X-Git-Url: https://git.proxmox.com/?p=pve-docs.git;a=blobdiff_plain;f=pve-storage-rbd.adoc;h=a94cade8f5293fed44976d5225254f5917af47b2;hp=ee073714ebcd51eb0d39af82d2161f96268ec81e;hb=HEAD;hpb=78f02fed81357f4720b07d1d045ff873b9c7c1dc diff --git a/pve-storage-rbd.adoc b/pve-storage-rbd.adoc index ee07371..5fe558a 100644 --- a/pve-storage-rbd.adoc +++ b/pve-storage-rbd.adoc @@ -1,3 +1,4 @@ +:fn-ceph-user-mgmt: footnote:cephusermgmt[Ceph user management {cephdocs-url}/rados/operations/user-management/] [[ceph_rados_block_devices]] Ceph RADOS Block Devices (RBD) ------------------------------ @@ -8,7 +9,7 @@ endif::wiki[] Storage pool type: `rbd` -http://ceph.com[Ceph] is a distributed object store and file system +https://ceph.com[Ceph] is a distributed object store and file system designed to provide excellent performance, reliability and scalability. RADOS block devices implement a feature rich block level storage, and you get the following advantages: @@ -37,7 +38,7 @@ This backend supports the common storage properties `nodes`, monhost:: List of monitor daemon IPs. Optional, only needed if Ceph is not running on the -PVE cluster. +{pve} cluster. pool:: @@ -45,12 +46,15 @@ Ceph pool name. username:: -RBD user Id. Optional, only needed if Ceph is not running on the PVE cluster. +RBD user ID. Optional, only needed if Ceph is not running on the {pve} cluster. +Note that only the user ID should be used. The "client." type prefix must be +left out. krbd:: -Access rbd through krbd kernel module. This is required if you want to -use the storage for containers. +Enforce access to rados block devices through the krbd kernel module. Optional. + +NOTE: Containers will use `krbd` independent of the option value. .Configuration Example for a external Ceph cluster (`/etc/pve/storage.cfg`) ---- @@ -66,22 +70,62 @@ TIP: You can use the `rbd` utility to do low-level management tasks. Authentication ~~~~~~~~~~~~~~ -If you use `cephx` authentication, you need to copy the keyfile from your -external Ceph cluster to a Proxmox VE host. +NOTE: If Ceph is installed locally on the {pve} cluster, the following is done +automatically when adding the storage. + +If you use `cephx` authentication, which is enabled by default, you need to +provide the keyring from the external Ceph cluster. + +To configure the storage via the CLI, you first need to make the file +containing the keyring available. One way is to copy the file from the external +Ceph cluster directly to one of the {pve} nodes. The following example will +copy it to the `/root` directory of the node on which we run it: + +---- +# scp :/etc/ceph/ceph.client.admin.keyring /root/rbd.keyring +---- + +Then use the `pvesm` CLI tool to configure the external RBD storage, use the +`--keyring` parameter, which needs to be a path to the keyring file that you +copied. For example: + +---- +# pvesm add rbd --monhost "10.1.1.20 10.1.1.21 10.1.1.22" --content images --keyring /root/rbd.keyring +---- -Create the directory `/etc/pve/priv/ceph` with +When configuring an external RBD storage via the GUI, you can copy and paste +the keyring into the appropriate field. - mkdir /etc/pve/priv/ceph +The keyring will be stored at -Then copy the keyring +---- +# /etc/pve/priv/ceph/.keyring +---- + +TIP: Creating a keyring with only the needed capabilities is recommend when +connecting to an external cluster. For further information on Ceph user +management, see the Ceph docs.footnoteref:[cephusermgmt,{cephdocs-url}/rados/operations/user-management/[Ceph User Management]] + +Ceph client configuration (optional) +~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + +Connecting to an external Ceph storage doesn't always allow setting +client-specific options in the config DB on the external cluster. You can add a +`ceph.conf` beside the Ceph keyring to change the Ceph client configuration for +the storage. + +The ceph.conf needs to have the same name as the storage. + +---- +# /etc/pve/priv/ceph/.conf +---- - scp :/etc/ceph/ceph.client.admin.keyring /etc/pve/priv/ceph/.keyring +See the RBD configuration reference footnote:[RBD configuration reference +{cephdocs-url}/rbd/rbd-config-ref/] for possible settings. -The keyring must be named to match your ``. Copying the -keyring generally requires root privileges. +NOTE: Do not change these settings lightly. {PVE} is merging the +.conf with the storage configuration. -If Ceph is installed locally on the PVE cluster, this is done automatically by -'pveceph' or in the GUI. Storage Features ~~~~~~~~~~~~~~~~