This topic explains how to mount a NAS file system to a Kubernetes cluster in an ACK One registered cluster using the CSI plug-in.
Prerequisites
-
Created an ACK One registered cluster and connected an external Kubernetes cluster to it. For more information, see Create an ACK One registered cluster.
-
A registered cluster running Kubernetes 1.24 or later.
-
(Required for data center deployments) An Express Connect circuit connecting your data center to Alibaba Cloud.
Precautions
-
If your self-managed Kubernetes cluster is deployed on Alibaba Cloud ECS instances, you must label the instances. For more information, see Initialize ECS nodes after you connect a self-managed Kubernetes cluster to an ACK registered cluster.
-
If you use the registered cluster's node pool feature to scale out a self-managed Kubernetes cluster in an on-premises data center using Alibaba Cloud ECS instances, the node label
alibabacloud.com/external=trueis added by default.
Step 1: Configure RAM permissions
Use onectl
-
Install and configure onectl on your local machine. For more information, see Manage registered clusters using onectl.
-
onectl uses the AccessKey of a RAM user to access cloud resources. Run the following command to grant the RAM user the required permissions for the CSI plug-in.
onectl ram-user grant --addon csi-pluginExpected output:
Ram policy ack-one-registered-cluster-policy-csi-plugin granted to ram user ack-one-user-ce313528c3 successfully.
Use the console
To install the CSI plug-in, your self-managed Kubernetes cluster requires an AccessKey to access cloud services. To obtain this AccessKey, you must first create a RAM user and grant it the necessary permissions.
-
Create a custom policy. Use the following sample policy to grant permissions to manage disks, snapshots, snapshot policies, resource tags, instances, file systems, and buckets.
-
Create an AccessKey for the RAM user.
WarningFor enhanced security, configure a network access control policy for the AccessKey to restrict access to trusted network environments and improve security. For more information, see AccessKey-based network access restriction policies.
-
Use the AccessKey to create a Secret resource named alibaba-addon-secret in the registered cluster.
The CSI plug-in automatically uses this AccessKey to access cloud services during installation.
kubectl -n kube-system create secret generic alibaba-addon-secret --from-literal='access-key-id=<your access key id>' --from-literal='access-key-secret=<your access key secret>'NoteReplace
<your access key id>and<your access key secret>with the AccessKey credentials from the preceding step.
Step 2: Install the CSI plug-in
Use onectl
Run the following commands to install the CSI plug-in.
onectl addon install csi-plugin
onectl addon install csi-provisioner
Expected output:
Addon csi-plugin, version **** installed.
Addon csi-provisioner, version **** installed.
Use the console
Log on to the ACK console. In the left navigation pane, click Clusters.
On the Clusters page, click the name of your cluster. In the left navigation pane, click Components and Add-ons.
-
Click the Storage tab. On the csi-plugin and csi-provisioner cards, click Install.
-
After confirming the version information in the Prompt dialog box, click OK.
Step 3: Use volumes
You can mount a NAS file system to persist application data using one of the following methods: