{"id":36484960,"url":"https://github.com/ccremer/kubernetes-zfs-provisioner","last_synced_at":"2026-01-12T01:46:53.864Z","repository":{"id":37080121,"uuid":"253203290","full_name":"ccremer/kubernetes-zfs-provisioner","owner":"ccremer","description":"Dynamic ZFS persistent volume provisioner for Kubernetes","archived":false,"fork":false,"pushed_at":"2025-12-18T03:12:01.000Z","size":481,"stargazers_count":93,"open_issues_count":16,"forks_count":12,"subscribers_count":7,"default_branch":"master","last_synced_at":"2025-12-21T13:01:25.502Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/ccremer.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE.txt","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2020-04-05T09:57:46.000Z","updated_at":"2025-10-31T12:48:30.000Z","dependencies_parsed_at":"2023-11-07T04:05:03.650Z","dependency_job_id":"52e0cebe-b012-4d32-87fc-aae47289a03e","html_url":"https://github.com/ccremer/kubernetes-zfs-provisioner","commit_stats":null,"previous_names":[],"tags_count":21,"template":false,"template_full_name":null,"purl":"pkg:github/ccremer/kubernetes-zfs-provisioner","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ccremer%2Fkubernetes-zfs-provisioner","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ccremer%2Fkubernetes-zfs-provisioner/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ccremer%2Fkubernetes-zfs-provisioner/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ccremer%2Fkubernetes-zfs-provisioner/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/ccremer","download_url":"https://codeload.github.com/ccremer/kubernetes-zfs-provisioner/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ccremer%2Fkubernetes-zfs-provisioner/sbom","scorecard":{"id":269383,"data":{"date":"2025-08-11","repo":{"name":"github.com/ccremer/kubernetes-zfs-provisioner","commit":"b005feb8fb0afb063149f71ccbd2e070a375f62d"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":2.6,"checks":[{"name":"Maintained","score":2,"reason":"2 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 2","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Code-Review","score":2,"reason":"Found 2/7 approved changesets -- score normalized to 2","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/build.yml:1","Warn: no topLevel permission defined: .github/workflows/chart-lint.yml:1","Warn: no topLevel permission defined: .github/workflows/chart-release.yml:1","Warn: no topLevel permission defined: .github/workflows/chart-test.yml:1","Warn: no topLevel permission defined: .github/workflows/lint.yml:1","Warn: no topLevel permission defined: .github/workflows/release.yml:1","Warn: no topLevel permission defined: .github/workflows/test.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/ccremer/kubernetes-zfs-provisioner/build.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/ccremer/kubernetes-zfs-provisioner/build.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/chart-lint.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/ccremer/kubernetes-zfs-provisioner/chart-lint.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/chart-lint.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/ccremer/kubernetes-zfs-provisioner/chart-lint.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/chart-lint.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/ccremer/kubernetes-zfs-provisioner/chart-lint.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/chart-release.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/ccremer/kubernetes-zfs-provisioner/chart-release.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/chart-release.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/ccremer/kubernetes-zfs-provisioner/chart-release.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/chart-release.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/ccremer/kubernetes-zfs-provisioner/chart-release.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/chart-release.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/ccremer/kubernetes-zfs-provisioner/chart-release.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/chart-test.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/ccremer/kubernetes-zfs-provisioner/chart-test.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/chart-test.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/ccremer/kubernetes-zfs-provisioner/chart-test.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/ccremer/kubernetes-zfs-provisioner/lint.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/ccremer/kubernetes-zfs-provisioner/lint.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/ccremer/kubernetes-zfs-provisioner/release.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/ccremer/kubernetes-zfs-provisioner/release.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/ccremer/kubernetes-zfs-provisioner/release.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/ccremer/kubernetes-zfs-provisioner/release.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/ccremer/kubernetes-zfs-provisioner/release.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/ccremer/kubernetes-zfs-provisioner/release.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/ccremer/kubernetes-zfs-provisioner/release.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/ccremer/kubernetes-zfs-provisioner/test.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/ccremer/kubernetes-zfs-provisioner/test.yml/master?enable=pin","Warn: containerImage not pinned by hash: docker/Dockerfile:1","Info:   0 out of  15 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   7 third-party GitHubAction dependencies pinned","Info:   0 out of   1 containerImage dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE.txt:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE.txt:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact v1.3.0 not signed: https://api.github.com/repos/ccremer/kubernetes-zfs-provisioner/releases/117010609","Warn: release artifact kubernetes-zfs-provisioner-2.2.1 not signed: https://api.github.com/repos/ccremer/kubernetes-zfs-provisioner/releases/117019679","Warn: release artifact kubernetes-zfs-provisioner-2.2.0 not signed: https://api.github.com/repos/ccremer/kubernetes-zfs-provisioner/releases/117011033","Warn: release artifact kubernetes-zfs-provisioner-2.1.0 not signed: https://api.github.com/repos/ccremer/kubernetes-zfs-provisioner/releases/78616444","Warn: release artifact v1.2.0 not signed: https://api.github.com/repos/ccremer/kubernetes-zfs-provisioner/releases/72939100","Warn: release artifact v1.3.0 does not have provenance: https://api.github.com/repos/ccremer/kubernetes-zfs-provisioner/releases/117010609","Warn: release artifact kubernetes-zfs-provisioner-2.2.1 does not have provenance: https://api.github.com/repos/ccremer/kubernetes-zfs-provisioner/releases/117019679","Warn: release artifact kubernetes-zfs-provisioner-2.2.0 does not have provenance: https://api.github.com/repos/ccremer/kubernetes-zfs-provisioner/releases/117011033","Warn: release artifact kubernetes-zfs-provisioner-2.1.0 does not have provenance: https://api.github.com/repos/ccremer/kubernetes-zfs-provisioner/releases/78616444","Warn: release artifact v1.2.0 does not have provenance: https://api.github.com/repos/ccremer/kubernetes-zfs-provisioner/releases/72939100"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 28 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":0,"reason":"14 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GO-2022-0635","Warn: Project is vulnerable to: GO-2022-0646","Warn: Project is vulnerable to: GO-2023-2402 / GHSA-45x7-px36-x8w8","Warn: Project is vulnerable to: GO-2024-3321 / GHSA-v778-237x-gjrc","Warn: Project is vulnerable to: GO-2025-3487 / GHSA-hcg3-q754-cr77","Warn: Project is vulnerable to: GO-2023-1988 / GHSA-2wrh-6pvc-2jm9","Warn: Project is vulnerable to: GO-2023-2102 / GHSA-4374-p667-p6c8","Warn: Project is vulnerable to: GHSA-qppj-fm5r-hxr3","Warn: Project is vulnerable to: GO-2024-2687 / GHSA-4v7x-pqxf-cx7m","Warn: Project is vulnerable to: GO-2024-3333","Warn: Project is vulnerable to: GO-2025-3503 / GHSA-qxp5-gwg8-xv66","Warn: Project is vulnerable to: GO-2025-3595 / GHSA-vvgc-356p-c3xw","Warn: Project is vulnerable to: GO-2025-3488 / GHSA-6v2p-p543-phr9","Warn: Project is vulnerable to: GO-2024-2611 / GHSA-8r3f-844c-mc37"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-17T12:57:30.609Z","repository_id":37080121,"created_at":"2025-08-17T12:57:30.609Z","updated_at":"2025-08-17T12:57:30.609Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28331253,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-12T00:36:25.062Z","status":"ssl_error","status_checked_at":"2026-01-12T00:36:15.229Z","response_time":60,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2026-01-12T01:46:52.946Z","updated_at":"2026-01-12T01:46:53.857Z","avatar_url":"https://github.com/ccremer.png","language":"Go","funding_links":[],"categories":["How to Use OpenZFS with Kubernetes for Persistent Storage (ZFS on K8S)"],"sub_categories":["ZFS other tools"],"readme":"# Looking for maintainer\n\nSee [137](https://github.com/ccremer/kubernetes-zfs-provisioner/issues/137)\n\n# Dynamic ZFS provisioner for Kubernetes\n\n[![Build](https://img.shields.io/github/workflow/status/ccremer/kubernetes-zfs-provisioner/Test)][build]\n![Go version](https://img.shields.io/github/go-mod/go-version/ccremer/kubernetes-zfs-provisioner)\n[![Version](https://img.shields.io/github/v/release/ccremer/kubernetes-zfs-provisioner)][releases]\n[![GitHub downloads](https://img.shields.io/github/downloads/ccremer/kubernetes-zfs-provisioner/total)][releases]\n\nkubernetes-zfs-provisioner is a dynamic ZFS persistent volume provisioner for Kubernetes.\nIt creates ZFS datasets via SSH on remote hosts and shares them via [NFS][nfs] to make them mountable to pods.\n\n![architecture with NFS](architecture.nfs.drawio.svg \"Architecture with NFS provisioning\")\n\nAlternatively, if the ZFS hosts are part of the cluster, [HostPath][hostpath] is also possible,\nbut the `PersistentVolume` objects will have a [NodeAffinity][node affinity] configured.\n\n![architecture with Hostpath](architecture.hostpath.drawio.svg \"Architecture with Hostpath provisioning\")\n\nAs a third option, if the ZFS host is part of the cluster, you can let the provisioner choose\nwhether [NFS][nfs] or [HostPath][hostpath] is used with the `Auto` mode. If the requested\n[AccessModes][access modes] in the Persistent Volume Claim contains `ReadWriteOnce` (the volume\ncan only be accessed by pods running on the same node), or `ReadWriteOncePod` (the volume can only\nbe accessed by one single Pod at any time), then [HostPath][hostpath] will be used and\nthe [NodeAffinity][node affinity] will be configured on the `PersistentVolume` objects so the\nscheduler will automatically place the corresponding Pods onto the ZFS host. Otherwise\n[NFS][nfs] will be used and [NodeAffinity][node affinity] will not be set. If multiple (exclusive)\n[AccessModes][access modes] are given, [NFS][nfs] takes precedence.\n\nCurrently all ZFS attributes are inherited from the parent dataset.\n\nFor more information about external storage in kubernetes, see\n[kubernetes-sigs/sig-storage-lib-external-provisioner][lib provisioner].\n\n## Installation\n\nRecommended option is via [Helm][helm chart]\n\n## Configuration\n\nThe provisioner relies on an already set up Zpool and a dataset by the administrator.\nIt also needs **SSH access** to the target ZFS hosts, i.e. mount the SSH private key and\nconfig to the container so that the executing user can find it.\n\n### Provisioner\n\nBy **default the container image should work out of the box** when installed in the cluster.\nThe only thing to configure is SSH, the [Helm Chart][helm chart] should help you with that.\n\nThe provisioner can be configured via the following environment variables:\n\n| Variable | Description | Default |\n| :------: | :---------- | :-----: |\n| `ZFS_METRICS_PORT` | Port on which to export Prometheus metrics. | `8080` |\n| `ZFS_METRICS_ADDR` | Interface binding address on which to export Prometheus metrics. | `0.0.0.0` |\n| `ZFS_KUBE_CONFIG_PATH` | Kubeconfig file path in which the credentials and API URL are defined. | `` |\n| `ZFS_PROVISIONER_INSTANCE` | The instance name needs to be unique if multiple provisioners are deployed. | `pv.kubernetes.io/zfs` |\n\nThe provisioner instance name is also stored as a ZFS user property in the created\ndataset of the form `io.kubernetes.pv.zfs:managed_by` for system administrators, but is not\nfurther significant to the provisioner.\n\n### Storage Classes\n\nThe provisioner relies on properly configured storage classes. The following shows an example\nfor the [HostPath][hostpath] type.\n\n```yaml\nkind: StorageClass\napiVersion: storage.k8s.io/v1\nmetadata:\n  name: zfs-hostpath\nprovisioner: pv.kubernetes.io/zfs\nreclaimPolicy: Delete\nparameters:\n  parentDataset: tank/kubernetes\n  hostname: storage-1.domain.tld\n  type: hostpath\n  node: storage-1 # the kubernetes.io/hostname label if different than hostname parameter (optional)\n  reserveSpace: true\n```\n\nFollowing example configures a storage class for ZFS over [NFS][nfs]:\n```yaml\nkind: StorageClass\napiVersion: storage.k8s.io/v1\nmetadata:\n  name: zfs-nfs\nprovisioner: pv.kubernetes.io/zfs\nreclaimPolicy: Retain\nparameters:\n  parentDataset: tank/kubernetes\n  hostname: storage-1.domain.tld\n  type: nfs\n  shareProperties: rw,no_root_squash # no_root_squash by default sets mode to 'ro'\n  reserveSpace: true\n```\nFor NFS, you can also specify other options, as described in [exports(5)][man exports].\n\nThe following example configures a storage class using the `Auto` type. The provisioner\nwill decide whether [HostPath][hostpath] or [NFS][nfs] will be used based on the\n[AccessModess][access modes] requested by the persistent volume claim.\n\n```yaml\nkind: StorageClass\napiVersion: storage.k8s.io/v1\nmetadata:\n  name: zfs-nfs\nprovisioner: pv.kubernetes.io/zfs\nreclaimPolicy: Retain\nparameters:\n  parentDataset: tank/kubernetes\n  hostname: storage-1.domain.tld\n  type: auto\n  node: storage-1 # the name of the node where the ZFS datasets are located.\n  shareProperties: rw,no_root_squash\n  reserveSpace: true\n```\n\n## Notes\n\n### Reclaim policy\n\nThis provisioner supports the `Delete` and `Retain` reclaim policies, with `Delete` being\ndefault if unspecified. The reclaim policy is also stored as ZFS user property of the form\n`io.kubernetes.pv.zfs:reclaim_policy` for system administrators, but is not\nfurther significant to the provisioner.\n\n### Storage space\n\nBy default, the provisioner uses the `refreservation` and `refquota` ZFS attributes\nto limit storage space for volumes. Each volume can not use more storage space than\nthe given resource request and also reserves exactly that much. To disable this and\nenable thin provisioning, set `reserveSpace` to `false` in your storage class parameters.\nSnapshots **do not** account for the storage space limit, however this provisioner\ndoes not do any snapshots or backups.\n\nSee [zfs(8)][man zfs] for more information.\n\n### Security\n\nFirst of all, no warranties and use at own risk.\n\nMaking a container image and creating ZFS datasets from a container is not exactly\neasy, as ZFS runs in kernel. While it's possible to pass `/dev/zfs` to a container\nso it can create and destroy datasets within the container, sharing the volume with NFS\ndoes not work.\n\nSetting `sharenfs` property to anything other than `off` invokes [exportfs(8)][man exportfs],\nthat requires also running the NFS Server to reload its exports. Which is not the case\nin a container (see [zfs(8)][man zfs]).\n\nBut most importantly: Mounting `/dev/zfs` inside the provisioner container would mean that\nthe datasets will only be created on the same host as the container currently runs.\n\nSo, in order to \"break out\" of the container the `zfs` calls are wrapped and redirected\nto another host over **SSH**. This requires SSH private keys to be mounted in the container\nfor a SSH user with sufficient permissions to run `zfs` commands on the target host.\n\nExample sudoers file in `/etc/sudoers.d/zfs-provisioner` (On the ZFS host):\n```\nzfs-provisioner ALL=(ALL) NOPASSWD:/sbin/zfs *,/bin/chmod *\n```\n\nFor increased performance and security install ZFS on all Kubernetes nodes thats should\nprovide ZFS storage. Then it's possible to create `PersistentVolume` objects with [HostPath][hostpath].\nThis eliminates network latency over unencrypted NFS, but schedules the pods to the ZFS hosts only.\n\n## Development\n\n### Requirements\n\n* go\n* docker\n* ZFS and NFS (run `make install:zfs` on Debian/Ubuntu if not already installed)\n\n### Building and Testing\n\nRun `make help` to see which target does what.\n\n## Troubleshooting\n\n### Filesystem created, but not shared\n\n```\ncontroller.go:920] error syncing claim \"56ea786a-e376-4911-a4b1-7b040dc3537f\": failed to provision volume\nwith StorageClass \"zfs-retain-pve-1\": creating ZFS dataset failed: exit status 1:\n\"/usr/bin/zfs zfs create -o sharenfs=rw,no_root_squash ... tank/kubernetes/\npvc-56ea786a-e376-4911-a4b1-7b040dc3537f\" =\u003e cannot share 'tank/kubernetes/\npvc-56ea786a-e376-4911-a4b1-7b040dc3537f': share(1M) failed\nfilesystem successfully created, but not shared\n```\n\nThis happens when the dataset got created, but invoking `zfs share` is failing.\nMost likely because from [zfs(8)][man zfs] it's stated that [exportfs(8)][man exportfs] is invoked, which talks to the NFS server.\n\nSo, have you got `nfs-kernel-server` installed on the host and is `exportfs` available?\n\nOnce you solve this, destroy the dataset again, as the following retries will fail forever:\n\n```\ncannot create 'tank/services/kubernetes/pvc-56ea786a-e376-4911-a4b1-7b040dc3537f': dataset already exists\n```\n\n## Credits\n\nThanks to [Gentics][gentics] for open sourcing the [initial version][gentics repo]!\n\nI (@ccremer) have been allowed to take over maintenance for this repository.\n\n\n[build]: https://github.com/ccremer/kubernetes-zfs-provisioner/actions?query=workflow%3ATest\n[releases]: https://github.com/ccremer/kubernetes-zfs-provisioner/releases\n[node affinity]: https://kubernetes.io/docs/concepts/storage/persistent-volumes/#node-affinity\n[lib provisioner]: https://github.com/kubernetes-sigs/sig-storage-lib-external-provisioner\n[hostpath]: https://kubernetes.io/docs/concepts/storage/volumes/#hostpath\n[nfs]: https://kubernetes.io/docs/concepts/storage/volumes/#nfs\n[man zfs]: https://linux.die.net/man/8/zfs\n[man exportfs]: https://linux.die.net/man/8/exportfs\n[man exports]: https://linux.die.net/man/5/exports\n[helm chart]: https://github.com/ccremer/kubernetes-zfs-provisioner/blob/master/charts/kubernetes-zfs-provisioner/README.md\n[gentics]: https://www.gentics.com/genticscms/index.en.html\n[gentics repo]: https://github.com/gentics/kubernetes-zfs-provisioner\n[access modes]: https://kubernetes.io/docs/concepts/storage/persistent-volumes/#access-modes\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fccremer%2Fkubernetes-zfs-provisioner","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fccremer%2Fkubernetes-zfs-provisioner","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fccremer%2Fkubernetes-zfs-provisioner/lists"}