Skip to content
Merged

0.27.2 #2043

Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
182 commits
Select commit Hold shift + click to select a range
d8717b3
fix: auto-heal Completed CHIs with sustained-NotReady hosts
dashashutosh80 May 29, 2026
4e127ba
0.27.2
sunsingerus Jun 5, 2026
3e995c0
env: manifests
sunsingerus Jun 5, 2026
16c69e8
env: helm chart
sunsingerus Jun 5, 2026
9b97f10
Merge remote-tracking branch 'altinity/master' into 0.27.2
sunsingerus Jun 5, 2026
d20f0d4
dev: brancher
sunsingerus Jun 5, 2026
8649295
dev: releaser
sunsingerus Jun 5, 2026
77520e7
Cleanup/improve inter-cluster comm tests
alex-zaitsev Jun 5, 2026
ab162a1
Removed 020013 that is fully covered by 020016
alex-zaitsev Jun 5, 2026
c996d30
Removed test-020 since multi-volume scenarios are fully tested by 021
alex-zaitsev Jun 5, 2026
735e90d
Remove test_018 that has functionality covered by test_016
alex-zaitsev Jun 5, 2026
0a90c71
fix(helm): wire watchNamespaces value into operator ConfigMap
jtomaszon Jun 6, 2026
6ab71fe
Bump go to 1.26.4 to address CVEs
alex-zaitsev Jun 6, 2026
3ed8cb4
dev: root ca ref
sunsingerus Jun 9, 2026
18d4767
dev: config
sunsingerus Jun 9, 2026
ef74352
dev:manifests
sunsingerus Jun 9, 2026
c2a93d1
dev: unit tests
sunsingerus Jun 9, 2026
35a9d1d
dev: new flags implementation
sunsingerus Jun 9, 2026
e0d6d65
Test for https://github.com/Altinity/clickhouse-operator/pull/1998
alex-zaitsev Jun 10, 2026
fbec479
Forgot test manifest
alex-zaitsev Jun 10, 2026
4fef142
dev: CRD fields
sunsingerus Jun 10, 2026
45c848c
dev: operator manifests
sunsingerus Jun 10, 2026
4f79eb5
dev: helm chart
sunsingerus Jun 10, 2026
721ca08
dev: unit tests
sunsingerus Jun 10, 2026
661cf16
dev: description
sunsingerus Jun 10, 2026
be6e8b0
dev: configuration
sunsingerus Jun 10, 2026
3e84e27
dev: test manifests
sunsingerus Jun 10, 2026
231272c
dev: ca root test
sunsingerus Jun 10, 2026
7dd5f38
dev: example
sunsingerus Jun 10, 2026
4ce730e
docs
sunsingerus Jun 10, 2026
4934437
Merge remote-tracking branch 'altinity/0.27.2' into 0.27.2
sunsingerus Jun 10, 2026
d04a86b
Merge PR #1998: auto-heal Completed CHIs with sustained-NotReady hosts
sunsingerus Jun 11, 2026
09ae7b3
feat(helm): add podSecurityContext and podAnnotations to crdHook Job
qlevasseur-genetec Jun 16, 2026
b3c1a28
dev:
sunsingerus Jun 16, 2026
622c5c4
dev: config implementation
sunsingerus Jun 16, 2026
9367ff6
dev: unit test for recovery toggles
sunsingerus Jun 16, 2026
be72a0c
dev: crd template
sunsingerus Jun 16, 2026
da634bd
dev: retry options
sunsingerus Jun 16, 2026
39d229e
doc: examples
sunsingerus Jun 16, 2026
060c645
test: polish fips
sunsingerus Jun 16, 2026
785585f
test: recovery
sunsingerus Jun 16, 2026
9d22070
dev: codegen
sunsingerus Jun 16, 2026
17e515a
test: manifests
sunsingerus Jun 16, 2026
0b09bc3
env: manifests
sunsingerus Jun 16, 2026
cdb87f6
env: helm
sunsingerus Jun 16, 2026
3ea7ab2
dev: config
sunsingerus Jun 16, 2026
2c5d083
dev: reconciler
sunsingerus Jun 16, 2026
08d615d
Merge pull request #2009 from qlevasseur-genetec/ql/crdhook-pod-security
Slach Jun 17, 2026
1eed6cc
dev: start naming normalization
sunsingerus Jun 18, 2026
74d6eb2
dev: crd from normalization
sunsingerus Jun 18, 2026
480206c
env: manifests
sunsingerus Jun 18, 2026
2b4c2e2
env: helm chart
sunsingerus Jun 18, 2026
f8c559c
dev: config
sunsingerus Jun 18, 2026
e37e205
dev: api structures
sunsingerus Jun 18, 2026
770e9d0
dev: adjust controller
sunsingerus Jun 18, 2026
2a16584
dev: codegen
sunsingerus Jun 18, 2026
2217b49
doc: examples
sunsingerus Jun 18, 2026
4409d05
doc: updated
sunsingerus Jun 18, 2026
ba084bf
test: adjust accordingly
sunsingerus Jun 18, 2026
b28dfe6
major improvement of FIPS coverage, added fips test plan to the requi…
Elmo33 Jun 18, 2026
f441c5c
major improvement of FIPS coverage, added fips test plan to the requi…
Elmo33 Jun 18, 2026
fafa5dc
fixed 035-2 scenario, added a new test for external client check via …
Elmo33 Jun 19, 2026
95dd756
added missing manifests
Elmo33 Jun 19, 2026
5f60ee3
dev: enum
sunsingerus Jun 19, 2026
558afe7
dev: emum unit test
sunsingerus Jun 19, 2026
aa1a51e
dev: hump-casing config
sunsingerus Jun 19, 2026
c7103d2
dev: allow both humped and lowercased const values in CRD
sunsingerus Jun 19, 2026
73ecf18
env: manifests
sunsingerus Jun 19, 2026
333233c
env: helm charts
sunsingerus Jun 19, 2026
cb11f4e
dev: humpe const
sunsingerus Jun 19, 2026
3aa538b
dev: string equal fold
sunsingerus Jun 19, 2026
50309fc
dev: folding
sunsingerus Jun 19, 2026
8fb51b8
updated expired certificates
Elmo33 Jun 19, 2026
dbce47d
dev: normalizer
sunsingerus Jun 20, 2026
5deef8b
dev: common wrappers
sunsingerus Jun 20, 2026
834c0cc
dev: switch to const
sunsingerus Jun 20, 2026
443868a
dev: config
sunsingerus Jun 20, 2026
dee54eb
dev: new service type
sunsingerus Jun 23, 2026
87cc91b
dev: service model
sunsingerus Jun 23, 2026
c5a8f17
minor adjustments to the FIPS test plan and requirements
Elmo33 Jun 23, 2026
4280c0a
dev: two services
sunsingerus Jun 23, 2026
6b6f173
test: manifests
sunsingerus Jun 23, 2026
b3ce0f2
test: services
sunsingerus Jun 23, 2026
6c02444
test: image preloader
sunsingerus Jun 23, 2026
7b41d0c
dev: minor
sunsingerus Jun 23, 2026
597158c
dev: notes
sunsingerus Jun 23, 2026
fbaa871
Merge remote-tracking branch 'altinity/0.27.2' into 0.27.2
sunsingerus Jun 23, 2026
36201dc
added godebug set to =only for every operator deployment
Elmo33 Jun 23, 2026
da6e5a4
added godebug set to =only for every operator deployment
Elmo33 Jun 23, 2026
52a879e
Merge PR #2011 (FIPS test plan/requirements/e2e alignment) into 0.27.2
sunsingerus Jun 23, 2026
33eb349
fixed chopconf install
Elmo33 Jun 23, 2026
22d816c
Fix test_010035_2/_3 after PR #2011 merge
sunsingerus Jun 23, 2026
d43abff
fixed gofips tag for failing scenario
Elmo33 Jun 23, 2026
d4d4c20
test: preloader
sunsingerus Jun 24, 2026
0daae88
test: polish
sunsingerus Jun 24, 2026
4ca7416
Merge branch 'pr2011-new' into 0.27.2
sunsingerus Jun 24, 2026
40c388a
dev: satisfy linter
sunsingerus Jun 25, 2026
cf7749c
test: delete outdated templates
sunsingerus Jun 30, 2026
8c0791a
test: kubectl ctx in tests
sunsingerus Jun 30, 2026
78de59e
test: use minikube profile
sunsingerus Jun 30, 2026
7f55009
test: introduce dual entry in local script
sunsingerus Jun 30, 2026
e6dd096
test: enhanse log
sunsingerus Jun 30, 2026
42c72d4
test: preloader
sunsingerus Jun 30, 2026
00fd5d8
test: dual resetter
sunsingerus Jun 30, 2026
5e66896
test: operator dual entrypoint
sunsingerus Jun 30, 2026
4856f1c
wire K8s client TLS minVersion into rest.Config transport
Elmo33 Jun 30, 2026
17acea7
add replica restart fix for operator when remote_servers configmap is…
oo007 Jul 1, 2026
2258433
dev: switch to olm.targtNamespaces in template
sunsingerus Jul 1, 2026
8b727ef
dev: special case for olm amespaces
sunsingerus Jul 1, 2026
7318c91
test: minor
sunsingerus Jul 1, 2026
4ce250b
dev: notes
sunsingerus Jul 1, 2026
f2c3fbf
dev: unit test
sunsingerus Jul 1, 2026
4e726f7
fix(helm): generate watchNamespaces ConfigMap wiring from the generator
jtomaszon Jul 2, 2026
159281a
Improve Keeper rescale test
alex-zaitsev Jul 3, 2026
9e78d09
Apply filter when scan SQL results
dentiny Jul 3, 2026
205cd1b
Expand FIPS TLS e2e coverage and add host-run cipher probes (test_030…
Elmo33 Jul 6, 2026
e1ad916
removed obsolete file
Elmo33 Jul 6, 2026
044d190
removed leftover debug code
Elmo33 Jul 6, 2026
cec2dac
Merge PR #2024: replica restart fix for scale-up remote_servers propa…
sunsingerus Jul 6, 2026
a2aef28
dev: check single node cluster
sunsingerus Jul 6, 2026
3fa6416
dev: expose with interface
sunsingerus Jul 6, 2026
163b497
dev: single node clusters
sunsingerus Jul 6, 2026
62346ec
dev: switch to helper func
sunsingerus Jul 6, 2026
0892d31
dev: restart new hosts
sunsingerus Jul 6, 2026
337d8a8
dev: explanation
sunsingerus Jul 6, 2026
cdd868d
dev: introduce error counter
sunsingerus Jul 6, 2026
27f0c08
dev: introduce error counter sql for cluster does not exist
sunsingerus Jul 6, 2026
0afd817
test: cover with test
sunsingerus Jul 6, 2026
030b366
dev: some explanation
sunsingerus Jul 6, 2026
1eb0629
Merge remote-tracking branch 'altinity/0.27.2' into 0.27.2
sunsingerus Jul 6, 2026
09d6b17
feat: add configurable MaxConcurrentReconciles for CHK controller
miguel-signoz Jul 6, 2026
b7db8b7
dev: minor
sunsingerus Jul 7, 2026
fc20c2e
dev: error deps
sunsingerus Jul 8, 2026
08233ec
Merge PR #2020: wire security.kubernetes.tls.minVersion into the Kube…
sunsingerus Jul 9, 2026
29f3ba4
Cleanup test_081
alex-zaitsev Jul 9, 2026
bfa805f
dev: config file clarification
sunsingerus Jul 10, 2026
95b7ef8
dev: crd minor
sunsingerus Jul 10, 2026
60235de
dev: enhanse tls handling
sunsingerus Jul 10, 2026
fee921f
dev: unit test
sunsingerus Jul 10, 2026
fd0245a
dev: config
sunsingerus Jul 10, 2026
2203c9e
dev: manifests
sunsingerus Jul 10, 2026
2cb9a37
dev: helm
sunsingerus Jul 10, 2026
155fb1a
Merge remote-tracking branch 'altinity/0.27.2' into 0.27.2
sunsingerus Jul 10, 2026
6b226b9
pkg/xml: escape reserved characters in element text
AruneshDwivedi Jul 12, 2026
e02c1a7
Merge PR #2031: expand FIPS TLS e2e coverage (host-run cipher probes,…
sunsingerus Jul 13, 2026
33e4a6b
test: acvp runner
sunsingerus Jul 14, 2026
ab3f955
test: minor
sunsingerus Jul 14, 2026
ea91c07
test: adop FIPS part 2
sunsingerus Jul 14, 2026
1ad196a
dev: adjust option description
sunsingerus Jul 15, 2026
e4a8c3b
dev: intorduce explicit metrics filter
sunsingerus Jul 15, 2026
3fb187c
dev: use metrics filter in fetcher
sunsingerus Jul 15, 2026
5edae95
dev: use mterics filter in prometheus writer
sunsingerus Jul 15, 2026
28c62cf
dev: unit test
sunsingerus Jul 15, 2026
cbcabfb
env: manifests
sunsingerus Jul 15, 2026
3b17a51
env: helm chart
sunsingerus Jul 15, 2026
52f09f6
fix(helm): wire watchNamespaces value into operator ConfigMap
jtomaszon Jun 6, 2026
5b6a06a
fix(helm): generate watchNamespaces ConfigMap wiring from the generator
jtomaszon Jul 2, 2026
89867a7
dev: polish helm generator
sunsingerus Jul 15, 2026
9248d7e
feat: add configurable MaxConcurrentReconciles for CHK controller
miguel-signoz Jul 6, 2026
1031226
Merge PR #2028: apply metrics exclude filter at SQL scan
sunsingerus Jul 16, 2026
b8c14aa
Merge PR #2007: wire watchNamespaces into operator ConfigMap
sunsingerus Jul 16, 2026
2b22cf0
dev: extract controller constructor
sunsingerus Jul 16, 2026
dc7481e
dev: swticj from struct fill to constructor
sunsingerus Jul 16, 2026
8bfca5d
dev: generator sideeffects
sunsingerus Jul 16, 2026
7bcb3b0
Canary tests. 082_1 is XFailed for now
alex-zaitsev Jul 16, 2026
a02c917
Merge remote-tracking branch 'altinity/0.27.2' into 0.27.2
sunsingerus Jul 17, 2026
4dfbea0
Merge PR #2033: configurable MaxConcurrentReconciles for CHK controller
sunsingerus Jul 17, 2026
fcdfcda
dev: carve out hidden pprof
sunsingerus Jul 17, 2026
44e1017
pkg/xml: escape reserved characters in element text
AruneshDwivedi Jul 12, 2026
ecbf1f3
dev: intoduce raw or escape writer options
sunsingerus Jul 17, 2026
5d57d65
dev: unit tests
sunsingerus Jul 17, 2026
c0f085f
Merge PR #2034: escape reserved characters in XML element text
sunsingerus Jul 20, 2026
51f2999
dev: github test cleaner
sunsingerus Jul 21, 2026
e2146dc
env: hub manifests
sunsingerus Jul 21, 2026
7cc22c5
Test for XML injection via settings
alex-zaitsev Jul 22, 2026
d38c54f
bump version in upgrade tests
alex-zaitsev Jul 22, 2026
02719a2
dev: review vet
sunsingerus Jul 22, 2026
c4caedc
Merge remote-tracking branch 'altinity/0.27.2' into 0.27.2
sunsingerus Jul 22, 2026
eb03965
dev: remove unused spces
sunsingerus Jul 23, 2026
245b085
dev: missed err
sunsingerus Jul 23, 2026
da05629
dev: explicitly move to defaulting values instead of panic
sunsingerus Jul 23, 2026
c712654
dev: release notes
sunsingerus Jul 23, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
35 changes: 35 additions & 0 deletions .github/workflows/run_tests.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,41 @@ jobs:
timeout-minutes: 300
steps:
- uses: actions/checkout@v4

# The e2e suite (notably test_010025's 100M-row insert + its replica) fills the
# runner's small root partition (~14 GB): with the minikube docker driver the k8s
# node runs as a container under the docker data-root (/var/lib/docker on /), so
# ClickHouse pod ephemeral storage lands there and exhausts it — the runner then
# loses communication mid-run. Move the docker data-root onto the large /mnt
# ephemeral SSD (~65 GB) before minikube starts, and trim unused preinstalled
# toolchains from / for headroom. MUST run before setup-minikube (no docker is
# used before this step, so restarting the daemon here is safe).
- name: Free disk and relocate docker data-root to /mnt
run: |
set -euxo pipefail
# If docker fails to restart on the moved data-root, surface disk + daemon logs
# so the failure is triageable rather than a bare non-zero exit at this early step.
trap 'ec=$?; echo "::error::disk/docker prep failed (exit $ec)"; df -h / /mnt || true; sudo journalctl -u docker --no-pager -n 50 || true' ERR
df -h /
# Reclaim space on / — none of these toolchains are used by this Go+Python+k8s job.
sudo rm -rf /usr/share/dotnet /opt/ghc /usr/local/.ghcup /usr/local/lib/android /opt/hostedtoolcache/CodeQL
# Relocate docker data-root to /mnt so the minikube node container (and thus the
# ClickHouse pod storage inside it) uses the 65 GB SSD, not the 14 GB root.
sudo systemctl stop docker docker.socket
sudo mkdir -p /mnt/docker
# Merge data-root into any existing daemon.json — do NOT clobber runner defaults
# (cgroup driver, registry mirrors) or the daemon may fail to restart.
if [ -s /etc/docker/daemon.json ]; then
sudo jq '. + {"data-root":"/mnt/docker"}' /etc/docker/daemon.json | sudo tee /etc/docker/daemon.json.tmp >/dev/null
sudo mv /etc/docker/daemon.json.tmp /etc/docker/daemon.json
else
echo '{"data-root":"/mnt/docker"}' | sudo tee /etc/docker/daemon.json >/dev/null
fi
sudo systemctl start docker
# Fail loudly if the relocation did not take effect.
test "$(docker info -f '{{.DockerRootDir}}')" = "/mnt/docker"
df -h /mnt /

- name: Cache python
uses: actions/cache@v4
id: cache-python
Expand Down
2 changes: 1 addition & 1 deletion cmd/metrics_exporter/app/metrics_exporter.go
Original file line number Diff line number Diff line change
Expand Up @@ -124,7 +124,7 @@ func Run() {
log.Infof("Starting metrics exporter. Version:%s GitSHA:%s BuiltAt:%s\n", version.Version, version.GitSHA, version.BuiltAt)

// Initialize k8s API clients
kubeClient, _, chopClient, _ := chop.GetClientset(kubeConfigFile, masterURL)
kubeClient, _, chopClient, _ := chop.GetClientset(kubeConfigFile, masterURL, chopConfigFile)

// Create operator instance
chop.New(kubeClient, chopClient, chopConfigFile)
Expand Down
2 changes: 1 addition & 1 deletion cmd/operator/app/thread_chi.go
Original file line number Diff line number Diff line change
Expand Up @@ -56,7 +56,7 @@ func initClickHouse(ctx context.Context) {
}

// Initialize k8s API clients
kubeClient, extClient, chopClient, dynamicClient := chop.GetClientset(kubeConfigFile, masterURL)
kubeClient, extClient, chopClient, dynamicClient := chop.GetClientset(kubeConfigFile, masterURL, chopConfigFile)

// Create operator instance. The chopconf load inside chop.New gates on
// clickhouse.security.kubernetes.allowInsecure BEFORE the first network call,
Expand Down
22 changes: 14 additions & 8 deletions cmd/operator/app/thread_keeper.go
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ import (
metricsserver "sigs.k8s.io/controller-runtime/pkg/metrics/server"
"sigs.k8s.io/controller-runtime/pkg/predicate"

// ctrl "sigs.k8s.io/controller-runtime/pkg/controller"
ctrlController "sigs.k8s.io/controller-runtime/pkg/controller"

api "github.com/altinity/clickhouse-operator/pkg/apis/clickhouse-keeper.altinity.com/v1"
"github.com/altinity/clickhouse-operator/pkg/chop"
Expand Down Expand Up @@ -75,7 +75,10 @@ func initKeeper(ctx context.Context) error {

// Build the apiextensions client for CRD deletion checks during CHK cleanup.
// Uses the same kubeConfigFile/masterURL package vars as the CHI thread.
_, extClient, _, _ := chop.GetClientset(kubeConfigFile, masterURL)
_, extClient, _, _ := chop.GetClientset(kubeConfigFile, masterURL, chopConfigFile)

maxConcurrentReconciles := chop.Config().Reconcile.Runtime.ReconcileCHKsThreadsNumber
logger.Info("init keeper - CHK controller concurrency", "maxConcurrentReconciles", maxConcurrentReconciles)

err = ctrlRuntime.
NewControllerManagedBy(manager).
Expand All @@ -84,13 +87,16 @@ func initKeeper(ctx context.Context) error {
builder.WithPredicates(keeperPredicate()),
).
Owns(&apps.StatefulSet{}).
WithOptions(ctrlController.Options{
MaxConcurrentReconciles: maxConcurrentReconciles,
}).
Complete(
&controller.Controller{
Client: manager.GetClient(),
APIReader: manager.GetAPIReader(),
Scheme: manager.GetScheme(),
ExtClient: extClient,
},
controller.NewController(
manager.GetClient(),
manager.GetAPIReader(),
manager.GetScheme(),
extClient,
),
)
if err != nil {
logger.Error(err, "init keeper - unable to ctrlRuntime.NewControllerManagedBy")
Expand Down
16 changes: 9 additions & 7 deletions config/config-dev.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -152,8 +152,8 @@ clickhouse:
# Possible values for 'scheme' are:
# 1. http - force http to be used to connect to ClickHouse instances
# 2. https - force https to be used to connect to ClickHouse instances
# 3. auto - either http or https is selected based on open ports
scheme: "auto"
# 3. Auto - either http or https is selected based on open ports
scheme: "Auto"
# ClickHouse credentials (username, password and port) to be used by the operator to connect to ClickHouse instances.
# These credentials are used for:
# 1. Metrics requests
Expand Down Expand Up @@ -316,6 +316,8 @@ reconcile:
runtime:
# Max number of concurrent CHI reconciles in progress
reconcileCHIsThreadsNumber: 1
# Max number of concurrent CHK reconciles in progress
reconcileCHKsThreadsNumber: 1

# The operator reconciles shards concurrently in each CHI with the following limitations:
# 1. Number of shards being reconciled (and thus having hosts down) in each CHI concurrently
Expand Down Expand Up @@ -437,12 +439,12 @@ reconcile:
##
################################################
recovery:
# Recovery scopes keyed by CHI state being recovered from.
# Recovery scopes keyed by the CHI .status.status they apply to.
# Each scope contains on<Event>: <action> mappings that apply while the CHI
# is in that state. Multi-scope design anticipates future states beyond Aborted
# is in that status. Multi-scope design anticipates future states beyond Aborted
# (e.g. Failed, Broken).
from:
# Recovery from Status=Aborted
onStatus:
# Recovery while Status=Aborted
aborted:
# Action when a pod belonging to an Aborted CHI transitions to Ready:
# retry (default) — re-enqueue the CHI for reconcile
Expand All @@ -457,7 +459,7 @@ reconcile:
# broken:
# onPodReady: retry

# Future global policy knobs (not yet implemented) — flat peers of `from`,
# Future global policy knobs (not yet implemented) — flat peers of `onStatus`,
# apply across all recovery scopes:
#
# Global kill-switch for auto-recovery:
Expand Down
45 changes: 36 additions & 9 deletions config/config.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -152,8 +152,8 @@ clickhouse:
# Possible values for 'scheme' are:
# 1. http - force http to be used to connect to ClickHouse instances
# 2. https - force https to be used to connect to ClickHouse instances
# 3. auto - either http or https is selected based on open ports
scheme: "auto"
# 3. Auto - either http or https is selected based on open ports
scheme: "Auto"
# ClickHouse credentials (username, password and port) to be used by the operator to connect to ClickHouse instances.
# These credentials are used for:
# 1. Metrics requests
Expand All @@ -162,7 +162,16 @@ clickhouse:
# located in 'clickhouse.configuration.file.path.user' folder
username: ""
password: ""
# Inline PEM CA bundle the operator uses to verify ClickHouse server TLS.
rootCA: ""
# Alternate source for rootCA — a Secret in the operator's namespace.
# Mutually exclusive with the inline rootCA above (inline wins). Empty
# `name` = not used (no-op). When `key` is empty, the operator tries
# "ca.crt" then "tls.crt". Resolved once at config load (an operator
# restart picks up a rotated Secret).
rootCASecretRef:
name: ""
key: ""

# Location of the k8s Secret with username and password to be used by the operator to connect to ClickHouse instances.
# Can be used instead of explicitly specified username and password available in sections:
Expand Down Expand Up @@ -256,7 +265,7 @@ clickhouse:
# Multiple tables can be matched using regexp. Matched tables are merged using merge() table function.
# Default is "^(metrics|custom_metrics)$" which fetches from both system.metrics and system.custom_metrics.
tablesRegexp: "^(metrics|custom_metrics)$"
# List of regexps to match ClickHouse metrics to exclude from export.
# List of regexps to match ClickHouse metrics to exclude from collection/export.
# Regexps match internal metric names before Prometheus normalization and prefixing.
# Default is the per-CPU OS metrics filter shown below; set to [] to disable.
excludeRegexp:
Expand Down Expand Up @@ -326,7 +335,7 @@ security:
tls:
# Strict refuses an insecure kubeconfig at startup
verify: ""
# Reserved — not yet enforced on K8s API transport
# Floors the K8s API client transport TLS version; coerced to 1.3 under FIPS/Enforced
minVersion: ""
ipc:
# Plain (default) | Secure (loopback + X-CHOP-Token)
Expand Down Expand Up @@ -410,6 +419,8 @@ reconcile:
runtime:
# Max number of concurrent CHI reconciles in progress
reconcileCHIsThreadsNumber: 10
# Max number of concurrent CHK reconciles in progress
reconcileCHKsThreadsNumber: 1

# The operator reconciles shards concurrently in each CHI with the following limitations:
# 1. Number of shards being reconciled (and thus having hosts down) in each CHI concurrently
Expand Down Expand Up @@ -531,12 +542,13 @@ reconcile:
##
################################################
recovery:
# Recovery scopes keyed by CHI state being recovered from.
# Recovery scopes keyed by the CHI .status.status they apply to.
# Each scope contains on<Event>: <action> mappings that apply while the CHI
# is in that state. Multi-scope design anticipates future states beyond Aborted
# is in that status. Multi-scope design anticipates future states beyond Aborted
# (e.g. Failed, Broken).
from:
# Recovery from Status=Aborted
onStatus:
# Recovery for a CHI whose .status.status is Aborted (reconcile did not complete)
# when one of its host pods transitions to Ready — auto-resumes the reconcile.
aborted:
# Action when a pod belonging to an Aborted CHI transitions to Ready:
# retry (default) — re-enqueue the CHI for reconcile
Expand All @@ -545,13 +557,28 @@ reconcile:
# Future events (not yet implemented):
# onKeeperReady: retry — retry when a referenced CHK becomes ready
# onOperatorRestart: retry — sweep Aborted CHIs on operator startup
# Recovery for a CHI whose .status.status is Completed (fully reconciled) when one
# of its host pods regresses to Ready=False and stays NotReady (sustained) without
# crashing — auto-heals stuck hosts.
completed:
# Action when a Completed CHI's pod flips Ready=True -> Ready=False and
# stays NotReady for at least onPodNotReadyThreshold:
# none (default) — do nothing
# retry — re-enqueue the CHI so the stuck host is force-restarted
# OFF by default: force-recreating a Completed CHI's pod is destructive — it can
# interrupt a replica's in-progress recovery and means hard downtime for a
# single-replica shard. Opt in with `retry` only where that trade-off is acceptable.
onPodNotReady: none
# Minimum duration a pod must stay Ready=False before recovery fires, once enabled
# (Go duration string; default 5m). Raise it for slow-recovering replicas.
onPodNotReadyThreshold: 5m
# Future scopes (not yet implemented):
# failed:
# onPodReady: retry
# broken:
# onPodReady: retry

# Future global policy knobs (not yet implemented) — flat peers of `from`,
# Future global policy knobs (not yet implemented) — flat peers of `onStatus`,
# apply across all recovery scopes:
#
# Global kill-switch for auto-recovery:
Expand Down
45 changes: 36 additions & 9 deletions deploy/builder/templates-config/config.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -146,8 +146,8 @@ clickhouse:
# Possible values for 'scheme' are:
# 1. http - force http to be used to connect to ClickHouse instances
# 2. https - force https to be used to connect to ClickHouse instances
# 3. auto - either http or https is selected based on open ports
scheme: "auto"
# 3. Auto - either http or https is selected based on open ports
scheme: "Auto"
# ClickHouse credentials (username, password and port) to be used by the operator to connect to ClickHouse instances.
# These credentials are used for:
# 1. Metrics requests
Expand All @@ -156,7 +156,16 @@ clickhouse:
# located in 'clickhouse.configuration.file.path.user' folder
username: "${CH_USERNAME_PLAIN}"
password: "${CH_PASSWORD_PLAIN}"
# Inline PEM CA bundle the operator uses to verify ClickHouse server TLS.
rootCA: ""
# Alternate source for rootCA — a Secret in the operator's namespace.
# Mutually exclusive with the inline rootCA above (inline wins). Empty
# `name` = not used (no-op). When `key` is empty, the operator tries
# "ca.crt" then "tls.crt". Resolved once at config load (an operator
# restart picks up a rotated Secret).
rootCASecretRef:
name: ""
key: ""

# Location of the k8s Secret with username and password to be used by the operator to connect to ClickHouse instances.
# Can be used instead of explicitly specified username and password available in sections:
Expand Down Expand Up @@ -250,7 +259,7 @@ clickhouse:
# Multiple tables can be matched using regexp. Matched tables are merged using merge() table function.
# Default is "^(metrics|custom_metrics)$" which fetches from both system.metrics and system.custom_metrics.
tablesRegexp: "^(metrics|custom_metrics)$"
# List of regexps to match ClickHouse metrics to exclude from export.
# List of regexps to match ClickHouse metrics to exclude from collection/export.
# Regexps match internal metric names before Prometheus normalization and prefixing.
# Default is the per-CPU OS metrics filter shown below; set to [] to disable.
excludeRegexp:
Expand Down Expand Up @@ -320,7 +329,7 @@ security:
tls:
# Strict refuses an insecure kubeconfig at startup
verify: ""
# Reserved — not yet enforced on K8s API transport
# Floors the K8s API client transport TLS version; coerced to 1.3 under FIPS/Enforced
minVersion: ""
ipc:
# Plain (default) | Secure (loopback + X-CHOP-Token)
Expand Down Expand Up @@ -404,6 +413,8 @@ reconcile:
runtime:
# Max number of concurrent CHI reconciles in progress
reconcileCHIsThreadsNumber: 10
# Max number of concurrent CHK reconciles in progress
reconcileCHKsThreadsNumber: 1

# The operator reconciles shards concurrently in each CHI with the following limitations:
# 1. Number of shards being reconciled (and thus having hosts down) in each CHI concurrently
Expand Down Expand Up @@ -525,12 +536,13 @@ reconcile:
##
################################################
recovery:
# Recovery scopes keyed by CHI state being recovered from.
# Recovery scopes keyed by the CHI .status.status they apply to.
# Each scope contains on<Event>: <action> mappings that apply while the CHI
# is in that state. Multi-scope design anticipates future states beyond Aborted
# is in that status. Multi-scope design anticipates future states beyond Aborted
# (e.g. Failed, Broken).
from:
# Recovery from Status=Aborted
onStatus:
# Recovery for a CHI whose .status.status is Aborted (reconcile did not complete)
# when one of its host pods transitions to Ready — auto-resumes the reconcile.
aborted:
# Action when a pod belonging to an Aborted CHI transitions to Ready:
# retry (default) — re-enqueue the CHI for reconcile
Expand All @@ -539,13 +551,28 @@ reconcile:
# Future events (not yet implemented):
# onKeeperReady: retry — retry when a referenced CHK becomes ready
# onOperatorRestart: retry — sweep Aborted CHIs on operator startup
# Recovery for a CHI whose .status.status is Completed (fully reconciled) when one
# of its host pods regresses to Ready=False and stays NotReady (sustained) without
# crashing — auto-heals stuck hosts.
completed:
# Action when a Completed CHI's pod flips Ready=True -> Ready=False and
# stays NotReady for at least onPodNotReadyThreshold:
# none (default) — do nothing
# retry — re-enqueue the CHI so the stuck host is force-restarted
# OFF by default: force-recreating a Completed CHI's pod is destructive — it can
# interrupt a replica's in-progress recovery and means hard downtime for a
# single-replica shard. Opt in with `retry` only where that trade-off is acceptable.
onPodNotReady: none
# Minimum duration a pod must stay Ready=False before recovery fires, once enabled
# (Go duration string; default 5m). Raise it for slow-recovering replicas.
onPodNotReadyThreshold: 5m
# Future scopes (not yet implemented):
# failed:
# onPodReady: retry
# broken:
# onPodReady: retry

# Future global policy knobs (not yet implemented) — flat peers of `from`,
# Future global policy knobs (not yet implemented) — flat peers of `onStatus`,
# apply across all recovery scopes:
#
# Global kill-switch for auto-recovery:
Expand Down
Loading
Loading