# Configuring GKE Storage Options and CSI Drivers: A Complete Guide

> Master GKE storage options and CSI drivers with our comprehensive guide. Learn to configure Persistent Disk, Filestore, Cloud Storage FUSE, and Parallelstore for your Kubernetes workloads.

- Repository: [Google/skills](https://github.com/google/skills)
- Tags: how-to-guide
- Published: 2026-08-13

---

**Google Kubernetes Engine (GKE) supports four primary CSI drivers—Persistent Disk, Filestore, Cloud Storage FUSE, and Parallelstore—which are configured through StorageClasses and PersistentVolumeClaims or directly via CSI volume definitions documented in the `google/skills` repository.**

According to the **gke-storage** skill in the `google/skills` repository, GKE provides native integration with Google Cloud storage backends through Container Storage Interface (CSI) drivers that abstract underlying infrastructure while supporting diverse access patterns from single-pod databases to multi-reader ML pipelines. The repository defines golden-path defaults for **Autopilot** clusters and provides production-ready manifest templates for both **Standard** and Autopilot configurations.

## Understanding GKE Storage Backends and CSI Drivers

The [`skills/cloud/gke-storage/SKILL.md`](https://github.com/google/skills/blob/main/skills/cloud/gke-storage/SKILL.md) file defines four primary storage options, each exposed through a specific CSI driver provisioner and supporting distinct access modes.

### Compute Engine Persistent Disk

The **Persistent Disk CSI driver** (`pd.csi.storage.gke.io`) provides **ReadWriteOnce** block storage backed by Compute Engine disks. This driver is ideal for databases and single-pod workloads requiring high IOPS and standard Kubernetes volume semantics.

### Filestore (NFS)

The **Filestore CSI driver** (`filestore.csi.storage.gke.io`) delivers **ReadWriteMany** shared file system access across multiple pods. Use this for workloads requiring concurrent read/write access from multiple nodes, such as content management systems or shared scratch space.

### Cloud Storage FUSE

The **Cloud Storage FUSE CSI driver** (`gcsfuse.csi.storage.gke.io`) mounts Google Cloud Storage buckets as file systems with **ReadWriteMany** or **ReadOnlyMany** access. As documented in [`skills/cloud/google-cloud-storage-basics/references/gcsfuse.md`](https://github.com/google/skills/blob/main/skills/cloud/google-cloud-storage-basics/references/gcsfuse.md), this driver is optimized for ML data pipelines and scenarios requiring direct bucket access without intermediate storage layers.

### Parallelstore

The **Parallelstore CSI driver** (`parallelstore.csi.storage.gke.io`) provides high-performance parallel file systems with **ReadWriteMany** access for large-scale compute workloads. This option is designed for high-throughput scenarios requiring concurrent access from many compute nodes.

## Enabling CSI Drivers on GKE Clusters

Driver availability depends on your GKE cluster mode and version requirements.

### Autopilot Cluster Defaults

**Autopilot clusters** automatically enable all four CSI drivers. The [`skills/cloud/gke-storage/SKILL.md`](https://github.com/google/skills/blob/main/skills/cloud/gke-storage/SKILL.md) file lists these under *Golden Path Storage Defaults*, meaning no manual driver installation is required for Autopilot deployments.

### Standard Cluster Configuration

For **Standard clusters**, you must manually enable specific CSI drivers using resource labels. The [`skills/cloud/google-cloud-storage-basics/references/high-performance-storage.md`](https://github.com/google/skills/blob/main/skills/cloud/google-cloud-storage-basics/references/high-performance-storage.md) reference notes that the GCS FUSE driver specifically requires GKE version **1.35.0-gke.3047001** or later. Enable the driver using:

```bash
gcloud container clusters update CLUSTER_NAME \
  --resource-labels=gke-csi-driver=gcsfuse

```

## Configuring Workload Identity and IAM

All GKE CSI drivers rely on **Workload Identity** for authentication. For Cloud Storage FUSE, the pod's service account requires specific IAM bindings configured at the project level.

According to [`skills/cloud/google-cloud-storage-basics/references/gcsfuse.md`](https://github.com/google/skills/blob/main/skills/cloud/google-cloud-storage-basics/references/gcsfuse.md), assign `roles/storage.objectViewer` for read-only access or `roles/storage.objectUser` for read/write operations. The repository emphasizes that Workload Identity is mandatory for secure, keyless authentication between GKE workloads and Cloud Storage buckets.

## Customizing StorageClasses for Production Workloads

The **gke-storage** skill demonstrates advanced StorageClass configurations using the `pd.csi.storage.gke.io` provisioner for regional durability.

Create a regional SSD StorageClass with volume expansion support by defining `parameters.type` as `pd-ssd` and `parameters.replication-type` as `regional-pd`. The [`skills/cloud/gke-storage/SKILL.md`](https://github.com/google/skills/blob/main/skills/cloud/gke-storage/SKILL.md) file provides the following example:

```yaml
apiVersion: storage.k8s.io/v1
kind: StorageClass
metadata:
  name: fast-regional
provisioner: pd.csi.storage.gke.io
parameters:
  type: pd-ssd
  replication-type: regional-pd
volumeBindingMode: WaitForFirstConsumer
allowVolumeExpansion: true

```

Set `volumeBindingMode: WaitForFirstConsumer` to ensure volumes are provisioned in the same topology as the consuming pod, and enable `allowVolumeExpansion: true` to support online volume resizing.

## Implementing Common Storage Patterns

The repository provides concrete manifests for typical storage use cases.

### Regional SSD Block Storage

For database workloads requiring high-performance block storage with regional replication:

```yaml
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
  name: database-pvc
spec:
  accessModes:
  - ReadWriteOnce
  storageClassName: premium-rwo
  resources:
    requests:
      storage: 100Gi

```

### GCS Bucket Mounting with FUSE

Mount Cloud Storage buckets directly without PersistentVolumeClaims using inline CSI volumes. This pattern requires the `gke-gcsfuse/volumes: "true"` annotation and the `gcsfuse.csi.storage.gke.io` driver:

```yaml
apiVersion: v1
kind: Pod
metadata:
  name: gcs-reader
  annotations:
    gke-gcsfuse/volumes: "true"
spec:
  containers:
  - name: reader
    image: busybox
    command: ["ls", "/data"]
    volumeMounts:
    - name: gcs-bucket
      mountPath: /data
  volumes:
  - name: gcs-bucket
    csi:
      driver: gcsfuse.csi.storage.gke.io
      readOnly: true
      volumeAttributes:
        bucketName: <BUCKET_NAME>

```

### Volume Expansion

Resize existing PVCs using the MCP-preferred patching method:

```bash
patch_k8s_resource(parent="...", resourceType="persistentvolumeclaim", name="<PVC_NAME>",
  patch='{"spec":{"resources":{"requests":{"storage":"200Gi"}}}}')

```

## Summary

- **Persistent Disk CSI** (`pd.csi.storage.gke.io`) provides **ReadWriteOnce** block storage for databases, while **Filestore** (`filestore.csi.storage.gke.io`) and **Parallelstore** offer **ReadWriteMany** for shared access.
- **Autopilot clusters** automatically enable all CSI drivers; **Standard clusters** require manual enablement with specific resource labels and version constraints (GCS FUSE requires GKE 1.35.0-gke.3047001+).
- **Workload Identity** is mandatory for all drivers, with Cloud Storage access requiring `roles/storage.objectUser` or `roles/storage.objectViewer` IAM bindings.
- Use **StorageClasses** with `provisioner`, `parameters.type`, and `allowVolumeExpansion` fields to define backend-specific behavior and enable online volume resizing.
- The [`skills/cloud/gke-storage/SKILL.md`](https://github.com/google/skills/blob/main/skills/cloud/gke-storage/SKILL.md) and [`skills/cloud/google-cloud-storage-basics/references/gcsfuse.md`](https://github.com/google/skills/blob/main/skills/cloud/google-cloud-storage-basics/references/gcsfuse.md) files in the `google/skills` repository provide the authoritative golden-path defaults and production manifest templates.

## Frequently Asked Questions

### Which CSI driver should I use for PostgreSQL or MySQL databases?

Use the **Persistent Disk CSI driver** (`pd.csi.storage.gke.io`) with a StorageClass specifying `type: pd-ssd` for databases requiring high IOPS and low latency. Configure `accessModes: ReadWriteOnce` since database pods typically require exclusive block device access, and enable `allowVolumeExpansion: true` to support future storage growth without downtime.

### How do I enable the GCS FUSE driver on an existing Standard GKE cluster?

Enable the driver by updating your cluster with the resource label `gke-csi-driver=gcsfuse` using the gcloud CLI. Ensure your cluster runs GKE version **1.35.0-gke.3047001** or later as required by the [`high-performance-storage.md`](https://github.com/google/skills/blob/main/high-performance-storage.md) reference, then verify the `gcsfuse.csi.storage.gke.io` driver pods are running in the `kube-system` namespace.

### What IAM permissions are required for Cloud Storage access via CSI?

Your GKE workload's Google Service Account must be granted `roles/storage.objectViewer` for read-only bucket access or `roles/storage.objectUser` for read/write permissions. According to [`skills/cloud/google-cloud-storage-basics/references/gcsfuse.md`](https://github.com/google/skills/blob/main/skills/cloud/google-cloud-storage-basics/references/gcsfuse.md), these bindings work in conjunction with **Workload Identity** to provide secure, keyless authentication between pods and Cloud Storage buckets.

### Can I expand PersistentVolumes after initial creation?

Yes, if the StorageClass defines `allowVolumeExpansion: true`. You can resize volumes by patching the PVC's `spec.resources.requests.storage` field or using the MCP-preferred `patch_k8s_resource` command. The Persistent Disk CSI driver supports online expansion for most volume types, though Filestore and Parallelstore may have specific constraints documented in the `gke-storage` skill.