chore: add local-path-provisioner csi
fail-fast: false
+ - local-path-provisioner
- rbd
- name: Checkout project
+# Patterns to ignore when building packages.
+# This supports shell glob matching, relative path matching, and
+# negation (prefixed with !). Only one pattern per line.
+# Common VCS dirs
+# Common backup files
+# Various IDEs
+apiVersion: v1
+description: Use HostPath for persistent local storage with Kubernetes
+name: local-path-provisioner
+version: 0.0.24
+appVersion: "v0.0.24"
+ - storage
+ - hostpath
+kubeVersion: ">=1.12.0-r0"
+ -
+# Local Path Provisioner
+[Local Path Provisioner]( provides a way for the Kubernetes users to
+utilize the local storage in each node. Based on the user configuration, the Local Path Provisioner will create
+`hostPath` based persistent volume on the node automatically. It utilizes the features introduced by Kubernetes [Local
+Persistent Volume feature](, but make it a simpler
+solution than the built-in `local` volume feature in Kubernetes.
+## TL;DR;
+$ git clone
+$ cd local-path-provisioner
+$ helm install --name local-path-storage --namespace local-path-storage ./deploy/chart/
+## Introduction
+This chart bootstraps a [Local Path Provisioner]( deployment on a
+[Kubernetes]( cluster using the [Helm]( package manager.
+## Prerequisites
+- Kubernetes 1.12+ with Beta APIs enabled
+## Installing the Chart
+To install the chart with the release name `local-path-storage`:
+$ git clone
+$ cd local-path-provisioner
+$ helm install ./deploy/chart/ --name local-path-storage --namespace local-path-storage
+The command deploys Local Path Provisioner on the Kubernetes cluster in the default configuration. The
+[configuration](#configuration) section lists the parameters that can be configured during installation.
+> **Tip**: List all releases using `helm list`
+## Uninstalling the Chart
+To uninstall/delete the `local-path-storage` deployment:
+$ helm delete --purge local-path-storage
+The command removes all the Kubernetes components associated with the chart and deletes the release.
+## Configuration
+The following table lists the configurable parameters of the Local Path Provisioner for Kubernetes chart and their
+default values.
+| Parameter | Description | Default |
+| ----------------------------------- | ------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------- |
+| `image.repository` | Local Path Provisioner image name | `rancher/local-path-provisioner` |
+| `image.tag` | Local Path Provisioner image tag | `v0.0.24` |
+| `image.pullPolicy` | Image pull policy | `IfNotPresent` |
+| `storageClass.create` | If true, create a `StorageClass` | `true` |
+| `storageClass.provisionerName` | The provisioner name for the storage class | `nil` |
+| `storageClass.defaultClass` | If true, set the created `StorageClass` as the cluster's default `StorageClass` | `false` |
+| `` | The name to assign the created StorageClass | local-path |
+| `storageClass.reclaimPolicy` | ReclaimPolicy field of the class | Delete |
+| `nodePathMap` | Configuration of where to store the data on each node | `[{node: DEFAULT_PATH_FOR_NON_LISTED_NODES, paths: [/opt/local-path-provisioner]}]` |
+| `resources` | Local Path Provisioner resource requests & limits | `{}` |
+| `rbac.create` | If true, create & use RBAC resources | `true` |
+| `serviceAccount.create` | If true, create the Local Path Provisioner service account | `true` |
+| `` | Name of the Local Path Provisioner service account to use or create | `nil` |
+| `nodeSelector` | Node labels for Local Path Provisioner pod assignment | `{}` |
+| `tolerations` | Node taints to tolerate | `[]` |
+| `affinity` | Pod affinity | `{}` |
+| `configmap.setup` | Configuration of script to execute setup operations on each node | #!/bin/sh<br>while getopts "m:s:p:" opt<br>do<br> case $opt in <br>  p)<br>  absolutePath=$OPTARG<br>  ;;<br>  s)<br>  sizeInBytes=$OPTARG<br>  ;;<br>  m)<br>  volMode=$OPTARG<br>  ;;<br> esac<br>done<br>mkdir -m 0777 -p ${absolutePath} |
+| `configmap.teardown` | Configuration of script to execute teardown operations on each node | #!/bin/sh<br>while getopts "m:s:p:" opt<br>do<br> case $opt in <br>  p)<br>  absolutePath=$OPTARG<br>  ;;<br>  s)<br>  sizeInBytes=$OPTARG<br>  ;;<br>  m)<br>  volMode=$OPTARG<br>  ;;<br> esac<br>done<br>rm -rf ${absolutePath} |
+| `` | configmap name | `local-path-config` |
+| `configmap.helperPod` | helper pod yaml file | apiVersion: v1<br>kind: Pod<br>metadata:<br> name: helper-pod<br>spec:<br> containers:<br> - name: helper-pod<br>  image: busybox |
+Specify each parameter using the `--set key=value[,key=value]` argument to `helm install`. For example,
+$ helm install ./deploy/chart/ --name local-path-storage --namespace local-path-storage --set
+Alternatively, a YAML file that specifies the values for the above parameters can be provided while installing the
+chart. For example,
+$ helm install --name local-path-storage --namespace local-path-storage ./deploy/chart/ -f values.yaml
+> **Tip**: You can use the default [values.yaml](values.yaml)
+## RBAC
+By default the chart will install the recommended RBAC roles and rolebindings.
+You need to have the flag `--authorization-mode=RBAC` on the api server. See the following document for how to enable
+To determine if your cluster supports RBAC, run the following command:
+$ kubectl api-versions | grep rbac
+If the output contains "beta", you may install the chart with RBAC enabled (see below).
+### Enable RBAC role/rolebinding creation
+To enable the creation of RBAC resources (On clusters with RBAC). Do the following:
+$ helm install ./deploy/chart/ --name local-path-storage --namespace local-path-storage --set rbac.create=true
+You can create a hostpath-backed persistent volume with a persistent volume claim like this:
+apiVersion: v1
+kind: PersistentVolumeClaim
+ name: local-path-pvc
+ accessModes:
+ - ReadWriteOnce
+ storageClassName: {{ }}
+ resources:
+ requests:
+ storage: 2Gi
+{{/* vim: set filetype=mustache: */}}
+Expand the name of the chart.
+{{- define "" -}}
+{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}}
+{{- end -}}
+Create a default fully qualified app name.
+We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
+If release name contains chart name it will be used as a full name.
+{{- define "local-path-provisioner.fullname" -}}
+{{- if .Values.fullnameOverride -}}
+{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
+{{- else -}}
+{{- $name := default .Chart.Name .Values.nameOverride -}}
+{{- if contains $name .Release.Name -}}
+{{- .Release.Name | trunc 63 | trimSuffix "-" -}}
+{{- else -}}
+{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" -}}
+{{- end -}}
+{{- end -}}
+{{- end -}}
+Create chart name and version as used by the chart label.
+{{- define "local-path-provisioner.chart" -}}
+{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" -}}
+{{- end -}}
+Common labels
+{{- define "local-path-provisioner.labels" -}} {{ include "" . }} {{ include "local-path-provisioner.chart" . }} {{ .Release.Name }}
+{{- if .Chart.AppVersion }} {{ .Chart.AppVersion | quote }}
+{{- end }} {{ .Release.Service }}
+{{- end -}}
+Create the name of the service account to use.
+{{- define "local-path-provisioner.serviceAccountName" -}}
+{{- if .Values.serviceAccount.create -}}
+ {{ default (include "local-path-provisioner.fullname" .) }}
+{{- else -}}
+ {{ default "default" }}
+{{- end -}}
+{{- end -}}
+Create the name of the provisioner to use.
+{{- define "local-path-provisioner.provisionerName" -}}
+{{- if .Values.storageClass.provisionerName -}}
+{{- printf .Values.storageClass.provisionerName -}}
+{{- else -}}
+cluster.local/{{ template "local-path-provisioner.fullname" . -}}
+{{- end -}}
+{{- end -}}
+{{- define "local-path-provisioner.secret" }}
+{{- printf "{\"auths\": {\"%s\": {\"auth\": \"%s\"}}}" .Values.privateRegistry.registryUrl (printf "%s:%s" .Values.privateRegistry.registryUser .Values.privateRegistry.registryPasswd | b64enc) | b64enc }}
+{{- end }}
+{{- if .Values.rbac.create -}}
+kind: ClusterRole
+ name: {{ include "local-path-provisioner.fullname" . }}
+ labels:
+{{ include "local-path-provisioner.labels" . | indent 4 }}
+- apiGroups: [""]
+ resources: ["nodes", "persistentvolumeclaims", "configmaps"]
+ verbs: ["get", "list", "watch"]
+- apiGroups: [""]
+ resources: ["endpoints", "persistentvolumes", "pods"]
+ verbs: ["*"]
+- apiGroups: [""]
+ resources: ["events"]
+ verbs: ["create", "patch"]
+- apiGroups: [""]
+ resources: ["storageclasses"]
+ verbs: ["get", "list", "watch"]
+{{- end -}}
+{{- if .Values.rbac.create -}}
+kind: ClusterRoleBinding
+ name: {{ include "local-path-provisioner.fullname" . }}
+ labels:
+{{ include "local-path-provisioner.labels" . | indent 4 }}
+ apiGroup:
+ kind: ClusterRole
+ name: {{ template "local-path-provisioner.fullname" . }}
+ - kind: ServiceAccount
+ name: {{ template "local-path-provisioner.serviceAccountName" . }}
+ namespace: {{ .Release.Namespace }}
+{{- end -}}
+apiVersion: v1
+kind: ConfigMap
+ name: {{ }}
+ labels:
+{{ include "local-path-provisioner.labels" . | indent 4 }}
+ config.json: |-
+ {{- $config := dict }}
+ {{- with .Values.nodePathMap }}
+ {{- $config = set $config "nodePathMap" . }}
+ {{- end }}
+ {{- with .Values.sharedFileSystemPath }}
+ {{- $config = set $config "sharedFileSystemPath" . }}
+ {{- end }}
+ {{- $config | toPrettyJson | nindent 4 }}
+ setup: |-
+ {{ .Values.configmap.setup | nindent 4 }}
+ teardown: |-
+ {{ .Values.configmap.teardown | nindent 4 }}
+ helperPod.yaml: |-
+ apiVersion: v1
+ kind: Pod
+ metadata:
+ name: helper-pod
+ spec:
+ containers:
+ - name: helper-pod
+ {{- if .Values.privateRegistry.registryUrl }}
+ image: {{ .Values.privateRegistry.registryUrl }}/{{ .Values.helperImage.repository }}:{{ .Values.helperImage.tag }}
+ {{- else }}
+ image: {{ .Values.helperImage.repository }}:{{ .Values.helperImage.tag }}
+ {{- end }}
+ imagePullPolicy: {{ .Values.image.pullPolicy }}
+apiVersion: apps/v1
+kind: Deployment
+ name: {{ include "local-path-provisioner.fullname" . }}
+ labels:
+{{ include "local-path-provisioner.labels" . | indent 4 }}
+ replicas: {{ .Values.replicaCount }}
+ selector:
+ matchLabels:
+ {{ include "" . }}
+ {{ .Release.Name }}
+ template:
+ metadata:
+ labels:
+ {{ include "" . }}
+ {{ .Release.Name }}
+ spec:
+ {{- with .Values.imagePullSecrets }}
+ imagePullSecrets:
+ {{- toYaml . | nindent 8 }}
+ {{- end }}
+ serviceAccountName: {{ template "local-path-provisioner.serviceAccountName" . }}
+ containers:
+ - name: {{ .Chart.Name }}
+ {{- if .Values.privateRegistry.registryUrl }}
+ image: "{{ .Values.privateRegistry.registryUrl }}/{{ .Values.image.repository }}:{{ .Values.image.tag }}"
+ {{- else }}
+ image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
+ {{- end }}
+ imagePullPolicy: {{ .Values.image.pullPolicy }}
+ command:
+ - local-path-provisioner
+ - --debug
+ - start
+ - --config
+ - /etc/config/config.json
+ - --service-account-name
+ - {{ template "local-path-provisioner.serviceAccountName" . }}
+ - --provisioner-name
+ - {{ template "local-path-provisioner.provisionerName" . }}
+ - --helper-image
+ {{- if .Values.privateRegistry.registryUrl }}
+ - "{{ .Values.privateRegistry.registryUrl }}/{{ .Values.helperImage.repository }}:{{ .Values.helperImage.tag }}"
+ {{- else }}
+ - "{{ .Values.helperImage.repository }}:{{ .Values.helperImage.tag }}"
+ {{- end }}
+ - --configmap-name
+ - {{ }}
+ {{- if .Values.workerThreads }}
+ - --worker-threads
+ - {{ .Values.workerThreads }}
+ {{- end }}
+ {{- if .Values.provisioningRetryCount }}
+ - --provisioning-retry-count
+ - {{ .Values.provisioningRetryCount }}
+ {{- end }}
+ {{- if .Values.deletionRetryCount }}
+ - --deletion-retry-count
+ - {{ .Values.deletionRetryCount }}
+ {{- end }}
+ volumeMounts:
+ - name: config-volume
+ mountPath: /etc/config/
+ env:
+ value: {{ .Release.Namespace }}
+ resources:
+ {{- toYaml .Values.resources | nindent 12 }}
+ volumes:
+ - name: config-volume
+ configMap:
+ name: {{ }}
+ {{- with .Values.nodeSelector }}
+ nodeSelector:
+ {{- toYaml . | nindent 8 }}
+ {{- end }}
+ {{- with .Values.affinity }}
+ affinity:
+ {{- toYaml . | nindent 8 }}
+ {{- end }}
+ {{- with .Values.tolerations }}
+ tolerations:
+ {{- toYaml . | nindent 8 }}
+ {{- end }}
+{{- if .Values.defaultSettings.registrySecret }}
+apiVersion: v1
+kind: Secret
+ name: {{ .Values.defaultSettings.registrySecret }}
+ .dockerconfigjson: {{ template "local-path-provisioner.secret" . }}
+{{- end }}
\ No newline at end of file
+{{- if .Values.serviceAccount.create -}}
+apiVersion: v1
+kind: ServiceAccount
+ name: {{ template "local-path-provisioner.serviceAccountName" . }}
+ labels:
+{{ include "local-path-provisioner.labels" . | indent 4 }}
+{{- with .Values.imagePullSecrets }}
+ {{- toYaml . | nindent 2 }}
+{{- end }}
+{{- if .Values.defaultSettings.registrySecret }}
+ - name: {{ .Values.defaultSettings.registrySecret }}
+{{- end }}
+{{- end }}
+{{ if .Values.storageClass.create -}}
+kind: StorageClass
+ name: {{ }}
+ labels:
+{{ include "local-path-provisioner.labels" . | indent 4 }}
+{{- if .Values.storageClass.defaultClass }}
+ annotations:
+ "true"
+{{- end }}
+provisioner: {{ template "local-path-provisioner.provisionerName" . }}
+volumeBindingMode: WaitForFirstConsumer
+reclaimPolicy: {{ .Values.storageClass.reclaimPolicy }}
+allowVolumeExpansion: true
+{{- end }}
+# Default values for local-path-provisioner.
+replicaCount: 1
+ repository: rancher/local-path-provisioner
+ tag: v0.0.24
+ pullPolicy: IfNotPresent
+ repository: busybox
+ tag: latest
+ registrySecret: ~
+ registryUrl: ~
+ registryUser: ~
+ registryPasswd: ~
+imagePullSecrets: []
+nameOverride: ""
+fullnameOverride: ""
+## For creating the StorageClass automatically:
+ create: true
+ ## Set a provisioner name. If unset, a name will be generated.
+ # provisionerName:
+ ## Set StorageClass as the default StorageClass
+ ## Ignored if storageClass.create is false
+ defaultClass: false
+ ## Set a StorageClass name
+ ## Ignored if storageClass.create is false
+ name: local-path
+ ## ReclaimPolicy field of the class, which can be either Delete or Retain
+ reclaimPolicy: Delete
+# nodePathMap is the place user can customize where to store the data on each node.
+# 1. If one node is not listed on the nodePathMap, and Kubernetes wants to create volume on it, the paths specified in
+# DEFAULT_PATH_FOR_NON_LISTED_NODES will be used for provisioning.
+# 2. If one node is listed on the nodePathMap, the specified paths will be used for provisioning.
+# 1. If one node is listed but with paths set to [], the provisioner will refuse to provision on this node.
+# 2. If more than one path was specified, the path would be chosen randomly when provisioning.
+# The configuration must obey following rules:
+# 1. A path must start with /, a.k.a an absolute path.
+# 2. Root directory (/) is prohibited.
+# 3. No duplicate paths allowed for one node.
+# 4. No duplicate node allowed.
+ paths:
+ - /opt/local-path-provisioner
+# `sharedFileSystemPath` allows the provisioner to use a filesystem that is mounted on all
+# nodes at the same time. In this case all access modes are supported: `ReadWriteOnce`,
+# `ReadOnlyMany` and `ReadWriteMany` for storage claims. In addition
+# `volumeBindingMode: Immediate` can be used in StorageClass definition.
+# Please note that `nodePathMap` and `sharedFileSystemPath` are mutually exclusive.
+# If `sharedFileSystemPath` is used, then `nodePathMap` must be set to `[]`.
+# sharedFileSystemPath: ""
+resources: {}
+ # We usually recommend not to specify default resources and to leave this as a conscious
+ # choice for the user. This also increases chances charts run on environments with little
+ # resources, such as Minikube. If you do want to specify resources, uncomment the following
+ # lines, adjust them as necessary, and remove the curly braces after 'resources:'.
+ # limits:
+ # cpu: 100m
+ # memory: 128Mi
+ # requests:
+ # cpu: 100m
+ # memory: 128Mi
+ # Specifies whether RBAC resources should be created
+ create: true
+ # Specifies whether a ServiceAccount should be created
+ create: true
+ # The name of the ServiceAccount to use.
+ # If not set and create is true, a name is generated using the fullname template
+ name:
+nodeSelector: {}
+tolerations: []
+affinity: {}
+ # specify the config map name
+ name: local-path-config
+ # specify the custom script for setup and teardown
+ setup: |-
+ #!/bin/sh
+ set -eu
+ mkdir -m 0777 -p "$VOL_DIR"
+ teardown: |-
+ #!/bin/sh
+ set -eu
+ rm -rf "$VOL_DIR"
+# Number of provisioner worker threads to call provision/delete simultaneously.
+# workerThreads: 4
+# Number of retries of failed volume provisioning. 0 means retry indefinitely.
+# provisioningRetryCount: 15
+# Number of retries of failed volume deletion. 0 means retry indefinitely.
+# deletionRetryCount: 15
| tar -xz -C ${ATMOSPHERE}/charts
+ | tar -xz -C charts --strip-components=3 ${ATMOSPHERE}/local-path-provisioner-${LOCAL_PATH_PROVISIONER_VERSION}/deploy/chart/
curl -sL${NEUTRON_VERSION}.tgz \
| tar -xz -C ${ATMOSPHERE}/charts
- ansible.builtin.import_playbook:
+ when: csi_driver == "rbd"
- ansible.builtin.import_playbook: vexxhost.atmosphere.kubernetes
- ansible.builtin.import_playbook: vexxhost.atmosphere.csi
+ - role: local_path_provisioner
+ when: csi_driver == "local-path-provisioner"
- role: ceph_csi_rbd
when: csi_driver == "rbd"
- role: powerstore_csi
+ local_path_provisioner_helper:
+ local_path_provisioner:
+# `local_path_provisioner`
+# Copyright (c) 2023 VEXXHOST, Inc.
+# Licensed under the Apache License, Version 2.0 (the "License"); you may
+# not use this file except in compliance with the License. You may obtain
+# a copy of the License at
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
+# WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
+# License for the specific language governing permissions and limitations
+# under the License.
+local_path_provisioner_helm_release_name: local-path-provisioner
+local_path_provisioner_helm_chart_path: "../../charts/local-path-provisioner/"
+local_path_provisioner_helm_chart_ref: /usr/local/src/local-path-provisioner
+local_path_provisioner_helm_release_namespace: local-path-storage
+local_path_provisioner_helm_values: {}
+# Copyright (c) 2022 VEXXHOST, Inc.
+# Licensed under the Apache License, Version 2.0 (the "License"); you may
+# not use this file except in compliance with the License. You may obtain
+# a copy of the License at
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
+# WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
+# License for the specific language governing permissions and limitations
+# under the License.
+ author: VEXXHOST, Inc.
+ description: Ansible role for "local-path-provisioner"
+ license: Apache-2.0
+ min_ansible_version: 5.5.0
+ standalone: false
+ platforms:
+ - name: Ubuntu
+ versions:
+ - focal
+ - role: defaults
+ - role: vexxhost.kubernetes.upload_helm_chart
+ vars:
+ upload_helm_chart_src: "{{ local_path_provisioner_helm_chart_path }}"
+ upload_helm_chart_dest: "{{ local_path_provisioner_helm_chart_ref }}"
+# Copyright (c) 2022 VEXXHOST, Inc.
+# Licensed under the Apache License, Version 2.0 (the "License"); you may
+# not use this file except in compliance with the License. You may obtain
+# a copy of the License at
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
+# WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
+# License for the specific language governing permissions and limitations
+# under the License.
+- name: Deploy Helm chart
+ run_once: true
+ kubernetes.core.helm:
+ name: "{{ local_path_provisioner_helm_release_name }}"
+ chart_ref: "{{ local_path_provisioner_helm_chart_ref }}"
+ release_namespace: "{{ local_path_provisioner_helm_release_namespace }}"
+ create_namespace: true
+ kubeconfig: /etc/kubernetes/admin.conf
+ values: "{{ _local_path_provisioner_helm_values | combine(local_path_provisioner_helm_values, recursive=True) }}"
+# Copyright (c) 2022 VEXXHOST, Inc.
+# Licensed under the Apache License, Version 2.0 (the "License"); you may
+# not use this file except in compliance with the License. You may obtain
+# a copy of the License at
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
+# WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
+# License for the specific language governing permissions and limitations
+# under the License.
+ image:
+ repository: "{{ atmosphere_images['local_path_provisioner'] | vexxhost.kubernetes.docker_image('name') }}"
+ tag: "{{ atmosphere_images['local_path_provisioner'] | vexxhost.kubernetes.docker_image('tag') }}"
+ helperImage:
+ repository: "{{ atmosphere_images['local_path_provisioner_helper'] | vexxhost.kubernetes.docker_image('name') }}"
+ tag: "{{ atmosphere_images['local_path_provisioner_helper'] | vexxhost.kubernetes.docker_image('tag') }}"
+ storageClass:
+ defaultClass: true
+ name: general