Updating Ceph

Keeping Ceph up-to-date is incredibly simple with croit. There are two different kinds of update.

Minor Version Updates

For minor version updates, the way to update is simply to select a new boot image and then rebooting your nodes.

  1. Navigate to Servers -> Images.
  2. Select and download the latest stable image. You will only be shown compatible images for your current Ceph version.
  3. Once the image has downloaded, click Default.
  4. Now select all servers and click Actions -> Rolling Reboot.

Major Version Updates

For major version updates, Ceph requires all services to be restarted in a specific order along with some other manual steps. croit takes care of all of this for you.

  1. Navigate to Maintenance -> Ceph Updates.
  2. If there is an upgrade available it will let you know.
  3. Eg. if you are on Pacific click Migrate to Quincy.
  4. Once the upgrade has started you can follow along, by clicking on the notification in the top right corner.

S3 requests after the Ceph 19.2.6 / 20.2.4 update

Those two point releases fix CVE-2026-54330: from them on, an object gateway rejects an S3 request whose SigV4 signature does not cover the host and x-amz- headers it carries.

For most clusters nothing has to be done. Ceph's own client signs correctly from these releases on, so a cluster whose S3 clients are current keeps working with the check enforced, which is where you want it.

A multisite setup is the exception, and only while it is part-way through. A site that has not been updated yet still signs the metadata writes it forwards to its peers the old way, so an updated peer rejects them. croit therefore sets the Ceph option rgw sigv4 insecure on a cluster that is already part of a multisite setup when it moves onto one of these releases, whether through a major version update or an image change, and the task transcript says so when it happens. A single-site cluster is never set to it. If croit cannot write the option, a major version update stops before restarting any gateway and tells you why, rather than rolling on into rejected metadata writes.

While the option is on, the task advisor shows S3 signature check is relaxed, because the cluster is accepting those signatures from any client, not only from its peer site. Once every site runs Tentacle 20.2.4 or later, Squid 19.2.6 or later, or a newer Ceph release, press the warning's button. It removes the option so the cluster uses Ceph's default, and the warning disappears. croit will not set it again: only a cluster whose gateways are moving onto the fix from an older Ceph gets it, so a later image change or a node you add leaves your decision alone. You can also find it as rgw sigv4 insecure under Ceph -> Configuration.