A Container Storage Interface (CSI) driver for cloudscale.ch volumes. The CSI plugin allows you to use cloudscale.ch volumes with your preferred Container Orchestrator.
The cloudscale.ch CSI plugin is mostly tested on kubernetes. Theoretically, it should also work with other container orchestrators.
This fork is ahead of cloudscale.ch's CSI driver and adds the following features:
bulk volumes (PR pending)The cloudscale.ch CSI plugin follows semantic versioning.
The current version of linkyard's fork is: 1.0.0.
This plugin supports the following volume parameters (in case of kubernetes: parameters on the
StorageClass object):
csi.cloudscale.ch/volume-type: ssd or bulk; defaults to ssd if not setFor LUKS encryption:
csi.cloudscale.ch/luks-encrypted: set to the string "true" if the volume should be encrypted
with LUKScsi.cloudscale.ch/luks-cipher: cipher to use; must be supported by the kernel and luks, we
suggest aes-xts-plain64csi.cloudscale.ch/luks-key-size: key-size to use; we suggest 512 for aes-xts-plain64For LUKS encrypted volumes, a secret that contains the LUKS key needs to be referenced through
the csiNodeStageSecretName and csiNodeStageSecretNamespace parameter. See the included
StorageClass definitions for examples.
Requirements:
--allow-privileged flag must be set to true for both the API server and the kubeletTo install the CSI plugin on kubernetes, the following steps are necessary:
The default deployment bundled in the deploy/kubernetes/releases folder includes three storage
classes:
cloudscale-volume-ssd - the default storage class; uses an ssd volume, no luks encryptioncloudscale-volume-bulk - uses a bulk volume, no luks encryptioncloudscale-volume-ssd-luks - uses an ssd volume that will be encrypyted with luks; a luks-key
must be suppliedcloudscale-volume-bulk-luks - uses a bulk volume that will be encrypyted with luks; a luks-key
must be suppliedTo use one of the shipped luks storage classes, you need to create a secret named
${pvc.name}-luks-key in the same namespace as the persistent volume claim. The secret must
contain an element called luksKey that will be used as the luks encryption key.
Example: If you create a persistent volume claim with the name my-pvc, you need to create a
secret my-pvc-luks-key.
Replace the placeholder string starting with a05... with your own secret and
save it as secret.yml:
apiVersion: v1
kind: Secret
metadata:
name: cloudscale
namespace: kube-system
stringData:
access-token: "a05dd2f26b9b9ac2asdas__REPLACE_ME____123cb5d1ec17513e06da"
and create the secret using kubectl:
$ kubectl create -f ./secret.yml
secret "cloudscale" created
Before you continue, be sure to checkout to a
tagged release.
Always use the latest stable version
For example, to use the latest stable version (1.0.0) you can execute the following command:
$ kubectl apply -f https://raw.githubusercontent.com/linkyard/csi-cloudscale/master/deploy/kubernetes/releases/csi-cloudscale-linkyard-v1.0.0.yaml
This file will be always updated to point to the latest stable release.
There are also dev images available:
$ kubectl apply -f https://raw.githubusercontent.com/linkyard/csi-cloudscale/master/deploy/kubernetes/releases/csi-cloudscale-linkyard-dev.yaml
The storage classes cloudscale-volume-ssd, cloudscale-volume-bulk, cloudscale-volume-ssd-luks
and cloudscale-volume-bulk-luks will be created. The storage-class cloudscale-volume-ssd will
be the "default" for dynamic provisioning.
Create a PersistentVolumeClaim. This makes sure a volume is created and provisioned on your behalf:
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: csi-pvc
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 5Gi
storageClassName: cloudscale-volume-ssd
Check that a new PersistentVolume is created based on your claim:
$ kubectl get pv
NAME CAPACITY ACCESS MODES RECLAIM POLICY STATUS CLAIM STORAGECLASS REASON AGE
pvc-0879b207-9558-11e8-b6b4-5218f75c62b9 5Gi RWO Delete Bound default/csi-pvc cloudscale-volume-ssd 3m
The above output means that the CSI plugin successfully created (provisioned) a new Volume on behalf of you. You should be able to see this newly created volumes in the server detail view in the cloudscale.ch UI.
The volume is not attached to any node yet. It'll only attached to a node if a workload (i.e: pod) is scheduled to a specific node. Now let us create a Pod that refers to the above volume. When the Pod is created, the volume will be attached, formatted and mounted to the specified Container:
kind: Pod
apiVersion: v1
metadata:
name: my-csi-app
spec:
containers:
- name: my-frontend
image: busybox
volumeMounts:
- mountPath: "/data"
name: my-cloudscale-volume
command: [ "sleep", "1000000" ]
volumes:
- name: my-cloudscale-volume
persistentVolumeClaim:
claimName: csi-pvc
Check if the pod is running successfully:
$ kubectl describe pods/my-csi-app
Write inside the app container:
$ kubectl exec -ti my-csi-app /bin/sh
/ # touch /data/hello-world
/ # exit
$ kubectl exec -ti my-csi-app /bin/sh
/ # ls /data
hello-world
Requirements:
v1.10.xAfter making your changes, run the unit tests:
$ make test
To run the integration tests run the following:
$ KUBECONFIG=$(pwd)/kubeconfig make test-integration
At cloudscale.ch we value and love our community! If you have any issues or would like to contribute, feel free to open an issue/PR
Content type
Image
Digest
Size
9.1 MB
Last updated
over 7 years ago
docker pull linkyard/cloudscale-csi-plugin