Local volumes (local-path)
KubeSolo deploys Rancher's local-path-provisioner (v0.0.36) by default. It creates a local-path StorageClass, marked as the cluster default, that provisions PersistentVolumes as directories on the node.
| Property | Value |
|---|---|
| StorageClass | local-path (default class) |
| Provisioner | rancher.io/local-path |
| Volume binding | WaitForFirstConsumer |
| Reclaim policy | Retain: data stays on disk after the PVC is deleted |
| Volume directory | /var/lib/kubesolo/local-path-storage |
| Namespace | local-path-storage |
Because the reclaim policy is Retain, deleting a claim leaves its directory and PersistentVolume behind. Delete the PV and its directory yourself when the data is no longer needed.
Turning it off
Local storage is on by default. To turn it off, set storage.localPath.enabled: false and restart, or pass --local-storage=false to the install script. That only stops KubeSolo deploying it on later starts. If it is already running, also remove it with kubectl delete namespace local-path-storage and kubectl delete storageclass local-path.
CSI drivers and the kubelet path
Full CSI drivers work on KubeSolo. One detail matters: the kubelet's root directory is under the data directory, not the upstream default.
Operators, add-ons and CSI drivers that assume /var/lib/kubelet need their kubelet directory setting pointed at KubeSolo's path. For example, the NFS CSI Helm chart exposes kubeletDir:
If you change path at install time, the kubelet directory moves with it: <path>/kubelet.
The cluster database
Cluster state lives in SQLite through Kine, which serves the etcd API to the API server on 127.0.0.1:2379. The database file is /var/lib/kubesolo/kine/state.db.
Two settings help on edge hardware:
| Setting | Default | Use it when |
|---|---|---|
| storage.dbWALRepair | false | Devices lose power without a clean shutdown. At startup KubeSolo checks the database and removes the WAL and SHM files (state.db-wal, state.db-shm) if it finds corruption. |
| kubernetes.apiServer.startupTimeoutSeconds | 600 | Storage is slow, such as SD cards, and components take longer than ten minutes to pass their startup health checks. |
Registry mirrors and private registries
KubeSolo's embedded containerd reads per-registry configuration from hosts.toml files, using containerd's standard hosts directory format. No flags are involved; create files in this directory:
containerd reads the files at pull time, so you do not need to restart after creating or changing them. Use fully qualified image references, such as docker.io/library/nginx:alpine, so each pull maps to the right directory.
Mirror for Docker Hub
If the mirror does not have an image, containerd falls back to registry-1.docker.io.
Harbor proxy cache, private CA and credentials
Harbor's API is scoped by project, so the mirror URL carries the project path and override_path = true stops containerd adding its own /v2/:
Create one directory per upstream registry (docker.io, ghcr.io, quay.io and so on).
Air-gapped: one registry for everything
The special _default directory catches every registry that has no directory of its own. Point it at an internal registry that holds your workload images:
A registry-specific hosts.toml always takes precedence over _default. Combine this with the offline build, which embeds KubeSolo's own system images.
Local registry without TLS
Verifying
Use an image that is not already cached on the node, then check the mirror's logs for the pull. Registry configuration applies to the embedded containerd only. With an external runtime, configure registries in that runtime.