This is the multi-page printable view of this section. Click here to print.

Return to the regular view of this page.

Managing Storage Backends Using kubectl

CSI storage backends are implemented based on Kubernetes custom resources (CRDs). In addition to using the oceanctl tool, you can also run kubectl commands to manage storage backend resources. Storage backends involve the following two types of CRD resources:

  • StorageBackendClaim (sbc for short): namespace-level resource, which indicates the user’s claim to a storage backend. You can create this resource to trigger the CSI controller to automatically connect the storage backend.
  • StorageBackendContent (sbct for short): cluster-level resource, which is automatically created by the CSI controller after a StorageBackendClaim is successfully bound. It indicates the actual storage backend instance in the cluster. You should not directly create or modify this resource.

  • Before using kubectl to manage storage backends, ensure that the CSI plug-in has been installed and the CRD has been correctly registered with the cluster.
  • StorageBackendContent is automatically managed by the controller. Do not directly create or manually modify it. Otherwise, the storage backend may be abnormal.
  • Do not delete a storage backend when a volume management operation is being performed on it.

1 - Creating a Storage Backend

Prerequisites

  • You have obtained the management IP address, username, and password of the storage device.
  • You have obtained configuration information such as the storage pool name and storage protocol. For details about the configuration items, see section Configuring the Storage Backend .

Procedure

  1. Prepare the secret configuration file, for example, backend-secret.yaml. For details about the fields in the secret configuration file, see Table 1 .

    apiVersion: v1
    kind: Secret
    metadata:
      name: backend-demo
      namespace: huawei-csi
    type: Opaque
    stringData:
      user: "admin"
      password: "******"
      authenticationMode: "0"
    

    Create a secret.

    kubectl apply -f backend-secret.yaml
    

    Table 1 Secret field description

    Parameter

    Description

    Mandatory

    Default Value

    Remarks

    user

    Username for logging in to the storage.

    Yes

    -

      

    password

    Password for logging in to the storage.

    Yes

    -

      

    authenticationMode

    Authentication mode for logging in to the storage. The value can be:

    • 0: local authentication
    • 1: LDAP authentication

    No

    0

    Only OceanStor Dorado, OceanStor V5, OceanStor V6, OceanStor A600, and OceanStor A800 support LDAP authentication.

    maxClientThreads

    Maximum number of concurrent connections to a storage backend.

    No

    30

    The value ranges from 1 to 30.

  2. Create a ConfigMap resource for the storage backend to store the management configuration of the storage device.

    Prepare the ConfigMap configuration file. The following describes how to create an OceanStor SAN storage backend of the iSCSI protocol type. The value of the csi.json key is the storage backend configuration in JSON format. For details about the configuration items, see Configuring the Storage Backend .

    apiVersion: v1
    kind: ConfigMap
    metadata:
      name: backend-demo
      namespace: huawei-csi
    data:
      csi.json: |-
        {
          "backends": {
            "storage": "oceanstor-san",
            "name": "backend-demo",
            "namespace": "huawei-csi",
            "urls": ["https://192.168.129.157:8088"],
            "pools": ["StoragePool001"],
            "provisioner": "csi.huawei.com",
            "parameters": {
              "protocol": "iscsi",
              "portals": ["10.10.30.20", "10.10.30.21"]
            },
            "maxClientThreads": "30"
          }
        }    
    

    Create a ConfigMap.

    kubectl apply -f backend-configmap.yaml
    
  3. Create a StorageBackendClaim resource to trigger the CSI controller to access the storage backend. For details about the fields in StorageBackendClaim, see Table 2 .

    Prepare the StorageBackendClaim configuration file, for example, backend-claim.yaml.

    apiVersion: xuanwu.huawei.io/v1
    kind: StorageBackendClaim
    metadata:
      name: backend-demo
      namespace: huawei-csi
    spec:
      provider: csi.huawei.com
      configmapMeta: huawei-csi/backend-demo
      secretMeta: huawei-csi/backend-demo
      maxClientThreads: "30"
    

    Create a StorageBackendClaim.

    kubectl apply -f backend-claim.yaml
    

    Table 2 StorageBackendClaim spec field description

    Parameter

    Description

    Mandatory

    Default Value

    Remarks

    provider

    Provider name, which is used to match the CSI plug-in.

    Yes

    -

    The value is fixed to csi.huawei.com.

    configmapMeta

    Reference to the ConfigMap of the storage configuration information. The format is <namespace>/<name>.

    Yes

    -

    The value must be the same as the name of the ConfigMap created in step 2.

    secretMeta

    Reference to the secret of the storage authentication information. The format is <namespace>/<name>.

    Yes

    -

    The value must be the same as the name of the secret created in step 1.

    maxClientThreads

    Maximum number of concurrent connections to a storage backend.

    No

    30

    The value ranges from 1 to 30.

  4. Check the storage backend creation result.

    kubectl get sbct
    

    The following is an example of the command output. If the online status of StorageBackendContent is true, the creation is successful.

    NAME              CLAIM                       SN               VENDORNAME   PROVIDERVERSION   ONLINE   AGE
    content-xxxxxxx   huawei-csi/backend-demo     xxxxxxxxxxxxxx   Huawei       4.12.0            true     53d
    

2 - Querying a Storage Backend

Querying StorageBackendClaim

  1. Run the following command to query all storage backend claims in the default namespace:

    kubectl get sbc -n huawei-csi
    

    The following is an example of the command output:

    NAME             STORAGEBACKENDCONTENTNAME      STATUS   AGE
    backend-demo     content-xxxxxxxxxxxx           Bound    53d
    
  2. Run the following command to view storage backend claims in YAML format:

    kubectl get sbc backend-demo -n huawei-csi -o yaml
    

Querying StorageBackendContent

  1. Run the following command to query all storage backend instances:

    kubectl get sbct
    

    The following is an example of the command output:

    NAME              CLAIM                       SN               VENDORNAME   PROVIDERVERSION   ONLINE   AGE
    content-xxxxxxx   huawei-csi/backend-demo     xxxxxxxxxxxxxx   Huawei       4.12.0            true     53d
    
  2. Run the following command to view storage backend instances in YAML format:

    kubectl get sbct content-xxxxxxx -o yaml
    

3 - Updating Storage Backend Authentication Information

To prevent the storage backend from becoming temporarily unavailable when the existing secret is modified directly, you are advised to update the authentication information by creating a new secret, replacing the reference to the existing secret, and then deleting the old secret.

Procedure

  1. Prepare a new secret configuration file, for example, backend-secret-new.yaml.

    apiVersion: v1
    kind: Secret
    metadata:
      name: backend-demo-new
      namespace: huawei-csi
    type: Opaque
    stringData:
      user: "admin"
      password: "******"
      authenticationMode: "0"
    
  2. Create a secret.

    kubectl apply -f backend-secret-new.yaml
    
  3. Update StorageBackendClaim and update secretMeta to reference the new secret. CSI automatically synchronizes the new secret to StorageBackendContent and uses the new authentication information to log in to the storage device again.

    kubectl patch sbc backend-demo -n huawei-csi --type merge -p '{"spec":{"secretMeta":"huawei-csi/backend-demo-new"}}'
    
  4. Check the storage backend creation result.

    kubectl get StorageBackendContent
    

    The following is an example of the command output. If the online status of StorageBackendContent is true, the update is successful.

    NAME              CLAIM                       SN               VENDORNAME   PROVIDERVERSION   ONLINE   AGE
    content-xxxxxxx   huawei-csi/backend-demo     xxxxxxxxxxxxxx   Huawei       4.12.0            true     53d
    
  5. Delete the old secret.

    kubectl delete secret backend-demo -n huawei-csi
    

4 - Managing Storage Backend Certificates

CSI allows you to add a storage certificate to use the TLS/SSL protocol to encrypt data transmission channels, improving the security of communication with storage devices.

Adding a Storage Certificate

  1. Create a certificate. Take OceanStor Dorado as an example. For details about how to create a certificate, click here .

  2. Run the following command to create a secret from the certificate file:

    kubectl create secret generic cert-1 --from-file=tls.crt=/path/to/cert.crt -n huawei-csi
    
  3. Run the following command to update the StorageBackendClaim, enable the certificate, and specify the certificate secret. The format of the certSecret field is <namespace>/<secret-name>.

    kubectl patch sbc backend-demo -n huawei-csi --type merge -p '{"spec":{"useCert":true,"certSecret":"huawei-csi/cert-1"}}'
    
  4. Check the storage backend creation result.

    kubectl get StorageBackendContent
    

    The following is an example of the command output. If the online status of StorageBackendContent is true, the update is successful.

    NAME              CLAIM                       SN               VENDORNAME   PROVIDERVERSION   ONLINE   AGE
    content-xxxxxxx   huawei-csi/backend-demo     xxxxxxxxxxxxxx   Huawei       4.12.0            true     53d
    

Deleting a Storage Certificate

  1. Delete the certificate configuration of StorageBackendClaim.

    kubectl patch sbc backend-demo -n huawei-csi --type merge -p '{"spec":{"useCert":false,"certSecret":""}}'
    
  2. Delete the certificate secret.

    kubectl delete secret cert-1 -n huawei-csi
    

5 - Deleting a Storage Backend


Do not delete a storage backend when a volume management operation is being performed on it.

  1. Delete the StorageBackendClaim.

    kubectl delete sbc backend-demo -n huawei-csi
    

    After the StorageBackendClaim is deleted, the controller automatically deletes the associated StorageBackendContent.

  2. Check whether StorageBackendContent is deleted.

    kubectl get sbct
    

    If the associated StorageBackendContent is no longer listed, the deletion is successful.

  3. Run the following commands to manually delete the associated ConfigMap and secret:

    kubectl delete configmap backend-demo -n huawei-csi
    kubectl delete secret backend-demo -n huawei-csi