跳到主要内容
知仓学习社ZHICANG

gke-storage

>-

不碰外部(只输出文字)无严重或高危命中google/skills

它会碰到什么

扫了多少1 个文本文件,5 KB
它会碰到什么不碰外部(只输出文字)
命中总数0 处
命中统计严重 0 · 高 0 · 中 0 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

GKE Storage

This reference covers storage configuration for GKE clusters including

persistent disks, file storage, and cloud storage integration.

> MCP Tools: apply_k8s_manifest, get_k8s_resource,

> describe_k8s_resource, get_cluster

Golden Path Storage Defaults

The golden path Autopilot config enables these CSI drivers:

| Driver | Golden Path | Access Mode | Use Case |

| --------------- | ----------------- | --------------- | -------------------- |

| Compute Engine | Enabled (default) | ReadWriteOnce | Block storage for |

: Persistent Disk : : : databases, :

: CSI : : : single-pod workloads :

| Google Cloud | Enabled | ReadWriteMany | Shared NFS for |

: Filestore CSI : : : multi-pod access :

| Cloud Storage | Enabled | ReadWriteMany / | Mount GCS buckets as |

: FUSE CSI : : ReadOnlyMany : volumes :

| Parallelstore | Enabled | ReadWriteMany | High-performance |

: CSI : : : parallel file system :

| Boot disk type | pd-balanced | N/A | Node boot disks |

StorageClasses

Default StorageClasses

GKE provides built-in StorageClasses:

StorageClass | Disk Type | Use Case

-------------- | --------------------- | ------------------------------

standard-rwo | pd-standard | Cost-effective, low IOPS

premium-rwo | pd-ssd | High IOPS, databases

standard-rwx | Filestore (Basic HDD) | Shared NFS

premium-rwx | Filestore (Basic SSD) | Shared NFS, higher performance

Custom StorageClass

apiVersion: storage.k8s.io/v1
kind: StorageClass
metadata:
  name: fast-regional
provisioner: pd.csi.storage.gke.io
parameters:
  type: pd-ssd
  replication-type: regional-pd    # Replicate across 2 zones
volumeBindingMode: WaitForFirstConsumer
allowVolumeExpansion: true         # Always enable for production

PersistentVolumeClaims

Block Storage (ReadWriteOnce)

apiVersion: v1
kind: PersistentVolumeClaim
metadata:
  name: database-pvc
spec:
  accessModes:
  - ReadWriteOnce
  storageClassName: premium-rwo
  resources:
    requests:
      storage: 100Gi

Shared File Storage (ReadWriteMany via Filestore)

apiVersion: v1
kind: PersistentVolumeClaim
metadata:
  name: shared-data
spec:
  accessModes:
  - ReadWriteMany
  storageClassName: standard-rwx
  resources:
    requests:
      storage: 1Ti    # Filestore minimum is 1 TiB for Basic tier

GCS Bucket Mount (Cloud Storage FUSE)

Mount a GCS bucket as a volume without a PVC:

apiVersion: v1
kind: Pod
metadata:
  name: gcs-reader
  annotations:
    gke-gcsfuse/volumes: "true"
spec:
  containers:
  - name: reader
    image: busybox
    command: ["ls", "/data"]
    volumeMounts:
    - name: gcs-bucket
      mountPath: /data
  volumes:
  - name: gcs-bucket
    csi:
      driver: gcsfuse.csi.storage.gke.io
      readOnly: true
      volumeAttributes:
        bucketName: <BUCKET_NAME>

> Requires Workload Identity for the pod's service account to have

> storage.objectViewer on the bucket.

Volume Expansion

If allowVolumeExpansion: true is set on the StorageClass, resize by updating

the PVC:

# kubectl
kubectl patch pvc <PVC_NAME> -p '{"spec":{"resources":{"requests":{"storage":"200Gi"}}}}'
# MCP (preferred)
patch_k8s_resource(parent="...", resourceType="persistentvolumeclaim", name="<PVC_NAME>",
  patch='{"spec":{"resources":{"requests":{"storage":"200Gi"}}}}')

Kubernetes automatically resizes the filesystem.

Best Practices

  1. Always enable volume expansion: Set allowVolumeExpansion: true on all

StorageClasses

  1. Use regional PDs for production: replication-type: regional-pd

replicates across 2 zones for HA

  1. Use WaitForFirstConsumer: Ensures the PV is provisioned in the same

zone as the pod

  1. Choose the right disk type: pd-ssd for databases, pd-balanced

(golden path default) for general use, pd-standard for cold storage

  1. Use Filestore for shared access: When multiple pods need to read/write

the same files

  1. Use GCS FUSE for data pipelines: Mount buckets directly for ML training

data, logs, etc.

  1. Back up PVCs: Use Backup for GKE (see the gke-backup-dr skill) to

protect persistent data

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。