The module lifecycle stage: General Availability

The module has requirements for installation

v0.5.37

Release date: 2026-10-01

Several CephClusterConnections to the same Ceph cluster no longer break each other’s volumes: RBD volumes detach with the secret of their own connection, a connection is not deleted while volumes or snapshots still need it, and a new condition reports the volumes the shared ceph-csi configuration cannot serve. Ceph CSI is updated to v3.18.0.

Highlights

Changes in this release:

  • RBD volumes detach with the secret of their own CephClusterConnection. Before, with two connections to the same Ceph cluster, a detach could run as the user of the other connection, fail with Operation not permitted and leave the VolumeAttachment behind, blocking the next attach of the volume with Multi-Attach.
  • A CephClusterConnection being deleted keeps its Secret and finalizer while PersistentVolumes or VolumeSnapshotContents still need them, and says so in its Ready condition with the reason PersistentVolumesExist or VolumeSnapshotContentsExist.
  • The new ClusterConfigConflict condition of CephClusterConnection names the volumes that need a Ceph user or a CephFS subvolume group other than the one the shared ceph-csi configuration of their cluster holds.

New features

This release adds:

  • CephClusterConnection has the ClusterConfigConflict condition. ceph-csi keeps one configuration entry per Ceph cluster with the user of one connection for RBD and the subvolume group of one connection for CephFS. The condition is True with the reason VolumesNeedOtherSettings when volumes created through the connection need another user or group than that entry holds, names up to ten such PersistentVolumes and the connection whose settings the entry holds, and is False with the reason ServedByClusterConfig otherwise. It is set on every connection that shares a Ceph cluster and is updated when the listed volumes change phase or are deleted. Affected are RBD volumes provisioned before this release whose connection has another user (they cannot detach) and CephFS volumes in another subvolume group (they can be mounted but not deleted, expanded or snapshotted).
  • On DKP 1.78 and later the module ships its access roles in the capability/scope RBACv2 scheme: d8:system-capability:csi-ceph:view and d8:system-capability:csi-ceph:edit for the CephClusterConnection, CephClusterAuthentication, CephStorageClass and CephMetadataBackup resources. On earlier DKP versions the d8:manage:permission:module:csi-ceph:view and d8:manage:permission:module:csi-ceph:edit roles are rendered unchanged.

Improvements

This release improves:

  • The module controller no longer keeps managedFields of PersistentVolumes and VolumeAttachments in its cache, which holds those of every CSI driver in the cluster, so its memory use grows less with the number of volumes.

Fixes

This release fixes:

  • Every RBD StorageClass now carries the csi.storage.k8s.io/controller-publish-secret-name and csi.storage.k8s.io/controller-publish-secret-namespace parameters, so each new RBD PersistentVolume names the Secret of its own CephClusterConnection for detach. Before, ceph-csi took the detach Secret from the one configuration entry per Ceph cluster, which the controller overwrote with the connection reconciled last; with two connections to one cluster, for example one for RBD and one for CephFS whose user has no access to the RBD pools, detach failed and the volume could not be attached on another node. For RBD volumes provisioned before the upgrade, which still rely on that entry, the entry keeps the connection whose volumes depend on it, and deleting one connection of a cluster no longer drops the entry the others need.
  • Deleting a CephClusterConnection no longer leaves its volumes stuck. Before, its Secret was deleted at once, and a volume it had provisioned could then no longer be detached, expanded or deleted. The connection now stays until no PersistentVolume needs its Secret (attached to a node, Bound or not yet claimed, or Released/Failed with the Delete reclaim policy) and no VolumeSnapshotContent with the Delete deletion policy refers to it. Its Ready condition is False with the reason PersistentVolumesExist or, when only snapshots are left, VolumeSnapshotContentsExist, and the message names up to ten of them. A Released or Failed PersistentVolume with the Retain policy that is attached nowhere does not hold the connection, so an ElasticCluster teardown in sds-elastic is not blocked by such a volume. The connection goes as soon as its last volume or snapshot is gone.
  • The CephFS subvolume group of the shared ceph-csi configuration entry no longer moves to the group of another CephClusterConnection once a second connection to the same cluster creates its first CephFS volume. Before, the CephFS volumes created earlier could then no longer be deleted or expanded. The group now follows the subvolumePath of the existing volumes, and the monitors of the entry are those of all connections to the cluster.

Upgrade notes

Before upgrading, note the following:

  • The controller recreates every existing RBD StorageClass once to add the controller-publish secret parameters; parameters of a StorageClass are immutable in Kubernetes. Existing PersistentVolumes and PVCs are not affected: only volumes provisioned after the upgrade carry the detach Secret, and older RBD volumes keep detaching through the shared ceph-csi configuration entry.
  • After the upgrade, check ClusterConfigConflict on clusters with several CephClusterConnections to the same Ceph cluster; the FAQ gives the command that lists the affected connections and explains how to let the listed RBD volumes detach by granting the user of the connection the entry holds access to their pools.
  • Deleting a CephClusterConnection now waits for the PersistentVolumes and VolumeSnapshotContents that need its Secret. Delete them, or the VolumeSnapshots of the listed contents, for the deletion to finish. The controller is granted read access to PersistentVolumes, VolumeAttachments and VolumeSnapshotContents for this.
  • On DKP 1.78 and later the d8:manage:permission:module:csi-ceph:* ClusterRoles are replaced by d8:system-capability:csi-ceph:*. Access granted through the Deckhouse role aggregation keeps working; a binding created by hand to one of the old role names has to be moved to the new name.

Docs

Documentation changes:

  • The FAQ explains why a CephClusterConnection is not deleted and which PersistentVolumes and VolumeSnapshotContents hold it, and what the ClusterConfigConflict condition means, how to find the affected connections and how to let the listed RBD volumes detach.

Dependencies

Dependency updates:

  • ceph-csi: 3.16.3 → 3.18.0 (changelog)
    • Upstream already ships the dependency updates that our CVE patch carried, so that patch is dropped; the two functional patches, including the ext4 superuser reserve, are rebased without changes in behaviour.

v0.5.36

Release date: 2026-09-14

A small release: the module logs at INFO by default, and the golang.org/x/crypto pin no longer shows up as a critical finding in scans of the hooks image.

Highlights

Changes in this release:

  • The default logLevel is now INFO instead of DEBUG, so a cluster that never set it explicitly gets far less log volume from the module.
  • The golang.org/x/crypto pin is raised to v0.57.0, which clears CVE-2026-56854, CVE-2026-56855 and CVE-2026-78662 from scans of the module’s hooks image.

Improvements

This release improves:

  • The default logLevel is now INFO instead of DEBUG, which is what a cluster that never set it explicitly will get.

Security updates

Security updates in this release:

  • The golang.org/x/crypto pin is raised from v0.53.0 to v0.57.0 in every component, which takes CVE-2026-56854, CVE-2026-56855 and CVE-2026-78662 out of scans of the module’s hooks image. None of the three was reachable: the vulnerable x/crypto/ssh package is not compiled into any binary the module ships, so this clears the finding rather than an exposure.

Upgrade notes

Before upgrading, note the following:

  • Nothing has to be done by hand. A cluster that relied on the previous default verbosity should set logLevel: DEBUG in the module configuration explicitly, because the default is now INFO.

v0.5.35

Release date: 2026-09-10

An RBD StorageClass can now keep a share of the filesystem for the superuser, the module controller exports its metrics to Prometheus, and the Ceph CSI driver is updated to v3.16.3.

Highlights

Changes in this release:

  • A CephStorageClass can ask for a percentage of every new ext4 volume to be reserved for the superuser through the storage.deckhouse.io/ext4-reserved-percent annotation.
  • The module controller publishes its metrics — reconcile counts and durations, workqueue depth, client-go latency — and Prometheus scrapes them through a ServiceMonitor.
  • Ceph CSI is updated from v3.15.1 to v3.16.3.

New features

This release adds:

  • CephStorageClass accepts the storage.deckhouse.io/ext4-reserved-percent annotation: a whole number of percent between 0 and 50 that mkfs.ext4 keeps for the superuser. It works for type: RBD classes whose volumes are formatted with ext4 and is ignored for CephFS and for XFS volumes; nothing is reserved by default. A value out of range or not a number puts the CephStorageClass into the Failed phase with the reason in its conditions instead of failing volume creation later.
  • The controller metrics are exported to Prometheus: a ServiceMonitor for the csi-ceph-controller job scrapes them through a kube-rbac-proxy, while the controller itself keeps the endpoint on loopback.

Improvements

This release improves:

  • The controller logs at the info level by default instead of debug, so a quiet cluster no longer fills the log with per-reconcile detail; LOG_LEVEL=debug brings the previous verbosity back.

Fixes

This release fixes:

  • An edit to the annotations of a CephStorageClass is reconciled right away. Previously only changes to spec and to the labels reached the reconciler, so an annotation-driven parameter took effect only once something else touched the resource.
  • The CSI Pods no longer wait in ContainerCreating on a fresh install until the first CephClusterConnection appears: the ceph-csi-config ConfigMap the controller creates is now mounted as optional, and replacing it no longer takes the driver down for minutes.

Dependencies

Dependency updates:

  • ceph-csi: 3.15.1 → 3.16.3 (changelog)
    • The stack of our patches is rebuilt on top of the new tag: the fixes that landed upstream are dropped, and the remaining dependency updates that close 2026 advisories are collapsed into a single patch.

v0.5.34

  • Fix: the release image is no longer built from cache with an outdated changelog.yaml — git-mapping dependencies are tied to the install stage, where the file is copied
  • Update base images to v2.1.4
  • Internal build changes for the module

v0.5.33

  • Bugfix: the controller is granted patch on events instead of list - a repeated event write is no longer denied by RBAC
  • CVE fixes
  • Base images updated to v2.1.2, Go to 1.26.6 and lib-helm to 1.72.14
  • Internal build changes: CI updated, crds, docs and openapi are shipped in the release image

v0.5.32

  • CephStorageClass, CephClusterConnection, and CephClusterAuthentication publish status.conditions and status.observedGeneration. The status.phase field retains the same set of values ​​and its column, but is now calculated from the Ready condition
  • CephClusterAuthentication received a status record that it did not have and publishes the condition Deprecated instead of Ready - this resource is not brought to the desired state
  • Updating base images to v1.3.25 and lib-helm to 1.72.13

v0.5.31

  • The snapshot-controller module is no longer a required dependency: VolumeSnapshotClass is created only if the CRD snapshot.storage.k8s.io is available, otherwise CephStorageClass is processed without the snapshot part; After installing CRD, restarting the controller is not required
  • Correction: when msCrcData is disabled, managed StorageClasses are transferred to msgr1 (ms_mode=legacy) - otherwise the kernel clients krbd and CephFS discarded frames without CRC and the mount ended with a timeout if the cluster was healthy
  • Updating base images, Go 1.26.5 and lib-helm to 1.72.12
  • Fixed vulnerabilities in third-party dependencies
  • Internal changes in module assembly and CI, added e2e tests

v0.5.30

  • Correction: CephStorageClass validation no longer rejects a resource with an empty parameter block of the opposite type (rbd or cephFS)
  • Updating base images, Go 1.26.5 and lib-helm to 1.72.9
  • Internal changes in module assembly

v0.5.29

  • Fixed generation of access secret to registry (deckhouse-registry): Now it only contains authorization data for the active image source

v0.5.28

  • The e2fsck and fsck utilities for checking file systems have been added to the CSI node image

v0.5.27

  • When forwarding labels from CephStorageClass to StorageClass, labels with specified ignored prefixes are now excluded
  • Updating base images and lib-helm to 1.72.0

v0.5.26

  • Reconciliation when changing CephStorageClass labels for forwarding to managed StorageClass Kubernetes
  • Update base images, Go 1.25.10 and lib-helm 1.71.12

v0.5.25

  • Fixed PromQL expressions in StorageClass alerts - brought the kube_storageclass_labels to the correct format and renamed the group to kubernetes.ceph.storage_class
  • Added Russian description for CRD CephMetadataBackup

v0.5.24

  • Internal changes in module structure and assembly

v0.5.23

  • Update base images, Go 1.25.10 and lib-helm 1.71.11
  • Internal changes to the module assembly

v0.5.22

  • Corrections to the module structure

v0.5.21

  • Added msCrcData parameter to disable CRC32C checking on Ceph data frames; when changing ceph-config, CSI pods (RBD/CephFS) are automatically restarted

v0.5.20

  • CI changes: DistroPackagesProxy and env proxy in werf, improvements to CVE scans (role_name, checkout, scanning restrictions)
  • Added user-authz cluster roles in templates

v0.5.19

  • Added missing mount points in csi-ceph distroless image
  • Updating base images and lib-helm

v0.5.18

  • Fix CVE
  • Documentation changes

v0.5.17

  • Module-sdk update for CVE fix
  • Update base images and golang
  • Disable Capacity request from k8s (CSI does not support Capacity issue)
  • Documentation processing

v0.5.16

  • Module-sdk update for CVE fix

v0.5.15

  • Updated version of base images
  • Updated Deckhouse dependency to 1.72
  • Updated CSI to 3.15.1
  • Reworking manifestos
  • Fixed a bug when creating VolumeSnapshotClasses

v0.5.14

  • Documentation fixes
  • Fix HA-mode, now it works correctly
  • Removed scheduler functionality, remaining for compatibility with old Deckhouse versions

v0.5.13

  • Updated base images versions
  • Fixed Prometheus rules
  • Fixed CVE
  • Updated Deckhouse dependency to 1.71
  • Updated Go version to 1.24.10

v0.5.12

  • Updated Go version to 1.24.9
  • Updated lib-helm to deckhouse_lib_helm-1.64.1

v0.5.11

  • Fix error in generating configmap with cluster connection data

v0.5.10

  • Fix CVE in ceph-csi

v0.5.9

  • Updated ceph-csi to v3.15.0

v0.5.8

  • Updated Go version to 1.24.8
  • Updated lib-helm to deckhouse_lib_helm-1.63.6

v0.5.7

  • Added release notes

v0.5.6

  • Added additional mount points for containerd v2 support

v0.5.5

  • Added information about the need for snapshot-controller for module operation
  • Added readonlyRootFilesystem for enhanced module security

v0.5.4

  • CVE fixes

v0.5.3

  • Added dependency on snapshot-controller
  • CVE fixes

v0.5.2

  • Added fixes for containerd v2 support
  • Fixes in CephClusterConnection processing

v0.5.1

  • Added support for subvolume group when specifying cluster data (field is also considered during migration from ceph-csi)

v0.5.0

  • Added automatic creation of VolumeSnapshotClassName annotations in StorageClass for proper snapshot-controller operation
  • Updated CSI to 3.14.2
  • Added setting to specify the number of worker threads for csi provisioner

v0.4.4

  • Module refactoring, documentation and build process fixes
  • Added HA mode support for CSI controller

v0.4.3

  • Technical release, module refactoring

v0.3.2

  • Updated lib-helm and CSI code patch fixes

v0.3.1

  • Fixed hook for automatic merging of CephClusterAuthorization and CephClusterConnection resources (now considers VolumeSnapshots, not just PV)
  • Cleaned metadata from images (cleaner images to reduce security client questions)

v0.3.0

  • Fixed error in generating internal configmap with ceph settings
  • Added hook for automatic merging of CephClusterAuthorization and CephClusterConnection resources (only CephClusterConnection will remain with all necessary fields)

v0.2.2

  • Added labels to our CRDs for proper Deckhouse backup operation
  • Fixed CSI controller templates for proper operation

v0.2.1

  • Updated golang to current 1.22.6 and replaced deprecated logging library to close known vulnerabilities

v0.2.0

  • Added liveness and readiness probes
  • Updated ceph-csi version to 3.12.1, and updated dependencies for which there are known CVEs in old versions
  • Enabled features needed for DVP in RBD StorageClass: exclusive-lock,object-map,fast-diff