All Products
Search
Document Center

Container Service for Kubernetes:Use static volumes with CPFS General-purpose Edition

Last Updated:Aug 31, 2026

This topic explains how to mount a statically provisioned Cloud Parallel File System (CPFS) General-purpose Edition volume to a workload in an ACK cluster. CPFS is designed for high-performance computing (HPC) workloads such as AI training, autonomous driving, gene computing, and video rendering.

How it works

The main workflow for mounting a CPFS General Purpose static storage volume in an ACK cluster is as follows.

image
  1. Create a PV: "Register" an existing CPFS General Purpose file system in the cluster by declaring its mount address, capacity, access mode, and other parameters.

  2. Create a PVC: Applications "request" registered storage resources through a PVC. The PVC automatically binds to a PV that meets the specified conditions.

  3. Mount in the application: Mount the bound PVC to the application Pod as a persistent directory inside the container.

Prerequisites

  • Check and upgrade CSI components: Ensure that the csi-plugin and csi-provisioner component versions are no earlier than v1.22.11-abbb810e-aliyun.

    To upgrade, see Upgrade CSI components.
  • The storage component has been configured to support CPFS mounting.

    Configuration procedure

    The configuration method depends on your csi-plugin version.

    csi-plugin 1.33 or later

    Install the cnfs-nas-daemon component and configure csi-plugin to enable the AlinasMountProxy=true FeatureGate so that CSI subsequently calls cnfs-nas-daemon for mounting. For detailed instructions, see Manage the cnfs-nas-daemon add-on.

    csi-plugin earlier than 1.33

    1. Configure ConfigMap to enable the NFS protocol used when mounting CPFS General Purpose.

      cat << EOF | kubectl apply -f -
      apiVersion: v1
      kind: ConfigMap
      metadata:
        name: csi-plugin
        namespace: kube-system
      data:
        cpfs-nas-enable: "true"
      EOF
    2. Restart csi-plugin to install related dependencies.

      This operation does not affect normal business operations.

      kubectl -n kube-system rollout restart daemonset csi-plugin

      Expected output:

      daemonset.apps/csi-plugin restarted
  • A CPFS General Purpose file system, a protocol service, and a mount address accessible to the ACK cluster have been prepared.

    If not yet created, Create a CPFS General-purpose Edition file system in the region where the cluster resides, use the VPC and vSwitch corresponding to the cluster to Create a protocol service, and generate a mount point.

    • File system: Must be CPFS General Purpose supported regions, located in the same region as the cluster, with version 2.3.0 or later.

      On the File System List page of the NAS console, click the target CPFS file system, and confirm the CPFS version number on the Basic Information page.
    • Protocol service: CPFS does not support cross-VPC mounting. The VPC used must be the same as the cluster.

    • Obtain the mount address of the protocol service (consisting of the mount point domain name and export directory). If the export / directory is specified, the mount address is cpfs-****.<Region ID>.cpfs.aliyuncs.com:/share.

      On the Protocol Service page, click Export Directory, and copy and save the mount address in the Mount address column.
  • You have understood the Limits of CPFS General Purpose.

Step 1: Create a PV

Create a PV in the cluster to "register" an existing CPFS file system.

  1. Save the following content as a cpfs-pv.yaml file.

    apiVersion: v1
    kind: PersistentVolume
    metadata:
      name: cpfs-pv
      labels:  # Define labels for subsequent PVC binding
        alicloud-pvname: cpfs-pv
    spec:
      accessModes:  # Access mode
      - ReadWriteMany
      capacity:
        storage: 20Gi  # Define the total capacity of the PV
      csi:
        driver: nasplugin.csi.alibabacloud.com  # Fixed to this value
        volumeAttributes:
          mountProtocol: cpfs-nfs   # Use the NFS protocol for mounting
          path: "/share"    # The mount directory in the mount address
          volumeAs: subpath    # Subdirectory
          server: "cpfs-******-******.cn-shanghai.cpfs.aliyuncs.com" # The mount point domain name in the mount address
        volumeHandle: cpfs-pv  # Unique identifier of the volume, must be consistent with metadata.name       
      mountOptions:  # NFS mount options
      - rsize=1048576,wsize=1048576,hard,timeo=600,retrans=2,noresvport
      - vers=3

    Key parameter description:

    Parameter

    Description

    accessModes

    Access mode for the PV.

    capacity.storage

    Storage capacity of the volume.

    csi.driver

    Driver type. When using CPFS General Purpose, this is fixed to nasplugin.csi.alibabacloud.com.

    csi.volumeAttributes.server

    The mount point domain name in the mount address of the CPFS General Purpose protocol service export directory.

    csi.volumeAttributes.path

    The mount directory in the mount address of the CPFS General Purpose protocol service export directory, for example, /share. You can also set it to a subdirectory, for example, /share/dir.

    csi.volumeAttributes.mountProtocol

    cpfs-nfs indicates using the NFS protocol to mount CPFS.

    csi.volumeAttributes.volumeAs

    subpath indicates creating a subdirectory type PV.

    csi.volumeHandle

    Must be consistent with the PV name.

  2. Run the following command to create the PV.

    kubectl apply -f cpfs-pv.yaml
  3. View the PV status.

    kubectl get pv cpfs-pv

    Expected output:

    NAME      CAPACITY   ACCESS MODES   RECLAIM POLICY   STATUS      CLAIM   STORAGECLASS   REASON   AGE
    cpfs-pv   20Gi       RWX            Retain           Available                                   2s

Step 2: Create a PVC

Create a PVC to "request" the use of the storage resources registered in the previous step.

  1. Save the following content as cpfs-pvc.yaml.

    apiVersion: v1
    kind: PersistentVolumeClaim
    metadata:
      name: cpfs-pvc
    spec:
      accessModes:
      - ReadWriteMany  # Access mode
      resources:
        requests: 
          storage: 20Gi  # Requested storage capacity
      selector:  # 
        matchLabels:
          alicloud-pvname: cpfs-pv  # Bind to the previously created PV

    PV parameters

    Description

    accessModes

    Access mode that the PVC requests from the PV.

    selector

    Uses the label on the PV for matching and binding.

    resources.requests.storage

    The storage capacity allocated to the Pod. It must not exceed the PV capacity.

  2. Create the PV and PVC.

    kubectl apply -f cpfs-pvc.yaml
  3. View the PVC status to confirm that it has been successfully bound to the PV.

    kubectl get pvc cpfs-pvc

    The following is an example of the output:

    NAME       STATUS   VOLUME    CAPACITY   ACCESS MODES   STORAGECLASS   VOLUMEATTRIBUTESCLASS   AGE
    cpfs-pvc   Bound    cpfs-pv   20Gi       RWO                           <unset>                 18m

Step 3: Create the application and mount the volume

Create an application workload and declare the use of the previously created PVC in its configuration.

  1. Save the following content as cpfs-test.yaml.

    apiVersion: apps/v1
    kind: StatefulSet
    metadata:
      name: cpfs-sts
    spec:
      selector:
        matchLabels:
          app: nginx
      serviceName: "nginx"
      replicas: 2
      template:
        metadata:
          labels:
            app: nginx
        spec:
          containers:
          - name: nginx
            image: anolis-registry.cn-zhangjiakou.cr.aliyuncs.com/openanolis/nginx:1.14.1-8.6
            volumeMounts:
            - name: cpfs-pvc
              mountPath: /data
          volumes:
          - name: cpfs-pvc
            persistentVolumeClaim:
              claimName: cpfs-pvc
  2. Create the StatefulSet.

    kubectl apply -f cpfs-test.yaml
  3. View the Pod status.

    kubectl get pods -l app=nginx

    Expected output:

    NAME         READY   STATUS    RESTARTS   AGE
    cpfs-sts-0   1/1     Running   0          58s
    cpfs-sts-1   1/1     Running   0          50s
  4. Check the mount point inside the container to confirm that CPFS has been mounted successfully.

    kubectl exec cpfs-sts-0 -- mount | grep /data

    The following expected output indicates that the CPFS General Purpose static volume has been mounted successfully.

    cpfs-******-******.cn-shanghai.cpfs.aliyuncs.com:/share on /data type nfs (rw,relatime,vers=3,rsize=1048576,wsize=1048576,namlen=255,hard,nolock,noresvport,proto=tcp,port=30000,timeo=600,retrans=2,sec=sys,mountaddr=127.0.1.255,mountvers=3,mountport=30000,mountproto=tcp,local_lock=all,addr=127.0.1.255)

Verify shared storage and persistent storage

After the application is successfully deployed, you can verify whether the storage volume works as expected.

Shared storage

Create a file in one Pod, then view it in another Pod to verify shared storage of data.

  1. View the Pod information to obtain the Pod names.

    kubectl get pod -l app=nginx

    Expected output:

    NAME         READY   STATUS    RESTARTS   AGE
    cpfs-sts-0   1/1     Running   0          10s
    cpfs-sts-1   1/1     Running   0          5s
  2. Create a file in one Pod.

    The following uses the Pod named cpfs-sts-0 as an example:

    kubectl exec cpfs-sts-0 -- touch /data/test.txt
  3. Check whether the file exists in another Pod.

    The following uses the Pod named cpfs-sts-1 as an example.

    kubectl exec cpfs-sts-1 -- ls /data

    Expected output:

    test.txt

    The previously created file is visible, indicating that data can be shared across multiple Pods.

Persistent storage

Rebuild the Deployment and check whether the data in the file system exists in the new Pod to verify persistent storage of data.

  1. Delete the application Pod to trigger a rebuild.

    kubectl rollout restart sts cpfs-sts
  2. View the Pod and wait for the new Pod to start and enter the Running state.

    kubectl get pod -l app=nginx

    Expected output:

    NAME         READY   STATUS    RESTARTS   AGE
    cpfs-sts-0   1/1     Running   0          1s
    cpfs-sts-1   1/1     Running   0          10s
  3. Check whether the previously created file exists in the new Pod.

    The following uses the Pod named cpfs-sts-0 as an example.

    kubectl exec cpfs-sts-0 -- ls /data

    Expected output:

    test.txt

    The previously written file is visible, indicating that data is persistently stored.

Recommendations for production environments

  • Performance tuning: CPFS is suitable for high-throughput and high-IOPS scenarios. You can adjust NFS mount options in the mountOptions of the PV (such as rsize and wsize) to optimize performance and meet specific workload requirements.

  • Data consistency: As shared storage, CPFS does not guarantee data consistency when multiple Pods concurrently write to the same file. To avoid file corruption, you need to implement distributed locks at the application layer or use an append-only write mode.

  • Storage volume management: The static storage volume approach requires manual PV management. For scenarios that require automatically creating and isolating storage volumes for multiple applications, we recommend using CNFS to manage CPFS dynamic storage volumes. For more information, see Manage dynamically provisioned volumes of General-purpose CPFS.