The module lifecycle stage: General Availability
The module has requirements for installation
v0.3.24
Release date: 2026-09-14
A maintenance release: the module is rebuilt with the Go 1.27.1 toolchain on the v2.1.17 base images, with no change to its behaviour.
Highlights
Changes in this release:
- Every component of the module is built with Go 1.27.1 on the v2.1.17 base images. Nothing in the module’s behaviour, resources or settings changes.
Upgrade notes
Before upgrading, note the following:
- The update needs nothing done by hand. Resources, module settings and existing volumes are untouched, and the controller and node pods are only restarted with the rebuilt images.
v0.3.23
Release date: 2026-09-09
The module now installs the iSCSI stack itself on nodes whose repositories cannot provide it, lets a HuaweiStorageClass decide how much of an ext4 volume stays with the superuser, and exports controller metrics.
Highlights
Changes in this release:
- A node whose repositories have no
open-iscsiandmultipath-toolsis no longer left unusable: the module unpacks its own package image there and runs the daemons from it. - An ext4 volume no longer keeps 5% of its space for the superuser; a
HuaweiStorageClasscan ask for a share back with an annotation. - The module controller exports metrics, and Prometheus is allowed to scrape them.
New features
This release adds:
- A node that cannot install
open-iscsiandmultipath-toolsfrom its own repositories now gets them from the module: theNodeGroupConfigurationunpacks the module’siscsi-toolsimage under/var/lib/deckhouse/sds/csi-huaweiand startsd8-csi-huawei-iscsid.serviceandd8-csi-huawei-multipathd.service. The node’s own packages stay the preferred path, and a node that has them is left untouched. - The
storage.deckhouse.io/ext4-reserved-percentannotation on aHuaweiStorageClasssets the share of a volume kept for the superuser: a whole number of percent from 0 to 50. It applies to ext filesystems only, a class withfsType: xfsignores it, and an invalid value leaves theHuaweiStorageClasswithReady=Falseand the reason in its status instead of failing volume creation later. - The module controller serves metrics through a kube-rbac-proxy: reconcile counts and durations, workqueue depth, client-go latency, with a ServiceMonitor for Prometheus. The ports are configurable through the
controllerMetricsPortandcontrollerMetricsProxyPortmodule settings.
Improvements
This release improves:
- When the storage system refuses to create a volume, the
ProvisioningFailedevent now carries the message and the suggestion the array returned, not just the numeric DeviceManager error code. - Controller log lines carry their fields as key-value pairs and name the component they come from, instead of packing a prefix into the message text.
Fixes
This release fixes:
- Prometheus could not scrape the module controller: the kube-rbac-proxy in front of the metrics was not allowed to create the
TokenReviewandSubjectAccessReviewit needs, so every scrape was refused and the target stayed down. - A node could be left with
csi-nodeinCrashLoopBackOffand the driver missing from itsCSINodeobject, with volumes failing to attach there. The liveness probe of the node container watched a port served by the registrar sidecar next to it, so an exiting registrar took the driver down with it.
Upgrade notes
Before upgrading, note the following:
- The change to the ext4 superuser reserve applies to volumes created after the update; filesystems that already exist keep the reserve they were created with. Nothing has to be done by hand, and a class that wants the reserve back needs the annotation.
- The controller metrics start being scraped once the module pods are recreated by the update. A
TargetDownalert raised for the module controller clears on its own.
Docs
Documentation changes:
- Two new FAQ entries: what happens if a node’s repositories cannot provide the iSCSI stack, and how much of a volume is reserved for the superuser.
Dependencies
Dependency updates:
deckhouse_lib_helm:1.72.18→1.72.22- Carries the csi-node liveness-probe fix and the RBAC contract for the metrics proxy.
v0.3.22
- Before mounting a pre-formatted volume, a file system check for ext2/3/4 is performed (e2fsck -p): repairable errors are fixed automatically, a volume with irreparable errors is no longer mounted until manual recovery
- The FAQ now includes a procedure for recovering a volume that fails to mount due to file system errors
- Base images updated to v2.1.5, Go to 1.26.6, and lib-helm to 1.72.17
- Internal build changes for the module
v0.3.21
- Fix: the release image is no longer built from cache with an outdated changelog.yaml — git-mapping dependencies are bound to the install stage, where the file is copied
- Update base images to v2.1.4
- Internal build changes for the module
v0.3.20
- Bugfix: the controller is granted patch on events instead of list - a repeated event write is no longer denied by RBAC
v0.3.19
- Fix: multipath stops holding I/O after deleting the last path to the LUN (added flush_on_last_del setting) - eliminates node hang in NotReady
- The documentation removed the outdated example of volumeBindingMode in HuaweiStorageClass, added an example of connecting via Fiber Channel
- Update base images to v2.1.2, Go to 1.26.6 and lib-helm to 1.72.14
- Internal changes in module assembly
v0.3.18
- HuaweiStorageClass and HuaweiStorageConnection publish status.conditions and status.observedGeneration, added Ready column. The status.phase field retains the same set of values, but is now calculated from the Ready condition
- Update base images to v1.3.25, Go 1.26.5 and lib-helm to 1.72.13
v0.3.17
- Bugfix: Fixed failure to launch the csi-node pod on nodes with containerd v2 - added mounting hostPath /sys/fs/cgroup
v0.3.16
- The snapshot-controller module is no longer a required dependency: VolumeSnapshotClass is created only if the snapshot.storage.k8s.io API is available
- Update base images, Go 1.26.5 and lib-helm to 1.72.12
- Fixed a vulnerability in gRPC (GHSA-hrxh-6v49-42gf)
- Internal changes in module assembly
v0.3.15
- Update base images, Go 1.26.5 and lib-helm to 1.72.10
- Internal changes in module assembly
v0.3.14
- Bugfix: fixed csi-node pod cyclic restart caused by synchronous cleanup of legacy devices
- Fix: Deckhouse registry access secrets are now limited to the active image source
- Update base images, Go 1.26.5 and lib-helm to 1.72.9
- Internal changes in module assembly
v0.3.13
- Added automatic recovery of inaccessible Huawei storage backends
- When forwarding labels from HuaweiStorageClass to StorageClass, labels with specified ignored prefixes are now excluded
- Update base images and lib-helm to 1.72.0
v0.3.12
- Tags from HuaweiStorageClass are now forwarded to the managed StorageClass Kubernetes
- Update base images, Go 1.25.10 and lib-helm 1.71.12
v0.3.11
- Internal changes in the structure and assembly of the module
v0.3.10
- Update base images, Go 1.25.10 and lib-helm 1.71.11
- Internal changes to the module assembly
v0.3.9
- Corrections to the module structure
v0.3.8
- Documentation updated (review, broken links fixed)
- Changes in CI: DistroPackagesProxy and env proxy in werf, improvements to CVE scans (role_name, checkout)
- Added user-authz cluster roles in templates
v0.3.7
- Installing packages in NodeGroupConfiguration no longer causes the script to crash on errors
v0.3.6
- Added missing mount points in csi-huawei distroless images
- Update base images, Go and lib-helm (CVE fix)
- Clarifications in the documentation
v0.3.5
- Added list of supported storage systems
v0.3.4
- Changes for distroless (complete rejection of nsenter where possible)
v0.3.3
- Fixes for regression when resizing a volume that arose as a result of switching to distroless (fixed too narrow mounting of /sys from the host)
v0.3.2
- Corrections for regression when remounting a volume that arose as a result of switching to distroless (in some cases the WWN of the volumes does not match)
v0.3.1
- Corrections for regression when remounting a volume that arose as a result of switching to distroless (in some cases the WWN of the volumes does not match)
v0.3.0
- Translation of the module into distroless (with active patching of the original CSI, which is not suitable for this)
- Changes in documentation
- Update base images and golang version
- Updated hooks that work when a module is removed
- Disabled Capacity request from k8s (CSI does not support issuing Capacity)
v0.2.9
- Corrections to the logic of working with volume snapshots
v0.2.8
- Edits to documentation
- Edits in manifestos
- Corrections to the logic of working with volume snapshots
- Update base images
v0.2.7
- Updated base images versions
v0.2.6
- Updated Go version to 1.24.9
- Updated lib-helm to deckhouse_lib_helm-1.64.1
v0.2.5
- Added release notes
v0.2.4
- Added information about the need for snapshot-controller for module operation
- Added readonlyRootFilesystem for enhanced module security
v0.2.3
- Added dependency on snapshot-controller
v0.2.2
- Added instructions for using Huawei storage systems in multiple Kubernetes clusters
v0.2.1
- Updated CSI to version v4.11.0
- CVE fix
- Added hook that removes unnecessary resources remaining after module deletion
v0.1.1
- Updated golang to 1.23.6
- Removed Experimental status
v0.1.0
- Initial release, basic functionality works