From f8a1cd6aa8ae197a87b5c42285d7c3bd19786a8e Mon Sep 17 00:00:00 2001 From: Yuquan Ren Date: Mon, 5 Mar 2018 17:39:51 +0800 Subject: [PATCH] add pv protection description (#7620) --- _data/tasks.yml | 6 + docs/concepts/storage/persistent-volumes.md | 12 + .../administer-cluster/pvc-protection.md | 225 ------------------ 3 files changed, 18 insertions(+), 225 deletions(-) delete mode 100644 docs/tasks/administer-cluster/pvc-protection.md diff --git a/_data/tasks.yml b/_data/tasks.yml index 07cc4a18f4..4b8996ebeb 100644 --- a/_data/tasks.yml +++ b/_data/tasks.yml @@ -186,9 +186,15 @@ toc: - docs/tasks/administer-cluster/configure-multiple-schedulers.md - docs/tasks/administer-cluster/ip-masq-agent.md - docs/tasks/administer-cluster/dns-custom-nameservers.md +<<<<<<< HEAD - docs/tasks/administer-cluster/dns-debugging-resolution.md - docs/tasks/administer-cluster/pvc-protection.md - docs/tasks/administer-cluster/storage-object-in-use-protection.md +||||||| merged common ancestors + - docs/tasks/administer-cluster/pvc-protection.md +======= + - docs/tasks/administer-cluster/storage-object-in-use-protection.md +>>>>>>> add pv protection description (#7620) - title: Federation - Run an App on Multiple Clusters landing_page: /docs/tasks/federation/set-up-cluster-federation-kubefed/ diff --git a/docs/concepts/storage/persistent-volumes.md b/docs/concepts/storage/persistent-volumes.md index c73438c613..2ba783f66f 100644 --- a/docs/concepts/storage/persistent-volumes.md +++ b/docs/concepts/storage/persistent-volumes.md @@ -74,6 +74,7 @@ Once a user has a claim and that claim is bound, the bound PV belongs to the use <<<<<<< HEAD ### Storage Object in Use Protection {% assign for_k8s_version="v1.10" %}{% include feature-state-beta.md %} +<<<<<<< HEAD The purpose of the Storage Object in Use Protection feature is to ensure that Persistent Volume Claims (PVCs) in active use by a pod and Persistent Volume (PVs) that are bound to PVCs are not removed from the system as this may result in data loss. ||||||| merged common ancestors ### Persistent Volume Claim Protection @@ -95,10 +96,16 @@ The purpose of the Storage Protection feature is to ensure that Persistent Volum ======= The purpose of the Storage Object in Use Protection feature is to ensure that Persistent Volume Claims (PVCs) in active use by a pod are not removed from the system as this may result in data loss. >>>>>>> Storage Protection was renamed to Storage Object in Use Protection (#7576) +||||||| merged common ancestors +The purpose of the Storage Object in Use Protection feature is to ensure that Persistent Volume Claims (PVCs) in active use by a pod are not removed from the system as this may result in data loss. +======= +The purpose of the Storage Object in Use Protection feature is to ensure that Persistent Volume Claims (PVCs) in active use by a pod and Persistent Volume (PVs) that are bound to PVCs are not removed from the system as this may result in data loss. +>>>>>>> add pv protection description (#7620) **Note:** PVC is in active use by a pod when the pod status is `Pending` and the pod is assigned to a node or the pod status is `Running`. {: .note} +<<<<<<< HEAD <<<<<<< HEAD <<<<<<< HEAD When the [Storage Object in Use Protection beta feature](/docs/tasks/administer-cluster/storage-object-in-use-protection/) is enabled, if a user deletes a PVC in active use by a pod, the PVC is not removed immediately. PVC removal is postponed until the PVC is no longer actively used by any pods, and also if admin deletes a PV that is bound to a PVC, the PV is not removed immediately. PV removal is postponed until the PV is not bound to a PVC any more. @@ -112,6 +119,11 @@ When the [Storage Protection beta feature](/docs/tasks/administer-cluster/pvc-pr ======= When the [Storage Object in Use Protection beta feature](/docs/tasks/administer-cluster/pvc-protection/) is enabled, if a user deletes a PVC in active use by a pod, the PVC is not removed immediately. PVC removal is postponed until the PVC is no longer actively used by any pods. >>>>>>> Storage Protection was renamed to Storage Object in Use Protection (#7576) +||||||| merged common ancestors +When the [Storage Object in Use Protection beta feature](/docs/tasks/administer-cluster/pvc-protection/) is enabled, if a user deletes a PVC in active use by a pod, the PVC is not removed immediately. PVC removal is postponed until the PVC is no longer actively used by any pods. +======= +When the [Storage Object in Use Protection beta feature](/docs/tasks/administer-cluster/storage-object-in-use-protection/) is enabled, if a user deletes a PVC in active use by a pod, the PVC is not removed immediately. PVC removal is postponed until the PVC is no longer actively used by any pods, and also if admin deletes a PV that is bound to a PVC, the PV is not removed immediately. PV removal is postponed until the PV is not bound to a PVC any more. +>>>>>>> add pv protection description (#7620) You can see that a PVC is protected when the PVC's status is `Terminating` and the `Finalizers` list includes `kubernetes.io/pvc-protection`: diff --git a/docs/tasks/administer-cluster/pvc-protection.md b/docs/tasks/administer-cluster/pvc-protection.md deleted file mode 100644 index 8e72c95b91..0000000000 --- a/docs/tasks/administer-cluster/pvc-protection.md +++ /dev/null @@ -1,225 +0,0 @@ ---- -reviewers: -- msau42 -- jsafrane -title: Storage Object in Use Protection ---- - -{% capture overview %} -{% assign for_k8s_version="v1.10" %}{% include feature-state-beta.md %} - -Persistent volume claims (PVCs) that are in active use by a pod can be protected from pre-mature removal. - -{% endcapture %} - -{% capture prerequisites %} - -- The Storage Object in Use Protection feature is enabled in a version of Kubernetes in which it is supported. - -{% endcapture %} - -{% capture steps %} - -## Storage Object in Use Protection feature used for PVC Protection - -The example below uses a GCE PD `StorageClass`, however, similar steps can be performed for any volume type. - -Create a `StorageClass` for convenient storage provisioning: -```yaml -apiVersion: storage.k8s.io/v1 -kind: StorageClass -metadata: - name: slow -provisioner: kubernetes.io/gce-pd -parameters: - type: pd-standard -``` - -Verification scenarios follow below. - -### Scenario 1: The PVC is not in active use by a pod - -- Create a PVC: - -```yaml -kind: PersistentVolumeClaim -apiVersion: v1 -metadata: - name: slzc -spec: - accessModes: - - ReadWriteOnce - storageClassName: slow - resources: - requests: - storage: 3.7Gi -``` - -- Check that the PVC has the finalizer `kubernetes.io/pvc-protection` set: -```shell -$ kubectl describe pvc slzc -Name: slzc -Namespace: default -StorageClass: slow -Status: Bound -Volume: pvc-bee8c30a-d6a3-11e7-9af0-42010a800002 -Labels: -Annotations: pv.kubernetes.io/bind-completed=yes - pv.kubernetes.io/bound-by-controller=yes - volume.beta.kubernetes.io/storage-provisioner=kubernetes.io/gce-pd -Finalizers: [kubernetes.io/pvc-protection] -Capacity: 4Gi -Access Modes: RWO -Events: - Type Reason Age From Message - ---- ------ ---- ---- ------- - Normal ProvisioningSucceeded 2m persistentvolume-controller Successfully provisioned volume pvc-bee8c30a-d6a3-11e7-9af0-42010a800002 using kubernetes.io/gce-pd -``` - -- Delete the PVC and check that the PVC (not in active use by a pod) was removed successfully. - -### Scenario 2: The PVC is in active use by a pod - -- Again, create the same PVC. -- Create a pod that uses the PVC: - -```yaml -kind: Pod -apiVersion: v1 -metadata: - name: app1 -spec: - containers: - - name: test-pod - image: k8s.gcr.io/busybox:1.24 - command: - - "/bin/sh" - args: - - "-c" - - "date > /mnt/app1.txt; sleep 60 && exit 0 || exit 1" - volumeMounts: - - name: path-pvc - mountPath: "/mnt" - restartPolicy: "Never" - volumes: - - name: path-pvc - persistentVolumeClaim: - claimName: slzc -``` - -- Wait until the pod status is `Running`, i.e. the PVC becomes in active use. -- Delete the PVC that is now in active use by a pod and verify that the PVC is not removed but its status is `Terminating`: - -```shell -Name: slzc -Namespace: default -StorageClass: slow -Status: Terminating (since Fri, 01 Dec 2017 14:47:55 +0000) -Volume: pvc-803a1f4d-d6a6-11e7-9af0-42010a800002 -Labels: -Annotations: pv.kubernetes.io/bind-completed=yes - pv.kubernetes.io/bound-by-controller=yes - volume.beta.kubernetes.io/storage-provisioner=kubernetes.io/gce-pd -Finalizers: [kubernetes.io/pvc-protection] -Capacity: 4Gi -Access Modes: RWO -Events: - Type Reason Age From Message - ---- ------ ---- ---- ------- - Normal ProvisioningSucceeded 52s persistentvolume-controller Successfully provisioned volume pvc-803a1f4d-d6a6-11e7-9af0-42010a800002 using kubernetes.io/gce-pd -``` -- Wait until the pod status is `Terminated` (either delete the pod or wait until it finishes). Afterwards, check that the PVC is removed. - -### Scenario 3: A pod starts using a PVC that is in Terminating state - -- Again, create the same PVC. -- Create a first pod that uses the PVC: - -```yaml -kind: Pod -apiVersion: v1 -metadata: - name: app1 -spec: - containers: - - name: test-pod - image: k8s.gcr.io/busybox:1.24 - command: - - "/bin/sh" - args: - - "-c" - - "date > /mnt/app1.txt; sleep 600 && exit 0 || exit 1" - volumeMounts: - - name: path-pvc - mountPath: "/mnt" - restartPolicy: "Never" - volumes: - - name: path-pvc - persistentVolumeClaim: - claimName: slzc -``` - -- Wait until the pod status is `Running`, i.e. the PVC becomes in active use. -- Delete the PVC that is now in active use by a pod and verify that the PVC is not removed but its status is `Terminating`: - -```shell -Name: slzc -Namespace: default -StorageClass: slow -Status: Terminating (since Fri, 01 Dec 2017 14:47:55 +0000) -Volume: pvc-803a1f4d-d6a6-11e7-9af0-42010a800002 -Labels: -Annotations: pv.kubernetes.io/bind-completed=yes - pv.kubernetes.io/bound-by-controller=yes - volume.beta.kubernetes.io/storage-provisioner=kubernetes.io/gce-pd -Finalizers: [kubernetes.io/pvc-protection] -Capacity: 4Gi -Access Modes: RWO -Events: - Type Reason Age From Message - ---- ------ ---- ---- ------- - Normal ProvisioningSucceeded 52s persistentvolume-controller Successfully provisioned volume pvc-803a1f4d-d6a6-11e7-9af0-42010a800002 using kubernetes.io/gce-pd -``` - -- Create a second pod that uses the same PVC: - -``` -kind: Pod -apiVersion: v1 -metadata: - name: app2 -spec: - containers: - - name: test-pod - image: gcr.io/google_containers/busybox:1.24 - command: - - "/bin/sh" - args: - - "-c" - - "date > /mnt/app1.txt; sleep 600 && exit 0 || exit 1" - volumeMounts: - - name: path-pvc - mountPath: "/mnt" - restartPolicy: "Never" - volumes: - - name: path-pvc - persistentVolumeClaim: - claimName: slzc -``` - -- Verify that the scheduling of the second pod fails with the below warning: - -``` -Warning FailedScheduling 18s (x4 over 21s) default-scheduler persistentvolumeclaim "slzc" is being deleted -``` - -- Wait until the pod status of both pods is `Terminated` or `Completed` (either delete the pods or wait until they finish). Afterwards, check that the PVC is removed. - -{% endcapture %} - -{% capture discussion %} - - -{% endcapture %} - -{% include templates/task.md %}