The module lifecycle stage: General Availability
The module has requirements for installation
v0.3.26
Release date: 2026-10-01
The Huawei CSI driver is updated to v4.12.1, nodes take the iSCSI and multipath stack from the module’s own package without asking the distribution’s repositories, and the module ships access roles for its resources.
Highlights
Changes in this release:
- The
NodeGroupConfigurationresources of the module no longer ask the node’s package manager foropen-iscsi,multipath-toolsandsg3-utils. Every node gets the module’siscsi-toolspackage, which supplies only the pairs the host lacks (iscsiadmwithiscsid,multipathwithmultipathd); a node with no route to its repositories no longer waits on them on every bashible run. - The Huawei CSI driver (eSDK) is updated from v4.10.1 to v4.12.1.
- The module ships ClusterRoles for viewing and managing
HuaweiStorageClassandHuaweiStorageConnection, aggregated into the storage manager role.
New features
This release adds:
- The module ships two ClusterRoles for its cluster-scoped resources
HuaweiStorageClassandHuaweiStorageConnection: view (get,list,watch) and edit (create,update,patch,delete,deletecollection), both aggregated into the storage manager role (rbac.deckhouse.io/aggregate-to-storage-as: manager). On DKP 1.78 and later they are the RBACv2 capabilitiesd8:system-capability:csi-huawei:viewandd8:system-capability:csi-huawei:edit; on earlier versions they ared8:manage:permission:module:csi-huawei:viewandd8:manage:permission:module:csi-huawei:edit.
Improvements
This release improves:
- The
NodeGroupConfigurationresources (ALT Linux, RED OS-like and Ubuntu-like nodes) install the module’siscsi-toolspackage on every node instead of trying the distribution’sopen-iscsiandmultipath-toolsfirst. The package decides for each pair separately: a pair the host already has stays the host’s, and the module only enables the distribution’s unit and runsmpathconffor it; a pair the host lacks comes from the package with its own unit (d8-csi-huawei-iscsid.service,d8-csi-huawei-multipathd.service). A host withopen-iscsibut nomultipath-toolsnow gets the module’smultipathd; previously the package did nothing on any host that had aniscsiadm. Thedeferred_remove/flush_on_last_delmultipath settings are written for whichevermultipathdruns on the node. sg3-utilsis no longer installed on nodes: no code path in the driver invokes its tools. Already installed packages are not removed.- When the tools on a node change after the module’s package was installed (the host loses
iscsiadmormultipath, or a distribution package with them is installed later), theNodeGroupConfigurationreinstalls the package, so the node gets the missing pair back or the package’s daemon steps aside for the distribution’s one. Previously that decision was made once per module version.
Fixes
This release fixes:
- On an update of the
iscsi-toolspackage, the multipath plugins in/usr/lib/multipathand theiscsiadmwrapper in/usr/local/sbinleft by the previous version were taken for the host’s own files: the wrapper stayed at the old version and neither was removed when the package went away. They are now recognised as the package’s own and replaced.
Upgrade notes
Before upgrading, note the following:
- No manual action is needed. On the first bashible run after the update, nodes that have the distribution’s
open-iscsiandmultipath-toolskeep using them; nodes missing either pair get it from the module’s package. Volumes already mounted are not affected.
Docs
Documentation changes:
- The FAQ entry on where
open-iscsiandmultipath-toolson a node come from is rewritten for the per-pair installation from the module’s package, including how to tell which pair a node took from where. The FC section of the README states thatmultipathandmultipathdcome from the module’s package on nodes withoutmultipath-toolsof their own. - The
specfield ofHuaweiStorageClassnow has a description in the CRD.
Dependencies
Dependency updates:
Huawei CSI (eSDK_K8S_Plugin):4.10.1→4.12.1(changelog)- The module’s patches are carried over unchanged in behaviour;
google.golang.org/grpcstays at v1.83.2. The new upstream features (NVMe over TCP, volume health monitoring, shallow-copy snapshot restore, Hyper-Metro volumes) are not exposed byHuaweiStorageConnectionorHuaweiStorageClass.
- The module’s patches are carried over unchanged in behaviour;
v0.3.25
Release date: 2026-09-24
Security update: the Huawei CSI binaries and the module’s hooks are rebuilt against patched grpc and x/crypto.
Highlights
Changes in this release:
google.golang.org/grpcis raised from v1.82.1 to v1.83.2 in all four Huawei eSDK binaries (huaweicsi,oceanctl,storage-backend-controller,storage-backend-sidecar), closing CVE-2026-84303, CVE-2026-84304 and CVE-2026-84445.
Security updates
Security updates in this release:
google.golang.org/grpcis raised from v1.82.1 to v1.83.2 in all four Huawei eSDK binaries (huaweicsi,oceanctl,storage-backend-controller,storage-backend-sidecar), closing CVE-2026-84303, CVE-2026-84304 and CVE-2026-84445.golang.org/x/cryptois raised from v0.53.0 to v0.57.0 in the module’s hooks (go-hooks), closing CVE-2026-56854 (authentication bypass by source address inx/crypto/ssh), CVE-2026-56855 and CVE-2026-78662.
v0.3.24
Release date: 2026-09-14
A maintenance release: the module is rebuilt with the Go 1.27.1 toolchain on the v2.1.17 base images, with no change to its behaviour.
Highlights
Changes in this release:
- Every component of the module is built with Go 1.27.1 on the v2.1.17 base images. Nothing in the module’s behaviour, resources or settings changes.
Upgrade notes
Before upgrading, note the following:
- The update needs nothing done by hand. Resources, module settings and existing volumes are untouched, and the controller and node pods are only restarted with the rebuilt images.
v0.3.23
Release date: 2026-09-09
The module now installs the iSCSI stack itself on nodes whose repositories cannot provide it, lets a HuaweiStorageClass decide how much of an ext4 volume stays with the superuser, and exports controller metrics.
Highlights
Changes in this release:
- A node whose repositories have no
open-iscsiandmultipath-toolsis no longer left unusable: the module unpacks its own package image there and runs the daemons from it. - An ext4 volume no longer keeps 5% of its space for the superuser; a
HuaweiStorageClasscan ask for a share back with an annotation. - The module controller exports metrics, and Prometheus is allowed to scrape them.
New features
This release adds:
- A node that cannot install
open-iscsiandmultipath-toolsfrom its own repositories now gets them from the module: theNodeGroupConfigurationunpacks the module’siscsi-toolsimage under/var/lib/deckhouse/sds/csi-huaweiand startsd8-csi-huawei-iscsid.serviceandd8-csi-huawei-multipathd.service. The node’s own packages stay the preferred path, and a node that has them is left untouched. - The
storage.deckhouse.io/ext4-reserved-percentannotation on aHuaweiStorageClasssets the share of a volume kept for the superuser: a whole number of percent from 0 to 50. It applies to ext filesystems only, a class withfsType: xfsignores it, and an invalid value leaves theHuaweiStorageClasswithReady=Falseand the reason in its status instead of failing volume creation later. - The module controller serves metrics through a kube-rbac-proxy: reconcile counts and durations, workqueue depth, client-go latency, with a ServiceMonitor for Prometheus. The ports are configurable through the
controllerMetricsPortandcontrollerMetricsProxyPortmodule settings.
Improvements
This release improves:
- When the storage system refuses to create a volume, the
ProvisioningFailedevent now carries the message and the suggestion the array returned, not just the numeric DeviceManager error code. - Controller log lines carry their fields as key-value pairs and name the component they come from, instead of packing a prefix into the message text.
Fixes
This release fixes:
- Prometheus could not scrape the module controller: the kube-rbac-proxy in front of the metrics was not allowed to create the
TokenReviewandSubjectAccessReviewit needs, so every scrape was refused and the target stayed down. - A node could be left with
csi-nodeinCrashLoopBackOffand the driver missing from itsCSINodeobject, with volumes failing to attach there. The liveness probe of the node container watched a port served by the registrar sidecar next to it, so an exiting registrar took the driver down with it.
Upgrade notes
Before upgrading, note the following:
- The change to the ext4 superuser reserve applies to volumes created after the update; filesystems that already exist keep the reserve they were created with. Nothing has to be done by hand, and a class that wants the reserve back needs the annotation.
- The controller metrics start being scraped once the module pods are recreated by the update. A
TargetDownalert raised for the module controller clears on its own.
Docs
Documentation changes:
- Two new FAQ entries: what happens if a node’s repositories cannot provide the iSCSI stack, and how much of a volume is reserved for the superuser.
Dependencies
Dependency updates:
deckhouse_lib_helm:1.72.18→1.72.22- Carries the csi-node liveness-probe fix and the RBAC contract for the metrics proxy.
v0.3.22
- Before mounting a pre-formatted volume, a file system check for ext2/3/4 is performed (e2fsck -p): repairable errors are fixed automatically, a volume with irreparable errors is no longer mounted until manual recovery
- The FAQ now includes a procedure for recovering a volume that fails to mount due to file system errors
- Base images updated to v2.1.5, Go to 1.26.6, and lib-helm to 1.72.17
- Internal build changes for the module
v0.3.21
- Fix: the release image is no longer built from cache with an outdated changelog.yaml — git-mapping dependencies are bound to the install stage, where the file is copied
- Update base images to v2.1.4
- Internal build changes for the module
v0.3.20
- Bugfix: the controller is granted patch on events instead of list - a repeated event write is no longer denied by RBAC
v0.3.19
- Fix: multipath stops holding I/O after deleting the last path to the LUN (added flush_on_last_del setting) - eliminates node hang in NotReady
- The documentation removed the outdated example of volumeBindingMode in HuaweiStorageClass, added an example of connecting via Fiber Channel
- Update base images to v2.1.2, Go to 1.26.6 and lib-helm to 1.72.14
- Internal changes in module assembly
v0.3.18
- HuaweiStorageClass and HuaweiStorageConnection publish status.conditions and status.observedGeneration, added Ready column. The status.phase field retains the same set of values, but is now calculated from the Ready condition
- Update base images to v1.3.25, Go 1.26.5 and lib-helm to 1.72.13
v0.3.17
- Bugfix: Fixed failure to launch the csi-node pod on nodes with containerd v2 - added mounting hostPath /sys/fs/cgroup
v0.3.16
- The snapshot-controller module is no longer a required dependency: VolumeSnapshotClass is created only if the snapshot.storage.k8s.io API is available
- Update base images, Go 1.26.5 and lib-helm to 1.72.12
- Fixed a vulnerability in gRPC (GHSA-hrxh-6v49-42gf)
- Internal changes in module assembly
v0.3.15
- Update base images, Go 1.26.5 and lib-helm to 1.72.10
- Internal changes in module assembly
v0.3.14
- Bugfix: fixed csi-node pod cyclic restart caused by synchronous cleanup of legacy devices
- Fix: Deckhouse registry access secrets are now limited to the active image source
- Update base images, Go 1.26.5 and lib-helm to 1.72.9
- Internal changes in module assembly
v0.3.13
- Added automatic recovery of inaccessible Huawei storage backends
- When forwarding labels from HuaweiStorageClass to StorageClass, labels with specified ignored prefixes are now excluded
- Update base images and lib-helm to 1.72.0
v0.3.12
- Tags from HuaweiStorageClass are now forwarded to the managed StorageClass Kubernetes
- Update base images, Go 1.25.10 and lib-helm 1.71.12
v0.3.11
- Internal changes in the structure and assembly of the module
v0.3.10
- Update base images, Go 1.25.10 and lib-helm 1.71.11
- Internal changes to the module assembly
v0.3.9
- Corrections to the module structure
v0.3.8
- Documentation updated (review, broken links fixed)
- Changes in CI: DistroPackagesProxy and env proxy in werf, improvements to CVE scans (role_name, checkout)
- Added user-authz cluster roles in templates
v0.3.7
- Installing packages in NodeGroupConfiguration no longer causes the script to crash on errors
v0.3.6
- Added missing mount points in csi-huawei distroless images
- Update base images, Go and lib-helm (CVE fix)
- Clarifications in the documentation
v0.3.5
- Added list of supported storage systems
v0.3.4
- Changes for distroless (complete rejection of nsenter where possible)
v0.3.3
- Fixes for regression when resizing a volume that arose as a result of switching to distroless (fixed too narrow mounting of /sys from the host)
v0.3.2
- Corrections for regression when remounting a volume that arose as a result of switching to distroless (in some cases the WWN of the volumes does not match)
v0.3.1
- Corrections for regression when remounting a volume that arose as a result of switching to distroless (in some cases the WWN of the volumes does not match)
v0.3.0
- Translation of the module into distroless (with active patching of the original CSI, which is not suitable for this)
- Changes in documentation
- Update base images and golang version
- Updated hooks that work when a module is removed
- Disabled Capacity request from k8s (CSI does not support issuing Capacity)
v0.2.9
- Corrections to the logic of working with volume snapshots
v0.2.8
- Edits to documentation
- Edits in manifestos
- Corrections to the logic of working with volume snapshots
- Update base images
v0.2.7
- Updated base images versions
v0.2.6
- Updated Go version to 1.24.9
- Updated lib-helm to deckhouse_lib_helm-1.64.1
v0.2.5
- Added release notes
v0.2.4
- Added information about the need for snapshot-controller for module operation
- Added readonlyRootFilesystem for enhanced module security
v0.2.3
- Added dependency on snapshot-controller
v0.2.2
- Added instructions for using Huawei storage systems in multiple Kubernetes clusters
v0.2.1
- Updated CSI to version v4.11.0
- CVE fix
- Added hook that removes unnecessary resources remaining after module deletion
v0.1.1
- Updated golang to 1.23.6
- Removed Experimental status
v0.1.0
- Initial release, basic functionality works