Install the driver

Install the driver from the kustomize base in the driver’s deploy/ directory. You need a cluster with standard CSI plumbing, kubectl with cluster-admin rights, and the liken-system namespace.

Add the base to your own kustomization and pin <tag> to the driver’s version, so the install is the same every time you apply it. The base creates the CSIDriver object, the ServiceAccounts and their roles, the DaemonSet that runs the node plugin beside the kubelet’s registrar, and the Deployment that runs the controller plugin beside the external-resizer and the external-provisioner. The external-resizer sends a claim’s class change to the driver. The external-provisioner deletes a released PersistentVolume of the Delete reclaim policy, and provisions nothing.

apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization

namespace: liken-system

resources:
  - https://github.com/liken-sh/liken//git-csi-driver/deploy?ref=<tag>

images:
  - name: ghcr.io/liken-sh/git-csi-driver
    newTag: <tag>

The driver’s version is the release tag that last published it. The GitHub release for each tag lists every component and its version.

Check that every node lists git.liken.sh among its drivers. A node appears there after the registrar tells its kubelet about the plugin and the kubelet calls the plugin. A node missing from the answer has no plugin pod running yet.

kubectl get csinode -o custom-columns=NODE:.metadata.name,DRIVERS:.spec.drivers[*].name

The plugin’s flags

One binary runs both plugins, and a subcommand picks which one runs. The base passes node to the DaemonSet and controller to the Deployment, and each subcommand accepts only its own flags. Change a flag through a kustomize patch on the container’s args.

git-csi-driver node takes these flags.

Flag Default Meaning
--endpoint unix:///csi/csi.sock The socket the kubelet and the sidecars call.
--node-id none The node’s name, which the base takes from the pod’s spec.nodeName.
--store /var/lib/liken/pod-storage/git-csi Where the node plugin keeps its bare repositories, trees, and records. On liken this is the pod-storage partition.
--metrics :9200 Where the node plugin serves its Prometheus metrics. An empty value serves none.
--demand-min-interval 10s How long a demanded pull waits after the last pull of the same repository on the node. A burst of demands inside that interval costs one pull.

git-csi-driver controller takes these flags.

Flag Default Meaning
--endpoint unix:///csi/csi.sock The socket the sidecars call.
--metrics :9200 Where the controller serves its Prometheus metrics. An empty value serves none.
--webhook :8080 Where the controller serves the webhook listener. An empty value serves none.

git-csi-driver --version prints the version and exits.

The controller pod declares both ports, and the base includes a Service named git-csi-driver-webhook on port 80 in front of the webhook port. The read-only guide says how a forge reaches it.

The base runs one controller pod. To run two, patch the Deployment named git-csi-driver-controller to replicas: 2. Either pod answers a webhook. The external-resizer in each pod acts only while it holds the Lease named external-resizer-git-liken-sh in liken-system, so one resizer at a time writes a claim’s status. The external-provisioner acts only while it holds the Lease named git-liken-sh, so one provisioner at a time deletes a PersistentVolume.