User Story
As a Kubernetes platform operator deploying the OpenShell gateway through Helm, I want to select the gateway PVC's size and StorageClass, so that encrypted gateway state lands on the cluster's retained stateful storage with capacity appropriate to the deployment.
Problem Statement
OpenShell Helm chart 0.0.116 hard-codes the StatefulSet volumeClaimTemplates request to 1Gi and does not set or expose storageClassName. The chart exposes workspace PVC size/class values, but not the gateway database claim.
Impact / Why This Matters
Without chart values, operators must accept the cluster's default StorageClass and fixed capacity or carry a post-render patch. This can put the gateway's encrypted credential database and control-plane state on an unintended storage tier. A later correction may require StatefulSet/PVC migration because volumeClaimTemplates fields are immutable in common upgrade paths. Post-render patches are also coupled to the template's claim order.
Proposed Design
Expose a small gateway persistence block in Helm values, for example:
persistence:
size: 1Gi
storageClassName: ""
The existing observable behavior should remain the default: a 1Gi claim using the cluster's default StorageClass when no values are set. Setting these values should render the requested capacity and storageClassName into the gateway StatefulSet. Naming is illustrative; the important user workflow is being able to declare both fields without a post-renderer.
Acceptance Criteria
Alternatives Considered
- Use the cluster's default StorageClass and expand the claim later. This does not guarantee the required retention/storage tier and depends on expansion support.
- Pre-create a PVC. The StatefulSet currently owns a
volumeClaimTemplate and has no existing-claim workflow.
- Carry a Flux/Helm post-render patch. This works, but is coupled to the StatefulSet resource name and claim index, and it shifts a normal storage choice out of the chart's supported interface.
Agent Investigation
- Verified the behavior against the released chart
0.0.116 at OCI digest sha256:df55cd1538bdfb7836834c30dfcf8373b85ffea83bbfd70d50dbe69407a0d2b3.
- Rendering with production values still produces
resources.requests.storage: 1Gi and no storageClassName until a post-render patch is applied.
- Searched open and closed issues for Helm persistence,
volumeClaimTemplates, storage size, and StorageClass; no existing issue matched this gateway PVC gap.
Checklist
User Story
As a Kubernetes platform operator deploying the OpenShell gateway through Helm, I want to select the gateway PVC's size and StorageClass, so that encrypted gateway state lands on the cluster's retained stateful storage with capacity appropriate to the deployment.
Problem Statement
OpenShell Helm chart
0.0.116hard-codes the StatefulSetvolumeClaimTemplatesrequest to1Giand does not set or exposestorageClassName. The chart exposes workspace PVC size/class values, but not the gateway database claim.Impact / Why This Matters
Without chart values, operators must accept the cluster's default StorageClass and fixed capacity or carry a post-render patch. This can put the gateway's encrypted credential database and control-plane state on an unintended storage tier. A later correction may require StatefulSet/PVC migration because
volumeClaimTemplatesfields are immutable in common upgrade paths. Post-render patches are also coupled to the template's claim order.Proposed Design
Expose a small gateway persistence block in Helm values, for example:
The existing observable behavior should remain the default: a
1Giclaim using the cluster's default StorageClass when no values are set. Setting these values should render the requested capacity andstorageClassNameinto the gateway StatefulSet. Naming is illustrative; the important user workflow is being able to declare both fields without a post-renderer.Acceptance Criteria
1Gi/default-StorageClass behavior.helm templatetests cover default and overridden values.Alternatives Considered
volumeClaimTemplateand has no existing-claim workflow.Agent Investigation
0.0.116at OCI digestsha256:df55cd1538bdfb7836834c30dfcf8373b85ffea83bbfd70d50dbe69407a0d2b3.resources.requests.storage: 1Giand nostorageClassNameuntil a post-render patch is applied.volumeClaimTemplates, storage size, and StorageClass; no existing issue matched this gateway PVC gap.Checklist