Skip to content

Update CSI sidecar images and set a csi-snapshotter timeout - #44

Open
mw-0 wants to merge 1 commit into
shapeblue:mainfrom
mw-0:fix/update-sidecars
Open

mw-0 wants to merge 1 commit into
shapeblue:mainfrom
mw-0:fix/update-sidecars

Conversation

@mw-0

@mw-0 mw-0 commented Oct 5, 2026

Copy link
Copy Markdown

These are the newest versions published on registry.k8s.io. csi-resizer v2.3.0 is tagged upstream but not yet published, so v2.2.1 is used.

Updated in both deploy/k8s/ and the Helm chart values; the chart version is bumped to 3.0.3.

VolumeAttributesClass RBAC: csi-resizer v2 (and csi-provisioner v6) use the storage.k8s.io/v1 VolumeAttributesClass API on Kubernetes 1.34+. This adds read access (get/list/watch on volumeattributesclasses) to the controller role in deploy/k8s/rbac.yaml and to the chart's resizer role, matching the upstream resizer RBAC.
On clusters without the v1 API, both sidecars switch the feature off automatically.
The driver doesn't implement ControllerModifyVolume, so this only lets the sidecars start cleanly; it adds no new behaviour.
Flags: all existing sidecar flags are still supported. --mode=kubelet-registration-probe and --health-port on the node registrar are deprecated upstream but still work; they are left unchanged here.
Sidecar images: bump csi-snapshotter and snapshot-controller from v6.3.0 to v8.6.0 in deploy/k8s/controller-deployment.yaml.
The bundled CRDs (deploy/k8s/00-snapshot-crds.yaml) were already the v8.3.0 versions, so the controllers and CRDs are now from the same release line.
The v8.6.0 CRD content is identical to v8.3.0; only the source comments change (they also previously pointed at a group-snapshot file by mistake). Existing clusters don't need to re-apply the CRDs.
Snapshotter timeout: add --timeout=300s to csi-snapshotter, matching the other sidecars in this manifest.
Without it, the sidecar uses its 1-minute default.
The CloudStack client doesn't cancel a request when the RPC times out, so any snapshot that takes longer than a minute was retried while CloudStack was still working.
On the 3.0.0 release, this produced duplicate CloudStack snapshots for a single VolumeSnapshot.
RBAC: add patch to the cloudstack-csi-snapshotter-role rules for volumesnapshotcontents, volumesnapshotcontents/status and volumesnapshots, matching the upstream v8.6.0 sidecar RBAC.
Volume group snapshots stay disabled: the CSIVolumeGroupSnapshot feature gate defaults to off in v8.6.0, so no group snapshot CRDs or RBAC are needed.

Fixes from v6.3.0 → v8.6.0 that affect this driver (from the external-snapshotter changelogs):

Snapshot deletion is now retried properly when the snapshot is being used as the source of a PVC restore. Previously it waited for a periodic resync, which took minutes.
Snapshots marked for deletion while the driver is still taking them are now handled.
Waiting for a snapshot to become ready uses exponential back-off. This matters for drivers that report ReadyToUse: false while CloudStack backs up the snapshot.
Fixed the sidecar making rapid repeated RPC calls after its own status updates.
Several finalizer-removal races and CVE fixes.

Compatibility: the v8 CRDs use CEL validation rules, which needs Kubernetes 1.25 or later. This requirement already applied, because the bundled CRDs were already v8.3.0. The Helm chart doesn't currently deploy the snapshotter, so it is unchanged here.

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant