Configure FA File PVC Size Enforcement
PX-CSI 26.3.0 and later automatically enforces the requested size of FlashArray File Services PVCs by creating and attaching a quota policy to each managed directory. This prevents applications from writing beyond the requested PVC size (enforced at a rounded-size quota limit) and ensures the mounted volume reports the correct capacity rather than the array-advertised file system capacity.
Prerequisites
Before configuring FA File PVC size enforcement, make sure:
- PX-CSI 26.3.0 or later is installed.
- Purity version is 6.7.1 or later.
- FlashArray file services are configured. For more information, see Configure FlashArray file services.
How FA File PVC size enforcement works
When a FlashArray file service PVC is provisioned, PX-CSI creates a quota policy named px_auto_<sizeGiB>gb and attaches it to the managed directory. The requested size is rounded up to the next whole GiB to determine the policy name and enforced limit. PVCs requesting the same rounded size share one quota policy, which limits the total number of quota policies created on the array.
| Requested size | Rounded (ceil) | Policy name | Enforced limit |
|---|---|---|---|
| 1 GiB | 1 GiB | px_auto_1gb | 1 GiB |
| 1.5 GiB | 2 GiB | px_auto_2gb | 2 GiB |
| 2 GiB | 2 GiB | px_auto_2gb | 2 GiB |
On volume expand, PX-CSI replaces the quota policy attachment with one for the new size and deletes the old policy if no other directories use it. On volume delete, PX-CSI deletes the policy if it is no longer attached to any directory.
On FlashArrays with Purity versions earlier than 6.7.1, quota policy operations are not supported. Auto-enforcement does not apply on these arrays.
Disable FA File PVC size enforcement
The ENABLE_AUTO_CREATE_QUOTA_POLICY environment variable controls this behavior. It is enabled by default; set the value to "false" to disable it.
To disable auto-enforcement:
-
Edit the
StorageClusterresource:kubectl edit storagecluster -n portworx -
Add the environment variable under
spec.env:apiVersion: core.libopenstorage.org/v1kind: StorageClustermetadata:name: px-clusternamespace: portworxspec:env:- name: ENABLE_AUTO_CREATE_QUOTA_POLICYvalue: "false" -
Save the changes. PX-CSI controller plugin pods restart automatically.
When disabled, PX-CSI does not enforce size limits on new FlashArray file service PVCs. If a PVC was previously backed by an auto-managed quota policy, expanding it detaches the policy and deletes it if no other directory is using it.
Override with an explicit quota policy
To apply a fixed quota policy to all PVCs provisioned from a StorageClass, set the pure_quota_policy StorageClass parameter. An explicit quota policy takes precedence over auto-creation.
parameters:
backend: "pure_fa_file"
pure_nfs_policy: "test-policy"
pure_fa_file_system: "name01"
pure_quota_policy: "100g_policy"
When pure_quota_policy is set, PX-CSI validates that the requested PVC size does not exceed the policy's limit and does not auto-create a size-named policy.
Behavior reference
| ENABLE_AUTO_CREATE_QUOTA_POLICY | Scenario | Behavior |
|---|---|---|
| Enabled (default) | Create a PVC with no explicit quota policy | Creates or reuses px_auto_<size>gb; attaches it to the directory; enforces the requested size |
| Enabled (default) | Create a PVC with an explicit pure_quota_policy set | Uses the provided policy; validates the requested size against it |
| Disabled | Create a PVC with no explicit quota policy | Does not enforce the requested size |
| Enabled (default) | Expand a PVC with an auto-managed policy attached | Replaces px_auto_<old>gb with px_auto_<new>gb; deletes the old policy if unused |
| Enabled (default) | Expand a PVC with an explicit pure_quota_policy set | Validates the new size against the fixed policy |
| Disabled | Expand a PVC with an auto-managed policy attached | Detaches and deletes the auto-managed policy if no longer attached to any directory; stops enforcing the requested size |
| Enabled (default) | Delete a PVC with an auto-managed policy attached | Deletes px_auto_<size>gb if no longer attached to any directory; retains it otherwise |
| Enabled (default) | Delete a PVC with an explicit pure_quota_policy set | Retains the user-created quota policy |