Add-ons and storage
EBS CSI
43 / 69

An EBS volume lives in one zone and attaches to one node, so provision it where the Pod will run.

Use gp3, set a zone-aware StorageClass, and plan replicas and spread constraints around it.

PVC data-pg-0StorageClass gp3-wffcScheduler places the Podin zone eu-west-1b(WaitForFirstConsumer)EBS CSI controllercreates gp3 volume in 1bNode attaches and mounts itone node at a time (RWO)Zone failure: the volume (and the Pod bound to it) cannot move to another zone. Replicate at the data layer or restore from snapshot.
StorageClass
kind: StorageClass
metadata: {name: gp3-wffc, annotations: {storageclass.kubernetes.io/is-default-class: "true"}}
provisioner: ebs.csi.aws.com
volumeBindingMode: WaitForFirstConsumer
allowVolumeExpansion: true
parameters: {type: gp3, encrypted: "true"}

Check your default class

Many clusters still ship a legacy gp2 default. Create a gp3 class, make it the default, and encrypt volumes. gp3 lets you set IOPS and throughput independently of size.