Description
A StatefulSet volume_claim_template can create persistent volume claims for its pods. This is normal for applications that need durable storage; requesting storage is not inherently a vulnerability.
Review the need for persistent storage when a workload only handles temporary or reproducible data. Unnecessary retention can increase cost and the scope of backup, encryption and disposal management.
Potential impact
- Unneeded persistent data can increase storage cost and management work.
- Removing required claims or changing retention incorrectly can cause data loss or service interruption.
Remediation
- Check the workload’s persistence needs and requested capacity. Do not simply remove the storage request from a required PVC.
- Configure backups, encryption and retention where persistence is needed. Otherwise, plan a deployment change after migrating or cleaning up the data.
- Before changing anything, check mutable StatefulSet fields, PVC retention and volume reclaim policies. A claim-template change may require recreating the workload.
Examples
These partial examples omit the Pod template and related Service. The after example represents a workload that does not need persistent claims; it is not a data-migration procedure or a universally safer configuration.
Before
hcl
resource "kubernetes_stateful_set" "example" {
metadata {
name = "prometheus"
}
spec {
service_name = "prometheus"
selector {
match_labels = {
app = "prometheus"
}
}
volume_claim_template {
metadata {
name = "data"
}
spec {
access_modes = ["ReadWriteOnce"]
storage_class_name = "standard"
resources {
requests = {
storage = "16Gi"
}
}
}
}
}
}
After
hcl
resource "kubernetes_stateful_set" "example" {
metadata {
name = "prometheus"
}
spec {
service_name = "prometheus"
selector {
match_labels = {
app = "prometheus"
}
}
}
}
Explanation:
- Before: The template requests 16Gi of persistent storage. This is appropriate when it matches the application’s data requirements.
- After: No claim template is declared. This excerpt alone does not automatically delete existing PVCs or data.