Storage Architecture
NFS Quota Agent runs as a lightweight, single-binary Go daemon on the NFS host server with root privileges.
Architecture Diagram
Kubernetes CSI Driver / Client
│
▼ gRPC (:50051) / HTTP (:8080)
┌──────────────────────────────────────────────────────────┐
│ nfs-quota-agent Daemon (Go) │
│ ├─ gRPC Server (CreateQuota, SetQuota, DeleteQuota) │
│ ├─ HTTP REST & Prometheus Metrics Exporter │
│ ├─ Project ID Allocator (/etc/projects, /etc/projid) │
│ └─ XFS Quota Controller (xfs_quota CLI / ioctl) │
└──────────────────────────┬───────────────────────────────┘
│
▼ Linux Kernel VFS / XFS Engine
┌──────────────────────────────────────────────────────────┐
│ /srv/nfs Filesystem (Mounted with 'pquota') │
│ ├─ /srv/nfs/pvc-aaaa (Project ID 1001, Limit: 10 GiB) │
│ ├─ /srv/nfs/pvc-bbbb (Project ID 1002, Limit: 50 GiB) │
│ └─ /srv/nfs/pvc-cccc (Project ID 1003, Limit: 5 GiB) │
└──────────────────────────────────────────────────────────┘XFS Project Quota Kernel Mechanics
- Mount Option: The XFS filesystem must be mounted with the
pquota(orprjquota) option. - Directory Association: When a new PVC is created, a unique
Project IDis assigned and linked to the directory:xfs_quota -x -c 'project -s -p /srv/nfs/pvc-12345 101' /srv/nfs - Limit Enforcement: Hard and soft byte thresholds are established:
xfs_quota -x -c 'limit -p bhard=10g 101' /srv/nfs - Kernel-Level Blocking: Any write attempting to exceed the 10GiB limit immediately fails with
EDQUOT (Disk quota exceeded).