Skip to content

Remove native WebDAV blobstore provider - #697

Merged
WeiQuan0605 merged 6 commits into
cloudfoundry:developfrom
sap-contributions:remove-webdav-provider
Oct 8, 2026
Merged

WeiQuan0605 merged 6 commits into
cloudfoundry:developfrom
sap-contributions:remove-webdav-provider

Conversation

@WeiQuan0605

@WeiQuan0605 WeiQuan0605 commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Migration note

Operators with an explicit blobstore_type: webdav in their CC config must migrate before upgrading:

  1. Change blobstore_type: webdav to blobstore_type: storage-cli with provider: dav
  2. Remove the blobstore job from their deployment

After this change, any deployment still using blobstore_type: webdav will fail at CC boot with:
blobstore_type 'webdav' is no longer supported; use 'storage-cli' with provider 'dav' (see cloud_controller_ng#5480).

Operators using cf-deployment are unaffected — cf-deployment already uses the storage-cli path.

  • I have viewed signed and have submitted the Contributor License Agreement

  • I have made this pull request to the develop branch

  • I have run CF Acceptance Tests on bosh lite

@WeiQuan0605
WeiQuan0605 force-pushed the remove-webdav-provider branch 2 times, most recently from 6bd1b6b to 50d1b58 Compare September 25, 2026 12:13
@kathap

kathap commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Maybe we need a spec verifying that webdav_config no longer renders in the CC templates?

@kathap

kathap commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

In config/blobs.yml. nginx/nginx-dav-ext-module-3.0.0.tar.gz and nginx/ngx_http_hmac_secure_link_module-0.3.tar.gz are still listed. Can they be removed?

@kathap

kathap commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Should we add somewhere a note for operators? A migration note?
Any deployment with an explicit blobstore_type: webdav will:
- at the manifest level: blobstore_type: webdav still renders fine, but
- at CC boot: hit #5480's new raise "Unknown blobstore type: "webdav"" and fail to start.

@kathap

kathap commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Are the jobs/cloud_controller_ng/templates/blobstore_waiter.sh.erb files and calls of wait_for_blobstore still needed?

Comment thread jobs/cloud_controller_worker/spec Outdated

@stephanme stephanme left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The blobstore job is still needed by cf-deployment for the singleton-blobstore (webdav, batteries included). But it is now accessed via storage-cli and not anymore by the webdav blobstore provider.

See https://github.com/cloudfoundry/cf-deployment/blob/v60.8.0/cf-deployment.yml#L774-L789

@kathap

kathap commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

jobs/blobstore/monit still references the removed url_signer process

@kathap

kathap commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

The PR deletes spec/blobstore/backup_spec.rb and restore_spec.rb, but backup.erb / restore.erb (bin/bbr/backup, bin/bbr/restore) are still shipped and still mapped in jobs/blobstore/spec. Should they stay in?

The native WebDAV blobstore (nginx + blobstore_url_signer) is no longer
supported. DAV is still available via blobstore_type: storage-cli with
provider: dav.

Removed:
- jobs/blobstore (nginx_webdav + blobstore_url_signer processes)
- packages/nginx_webdav and packages/blobstore_url_signer
- src/github.com/cloudfoundry/blobstore_url_signer submodule
- webdav_config sections from all job templates (cc_ng, worker, clock,
  cc_deployment_updater, blobstore_benchmark)
- webdav ca_cert.pem templates from cc_ng, cc_deployment_updater, and
  shared_job_templates
- webdav_config properties from cc_ng, worker, clock specs
- blobstore_waiter webdav health check (no-op for storage-cli providers)
- webdav test fixtures in cc_ng and cc_deployment_updater specs
…e spec

- Remove blobstore_waiter.sh.erb and all source/wait_for_blobstore calls
- Remove nginx-dav-ext-module and ngx_http_hmac_secure_link_module from blobs.yml
- Add spec verifying webdav_config no longer renders in CC templates
- Restore jobs/blobstore (nginx DAV server): still needed by cf-deployment
  as the singleton-blobstore backend; only CC's blobstore_type: webdav
  provider is removed, not the server itself
- Remove url_signer process from bpm.yml.erb: package no longer exists,
  storage-cli generates signed URLs locally and never calls /sign
- Remove upstream blob_url_signer and location /sign from blobstore.conf.erb:
  unix socket never exists without the process; keep /signed/ and
  secure_link_hmac directives which nginx still needs
- Remove blobstore_url_signer from jobs/blobstore/spec packages list
- Restore packages/nginx_webdav: still needed by jobs/blobstore
- Restore nginx-dav-ext-module and ngx_http_hmac_secure_link_module blobs
  in config/blobs.yml: still used by nginx_webdav package
- Remove broken *_ca_cert.pem.erb symlinks from cloud_controller_worker
  templates and their entries in cloud_controller_worker/spec
- Remove url_signer process from jobs/blobstore/monit: process no longer
  exists in bpm.yml.erb so monit would fail to start it
- Restore spec/blobstore/backup_spec.rb and restore_spec.rb: backup.erb
  and restore.erb are still shipped in the blobstore job and still need tests
@WeiQuan0605
WeiQuan0605 force-pushed the remove-webdav-provider branch from 0f3b721 to 5fc209b Compare October 6, 2026 07:19
kathap
kathap previously approved these changes Oct 6, 2026
Comment thread jobs/cloud_controller_ng/templates/bin/cloud_controller_ng.erb
Comment thread jobs/cloud_controller_ng/templates/bin/local_worker.erb
Comment thread shared_job_templates/blobstore_waiter.sh.erb
@WeiQuan0605
WeiQuan0605 force-pushed the remove-webdav-provider branch 2 times, most recently from 0339247 to 34df3f8 Compare October 7, 2026 12:16
@WeiQuan0605
WeiQuan0605 force-pushed the remove-webdav-provider branch from 34df3f8 to f0201c2 Compare October 7, 2026 12:19
@WeiQuan0605
WeiQuan0605 requested a review from stephanme October 7, 2026 12:21
@WeiQuan0605
WeiQuan0605 merged commit 56e894c into cloudfoundry:develop Oct 8, 2026
2 checks passed
@WeiQuan0605
WeiQuan0605 deleted the remove-webdav-provider branch October 8, 2026 13:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants