ACK integrates deeply with Alibaba Cloud storage and supports native Kubernetes storage services. Deploy the CSI plug-in in a registered cluster to automatically attach cloud disks, NAS, OSS, and local volumes to pods. This topic explains how to use Alibaba Cloud CSI storage in a registered cluster.
Configure RAM permissions, install the CSI plug-in, and mount volumes to your pods.
Considerations
Check whether the following restrictions apply:
-
For data center clusters, ECS nodes added via node pools automatically receive the
alibabacloud.com/external=truelabel.
Prerequisites
Ensure you have:
-
An ACK One registered cluster is created with an external Kubernetes cluster connected.
-
A registered cluster running Kubernetes 1.24 or later.
-
(Required for data center deployments) An Express Connect circuit between your data center and Alibaba Cloud.
Step 1: Configure RAM permissions
The Container Storage Interface (CSI) plug-in requires an AccessKey pair to call Alibaba Cloud APIs. Without one, the plug-in cannot access cloud storage.
Choose a method:
Use onectl
-
Install onectl on your on-premises machine.
-
Grant the RAM user CSI plug-in permissions:
onectl ram-user grant --addon csi-pluginExpected output:
Ram policy ack-one-registered-cluster-policy-csi-plugin granted to ram user ack-one-user-ce313528c3 successfully.
Use the console
-
Create a custom policy with the following sample. It grants permissions to manage disks, snapshots, snapshot policies, tags, instances, NAS file systems, and OSS buckets.
-
Create an AccessKey for the RAM user.
WarningConfigure an AccessKey network restriction policy to limit calls to trusted networks.
-
Create a Secret named
alibaba-addon-secretin thekube-systemnamespace with the AccessKey pair. The CSI plug-in uses this Secret to authenticate with Alibaba Cloud.kubectl -n kube-system create secret generic alibaba-addon-secret \ --from-literal='access-key-id=<your-access-key-id>' \ --from-literal='access-key-secret=<your-access-key-secret>'Replace
<your-access-key-id>and<your-access-key-secret>with your AccessKey pair.
Step 2: Install the CSI plug-in
Install both csi-plugin and csi-provisioner.
Use onectl
Install the add-ons:
onectl addon install csi-plugin
onectl addon install csi-provisioner
Expected output:
Addon csi-plugin, version **** installed.
Addon csi-provisioner, version **** installed.
Use the console
-
Log on to the ACK console. In the left navigation pane, click Clusters.
-
Click the name of your cluster. In the left navigation pane, click Add-ons.
-
Click the Volumes tab. Find the csi-plugin and csi-provisioner cards, then click Install on each card.
-
In the Message dialog box, confirm the versions and click OK.
Step 3: Use volumes
After the CSI plug-in is installed, mount different volume types in your registered cluster.
Next steps
-
Manage or remove CSI add-ons from the Add-ons page in the ACK console, or use onectl.
-
Manage storage across multiple registered clusters with ACK One fleet management.