Configuring GKE Storage Options and CSI Drivers: A Complete Guide

Google Kubernetes Engine (GKE) supports four primary CSI drivers—Persistent Disk, Filestore, Cloud Storage FUSE, and Parallelstore—which are configured through StorageClasses and PersistentVolumeClaims or directly via CSI volume definitions documented in the google/skills repository.

According to the gke-storage skill in the google/skills repository, GKE provides native integration with Google Cloud storage backends through Container Storage Interface (CSI) drivers that abstract underlying infrastructure while supporting diverse access patterns from single-pod databases to multi-reader ML pipelines. The repository defines golden-path defaults for Autopilot clusters and provides production-ready manifest templates for both Standard and Autopilot configurations.

Understanding GKE Storage Backends and CSI Drivers

The skills/cloud/gke-storage/SKILL.md file defines four primary storage options, each exposed through a specific CSI driver provisioner and supporting distinct access modes.

Compute Engine Persistent Disk

The Persistent Disk CSI driver (pd.csi.storage.gke.io) provides ReadWriteOnce block storage backed by Compute Engine disks. This driver is ideal for databases and single-pod workloads requiring high IOPS and standard Kubernetes volume semantics.

Filestore (NFS)

The Filestore CSI driver (filestore.csi.storage.gke.io) delivers ReadWriteMany shared file system access across multiple pods. Use this for workloads requiring concurrent read/write access from multiple nodes, such as content management systems or shared scratch space.

Cloud Storage FUSE

The Cloud Storage FUSE CSI driver (gcsfuse.csi.storage.gke.io) mounts Google Cloud Storage buckets as file systems with ReadWriteMany or ReadOnlyMany access. As documented in skills/cloud/google-cloud-storage-basics/references/gcsfuse.md, this driver is optimized for ML data pipelines and scenarios requiring direct bucket access without intermediate storage layers.

Parallelstore

The Parallelstore CSI driver (parallelstore.csi.storage.gke.io) provides high-performance parallel file systems with ReadWriteMany access for large-scale compute workloads. This option is designed for high-throughput scenarios requiring concurrent access from many compute nodes.

Enabling CSI Drivers on GKE Clusters

Driver availability depends on your GKE cluster mode and version requirements.

Autopilot Cluster Defaults

Autopilot clusters automatically enable all four CSI drivers. The skills/cloud/gke-storage/SKILL.md file lists these under Golden Path Storage Defaults, meaning no manual driver installation is required for Autopilot deployments.

Standard Cluster Configuration

For Standard clusters, you must manually enable specific CSI drivers using resource labels. The skills/cloud/google-cloud-storage-basics/references/high-performance-storage.md reference notes that the GCS FUSE driver specifically requires GKE version 1.35.0-gke.3047001 or later. Enable the driver using:

gcloud container clusters update CLUSTER_NAME \
  --resource-labels=gke-csi-driver=gcsfuse

Configuring Workload Identity and IAM

All GKE CSI drivers rely on Workload Identity for authentication. For Cloud Storage FUSE, the pod's service account requires specific IAM bindings configured at the project level.

According to skills/cloud/google-cloud-storage-basics/references/gcsfuse.md, assign roles/storage.objectViewer for read-only access or roles/storage.objectUser for read/write operations. The repository emphasizes that Workload Identity is mandatory for secure, keyless authentication between GKE workloads and Cloud Storage buckets.

Customizing StorageClasses for Production Workloads

The gke-storage skill demonstrates advanced StorageClass configurations using the pd.csi.storage.gke.io provisioner for regional durability.

Create a regional SSD StorageClass with volume expansion support by defining parameters.type as pd-ssd and parameters.replication-type as regional-pd. The skills/cloud/gke-storage/SKILL.md file provides the following example:

apiVersion: storage.k8s.io/v1
kind: StorageClass
metadata:
  name: fast-regional
provisioner: pd.csi.storage.gke.io
parameters:
  type: pd-ssd
  replication-type: regional-pd
volumeBindingMode: WaitForFirstConsumer
allowVolumeExpansion: true

Set volumeBindingMode: WaitForFirstConsumer to ensure volumes are provisioned in the same topology as the consuming pod, and enable allowVolumeExpansion: true to support online volume resizing.

Implementing Common Storage Patterns

The repository provides concrete manifests for typical storage use cases.

Regional SSD Block Storage

For database workloads requiring high-performance block storage with regional replication:

apiVersion: v1
kind: PersistentVolumeClaim
metadata:
  name: database-pvc
spec:
  accessModes:
  - ReadWriteOnce
  storageClassName: premium-rwo
  resources:
    requests:
      storage: 100Gi

GCS Bucket Mounting with FUSE

Mount Cloud Storage buckets directly without PersistentVolumeClaims using inline CSI volumes. This pattern requires the gke-gcsfuse/volumes: "true" annotation and the gcsfuse.csi.storage.gke.io driver:

apiVersion: v1
kind: Pod
metadata:
  name: gcs-reader
  annotations:
    gke-gcsfuse/volumes: "true"
spec:
  containers:
  - name: reader
    image: busybox
    command: ["ls", "/data"]
    volumeMounts:
    - name: gcs-bucket
      mountPath: /data
  volumes:
  - name: gcs-bucket
    csi:
      driver: gcsfuse.csi.storage.gke.io
      readOnly: true
      volumeAttributes:
        bucketName: <BUCKET_NAME>

Volume Expansion

Resize existing PVCs using the MCP-preferred patching method:

patch_k8s_resource(parent="...", resourceType="persistentvolumeclaim", name="<PVC_NAME>",
  patch='{"spec":{"resources":{"requests":{"storage":"200Gi"}}}}')

Summary

  • Persistent Disk CSI (pd.csi.storage.gke.io) provides ReadWriteOnce block storage for databases, while Filestore (filestore.csi.storage.gke.io) and Parallelstore offer ReadWriteMany for shared access.
  • Autopilot clusters automatically enable all CSI drivers; Standard clusters require manual enablement with specific resource labels and version constraints (GCS FUSE requires GKE 1.35.0-gke.3047001+).
  • Workload Identity is mandatory for all drivers, with Cloud Storage access requiring roles/storage.objectUser or roles/storage.objectViewer IAM bindings.
  • Use StorageClasses with provisioner, parameters.type, and allowVolumeExpansion fields to define backend-specific behavior and enable online volume resizing.
  • The skills/cloud/gke-storage/SKILL.md and skills/cloud/google-cloud-storage-basics/references/gcsfuse.md files in the google/skills repository provide the authoritative golden-path defaults and production manifest templates.

Frequently Asked Questions

Which CSI driver should I use for PostgreSQL or MySQL databases?

Use the Persistent Disk CSI driver (pd.csi.storage.gke.io) with a StorageClass specifying type: pd-ssd for databases requiring high IOPS and low latency. Configure accessModes: ReadWriteOnce since database pods typically require exclusive block device access, and enable allowVolumeExpansion: true to support future storage growth without downtime.

How do I enable the GCS FUSE driver on an existing Standard GKE cluster?

Enable the driver by updating your cluster with the resource label gke-csi-driver=gcsfuse using the gcloud CLI. Ensure your cluster runs GKE version 1.35.0-gke.3047001 or later as required by the high-performance-storage.md reference, then verify the gcsfuse.csi.storage.gke.io driver pods are running in the kube-system namespace.

What IAM permissions are required for Cloud Storage access via CSI?

Your GKE workload's Google Service Account must be granted roles/storage.objectViewer for read-only bucket access or roles/storage.objectUser for read/write permissions. According to skills/cloud/google-cloud-storage-basics/references/gcsfuse.md, these bindings work in conjunction with Workload Identity to provide secure, keyless authentication between pods and Cloud Storage buckets.

Can I expand PersistentVolumes after initial creation?

Yes, if the StorageClass defines allowVolumeExpansion: true. You can resize volumes by patching the PVC's spec.resources.requests.storage field or using the MCP-preferred patch_k8s_resource command. The Persistent Disk CSI driver supports online expansion for most volume types, though Filestore and Parallelstore may have specific constraints documented in the gke-storage skill.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →