The module lifecycle stage: Preview

The module has requirements for installation

v0.3.18

Release date: 2026-10-01

The module now takes the iSCSI stack only from its own package, its metrics are actually scraped, raw block volumes no longer read stale data left by a previous volume, and DKP 1.78 gets the capability/scope access roles.

Highlights

Changes in this release:

  • The NodeGroupConfiguration no longer asks a node’s package manager for open-iscsi, multipath-tools and sg3-utils: it always installs the module’s own iscsi-tools package, which keeps each pair of tools the host already has and supplies only the missing one.
  • Metrics of the controller and the CSI driver, introduced in v0.3.16, are now actually scraped: the kube-rbac-proxy sidecars of the module’s pods could not authenticate Prometheus, so every scrape got 401 and the targets stayed down with a permanent TargetDown.
  • Staging a raw block volume (volumeMode: Block) now drops the page cache of its multipath device, so a pod no longer reads data cached from another volume that used the same multipath map name on that node.

New features

This release adds:

  • On DKP 1.78 and later the module ships its access roles in the capability/scope scheme: d8:system-capability:csi-scsi-generic:view and d8:system-capability:csi-scsi-generic:edit for the cluster-scoped SCSIStorageClass, SCSITarget and SCSIDevice, and d8:namespace-capability:csi-scsi-generic:view and d8:namespace-capability:csi-scsi-generic:edit for PendingResizeRequest. The version is taken from global.deckhouseVersion; below 1.78 the previous d8:manage:permission:module:csi-scsi-generic:* and d8:use:capability:module:csi-scsi-generic:* roles are rendered unchanged.

Improvements

This release improves:

  • The iSCSI stack comes only from the module’s iscsi-tools package; a node without access to its distribution repositories no longer waits out the package manager on every bashible run. The package decides for each pair separately, iscsiadm with iscsid and multipath with multipathd: a pair the host has stays the host’s and only its distribution unit is enabled, a missing pair is installed under /var/lib/deckhouse/sds/csi-scsi-generic and runs as d8-csi-scsi-generic-iscsid.service or d8-csi-scsi-generic-multipathd.service. A host with open-iscsi but no multipath-tools now gets the module’s multipathd, which it did not before.
  • When the tools of a node change after the package was installed (a host tool removed, or a distribution package installed next to the module’s), the NodeGroupConfiguration runs the package install again, so the node neither stays without a tool nor runs two copies of the same daemon. A unit of the module’s left for a pair that the host now provides is disabled and removed.

Fixes

This release fixes:

  • The kube-rbac-proxy sidecars of the controller, the CSI controller and the CSI node are bound to d8:rbac-proxy, so they can authenticate Prometheus scrapes. Before that every scrape got 401, up stayed 0 and TargetDown fired permanently; nothing has to be changed in the module configuration.
  • Staging a raw block volume (volumeMode: Block) runs blockdev --flushbufs on its multipath device, as was already done for filesystem volumes. A multipath map name is reused on a node, and the host page cache, which kubelet’s loop device and any container opening the device without O_DIRECT read through, could still hold another volume. A failed flush is logged and does not fail the stage.
  • The CSI node driver no longer panics when an iSCSI session is logged out between two session listings during volume attach; the attach now fails with not all sessions exist for IQN ..., but no portal is reported missing and is retried.
  • On upgrade, the multipath path checkers that an earlier version of the iscsi-tools package had put into /usr/lib/multipath are no longer mistaken for the host’s own files, so the package’s uninstall removes them.

Upgrade notes

Before upgrading, note the following:

  • On nodes where the distribution’s open-iscsi or multipath-tools is not installed, the module’s own copy is used from now on instead of installing distribution packages. Packages that are already installed are not removed and keep being used. sg3-utils is no longer installed by the module; install it yourself if you need its tools on the nodes.
  • On DKP 1.78 and later the legacy ClusterRoles d8:manage:permission:module:csi-scsi-generic:{view,edit} and d8:use:capability:module:csi-scsi-generic:{view,edit} are replaced by the d8:system-capability:* and d8:namespace-capability:* roles. A RoleBinding or ClusterRoleBinding that references a legacy role by name must be pointed to the new one.

Docs

Documentation changes:

  • The FAQ entry on open-iscsi and multipath-tools now describes where a node’s iSCSI stack comes from, how each pair is chosen, and how to check which source a node uses.

v0.3.17

Release date: 2026-09-24

Security update: the CSI driver and the controller are rebuilt against google.golang.org/grpc v1.83.2.

Highlights

Changes in this release:

  • google.golang.org/grpc is raised from v1.82.1 to v1.83.2 in the CSI driver and the controller, closing CVE-2026-84303, CVE-2026-84304 and CVE-2026-84445.

Security updates

Security updates in this release:

  • google.golang.org/grpc is raised from v1.82.1 to v1.83.2 in the CSI driver and the controller, closing CVE-2026-84303, CVE-2026-84304 and CVE-2026-84445.

v0.3.16

Release date: 2026-09-14

The module now exposes metrics for the controller and the CSI driver, installs the iSCSI stack itself where a node’s repositories cannot provide it, and lets a StorageClass ask for an ext4 superuser reserve.

Highlights

Changes in this release:

  • The controller and the CSI driver serve operation metrics, scraped through the kube-rbac-proxy of their own pod; a PodMonitor for each ships with the module.
  • Where a node’s package manager cannot install open-iscsi and multipath-tools, the module installs them from its own iscsi-tools image instead of leaving the node without an iSCSI stack.
  • The storage.deckhouse.io/ext4-reserved-percent annotation on a SCSIStorageClass sets the share of an ext4 filesystem kept for the superuser.

New features

This release adds:

  • The controller and the CSI driver record what they serve. The CSI driver publishes csi_scsi_generic_csi_operations_total and csi_scsi_generic_csi_operation_duration_seconds; both the controller and the driver are scraped over TLS through the kube-rbac-proxy of their pod, and a PodMonitor for each is part of the module.
  • Three ports carry those metrics on the node, all settable in the module values: controllerMetricsPort (8080) for the controller, csiControllerMetricsPort (4266) and csiNodeMetricsPort (4267) for the CSI controller and the CSI node. The CSI pods are hostNetwork, so the last two are node-level ports.
  • When a node’s package manager cannot install open-iscsi and multipath-tools, the module falls back to its own iscsi-tools package image: the payload is unpacked under /var/lib/deckhouse/sds/csi-scsi-generic and the daemons come up as d8-csi-scsi-generic-iscsid.service and d8-csi-scsi-generic-multipathd.service. A node that already has a stack of its own keeps it untouched, and an existing /etc/iscsi/initiatorname.iscsi is never rewritten, so a node keeps the IQN the array knows it by.
  • The storage.deckhouse.io/ext4-reserved-percent annotation on a SCSIStorageClass sets the percentage of a volume kept for the superuser: a whole number from 0 to 50, still 0 by default. It applies only to volumes created after the annotation was set, is ignored with a warning in the node log for fsType: xfs, and an invalid value puts the SCSIStorageClass into the Failed phase with the reason in status.reason instead of failing volume creation later. Changing the annotation makes the controller recreate the StorageClass, because the parameters of an existing one are immutable in Kubernetes; existing volumes and PVCs are not affected.

Improvements

This release improves:

  • The controller and the CSI driver log through one logger on a single LOG_LEVEL scale, so the same value means the same verbosity in every component of the module.
  • The default logLevel is now INFO instead of DEBUG, which is what a cluster that never set it explicitly will get.

Fixes

This release fixes:

  • A SCSI device identified by an EUI identifier (a WWID with the 6 prefix) no longer panics the controller in the block device filter reconciler.

Upgrade notes

Before upgrading, note the following:

  • Nothing has to be done by hand. A cluster that relied on the previous default verbosity should set logLevel: DEBUG in the module configuration explicitly, because the default is now INFO.
  • The CSI pods are hostNetwork and now bind ports 4266 and 4267 on every node they run on. Both are registered in the Deckhouse port reference; change them in the module values only if something else on the node already holds them.

v0.3.15

  • libiscsi updated to 0.0.6 based on upstream 1.20.3: fixed remotely triggerable memory handling errors during data-in parsing, added CHAP-SHA1 support, iscsi-ls no longer truncates JSON if the target publishes an inaccessible portal
  • Fix: the iscsi-command service (0.0.10) reads stdout of iscsi-ls separately from stderr, so a diagnostic line next to a correct listing no longer breaks JSON parsing; the child process terminates on request cancellation or timeout
  • Removed the unused libiscsi artifact (source code, build tree, and shared libraries) from the controller image — its CVE surface area is also removed from the image
  • Fix: the release image is no longer built from a cache with an outdated changelog.yaml — git-mapping dependencies are tied to the install stage where the file is copied
  • Base images updated to v2.1.4
  • Internal build changes for the module

v0.3.14

  • Bugfix: the controller is granted patch on events instead of list - a repeated event write is no longer denied by RBAC
  • Optional resources are enabled based on the presence of the CRD in the API, not on the list of enabled modules
  • Base images updated to v2.1.2, Go to 1.26.6 and lib-helm to 1.72.14

v0.3.13

  • Bugfix: targets are re-detected again - due to the TTL being extended on each read, the target was detected once during the life of the controller, and the LUN presented after the start was never picked up. The re-detection interval is included in a separate parameter TARGET_RESCAN_INTERVAL with a default value of 5 minutes
  • SCSIStorageClass, SCSITarget and SCSIDevice publish status.conditions and status.observedGeneration, added Ready column
  • SCSIDevice: custom condition type and status.aggregatedStatus field replaced with standard metav1.Condition, status.phase field is now calculated from conditions, Attached, Mounted and Error conditions are published
  • Controller errors are no longer suppressed by a fixed retry after 3 seconds, but are returned to controller-runtime - this enables exponential delay of retries and accounting for errors in metrics
  • Update base images to v1.3.25, Go 1.26.5 and lib-helm to 1.72.13

v0.3.12

  • Fixed launching module components - the hostPath /sys/fs/cgroup mount, removed in v0.3.11 as redundant, has been returned and added to the module controller, where it was not there. Mounting is needed not by the driver, but by the container launch environment - when mounting the host /sys, the sysfs substitution for privileged containers is replaced, and the cgroup is mounted before /sys, in the directory of the distroless image (an image without a package environment), where /sys/fs is missing and cannot be created due to readOnlyRootFilesystem
  • Fixed mounting of initiatorname.iscsi - instead of hostPath of type File, the /etc/iscsi directory is mounted. Previously, on a node with unconfigured open-iscsi under the controller, it remained forever in ContainerCreating, and the only diagnostic was the kubelet event; now the controller starts and reports the absence of the initiator name in its log
  • Removed unnecessary mounting of /etc/iscsi into the iscsi-command-service container - the service receives the initiator name via gRPC and does not access the file, and the file was not readable by an unprivileged user
  • Updated base images v1.3.21, Go 1.26.5 and lib-helm to 1.72.12

v0.3.11

  • Fixed SCSIDevice status update - a device in Bound state no longer loses the list of SCSI targets if background scanning did not detect them (this reset the device size to zero, put it in Degraded and broke volume deletion)
  • Fixed a race when connecting a device - the module waits for the appearance of the symlink /dev/disk/by-id/scsi-, which udev creates asynchronously, instead of trying to read it once
  • Removed redundant hostPath /sys/fs/cgroup mounts from the CSI controller and CSI node containers - the driver does not work with cgroups, and the host /sys is already mounted entirely
  • Fixed the GHSA-hrxh-6v49-42gf vulnerability in google.golang.org/grpc, updated the dependency to 1.82.1
  • Update base images v1.3.10, Go 1.26.5 and lib-helm to 1.72.10
  • Internal changes in module assembly

v0.3.10

  • Update base images, Go 1.26.5 and lib-helm to 1.72.9
  • Internal changes in module assembly

v0.3.9

  • Fixed the formation of the registry access secret (deckhouse-registry): now it only includes authorization data for the active image source
  • Added Fiber Channel configuration examples to the documentation
  • Updating container-base images to v1.1.8, Go 1.26.4 and lib-helm to 1.72.4

v0.3.8

  • When forwarding labels from SCSIStorageClass to StorageClass, labels with specified ignored prefixes are now excluded
  • Update base images and lib-helm to 1.72.0

v0.3.7

  • Labels from SCSIStorageClass are now forwarded to the managed StorageClass Kubernetes
  • Update base images, Go 1.25.10 and lib-helm 1.71.12

v0.3.6

  • Internal changes in the structure and assembly of the module

v0.3.5

  • Update base images, Go 1.25.10 and lib-helm 1.71.11
  • Internal changes to the module assembly

v0.3.4

  • Changes in CI: DistroPackagesProxy and env proxy in werf, improvements to CVE scans (role_name, checkout)
  • Added user-authz cluster roles in templates

v0.3.3

  • Installing packages in NodeGroupConfiguration no longer causes the script to crash on errors

v0.3.2

  • Added missing mount points in csi-scsi-generic distroless images
  • Update base images, Go and lib-helm
  • Translation of resource documentation

v0.3.1

  • CVE fixes

v0.3.0

  • Update base images and golang version for CVE fixes
  • Refactoring of image assembly for transfer to distroless

v0.2.10

  • Update base images and golang version
  • Updated hooks that work when a module is removed
  • Disabled Capacity request from k8s (CSI does not support issuing Capacity)
  • Edits of module manifests and documentation

v0.2.9

  • Updated base images versions

v0.2.8

  • Updated Go version to 1.24.9
  • Updated lib-helm to deckhouse_lib_helm-1.64.1

v0.2.7

  • Updated Go version to 1.24.8
  • Updated lib-helm to deckhouse_lib_helm-1.64.1

v0.2.6

  • CVE fixes

v0.2.5

  • Updated Go version to 1.24.8
  • Updated lib-helm to deckhouse_lib_helm-1.63.6

v0.2.4

  • Added release notes

v0.2.3

  • Changes for containerd v2 support

v0.2.2

  • Added readonlyRootFilesystem for enhanced module security

v0.2.1

  • CVE fixes

v0.2.0

  • Module refactoring
  • Added HA mode support
  • Added hiding of used devices from sds-node-configurator module
  • Fixed bugs related to multipathd
  • Extended documentation

v0.1.2

  • Support for automatic filesystem resize when volume size changes (and semi-automatic volume expansion requests)

v0.1.1

  • Multiple improvements and fixes in FibreChannel operations

v0.1.0

  • Initial release, basic functionality is working