Managing Storage Backends Using kubectl
CSI storage backends are implemented based on Kubernetes custom resources (CRDs). In addition to using the oceanctl tool, you can also run kubectl commands to manage storage backend resources. Storage backends involve the following two types of CRD resources:
- StorageBackendClaim (sbc for short): namespace-level resource, which indicates the user’s claim to a storage backend. You can create this resource to trigger the CSI controller to automatically connect the storage backend.
- StorageBackendContent (sbct for short): cluster-level resource, which is automatically created by the CSI controller after a StorageBackendClaim is successfully bound. It indicates the actual storage backend instance in the cluster. You should not directly create or modify this resource.

- Before using kubectl to manage storage backends, ensure that the CSI plug-in has been installed and the CRD has been correctly registered with the cluster.
- StorageBackendContent is automatically managed by the controller. Do not directly create or manually modify it. Otherwise, the storage backend may be abnormal.
- Do not delete a storage backend when a volume management operation is being performed on it.
3 - Updating Storage Backend Authentication Information
To prevent the storage backend from becoming temporarily unavailable when the existing secret is modified directly, you are advised to update the authentication information by creating a new secret, replacing the reference to the existing secret, and then deleting the old secret.
Procedure
Prepare a new secret configuration file, for example, backend-secret-new.yaml.
apiVersion: v1
kind: Secret
metadata:
name: backend-demo-new
namespace: huawei-csi
type: Opaque
stringData:
user: "admin"
password: "******"
authenticationMode: "0"
Create a secret.
kubectl apply -f backend-secret-new.yaml
Update StorageBackendClaim and update secretMeta to reference the new secret. CSI automatically synchronizes the new secret to StorageBackendContent and uses the new authentication information to log in to the storage device again.
kubectl patch sbc backend-demo -n huawei-csi --type merge -p '{"spec":{"secretMeta":"huawei-csi/backend-demo-new"}}'
Check the storage backend creation result.
kubectl get StorageBackendContent
The following is an example of the command output. If the online status of StorageBackendContent is true, the update is successful.
NAME CLAIM SN VENDORNAME PROVIDERVERSION ONLINE AGE
content-xxxxxxx huawei-csi/backend-demo xxxxxxxxxxxxxx Huawei 4.12.0 true 53d
Delete the old secret.
kubectl delete secret backend-demo -n huawei-csi
4 - Managing Storage Backend Certificates
CSI allows you to add a storage certificate to use the TLS/SSL protocol to encrypt data transmission channels, improving the security of communication with storage devices.
Adding a Storage Certificate
Create a certificate. Take OceanStor Dorado as an example. For details about how to create a certificate,
click here
.
Run the following command to create a secret from the certificate file:
kubectl create secret generic cert-1 --from-file=tls.crt=/path/to/cert.crt -n huawei-csi
Run the following command to update the StorageBackendClaim, enable the certificate, and specify the certificate secret. The format of the certSecret field is <namespace>/<secret-name>.
kubectl patch sbc backend-demo -n huawei-csi --type merge -p '{"spec":{"useCert":true,"certSecret":"huawei-csi/cert-1"}}'
Check the storage backend creation result.
kubectl get StorageBackendContent
The following is an example of the command output. If the online status of StorageBackendContent is true, the update is successful.
NAME CLAIM SN VENDORNAME PROVIDERVERSION ONLINE AGE
content-xxxxxxx huawei-csi/backend-demo xxxxxxxxxxxxxx Huawei 4.12.0 true 53d
Deleting a Storage Certificate
Delete the certificate configuration of StorageBackendClaim.
kubectl patch sbc backend-demo -n huawei-csi --type merge -p '{"spec":{"useCert":false,"certSecret":""}}'
Delete the certificate secret.
kubectl delete secret cert-1 -n huawei-csi
5 - Deleting a Storage Backend

Do not delete a storage backend when a volume management operation is being performed on it.
Delete the StorageBackendClaim.
kubectl delete sbc backend-demo -n huawei-csi
After the StorageBackendClaim is deleted, the controller automatically deletes the associated StorageBackendContent.
Check whether StorageBackendContent is deleted.
If the associated StorageBackendContent is no longer listed, the deletion is successful.
Run the following commands to manually delete the associated ConfigMap and secret:
kubectl delete configmap backend-demo -n huawei-csi
kubectl delete secret backend-demo -n huawei-csi