CRD reference
Field reference for the pillar-csi v1alpha1 CRDs: PillarAgent, PillarStore, PillarProtocol, PillarStorageClass and PillarVolumeState, from the Go types.
On this page
- Packages
- pillar-csi.bhyoo.com/v1alpha1
- Resource Types
- AgentCapabilities
- BackendOverrides
- BackendSpec
- DiscoveredPool
- ExternalSpec
- FilesystemConfig
- LVMBackendConfig
- LVMBackendOverrides
- LVMProvisioningMode
- NVMeOFTCPConfig
- NVMeOFTCPOverrides
- NodeRefSpec
- PartialFailureInfo
- PillarAgent
- PillarAgentSpec
- PillarAgentStatus
- PillarProtocol
- PillarProtocolSpec
- PillarProtocolStatus
- PillarStorageClass
- PillarStorageClassSpec
- PillarStorageClassStatus
- PillarStore
- PillarStoreSpec
- PillarStoreStatus
- PillarVolumeState
- PillarVolumeStatePhase
- PillarVolumeStateSpec
- PillarVolumeStateStatus
- ProtocolOverrides
- ProtocolSpec
- ReclaimPolicy
- ResolvedVolumeConfig
- StorageClassOverrides
- StorageClassTemplate
- StoreCapacity
- VolumeBindingMode
- VolumeClaimRef
- VolumeExportInfo
- VolumeExportSpec
- VolumePublication
- ZFSBackendConfig
- ZFSBackendOverrides
- ZFSVolumeType
All pillar-csi resources are cluster-scoped. The controller manages PillarVolumeState objects; do not create them by hand.
The field descriptions come from comments in the Go API types. A few of them mention iSCSI, NFS or other file protocols. Those protocols are not supported yet; NVMe-oF/TCP is the only protocol pillar-csi exports today.
Packages
pillar-csi.bhyoo.com/v1alpha1
Package v1alpha1 contains API Schema definitions for the pillar-csi v1alpha1 API group.
Resource Types
AgentCapabilities
AgentCapabilities describes what backends and protocols the remote agent supports.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
backends string array | backends lists the backend driver types the agent can manage (zfs-zvol, lvm-lv). | Optional | |
protocols string array | protocols lists the network protocols the agent can export storage over (nvmeof-tcp). | Optional |
BackendOverrides
BackendOverrides is the per-binding or per-volume override document for the storage backend. Exactly one member must be set, and it must match the backend member configured on the referenced PillarStore.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
zfs ZFSBackendOverrides | zfs overrides ZFS-specific tunables; valid only when the store’s backend is zfs. | Optional | |
lvm LVMBackendOverrides | lvm overrides LVM-specific tunables; valid only when the store’s backend is lvm. | Optional |
BackendSpec
BackendSpec describes the storage backend of a PillarStore. Exactly one member must be set: the member name selects the backend (zfs or lvm) and its value carries that backend’s configuration.
The same union shape is reused for the agent’s backend placement config file; per-volume and per-binding override documents use BackendOverrides, which keeps only the tunable subset.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
zfs ZFSBackendConfig | zfs holds ZFS-specific configuration. | Optional | |
lvm LVMBackendConfig | lvm holds LVM-specific configuration. | Optional |
DiscoveredPool
DiscoveredPool is a storage pool reported by the remote agent.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
name string | name is the pool name as known to the storage subsystem (e.g. ZFS pool name). | Required | |
type string | type is the storage technology (e.g. zfs, lvm). | Required | |
total Quantity | total is the total raw capacity of the pool. | Optional | |
available Quantity | available is the free capacity of the pool. | Optional | |
parentDataset string | parentDataset is, for ZFS pools, the dataset relative to the pool under which the agent creates volumes (its config zfs.parentDataset); empty means the pool root dataset. A PillarStore on this pool must declare the same spec.backend.zfs.parentDataset to become Ready. | Optional | |
thinPool string | thinPool is, for LVM volume groups, the thin pool LV the agent creates thin volumes in (its config lvm.thinPool); empty means none. A PillarStore on this VG must declare the same spec.backend.lvm.thinPool to become Ready. | Optional |
ExternalSpec
ExternalSpec defines a storage agent outside the Kubernetes cluster.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
address string | address is the IP or hostname of the external agent. | MinLength: 1 Required | |
port integer | port is the agent gRPC port. | Maximum: 65535 Minimum: 1 Required |
FilesystemConfig
FilesystemConfig describes the filesystem axis: which filesystem the CSI node creates on a new block volume and how it mounts it. The same shape is used at every layer that may set it — PillarStorageClass.spec.filesystem, a hand-written StorageClass’s pillar-csi.bhyoo.com/filesystem parameter and the pillar-csi.bhyoo.com/filesystem PVC annotation.
List fields use list semantics on every layer: omitted (absent or null) inherits the value of the layer below, an explicit empty list [] clears it.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
fsType string | fsType is the filesystem the node formats a new volume with when volumeMode is Filesystem. | ext4 | Enum: [ext4 xfs] Optional |
mkfsOptions string | mkfsOptions are additional mkfs arguments used when the node formats a new volume; a volume that already carries a filesystem is never reformatted. Each element is one argv element (no shell); only filesystem tuning flags of the formatted type are accepted. A null/omitted value inherits the options of the layer below; an explicit empty list [] clears them. | Optional | |
mountOptions string | mountOptions are the mount options the node applies when mounting a Filesystem-mode volume. On a PillarStorageClass they are written to the generated Kubernetes StorageClass’s mountOptions; a PVC annotation value overrides them for that volume. A null/omitted value inherits the options of the layer below; an explicit empty list [] clears them. | Optional |
LVMBackendConfig
LVMBackendConfig holds LVM-specific volume group and thin pool settings.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
volumeGroup string | volumeGroup is the LVM Volume Group name that pillar-csi will create logical volumes in (e.g. “data-vg”). The VG must be pre-created on the node before the agent starts; the driver does not manage VG lifecycle. | MinLength: 1 Required | |
thinPool string | thinPool is the name of the LVM thin pool LV within the volume group (e.g. “thin-pool-0”). When non-empty the backend operates in thin- provisioned mode; when empty it creates fully-allocated linear LVs. The thin pool must be pre-created before the agent starts, and must equal the thinPool of the agent’s backend configuration for this VG (chart agent.backends[].lvm.thinPool; empty = none): on a mismatch the store is not Ready (PoolDiscovered=False, BackendLayoutMismatch) and CreateVolume fails instead of using another thin pool. | Optional | |
provisioningMode LVMProvisioningMode | provisioningMode controls whether new volumes are created as fully- allocated linear LVs or as thin-provisioned LVs inside the thinPool. Defaults to “linear”; set to “thin” together with a non-empty thinPool to enable thin provisioning. | linear | Enum: [linear thin] Optional |
LVMBackendOverrides
LVMBackendOverrides holds the per-volume-tunable subset of LVMBackendConfig. Structural placement fields (volumeGroup, thinPool) are not part of this type and are rejected with their path by the shared document decoder.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
provisioningMode LVMProvisioningMode | provisioningMode overrides the LVM provisioning mode for this volume or binding: “linear” (fully-allocated LV) or “thin” (thin-provisioned LV inside the backend’s thin pool). When omitted, the PillarStore-level value is used. | Enum: [linear thin] Optional |
LVMProvisioningMode
Underlying type: string
LVMProvisioningMode selects between linear and thin LV provisioning.
Validation:
- Enum: [linear thin]
Appears in:
| Field | Description |
|---|---|
linear | LVMProvisioningModeLinear creates fully-allocated linear logical volumes directly in the volume group (lvcreate -L <size>b). |
thin | LVMProvisioningModeThin creates thin-provisioned logical volumes inside a pre-existing thin pool LV (lvcreate -V <size>b --thinpool <pool>). |
NVMeOFTCPConfig
NVMeOFTCPConfig holds NVMe-oF/TCP-specific protocol parameters. Target bind IP is not included here — the controller resolves it at runtime from the referenced PillarAgent.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
port integer | port is the TCP port on which the NVMe-oF target listens. Defaults to 4420. | 4420 | Maximum: 65535 Minimum: 1 Optional |
acl boolean | acl enables host NQN-based access control when true. When false the subsystem uses allow_any_host. Defaults to false (allow_any_host) so that e2e tests and simple deployments work without registering initiator NQNs. | false | Optional |
maxQueueSize integer | maxQueueSize is the I/O queue depth the initiator requests for each queue of the connection (the fabrics queue_size connect option). Unset keeps the kernel default (128). The kernel accepts 16-1024. Applies to connections made after the change; a staged volume keeps the value from its CreateVolume. | Maximum: 1024 Minimum: 16 Optional | |
inCapsuleDataSize integer | inCapsuleDataSize is the maximum in-capsule data size in bytes the target advertises (the nvmet port’s param_inline_data_size). It is a property of the listening port, shared by every volume exported on the same storage node address and port: exporting a volume that requests a value different from the port’s current value fails instead of silently using the port’s value. Unset keeps the transport default (16384 for TCP on 4 KiB pages) and accepts whatever value the port has. The minimum is 1024: NVMe/TCP hosts send the 1024-byte fabrics Connect data in-capsule, so a smaller value makes every connect fail. | Minimum: 1024 Optional | |
ctrlLossTmo integer | ctrlLossTmo is the maximum seconds to wait before declaring a target permanently lost after connectivity failure. | Minimum: 0 Optional | |
reconnectDelay integer | reconnectDelay is the interval in seconds between reconnect attempts. | Minimum: 0 Optional |
NVMeOFTCPOverrides
NVMeOFTCPOverrides holds the per-volume-tunable subset of NVMeOFTCPConfig. Structural fields (port — which listener the export lives on — and acl — the security policy anchor) are not part of this type and are rejected with their path by the shared document decoder.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
maxQueueSize integer | maxQueueSize overrides the protocol-level maxQueueSize (the initiator’s fabrics queue_size; the kernel accepts 16-1024). | Maximum: 1024 Minimum: 16 Optional | |
inCapsuleDataSize integer | inCapsuleDataSize overrides the protocol-level inCapsuleDataSize (the target port’s param_inline_data_size, shared by every volume exported on the same storage node address and port; at least 1024). | Minimum: 1024 Optional | |
ctrlLossTmo integer | ctrlLossTmo overrides the protocol-level ctrlLossTmo (seconds before declaring a target permanently lost). | Minimum: 0 Optional | |
reconnectDelay integer | reconnectDelay overrides the protocol-level reconnectDelay (seconds between reconnect attempts). | Minimum: 0 Optional |
NodeRefSpec
NodeRefSpec references a Kubernetes Node for agent address resolution.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
name string | name is the Kubernetes Node name. | MinLength: 1 Required | |
addressType string | addressType selects which address type to use from the node’s status.addresses. Defaults to InternalIP. | InternalIP | Enum: [InternalIP ExternalIP] Optional |
addressSelector string | addressSelector is an optional CIDR filter applied when multiple addresses of the same type exist on the node. | Optional | |
port integer | port overrides the default agent gRPC port (9500). | Maximum: 65535 Minimum: 1 Optional |
PartialFailureInfo
PartialFailureInfo records what happened when a CSI operation partially succeeded, leaving the volume in an inconsistent state that requires explicit recovery or cleanup.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
failedOperation string | failedOperation is the name of the CSI or agent-level operation that failed (e.g., “ExportVolume”, “NodeStageMount”). | Required | |
failedAt Time | failedAt is the time when the partial failure was recorded. | Required | |
reason string | reason is a brief, machine-readable CamelCase word that describes the category of failure (e.g., “AgentRPCFailed”, “MountFailed”). | Optional | |
message string | message is a human-readable sentence describing what failed and how to recover. | Optional | |
backendCreated boolean | backendCreated is true when the backend storage resource (zvol, LVM LV, etc.) was successfully created before the failure occurred. When false, DeleteVolume only needs to call UnexportVolume (idempotent no-op); when true, it must also call DeleteVolume on the agent to reclaim the storage. | Optional | |
exportCreated boolean | exportCreated is true when the network export (NVMe-oF subsystem) was successfully created before the failure. When true, cleanup must call UnexportVolume before DeleteVolume. | Optional |
PillarAgent
PillarAgent represents a storage agent instance that pillar-csi controller manages. Users create PillarAgent resources; the controller reconciles gRPC connectivity and populates status fields.
| Field | Description | Default | Validation |
|---|---|---|---|
apiVersion string | pillar-csi. | ||
kind string | PillarAgent | ||
metadata ObjectMeta | Refer to Kubernetes API documentation for fields of metadata. | Optional | |
spec PillarAgentSpec | spec defines the desired state of PillarAgent. | Required | |
status PillarAgentStatus | status defines the observed state of PillarAgent. | Optional |
PillarAgentSpec
PillarAgentSpec defines the desired state of PillarAgent. Exactly one of nodeRef or external must be set (discriminated union).
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
nodeRef NodeRefSpec | nodeRef references a Kubernetes Node whose agent is accessible via the node’s IP. Mutually exclusive with external. | Optional | |
external ExternalSpec | external addresses a storage agent that lives outside the Kubernetes cluster. Mutually exclusive with nodeRef. | Optional |
PillarAgentStatus
PillarAgentStatus defines the observed state of PillarAgent.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
resolvedAddress string | resolvedAddress is the IP address selected for gRPC communication with the agent. | Optional | |
agentVersion string | agentVersion is the version string reported by the connected agent. | Optional | |
capabilities AgentCapabilities | capabilities summarizes what the connected agent is capable of. | Optional | |
discoveredPools DiscoveredPool array | discoveredPools lists storage pools found on the agent at last reconcile. | Optional | |
conditions Condition array | conditions represent the current state of the PillarAgent resource. Known condition types: • “NodeExists” – the referenced K8s Node is present in the cluster. • “AgentConnected” – the gRPC connection to the storage agent. The reason field distinguishes the authentication level: True / “Authenticated” – mTLS handshake succeeded; both sides verified. True / “Dialed” – TCP connection established; no mTLS in use. False / “TLSHandshakeFailed” – mTLS configured but handshake failed (cert error). False / “HealthCheckFailed” – TCP-level or transport error. False / “AgentUnhealthy” – agent reachable but reports degraded health. False / “DialerNotConfigured”– no gRPC dialer is wired (dev/test only). • “ExportsReady” – the agent’s export restore has completed and it serves exports. Reasons: True / “ExportsServing” – no export restore is pending (or it finished). False / “ExportRestorePending” – the agent is restoring exports after a restart. False / “ExportRestoreFailed” – the last restore attempt failed; it is retried. Unknown – agent connectivity is not established. • “Ready” – all checks pass; the target is ready to serve pools. | Optional |
PillarProtocol
PillarProtocol describes a reusable network-storage protocol configuration. It is node-independent: the same PillarProtocol can be referenced by multiple PillarStorageClass resources across different pools and targets. The controller resolves the target bind address at runtime from the relevant PillarAgent.
| Field | Description | Default | Validation |
|---|---|---|---|
apiVersion string | pillar-csi. | ||
kind string | PillarProtocol | ||
metadata ObjectMeta | Refer to Kubernetes API documentation for fields of metadata. | ||
spec PillarProtocolSpec | |||
status PillarProtocolStatus |
PillarProtocolSpec
PillarProtocolSpec defines the desired state of PillarProtocol.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
protocol ProtocolSpec | protocol selects the network storage protocol and its configuration. Exactly one member must be set. | Required |
PillarProtocolStatus
PillarProtocolStatus defines the observed state of PillarProtocol.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
storageClassCount integer | storageClassCount is the number of PillarStorageClass resources that reference this protocol. Maintained automatically by the reconciler. | Optional | |
activeAgents string array | activeAgents lists the names of PillarAgents currently serving volumes via this protocol. Maintained automatically by the reconciler. | Optional | |
conditions Condition array | conditions represent the current state of the PillarProtocol resource. Known condition types: • “Ready” – the protocol configuration is valid and ready for use. | Optional |
PillarStorageClass
PillarStorageClass combines a PillarStore and a PillarProtocol to create a Kubernetes StorageClass. A validation webhook rejects incompatible backend/protocol combinations (e.g. a block backend with a file protocol). Parameter overrides allow fine-tuning per binding without changing the shared store or protocol resources.
| Field | Description | Default | Validation |
|---|---|---|---|
apiVersion string | pillar-csi. | ||
kind string | PillarStorageClass | ||
metadata ObjectMeta | Refer to Kubernetes API documentation for fields of metadata. | ||
spec PillarStorageClassSpec | |||
status PillarStorageClassStatus |
PillarStorageClassSpec
PillarStorageClassSpec defines the desired state of PillarStorageClass.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
storeRef string | storeRef is the name of the PillarStore to use for provisioning. | MinLength: 1 Required | |
protocolRef string | protocolRef is the name of the PillarProtocol used to expose volumes. | MinLength: 1 Required | |
storageClass StorageClassTemplate | storageClass configures the Kubernetes StorageClass that this binding generates. The controller creates and owns the StorageClass; deleting the PillarStorageClass also deletes the StorageClass. | Optional | |
filesystem FilesystemConfig | filesystem configures the filesystem axis for volumes of this binding: which filesystem the node formats and which mount options it applies. | Optional | |
overrides StorageClassOverrides | overrides provides a fine-grained parameter layer on top of the referenced store and protocol defaults. | Optional |
PillarStorageClassStatus
PillarStorageClassStatus defines the observed state of PillarStorageClass.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
storageClassName string | storageClassName is the name of the generated StorageClass. | Optional | |
conditions Condition array | conditions represent the current state of the PillarStorageClass resource. Known condition types: • “StoreReady” – the referenced PillarStore is in Ready state. • “ProtocolValid” – the referenced PillarProtocol exists and is valid. • “Compatible” – the pool backend and protocol are compatible (e.g. block backend cannot be combined with a file protocol). • “StorageClassCreated” – the Kubernetes StorageClass has been created. • “Ready” – all checks pass; the binding is operational. | Optional |
PillarStore
PillarStore represents a specific storage pool on a PillarAgent. Users create PillarStore resources to declare that a pool is available for CSI volume provisioning; the controller validates availability and updates status.
| Field | Description | Default | Validation |
|---|---|---|---|
apiVersion string | pillar-csi. | ||
kind string | PillarStore | ||
metadata ObjectMeta | Refer to Kubernetes API documentation for fields of metadata. | ||
spec PillarStoreSpec | |||
status PillarStoreStatus |
PillarStoreSpec
PillarStoreSpec defines the desired state of PillarStore.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
agentRef string | agentRef is the name of the PillarAgent this pool lives on. | MinLength: 1 Required | |
backend BackendSpec | backend describes the storage backend and pool to use. Exactly one member (zfs or lvm) must be set. | Required |
PillarStoreStatus
PillarStoreStatus defines the observed state of PillarStore.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
capacity StoreCapacity | capacity reflects the latest capacity reading for this pool. | Optional | |
conditions Condition array | conditions represent the current state of the PillarStore resource. Known condition types: • “AgentReady” – the referenced PillarAgent is in Ready state. • “PoolDiscovered” – the pool named in spec.backend has been found on the agent and the agent creates volumes in it where the store declares (zfs.parentDataset, lvm.thinPool); reason BackendLayoutMismatch otherwise. • “BackendSupported” – the backend is listed in the agent’s capabilities. • “Ready” – all checks pass; the pool can provision volumes. | Optional |
PillarVolumeState
PillarVolumeState tracks the lifecycle state of a single CSI volume provisioned by pillar-csi. The controller creates a PillarVolumeState during CreateVolume, updates it at each lifecycle stage, and deletes it during DeleteVolume.
The primary purpose of PillarVolumeState is to provide durable partial-failure state tracking: if CreateVolume creates the backend zvol but then crashes before ExportVolume returns, the PillarVolumeStatePhaseCreatePartial phase is already written to etcd, allowing the next CreateVolume call (or an automated recovery controller) to skip the backend-creation step and retry only the export.
| Field | Description | Default | Validation |
|---|---|---|---|
apiVersion string | pillar-csi. | ||
kind string | PillarVolumeState | ||
metadata ObjectMeta | Refer to Kubernetes API documentation for fields of metadata. | Optional | |
spec PillarVolumeStateSpec | spec holds the immutable volume identity and routing parameters. | Required | |
status PillarVolumeStateStatus | status reflects the mutable lifecycle state of the volume. | Optional |
PillarVolumeStatePhase
Underlying type: string
PillarVolumeStatePhase describes the lifecycle phase of a CSI volume as tracked by the pillar-csi controller.
The phases map to VolumeState constants in the internal/csi package:
PillarVolumeStatePhaseProvisioning → in-progress CreateVolume (transient)
PillarVolumeStatePhaseCreatePartial → StateCreatePartial (backend created, export failed)
PillarVolumeStatePhaseReady → StateCreated (fully provisioned)
PillarVolumeStatePhaseControllerPublished → StateControllerPublished
PillarVolumeStatePhaseNodeStagePartial → StateNodeStagePartial
PillarVolumeStatePhaseNodeStaged → StateNodeStaged
PillarVolumeStatePhaseNodePublished → StateNodePublishedValidation:
- Enum: [Provisioning CreatePartial Ready ControllerPublished NodeStagePartial NodeStaged NodePublished]
Appears in:
| Field | Description |
|---|---|
Provisioning | PillarVolumeStatePhaseProvisioning means CreateVolume has been started but has not yet completed. This is a transient state; the controller should advance it to CreatePartial or Ready before returning to the caller. |
CreatePartial | PillarVolumeStatePhaseCreatePartial means the backend storage resource (zvol, LVM LV, etc.) was created successfully, but the ExportVolume step failed. The volume exists on the storage node but is not yet accessible over the network. Recovery options: • Retry CreateVolume: the controller re-attempts ExportVolume. • Call DeleteVolume: the controller calls UnexportVolume (noop) and then DeleteVolume on the agent to clean up the backend resource. |
Ready | PillarVolumeStatePhaseReady means CreateVolume completed fully: both the backend resource and its network export (NVMe-oF target, iSCSI target, NFS share) exist. Corresponds to StateCreated in VolumeStateMachine. |
ControllerPublished | PillarVolumeStatePhaseControllerPublished means ControllerPublishVolume has succeeded. The initiator NQN has been granted access to the NVMe-oF subsystem. |
NodeStagePartial | PillarVolumeStatePhaseNodeStagePartial means NodeStageVolume partially succeeded: the NVMe-oF connect step completed but the mount step failed. Corresponds to StateNodeStagePartial in VolumeStateMachine. |
NodeStaged | PillarVolumeStatePhaseNodeStaged means NodeStageVolume has succeeded. The volume is formatted and mounted at the CSI staging target path. |
NodePublished | PillarVolumeStatePhaseNodePublished means NodePublishVolume has succeeded. The staging path has been bind-mounted into a pod’s target path. |
PillarVolumeStateSpec
PillarVolumeStateSpec defines the immutable identity and routing information for a CSI volume. Fields are populated by the controller at CreateVolume time and never changed thereafter.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
volumeID string | volumeID is the CSI volume ID assigned by the controller. Format: <target-name>/<protocol-type>/<backend-type>/<agent-vol-id> | MinLength: 1 Required | |
agentVolumeID string | agentVolumeID is the volume identifier used in agent RPCs. The format is “<pool>/<volume-name>” where pool is the storage pool name (e.g. ZFS pool name), or just “<volume-name>” for backends with no pool prefix. | MinLength: 1 Required | |
agentRef string | agentRef is the name of the PillarAgent that hosts this volume. | MinLength: 1 Required | |
backendType string | backendType is the storage backend routing token (e.g. “zfs-zvol”, “lvm-lv”). It is the backend member selected by the store’s spec.backend union at CreateVolume time. | Required | |
protocolType string | protocolType is the network storage protocol routing token (e.g. “nvmeof-tcp”). It is the protocol member selected by the protocol’s spec.protocol union at CreateVolume time. | Required | |
capacityBytes integer | capacityBytes is the requested volume size in bytes. | Minimum: 0 Optional | |
claimRef VolumeClaimRef | claimRef identifies the PersistentVolumeClaim this volume was provisioned for, when the provisioner named it (external-provisioner --extra-create-metadata); its UID is read from the claim at the firstCreateVolume. The controller uses it to recognize a provisioning attempt that was abandoned because its claim was removed before any PersistentVolume was created. Without it the claim UID is derived from the default “pvc-<claim UID>” volume name. | Optional | |
resolved ResolvedVolumeConfig | resolved is the effective per-volume configuration resolved at the first CreateVolume attempt from the PillarStore, PillarProtocol, PillarStorageClass overrides, StorageClass parameter documents and PVC annotations (in that precedence order). It is replayed on every retry so the volume keeps the settings it was provisioned with even when the claim or the CRDs behind the overrides no longer exist. | Optional |
PillarVolumeStateStatus
PillarVolumeStateStatus reflects the controller-observed state of a PillarVolumeState.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
phase PillarVolumeStatePhase | phase is the current lifecycle phase of the volume. See PillarVolumeStatePhase for the full state diagram. | Enum: [Provisioning CreatePartial Ready ControllerPublished NodeStagePartial NodeStaged NodePublished] Optional | |
partialFailure PartialFailureInfo | partialFailure is populated whenever the volume is in a partial-failure phase (CreatePartial, NodeStagePartial). It records what succeeded and what failed so that the recovery controller can take the minimum necessary corrective action. Cleared when the partial failure is resolved. | Optional | |
backendDevicePath string | backendDevicePath is the device path returned by agent.CreateVolume (e.g. “/dev/zvol/pool/pvc-abc123”). Persisted when the volume enters the CreatePartial phase so that a retry of CreateVolume can skip the backend-creation step and call agent.ExportVolume directly, using this stored path rather than re-querying the agent. Cleared when the volume reaches the Ready phase. | Optional | |
exportInfo VolumeExportInfo | exportInfo holds the network export parameters returned by ExportVolume. Populated when phase is Ready or later. Used by DeleteVolume to unmount the export after a controller restart without re-querying the agent. | Optional | |
publishedNodes VolumePublication array | publishedNodes lists every node the volume is currently published to by ControllerPublishVolume. ControllerPublishVolume rejects a publish that is incompatible with an existing entry (for example a second node for a SINGLE_NODE_* access mode); ControllerUnpublishVolume removes the entry after the agent revoked the node’s access; DeleteVolume refuses to delete a volume while this list is non-empty. Entries are also the exact initiator set the storage target’s ACL must contain. | Optional | |
exportSpec VolumeExportSpec | exportSpec is the export configuration the controller requested at CreateVolume time. It is the durable desired state the resync controller uses to re-create the export after the storage node loses its target state. Volumes created before this field existed have no exportSpec and are reported via the ExportReconciled condition instead of being recovered. | Optional | |
publicationGeneration integer | publicationGeneration is a monotonically increasing counter bumped by exactly 1 on every status update that changes publishedNodes or sets deleting. The value committed by that update is sent to the agent as the fencing generation on AllowInitiator, DenyInitiator, UnexportVolume and ReconcileState; the agent rejects any request carrying a lower generation than the one it last applied. This closes the window where a stale (former leader) controller’s in-flight RPC lands after a new leader already changed the publication set. | Minimum: 0 Optional | |
deleting boolean | deleting is set by DeleteVolume before it removes the export and the backend resource. It is written by a resourceVersion compare-and-swap that only succeeds while publishedNodes is empty, so a volume can never be concurrently published and deleted. ControllerPublishVolume rejects reservations while deleting is true, and state resync skips the volume. | Optional | |
conditions Condition array | conditions represent the current observed state of the PillarVolumeState. Known condition types: • “BackendCreated” – the backend storage resource exists on the agent. • “ExportCreated” – the network export exists on the agent. • “Ready” – both backend and export exist; volume is usable. | Optional |
ProtocolOverrides
ProtocolOverrides is the per-binding or per-volume override document for the transport protocol. Exactly one member must be set, and it must match the protocol member configured on the referenced PillarProtocol.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
nvmeofTcp NVMeOFTCPOverrides | nvmeofTcp overrides NVMe-oF/TCP tunables; valid only when the protocol’s member is nvmeofTcp. | Optional |
ProtocolSpec
ProtocolSpec describes the transport protocol of a PillarProtocol. Exactly one member must be set: the member name selects the protocol (nvmeofTcp) and its value carries that protocol’s configuration.
Per-binding and per-volume override documents use ProtocolOverrides, which keeps only the tunable subset.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
nvmeofTcp NVMeOFTCPConfig | nvmeofTcp holds NVMe-oF/TCP configuration. | Optional |
ReclaimPolicy
Underlying type: string
ReclaimPolicy mirrors corev1.PersistentVolumeReclaimPolicy for inline use.
Validation:
- Enum: [Delete Retain]
Appears in:
| Field | Description |
|---|---|
Delete | |
Retain |
ResolvedVolumeConfig
ResolvedVolumeConfig is the durable record of the effective configuration a volume was provisioned with. The shapes reuse the CRD union documents so the stored object reads exactly like the layers it was resolved from.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
backend BackendSpec | backend is the effective storage backend configuration: the store’s spec.backend with binding, StorageClass-document and PVC tunable overrides applied. | Required | |
protocol ProtocolSpec | protocol is the effective transport configuration: the protocol’s spec.protocol with binding, StorageClass-document and PVC tunable overrides applied. | Required | |
filesystem FilesystemConfig | filesystem is the effective filesystem configuration the node applies when the volume is a Filesystem-mode mount. | Optional |
StorageClassOverrides
StorageClassOverrides is the optional layer of per-binding parameter overrides applied on top of the store and protocol defaults.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
backend BackendOverrides | backend contains backend tunable overrides (same shape as the pillar-csi.bhyoo.com/backend PVC annotation document). | Optional | |
protocol ProtocolOverrides | protocol contains protocol tunable overrides (same shape as the pillar-csi.bhyoo.com/protocol PVC annotation document). | Optional |
StorageClassTemplate
StorageClassTemplate defines the parameters used to generate a Kubernetes StorageClass from this binding.
A StorageClass is immutable apart from allowVolumeExpansion, so a change to reclaimPolicy or volumeBindingMode makes the controller delete and re-create the StorageClass. Tunable overrides do not feed the StorageClass parameters — they are resolved from live CRs at CreateVolume — so editing them never forces a StorageClass recreation.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
name string | name is the name of the generated StorageClass. Defaults to the PillarStorageClass’s own name when omitted. Immutable: PVCs reference their StorageClass by name. | MinLength: 1 Optional | |
reclaimPolicy ReclaimPolicy | reclaimPolicy determines what happens to a PersistentVolume when its PersistentVolumeClaim is deleted. | Delete | Enum: [Delete Retain] Optional |
volumeBindingMode VolumeBindingMode | volumeBindingMode controls when volume binding and dynamic provisioning occur. | Immediate | Enum: [Immediate WaitForFirstConsumer] Optional |
allowVolumeExpansion boolean | allowVolumeExpansion enables online volume expansion. When unset the controller derives the value from backend capabilities. | Optional |
StoreCapacity
StoreCapacity reports the measured capacity of the pool.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
total Quantity | total is the gross capacity of the pool. | Optional | |
available Quantity | available is the free capacity available for new volumes. | Optional | |
used Quantity | used is the amount of capacity already consumed. | Optional |
VolumeBindingMode
Underlying type: string
VolumeBindingMode mirrors storagev1.VolumeBindingMode for inline use.
Validation:
- Enum: [Immediate WaitForFirstConsumer]
Appears in:
| Field | Description |
|---|---|
Immediate | |
WaitForFirstConsumer |
VolumeClaimRef
VolumeClaimRef identifies the PersistentVolumeClaim a volume was provisioned for. The UID pins one claim: a claim deleted and re-created under the same name is a different claim.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
uid string | uid is the UID of the PersistentVolumeClaim. | MinLength: 1 Required | |
namespace string | namespace is the namespace of the PersistentVolumeClaim. | Optional | |
name string | name is the name of the PersistentVolumeClaim. | Optional |
VolumeExportInfo
VolumeExportInfo holds the network export information returned by the agent’s ExportVolume RPC. These values are stored durably so that DeleteVolume can tear down the export after a controller restart.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
targetID string | targetID is the NVMe Qualified Name (NQN) of the NVMe-oF subsystem. | Optional | |
address string | address is the IP address of the storage node (same as PillarAgent.Status.ResolvedAddress with the port stripped). | Optional | |
port integer | port is the TCP port on which the NVMe-oF target listens. | Optional | |
volumeRef string | volumeRef is the protocol-level reference for this volume (the NVMe-oF subsystem name). | Optional |
VolumeExportSpec
VolumeExportSpec is the export configuration requested from the agent at CreateVolume time. It is the durable desired state from which the controller re-creates the export after the storage node loses its target state (agent restart, node reboot), independent of later StorageClass or PillarProtocol changes.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
bindAddress string | bindAddress is the storage node address the target listens on. | MinLength: 1 Required | |
port integer | port is the TCP port the target listens on; 0 selects the protocol’s default port, exactly as in the original export request. | Maximum: 65535 Minimum: 0 Required | |
aclEnabled boolean | aclEnabled is true when the target admits only the initiators of published nodes; false admits any initiator. | Required | |
inCapsuleDataSize integer | inCapsuleDataSize is the NVMe-oF/TCP in-capsule data size in bytes the export requires on its port; absent when the export accepts the port’s value. NVMe-oF/TCP only. | Minimum: 1024 Optional |
VolumePublication
VolumePublication records one node to which ControllerPublishVolume granted access to this volume. The list of publications is the durable source of truth for CSI publish exclusivity (a SINGLE_NODE_* volume may be published to at most one node) and for the initiator ACL set the storage target must hold. An entry is written before the agent grants access and removed only after the agent revoked it, so a crash between the two steps leaves the record fail-closed.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
nodeID string | nodeID is the CSI node_id (Kubernetes node name) the volume is published to. | MinLength: 1 Required | |
initiatorID string | initiatorID is the protocol-specific initiator identity granted access (NVMe-oF host NQN, iSCSI IQN, or the node ID for file protocols). It is recorded so the grant can be revoked even after the node’s CSINode object is gone. | MinLength: 1 Required | |
accessMode string | accessMode is the CSI VolumeCapability access mode name requested by the publish (e.g. “SINGLE_NODE_WRITER”, “MULTI_NODE_READER_ONLY”). | MinLength: 1 Required | |
readonly boolean | readonly mirrors ControllerPublishVolumeRequest.readonly. | Optional | |
revoking boolean | revoking is set by ControllerUnpublishVolume in the same update that allocates the fencing generation for the revoke, and the record is removed once the agent revoked the initiator. A revoking record still occupies the volume for exclusivity (fail-closed) but is not part of the initiator set the target should grant: state recovery must exclude it, and a publish to the same node is rejected until the unpublish finishes. | Optional |
ZFSBackendConfig
ZFSBackendConfig holds ZFS-specific pool and dataset settings.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
volumeType ZFSVolumeType | volumeType selects the ZFS volume kind. Only “zvol” is implemented. | zvol | Enum: [zvol] Optional |
pool string | pool is the ZFS pool name (e.g. “hot-data”). | MinLength: 1 Required | |
parentDataset string | parentDataset is the ZFS dataset path under which pillar-csi will create per-volume zvols (e.g. “k8s”). It must equal the parentDataset of the agent’s backend configuration for this pool (chart agent.backends[].zfs.parentDataset; empty = pool root): on a mismatch the store is not Ready (PoolDiscovered=False, BackendLayoutMismatch) and CreateVolume fails instead of placing volumes elsewhere. | Optional | |
properties object (keys:string, values:string) | properties are arbitrary ZFS properties applied to every volume created in this pool (e.g. compression, volblocksize). | Optional |
ZFSBackendOverrides
ZFSBackendOverrides holds the per-volume-tunable subset of ZFSBackendConfig. Structural placement fields (pool, parentDataset, volumeType) are not part of this type and are rejected with their path by the shared document decoder.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
properties object (keys:string, values:string) | properties are arbitrary ZFS properties that override pool defaults (e.g. volblocksize, compression). Entries merge key-wise onto the PillarStore’s zfs.properties. | Optional |
ZFSVolumeType
Underlying type: string
ZFSVolumeType enumerates the ZFS volume kinds the driver can create.
Validation:
- Enum: [zvol]
Appears in:
| Field | Description |
|---|---|
zvol | ZFSVolumeTypeZvol creates block-device zvols. It is currently the only implemented kind; zfs datasets are a future variant. |