rook-ceph-best-practiceslisted
Install: claude install-skill air-gapped/skills
# rook-ceph-best-practices
Facts verified **2026-09-23** against rook/rook releases v1.16.0–v1.20.7
(unfiltered), the Rook docs at tag v1.20.7, the ceph.io release posts,
the rook/rook and ceph/ceph-csi issue trackers, and one live upgrade
(Rook v1.19.6 → v1.19.11, Ceph 19.2.3 → 19.2.6 with daemon key rotation).
Everything here is version-gated: re-check `references/sources.md` before
relying on it for a newer release.
## Version gates (2026-09-23)
| Rook | Kubernetes | Ceph supported | Notes |
|---|---|---|---|
| v1.18.x | 1.29–1.34 | Reef 18.2, Squid 19.2 | Last line that runs Reef. ceph-csi-operator becomes the default CSI config path. Key rotation experimental. |
| v1.19.x | 1.30–1.35 | Squid 19.2.0+, Tentacle | **Reef dropped** (min Ceph 19.2.0). AES256K from **v1.19.9**; CVE floor **v1.19.10**. v1.19.11 ships ceph-csi 3.16.3 (AES256K backport). |
| v1.20.x | 1.31–1.36 | Squid 19.2.0+, Tentacle 20.2.1+ | **Rook no longer deploys CSI** — ceph-csi-operator + new `ceph-csi-drivers` chart required. AES256K from v1.20.5; CVE floor **v1.20.6**. v1.20.7 ships ceph-csi 3.17.1. |
Ceph lines: Reef 18.2.x is EOL (last 18.2.8, 2026-03-20). Squid 19.2.x
latest 19.2.6. Tentacle 20.2.x latest 20.2.4. Do not run **20.2.0** (data
corruption with CSI read affinity, rook#16839) or **18.2.5/18.2.6**
(BlueStore corruption regression, fixed 18.2.7). `x.2.z` is a stable
release; a `v19.3.0`-style tag is a development tag, never deploy it.
## Upgrade order — never reorder
1. **Rook operat