← ClaudeAtlas

rook-ceph-best-practiceslisted

Operate, configure and upgrade Rook-managed Ceph on Kubernetes (CephCluster CR; rook-ceph, rook-ceph-cluster and ceph-csi-drivers charts; ceph-csi-operator). Core knowledge: the Rook -> Ceph -> key-rotation upgrade order and its version gates; the CVE-2025-30156 fix (new AES256K CephX key type, daemon key rotation, the six AUTH_INSECURE_* health codes, kernel 7.0 for CSI keys); the Rook v1.20 move of CSI to ceph-csi-operator and the new ceph-csi-drivers chart; disabling the rook mgr module before Tentacle; Helm monitoring RBAC.
air-gapped/skills · ★ 5 · AI & Automation · score 80
Install: claude install-skill air-gapped/skills
# rook-ceph-best-practices Facts verified **2026-09-23** against rook/rook releases v1.16.0–v1.20.7 (unfiltered), the Rook docs at tag v1.20.7, the ceph.io release posts, the rook/rook and ceph/ceph-csi issue trackers, and one live upgrade (Rook v1.19.6 → v1.19.11, Ceph 19.2.3 → 19.2.6 with daemon key rotation). Everything here is version-gated: re-check `references/sources.md` before relying on it for a newer release. ## Version gates (2026-09-23) | Rook | Kubernetes | Ceph supported | Notes | |---|---|---|---| | v1.18.x | 1.29–1.34 | Reef 18.2, Squid 19.2 | Last line that runs Reef. ceph-csi-operator becomes the default CSI config path. Key rotation experimental. | | v1.19.x | 1.30–1.35 | Squid 19.2.0+, Tentacle | **Reef dropped** (min Ceph 19.2.0). AES256K from **v1.19.9**; CVE floor **v1.19.10**. v1.19.11 ships ceph-csi 3.16.3 (AES256K backport). | | v1.20.x | 1.31–1.36 | Squid 19.2.0+, Tentacle 20.2.1+ | **Rook no longer deploys CSI** — ceph-csi-operator + new `ceph-csi-drivers` chart required. AES256K from v1.20.5; CVE floor **v1.20.6**. v1.20.7 ships ceph-csi 3.17.1. | Ceph lines: Reef 18.2.x is EOL (last 18.2.8, 2026-03-20). Squid 19.2.x latest 19.2.6. Tentacle 20.2.x latest 20.2.4. Do not run **20.2.0** (data corruption with CSI read affinity, rook#16839) or **18.2.5/18.2.6** (BlueStore corruption regression, fixed 18.2.7). `x.2.z` is a stable release; a `v19.3.0`-style tag is a development tag, never deploy it. ## Upgrade order — never reorder 1. **Rook operat