The module lifecycle stage: Generally available version

The module has requirements for installation

v0.2.32

Release date: 2026-10-01

The iSCSI, multipath and NVMe tools on a node now always come from the module’s own packages instead of the distribution’s repositories, and the module grants access to its resources through the RBACv2 roles of DKP 1.78.

Highlights

Changes in this release:

  • The NodeGroupConfiguration no longer asks the node’s package manager for open-iscsi, multipath-tools or nvme-cli: a node without a route to its repositories no longer waits for them on every bashible run, and the tools a node lacks come from the module’s iscsi-tools and nvme-tools packages.
  • On DKP 1.78 and later the module ships the d8:system-capability:csi-yadro-tatlin-unified:view and d8:system-capability:csi-yadro-tatlin-unified:edit roles for YadroTatlinUnifiedStorageClass and YadroTatlinUnifiedStorageConnection.

New features

This release adds:

  • The module ships RBACv2 roles for its cluster-scoped resources YadroTatlinUnifiedStorageClass and YadroTatlinUnifiedStorageConnection: view grants get, list and watch, edit grants create, update, patch, delete and deletecollection. On DKP 1.78 and later they are the capabilities d8:system-capability:csi-yadro-tatlin-unified:view and d8:system-capability:csi-yadro-tatlin-unified:edit with rbac.deckhouse.io/scope: system; on earlier DKP versions the same rules come as d8:manage:permission:module:csi-yadro-tatlin-unified:view and d8:manage:permission:module:csi-yadro-tatlin-unified:edit. view is aggregated into the storage viewer role and edit into the storage manager role.

Improvements

This release improves:

  • The NodeGroupConfiguration installs the iscsi-tools package on every node the module serves, and nvme-tools on every such node where NVMe-TCP is configured, instead of trying the distribution’s open-iscsi, multipath-tools and nvme-cli first. iscsi-tools now decides for each pair separately: an iscsiadm/iscsid or multipath/multipathd pair the host already has stays the host’s and only its distribution unit is enabled, a missing pair lands under /var/lib/deckhouse/sds/csi-yadro-tatlin-unified with a d8-csi-yadro-tatlin-unified-* unit of its own. A host with open-iscsi but no multipath-tools now gets the module’s multipathd; previously the module’s package stepped aside as soon as the host had any iscsiadm. nvme-tools still lands nvme only on a host that has none.
  • spec.controlPlane.nodeSelector and spec.dataPlane.nodeSelector of YadroTatlinUnifiedStorageConnection are now atomic for server-side apply: a selector is replaced as a whole instead of being merged field by field between two appliers. Every matchExpressions item now requires key and operator; an item without them selected nothing before.

Fixes

This release fixes:

  • A node whose own tools changed after the module’s package was installed is set up again on the next bashible run. The package’s install step ran only once per module version, so a tool the host later lost stayed missing until the next release, and a distribution package installed later ran its daemon next to the module’s. The NodeGroupConfiguration now compares, for iscsiadm, multipathd and nvme, whether the host and the package provide it, and reinstalls the package when the two no longer agree.
  • Files that an earlier version of iscsi-tools or nvme-tools put outside its own directory, such as the /usr/local/sbin/iscsiadm and /usr/local/sbin/nvme wrappers and the multipath links and plugins, are no longer mistaken for the host’s own after an update and are removed when the package is uninstalled.

Upgrade notes

Before upgrading, note the following:

  • Nothing has to be done by hand. Nodes that already run the distribution’s iscsid, multipathd or nvme keep them; a node that relies on the module’s packages keeps them as well. A node that needs the distribution’s tools from now on has to have them installed by an administrator: on the next bashible run the module notices them and steps aside for that pair.

Docs

Documentation changes:

  • The FAQ entry on open-iscsi, multipath-tools and nvme-cli now describes where each tool on a node comes from, which files the module’s packages put on the host and how to check which pair a node took from where.
  • The reference for YadroTatlinUnifiedStorageClass now describes spec, and the reference for YadroTatlinUnifiedStorageConnection describes the matchExpressions items of both node selectors, in English and Russian.

v0.2.31

Release date: 2026-09-24

Security update: the CSI driver and the module’s hooks are rebuilt against patched grpc and x/crypto.

Highlights

Changes in this release:

  • google.golang.org/grpc is raised from v1.82.1 to v1.83.2 in the CSI driver (csi-tatlin-u), closing CVE-2026-84303, CVE-2026-84304 and CVE-2026-84445.

Security updates

Security updates in this release:

  • google.golang.org/grpc is raised from v1.82.1 to v1.83.2 in the CSI driver (csi-tatlin-u), closing CVE-2026-84303, CVE-2026-84304 and CVE-2026-84445.
  • golang.org/x/crypto is raised from v0.53.0 to v0.57.0 in the module’s hooks (go-hooks), closing CVE-2026-56854 (authentication bypass by source address in x/crypto/ssh), CVE-2026-56855 and CVE-2026-78662.

v0.2.30

Release date: 2026-09-14

The module now installs the iSCSI and NVMe userspace itself where a node’s repositories cannot, exports metrics for the controller and the scheduler extender, and no longer hands 5% of every ext4 volume to the superuser.

Highlights

Changes in this release:

  • A node whose repositories cannot provide open-iscsi, multipath-tools or nvme-cli is no longer left unable to attach a volume: the module installs them from package images of its own.
  • The controller and the scheduler extender export metrics, scraped through the kube-rbac-proxy of their pod; a ServiceMonitor and a PodMonitor ship with the module.
  • An ext4 volume no longer keeps 5% of its space for the superuser, and a YadroTatlinUnifiedStorageClass can ask for a share back with an annotation.

New features

This release adds:

  • Where a node’s package manager cannot install open-iscsi and multipath-tools, the NodeGroupConfiguration falls back to the module’s own iscsi-tools image: the payload is unpacked under /var/lib/deckhouse/sds and the daemons come up as d8-csi-yadro-tatlin-unified-iscsid.service and d8-csi-yadro-tatlin-unified-multipathd.service. A node that already has open-iscsi of its own is left untouched, because a client of one version does not speak to a daemon of another.
  • nvme-cli gets a package image and a fallback of its own, nvme-tools, used only where the module is configured for NVMe-TCP. Its fallback is independent of the iSCSI one: a distribution may provide one set and not the other. Without nvme-cli a node kept no NVMe Qualified Name and the driver reported initiators is empty for every volume it was asked to publish there.
  • The controller and the scheduler extender serve metrics behind a kube-rbac-proxy: the component binds on 127.0.0.1 and the proxy publishes it over TLS behind an authorization check. A ServiceMonitor for the controller and a PodMonitor for the extender are part of the module, and the ports are settable through the controllerMetricsPort, controllerMetricsProxyPort, schedulerExtenderMetricsPort and schedulerExtenderMetricsProxyPort module values.
  • The storage.deckhouse.io/ext4-reserved-percent annotation on a YadroTatlinUnifiedStorageClass sets the share of a volume kept for the superuser: a whole number from 0 to 50. It applies only to volumes created after the annotation was set, a class with fsType: xfs ignores it, and an invalid value leaves the YadroTatlinUnifiedStorageClass with Ready=False and the reason in its status instead of failing volume creation later. Changing the annotation makes the controller recreate the StorageClass, because the parameters of an existing one are immutable in Kubernetes.

Improvements

This release improves:

  • An ext4 volume is now formatted with no superuser reserve at all. Every volume this module created before handed ext4’s default 5% to root, because the formatting step passed no -m; volumes created from now on give that space to the workload.
  • The controller and the scheduler extender log through one shared logger in the structured format the rest of the fleet uses.
  • The default logLevel is now INFO instead of DEBUG, which is what a cluster that never set it explicitly will get.

Fixes

This release fixes:

  • The CSI Pods no longer wait for a YadroTatlinUnifiedStorageConnection to exist before they start. Both Secrets they mount are written by the controller while it reconciles a connection, and the chart required those volumes, so on a fresh install every CSI Pod sat in ContainerCreating with secret not found and the driver was down until somebody declared a connection. The mounts are optional now, and kubelet fills them in once the Secrets appear.

Upgrade notes

Before upgrading, note the following:

  • Nothing has to be done by hand. The new packages are installed only on nodes where the distribution packages cannot be, and nodes that already carry their own stack are not touched.
  • The ext4 superuser reserve changes for volumes created after the update only. Filesystems that already exist keep the 5% they were formatted with; to keep a reserve on new volumes, annotate the class with storage.deckhouse.io/ext4-reserved-percent=5.
  • A cluster that relied on the previous default verbosity should set logLevel: DEBUG in the module configuration explicitly, because the default is now INFO.

v0.2.29

  • Fix: successful mount is no longer considered an error — the image now includes /etc/mtab (a symlink to /proc/self/mounts), whose absence previously caused mount to return exit code 16. The wrap-mount wrapper is now limited to iscsiadm and no longer replaces mount
  • Fix: the release image is no longer built from a cache with an outdated changelog.yaml — git-mapping dependencies are tied to the install stage, where the file is copied
  • Internal build changes for the module

v0.2.28

  • Bugfix: the controller is granted patch on events instead of list - a repeated event write is no longer denied by RBAC
  • Bugfix: the VPA is switched from the deprecated Auto update mode to InPlaceOrRecreate
  • Optional resources are enabled based on the presence of the CRD in the API, not on the list of enabled modules
  • CVE fixes
  • Base images updated to v2.1.2, Go to 1.26.6 and lib-helm to 1.72.14

v0.2.27

  • YadroTatlinUnifiedStorageClass and YadroTatlinUnifiedStorageConnection publish status.conditions and status.observedGeneration, added Ready column. The status.phase field retains the same set of values, but is now calculated from the Ready condition
  • Update base images to v1.3.25, Go 1.26.5 and lib-helm to 1.72.13

v0.2.26

  • The snapshot-controller module is no longer a required dependency: VolumeSnapshotClass is created only if the snapshot.storage.k8s.io API is available
  • Update base images, Go 1.26.5 and lib-helm to 1.72.12
  • Fixed a vulnerability in gRPC (GHSA-hrxh-6v49-42gf)
  • Internal changes in module assembly

v0.2.25

  • Driver update to vendor version v26.06
  • Bugfix: numerous fixes in the operation of the NVMe-over-TCP mode
  • Bugfix: secret deckhouse-registry scope limited to active image source
  • Fixed vulnerabilities in third-party dependencies
  • Internal changes in module assembly

v0.2.24

  • Updating container-base images to v1.1.2

v0.2.23

  • Fixed mount paths in the scheduler-extender image
  • Added instructions for setting up NQN hosts for NVMe-over-TCP to the documentation

v0.2.22

  • When forwarding labels from YadroTatlinUnifiedStorageClass to StorageClass, labels with specified ignored prefixes are now excluded
  • Updated CSI driver to version yadro/tatlin-unified v26.02

v0.2.21

  • Added support for the NVMe-over-TCP protocol in YadroTatlinUnifiedStorageConnection (requires Tatlin Unified Gen2 with firmware 3.2.0 or later and a pre-created access group of type nvme)
  • Update base images and lib-helm to 1.72.0

v0.2.20

  • Labels from YadroTatlinUnifiedStorageClass are now forwarded to the managed StorageClass Kubernetes
  • Update base images, Go 1.25.10 and lib-helm 1.71.12

v0.2.19

  • Internal changes in the structure and assembly of the module

v0.2.18

  • Update base images, Go 1.25.10 and lib-helm 1.71.11
  • Internal changes to the module assembly

v0.2.17

  • Changes in CI: DistroPackagesProxy and env proxy in werf, improvements to CVE scans (role_name, checkout)
  • Added user-authz cluster roles in templates

v0.2.16

  • Installing packages in NodeGroupConfiguration no longer causes the script to crash on errors
  • Replacement of yum with bb-dnf, separation of NGC for Debian and Altlinux, unification of naming

v0.2.15

  • Added missing mount points in the csi-yadro-tatlin-unified distroless image
  • Update base images, Go and lib-helm

v0.2.14

  • CVE fixes
  • Documentation edits

v0.2.13

  • Update base images and golang version
  • Updated hooks that work when a module is removed

v0.2.12

  • Reworking module manifests
  • Update CSI version to 25.12

v0.2.11

  • Fix CVE
  • Fix manifests

v0.2.10

  • Updated base images versions
  • Updated Go to 1.24.11
  • Updated lib-helm to deckhouse_lib_helm-1.64.10
  • Added volumesnapshotclass annotation to StorageClass for compatibility
  • Fixed build of CSI
  • Updated CSI

v0.2.9

  • Updated base images versions

v0.2.8

  • Updated Go version to 1.24.9
  • Updated lib-helm to deckhouse_lib_helm-1.64.1

v0.2.7

  • Updated sources for CVE fix

v0.2.6

  • Updated Go version to 1.24.8
  • Updated lib-helm to deckhouse_lib_helm-1.63.6

v0.2.5

  • Added release notes
  • Module refactoring
  • Switched to csi service account
  • Added support for containerd v2
  • Switch to distroless image

v0.2.4

  • Added postStop hook for socket file cleanup when stopping csi-node
  • Added HA mode support for CSI controller

v0.2.3

  • Added nodeSelector parameter to specify nodes with workload

v0.2.0

  • CSI update to version 25.04
  • Several bug fixes

v0.1.1

  • Multiple fixes to comply with style guides
  • Migration of hooks to Golang

v0.1.0

  • Module rollout after renaming (old one left with deprecated mark)