Gke Storage

作者 google55b4e13eba6d無授權條款21K 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫今天更新

Manages GKE storage, including PVCs, PersistentVolumes, and Filestore. Use when configuring GKE storage or creating PVCs. For GCS FUSE mounts, use google-cloud-storage-fuse. For diagnosing storage failures (volume attach/mount errors, disk performance/node storage pressure, or Cloud Storage FUSE OOM), use gke-storage-troubleshooting. Don't use for database administration or replication strategies outside volume provisioning context.

精選僅含說明DevOps & Cloud
AI 產生的概覽

用於設定 GKE 儲存的參考指南:StorageClass、PVC、PersistentVolume、Filestore 及磁碟區擴充。

功能
提供在 Google Kubernetes Engine 叢集上設定儲存的參考說明,涵蓋 CSI 驅動程式、內建與自訂 StorageClass、用於區塊儲存與共用檔案儲存的 PersistentVolumeClaim 資訊清單、GCS 值區掛載,以及磁碟區擴充。它也列出具狀態工作負載的容量與排程限制,以及啟用磁碟區擴充、使用區域級永久磁碟等最佳做法。產出的是設定指引與 YAML 範例,而非執行指令碼。
適用情境
適用於設定 GKE 儲存或建立 PVC、選擇 StorageClass 或磁碟類型,以及規劃磁碟區擴充與具狀態工作負載容量時。不適用於 Cloud Storage FUSE 掛載、儲存故障診斷,或磁碟區佈建範圍之外的資料庫管理。
執行需求
此技能不隨附指令碼,僅為說明文件。它引用 MCP 工具(apply_k8s_manifest、get_k8s_resource、describe_k8s_resource、get_cluster)與 kubectl 來套用資訊清單及修補 PVC;GCS FUSE 掛載需要 Workload Identity,並為值區授予 storage.objectViewer 權限。

GKE Storage

Routing Note: For Cloud Storage FUSE (gcsfuse) mounts or the GKE gcsfuse.csi.storage.gke.io CSI driver, open google-cloud-storage-fuse/SKILL.md.

This reference covers storage configuration for GKE clusters including persistent disks, file storage, and cloud storage integration.

MCP Tools: apply_k8s_manifest, get_k8s_resource, describe_k8s_resource, get_cluster

Golden Path Storage Defaults

The golden path Autopilot config enables these CSI drivers:

DriverGolden PathAccess ModeUse Case
Compute EngineEnabled (default)ReadWriteOnceBlock storage for
: Persistent Disk : : : databases, :
: CSI : : : single-pod workloads :
Google CloudEnabledReadWriteManyShared NFS for
: Filestore CSI : : : multi-pod access :
Cloud StorageEnabledReadWriteMany /Mount GCS buckets as
: FUSE CSI : : ReadOnlyMany : volumes :
ParallelstoreEnabledReadWriteManyHigh-performance
: CSI : : : parallel file system :
Boot disk typepd-balancedN/ANode boot disks

StorageClasses

Default StorageClasses

GKE provides built-in StorageClasses:

StorageClassDisk TypeUse Case
standard-rwopd-standardCost-effective, low IOPS
premium-rwopd-ssdHigh IOPS, databases
standard-rwxFilestore (Basic HDD)Shared NFS
premium-rwxFilestore (Basic SSD)Shared NFS, higher performance

Custom StorageClass

yaml
apiVersion: storage.k8s.io/v1kind: StorageClassmetadata:  name: fast-regionalprovisioner: pd.csi.storage.gke.ioparameters:  type: pd-ssd  replication-type: regional-pd    # Replicate across 2 zonesvolumeBindingMode: WaitForFirstConsumerallowVolumeExpansion: true         # Always enable for production

PersistentVolumeClaims

Block Storage (ReadWriteOnce)

yaml
apiVersion: v1kind: PersistentVolumeClaimmetadata:  name: database-pvcspec:  accessModes:  - ReadWriteOnce  storageClassName: premium-rwo  resources:    requests:      storage: 100Gi

Shared File Storage (ReadWriteMany via Filestore)

yaml
apiVersion: v1kind: PersistentVolumeClaimmetadata:  name: shared-dataspec:  accessModes:  - ReadWriteMany  storageClassName: standard-rwx  resources:    requests:      storage: 1Ti    # Filestore minimum is 1 TiB for Basic tier

GCS Bucket Mount (Cloud Storage FUSE)

Mount a GCS bucket as a volume without a PVC:

yaml
apiVersion: v1kind: Podmetadata:  name: gcs-reader  annotations:    gke-gcsfuse/volumes: "true"spec:  containers:  - name: reader    image: busybox    command: ["ls", "/data"]    volumeMounts:    - name: gcs-bucket      mountPath: /data  volumes:  - name: gcs-bucket    csi:      driver: gcsfuse.csi.storage.gke.io      readOnly: true      volumeAttributes:        bucketName: <BUCKET_NAME>

Requires Workload Identity for the pod's service account to have storage.objectViewer on the bucket.

Volume Expansion

If allowVolumeExpansion: true is set on the StorageClass, resize by updating the PVC:

bash
# kubectlkubectl patch pvc <PVC_NAME> -p '{"spec":{"resources":{"requests":{"storage":"200Gi"}}}}'
# MCP (preferred)patch_k8s_resource(parent="...", resourceType="persistentvolumeclaim", name="<PVC_NAME>",  patch='{"spec":{"resources":{"requests":{"storage":"200Gi"}}}}')

Kubernetes automatically resizes the filesystem.

Stateful Storage & Capacity Constraints

When configuring storage for stateful workloads, keep the following capacity and scheduling constraints in mind:

  • Existing zonal PVs pin the workload to a zone: A Pod that uses an existing zonal PersistentVolume (for example, in europe-north1-b) can only run in that zone. The cluster autoscaler can't work around a capacity shortage by adding nodes in another zone; any fallback must be in the same zone.
  • Use automated disk type selection and topology-aware scheduling for new workloads: Use volumeBindingMode: WaitForFirstConsumer so the volume is created in the zone where the Pod lands. When a ComputeClass mixes machine generations (for example, C4/N4 priority with N2 fallback), configure the StorageClass for automated disk type selection (parameters.type: dynamic with pd-type: pd-balanced, hyperdisk-type: hyperdisk-balanced, disk-type-preference: hyperdisk-type, and use-allowed-disk-topology: "true", GKE 1.35.3-gke.1290000+; or use-allowed-disk-topology: "true" on GKE 1.34.1-gke.2541000+) so the autoscaler only picks nodes that support the disk type and new volumes get a compatible disk type per node.
  • Same-zone PD-type swaps rarely help: Switching a same-zone fallback from pd-ssd to pd-balanced is unlikely to resolve a zonal capacity shortage, because both can be affected by the same zonal constraints. Prefer a fallback to a Hyperdisk-capable machine series (for example, C3 or N4) with hyperdisk-balanced.
  • Check Hyperdisk quotas first: Hyperdisk quotas (for example, HDB-TOTAL-GB, throughput, and IOPS) are separate from Persistent Disk quotas. Verify the regional limits before recommending a Hyperdisk Balanced fallback.

Best Practices

  1. Always enable volume expansion: Set allowVolumeExpansion: true on all StorageClasses
  2. Use regional PDs for production: replication-type: regional-pd replicates across 2 zones for HA
  3. Use WaitForFirstConsumer: Ensures the PV is provisioned in the same zone as the pod
  4. Choose the right disk type: pd-ssd for databases, pd-balanced (golden path default) for general use, pd-standard for cold storage
  5. Use Filestore for shared access: When multiple pods need to read/write the same files
  6. Use GCS FUSE for data pipelines: Mount buckets directly for ML training data, logs, etc.
  7. Back up PVCs: Use Backup for GKE (see the gke-backup-dr skill) to protect persistent data

來源與署名

來源:google/skills位於skills/cloud/gke-storage提交55b4e13

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架

更多來自 google/skills 的技能

Dpop Adoption

google

精選

指導為 Google OAuth 平台實作 OAuth 2.0 DPoP(RFC 9449)傳送方約束的更新權杖。

Security21K今天更新

Finding Google Skills

google

精選

Google platform decision and setup guidance, loaded on demand from Google's skill catalog. Use when a developer is choosing or setting up part of their stack, such as where to run a service, a database, storage, messaging, authentication, analytics, ads, or AI model serving, and a Google product is a reasonable candidate - whether or not a vendor is named - or when a request names a Google product or API. Brings in the matching Google skill so the answer can weigh Google options, their trade-offs, and when they are not the right fit. Skip when the stack is already settled on another provider and no Google product is named, or the task involves no platform choice.

待分類21K今天更新

Spanner Basics

google

精選

指導 Google Cloud Spanner 的執行個體與資料庫管理、結構定義設計、查詢與效能診斷。

Data & Analytics21K今天更新

Secops Triage

google

精選

引導 SOC 分析師對 Google SecOps 安全警示進行分診,從調查到結案或升級。

Security21K今天更新

Secops Investigate

google

精選

指導 SOC 分析師在 Google SecOps 中使用 UDM 查詢與時間軸進行深入的安全事件與實體調查。

Security21K今天更新

Secops Hunt

google

精選

指導在 Google SecOps 中使用 UDM 查詢、IoC 回溯、普遍性與異常分析進行主動威脅狩獵。

Security21K今天更新