Review StatefulSet persistent-storage requirements

Review persistence needs together with capacity and retention policies.

Description

A StatefulSet volume_claim_template can create persistent volume claims for its pods. This is normal for applications that need durable storage; requesting storage is not inherently a vulnerability.

Review the need for persistent storage when a workload only handles temporary or reproducible data. Unnecessary retention can increase cost and the scope of backup, encryption and disposal management.

Potential impact

  • Unneeded persistent data can increase storage cost and management work.
  • Removing required claims or changing retention incorrectly can cause data loss or service interruption.

Remediation

  • Check the workload’s persistence needs and requested capacity. Do not simply remove the storage request from a required PVC.
  • Configure backups, encryption and retention where persistence is needed. Otherwise, plan a deployment change after migrating or cleaning up the data.
  • Before changing anything, check mutable StatefulSet fields, PVC retention and volume reclaim policies. A claim-template change may require recreating the workload.

Examples

These partial examples omit the Pod template and related Service. The after example represents a workload that does not need persistent claims; it is not a data-migration procedure or a universally safer configuration.

Before

hcl
resource "kubernetes_stateful_set" "example" {
  metadata {
    name = "prometheus"
  }

  spec {
    service_name = "prometheus"

    selector {
      match_labels = {
        app = "prometheus"
      }
    }

    volume_claim_template {
      metadata {
        name = "data"
      }

      spec {
        access_modes       = ["ReadWriteOnce"]
        storage_class_name = "standard"

        resources {
          requests = {
            storage = "16Gi"
          }
        }
      }
    }
  }
}

After

hcl
resource "kubernetes_stateful_set" "example" {
  metadata {
    name = "prometheus"
  }

  spec {
    service_name = "prometheus"

    selector {
      match_labels = {
        app = "prometheus"
      }
    }
  }
}

Explanation:

  • Before: The template requests 16Gi of persistent storage. This is appropriate when it matches the application’s data requirements.
  • After: No claim template is declared. This excerpt alone does not automatically delete existing PVCs or data.

References