[root@k8s01 object-store-01]# vi rgw-external.yaml
apiVersion: v1
kind: Service
metadata:
name: rook-ceph-rgw-object-store-01-external
namespace: rook-ceph # namespace:cluster
labels:
app: rook-ceph-rgw
rook_cluster: rook-ceph # namespace:cluster
rook_object_store: object-store-01
spec:
ports:
- name: rgw
nodePort: 30071
port: 80 # service port mentioned in object store crd
protocol: TCP
targetPort: 8080
selector:
app: rook-ceph-rgw
rook_cluster: rook-ceph # namespace:cluster
rook_object_store: object-store-01
sessionAffinity: None
type: NodePort
[root@k8s01 object-store-01]# kubectl create -f rgw-external.yaml
[root@k8s01 object-store-01]# kubectl -n rook-ceph get service
rook-ceph-rgw-object-store-01 ClusterIP 10.102.125.183 <none> 80/TCP 176m
rook-ceph-rgw-object-store-01-external NodePort 10.100.226.234 <none> 80:30071/TCP 3s
[root@k8s01 object-store-01]# vi object-user.yaml
#################################################################################################################
# Create an object store user for access to the s3 endpoint.
# kubectl create -f object-user.yaml
#################################################################################################################
apiVersion: ceph.rook.io/v1
kind: CephObjectStoreUser
metadata:
name: cox
namespace: rook-ceph # namespace:cluster
spec:
store: object-store-01
displayName: "cox"
# Quotas set on the user
# quotas:
# maxBuckets: 100
# maxSize: 10G
# maxObjects: 10000
# Additional permissions given to the user
# capabilities:
# user: "*"
# bucket: "*"
# metadata: "*"
# usage: "*"
# zone: "*"
[root@k8s01 object-store-01]# kubectl create -f object-user.yaml
$ k get cephobjectstoreuser -n rook-ceph
NAME PHASE
encore Ready
$ k apply -f toolbox.yaml -n rook-ceph
[root@k8s01 object-store-01]# k -n rook-ceph exec -it rook-ceph-tools-d6d7c985c-2trbn -- /bin/bash
radosgw-admin user modify --uid={USER_ID} --access-key=${ACCESS_KEY} --secret-key={SECRET_KEY}
[rook@rook-ceph-tools-d6d7c985c-2trbn /]$ radosgw-admin user modify --uid=cox --access-key=${REDACTED} --secret-key=secret-key
kubectl patch sc rook-ceph-block -p '{"metadata": {"annotations": {"storageclass.kubernetes.io/is-default-class": "true"}}}'
$ kubectl get sc
NAME PROVISIONER RECLAIMPOLICY VOLUMEBINDINGMODE ALLOWVOLUMEEXPANSION AGE
rook-ceph-block (default) rook-ceph.rbd.csi.ceph.com Delete Immediate true 69m
rook-ceph-delete-bucket rook-ceph.ceph.rook.io/bucket Delete Immediate false 65m