Hands-on Lab·Kubernetes and Cloud Native Security Associate
Storage Security: StorageClass, PV and CSI
Storage is a component like the kubelet or etcd, and it has its own security questions: who may provision it, where the bytes actually live, and what happens to them when the workload goes away. This guide answers all three on a cluster that can provision nothing at all - which is the honest starting point.
Cluster Component Security Guide 17 of 42 Intermediate
- Kubernetesapiserver v1.36.4, kubelet v1.36.3
- Runtimecontainerd 2.2.6
- CNICilium 1.18.1 - tunnel/VXLAN, with Hubble relay and UI
- Host OSUbuntu 26.04 LTS, kernel 7.0.0-29
- Built withkubeadm v1.36.3 - podSubnet 10.244.0.0/16, serviceSubnet 10.96.0.0/12
- TimeAbout 17 min
- Reviewed25 August 2026
Written against the versions above. A default kubeadm cluster ships no StorageClass and no CSI driver. A PersistentVolume created by hand defaults to `persistentVolumeReclaimPolicy: Retain`, which is why the data below survives its claim.
| Server Name | IP Address | OS | Roles | CPU | RAM | HDD |
|---|---|---|---|---|---|---|
| CKA5001 | 192.168.0.41 | Ubuntu 26.04 LTS | Control Plane Node (tainted NoSchedule) | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE01 | 192.168.0.42 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE02 | 192.168.0.43 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE03 | 192.168.0.44 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
Before you start
- guide 11 - the cluster's own data at rest, for contrast.
- guide 13 - what else can read a node's disk.
-
What a default cluster can provision, which is nothing
-
A claim that nothing answers
-
A PersistentVolume you create by hand
-
Where the bytes actually live
-
Deleting the claim does not delete the data
-
Who is allowed to do any of this