Using volumes to persist container data¶
You can use volumes to persist the data used by the containers in a pod. A volume is directory, accessible to the containers in a pod, where data is stored for the life of the pod.
Files in a container are ephemeral. As such, when a container crashes or stops, the data is lost.
Understanding volumes¶
You can provide persistent or temporary storage for your applications by mounting volumes to pods and containers. Using volumes ensures that data remains available even if a container restarts by backing the file system with host-local or network-attached storage.
Volumes are mounted file systems available to pods and their containers which may be backed by a number of host-local or network attached storage endpoints. Containers are not persistent by default; on restart, their contents are cleared.
To ensure that the file system on the volume contains no errors and, if errors are present, to repair them when possible, OpenShift Container Platform invokes the fsck utility prior to the mount utility. This occurs when either adding a volume or updating an existing volume.
The simplest volume type is emptyDir, which is a temporary directory on a single machine. Administrators may also allow you to request a persistent volume that is automatically attached to your pods.
Note
emptyDir volume storage may be restricted by a quota based on the pod’s FSGroup, if the FSGroup parameter is enabled by your cluster administrator.
Working with volumes using the OpenShift Container Platform CLI¶
You can use the CLI command oc set volume to add and remove volumes and volume mounts for any object that has a pod template like replication controllers or deployment configs. You can also list volumes in pods or any object that has a pod template.
The oc set volume command uses the following general syntax:
- Object selection
-
Specify one of the following for the
object_selectionparameter in theoc set volumecommand:Object Selection
| Syntax |
|---|
| Description |
| Example |
_<object_type> <name>_ |
Selects <name> of type _<object_type>_. |
deploymentConfig registry |
_<object_type>/<name>_ |
Selects <name> of type _<object_type>_. |
deploymentConfig/registry |
_<object_type>_ --selector=_<object_label_selector>_ |
Selects resources of type _<object_type>_ that matched the given label selector. |
deploymentConfig --selector="name=registry" |
_<object_type>_ --all |
Selects all resources of type _<object_type>_. |
deploymentConfig --all |
-f or --filename=_<file_name>_ |
| File name, directory, or URL to file to use to edit the resource. |
-f registry-deployment-config.json |
- Operation
- Specify
--addor--removefor theoperationparameter in theoc set volumecommand. - Mandatory parameters
- Any mandatory parameters are specific to the selected operation and are discussed in later sections.
- Options
- Any options are specific to the selected operation and are discussed in later sections.
About listing volumes and volume mounts in a pod¶
You can list volumes and volume mounts in pods or pod templates.
You can list volumes by running the following command:
List volume supported options:
| Option |
|---|
| Description |
| Default |
--name |
| Name of the volume. |
-c, --containers |
Select containers by name. It can also take wildcard '*' that matches any character. |
'*' |
For example:
-
To list all volumes for pod p1:
-
To list volume v1 defined on all deployment configs:
About adding volumes to a pod¶
You can add volumes and volume mounts to a pod. Volumes persist the data used by the containers, even if container crashes or stops.
You can add a volume, a volume mount, or both to pod templates by running the following command:
Supported Options for Adding Volumes
| Option |
|---|
| Description |
| Default |
--name |
| Name of the volume. |
| Automatically generated, if not specified. |
-t, --type |
Name of the volume source. Supported values: emptyDir, hostPath, secret, configmap, persistentVolumeClaim or projected. |
emptyDir |
-c, --containers |
Select containers by name. It can also take wildcard '*' that matches any character. |
'*' |
-m, --mount-path |
Mount path inside the selected containers. Do not mount to the container root, /, or any path that is the same in the host and the container. This can corrupt your host system if the container is sufficiently privileged, such as the host /dev/pts files. It is safe to mount the host by using /host. |
--path |
Host path. Mandatory parameter for --type=hostPath. Do not mount to the container root, /, or any path that is the same in the host and the container. This can corrupt your host system if the container is sufficiently privileged, such as the host /dev/pts files. It is safe to mount the host by using /host. |
--secret-name |
Name of the secret. Mandatory parameter for --type=secret. |
--configmap-name |
Name of the configmap. Mandatory parameter for --type=configmap. |
--claim-name |
Name of the persistent volume claim. Mandatory parameter for --type=persistentVolumeClaim. |
--source |
Details of volume source as a JSON string. Recommended if the desired volume source is not supported by --type. |
-o, --output |
Display the modified objects instead of updating them on the server. Supported values: json, yaml. |
--output-version |
| Output the modified objects with the given version. |
api-version |
For example:
-
To add a new volume source emptyDir to the registry
DeploymentConfigobject:Tip
You can alternatively apply the following YAML to add the volume:
Sample deployment config with an added volume
kind: DeploymentConfig apiVersion: apps.openshift.io/v1 metadata: name: registry namespace: registry spec: replicas: 3 selector: app: httpd template: metadata: labels: app: httpd spec: volumes: - name: volume-pppsw emptyDir: {} containers: - name: httpd image: >- image-registry.openshift-image-registry.svc:5000/openshift/httpd:latest ports: - containerPort: 8080 protocol: TCPwhere:
spec.template.spec.volumes- Specifies the volume source emptyDir.
-
To add volume v1 with secret secret1 for replication controller r1 and mount inside the containers at /data:
Tip
You can alternatively apply the following YAML to add the volume:
Sample replication controller with added volume and secret
kind: ReplicationController apiVersion: v1 metadata: name: example-1 namespace: example spec: replicas: 0 selector: app: httpd deployment: example-1 deploymentconfig: example template: metadata: creationTimestamp: null labels: app: httpd deployment: example-1 deploymentconfig: example spec: volumes: - name: v1 secret: secretName: secret1 defaultMode: 420 containers: - name: httpd image: >- image-registry.openshift-image-registry.svc:5000/openshift/httpd:latest volumeMounts: - name: v1 mountPath: /datawhere:
spec.template.spec.volumes- Specifies the volume and secret.
spec.template.spec.containers.volumeMounts- Specifies the container mount path.
-
To add existing persistent volume v1 with claim name pvc1 to deployment configuration dc.json on disk, mount the volume on container c1 at /data, and update the
DeploymentConfigobject on the server:$ oc set volume -f dc.json --add --name=v1 --type=persistentVolumeClaim \ --claim-name=pvc1 --mount-path=/data --containers=c1Tip
You can alternatively apply the following YAML to add the volume:
Sample deployment config with persistent volume added
kind: DeploymentConfig apiVersion: apps.openshift.io/v1 metadata: name: example namespace: example spec: replicas: 3 selector: app: httpd template: metadata: labels: app: httpd spec: volumes: - name: volume-pppsw emptyDir: {} - name: v1 persistentVolumeClaim: claimName: pvc1 containers: - name: httpd image: >- image-registry.openshift-image-registry.svc:5000/openshift/httpd:latest ports: - containerPort: 8080 protocol: TCP volumeMounts: - name: v1 mountPath: /datawhere:
spec.template.spec.volumes.name.v1- Specifies the persistent volume claim named
pvc1. spec.template.spec.containers.volumeMounts- Specifies the container mount path.
-
To add a volume v1 based on Git repository \(**\)https://github.com/namespace1/project1\(**\) with revision 5125c45f9f563 for all replication controllers:
About updating volumes and volume mounts in a pod¶
You can modify the volumes and volume mounts in a pod.
You can update existing volumes by using the --overwrite option:
For example:
-
To replace existing volume v1 for replication controller r1 with existing persistent volume claim pvc1:
Tip
You can alternatively apply the following YAML to replace the volume:
Sample replication controller with persistent volume claim named
pvc1kind: ReplicationController apiVersion: v1 metadata: name: example-1 namespace: example spec: replicas: 0 selector: app: httpd deployment: example-1 deploymentconfig: example template: metadata: labels: app: httpd deployment: example-1 deploymentconfig: example spec: volumes: - name: v1 persistentVolumeClaim: claimName: pvc1 containers: - name: httpd image: >- image-registry.openshift-image-registry.svc:5000/openshift/httpd:latest ports: - containerPort: 8080 protocol: TCP volumeMounts: - name: v1 mountPath: /dataThe
spec.template.spec.volumesstanza sets the persistent volume claim topvc1. -
To change the
DeploymentConfigobject d1 mount point to /opt for volume v1:Tip
You can alternatively apply the following YAML to change the mount point:
Sample deployment config with mount point set to
opt.kind: DeploymentConfig apiVersion: apps.openshift.io/v1 metadata: name: example namespace: example spec: replicas: 3 selector: app: httpd template: metadata: labels: app: httpd spec: volumes: - name: volume-pppsw emptyDir: {} - name: v2 persistentVolumeClaim: claimName: pvc1 - name: v1 persistentVolumeClaim: claimName: pvc1 containers: - name: httpd image: >- image-registry.openshift-image-registry.svc:5000/openshift/httpd:latest ports: - containerPort: 8080 protocol: TCP volumeMounts: - name: v1 mountPath: /optThe
spec.template.spec.containers.volumeMountsstanza sets the mount point to/opt.
About removing volumes and volume mounts from a pod¶
You can remove a volume or volume mount from a pod.
You can remove a volume from a pod template by running the following command:
Supported options for removing volumes
| Option |
|---|
| Description |
| Default |
--name |
| Name of the volume. |
-c, --containers |
Select containers by name. It can also take wildcard '*' that matches any character. |
'*' |
--confirm |
| Indicate that you want to remove multiple volumes at once. |
-o, --output |
Display the modified objects instead of updating them on the server. Supported values: json, yaml. |
--output-version |
| Output the modified objects with the given version. |
api-version |
For example:
-
To remove a volume v1 from the
DeploymentConfigobject d1: -
To unmount volume v1 from container c1 for the
DeploymentConfigobject d1 and remove the volume v1 if it is not referenced by any containers on d1: -
To remove all volumes for replication controller r1:
Configuring volumes for multiple uses in a pod¶
You can configure a volume to share one volume for multiple uses in a single pod by using the volumeMounts.subPath property to specify a subPath value inside a volume instead of the volume’s root.
Note
You cannot add a subPath parameter to an existing scheduled pod.
Procedure
-
To view the list of files in the volume, run the
oc rshcommand: -
Specify the
subPath:Example Pod spec with subPath parameterapiVersion: v1 kind: Pod metadata: name: my-site spec: securityContext: runAsNonRoot: true seccompProfile: type: RuntimeDefault containers: - name: mysql image: mysql volumeMounts: - mountPath: /var/lib/mysql name: site-data subPath: mysql securityContext: allowPrivilegeEscalation: false capabilities: drop: [ALL] - name: php image: php volumeMounts: - mountPath: /var/www/html name: site-data subPath: html securityContext: allowPrivilegeEscalation: false capabilities: drop: [ALL] volumes: - name: site-data persistentVolumeClaim: claimName: my-site-datawhere:
spec.containers.volumeMounts.subPath.mysql- Specifies that databases are stored in the
mysqlfolder. spec.containers.volumeMounts.subPath.html- Specifies that HTML content is stored in the
htmlfolder.