- Getting Started Configuration
- OpenID & LDAP
- Custom TLS Certificate
- Custom OS Images
- Extra Files
- Network Interface Bonding
- Multipath disks
- Accessing your Cluster
- CephFS
- MDS Notifications
- CephFS Guard
- RBD
- S3
- S3 Multisite
- NVMe over Fabrics
- SMB
- NFS
- Ceph Keys
- Updating croit
- Replacing OSDs
- Replacing NIC
- PG numbers
- Updating Ceph
- Migrating or restoring croit container
- Backups
Updating Ceph
Keeping Ceph up-to-date is incredibly simple with croit. There are two different kinds of update.
Minor Version Updates
For minor version updates, the way to update is simply to select a new boot image and then rebooting your nodes.
- Navigate to
Servers -> Images. - Select and download the latest stable image. You will only be shown compatible images for your current Ceph version.
- Once the image has downloaded, click
Default. - Now select all servers and click
Actions -> Rolling Reboot.
Major Version Updates
For major version updates, Ceph requires all services to be restarted in a specific order along with some other manual steps. croit takes care of all of this for you.
- Navigate to
Maintenance -> Ceph Updates. - If there is an upgrade available it will let you know.
- Eg. if you are on Pacific click
Migrate to Quincy. - Once the upgrade has started you can follow along, by clicking on the notification in the top right corner.
S3 requests after the Ceph 19.2.6 / 20.2.4 update
Those two point releases fix CVE-2026-54330: from them on, an object gateway rejects an S3
request whose SigV4 signature does not cover the host and x-amz- headers it carries.
For most clusters nothing has to be done. Ceph's own client signs correctly from these releases on, so a cluster whose S3 clients are current keeps working with the check enforced, which is where you want it.
A multisite setup is the exception, and only while it is part-way through. A site that has
not been updated yet still signs the metadata writes it forwards to its peers the old way, so an
updated peer rejects them. croit therefore sets the Ceph option rgw sigv4 insecure on a cluster
that is already part of a multisite setup when it moves onto one of these releases, whether
through a major version update or an image change, and the task transcript says so when it
happens. A single-site cluster is never set to it. If croit cannot write the option, a major
version update stops before restarting any gateway and tells you why, rather than rolling on into
rejected metadata writes.
While the option is on, the task advisor shows S3 signature check is relaxed, because the
cluster is accepting those signatures from any client, not only from its peer site. Once every
site runs Tentacle 20.2.4 or later, Squid 19.2.6 or later, or a newer Ceph release, press the
warning's button. It removes the option so the cluster uses Ceph's default, and the warning
disappears. croit will not set it again: only a cluster whose gateways are moving onto the fix
from an older Ceph gets it, so a later image change or a node you add leaves your decision alone.
You can also find it as rgw sigv4 insecure under Ceph -> Configuration.
