||||||
|
Для подключения Vault включите следующие настройки в Vitastor.conf:
|
||||||
|
- `vault_url` - адрес Vault (например, `https://vault:8200`)
|
||||||
|
- `vault_ca` - сертификат самого Vault
|
||||||
|
|
||||||
|
После этого, если создать образ (`vitastor-cli create`) с опцией `--enc_key vault:<ID>`,
|
||||||
|
то для получения ключа клиенты Vitastor сначала обратятся к Vault для получения токена
|
||||||
|
по адресу `/v1/auth/cert/login`, а потом запросят из Vault сам секрет по адресу `/v1/secret/<ID>`.
|
||||||
|
|
||||||
|
#### Пример настройки Vault
|
||||||
|
|
||||||
|
Пошаговая инструкция для настройки тестового Vault на примере OpenBao:
|
||||||
|
|
||||||
|
1. Если ещё не настроен TLS, генерируем самоподписанный TLS сертификат для Vault:
|
||||||
|
```
|
||||||
|
openssl req -days 3650 -x509 -addext basicConstraints=critical,CA:TRUE,pathlen:1 --addext subjectAltName=DNS:vault \
|
||||||
|
-new -newkey rsa:4096 -nodes -keyout /etc/openbao/vault.key -out /etc/openbao/vault.crt
|
||||||
|
```
|
||||||
|
Настраиваем его в `/etc/openbao/openbao.hcl`:
|
||||||
|
```
|
||||||
|
listener "tcp" {
|
||||||
|
address = "0.0.0.0:8200"
|
||||||
|
tls_cert_file = "/etc/openbao/vault.crt"
|
||||||
|
tls_key_file = "/etc/openbao/vault.key"
|
||||||
|
}
|
||||||
|
```
|
||||||
|
И перезапускаем OpenBao (`systemctl restart openbao`).
|
||||||
|
2. Копируем TLS сертификат Vault для Vitastor:
|
||||||
|
```
|
||||||
|
cp /etc/openbao/vault.crt /etc/vitastor/vault.crt
|
||||||
|
```
|
||||||
|
Переносим его на все клиентские ноды и прописываем в `/etc/vitastor/vitastor.conf`:
|
||||||
|
```
|
||||||
|
{
|
||||||
|
...
|
||||||
|
"vault_url": "http://vault:8200",
|
||||||
|
"vault_ca": "/etc/vitastor/vault.crt"
|
||||||
|
}
|
||||||
|
```
|
||||||
|
3. Проверяем статус Vault:
|
||||||
|
```
|
||||||
|
bao status -ca-cert /etc/openbao/vault.crt -address=https://vault:8200
|
||||||
|
```
|
||||||
|
4. Инициализируем Vault в тестовом режиме из 1 ноды (с 1 частью ключа):
|
||||||
|
```
|
||||||
|
bao operator init -n 1 -t 1 -ca-cert /etc/openbao/vault.crt -address=https://vault:8200
|
||||||
|
```
|
||||||
|
5. Разблокируем Vault:
|
||||||
|
```
|
||||||
|
bao operator unseal -ca-cert /etc/openbao/vault.crt -address=https://vault:8200
|
||||||
|
```
|
||||||
|
6. Включаем аутентификацию по сертификатам:
|
||||||
|
```
|
||||||
|
bao auth enable -ca-cert /etc/openbao/vault.crt -address=https://vault:8200 cert
|
||||||
|
```
|
||||||
|
7. Включаем секреты v1:
|
||||||
|
```
|
||||||
|
bao secrets enable -ca-cert /etc/openbao/vault.crt -address=https://vault:8200 -path=secret kv-v1
|
||||||
|
```
|
||||||
|
8. Создаём тестовый секрет:
|
||||||
|
```
|
||||||
|
bao kv put -ca-cert /etc/openbao/vault.crt -address=https://vault:8200 secret/vitastor/testimg3 key=$(openssl rand -hex 64)
|
||||||
|
```
|
||||||
|
9. Генерируем подписанный сертификат для пользователя Vitastor (там, где у вас есть `client_ca.crt` и `client_ca.key`):
|
||||||
|
```
|
||||||
|
openssl req -subj '/CN=testimg3' -nodes -new -keyout testimg3.key -out testimg3.csr
|
||||||
|
openssl x509 -req -days 3650 -CA client_ca.crt -CAkey client_ca.key -CAcreateserial -in testimg3.csr -out testimg3.crt
|
||||||
|
rm testimg3.csr
|
||||||
|
```
|
||||||
|
10. Создаём пользователя в Vault и даём ему доступ к секрету:
|
||||||
|
```
|
||||||
|
cat >testimg3.policy <<EOF
|
||||||
|
path "/secret/vitastor/testimg3" {
|
||||||
|
capabilities = ["read"]
|
||||||
|
}
|
||||||
|
EOF
|
||||||
|
|
||||||
|
bao policy write -ca-cert /etc/openbao/vault.crt -address=https://vault:8200 testimg3 testimg3.policy
|
||||||
|
|
||||||
|
bao write -ca-cert /etc/openbao/vault.crt -address=https://vault:8200 auth/cert/certs/testimg3 \
|
||||||
|
certificate=@testimg3.crt display_name=testimg3 token_ttl=24h token_policies=testimg3
|
||||||
|
```
|
||||||
|
11. Тестируем доступ к секрету:
|
||||||
|
```
|
||||||
|
curl --cacert /etc/vitastor/vault.crt --cert testimg3.crt --key testimg3.key \
|
||||||
|
--json '{}' https://vault:8200/v1/auth/cert/login
|
||||||
|
```
|
||||||
|
Будет выведен токен, подставляем его в следующий запрос:
|
||||||
|
```
|
||||||
|
curl --cacert /etc/vitastor/vault.crt --cert testimg3.crt --key testimg3.key \
|
||||||
|
-H 'X-Vault-Token: <ПОЛУЧЕННЫЙ ТОКЕН>' https://vault:8200/v1/secret/vitastor/testimg3
|
||||||
|
```
|
||||||
|
12. Создаём образ в Vitastor с заданным секретом (от имени администратора или того, кто имеет
|
||||||
|
право создавать образы в вашем пуле):
|
||||||
|
```
|
||||||
|
vitastor-cli create -s 100G --enc_key vault:vitastor/testimg3 --owner testimg3 testimg3
|
||||||
|
```
|
||||||
|
13. Тестируем доступ к образу от имени пользователя testimg3:
|
||||||
|
```
|
||||||
|
vitastor-cli --cert testimg3.crt --pkey testimg3.key dd if=/dev/urandom oimg=testimg3 bs=1M count=100
|
||||||
|
```
|
||||||
|
|
||||||
|
## Списки разрешённых операций
|
||||||
|
|
||||||
|
### Права доступа к данным etcd
|
||||||
|
|
||||||
|
Ниже все названия ключей приведены без общего префикса `/vitastor`.
|
||||||
|
|
||||||
|
Разрешённые операции с ключами в Antietcd для клиентов (`type=client`):
|
||||||
|
- Только чтение:
|
||||||
|
- Разрешено всегда:
|
||||||
|
- `/config/global`
|
||||||
|
- `/config/node_placement`
|
||||||
|
- `/config/pools`
|
||||||
|
- `/pg/config`
|
||||||
|
- `/osd/state/*`
|
||||||
|
- `/pg/state/*`
|
||||||
|
- `/index/maxid/*`
|
||||||
|
- Для образов, которые [может читать пользователь](#пользователи-и-права-доступа):
|
||||||
|
- `/config/inode/*`
|
||||||
|
- `/index/image/*`
|
||||||
|
- `/inode/stats/*`
|
||||||
|
- Чтение и запись:
|
||||||
|
- Для пулов, в которых может создавать образы пользователь:
|
||||||
|
- `/index/maxid/*`
|
||||||
|
- Для образов, которыми владеет пользователь:
|
||||||
|
- `/config/inode/*`
|
||||||
|
- `/index/image/*`
|
||||||
|
|
||||||
|
Разрешённые операции с ключами в Antietcd для администраторов (`type=admin`):
|
||||||
|
- Чтение:
|
||||||
|
- `/stats`
|
||||||
|
- `/mon/*`
|
||||||
|
- `/pg/*`
|
||||||
|
- `/pgstats/*`
|
||||||
|
- `/inode/stats/*`
|
||||||
|
- `/pool/stats/*`
|
||||||
|
- Чтение и запись:
|
||||||
|
- `/config/*`
|
||||||
|
- `/osd/*`
|
||||||
|
- `/index/*`
|
||||||
|
- `/pg/history/*`
|
||||||
|
|
||||||
|
Разрешённые операции с ключами в etcd для OSD:
|
||||||
|
- Чтение:
|
||||||
|
- `/pg/config`
|
||||||
|
- `/config/*`
|
||||||
|
- Чтение и запись:
|
||||||
|
- `/osd/*`
|
||||||
|
- `/pg/state/*`
|
||||||
|
- `/pg/history/*`
|
||||||
|
- `/pgstats/*`
|
||||||
|
|
||||||
|
Разрешённые операции с ключами в etcd для мониторов:
|
||||||
|
- Чтение:
|
||||||
|
- `/config/*`
|
||||||
|
- `/osd/*`
|
||||||
|
- `/pgstats/*`
|
||||||
|
- Чтение и запись:
|
||||||
|
- `/pg/config`
|
||||||
|
- `/stats`
|
||||||
|
- `/history/last_clean_pgs`
|
||||||
|
- `/mon/*`
|
||||||
|
- `/pg/history/*`
|
||||||
|
- `/inode/stats/*`
|
||||||
|
- `/pool/stats/*`
|
||||||
|
|
||||||
|
### Права доступа к данным OSD
|
||||||
|
|
||||||
|
При включённой опции `use_perms` и шифровании OSD аутентифицирует клиентов по сертификатам
|
||||||
|
и разрешает каждому клиенту только то, что ему разрешено согласно модели прав доступа.
|
||||||
|
|
||||||
|
Клиентские операции:
|
||||||
|
- READ - разрешено для образов, доступных пользователю на чтение.
|
||||||
|
- WRITE, DELETE, SCRUB - разрешены для образов, доступных пользователю на запись.
|
||||||
|
- SYNC - операция не связана с образом и разрешена всегда.
|
||||||
|
- DESCRIBE - операция разрешена только для администраторов (используются командами
|
||||||
|
`vitastor-cli describe` и `fix`).
|
||||||
|
- PING - операция разрешена всегда.
|
||||||
|
- SHOW_CONFIG - операция разрешена всегда, однако если в ней клиент представляется
|
||||||
|
как OSD, то проверяется, что он использует сертификат, подписанный `osd_ca`.
|
||||||
|
- SEC_LIST (листинг) - разрешена другим OSD и администраторам с любыми параметрами,
|
||||||
|
а обычным клиентам разрешена только для запросов, ограниченных образом, доступным
|
||||||
|
пользователю на чтение.
|
||||||
|
|
||||||
|
Кластерные операции - разрешаются только другим OSD:
|
||||||
|
- SEC_READ
|
||||||
|
- SEC_WRITE
|
||||||
|
- SEC_WRITE_STABLE
|
||||||
|
- SEC_SYNC
|
||||||
|
- SEC_STABILIZE
|
||||||
|
- SEC_ROLLBACK
|
||||||
|
- SEC_DELETE
|
||||||
|
- SEC_READ_BMP
|
||||||
|
- SEC_LOCK
|
||||||
|
|
||||||
|
### Права доступа к API
|
||||||
|
|
||||||
|
[vitastor-cli serve](../usage/cli.ru.md#serve) также поддерживает клиентскую
|
||||||
|
аутентификацию по сертификатам. Принимаются только сертификаты, подписанные
|
||||||
|
`client_ca`. В качестве серверного сертификата используется отдельный сертификат
|
||||||
|
`server_cert` с ключом `server_pkey`.
|
||||||
|
|
||||||
|
При этом для корректной работы `vitastor-cli serve` он сам должен использовать
|
||||||
|
для доступа в Vitastor сертификат (`cert`+`pkey`) пользователя с правами
|
||||||
|
администратора (`type=admin`).
|
||||||
|
|
||||||
|
Обычным клиентам при доступе к API разрешаются только API-операции с образами,
|
||||||
|
доступными им либо на чтение (для чтения), либо на запись (для модификации).
|
||||||
|
Все остальные API-вызовы разрешаются только для администраторов.
|
||||||
|
|
||||||
|
Список разрешённых операций API:
|
||||||
|
|
||||||
|
Клиентам (пользователям с `type=client`) разрешаются операции:
|
||||||
|
- image/list - для образов, которые пользователь может читать.
|
||||||
|
- image/create - для пулов, в которых пользователю разрешено создавать образы, либо
|
||||||
|
для создания снимков образов, которыми пользователь владеет.
|
||||||
|
- image/delete, image/flatten, image/modify - для образов, которыми пользователь владеет.
|
||||||
|
|
||||||
|
Все остальные операции разрешаются только администраторам (`type=admin`).
|
||||||
|
|
||||||
|
## Производительность шифрования
|
||||||
|
|
||||||
|
У вас может возникнуть вопрос - а как быстро всё это прекрасное шифрование работает?
|
||||||
|
|
||||||
|
Ответ - сильно зависит от процессора. На современных процессорах (при наличии AVX512 с VAES)
|
||||||
|
очень быстро - скорость шифрования AES может составлять 10-20 Гбайт/с и выше. В первую очередь
|
||||||
|
подразумевается CPU клиентских машин, потому что сквозное шифрование выполняется целиком на
|
||||||
|
клиенте, а транспортное хоть также и затрагивает OSD, но у клиента поток один, а OSD на стороне
|
||||||
|
сервера много и добавить там ресурсов легче.
|
||||||
|
|
||||||
|
На более старых процессорах скорость заметно хуже, например, на Xeon E5 v4 она составляет
|
||||||
|
буквально 3 Гбайт/с.
|
||||||
|
|
||||||
|
Вы можете оценить производительность своих процессоров с помощью команды `vitastor-cli cpubench`.
|
||||||
|
|
||||||
|
Пример вывода (💪 AMD EPYC 9575F):
|
||||||
|
|
||||||
|
```
|
||||||
|
$ vitastor-cli cpubench
|
||||||
|
Vitastor transport encryption benchmark (AES-256-GCM, AES-256-XTS and xxhash3)
|
||||||
|
|
||||||
|
Warmup...
|
||||||
|
|
||||||
|
No transport encryption, data checksums enabled, e2e unencrypted image
|
||||||
|
xxhash3 1 M block... 209000 iterations in 2001 ms = 104447.78 MB/s
|
||||||
|
xxhash3 4 K block... 37000000 iterations in 2022 ms = 71479.35 MB/s
|
||||||
|
|
||||||
|
Header encryption with payload checksums, e2e unencrypted image
|
||||||
|
AES-256-GCM encrypt header + xxhash3 1 M block... 210000 iterations in 2015 ms = 104218.36 MB/s
|
||||||
|
AES-256-GCM encrypt header + xxhash3 4 K block... 26000000 iterations in 2073 ms = 48993.01 MB/s
|
||||||
|
|
||||||
|
Full transport encryption, e2e unencrypted image
|
||||||
|
AES-256-GCM encrypt header and 1 M block... 54000 iterations in 2000 ms = 27000.00 MB/s
|
||||||
|
AES-256-GCM encrypt header and 4 K block... 11700000 iterations in 2014 ms = 22692.71 MB/s
|
||||||
|
|
||||||
|
No transport encryption, no checksums, e2e encrypted image
|
||||||
|
AES-256-XTS encrypt 1 M block... 50000 iterations in 2039 ms = 24521.82 MB/s
|
||||||
|
AES-256-XTS encrypt 4 K block... 12600000 iterations in 2009 ms = 24499.13 MB/s
|
||||||
|
|
||||||
|
No transport encryption, e2e encrypted image, data checksums enabled
|
||||||
|
AES-256-XTS encrypt + xxhash3 1 M block... 40000 iterations in 2013 ms = 19870.84 MB/s
|
||||||
|
AES-256-XTS encrypt + xxhash3 4 K block... 10200000 iterations in 2011 ms = 19812.90 MB/s
|
||||||
|
|
||||||
|
Header encryption with payload checksums, e2e encrypted image
|
||||||
|
AES-256-GCM encrypt header + AES-256-XTS encrypt + xxhash3 1 M block... 40000 iterations in 2014 ms = 19860.97 MB/s
|
||||||
|
AES-256-GCM encrypt header + AES-256-XTS encrypt + xxhash3 4 K block... 8700000 iterations in 2011 ms = 16899.24 MB/s
|
||||||
|
|
||||||
|
Full transport encryption, e2e encrypted image
|
||||||
|
AES-256-XTS + AES-256-GCM encrypt 1 M block... 26000 iterations in 2062 ms = 12609.12 MB/s
|
||||||
|
AES-256-XTS + AES-256-GCM encrypt 4 K block... 6300000 iterations in 2006 ms = 12267.88 MB/s
|
||||||
|
```
|
||||||
|
|
||||||
|
А вот Xeon E5-2680v4:
|
||||||
|
|
||||||
|
```
|
||||||
|
$ vitastor-cli cpubench
|
||||||
|
Vitastor transport encryption benchmark (AES-256-GCM, AES-256-XTS and xxhash3)
|
||||||
|
|
||||||
|
Warmup...
|
||||||
|
|
||||||
|
No transport encryption, data checksums enabled, e2e unencrypted image
|
||||||
|
xxhash3 1 M block... 62000 iterations in 2021 ms = 30677.88 MB/s
|
||||||
|
xxhash3 4 K block... 12400000 iterations in 2006 ms = 24146.31 MB/s
|
||||||
|
|
||||||
|
Header encryption with payload checksums, e2e unencrypted image
|
||||||
|
AES-256-GCM encrypt header + xxhash3 1 M block... 62000 iterations in 2027 ms = 30587.07 MB/s
|
||||||
|
AES-256-GCM encrypt header + xxhash3 4 K block... 6800000 iterations in 2011 ms = 13208.60 MB/s
|
||||||
|
|
||||||
|
Full transport encryption, e2e unencrypted image
|
||||||
|
AES-256-GCM encrypt header and 1 M block... 7000 iterations in 2317 ms = 3021.15 MB/s
|
||||||
|
AES-256-GCM encrypt header and 4 K block... 1500000 iterations in 2102 ms = 2787.52 MB/s
|
||||||
|
|
||||||
|
No transport encryption, no checksums, e2e encrypted image
|
||||||
|
AES-256-XTS encrypt 1 M block... 7000 iterations in 2317 ms = 3021.15 MB/s
|
||||||
|
AES-256-XTS encrypt 4 K block... 1600000 iterations in 2088 ms = 2993.30 MB/s
|
||||||
|
|
||||||
|
No transport encryption, e2e encrypted image, data checksums enabled
|
||||||
|
AES-256-XTS encrypt + xxhash3 1 M block... 6000 iterations in 2188 ms = 2742.23 MB/s
|
||||||
|
AES-256-XTS encrypt + xxhash3 4 K block... 1400000 iterations in 2053 ms = 2663.78 MB/s
|
||||||
|
|
||||||
|
Header encryption with payload checksums, e2e encrypted image
|
||||||
|
AES-256-GCM encrypt header + AES-256-XTS encrypt + xxhash3 1 M block... 6000 iterations in 2190 ms = 2739.73 MB/s
|
||||||
|
AES-256-GCM encrypt header + AES-256-XTS encrypt + xxhash3 4 K block... 1300000 iterations in 2101 ms = 2417.00 MB/s
|
||||||
|
|
||||||
|
Full transport encryption, e2e encrypted image
|
||||||
|
AES-256-XTS + AES-256-GCM encrypt 1 M block... 4000 iterations in 2666 ms = 1500.38 MB/s
|
||||||
|
AES-256-XTS + AES-256-GCM encrypt 4 K block... 800000 iterations in 2113 ms = 1478.94 MB/s
|
||||||
|
```
|
||||||
@@ -14,7 +14,7 @@ Replicated setups:
|
|||||||
- Linear read: `min(total network bandwidth, sum(disk read MB/s))`.
|
- Linear read: `min(total network bandwidth, sum(disk read MB/s))`.
|
||||||
- Linear write: `min(total network bandwidth, sum(disk write MB/s / number of replicas))`.
|
- Linear write: `min(total network bandwidth, sum(disk write MB/s / number of replicas))`.
|
||||||
- Saturated parallel read iops: `min(total network bandwidth, sum(disk read iops))`.
|
- Saturated parallel read iops: `min(total network bandwidth, sum(disk read iops))`.
|
||||||
- Saturated parallel write iops: `min(total network bandwidth / number of replicas, sum(disk write iops / number of replicas / (write amplification = 4)))`.
|
- Saturated parallel write iops: `min(total network bandwidth / number of replicas, sum(disk write iops / number of replicas / write amplification))`.
|
||||||
|
|
||||||
EC/XOR setups (EC N+K):
|
EC/XOR setups (EC N+K):
|
||||||
- Single-threaded (T1Q1) read latency: 1.5 network roundtrips + 1 disk read.
|
- Single-threaded (T1Q1) read latency: 1.5 network roundtrips + 1 disk read.
|
||||||
@@ -26,28 +26,36 @@ EC/XOR setups (EC N+K):
|
|||||||
- Linear read: `min(total network bandwidth, sum(disk read MB/s))`.
|
- Linear read: `min(total network bandwidth, sum(disk read MB/s))`.
|
||||||
- Linear write: `min(total network bandwidth, sum(disk write MB/s * N/(N+K)))`.
|
- Linear write: `min(total network bandwidth, sum(disk write MB/s * N/(N+K)))`.
|
||||||
- Saturated parallel read iops: `min(total network bandwidth, sum(disk read iops))`.
|
- Saturated parallel read iops: `min(total network bandwidth, sum(disk read iops))`.
|
||||||
- Saturated parallel write iops: roughly `total iops / (N+K) / WA`. More exactly,
|
- Saturated parallel write iops: roughly `total iops / (N+K) / WA`. More exactly:
|
||||||
`min(total network bandwidth * N/(N+K), sum(disk randrw iops / (N*4 + K*5 + 1)))` with
|
- With the new store: `min(total network bandwidth * N/(N+K), sum(disk randrw iops / (2 + N-1 + K*2)))`,
|
||||||
random read/write mix corresponding to `(N-1)/(N*4 + K*5 + 1)*100 % reads`.
|
with random read/write mix corresponding to `(N-1)/(2 + N-1 + K*2)*100 % reads`.
|
||||||
- For example, with EC 2+1 it is: `(7% randrw iops) / 14`.
|
- For example, with EC 2+1 it is: `(20% randrw iops) / 5`.
|
||||||
- With EC 6+3 it is: `(12.5% randrw iops) / 40`.
|
- With EC 6+3 it is: `(38% randrw iops) / 13`.
|
||||||
|
- With the old store: `min(total network bandwidth * N/(N+K), sum(disk randrw iops / (3 + N-1 + K*3)))`,
|
||||||
|
with random read/write mix corresponding to `(N-1)/(3 + N-1 + K*3)*100 % reads`.
|
||||||
|
- For example, with EC 2+1 it is: `(14% randrw iops) / 7`.
|
||||||
|
- With EC 6+3 it is: `(30% randrw iops) / 17`.
|
||||||
|
|
||||||
Write amplification for 4 KB blocks is usually 3-5 in Vitastor:
|
Write Amplification factor:
|
||||||
1. Journal block write
|
- For the new store and for 4 KB writes: WA is always 1 unless you set [atomic_write_size](../config/osd.en.md#atomic_write_size) to 0 manually.
|
||||||
2. Journal data write
|
- For the new store and for 8-124 KB writes: WA is 1 if you use NVMe drives with atomic write support, or roughly 2 if you use other drives.
|
||||||
3. Metadata block write
|
- For the old store, WA is roughly `(2 * write size + 4 KB) / (write size)`. So, for 4 KB writes it's 3, and for 8-124 KB writes it's closer to 2.
|
||||||
4. Another journal block write for EC/XOR setups
|
- For both the new and the old store and for writes of [block_size](../config/layout-cluster.en.md#block_size): WA is almost 1.
|
||||||
5. Data block write
|
|
||||||
|
|
||||||
If you manage to get an SSD which handles 512 byte blocks well (Optane?) you may
|
Write Amplification consists of:
|
||||||
lower 1, 3 and 4 to 512 bytes (1/8 of data size) and get WA as low as 2.375.
|
- For the new store:
|
||||||
|
- Buffer block write if non-atomic
|
||||||
|
- Data block write
|
||||||
|
- Metadata write(s) (amortized)
|
||||||
|
- For the old store:
|
||||||
|
- Journal block write (amortized)
|
||||||
|
- Journal data write
|
||||||
|
- Metadata block write
|
||||||
|
- Another journal block write for EC/XOR setups (amortized)
|
||||||
|
- Data block write
|
||||||
|
|
||||||
Implemented NVDIMM support can basically eliminate WA at all - all extra writes will
|
Other possibilities to reduce WA would be to use SSDs with internal 512-byte blocks
|
||||||
go to DRAM memory. But this requires a test cluster with NVDIMM - please contact me
|
or NVDIMM, but both options seem unavailable on the market at the moment.
|
||||||
if you want to provide me with such cluster for tests.
|
|
||||||
|
|
||||||
Lazy fsync also reduces WA for parallel workloads because journal blocks are only
|
|
||||||
written when they fill up or fsync is requested.
|
|
||||||
|
|
||||||
## In Practice
|
## In Practice
|
||||||
|
|
||||||
|
|||||||
@@ -27,29 +27,36 @@
|
|||||||
- Линейное чтение: сумма МБ/с чтения всех дисков, либо общая производительность сети, если в сеть упрётся раньше.
|
- Линейное чтение: сумма МБ/с чтения всех дисков, либо общая производительность сети, если в сеть упрётся раньше.
|
||||||
- Линейная запись: сумма МБ/с записи всех дисков * N/(N+K), либо производительность сети * N / (N+K), если в сеть упрётся раньше.
|
- Линейная запись: сумма МБ/с записи всех дисков * N/(N+K), либо производительность сети * N / (N+K), если в сеть упрётся раньше.
|
||||||
- Параллельное случайное мелкое чтение: сумма IOPS чтения всех дисков либо производительность сети, если в сеть упрётся раньше.
|
- Параллельное случайное мелкое чтение: сумма IOPS чтения всех дисков либо производительность сети, если в сеть упрётся раньше.
|
||||||
- Параллельная случайная мелкая запись: грубо `(сумма IOPS / (N+K) / WA)`. Если точнее, то:
|
- Параллельная случайная мелкая запись: грубо `(сумма IOPS / (N+K) / WA)`.
|
||||||
сумма смешанного IOPS всех дисков при `(N-1)/(N*4 + K*5 + 1)*100 %` чтения, делённая на `(N*4 + K*5 + 1)`.
|
Либо `производительность сети * N/(N+K)`, если в сеть упрётся раньше. Если точнее, то:
|
||||||
Либо, производительность сети * N/(N+K), если в сеть упрётся раньше.
|
- С новым хранилищем: сумма смешанного IOPS всех дисков при `(N-1)/(2 + N-1 + K*2)*100 %` чтения, делённая на `(2 + N-1 + K*2)`.
|
||||||
- Например, при EC 2+1 это: `(сумма IOPS при 7% чтения) / 14`.
|
- Например, при EC 2+1 это: `(сумма IOPS при 20% чтения) / 5`.
|
||||||
- При EC 6+3 это: `(сумма IOPS при 12.5% чтения) / 40`.
|
- При EC 6+3 это: `(сумма IOPS при 38% чтения) / 13`.
|
||||||
|
- Со старым хранилищем: сумма смешанного IOPS всех дисков при `(N-1)/(3 + N-1 + K*3)*100 %` чтения, делённая на `(3 + N-1 + K*3)`.
|
||||||
|
- Например, при EC 2+1 это: `(сумма IOPS при 14% чтения) / 7`.
|
||||||
|
- При EC 6+3 это: `(сумма IOPS при 30% чтения) / 17`.
|
||||||
|
|
||||||
WA (мультипликатор записи) для 4 КБ блоков в Vitastor обычно составляет 3-5:
|
WA (Write Amplification, мультипликатор записи):
|
||||||
1. Запись метаданных в журнал
|
- С новым хранилищем для 4 КБ записи: WA всегда примерно 1, если только вы не установите [atomic_write_size](../config/osd.ru.md#atomic_write_size) вручную в 0.
|
||||||
2. Запись блока данных в журнал
|
- С новым хранилищем и большими записями (8-124 КБ): WA примерно 1, если вы используете NVMe-диски с поддержкой атомарной записи,
|
||||||
3. Запись метаданных в БД
|
или примерно 2, если вы используете другие диски.
|
||||||
4. Ещё одна запись метаданных в журнал при использовании EC
|
- Со старым хранилищем, WA примерно `(2 * размер записи + 4 КБ) / (размер записи)`. То есть, для 4 КБ записи WA=3, а для 8-124 КБ WA ближе к 2.
|
||||||
5. Запись блока данных на диск данных
|
- И с новым, и со старым хранилищем и для записи размером [block_size](../config/layout-cluster.ru.md#block_size): WA примерно равен 1.
|
||||||
|
|
||||||
Если вы найдёте SSD, хорошо работающий с 512-байтными блоками данных (Optane?),
|
Мультипликатор записи состоит из:
|
||||||
то 1, 3 и 4 можно снизить до 512 байт (1/8 от размера данных) и получить WA всего 2.375.
|
- С новым хранилищем:
|
||||||
|
- Запись блока буфера, если диски без поддержки атомарной записи
|
||||||
|
- Запись блока данных
|
||||||
|
- Запись(-и) блоков метаданных (амортизированные)
|
||||||
|
- Со старым хранилищем:
|
||||||
|
- Запись блока журнала (амортизированная)
|
||||||
|
- Запись данных в журнал
|
||||||
|
- Запись блока метаданных
|
||||||
|
- Ещё одна запись блока журнала для EC/XOR пулов (амортизированная)
|
||||||
|
- Запись блока данных
|
||||||
|
|
||||||
Если реализовать поддержку NVDIMM, то WA можно, условно говоря, ликвидировать вообще - все
|
Другими потенциальными возможностями снижения WA могли бы быть SSD с внутренним 512-байтным блоком
|
||||||
дополнительные операции записи смогут обслуживаться DRAM памятью. Но для этого необходим
|
либо NVDIMM, но и то, и другое сейчас выглядит недоступным на рынке.
|
||||||
тестовый кластер с NVDIMM - пишите, если готовы предоставить такой для тестов.
|
|
||||||
|
|
||||||
Кроме того, WA снижается при использовании отложенного/ленивого сброса при параллельной
|
|
||||||
нагрузке, т.к. блоки журнала записываются на диск только когда они заполняются или явным
|
|
||||||
образом запрашивается fsync.
|
|
||||||
|
|
||||||
## На практике
|
## На практике
|
||||||
|
|
||||||
|
|||||||
@@ -231,6 +231,18 @@ Upgrading from <= 0.5.x to >= 0.6.x is not supported.
|
|||||||
|
|
||||||
Downgrade are also allowed freely, except the following specific instructions:
|
Downgrade are also allowed freely, except the following specific instructions:
|
||||||
|
|
||||||
|
### 3.x -> 2.x
|
||||||
|
|
||||||
|
Versions 3.0.0 and newer contain two store implementations - an old one and a new
|
||||||
|
one, unsupported in 2.x and previous versions. So you should check your OSD store
|
||||||
|
versions before downgrading to 2.x with the following command:
|
||||||
|
|
||||||
|
`vitastor-disk read-sb /dev/vitastor/osdXX-data | jq -r .meta_format`
|
||||||
|
|
||||||
|
If it prints 3 then OSD uses the new store and you can't downgrade it to 2.x.
|
||||||
|
|
||||||
|
If it prints 2 or nothing then OSD uses the old store and the downgrade is allowed.
|
||||||
|
|
||||||
### 1.8.0 to 1.7.1
|
### 1.8.0 to 1.7.1
|
||||||
|
|
||||||
Before downgrading from version >= 1.8.0 to version <= 1.7.1
|
Before downgrading from version >= 1.8.0 to version <= 1.7.1
|
||||||
|
|||||||
@@ -228,6 +228,18 @@ done
|
|||||||
|
|
||||||
Откат (понижение версии) тоже свободно разрешён, кроме указанных ниже случаев:
|
Откат (понижение версии) тоже свободно разрешён, кроме указанных ниже случаев:
|
||||||
|
|
||||||
|
### 3.x -> 2.x
|
||||||
|
|
||||||
|
Версии 3.0.0 и более новые содержат две реализации хранилища - старую и новую, не
|
||||||
|
поддерживаемую в 2.x и предыдущих версиях. Таким образом, перед откатом на 2.x вам
|
||||||
|
следует проверить, какая версия хранилища используется вашими OSD - командой:
|
||||||
|
|
||||||
|
`vitastor-disk read-sb /dev/vitastor/osdXX-data | jq -r .meta_format`
|
||||||
|
|
||||||
|
Если выводится 3, это новое хранилище и откатить такой OSD до 2.x нельзя.
|
||||||
|
|
||||||
|
Если выводится 2 или не выводится ничего, это старое хранилище и откат разрешён.
|
||||||
|
|
||||||
### 1.8.0 -> 1.7.1
|
### 1.8.0 -> 1.7.1
|
||||||
|
|
||||||
Перед понижением версии с >= 1.8.0 до <= 1.7.1 вы должны скопировать ключ
|
Перед понижением версии с >= 1.8.0 до <= 1.7.1 вы должны скопировать ключ
|
||||||
|
|||||||
+23
-7
@@ -100,12 +100,14 @@ List images (only matching `<glob>` pattern(s) if passed).
|
|||||||
Options:
|
Options:
|
||||||
|
|
||||||
```
|
```
|
||||||
|
--exact Do not match glob patterns as names, select only exact name matches.
|
||||||
-p|--pool POOL Filter images by pool ID or name
|
-p|--pool POOL Filter images by pool ID or name
|
||||||
-l|--long Also report allocated size and I/O statistics
|
-l|--long Also report allocated size and I/O statistics
|
||||||
--del Also include delete operation statistics
|
--del Also include delete operation statistics
|
||||||
--sort FIELD Sort by specified field (name, size, used_size, <read|write|delete>_<iops|bps|lat|queue>)
|
--sort FIELD Sort by specified field (name, size, used_size, <read|write|delete>_<iops|bps|lat|queue>)
|
||||||
-r|--reverse Sort in descending order
|
-r|--reverse Sort in descending order
|
||||||
-n|--count N Only list first N items
|
-n|--count N Only list first N items
|
||||||
|
--tree Show image snapshot/clone tree
|
||||||
```
|
```
|
||||||
|
|
||||||
Example output:
|
Example output:
|
||||||
@@ -123,18 +125,31 @@ bench-kaveri kaveri 10 G 10 G 0 B/s 0 0 0 us 0 B/s 0
|
|||||||
|
|
||||||
## create
|
## create
|
||||||
|
|
||||||
`vitastor-cli create -s|--size <size> [-p|--pool <id|name>] [--parent <parent_name>[@<snapshot>]] <name>`
|
`vitastor-cli create -s|--size SIZE [OPTIONS] <name>`
|
||||||
|
|
||||||
Create an image. You may use K/M/G/T suffixes for `<size>`. If `--parent` is specified,
|
Create an image. Options:
|
||||||
a copy-on-write image clone is created. Parent must be a snapshot (readonly image).
|
|
||||||
Pool must be specified if there is more than one pool.
|
* `-s|--size SIZE` - New image size in bytes or with a K/M/G/T unit suffix.
|
||||||
|
* `-p|--pool POOL` - Specify pool for the new image (may be omitted if there is only 1 pool).
|
||||||
|
* `--parent PARENT` - Create a copy-on-write image clone based on PARENT (or PARENT@SNAPSHOT).
|
||||||
|
If parent is not a snapshot, it must be a read-only image.
|
||||||
|
* `--enc-key random` - Generate a new random AES-256-XTS encryption key for the new image.
|
||||||
|
* `--enc-key HEX` - Set a specified AES-256-XTS key (64 bytes in hex) for the new image.
|
||||||
|
* `--enc-key vault:ID` - Use an encryption key from an external Vault secret with specified ID.
|
||||||
|
|
||||||
```
|
```
|
||||||
vitastor-cli create --snapshot <snapshot> [-p|--pool <id|name>] <image>
|
vitastor-cli create --snapshot <snapshot> [OPTIONS] <image>
|
||||||
vitastor-cli snap-create [-p|--pool <id|name>] <image>@<snapshot>
|
vitastor-cli snap-create [OPTIONS] <image>@<snapshot>
|
||||||
```
|
```
|
||||||
|
|
||||||
Create a snapshot of image `<name>` (either form can be used). May be used live if only a single writer is active.
|
Create a snapshot of image `<image>`. May be used live if only a single writer is active.
|
||||||
|
|
||||||
|
Options:
|
||||||
|
|
||||||
|
* `-p|--pool POOL` - Move image to pool POOL, leaving the snapshot in the old pool.
|
||||||
|
* `--enc-key random` - Change image encryption key to a new random AES-256-XTS key.
|
||||||
|
* `--enc-key KEY` - Change image encryption key to a specified key, Vault key or to an empty key.
|
||||||
|
By default, the image retains its old encryption key when taking a snapshot.
|
||||||
|
|
||||||
See also about [how to export snapshots](qemu.en.md#exporting-snapshots).
|
See also about [how to export snapshots](qemu.en.md#exporting-snapshots).
|
||||||
|
|
||||||
@@ -149,6 +164,7 @@ You should resize file system in the image, if present, before shrinking it.
|
|||||||
* `--deleted 1|0` - Set/clear 'deleted image' flag (set automatically during unfinished deletes).
|
* `--deleted 1|0` - Set/clear 'deleted image' flag (set automatically during unfinished deletes).
|
||||||
* `-f|--force` - Proceed with shrinking or setting readwrite flag even if the image has children.
|
* `-f|--force` - Proceed with shrinking or setting readwrite flag even if the image has children.
|
||||||
* `--down-ok` - Proceed with shrinking even if some data will be left on unavailable OSDs.
|
* `--down-ok` - Proceed with shrinking even if some data will be left on unavailable OSDs.
|
||||||
|
* `--enc-key HEX` - Change image encryption key (allowed only with `--force`).
|
||||||
|
|
||||||
## dd
|
## dd
|
||||||
|
|
||||||
|
|||||||
+24
-8
@@ -102,12 +102,14 @@ kaveri 2/1 32 0 B 10 G 0 B 100% 0%
|
|||||||
Опции:
|
Опции:
|
||||||
|
|
||||||
```
|
```
|
||||||
|
--exact Не применять ФС-шаблоны к именам, выводить только точные совпадения
|
||||||
-p|--pool POOL Фильтровать образы по пулу (ID или имени)
|
-p|--pool POOL Фильтровать образы по пулу (ID или имени)
|
||||||
-l|--long Также выводить статистику занятого места и ввода-вывода
|
-l|--long Также выводить статистику занятого места и ввода-вывода
|
||||||
--del Также выводить статистику операций удаления
|
--del Также выводить статистику операций удаления
|
||||||
--sort FIELD Сортировать по заданному полю (name, size, used_size, <read|write|delete>_<iops|bps|lat|queue>)
|
--sort FIELD Сортировать по заданному полю (name, size, used_size, <read|write|delete>_<iops|bps|lat|queue>)
|
||||||
-r|--reverse Сортировать в обратном порядке
|
-r|--reverse Сортировать в обратном порядке
|
||||||
-n|--count N Показывать только первые N записей
|
-n|--count N Показывать только первые N записей
|
||||||
|
--tree Вывести снапшоты и клоны в виде дерева
|
||||||
```
|
```
|
||||||
|
|
||||||
Пример вывода:
|
Пример вывода:
|
||||||
@@ -125,19 +127,32 @@ bench-kaveri kaveri 10 G 10 G 0 B/s 0 0 0 us 0 B/s 0
|
|||||||
|
|
||||||
## create
|
## create
|
||||||
|
|
||||||
`vitastor-cli create -s|--size <size> [-p|--pool <id|name>] [--parent <parent_name>[@<snapshot>]] <name>`
|
`vitastor-cli create -s|--size SIZE [ОПЦИИ] <name>`
|
||||||
|
|
||||||
Создать образ. Для размера `<size>` можно использовать суффиксы K/M/G/T (килобайт-мегабайт-гигабайт-терабайт).
|
Создать образ. Опции:
|
||||||
Если указана опция `--parent`, создаётся клон образа. Родитель `<parent_name>[@<snapshot>]` должен быть
|
|
||||||
снимком (или просто немодифицируемым образом). Пул обязательно указывать, если в кластере больше одного пула.
|
* `-s|--size SIZE` - Размер нового образа в байтах или с суффиксом K/M/G/T (кило/мега/гига/терабайт).
|
||||||
|
* `-p|--pool POOL` - Создать образ в заданном пуле (можно не указывать, если пул всего один).
|
||||||
|
* `--parent PARENT` - Создать легковесный клон на основе образа `PARENT` или снимка `PARENT@SNAP`.
|
||||||
|
Если `PARENT` - не снимок, он должен быть помечен как образ только для чтения.
|
||||||
|
* `--enc-key random` - Сгенерировать случайный ключ шифрования AES-256-XTS для нового образа.
|
||||||
|
* `--enc-key HEX` - Установить заданный ключ AES-256-XTS (64 байта в hex) для нового образа.
|
||||||
|
* `--enc-key vault:ID` - Использовать ключ из внешнего секрета с заданным ID из Vault.
|
||||||
|
|
||||||
```
|
```
|
||||||
vitastor-cli create --snapshot <snapshot> [-p|--pool <id|name>] <image>
|
vitastor-cli create --snapshot <snapshot> [ОПЦИИ] <image>
|
||||||
vitastor-cli snap-create [-p|--pool <id|name>] <image>@<snapshot>
|
vitastor-cli snap-create [ОПЦИИ] <image>@<snapshot>
|
||||||
```
|
```
|
||||||
|
|
||||||
Создать снимок образа `<name>` (можно использовать любую форму команды). Снимок можно создавать без остановки
|
Создать снимок образа `<image>` (можно использовать любую форму команды).
|
||||||
клиентов, если пишущий клиент максимум 1.
|
Снимок можно создавать без остановки клиентов, если пишущих клиентов не больше одного.
|
||||||
|
|
||||||
|
Опции:
|
||||||
|
|
||||||
|
* `-p|--pool POOL` - Переместить образ в пул POOL, оставив снимок в старом пуле.
|
||||||
|
* `--enc-key random` - Изменить ключ шифрования образа на новый случайный ключ AES-256-XTS.
|
||||||
|
* `--enc-key KEY` - Изменить ключ шифрования образа на заданный ключ, ключ из Vault или пустой ключ.
|
||||||
|
По умолчанию шифрованные образы сохраняют старый ключ при снятии снимка.
|
||||||
|
|
||||||
Смотрите также информацию о том, [как экспортировать снимки](qemu.ru.md#экспорт-снимков).
|
Смотрите также информацию о том, [как экспортировать снимки](qemu.ru.md#экспорт-снимков).
|
||||||
|
|
||||||
@@ -154,6 +169,7 @@ vitastor-cli snap-create [-p|--pool <id|name>] <image>@<snapshot>
|
|||||||
* `--deleted 1|0` - Установить/снять флаг "образ удалён" (устанавливается при незавершённом удалении).
|
* `--deleted 1|0` - Установить/снять флаг "образ удалён" (устанавливается при незавершённом удалении).
|
||||||
* `-f|--force` - Разрешить уменьшение или перевод в чтение-запись образа, у которого есть клоны.
|
* `-f|--force` - Разрешить уменьшение или перевод в чтение-запись образа, у которого есть клоны.
|
||||||
* `--down-ok` - Разрешить уменьшение, даже если часть данных останется неудалённой на недоступных OSD.
|
* `--down-ok` - Разрешить уменьшение, даже если часть данных останется неудалённой на недоступных OSD.
|
||||||
|
* `--enc-key HEX` - Изменить ключ шифрования образа (разрешено только с `--force`).
|
||||||
|
|
||||||
## dd
|
## dd
|
||||||
|
|
||||||
|
|||||||
@@ -51,6 +51,9 @@ Options (automatic mode):
|
|||||||
```
|
```
|
||||||
--osd_per_disk <N>
|
--osd_per_disk <N>
|
||||||
Create <N> OSDs on each disk (default 1)
|
Create <N> OSDs on each disk (default 1)
|
||||||
|
--meta_format 3
|
||||||
|
Metadata store version. 3 is the new log-structured store, 2 is the stable store
|
||||||
|
from Vitastor 0.9-2.x, 1 is the legacy store from Vitastor 0.6-0.8.
|
||||||
--hybrid
|
--hybrid
|
||||||
Prepare hybrid (HDD+SSD, NVMe+SATA or etc) OSDs using provided devices. By default,
|
Prepare hybrid (HDD+SSD, NVMe+SATA or etc) OSDs using provided devices. By default,
|
||||||
any passed SSDs will be used for journals and metadata, HDDs will be used for data,
|
any passed SSDs will be used for journals and metadata, HDDs will be used for data,
|
||||||
@@ -73,6 +76,8 @@ Options (automatic mode):
|
|||||||
--max_other 10%
|
--max_other 10%
|
||||||
Use disks for OSD data even if they already have non-Vitastor partitions,
|
Use disks for OSD data even if they already have non-Vitastor partitions,
|
||||||
but only if these take up no more than this percent of disk space.
|
but only if these take up no more than this percent of disk space.
|
||||||
|
--dry-run
|
||||||
|
Check and print new OSD count for each disk but do not actually create them.
|
||||||
```
|
```
|
||||||
|
|
||||||
Options (single-device mode):
|
Options (single-device mode):
|
||||||
@@ -90,6 +95,8 @@ Options (single-device mode):
|
|||||||
Options (both modes):
|
Options (both modes):
|
||||||
|
|
||||||
```
|
```
|
||||||
|
--tags tag1,tag2 Set new OSD tag(s)
|
||||||
|
--weight <number> Set new OSD weight (between 0 to 1)
|
||||||
--journal_size 1G/32M Set journal size (area or partition size)
|
--journal_size 1G/32M Set journal size (area or partition size)
|
||||||
--block_size 1M/128k Set blockstore object size
|
--block_size 1M/128k Set blockstore object size
|
||||||
--bitmap_granularity 4k Set bitmap granularity
|
--bitmap_granularity 4k Set bitmap granularity
|
||||||
|
|||||||
@@ -50,6 +50,9 @@ vitastor-disk - инструмент командной строки для уп
|
|||||||
```
|
```
|
||||||
--osd_per_disk <N>
|
--osd_per_disk <N>
|
||||||
Создавать по несколько (<N>) OSD на каждом диске (по умолчанию 1)
|
Создавать по несколько (<N>) OSD на каждом диске (по умолчанию 1)
|
||||||
|
--meta_format 3
|
||||||
|
Версия хранилища метаданных. 3 - новое лог-структурированное хранилище,
|
||||||
|
2 - стабильное хранилище из Vitastor 0.9-2.x, 1 - старое хранилище из Vitastor 0.6-0.8.
|
||||||
--hybrid
|
--hybrid
|
||||||
Инициализировать гибридные (HDD+SSD, NVMe+SATA и т.п.) OSD на указанных дисках.
|
Инициализировать гибридные (HDD+SSD, NVMe+SATA и т.п.) OSD на указанных дисках.
|
||||||
По умолчанию, SSD будут использованы для журналов и метаданных, а HDD - для данных,
|
По умолчанию, SSD будут использованы для журналов и метаданных, а HDD - для данных,
|
||||||
@@ -74,6 +77,8 @@ vitastor-disk - инструмент командной строки для уп
|
|||||||
--max_other 10%
|
--max_other 10%
|
||||||
Использовать диски под данные OSD, даже если на них уже есть не-Vitastor-овые
|
Использовать диски под данные OSD, даже если на них уже есть не-Vitastor-овые
|
||||||
разделы, но только в случае, если они занимают не более данного процента диска.
|
разделы, но только в случае, если они занимают не более данного процента диска.
|
||||||
|
--dry-run
|
||||||
|
Проверить и вывести число новых OSD для каждого диска, но не создавать их.
|
||||||
```
|
```
|
||||||
|
|
||||||
Опции для режима одного OSD:
|
Опции для режима одного OSD:
|
||||||
@@ -91,6 +96,8 @@ vitastor-disk - инструмент командной строки для уп
|
|||||||
Опции для обоих режимов:
|
Опции для обоих режимов:
|
||||||
|
|
||||||
```
|
```
|
||||||
|
--tags tag1,tag2 Задать теги для новых OSD
|
||||||
|
--weight <number> Задать вес для новых OSD (от 0 до 1)
|
||||||
--journal_size 1G/32M Задать размер журнала (области или раздела журнала)
|
--journal_size 1G/32M Задать размер журнала (области или раздела журнала)
|
||||||
--block_size 1M/128k Задать размер объекта хранилища
|
--block_size 1M/128k Задать размер объекта хранилища
|
||||||
--bitmap_granularity 4k Задать гранулярность битовых карт
|
--bitmap_granularity 4k Задать гранулярность битовых карт
|
||||||
|
|||||||
@@ -89,6 +89,8 @@ POSIX features currently not implemented in VitastorFS:
|
|||||||
instead of actually allocated space
|
instead of actually allocated space
|
||||||
- Access times (`atime`) are not tracked (like `-o noatime`)
|
- Access times (`atime`) are not tracked (like `-o noatime`)
|
||||||
- Modification time (`mtime`) is updated lazily every second (like `-o lazytime`)
|
- Modification time (`mtime`) is updated lazily every second (like `-o lazytime`)
|
||||||
|
- Permission enforcement is disabled by default (and Linux NFS client doesn't
|
||||||
|
enforce them too). Use `--enforce 1` to enable it.
|
||||||
|
|
||||||
Other notable missing features which should be addressed in the future:
|
Other notable missing features which should be addressed in the future:
|
||||||
- Inode ID reuse. Currently inode IDs always grow, the limit is 2^48 inodes, so
|
- Inode ID reuse. Currently inode IDs always grow, the limit is 2^48 inodes, so
|
||||||
@@ -258,4 +260,6 @@ Options:
|
|||||||
| `--nfspath <PATH>` | set NFS export path to \<PATH> (default is /) |
|
| `--nfspath <PATH>` | set NFS export path to \<PATH> (default is /) |
|
||||||
| `--pidfile <FILE>` | write process ID to the specified file |
|
| `--pidfile <FILE>` | write process ID to the specified file |
|
||||||
| `--logfile <FILE>` | log to the specified file |
|
| `--logfile <FILE>` | log to the specified file |
|
||||||
|
| `--enforce 1` | enforce permissions at the server side (no by default) |
|
||||||
| `--foreground 1` | stay in foreground, do not daemonize |
|
| `--foreground 1` | stay in foreground, do not daemonize |
|
||||||
|
| `--trace` | trace all NFS requests |
|
||||||
|
|||||||
@@ -91,6 +91,8 @@ JSON-формате :-). Для инспекции содержимого БД
|
|||||||
stat(2), так что `du` всегда показывает сумму размеров файлов, а не фактически занятое место
|
stat(2), так что `du` всегда показывает сумму размеров файлов, а не фактически занятое место
|
||||||
- Времена доступа (`atime`) не отслеживаются (как будто ФС смонтирована с `-o noatime`)
|
- Времена доступа (`atime`) не отслеживаются (как будто ФС смонтирована с `-o noatime`)
|
||||||
- Времена модификации (`mtime`) отслеживаются асинхронно (как будто ФС смонтирована с `-o lazytime`)
|
- Времена модификации (`mtime`) отслеживаются асинхронно (как будто ФС смонтирована с `-o lazytime`)
|
||||||
|
- Привилегии доступа по умолчанию не проверяются сервером (клиент NFS Linux их также не проверяет).
|
||||||
|
Чтобы включить проверки, используйте опцию `--enforce 1`.
|
||||||
|
|
||||||
Другие недостающие функции, которые нужно добавить в будущем:
|
Другие недостающие функции, которые нужно добавить в будущем:
|
||||||
- Переиспользование номеров инодов. В текущей реализации номера инодов всё время
|
- Переиспользование номеров инодов. В текущей реализации номера инодов всё время
|
||||||
@@ -270,4 +272,6 @@ VitastorFS из GPUDirect.
|
|||||||
| `--nfspath <PATH>` | установить путь NFS-экспорта в \<PATH> (по умолчанию /) |
|
| `--nfspath <PATH>` | установить путь NFS-экспорта в \<PATH> (по умолчанию /) |
|
||||||
| `--pidfile <FILE>` | записать ID процесса в заданный файл |
|
| `--pidfile <FILE>` | записать ID процесса в заданный файл |
|
||||||
| `--logfile <FILE>` | записывать логи в заданный файл |
|
| `--logfile <FILE>` | записывать логи в заданный файл |
|
||||||
|
| `--enforce 1` | проверять права доступа на стороне сервера (по умолчанию нет) |
|
||||||
| `--foreground 1` | не уходить в фон после запуска |
|
| `--foreground 1` | не уходить в фон после запуска |
|
||||||
|
| `--trace` | логгировать все запросы NFS |
|
||||||
|
|||||||
+17
-15
@@ -130,23 +130,16 @@ Linux kernel, starting with version 5.15, supports a new interface for attaching
|
|||||||
to the host - VDUSE (vDPA Device in Userspace). QEMU, starting with 7.2, has support for
|
to the host - VDUSE (vDPA Device in Userspace). QEMU, starting with 7.2, has support for
|
||||||
exporting QEMU block devices over this protocol using qemu-storage-daemon.
|
exporting QEMU block devices over this protocol using qemu-storage-daemon.
|
||||||
|
|
||||||
VDUSE is currently the best interface to attach Vitastor disks as kernel devices because:
|
VDUSE advantages:
|
||||||
- It avoids data copies and thus achieves much better performance than [NBD](nbd.en.md)
|
|
||||||
- It doesn't have NBD timeout problem - the device doesn't die if an operation executes for too long
|
- VDUSE copies memory 1 time instead of 2, and is thus faster than [NBD](nbd.en.md) for linear read/write.
|
||||||
|
- It doesn't have NBD timeout problem - the device doesn't die if an operation executes for too long.
|
||||||
- It doesn't have hung device problem - if the userspace process dies it can be restarted (!)
|
- It doesn't have hung device problem - if the userspace process dies it can be restarted (!)
|
||||||
and block device will continue operation
|
and block device will continue operation (UBLK can do it too).
|
||||||
- It doesn't seem to have the device number limit
|
- It doesn't seem to have the device number limit (UBLK also doesn't).
|
||||||
|
|
||||||
Example performance comparison:
|
At the same time, VDUSE may be slower or faster than [UBLK](ublk.en.md) for linear read/write,
|
||||||
|
and iops-wise it's sometimes even slower than NBD. See performance comparison examples at the page [UBLK](ublk.en.md).
|
||||||
| | direct fio | NBD | VDUSE |
|
|
||||||
|----------------------|-------------|-------------|-------------|
|
|
||||||
| linear write | 3.85 GB/s | 1.12 GB/s | 3.85 GB/s |
|
|
||||||
| 4k random write Q128 | 240000 iops | 120000 iops | 178000 iops |
|
|
||||||
| 4k random write Q1 | 9500 iops | 7620 iops | 7640 iops |
|
|
||||||
| linear read | 4.3 GB/s | 1.8 GB/s | 2.85 GB/s |
|
|
||||||
| 4k random read Q128 | 287000 iops | 140000 iops | 189000 iops |
|
|
||||||
| 4k random read Q1 | 9600 iops | 7640 iops | 7780 iops |
|
|
||||||
|
|
||||||
To try VDUSE you need at least Linux 5.15, built with VDUSE support
|
To try VDUSE you need at least Linux 5.15, built with VDUSE support
|
||||||
(CONFIG_VDPA=m, CONFIG_VDPA_USER=m, CONFIG_VIRTIO_VDPA=m).
|
(CONFIG_VDPA=m, CONFIG_VDPA_USER=m, CONFIG_VIRTIO_VDPA=m).
|
||||||
@@ -193,3 +186,12 @@ To remove the device:
|
|||||||
vdpa dev del test1
|
vdpa dev del test1
|
||||||
kill <qemu-storage-daemon_process_PID>
|
kill <qemu-storage-daemon_process_PID>
|
||||||
```
|
```
|
||||||
|
|
||||||
|
## Veeam
|
||||||
|
|
||||||
|
Vitastor QEMU driver has a feature that allows to trick third-party systems like Veeam not able to parse qemu-img
|
||||||
|
vitastor URIs: [qemu_file_mirror_path](../config/client.en.md#qemu_file_mirror_path).
|
||||||
|
|
||||||
|
To make such systems work, you should set this option to an FS directory path (for example, `/mnt/vitastor/`) and
|
||||||
|
mount this directory using [`vitastor-nfs mount --block`](../usage/nfs.en.md). It will make them access
|
||||||
|
your images using files and, hopefully, succeed in doing their normal job :).
|
||||||
|
|||||||
+17
-16
@@ -132,24 +132,16 @@ qemu-system-x86_64 -enable-kvm -m 2048 -M accel=kvm,memory-backend=mem \
|
|||||||
к системе - VDUSE (vDPA Device in Userspace), а в QEMU, начиная с версии 7.2, есть поддержка
|
к системе - VDUSE (vDPA Device in Userspace), а в QEMU, начиная с версии 7.2, есть поддержка
|
||||||
экспорта блочных устройств QEMU по этому протоколу через qemu-storage-daemon.
|
экспорта блочных устройств QEMU по этому протоколу через qemu-storage-daemon.
|
||||||
|
|
||||||
VDUSE - на данный момент лучший интерфейс для подключения дисков Vitastor в виде блочных
|
Преимущества VDUSE:
|
||||||
устройств на уровне ядра, ибо:
|
|
||||||
- VDUSE не копирует данные и поэтому достигает значительно лучшей производительности, чем [NBD](nbd.ru.md)
|
|
||||||
- Также оно не имеет проблемы NBD-таймаута - устройство не умирает, если операция выполняется слишком долго
|
|
||||||
- Также оно не имеет проблемы подвисающих устройств - если процесс-обработчик умирает, его можно
|
|
||||||
перезапустить (!) и блочное устройство продолжит работать
|
|
||||||
- По-видимому, у него нет предела числа подключаемых в систему устройств
|
|
||||||
|
|
||||||
Пример сравнения производительности:
|
- VDUSE копирует данные 1 раз, а не 2, и поэтому он быстрее, чем [NBD](nbd.ru.md) при линейном доступе.
|
||||||
|
- VDUSE не имеет проблемы NBD-таймаута - устройство не умирает, если операция выполняется слишком долго.
|
||||||
|
- VDUSE не имеет проблемы подвисающих устройств - если процесс-обработчик умирает, его можно
|
||||||
|
перезапустить (!) и блочное устройство продолжит работать (в UBLK это тоже поддерживается).
|
||||||
|
- По-видимому, у него нет предела числа подключаемых в систему устройств (в UBLK лимита тоже нет).
|
||||||
|
|
||||||
| | Прямой fio | NBD | VDUSE |
|
Однако, при линейном доступе VDUSE может быть медленнее UBLK (а может быть и быстрее), а по iops
|
||||||
|--------------------------|-------------|-------------|-------------|
|
VDUSE иногда даже медленнее NBD. Пример сравнения производительности смотрите на странице [UBLK](ublk.ru.md).
|
||||||
| линейная запись | 3.85 GB/s | 1.12 GB/s | 3.85 GB/s |
|
|
||||||
| 4k случайная запись Q128 | 240000 iops | 120000 iops | 178000 iops |
|
|
||||||
| 4k случайная запись Q1 | 9500 iops | 7620 iops | 7640 iops |
|
|
||||||
| линейное чтение | 4.3 GB/s | 1.8 GB/s | 2.85 GB/s |
|
|
||||||
| 4k случайное чтение Q128 | 287000 iops | 140000 iops | 189000 iops |
|
|
||||||
| 4k случайное чтение Q1 | 9600 iops | 7640 iops | 7780 iops |
|
|
||||||
|
|
||||||
Чтобы попробовать VDUSE, вам нужно ядро Linux как минимум версии 5.15, собранное с поддержкой
|
Чтобы попробовать VDUSE, вам нужно ядро Linux как минимум версии 5.15, собранное с поддержкой
|
||||||
VDUSE (CONFIG_VDPA=m, CONFIG_VDPA_USER=m, CONFIG_VIRTIO_VDPA=m).
|
VDUSE (CONFIG_VDPA=m, CONFIG_VDPA_USER=m, CONFIG_VIRTIO_VDPA=m).
|
||||||
@@ -196,3 +188,12 @@ vdpa dev add name test1 mgmtdev vduse
|
|||||||
vdpa dev del test1
|
vdpa dev del test1
|
||||||
kill <PID_процесса_qemu-storage-daemon>
|
kill <PID_процесса_qemu-storage-daemon>
|
||||||
```
|
```
|
||||||
|
|
||||||
|
## Veeam
|
||||||
|
|
||||||
|
Драйвер Vitastor QEMU имеет функцию, которая позволяет обманывать сторонние системы типа Veeam, которые
|
||||||
|
не могут сами по себе разобрать адреса дисков в vitastor: [qemu_file_mirror_path](../config/client.ru.md#qemu_file_mirror_path).
|
||||||
|
|
||||||
|
Чтобы заставить такие системы работать, вам нужно установить эту опцию равной пути к некоторому каталогу
|
||||||
|
в ФС (например, `/mnt/vitastor/`) и примонтировать этот каталог с помощью [`vitastor-nfs mount --block`](../usage/nfs.ru.md).
|
||||||
|
Они начнут обращаться к образам как к файлам и, вероятно, смогут заработать корректно :).
|
||||||
|
|||||||
@@ -0,0 +1,116 @@
|
|||||||
|
[Documentation](../../README.md#documentation) → Usage → UBLK
|
||||||
|
|
||||||
|
-----
|
||||||
|
|
||||||
|
[Читать на русском](ublk.ru.md)
|
||||||
|
|
||||||
|
# UBLK
|
||||||
|
|
||||||
|
[ublk](https://docs.kernel.org/block/ublk.html) is a new io_uring-based Linux interface
|
||||||
|
for user-space block device drivers, available since Linux 6.0.
|
||||||
|
|
||||||
|
It's not zero-copy, but it's still a fast implementation, outperforming both [NBD](nbd.en.md)
|
||||||
|
and [VDUSE](qemu.en.md#vduse) iops-wise and may or may not outperform VDUSE in linear I/O MB/s.
|
||||||
|
ublk also allows to recover devices even if the server (vitastor-ublk process) dies.
|
||||||
|
|
||||||
|
## Example performance comparison
|
||||||
|
|
||||||
|
TCP (100G), 3 hosts each with 6 NVMe OSDs, 3 replicas, single client
|
||||||
|
|
||||||
|
| | direct fio | NBD | VDUSE | UBLK |
|
||||||
|
|----------------------|-------------|-------------|------------|-------------|
|
||||||
|
| linear write | 3807 MB/s | 1832 MB/s | 3226 MB/s | 3027 MB/s |
|
||||||
|
| linear read | 3067 MB/s | 1885 MB/s | 1800 MB/s | 2076 MB/s |
|
||||||
|
| 4k random write Q128 | 128624 iops | 91060 iops | 94621 iops | 149450 iops |
|
||||||
|
| 4k random read Q128 | 117769 iops | 153408 iops | 93157 iops | 171987 iops |
|
||||||
|
| 4k random write Q1 | 8090 iops | 6442 iops | 6316 iops | 7272 iops |
|
||||||
|
| 4k random read Q1 | 9474 iops | 7200 iops | 6840 iops | 8038 iops |
|
||||||
|
|
||||||
|
RDMA (100G), 3 hosts each with 6 NVMe OSDs, 3 replicas, single client
|
||||||
|
|
||||||
|
| | direct fio | NBD | VDUSE | UBLK |
|
||||||
|
|----------------------|-------------|-------------|-------------|-------------|
|
||||||
|
| linear write | 6998 MB/s | 1878 MB/s | 4249 MB/s | 3140 MB/s |
|
||||||
|
| linear read | 8628 MB/s | 3389 MB/s | 5062 MB/s | 3674 MB/s |
|
||||||
|
| 4k random write Q128 | 222541 iops | 181589 iops | 138281 iops | 218222 iops |
|
||||||
|
| 4k random read Q128 | 412647 iops | 239987 iops | 151663 iops | 269583 iops |
|
||||||
|
| 4k random write Q1 | 11601 iops | 8592 iops | 9111 iops | 10000 iops |
|
||||||
|
| 4k random read Q1 | 10102 iops | 7788 iops | 8111 iops | 8965 iops |
|
||||||
|
|
||||||
|
## Commands
|
||||||
|
|
||||||
|
vitastor-ublk supports the following commands:
|
||||||
|
|
||||||
|
- [map](#map)
|
||||||
|
- [unmap](#unmap)
|
||||||
|
- [ls](#ls)
|
||||||
|
|
||||||
|
## map
|
||||||
|
|
||||||
|
To create a local block device for a Vitastor image run:
|
||||||
|
|
||||||
|
```
|
||||||
|
vitastor-ublk map [/dev/ublkbN] --image testimg
|
||||||
|
```
|
||||||
|
|
||||||
|
It will output a block device name like /dev/ublkb0 which you can then use as a normal disk.
|
||||||
|
|
||||||
|
You can also use `--pool <POOL> --inode <INODE> --size <SIZE>` instead of `--image <IMAGE>` if you want.
|
||||||
|
|
||||||
|
vitastor-ublk supports all usual Vitastor configuration options like `--config_path <path_to_config>` plus ublk-specific:
|
||||||
|
|
||||||
|
* `--recover` \
|
||||||
|
Recover a mapped device if the previous ublk server is dead.
|
||||||
|
* `--queue_depth 256` \
|
||||||
|
Maximum queue size for the device.
|
||||||
|
* `--max_io_size 1M` \
|
||||||
|
Maximum single I/O size for the device. Default: `max(1 MB, pool block size * EC part count)`.
|
||||||
|
* `--readonly` \
|
||||||
|
Make the device read-only.
|
||||||
|
* `--hdd` \
|
||||||
|
Mark the device as rotational.
|
||||||
|
* `--logfile /path/to/log/file.txt` \
|
||||||
|
Write log messages to the specified file instead of dropping them (in background mode)
|
||||||
|
or printing them to the standard output (in foreground mode).
|
||||||
|
* `--dev_num N` \
|
||||||
|
Use the specified device /dev/ublkbN instead of automatic selection (alternative syntax
|
||||||
|
to /dev/ublkbN positional parameter).
|
||||||
|
* `--foreground 1` \
|
||||||
|
Stay in foreground, do not daemonize.
|
||||||
|
|
||||||
|
Note that `ublk_queue_depth` and `ublk_max_io_size` may also be specified
|
||||||
|
in `/etc/vitastor/vitastor.conf` or in other configuration file specified with `--config_path`.
|
||||||
|
|
||||||
|
## unmap
|
||||||
|
|
||||||
|
To unmap the device run:
|
||||||
|
|
||||||
|
```
|
||||||
|
vitastor-ublk unmap /dev/ublkb0
|
||||||
|
```
|
||||||
|
|
||||||
|
## ls
|
||||||
|
|
||||||
|
```
|
||||||
|
vitastor-ublk ls [--json]
|
||||||
|
```
|
||||||
|
|
||||||
|
List mapped images.
|
||||||
|
|
||||||
|
Example output (normal format):
|
||||||
|
|
||||||
|
```
|
||||||
|
/dev/ublkb0
|
||||||
|
image: bench
|
||||||
|
pid: 584536
|
||||||
|
|
||||||
|
/dev/ublkb1
|
||||||
|
image: bench1
|
||||||
|
pid: 584546
|
||||||
|
```
|
||||||
|
|
||||||
|
Example output (JSON format):
|
||||||
|
|
||||||
|
```
|
||||||
|
{"/dev/ublkb0": {"image": "bench", "pid": 584536}, "/dev/ublkb1": {"image": "bench1", "pid": 584546}}
|
||||||
|
```
|
||||||
@@ -0,0 +1,121 @@
|
|||||||
|
[Документация](../../README-ru.md#документация) → Использование → UBLK
|
||||||
|
|
||||||
|
-----
|
||||||
|
|
||||||
|
[Read in English](ublk.en.md)
|
||||||
|
|
||||||
|
# UBLK
|
||||||
|
|
||||||
|
[ublk](https://docs.kernel.org/block/ublk.html) - это новый Linux-интерфейс на основе io_uring
|
||||||
|
для реализации блочных устройств в пространстве пользователя, доступный, начиная с Linux 6.0.
|
||||||
|
|
||||||
|
ublk тоже копирует память (т.е. не является zero-copy), но по IOPS всё равно обгоняет и
|
||||||
|
[NBD](nbd.ru.md), и [VDUSE](qemu.ru.md#vduse), и иногда может даже обгонять VDUSE по
|
||||||
|
скорости линейного доступа. Также ublk позволяет оживлять устройства, у которых умер
|
||||||
|
сервер (процесс-обработчик vitastor-ublk).
|
||||||
|
|
||||||
|
## Пример сравнения производительности
|
||||||
|
|
||||||
|
TCP (100G), 3 сервера с 6 NVMe OSD каждый, 3 реплики, один клиент
|
||||||
|
|
||||||
|
| | Прямой fio | NBD | VDUSE | UBLK |
|
||||||
|
|--------------------------|-------------|-------------|------------|-------------|
|
||||||
|
| линейная запись | 3807 MB/s | 1832 MB/s | 3226 MB/s | 3027 MB/s |
|
||||||
|
| линейное чтение | 3067 MB/s | 1885 MB/s | 1800 MB/s | 2076 MB/s |
|
||||||
|
| 4k случайная запись Q128 | 128624 iops | 91060 iops | 94621 iops | 149450 iops |
|
||||||
|
| 4k случайное чтение Q128 | 117769 iops | 153408 iops | 93157 iops | 171987 iops |
|
||||||
|
| 4k случайная запись Q1 | 8090 iops | 6442 iops | 6316 iops | 7272 iops |
|
||||||
|
| 4k случайное чтение Q1 | 9474 iops | 7200 iops | 6840 iops | 8038 iops |
|
||||||
|
|
||||||
|
RDMA (100G), 3 сервера с 6 NVMe OSD каждый, 3 реплики, один клиент
|
||||||
|
|
||||||
|
| | Прямой fio | NBD | VDUSE | UBLK |
|
||||||
|
|--------------------------|-------------|-------------|-------------|-------------|
|
||||||
|
| линейная запись | 6998 MB/s | 1878 MB/s | 4249 MB/s | 3140 MB/s |
|
||||||
|
| линейное чтение | 8628 MB/s | 3389 MB/s | 5062 MB/s | 3674 MB/s |
|
||||||
|
| 4k случайная запись Q128 | 222541 iops | 181589 iops | 138281 iops | 218222 iops |
|
||||||
|
| 4k случайное чтение Q128 | 412647 iops | 239987 iops | 151663 iops | 269583 iops |
|
||||||
|
| 4k случайная запись Q1 | 11601 iops | 8592 iops | 9111 iops | 10000 iops |
|
||||||
|
| 4k случайное чтение Q1 | 10102 iops | 7788 iops | 8111 iops | 8965 iops |
|
||||||
|
|
||||||
|
## Команды
|
||||||
|
|
||||||
|
vitastor-ublk поддерживает следующие команды:
|
||||||
|
|
||||||
|
- [map](#map)
|
||||||
|
- [unmap](#unmap)
|
||||||
|
- [ls](#ls)
|
||||||
|
|
||||||
|
## map
|
||||||
|
|
||||||
|
Чтобы создать локальное блочное устройство для образа, выполните команду:
|
||||||
|
|
||||||
|
```
|
||||||
|
vitastor-ublk map [/dev/ublkbN] --image testimg
|
||||||
|
```
|
||||||
|
|
||||||
|
Команда напечатает название блочного устройства вида /dev/ublkb0, которое потом можно
|
||||||
|
будет использовать как обычный диск.
|
||||||
|
|
||||||
|
Для обращения по номеру инода, аналогично другим командам, можно использовать опции
|
||||||
|
`--pool <POOL> --inode <INODE> --size <SIZE>` вместо `--image testimg`.
|
||||||
|
|
||||||
|
vitastor-ublk поддерживает все обычные опции Vitastor, например, `--config_path <path_to_config>`,
|
||||||
|
плюс специфичные для ublk:
|
||||||
|
|
||||||
|
* `--recover` \
|
||||||
|
Восстановить ранее подключённое устройство, у которого умер обработчик.
|
||||||
|
* `--queue_depth 256` \
|
||||||
|
Максимальная глубина очереди устройства.
|
||||||
|
* `--max_io_size 1M` \
|
||||||
|
Максимальный размер запроса ввода-вывода для устройства. По умолчанию: `max(1 MB, блок данных пула * число частей данных EC)`.
|
||||||
|
* `--readonly` \
|
||||||
|
Подключить устройство в режиме только для чтения.
|
||||||
|
* `--hdd` \
|
||||||
|
Пометить устройство как вращающийся жёсткий диск (флаг rotational).
|
||||||
|
* `--logfile /path/to/log/file.txt` \
|
||||||
|
Писать сообщения о процессе работы в заданный файл, вместо пропуска их
|
||||||
|
при фоновом режиме запуска или печати на стандартный вывод при запуске
|
||||||
|
в консоли с `--foreground 1`.
|
||||||
|
* `--dev_num N` \
|
||||||
|
Использовать заданное устройство `/dev/ublkbN` вместо автоматического подбора.
|
||||||
|
* `--foreground 1` \
|
||||||
|
Не уводить процесс в фоновый режим.
|
||||||
|
|
||||||
|
Обратите внимание, что опции `ublk_queue_depth` и `ublk_max_io_size` можно
|
||||||
|
также задавать в `/etc/vitastor/vitastor.conf` или в другом файле конфигурации,
|
||||||
|
заданном опцией `--config_path`.
|
||||||
|
|
||||||
|
## unmap
|
||||||
|
|
||||||
|
Для отключения устройства выполните:
|
||||||
|
|
||||||
|
```
|
||||||
|
vitastor-ublk unmap /dev/ublkb0
|
||||||
|
```
|
||||||
|
|
||||||
|
## ls
|
||||||
|
|
||||||
|
```
|
||||||
|
vitastor-ublk ls [--json]
|
||||||
|
```
|
||||||
|
|
||||||
|
Вывести подключённые устройства.
|
||||||
|
|
||||||
|
Пример вывода в обычном формате:
|
||||||
|
|
||||||
|
```
|
||||||
|
/dev/ublkb0
|
||||||
|
image: bench
|
||||||
|
pid: 584536
|
||||||
|
|
||||||
|
/dev/ublkb1
|
||||||
|
image: bench1
|
||||||
|
pid: 584546
|
||||||
|
```
|
||||||
|
|
||||||
|
Пример вывода в JSON-формате:
|
||||||
|
|
||||||
|
```
|
||||||
|
{"/dev/ublkb0": {"image": "bench", "pid": 584536}, "/dev/ublkb1": {"image": "bench1", "pid": 584546}}
|
||||||
|
```
|
||||||
+1
-1
Submodule json11 updated: fd37016cf8...edcd85b8bd
+49
-8
@@ -3,6 +3,7 @@
|
|||||||
|
|
||||||
const AntiEtcd = require('antietcd');
|
const AntiEtcd = require('antietcd');
|
||||||
|
|
||||||
|
const vitastor_auth_filter = require('./vitastor_auth_filter.js');
|
||||||
const vitastor_persist_filter = require('./vitastor_persist_filter.js');
|
const vitastor_persist_filter = require('./vitastor_persist_filter.js');
|
||||||
const { b64, local_ips } = require('./utils.js');
|
const { b64, local_ips } = require('./utils.js');
|
||||||
|
|
||||||
@@ -18,7 +19,7 @@ class AntiEtcdAdapter
|
|||||||
cluster = cluster ? (''+(cluster||'')).split(/,+/) : [];
|
cluster = cluster ? (''+(cluster||'')).split(/,+/) : [];
|
||||||
cluster = Object.keys(cluster.reduce((a, url) =>
|
cluster = Object.keys(cluster.reduce((a, url) =>
|
||||||
{
|
{
|
||||||
a[url.toLowerCase().replace(/^(https?:\/\/)/, '').replace(/\/.*$/, '')] = true;
|
a[url.toLowerCase().replace(/^(https?:\/\/)?(.*?)(\/.*)?$/, (m, m1, m2) => (m1||'http://')+m2)] = true;
|
||||||
return a;
|
return a;
|
||||||
}, {}));
|
}, {}));
|
||||||
const cfg_port = config.antietcd_port;
|
const cfg_port = config.antietcd_port;
|
||||||
@@ -26,7 +27,18 @@ class AntiEtcdAdapter
|
|||||||
is_local['0.0.0.0'] = true;
|
is_local['0.0.0.0'] = true;
|
||||||
is_local['::'] = true;
|
is_local['::'] = true;
|
||||||
is_local[''] = true;
|
is_local[''] = true;
|
||||||
const selected = cluster.map(s => s.split(':', 2)).filter(ip => is_local[ip[0]] && (!cfg_port || ip[1] == cfg_port));
|
// split :, 3 -> <schema>:<//ip>:<port>
|
||||||
|
const selected = [];
|
||||||
|
for (let i = 0; i < cluster.length; i++)
|
||||||
|
{
|
||||||
|
const m = /^(https?:\/\/)?(?:\[(.*)\]|([^\[\:]+))(?::(\d+))?$/.exec(cluster[i]);
|
||||||
|
if (!m)
|
||||||
|
continue;
|
||||||
|
const ip = m[3] || m[2];
|
||||||
|
const port = m[4] || 2379;
|
||||||
|
if (is_local[ip] && (!cfg_port || port == cfg_port))
|
||||||
|
selected.push({ idx: i, ip, port });
|
||||||
|
}
|
||||||
if (selected.length > 1)
|
if (selected.length > 1)
|
||||||
{
|
{
|
||||||
console.error('More than 1 etcd_address matches local IPs, please specify port');
|
console.error('More than 1 etcd_address matches local IPs, please specify port');
|
||||||
@@ -35,16 +47,45 @@ class AntiEtcdAdapter
|
|||||||
else if (selected.length == 1)
|
else if (selected.length == 1)
|
||||||
{
|
{
|
||||||
const antietcd_config = {
|
const antietcd_config = {
|
||||||
ip: selected[0][0],
|
ip: selected[0].ip,
|
||||||
port: selected[0][1],
|
port: selected[0].port,
|
||||||
data: config.antietcd_data_file || ((config.antietcd_data_dir || '/var/lib/vitastor') + '/mon_'+selected[0][1]+'.json.gz'),
|
cert: config.antietcd_cert,
|
||||||
|
key: config.antietcd_key,
|
||||||
|
ca: config.client_ca,
|
||||||
|
data: config.antietcd_data_file || ((config.antietcd_data_dir || '/var/lib/vitastor') + '/mon_'+selected[0].port+'.json.gz'),
|
||||||
persist_filter: vitastor_persist_filter({ vitastor_prefix: config.etcd_prefix || '/vitastor' }),
|
persist_filter: vitastor_persist_filter({ vitastor_prefix: config.etcd_prefix || '/vitastor' }),
|
||||||
node_id: selected[0][0]+':'+selected[0][1], // node_id = ip:port
|
node_id: cluster[selected[0].idx].replace(/^(https?:\/\/)/, ''), // same as in <cluster> below
|
||||||
cluster: (cluster.length == 1 ? null : cluster.reduce((a, c) => { a[c] = "http://"+c; return a; }, {})),
|
cluster: (cluster.length == 1 ? null : cluster.reduce((a, c) => { a[c.replace(/^(https?:\/\/)/, '')] = c; return a; }, {})),
|
||||||
cluster_key: (config.etcd_prefix || '/vitastor'),
|
cluster_key: (config.etcd_prefix || '/vitastor'),
|
||||||
stale_read: 1,
|
stale_read: 1,
|
||||||
log_level: 1,
|
log_level: 1,
|
||||||
|
logs: { cluster: true },
|
||||||
};
|
};
|
||||||
|
if (config.etcd_proxy)
|
||||||
|
{
|
||||||
|
// Monitor may use the builtin etcd_proxy mode
|
||||||
|
if (!config.etcd_proxy.urls)
|
||||||
|
{
|
||||||
|
console.error('etcd_proxy.urls are empty');
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
antietcd_config.etcd_proxy = config.etcd_proxy.urls;
|
||||||
|
antietcd_config.etcd_cert = config.etcd_proxy.cert;
|
||||||
|
antietcd_config.etcd_key = config.etcd_proxy.key;
|
||||||
|
antietcd_config.etcd_ca = config.etcd_proxy.ca;
|
||||||
|
delete antietcd_config.data;
|
||||||
|
delete antietcd_config.persist_filter;
|
||||||
|
delete antietcd_config.cluster;
|
||||||
|
delete antietcd_config.cluster_key;
|
||||||
|
}
|
||||||
|
if (config.use_perms)
|
||||||
|
{
|
||||||
|
antietcd_config.client_cert_auth = true;
|
||||||
|
antietcd_config.auth_filter = vitastor_auth_filter;
|
||||||
|
antietcd_config.ca = config.client_ca;
|
||||||
|
antietcd_config.osd_ca = config.osd_ca;
|
||||||
|
antietcd_config.mon_ca = config.mon_ca;
|
||||||
|
}
|
||||||
for (const key in config)
|
for (const key in config)
|
||||||
{
|
{
|
||||||
if (key.substr(0, 9) === 'antietcd_')
|
if (key.substr(0, 9) === 'antietcd_')
|
||||||
@@ -169,7 +210,7 @@ class AntiEtcdAdapter
|
|||||||
await new Promise(ok => setTimeout(ok, timeout-(Date.now()-prev)));
|
await new Promise(ok => setTimeout(ok, timeout-(Date.now()-prev)));
|
||||||
}
|
}
|
||||||
prev = Date.now();
|
prev = Date.now();
|
||||||
const res = await this.antietcd.api(path.replace(/^\/+/, '').replace(/\/+$/, '').replace(/\/+/g, '_'), body);
|
const res = await this.antietcd.api(path.replace(/^\/+/, '').replace(/\/+$/, '').replace(/\/+/g, '_'), body, { user_type: 'mon' });
|
||||||
if (res.error)
|
if (res.error)
|
||||||
{
|
{
|
||||||
console.error('Failed to query antietcd '+path+' (retry '+retry+'/'+retries+'): '+res.error);
|
console.error('Failed to query antietcd '+path+' (retry '+retry+'/'+retries+'): '+res.error);
|
||||||
|
|||||||
+27
-6
@@ -1,7 +1,9 @@
|
|||||||
// Copyright (c) Vitaliy Filippov, 2019+
|
// Copyright (c) Vitaliy Filippov, 2019+
|
||||||
// License: VNPL-1.1 (see README.md for details)
|
// License: VNPL-1.1 (see README.md for details)
|
||||||
|
|
||||||
|
const fs = require('fs');
|
||||||
const http = require('http');
|
const http = require('http');
|
||||||
|
const https = require('https');
|
||||||
const WebSocket = require('ws');
|
const WebSocket = require('ws');
|
||||||
const { b64, local_ips } = require('./utils.js');
|
const { b64, local_ips } = require('./utils.js');
|
||||||
|
|
||||||
@@ -15,11 +17,30 @@ class EtcdAdapter
|
|||||||
this.ws = null;
|
this.ws = null;
|
||||||
this.ws_alive = false;
|
this.ws_alive = false;
|
||||||
this.ws_keepalive_timer = null;
|
this.ws_keepalive_timer = null;
|
||||||
|
this.opts = {};
|
||||||
}
|
}
|
||||||
|
|
||||||
parse_config(config)
|
parse_config(config)
|
||||||
{
|
{
|
||||||
this.parse_etcd_addresses(config.etcd_address||config.etcd_url);
|
this.parse_etcd_addresses(config.etcd_address||config.etcd_url);
|
||||||
|
if (config.mon_etcd_client_cert || config.etcd_client_cert)
|
||||||
|
{
|
||||||
|
this.opts.cert = config.mon_etcd_client_cert || config.etcd_client_cert;
|
||||||
|
if (this.opts.cert.substr(0, 5) != '-----')
|
||||||
|
this.opts.cert = fs.readFileSync(this.opts.cert, { encoding: 'utf-8' });
|
||||||
|
}
|
||||||
|
if (config.mon_etcd_client_key || config.etcd_client_key)
|
||||||
|
{
|
||||||
|
this.opts.key = config.mon_etcd_client_key || config.etcd_client_key;
|
||||||
|
if (this.opts.key.substr(0, 5) != '-----')
|
||||||
|
this.opts.key = fs.readFileSync(this.opts.key, { encoding: 'utf-8' });
|
||||||
|
}
|
||||||
|
if (config.etcd_ca)
|
||||||
|
{
|
||||||
|
this.opts.ca = config.etcd_ca;
|
||||||
|
if (this.opts.ca.substr(0, 5) != '-----')
|
||||||
|
this.opts.ca = fs.readFileSync(this.opts.ca, { encoding: 'utf-8' });
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
parse_etcd_addresses(addrs)
|
parse_etcd_addresses(addrs)
|
||||||
@@ -39,7 +60,7 @@ class EtcdAdapter
|
|||||||
for (let url of addrs)
|
for (let url of addrs)
|
||||||
{
|
{
|
||||||
let scheme = 'http';
|
let scheme = 'http';
|
||||||
url = url.trim().replace(/^(https?):\/\//, (m, m1) => { scheme = m1; return ''; });
|
url = url.trim().replace(/^(https?):\/\//i, (m, m1) => { scheme = m1.toLowerCase(); return ''; });
|
||||||
const slash = url.indexOf('/');
|
const slash = url.indexOf('/');
|
||||||
const colon = url.indexOf(':');
|
const colon = url.indexOf(':');
|
||||||
const is_local = is_local_ip[colon >= 0 ? url.substr(0, colon) : (slash >= 0 ? url.substr(0, slash) : url)];
|
const is_local = is_local_ip[colon >= 0 ? url.substr(0, colon) : (slash >= 0 ? url.substr(0, slash) : url)];
|
||||||
@@ -130,7 +151,7 @@ class EtcdAdapter
|
|||||||
}
|
}
|
||||||
ok(false);
|
ok(false);
|
||||||
}, this.mon.config.etcd_mon_timeout);
|
}, this.mon.config.etcd_mon_timeout);
|
||||||
this.ws = new WebSocket(base+'/watch');
|
this.ws = new WebSocket(base+'/watch', this.opts);
|
||||||
this.ws_used_url = cur_addr;
|
this.ws_used_url = cur_addr;
|
||||||
const fail = () =>
|
const fail = () =>
|
||||||
{
|
{
|
||||||
@@ -272,7 +293,7 @@ class EtcdAdapter
|
|||||||
{
|
{
|
||||||
throw new Error(MON_STOPPED);
|
throw new Error(MON_STOPPED);
|
||||||
}
|
}
|
||||||
const res = await POST(base+path, body, timeout);
|
const res = await POST(base+path, body, timeout, this.opts);
|
||||||
if (this.mon.stopped)
|
if (this.mon.stopped)
|
||||||
{
|
{
|
||||||
throw new Error(MON_STOPPED);
|
throw new Error(MON_STOPPED);
|
||||||
@@ -298,7 +319,7 @@ class EtcdAdapter
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
function POST(url, body, timeout)
|
function POST(url, body, timeout, opts)
|
||||||
{
|
{
|
||||||
return new Promise(ok =>
|
return new Promise(ok =>
|
||||||
{
|
{
|
||||||
@@ -310,10 +331,10 @@ function POST(url, body, timeout)
|
|||||||
req = null;
|
req = null;
|
||||||
ok({ error: 'timeout' });
|
ok({ error: 'timeout' });
|
||||||
}, timeout) : null;
|
}, timeout) : null;
|
||||||
let req = http.request(url, { method: 'POST', headers: {
|
let req = (url.substr(0, 5) == 'https' ? https : http).request(url, { method: 'POST', headers: {
|
||||||
'Content-Type': 'application/json',
|
'Content-Type': 'application/json',
|
||||||
'Content-Length': body_text.length,
|
'Content-Length': body_text.length,
|
||||||
} }, (res) =>
|
}, ...(opts||{}) }, (res) =>
|
||||||
{
|
{
|
||||||
if (!req)
|
if (!req)
|
||||||
{
|
{
|
||||||
|
|||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user