AKS Azure Disk CSI — StorageClass, PVC binding, reclaim
A StorageClass is a recipe. A PVC is a request. The Azure Disk appears only after bind and provision succeed.
<!-- hal:authoritative:yaml -->
A StorageClass is a recipe. A PVC is a request. The Azure Disk appears only after bind and provision succeed.
§I - Frame
09-21 spent EKS Pod Identity associations. 09-18 spent GKE Gateway listeners. 09-12 spent AKS PSA namespace labels. Those fires stay filed.
Today the cloud referent is AKS block storage. Concrete objects: Azure Disk CSI (disk.csi.azure.com), built-in managed-csi / managed-csi-premium StorageClasses, a PersistentVolumeClaim that selects a class, and the reclaim policy copied onto the PersistentVolume at provision time.
Bootcamp azurecheatsheet lists Disk Storage as managed disks and names AKS as managed Kubernetes. AZ-900 places AKS on compute and Disk / Blob / File on storage. Tonight: class recipe, claim bind, disk SKU and zone, reclaim edge. Azure Files CSI stays adjacent (often RWX), not the primary spine.
08-10 taught EKS EBS CSI and WaitForFirstConsumer. 08-22 taught GKE PD CSI Retain. This fire rotates the same PV subsystem onto AKS disk CSI.
§II - Three shelves
| Shelf | What it is | What it is not |
|---|---|---|
| StorageClass | Named recipe: provisioner disk.csi.azure.com, parameters (skuname), reclaimPolicy, volumeBindingMode | A disk you can mount without a claim |
| PVC | Namespaced request: size, accessModes, storageClassName | The Azure Disk resource itself |
| PV (dynamic) | Cluster object CSI creates and binds to the claim | Something to hand-edit for ordinary app volumes on AKS |
Azure Disk access mode in practice is ReadWriteOnce. Two Pods on different nodes cannot share one disk. Shared writers need Azure Files CSI or a different data shape.
§III - Mechanism on AKS
kubectl get sc
kubectl describe sc managed-csi
kubectl get csidriver disk.csi.azure.com
Typical AKS disk classes (names vary slightly by version):
| Class | Provisioner | Common skuname | Usual bind mode |
|---|---|---|---|
| managed-csi | disk.csi.azure.com | StandardSSD_LRS | WaitForFirstConsumer |
| managed-csi-premium | disk.csi.azure.com | Premium_LRS | WaitForFirstConsumer |
| legacy managed / default | older alias | Standard_LRS family | verify before reuse |
WaitForFirstConsumer waits for a consumer Pod to schedule before creating the disk, keeping disk and node in the same zone. Immediate provisions when the PVC appears; on multi-zone pools that can strand a zonal disk the scheduler cannot place.
SKU: StandardSSD_LRS is the balanced default for many managed-csi installs. Premium_LRS raises IOPS cost. UltraSSD and PremiumV2 need explicit parameters and region/node support; do not invent them on a stem that only shows managed-csi.
Reclaim (Poulton Ch.10): StorageClass reclaimPolicy is copied onto the PV at create. Delete removes the PV and asks CSI to delete the Azure Disk when the PVC goes. Retain keeps PV and disk; clear claimRef before any reuse. AKS managed-csi defaults to Delete. Treat Retain as an intentional class you create.
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: app-data
namespace: demo
spec:
accessModes: ["ReadWriteOnce"]
storageClassName: managed-csi
resources:
requests:
storage: 20Gi
Mount from a single-writer Pod (Deployment Recreate, or StatefulSet volumeClaimTemplate). A rolling update that runs two RWO consumers on different nodes leaves the second Pod Pending.
§IV - Failure modes
- Surprising default class. Check
kubectl get scfor the(default)marker. Q14 shape: exactly one default. Zero defaults plus omitted class yields Pending. Two defaults break the cluster contract. - Immediate bind across zones. PVC Bound in zone A; Pod toward zone B; volume node affinity conflict. Prefer WaitForFirstConsumer on disk classes.
- RWX expectation on Azure Disk. Disk CSI will not multi-node write. Change product or architecture.
- Delete reclaim on durable data. PVC delete destroys the disk. Use a Retain class when bytes must survive claim removal.
- Mixing provision with attach. Provision creates the disk. Attach/mount is the node CSI half after the Pod lands. Describe PVC events and Pod events separately.
§V - Ops drill
kubectl get scon an AKS lab cluster; note default class and provisioner strings.- Create namespace
demo; apply a 20Gi RWO PVC onmanaged-csi(or the cluster disk CSI default). - Before any Pod: observe PVC phase (Pending vs Bound by bind mode).
- Start one Pod that mounts the claim. Confirm Bound and an Azure Disk in the node resource group.
- Optional: create a one-off class with
disk.csi.azure.com,reclaimPolicy: Retain,volumeBindingMode: WaitForFirstConsumer; provision tiny PVC+Pod; delete PVC; confirm PV Released and disk still present; clean up by hand.
Success criteria: name provisioner, default class, bind mode, SKU parameter, and reclaim consequence from kubectl alone; PVC Bound with a consumer Pod; Retain contrast (if run) leaves the disk after PVC delete.
§VI - Close instruction
Apply the drill on AKS. Paste kubectl get sc,pvc,pv from the Bound state. Pair: Dev censuses StorageClasses and PVC phases with the Python kubernetes client; Cert drills CKA StorageClass create/default (Q14) plus PVC/PV bind and reclaim. Maghrib owns quiz.html later.
Related
- Prior AKS Ops: PSA + Azure Policy (09-12)
- Prior: EKS EBS CSI (08-10)
- Dev: StorageClass + PVC census
- Cert: CKA StorageClass PVC PV
- Bootcamp: CKA Q14