You set noout to upgrade Ceph and switched off re-replication
The Ceph upgrade procedure on Proxmox recommends, as its fourth step, that you run "ceph osd set noout": "optional, but recommended", says the wiki. Ceph's own OSD troubleshooting page says this is "more a thought exercise" than a suggestion that anyone "in the post-Luminous world" should run it. Both sentences are published today and both are defensible. What that flag switches off is not rebalancing: it is a "down" OSD ever reaching "out", which is precisely the step that makes CRUSH recompute and recreate the missing copy. And the flag does not tell the disk you rebooted apart from the disk that genuinely died. Inside: why mon_osd_down_out_subtree_limit already brakes the scenario that actually frightens you, the chain almost nobody spells out (degraded PGs are not flagged as clean, and what is not clean is not scrubbed, so checksum verification stops on exactly the data that just lost a copy), the arithmetic of the two warnings arriving at 10.5 and 12.25 days to a dashboard that has been amber since minute one, the table of what each flag really switches off, and the four commands that do the same job on one disk or one host without touching the rest of the cluster.