Re: [ceph-users] How to (permanently) disable msgr v1 on Ceph?
On 13-03-2025 16:08, Frédéric Nass wrote:
Hi Stefan,
If ceph-mon respected ms_bind_msgr1 = false, then one could add --ms-bind-msgr1=false as extra_entrypoint_args in the mon service_type [1], so as to have any ceph-mon daemons deployed or redeployed using msgr v2 exclusively. Unfortunately, ceph-mon doesn't respect this setting as suspected by Ilya here [2] and confirmed on a test cluster on my side. I think we can make this a tracker.
Thanks for double checking, I've created [1].
As for your other question as to when v1 will be disabled by default on new Ceph clusters, I have no idea at all.
I'll leave it to the devs to discuss this one. Gr. Stefan [1]: https://tracker.ceph.com/issues/70457
On 13-03-2025 16:08, Frédéric Nass wrote:
If ceph-mon respected ms_bind_msgr1 = false, then one could add --ms-bind-msgr1=false as extra_entrypoint_args in the mon service_type [1], so as to have any ceph-mon daemons deployed or redeployed using msgr v2 exclusively. Unfortunately, ceph-mon doesn't respect this setting as suspected by Ilya here [2] and confirmed on a test cluster on my side. I think we can make this a tracker.
Thanks for double checking, I've created [1].
As for your other question as to when v1 will be disabled by default on new Ceph clusters, I have no idea at all.
I'll leave it to the devs to discuss this one.
It would be nice if the defaults for newly created clusters also came with the global reclaim id thing disabled, so we didn't have to manually enable msgrv2 (and disable v1 possibly as per this thread) and also disable the reclaim thing every time. If you upgrade an old cluster into Reef/Squid it might also hold old clients, but newly built ones probably won't see a lot of old clients that must have the reclaim thing enabled, right?
On 14-03-2025 09:53, Janne Johansson wrote:
On 13-03-2025 16:08, Frédéric Nass wrote:
If ceph-mon respected ms_bind_msgr1 = false, then one could add --ms-bind-msgr1=false as extra_entrypoint_args in the mon service_type [1], so as to have any ceph-mon daemons deployed or redeployed using msgr v2 exclusively. Unfortunately, ceph-mon doesn't respect this setting as suspected by Ilya here [2] and confirmed on a test cluster on my side. I think we can make this a tracker.
Thanks for double checking, I've created [1].
As for your other question as to when v1 will be disabled by default on new Ceph clusters, I have no idea at all.
I'll leave it to the devs to discuss this one.
It would be nice if the defaults for newly created clusters also came with the global reclaim id thing disabled, so we didn't have to manually enable msgrv2 (and disable v1 possibly as per this thread) and also disable the reclaim thing every time. If you upgrade an old cluster into Reef/Squid it might also hold old clients, but newly built ones probably won't see a lot of old clients that must have the reclaim thing enabled, right?
For the Reef clusters that I have created the "auth_allow_insecure_global_id_reclaim" is false. So this already seems to be the default (as it should be, shipping known weaknesses is bad practice to say the least). Gr. Stefan
I'll leave it to the devs to discuss this one.
It would be nice if the defaults for newly created clusters also came with the global reclaim id thing disabled, so we didn't have to manually enable msgrv2 (and disable v1 possibly as per this thread) and also disable the reclaim thing every time. If you upgrade an old cluster into Reef/Squid it might also hold old clients, but newly built ones probably won't see a lot of old clients that must have the reclaim thing enabled, right?
For the Reef clusters that I have created the "auth_allow_insecure_global_id_reclaim" is false. So this already seems to be the default (as it should be, shipping known weaknesses is bad practice to say the least).
I literally made an 18.2.4 cluster yesterday and had to enable msgrv2 and disable global id reclaim. Installed from .debs on ubuntu hosts. https://github.com/ceph/ceph/blob/d4ce7b60b2f2472c86f8f41f89907aedec8b1c54/s... seems to list it as true still. -- May the most significant bit of your life be positive.
On 14-03-2025 10:44, Janne Johansson wrote:
I'll leave it to the devs to discuss this one.
It would be nice if the defaults for newly created clusters also came with the global reclaim id thing disabled, so we didn't have to manually enable msgrv2 (and disable v1 possibly as per this thread) and also disable the reclaim thing every time. If you upgrade an old cluster into Reef/Squid it might also hold old clients, but newly built ones probably won't see a lot of old clients that must have the reclaim thing enabled, right?
For the Reef clusters that I have created the "auth_allow_insecure_global_id_reclaim" is false. So this already seems to be the default (as it should be, shipping known weaknesses is bad practice to say the least).
I literally made an 18.2.4 cluster yesterday and had to enable msgrv2 and disable global id reclaim. Installed from .debs on ubuntu hosts.
https://github.com/ceph/ceph/blob/d4ce7b60b2f2472c86f8f41f89907aedec8b1c54/s... seems to list it as true still.
Ah, interesting. I have it installed via Cephadm ... so apparently it's fixed there, but not in packages ... :/. For the record, v1 and v2 are enabled by default (as the docs state [1]) ... on a Cephadm based cluster that is ... Gr. Stefan [1]: https://docs.ceph.com/en/reef/rados/configuration/msgr2/#bind-configuration-...
participants (2)
-
Janne Johansson
-
Stefan Kooman