Azure Disk CSI Driver Operator¶
You can provision and manage Azure Disk storage in OpenShift Container Platform by using the Azure Disk Container Storage Interface (CSI) Driver Operator and driver, which provide dynamic volume provisioning and eliminate the need to pre-provision storage.
Overview of Azure Disk CSI Driver Operator¶
OpenShift Container Platform is capable of provisioning persistent volumes (PVs) using the Container Storage Interface (CSI) driver for Microsoft Azure Disk Storage.
Familiarity with persistent storage and configuring CSI volumes is recommended when working with a CSI Operator and driver. For more information about these topics, see "Understanding persistent storage" and "Configuring CSI volumes".
To create CSI-provisioned PVs that mount to Azure Disk storage assets, OpenShift Container Platform installs the Azure Disk CSI Driver Operator and the Azure Disk CSI driver by default in the openshift-cluster-csi-drivers namespace.
- Azure Disk CSI Driver Operator
- The Azure Disk CSI Driver Operator provides a storage class named
managed-csithat you can use to create persistent volume claims (PVCs). The Azure Disk CSI Driver Operator supports dynamic volume provisioning by allowing storage volumes to be created on-demand, eliminating the need for cluster administrators to pre-provision storage. You can disable this default storage class if desired (see "Managing the default storage class"). - Azure Disk CSI driver
- The Azure Disk CSI driver enables you to create and mount Azure Disk PVs.
Note
OpenShift Container Platform provides automatic migration for the Azure Disk in-tree volume plugin to its equivalent CSI driver. For more information, see "CSI automatic migration".
Additional resources
- Understanding persistent storage
- Configuring CSI volumes
- Managing the default storage class
- CSI automatic migration
About CSI¶
The Container Storage Interface (CSI) enables storage vendors to deliver plugins through a standard interface without modifying Kubernetes core code, replacing traditional embedded storage drivers.
CSI Operators give OpenShift Container Platform users storage options, such as volume snapshots, that are not possible with in-tree volume plugins.
Creating a storage class with storage account type¶
To provision persistent volumes with specific performance and redundancy characteristics, create a storage class that designates an Azure storage account type corresponding to your SKU tier.
Storage classes are used to differentiate and delineate storage levels and usages. By defining a storage class, you can obtain dynamically provisioned persistent volumes.
When creating a storage class, you can designate the storage account type. This corresponds to your Azure storage account SKU tier. Valid options are Standard_LRS, Premium_LRS, StandardSSD_LRS, UltraSSD_LRS, Premium_ZRS, and StandardSSD_ZRS. For information about finding your Azure SKU tier, see "SKU Types".
Both zone-redundant storage (ZRS) and PremiumV2_LRS have some region limitations. For information about these limitations, see "ZRS limitations" and "Premium_LRS limitations".
Prerequisites
- Access to an OpenShift Container Platform cluster with administrator rights
Procedure
-
Create a storage class designating the storage account type using a YAML file similar to the following: $ oc create -f - << EOF apiVersion: storage.k8s.io/v1 kind: StorageClass metadata: name: <storage-class> provisioner: disk.csi.azure.com parameters: skuName: <storage-class-account-type> reclaimPolicy: Delete volumeBindingMode: WaitForFirstConsumer allowVolumeExpansion: true EOF
-
metadata.name: Specifies the storage class name. -
parameters.skuName: The storage account type. This corresponds to your Azure storage account SKU tier:Standard_LRS,Premium_LRS,StandardSSD_LRS,UltraSSD_LRS,Premium_ZRS,StandardSSD_ZRS,PremiumV2_LRS.Note
For PremiumV2_LRS, specify
cachingMode: Noneinstorageclass.parameters.
-
-
Ensure that the storage class was created by listing the storage classes:
Example outputNAME PROVISIONER RECLAIMPOLICY VOLUMEBINDINGMODE ALLOWVOLUMEEXPANSION AGE azurefile-csi file.csi.azure.com Delete Immediate true 68m managed-csi (default) disk.csi.azure.com Delete WaitForFirstConsumer true 68m sc-prem-zrs disk.csi.azure.com Delete WaitForFirstConsumer true 4m25sIn this example,
sc-prem-zrsis the new storage class with storage account type.
Additional resources
Performance plus for Azure Disk¶
You can enhance Azure disk performance by enabling performance plus to increase IOPS and throughput limits for certain Azure disk types 513 GiB, and larger.
Overview of performance plus¶
Performance plus increases Input/Output Operations Per Second (IOPS) and throughput limits for certain Azure disk types 513 GiB, and larger.
The following Azure disk types support performance plus:
- Azure Premium solid-state drives (SSD)
- Standard SSDs
- Standard hard disk drives (HDD)
To see what the increased limits are for IOPS and throughput, consult the columns that begin with Expanded in the tables in "Scalability and performance targets for VM disks".
Additional resources
Limitations for performance plus¶
To successfully enable performance plus, verify that your disk configuration meets the required type, size, and provisioning criteria before attempting to use this feature.
Performance plus for Azure Disk has the following limitations:
-
Can be enabled only on Standard HDD, Standard SSD, and Premium SSD managed disks that are 513 GiB or larger.
Warning
If you request a smaller value, the disk size is rounded up to 513GiB.
-
Can be enabled only on new disks. For a workaround, see "Enabling performance plus by snapshot or cloning".
Additional resources
Creating a storage class to use performance plus enhanced disks¶
To provision Azure disks with enhanced IOPS and throughput, create a storage class with performance plus enabled that automatically applies to persistent volume claims.
Prerequisites
-
Access to a Microsoft Azure cluster with cluster-admin privileges.
-
Access to an Azure disk with performance plus enabled.
For information about enabling performance plus on disks, see the "Microsoft Azure storage documentation".
Procedure
-
Create a storage class using the following example YAML file:
Example storage class YAML fileapiVersion: storage.k8s.io/v1 kind: StorageClass metadata: name: <azure-disk-performance-plus-sc> provisioner: disk.csi.azure.com parameters: skuName: Premium_LRS cachingMode: ReadOnly enablePerformancePlus: "true" reclaimPolicy: Delete volumeBindingMode: WaitForFirstConsumer allowVolumeExpansion: truemetadata.name: Specifies the name of the storage class.provisioner: Specifies the Azure Disk Container Storage Interface (CSI) driver provisioner.parameters.skuName: Specifies the Azure disk type SKU. In this example,Premium_LRSfor Premium SSD Locally Redundant Storage.parameters.enablePerformancePlus: Enables Azure Disk performance plus.
-
Create a persistent volume claim (PVC) that uses this storage class by using the following example YAML file:
Example PVC YAML fileapiVersion: v1 kind: PersistentVolumeClaim metadata: name: <my-azure-pvc> spec: accessModes: - ReadWriteOnce storageClassName: <azure-disk-performance-plus-sc> resources: requests: storage: 513Gimetadata.name: Specifies the PVC name.spec.storageClassName: References the performance plus storage class.spec.resources.requests.storage: Any disk size smaller than 513GiB is automatically rounded up.
Enabling performance plus by snapshot or cloning¶
To work around the limitation that performance plus applies only to new disks, snapshot or clone an existing volume to provision a new disk with performance plus enabled.
Normally, performance plus can be enabled only on new disks. For a workaround, you can use this procedure.
Prerequisites
-
Access to a Microsoft Azure cluster with cluster-admin privileges.
-
Access to an Azure disk with performance plus enabled.
-
Have created a storage class to use performance plus enhanced Azure disks.
For more information about creating the storage class, see "Creating a storage class to use performance plus enhanced disks".
Procedure
-
Do one of the following to enable performance plus:
- Create a snapshot of the existing volume that does not have performance plus enabled on it, and then provision a new disk from that snapshot using a storage class with
enablePerformancePlusset to "true". - Clone the persistent volume claim (PVC) using a storage class with
enablePerformancePlusset to "true" to create a new disk clone.
- Create a snapshot of the existing volume that does not have performance plus enabled on it, and then provision a new disk from that snapshot using a storage class with
Additional resources
User-managed encryption¶
The user-managed encryption feature allows you to provide keys during installation that encrypt OpenShift Container Platform node root volumes, and enables all managed storage classes to use these keys to encrypt provisioned storage volumes.
You must specify the custom key in the platform.<cloud_type>.defaultMachinePlatform field in the install-config YAML file.
This features supports the following storage types:
-
Amazon Web Services (AWS) Elastic Block storage (EBS)
Note
If there is no encrypted key defined in the storage class, only set
encrypted: "true"in the storage class. The AWS EBS CSI driver uses the AWS managed alias/aws/ebs, which is created by Amazon EBS automatically in each region by default to encrypt provisioned storage volumes. In addition, the managed storage classes all have theencrypted: "true"setting.For information about installing AWS EBS with user-managed encryption, see "Optional AWS configuration parameters".
-
Microsoft Azure Disk storage
Note
If the OS (root) disk is encrypted, and there is no encrypted key defined in the storage class, Azure Disk CSI driver uses the OS disk encryption key by default to encrypt provisioned storage volumes.
For information about installing Azure Disk with user-managed encryption, see "Preparing an Azure Disk Encryption Set".
-
Google Cloud Platform (GCP) persistent disk (PD) storage
For information about installing GCP PD with user-managed encryption, see "Additional Google Cloud configuration parameters".
-
IBM Cloud(R) Virtual Private Cloud (VPC) Block storage
For information about installing with IBM Cloud with user-managed encryption, see "User-managed encryption for IBM Cloud" and "Installing on IBM Cloud".
Additional resources
Machine sets that deploy machines with ultra disks using PVCs¶
You can create a machine set running on Microsoft Azure that deploys machines with ultra disks. Ultra disks are high-performance storage that are intended for use with the most demanding data workloads.
Both the in-tree plugin and CSI driver support using PVCs to enable ultra disks. You can also deploy machines with ultra disks as data disks without creating a PVC.
Additional resources
- Microsoft Azure ultra disks documentation
- Machine sets that deploy machines on ultra disks using in-tree PVCs
- Machine sets that deploy machines on ultra disks as data disks
Creating machines with ultra disks by using machine sets¶
You can deploy machines with ultra disks on Microsoft Azure by editing your machine set YAML file.
Prerequisites
- Have an existing Microsoft Azure cluster.
Procedure
-
Copy an existing Azure
MachineSetcustom resource (CR) and edit it by running the following command:where:
<machine_set_name>- Indicates the machine set that you want to provision machines with ultra disks.
-
Add the following lines in the positions indicated:
apiVersion: machine.openshift.io/v1beta1 kind: MachineSet spec: template: spec: metadata: labels: disk: ultrassd providerSpec: value: ultraSSDCapability: Enabledwhere:
spec.template.spec.metadata.labels.disk- Specifies a label to use to select a node that is created by this machine set. The example uses
disk.ultrassdfor this value. spec.template.spec.providerSpec.value.ultraSSDCapability- Enables the use of ultra disks.
-
Create a machine set by using the updated configuration by running the following command:
-
Create a storage class that contains the following YAML definition:
apiVersion: storage.k8s.io/v1 kind: StorageClass metadata: name: ultra-disk-sc parameters: cachingMode: None diskIopsReadWrite: "2000" diskMbpsReadWrite: "320" kind: managed skuname: UltraSSD_LRS provisioner: disk.csi.azure.com reclaimPolicy: Delete volumeBindingMode: WaitForFirstConsumerwhere:
metadata.name- Specifies the name of the storage class. The example uses
ultra-disk-scfor this value. parameters.diskIopsReadWrite- Specifies the number of Input/Output Operations Per Second (IOPS) for the storage class.
parameters.diskMbpsReadWrite- Specifies the throughput in MBps for the storage class.
provisioner- For Microsoft Azure Kubernetes Service (AKS) version 1.21 or later, use
disk.csi.azure.com. For earlier versions of AKS, usekubernetes.io/azure-disk. volumeBindingMode- Optional parameter. Specifies this parameter to wait for the creation of the pod that will use the disk.
-
Create a persistent volume claim (PVC) to reference the
ultra-disk-scstorage class that contains the following YAML definition:apiVersion: v1 kind: PersistentVolumeClaim metadata: name: ultra-disk spec: accessModes: - ReadWriteOnce storageClassName: ultra-disk-sc resources: requests: storage: 4Giwhere:
metadata.name- Specifies the name of the PVC. The example uses
ultra-diskfor this value. spec.storageClassName- Specifies the name of the storage class to use. The example uses
ultra-disk-scstorage class. spec.resources.requests.storage- Specifies the size for the storage class. The minimum value is
4Gi.
-
Create a pod that contains the following YAML definition:
apiVersion: v1 kind: Pod metadata: name: nginx-ultra spec: nodeSelector: disk: ultrassd containers: - name: nginx-ultra image: alpine:latest command: - "sleep" - "infinity" volumeMounts: - mountPath: "/mnt/azure" name: volume volumes: - name: volume persistentVolumeClaim: claimName: ultra-diskwhere:
spec.nodeSelector.disk- Specifies the label of the machine set that enables the use of ultra disks. The example uses
disk.ultrassdfor this value. spec.volumes.persistentVolumeClaim.claimName- Specifies the name of the PVC to attach. This pod references the
ultra-diskPVC.
Verification
-
Validate that the machines are created by running the following command:
The machines should be in the
Runningstate. -
For a machine that is running and has a node attached, validate the partition by running the following command:
In this command,
oc debug node/<node_name>starts a debugging shell on the node<node_name>and passes a command with--. The passed commandchroot /hostprovides access to the underlying host OS binaries, andlsblkshows the block devices that are attached to the host OS machine.
Next steps
-
To use an ultra disk from within a pod, create a workload that uses the mount point. Create a YAML file similar to the following example:
apiVersion: v1 kind: Pod metadata: name: ssd-benchmark1 spec: containers: - name: ssd-benchmark1 image: nginx ports: - containerPort: 80 name: "http-server" volumeMounts: - name: lun0p1 mountPath: "/tmp" volumes: - name: lun0p1 hostPath: path: /var/lib/lun0p1 type: DirectoryOrCreate nodeSelector: disktype: ultrassd
Troubleshooting resources for machine sets that enable ultra disks¶
You can recover from issues that you might encounter when you enable ultra disks for machine sets. Review fields, such as disk settings, and ensure that the parameters are correctly configured.
Unable to mount a persistent volume claim backed by an ultra disk¶
If there is an issue mounting a persistent volume claim backed by an ultra disk, the pod becomes stuck in the ContainerCreating state and an alert is triggered.
For example, if the additionalCapabilities.ultraSSDEnabled parameter is not set on the machine that backs the node that hosts the pod, the following error message appears:
StorageAccountType UltraSSD_LRS can be used only when additionalCapabilities.ultraSSDEnabled is set.
-
To resolve this issue, describe the pod by running the following command:
Additional resources