Available with limitations in: CE
Available without limitations in: BE, SE, SE+, EE
The module lifecycle stage: Preview
The module has requirements for installation
The module is only guaranteed to work if the system requirements are met. As for any other configurations, the module may work, but its smooth operation is not guaranteed.
Requirements
To the Kubernetes version: 1.31 and above.
To the Deckhouse version: 1.72 and above.
To the versions of other modules:
-
sds-node-configurator: 0.6.1 and above.
Conversions
The module is configured using the ModuleConfig resource, the schema of which contains a version number. When you apply an old version of the ModuleConfig schema in a cluster, automatic transformations are performed. To manually update the ModuleConfig schema version, the following steps must be completed sequentially for each version:
-
Updates from version 1 to 2:
Need to remove the
.enableThinProvisioningparameter.
Parameters
Schema version: 2
-
-
objectsettings.backupModule backup settings
-
booleansettings.backup.enabledModule backup state
Default:
true -
integersettings.backup.retentionCountNumber of backups to keep
Default:
7 -
stringsettings.backup.scheduleBackup schedule
Default:
0 3 * * *
-
-
objectsettings.dataNodesSettings for Linstor on nodes with data
Default:
{}-
objectsettings.dataNodes.nodeSelector
The same as in the Pods
spec.nodeSelectorparameter in Kubernetes.If parameter is omitted, Linstor nodes will be placed on all nodes.
Caution! Changing this parameter does not result in data redistribution. If node with data no longer matches the
nodeSelector, data on that node will become inaccessible.Default:
{ "kubernetes.io/os": "linux" }
-
-
objectsettings.drbdPortRangeSettings for DRBD TCP ports
Default:
{}-
integersettings.drbdPortRange.maxPortDRBD ports range end
Default:
7999 -
integersettings.drbdPortRange.minPortDRBD ports range start
Default:
7000
-
-
stringsettings.logLevelModule log level
Default:
INFOAllowed values:
ERROR,WARN,INFO,DEBUG,TRACE -
booleansettings.newControlPlane
When true, use the new control-plane as a backend for the module. Once switched to true, reverting back to false is prohibited.
Enabling it is only allowed on Deckhouse development builds; on any release channel the setting is rejected and ignored.
Default:
false -
stringsettings.registrySchemeDeprecated parameter. Remove it from ModuleConfig for Deckhouse with version greater than 1.57.
Default:
https -
integersettings.resyncSlotsPerNode
How many concurrent resyncs a single node may take part in.
0, the default, means no limit: the limiter is opt-in and has to be switched on deliberately.A resync is the transfer of a volume’s contents over the network into a replica that has no data yet or whose data is stale. It is counted in resync ends: a transfer between two nodes occupies one end on the sending node (reading its disk and pushing to the network) and one on the receiving node (receiving and writing). This parameter caps the number of ends per node, because the bottleneck is the network interface and the disk of that particular node — not the volume, not the replica, and not the cluster as a whole.
When every node that could send a replica its data is already at the limit, placement of that replica is deferred and retried; nothing is interrupted. A resync already in progress is never aborted, since that would discard everything already transferred.
Volumes that are still being created are never deferred, but the load of their resyncs is still counted, so that recovery of an existing volume does not oversubscribe a node that volume creation is already using.
A good value to start from is
2— the smallest that still lets a node send and receive at the same time. Switching the limit on defers the placement of replicas that would otherwise be placed at once, so expect recovery of a large cluster to take visibly longer.Caution! This parameter and the DRBD resync rate ceiling are configured independently. Their product must stay within the throughput of the node’s link.
Default:
0Allowed values:
0 <= X -
array of stringssettings.storageClassLabelIgnoredPrefixes
List of label-key prefixes that MUST NOT be propagated from a ReplicatedStorageClass to the managed Kubernetes StorageClass.
The controller treats this list as a complement to a built-in (system) list and drops any ReplicatedStorageClass label whose key starts with any prefix from either list.
Matching is literal
strings.HasPrefix(Go semantics): an entry without a trailing/matches by substring, NOT by full label key. For example,teamwould drop every key starting withteam(team,team-id,team.example.com/...). To restrict matching to a specific subdomain, end the entry with/(e.g.argocd.argoproj.io/). To target an exact label key, write the full key and be aware it also matches keys whose name extends it (e.g.app.kubernetes.io/managed-byalso dropsapp.kubernetes.io/managed-by-foo).Note that
kubernetes.io/in the system list matches only labels whose key literally starts withkubernetes.io/; reserved subdomains such astopology.kubernetes.io/zoneornode.kubernetes.io/*are NOT covered by default — add them here explicitly if your environment requires it.The defaults cover labels typically added by GitOps tooling (Argo CD, Flux, Rancher Fleet) so that their reconcilers do not fight the storage controller over labels on the managed StorageClass.
Default:
[ "argocd.argoproj.io/", "kustomize.toolkit.fluxcd.io/", "helm.toolkit.fluxcd.io/", "fleet.cattle.io/" ]
-