Configuring GKE Storage Options and CSI Drivers: A Complete Guide
Google Kubernetes Engine (GKE) supports four primary CSI drivers—Persistent Disk, Filestore, Cloud Storage FUSE, and Parallelstore—which are configured through StorageClasses and PersistentVolumeClaims or directly via CSI volume definitions documented in the google/skills repository.
According to the gke-storage skill in the google/skills repository, GKE provides native integration with Google Cloud storage backends through Container Storage Interface (CSI) drivers that abstract underlying infrastructure while supporting diverse access patterns from single-pod databases to multi-reader ML pipelines. The repository defines golden-path defaults for Autopilot clusters and provides production-ready manifest templates for both Standard and Autopilot configurations.
Understanding GKE Storage Backends and CSI Drivers
The skills/cloud/gke-storage/SKILL.md file defines four primary storage options, each exposed through a specific CSI driver provisioner and supporting distinct access modes.
Compute Engine Persistent Disk
The Persistent Disk CSI driver (pd.csi.storage.gke.io) provides ReadWriteOnce block storage backed by Compute Engine disks. This driver is ideal for databases and single-pod workloads requiring high IOPS and standard Kubernetes volume semantics.
Filestore (NFS)
The Filestore CSI driver (filestore.csi.storage.gke.io) delivers ReadWriteMany shared file system access across multiple pods. Use this for workloads requiring concurrent read/write access from multiple nodes, such as content management systems or shared scratch space.
Cloud Storage FUSE
The Cloud Storage FUSE CSI driver (gcsfuse.csi.storage.gke.io) mounts Google Cloud Storage buckets as file systems with ReadWriteMany or ReadOnlyMany access. As documented in skills/cloud/google-cloud-storage-basics/references/gcsfuse.md, this driver is optimized for ML data pipelines and scenarios requiring direct bucket access without intermediate storage layers.
Parallelstore
The Parallelstore CSI driver (parallelstore.csi.storage.gke.io) provides high-performance parallel file systems with ReadWriteMany access for large-scale compute workloads. This option is designed for high-throughput scenarios requiring concurrent access from many compute nodes.
Enabling CSI Drivers on GKE Clusters
Driver availability depends on your GKE cluster mode and version requirements.
Autopilot Cluster Defaults
Autopilot clusters automatically enable all four CSI drivers. The skills/cloud/gke-storage/SKILL.md file lists these under Golden Path Storage Defaults, meaning no manual driver installation is required for Autopilot deployments.
Standard Cluster Configuration
For Standard clusters, you must manually enable specific CSI drivers using resource labels. The skills/cloud/google-cloud-storage-basics/references/high-performance-storage.md reference notes that the GCS FUSE driver specifically requires GKE version 1.35.0-gke.3047001 or later. Enable the driver using:
gcloud container clusters update CLUSTER_NAME \
--resource-labels=gke-csi-driver=gcsfuse
Configuring Workload Identity and IAM
All GKE CSI drivers rely on Workload Identity for authentication. For Cloud Storage FUSE, the pod's service account requires specific IAM bindings configured at the project level.
According to skills/cloud/google-cloud-storage-basics/references/gcsfuse.md, assign roles/storage.objectViewer for read-only access or roles/storage.objectUser for read/write operations. The repository emphasizes that Workload Identity is mandatory for secure, keyless authentication between GKE workloads and Cloud Storage buckets.
Customizing StorageClasses for Production Workloads
The gke-storage skill demonstrates advanced StorageClass configurations using the pd.csi.storage.gke.io provisioner for regional durability.
Create a regional SSD StorageClass with volume expansion support by defining parameters.type as pd-ssd and parameters.replication-type as regional-pd. The skills/cloud/gke-storage/SKILL.md file provides the following example:
apiVersion: storage.k8s.io/v1
kind: StorageClass
metadata:
name: fast-regional
provisioner: pd.csi.storage.gke.io
parameters:
type: pd-ssd
replication-type: regional-pd
volumeBindingMode: WaitForFirstConsumer
allowVolumeExpansion: true
Set volumeBindingMode: WaitForFirstConsumer to ensure volumes are provisioned in the same topology as the consuming pod, and enable allowVolumeExpansion: true to support online volume resizing.
Implementing Common Storage Patterns
The repository provides concrete manifests for typical storage use cases.
Regional SSD Block Storage
For database workloads requiring high-performance block storage with regional replication:
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: database-pvc
spec:
accessModes:
- ReadWriteOnce
storageClassName: premium-rwo
resources:
requests:
storage: 100Gi
GCS Bucket Mounting with FUSE
Mount Cloud Storage buckets directly without PersistentVolumeClaims using inline CSI volumes. This pattern requires the gke-gcsfuse/volumes: "true" annotation and the gcsfuse.csi.storage.gke.io driver:
apiVersion: v1
kind: Pod
metadata:
name: gcs-reader
annotations:
gke-gcsfuse/volumes: "true"
spec:
containers:
- name: reader
image: busybox
command: ["ls", "/data"]
volumeMounts:
- name: gcs-bucket
mountPath: /data
volumes:
- name: gcs-bucket
csi:
driver: gcsfuse.csi.storage.gke.io
readOnly: true
volumeAttributes:
bucketName: <BUCKET_NAME>
Volume Expansion
Resize existing PVCs using the MCP-preferred patching method:
patch_k8s_resource(parent="...", resourceType="persistentvolumeclaim", name="<PVC_NAME>",
patch='{"spec":{"resources":{"requests":{"storage":"200Gi"}}}}')
Summary
- Persistent Disk CSI (
pd.csi.storage.gke.io) provides ReadWriteOnce block storage for databases, while Filestore (filestore.csi.storage.gke.io) and Parallelstore offer ReadWriteMany for shared access. - Autopilot clusters automatically enable all CSI drivers; Standard clusters require manual enablement with specific resource labels and version constraints (GCS FUSE requires GKE 1.35.0-gke.3047001+).
- Workload Identity is mandatory for all drivers, with Cloud Storage access requiring
roles/storage.objectUserorroles/storage.objectViewerIAM bindings. - Use StorageClasses with
provisioner,parameters.type, andallowVolumeExpansionfields to define backend-specific behavior and enable online volume resizing. - The
skills/cloud/gke-storage/SKILL.mdandskills/cloud/google-cloud-storage-basics/references/gcsfuse.mdfiles in thegoogle/skillsrepository provide the authoritative golden-path defaults and production manifest templates.
Frequently Asked Questions
Which CSI driver should I use for PostgreSQL or MySQL databases?
Use the Persistent Disk CSI driver (pd.csi.storage.gke.io) with a StorageClass specifying type: pd-ssd for databases requiring high IOPS and low latency. Configure accessModes: ReadWriteOnce since database pods typically require exclusive block device access, and enable allowVolumeExpansion: true to support future storage growth without downtime.
How do I enable the GCS FUSE driver on an existing Standard GKE cluster?
Enable the driver by updating your cluster with the resource label gke-csi-driver=gcsfuse using the gcloud CLI. Ensure your cluster runs GKE version 1.35.0-gke.3047001 or later as required by the high-performance-storage.md reference, then verify the gcsfuse.csi.storage.gke.io driver pods are running in the kube-system namespace.
What IAM permissions are required for Cloud Storage access via CSI?
Your GKE workload's Google Service Account must be granted roles/storage.objectViewer for read-only bucket access or roles/storage.objectUser for read/write permissions. According to skills/cloud/google-cloud-storage-basics/references/gcsfuse.md, these bindings work in conjunction with Workload Identity to provide secure, keyless authentication between pods and Cloud Storage buckets.
Can I expand PersistentVolumes after initial creation?
Yes, if the StorageClass defines allowVolumeExpansion: true. You can resize volumes by patching the PVC's spec.resources.requests.storage field or using the MCP-preferred patch_k8s_resource command. The Persistent Disk CSI driver supports online expansion for most volume types, though Filestore and Parallelstore may have specific constraints documented in the gke-storage skill.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →