如何在GKE集群中启用DefaultStorageClass等准入控制器?
Great question! Since Google Kubernetes Engine (GKE) is a managed Kubernetes service, you don’t have direct access to tweak the API Server’s admission controller flags like you would in a self-hosted cluster. But the admission controllers you mentioned—DefaultStorageClass, StorageObjectInUseProtection, and PersistentVolumeClaimResize—can all be enabled or configured through GKE’s managed workflows. Here’s a breakdown for each:
DefaultStorageClass
This admission controller is actually enabled by default in GKE, but you need to ensure there’s a default StorageClass set (since the controller relies on that to dynamically provision volumes for unbound PVCs). If you need to set or change the default StorageClass:
- To mark a StorageClass as default:
kubectl annotate storageclass <your-storageclass-name> storageclass.kubernetes.io/is-default-class="true" - If there’s an existing default StorageClass, remove its default annotation first:
kubectl annotate storageclass <old-default-storageclass> storageclass.kubernetes.io/is-default-class-
StorageObjectInUseProtection
This controller is automatically enabled in all supported GKE versions (Kubernetes 1.14+ which covers all currently supported GKE clusters). It works out of the box to prevent accidental deletion of PersistentVolumes (PVs) that are bound to active PersistentVolumeClaims (PVCs), or PVCs that are mounted by running Pods. No manual configuration is needed here.
PersistentVolumeClaimResize
To use this admission controller (which allows expanding PVCs), you need to ensure two key things are in place:
- Your StorageClass allows volume expansion: Edit your target StorageClass to add the
allowVolumeExpansion: truefield. Use this command to edit the StorageClass:
Add the line at the top level of the StorageClass YAML:kubectl edit storageclass <your-storageclass-name>allowVolumeExpansion: true - Ensure the underlying storage driver supports expansion: GKE’s default StorageClasses (like
pd-standard,pd-ssd, andstandard-rwofor regional clusters) already support volume expansion. For custom StorageClasses, confirm the CSI driver used supports resizing.
Once these are set, you can expand a PVC by editing its spec.resources.requests.storage field, and the admission controller will validate the request and trigger the resize.
Important Notes
- GKE manages many admission controllers internally (like security-focused ones) and doesn’t let users toggle them directly. But the ones you asked about are all configurable through the methods above.
- Always verify your cluster’s Kubernetes version compatibility if you’re using older GKE clusters, but all currently supported versions will work with the steps above.
内容的提问来源于stack exchange,提问作者Shay Berman

