All Products
Search
Document Center

File Storage NAS:Mount a NAS file system with the Alibaba Cloud CSI plug-in (Recommended)

Last Updated:Sep 20, 2026

This topic explains how to mount a NAS file system to a Kubernetes cluster in an ACK One registered cluster using the CSI plug-in.

Prerequisites

  • An ACK One registered cluster is created with an external Kubernetes cluster connected.

  • A registered cluster running Kubernetes 1.24 or later.

  • (Required for data center deployments) An Express Connect circuit between your data center and Alibaba Cloud.

Precautions

  • For data center clusters, ECS nodes added via node pools automatically receive the alibabacloud.com/external=true label.

Step 1: Configure RAM permissions

Use onectl

  1. Install onectl on your on-premises machine.

  2. Grant the RAM user CSI plug-in permissions:

    onectl ram-user grant --addon csi-plugin

    Expected output:

    Ram policy ack-one-registered-cluster-policy-csi-plugin granted to ram user ack-one-user-ce313528c3 successfully.

Use the console

  1. Create a RAM user.

  2. Create a custom policy with the following sample. It grants permissions to manage disks, snapshots, snapshot policies, tags, instances, NAS file systems, and OSS buckets.

    Show sample policy

    {
        "Version": "1",
        "Statement": [
            {
                "Action": [
                    "ecs:AttachDisk",
                    "ecs:DetachDisk",
                    "ecs:DescribeDisks",
                    "ecs:CreateDisk",
                    "ecs:ResizeDisk",
                    "ecs:CreateSnapshot",
                    "ecs:DeleteSnapshot",
                    "ecs:CreateAutoSnapshotPolicy",
                    "ecs:ApplyAutoSnapshotPolicy",
                    "ecs:CancelAutoSnapshotPolicy",
                    "ecs:DeleteAutoSnapshotPolicy",
                    "ecs:DescribeAutoSnapshotPolicyEX",
                    "ecs:ModifyAutoSnapshotPolicyEx",
                    "ecs:AddTags",
                    "ecs:DescribeTags",
                    "ecs:DescribeSnapshots",
                    "ecs:ListTagResources",
                    "ecs:TagResources",
                    "ecs:UntagResources",
                    "ecs:ModifyDiskSpec",
                    "ecs:DeleteDisk",
                    "ecs:DescribeInstanceAttribute",
                    "ecs:DescribeInstances"
                ],
                "Resource": ["*"],
                "Effect": "Allow"
            },
            {
                "Action": [
                    "nas:DescribeFileSystems",
                    "nas:DescribeMountTargets",
                    "nas:AddTags",
                    "nas:DescribeTags",
                    "nas:RemoveTags",
                    "nas:CreateFileSystem",
                    "nas:DeleteFileSystem",
                    "nas:ModifyFileSystem",
                    "nas:CreateMountTarget",
                    "nas:DeleteMountTarget",
                    "nas:ModifyMountTarget",
                    "nas:TagResources",
                    "nas:SetDirQuota",
                    "nas:EnableRecycleBin",
                    "nas:GetRecycleBinAttribute"
                ],
                "Resource": ["*"],
                "Effect": "Allow"
            },
            {
                "Action": [
                    "oss:PutBucket",
                    "oss:GetObjectTagging",
                    "oss:ListBuckets",
                    "oss:PutBucketTags",
                    "oss:GetBucketTags",
                    "oss:PutBucketEncryption",
                    "oss:GetBucketInfo"
                ],
                "Resource": ["*"],
                "Effect": "Allow"
            }
        ]
    }
  3. Attach the custom policy to the RAM user.

  4. Create an AccessKey for the RAM user.

    Warning

    Configure an AccessKey network restriction policy to limit calls to trusted networks.

  5. Create a Secret named alibaba-addon-secret in the kube-system namespace with the AccessKey pair. The CSI plug-in uses this Secret to authenticate with Alibaba Cloud.

    kubectl -n kube-system create secret generic alibaba-addon-secret \
      --from-literal='access-key-id=<your-access-key-id>' \
      --from-literal='access-key-secret=<your-access-key-secret>'

    Replace <your-access-key-id> and <your-access-key-secret> with your AccessKey pair.

Step 2: Install the CSI plug-in

Use onectl

Run the following commands to install the CSI plug-in.

onectl addon install csi-plugin
onectl addon install csi-provisioner

Expected output:

Addon csi-plugin, version **** installed.
Addon csi-provisioner, version **** installed.

Use the console

  1. Log on to the ACK console. In the left navigation pane, click Clusters.

  2. On the Clusters page, click the name of your cluster. In the left navigation pane, click Components and Add-ons .

  3. Click the Storage tab. On the csi-plugin and csi-provisioner cards, click Install.

  4. After confirming the version information in the Prompt dialog box, click OK.

Step 3: Use volumes

You can mount a NAS file system to persist application data using one of the following methods: