Kubernetes storage location information

Storage classes, persistent volume claims, and container storage details for Kubernetes deployments

Contents

Overview

This document describes all storage locations used across the containers in a CAST Imaging Kubernetes deployment: persistent volumes, ConfigMap-backed configuration files, Secrets, and ephemeral (in-memory) volumes.


1. Storage Classes

Two storage class types are used, depending on the feature set enabled.

1.1 Block Storage Class (castimaging-ds)

Used for all standard persistent volumes (databases, logs, archives, etc.).

Parameter Value
Default name castimaging-ds (configurable via DiskClassName)
volumeBindingMode WaitForFirstConsumer
reclaimPolicy Delete
allowVolumeExpansion true

CSI provisioner and parameters vary by cloud provider:

Provider (K8SProvider) Provisioner Key Parameters
EKS (AWS) ebs.csi.aws.com type: gp3, fsType: ext4
AKS (Azure) disk.csi.azure.com skuName: Premium_LRS, kind: Managed
GKE (Google) pd.csi.storage.gke.io type: pd-standard (or pd-ssd)

1.2 File Storage Class (castimaging-fs)

This allows the Analysis Node’s shared data directory to use ReadWriteMany (RWX) access mode, enabling horizontal scaling of analysis nodes.

Provider Provisioner Notes
EKS efs.csi.aws.com provisioningMode: efs-ap (creates an EFS Access Point), directoryPerms: "770", uid/gid: "10001". Requires EFSsystemID; optionally EFSaccessPointID for an explicit PV. Does not set allowVolumeExpansion (not supported by EFS access points)
AKS file.csi.azure.com SMB protocol; mountOptions (dir_mode=0770, file_mode=0660, uid/gid=10001, mfsymlinks, cache=strict, nobrl); optional AKSresourceGroup / AKSstorageAccount / AKSsharedDatadirPV
GKE filestore.csi.storage.gke.io tier: standard or premium

2. Persistent Volume Claims (PVCs)

All PVCs are created in the deployment namespace with the annotation helm.sh/resource-policy: keep, ensuring they are not deleted on helm uninstall.

PVC Name Default Size Storage Class Access Mode Service Conditional
pvc-shared-datadir 100Gi castimaging-fs SharedVolumeAccessMode (default ReadWriteMany) console-analysis-node, console-control-panel, console-service Always created
db-data 128Gi castimaging-ds RWO console-postgres Only if CastStorageService.enable: true
pvc-imagingviewer-v3-server-log 1Gi castimaging-ds RWO viewer-server Always created
pvc-imagingviewer-v3-etl-logs 10Gi castimaging-ds RWO viewer-etl Always created
pvc-imagingviewer-v3-etl-csvarchive 10Gi castimaging-ds RWO viewer-etl Always created
pvc-imagingviewer-v3-aimanager-logs 2Gi castimaging-ds RWO viewer-aimanager Always created
pvc-imagingviewer-v3-api-logs 2Gi castimaging-ds RWO viewer-api Always created
pvc-mcpserver-logs 2Gi castimaging-ds RWO mcp-server Only if McpServer.enable: true
pvc-extendproxy-data 10Gi castimaging-ds RWO extendproxy Only if ExtendProxy.enable: true
pvc-controlpanel-logs 2Gi castimaging-ds RWO console-control-panel Always created (≥ 3.6.8)
pvc-gatewayservice-logs 2Gi castimaging-ds RWO console-gateway-service Always created (≥ 3.6.8)
pvc-authenticationservice-logs 2Gi castimaging-ds RWO console-authentication-service Always created (≥ 3.6.8)
pvc-consoleservice-logs 2Gi castimaging-ds RWO console-service Always created (≥ 3.6.8)
pvc-ssoservice-logs 2Gi castimaging-ds RWO console-sso-service Always created (≥ 3.6.8)
pvc-dashboards-logs 2Gi castimaging-ds RWO console-dashboards Always created (≥ 3.6.8)

All PVC sizes are configurable through values.yaml (e.g. size_db_data, size_shared_datadir, etc.). The console log PVCs introduced in 3.6.8 are sized with size_controlpanel_logs, size_gatewayservice_logs, size_authenticationservice_logs, size_consoleservice_logs, size_ssoservice_logs and size_dashboards_logs (default 2Gi each).


3. StatefulSet Volume Claim Templates

These volumes are provisioned automatically per pod replica via volumeClaimTemplates in StatefulSets. They use the castimaging-ds block storage class.

console-analysis-node (StatefulSet)

Template Name Default Size Mount Path Purpose
castdir 100Gi /usr/share/CAST CAST installation directory: extensions, LISA data, analysis engine logs

viewer-neo4j (StatefulSet)

A single neo4jdata volume (100Gi) is provisioned per pod. It is sub-divided using subPathExpr into three logical directories:

Sub-Path Mount Path Purpose
logs /var/lib/neo4j/logs Neo4j operational logs
neo4jdata /var/lib/neo4j/config/neo4j5_data Neo4j graph database data files
csvarchive /var/lib/neo4j/config/csv/archive Archived CSV import files

4. Per-Container Storage Details

4.1 console-postgres

The PostgreSQL database server used by all Console services and Keycloak.

Volume Type Mount Path Purpose
db-data PVC (db-data, 128Gi) /var/lib/postgresql/data (subPath: postgres) Database data files
pgconf ConfigMap (console-v3-postgresqlconf) /usr/share/postgresql/postgresql.conf.sample Custom PostgreSQL configuration
pginit ConfigMap (console-v3-init-db) /docker-entrypoint-initdb.d/init-db.sh Database initialization script (users, databases, grants)
dshm EmptyDir (Memory, 4G) /dev/shm Shared memory for PostgreSQL
db-creds Secret (imaging-pwd-sec) /opt/secrets Database passwords, read-only
postgres-ssl EmptyDir /var/lib/postgresql/ssl Self-signed SSL certificate/key generated at startup by the generate-ssl-cert init container. Only when CastStorageService.ssl: true
pghbaconf ConfigMap (console-v3-pghbaconf) /etc/postgresql/pg_hba.conf Host-based authentication file requiring SSL connections. Only when CastStorageService.ssl: true

The db-data PVC is only created when CastStorageService.enable: true. When using an external PostgreSQL instance (CustomPostgres.enable: true), no PVC is created and a separate init script (init-db-custom-pg.sh) is executed as an init container to set up the required users and databases on the external server.

4.2 console-analysis-node

The CAST analysis engine. Runs as a StatefulSet.

Volume Type Mount Path Purpose
castdir VolumeClaimTemplate (100Gi) /usr/share/CAST CAST engine binaries, extensions, logs, LISA data
shared-datadir PVC (pvc-shared-datadir, 100Gi) /opt/cast/shared Shared analysis workspace: delivery, deploy, and common-data folders
dshm EmptyDir (Memory, 1G) /dev/shm Shared memory for analysis processing

The pvc-shared-datadir sub-directories used at runtime:

Sub-directory Path Purpose
Delivery /opt/cast/shared/delivery Source code and artifacts delivered for analysis
Deploy /opt/cast/shared/deploy Analysis deployment output
Common data /opt/cast/shared/common-data Shared configuration and data across analysis nodes

The analysisnode-upgrade-script ConfigMap is mounted into a postgres-upgrade init container (see Section 5).

4.3 viewer-neo4j

The graph database for the Imaging Viewer. Runs as a StatefulSet.

Volume Type Mount Path Purpose
neo4jdata (subPath: logs) VolumeClaimTemplate (100Gi) /var/lib/neo4j/logs Neo4j logs
neo4jdata (subPath: neo4jdata) VolumeClaimTemplate (100Gi) /var/lib/neo4j/config/neo4j5_data Graph database data files
neo4jdata (subPath: csvarchive) VolumeClaimTemplate (100Gi) /var/lib/neo4j/config/csv/archive Archived CSV files after import

All three paths share a single underlying 100Gi PVC via sub-paths.

4.4 viewer-server

The main Imaging Viewer frontend and backend service, fronted by Nginx.

Volume Type Mount Path Purpose
log PVC (pvc-imagingviewer-v3-server-log, 1Gi) /opt/imaging/imaging-service/logs Application and Nginx access/error logs
servernginxconf ConfigMap (servernginxconf) /opt/imaging/config/nginx/conf/nginx.conf Nginx reverse-proxy configuration

4.5 viewer-etl

The ETL (Extract, Transform, Load) service responsible for importing analysis data into Neo4j.

Volume Type Mount Path Purpose
logdir PVC (pvc-imagingviewer-v3-etl-logs, 10Gi) /opt/imaging/imaging-etl/logs ETL operational logs
csvarchive PVC (pvc-imagingviewer-v3-etl-csvarchive, 10Gi) /opt/imaging/imaging-etl/upload/archive Archived CSV files after they have been processed and loaded

4.6 viewer-aimanager

The AI/enrichment manager service.

Volume Type Mount Path Purpose
logdir PVC (pvc-imagingviewer-v3-aimanager-logs, 2Gi) /opt/imaging/open_ai-manager/logs AI Manager operational logs

4.7 viewer-api

The public REST API service for querying the Imaging graph.

Volume Type Mount Path Purpose
logdir PVC (pvc-imagingviewer-v3-api-logs, 2Gi) /opt/imaging/imaging-api/logs API service operational logs

4.8 mcp-server

The Model Context Protocol server. Only deployed when McpServer.enable: true.

Volume Type Mount Path Purpose
logdir PVC (pvc-mcpserver-logs, 2Gi) /app/logs MCP server operational logs
mcpserverappconfig ConfigMap (mcpserverappconfig) /app/server/config/app.config MCP server application configuration

4.9 extendproxy

The CAST Extend proxy service. Only deployed when ExtendProxy.enable: true.

Volume Type Mount Path Purpose
extendproxy PVC (pvc-extendproxy-data, 10Gi) /opt/cast_extend_proxy/data Proxy cache, configuration, and runtime data

4.10 console-control-panel

Volume Type Mount Path Purpose
shared-datadir PVC (pvc-shared-datadir, 100Gi) /opt/cast/shared Audit trail data (common-data sub-directory) and other data shared with console-analysis-node and console-service
controlpanel-logs PVC (pvc-controlpanel-logs, 2Gi) /opt/cast/imaging-services/logs/control-panel Control Panel operational logs (LOGS_FOLDER). Since 3.6.8

Init containers use the contexturl-controlpanel-update-script and contexturl-keycloak-update-script ConfigMap-backed SQL scripts to update context URLs in the PostgreSQL database on startup (see Section 5).

4.11 console-authentication-service

Volume Type Mount Path Purpose
authenticationservice-logs PVC (pvc-authenticationservice-logs, 2Gi) /opt/cast/imaging-services/logs/auth-service Authentication service operational logs (LOGS_FOLDER). Since 3.6.8

4.12 console-service

Volume Type Mount Path Purpose
shared-datadir PVC (pvc-shared-datadir, 100Gi) /opt/cast/shared Shared configuration and data across analysis nodes, console-control-panel, and Console service
consoleservice-logs PVC (pvc-consoleservice-logs, 2Gi) /opt/cast/imaging-services/logs/console Console service operational logs (LOGS_FOLDER). Since 3.6.8

An init container also uses the contexturl-controlpanel-update-script, contexturl-keycloak-update-script, and license-extend-update-script ConfigMap-backed SQL scripts (see Section 5).

4.13 console-gateway-service

Volume Type Mount Path Purpose
gatewayservice-logs PVC (pvc-gatewayservice-logs, 2Gi) /opt/cast/imaging-services/logs/gateway Gateway service operational logs (LOGS_FOLDER). Since 3.6.8

4.14 console-sso-service

Volume Type Mount Path Purpose
ssoservice-logs PVC (pvc-ssoservice-logs, 2Gi) /opt/cast/imaging-services/logs/sso Keycloak log files. Since 3.6.8

Keycloak is configured to log both to the standard output and to the file /opt/cast/imaging-services/logs/sso/sso.log (KC_LOG=console,file). The file is rotated daily (suffix .yyyy-MM-dd.gz) or when it reaches 10M (KC_LOG_FILE_ROTATION_MAX_FILE_SIZE), and is not rotated on pod startup.

4.15 console-dashboards

Volume Type Mount Path Purpose
dashboards-logs PVC (pvc-dashboards-logs, 2Gi) /opt/cast/imaging-dashboards/logs Dashboards operational logs (LOGS_FOLDER). Since 3.6.8

4.16 proxy-exclusions-cronjob

A suspended CronJob (schedule intentionally invalid) that can be triggered manually with kubectl create job --from=cronjob/proxy-exclusions-cronjob to refresh the reverse-proxy’s non_proxy_hosts list from the currently registered service subnets. It mounts no PVC.

Volume Type Mount Path Purpose
proxy-exclusions-update-script ConfigMap (proxy-exclusions-update-script) /proxy-exclusions-update-script.sh Script that discovers registered service subnets and updates control_panel.settings.non_proxy_hosts

5. ConfigMap-Backed File Mounts

The following ConfigMaps are mounted as files into containers or init containers.

ConfigMap Mounted In Mount Path Content
console-v3-postgresqlconf console-postgres /usr/share/postgresql/postgresql.conf.sample Tuned PostgreSQL configuration (memory, WAL, logging, auto_explain)
console-v3-init-db console-postgres (init via docker-entrypoint-initdb.d) /docker-entrypoint-initdb.d/init-db.sh Creates operator, guest, keycloak users and the keycloak database on first startup
init-db-custom-pg Init container in console-postgres Executed as a script Used when CustomPostgres.enable: true to initialize users/databases on an external PostgreSQL server
console-v3-pghbaconf console-postgres /etc/postgresql/pg_hba.conf Host-based authentication file requiring SSL. Only when CastStorageService.ssl: true
contexturl-controlpanel-update-script Init container in console-control-panel and console-service /home/imaging/sql/contexturl-controlpanel-update-script.sql Sets keycloak.uri property in control_panel.properties
contexturl-keycloak-update-script Init container in console-control-panel and console-service /home/imaging/sql/contexturl-keycloak-update-script.sql Removes frontendUrl from Keycloak realm attributes
license-extend-update-script Init container in console-service /home/imaging/sql/license-extend-update-script.sql Runs license/extend-related update SQL against the postgres database
analysisnode-upgrade-script Init container in console-analysis-node /home/imaging/sql/analysisnode-upgrade-script.sql Runs schema upgrade SQL on the postgres database
servernginxconf viewer-server /opt/imaging/config/nginx/conf/nginx.conf Nginx reverse-proxy rules for routing API, ETL, Neo4j, AI, login, SAML, and sourcecode endpoints
mcpserverappconfig mcp-server /app/server/config/app.config MCP server runtime configuration (ports, control panel host, domain, etc.)
keycloak-init-script One-time keycloak-init-job Job /init-keycloak.sh Bootstraps the Keycloak realm on first install
proxy-exclusions-update-script proxy-exclusions-cronjob (manually triggered) /proxy-exclusions-update-script.sh Refreshes control_panel.settings.non_proxy_hosts from registered service subnets

6. Secret Mounts

The Secret imaging-pwd-sec is used both as environment variable source and as a file-system mount.

Secret Key Used By (env var) Mounted As File In
postgres-db-password console-postgres, postgres-upgrade init container in console-analysis-node console-postgres → /opt/secrets/postgres-db-password
operator-db-password console-authentication-service, console-control-panel, console-service, console-sso-service, postgres-upgrade init container in console-analysis-node, keycloak-init-job, proxy-exclusions-cronjob console-postgres → /opt/secrets/operator-db-password
operator-db-password-crypted2 console-control-panel (DB_ENCRYPTED_PASSWORD) —
guest-db-password (init script only) console-postgres → /opt/secrets/guest-db-password
keycloak-db-password (init script only) console-postgres → /opt/secrets/keycloak-db-password
keycloak-admin-password console-authentication-service, console-sso-service, keycloak-init-job —
neo4j-password viewer-neo4j, viewer-server, viewer-etl, viewer-aimanager, viewer-api —
smtp-password console-control-panel (SPRING_MAIL_PASSWORD). Only present when SMTP.enable: true —

The file-system mount (/opt/secrets) in console-postgres is read-only and used by the init script to read passwords at startup.


7. Ephemeral (In-Memory) Volumes

Volume Name Container Type Size Mount Path Purpose
dshm console-postgres EmptyDir (Memory) 4G /dev/shm PostgreSQL shared memory (required for work_mem, parallel queries)
dshm console-analysis-node EmptyDir (Memory) 1G /dev/shm Analysis engine shared memory
postgres-ssl console-postgres EmptyDir — /var/lib/postgresql/ssl Self-signed SSL certificate/key. Only when CastStorageService.ssl: true


8. Deployment Options Affecting Storage

8.1 Cloud Provider (K8SProvider)

Controls which CSI drivers are used for the castimaging-ds (and optionally castimaging-fs) storage classes. Accepted values: EKS, AKS, GKE.

8.2 Built-in vs. External PostgreSQL

Option Behavior
CastStorageService.enable: true (default) PostgreSQL is deployed as part of the Helm chart. The db-data PVC (128Gi) is created automatically.
CastStorageService.enable: false + CustomPostgres.enable: true No PostgreSQL deployment and no db-data PVC. An init container runs init-db-custom-pg.sh against the external host specified by CustomPostgres.host / CustomPostgres.port.

8.3 Analysis Node Shared File Storage (AnalysisNodeFS.enable) - Imaging version < 3.6.0

Option pvc-shared-datadir Access Mode Storage Class Supports Multiple Analysis Nodes
false (default) ReadWriteOnce castimaging-ds (block) No — single node only
true ReadWriteMany castimaging-fs (file) Yes

When enabling file storage on EKS, the EFSsystemID value is required. Optionally, providing EFSaccessPointID causes an explicit PersistentVolume (pv-shared-datadir) to be created.

On AKS, if auto-provisioning is not available, set AnalysisNodeFS.AKSsharedDatadirPV.create: true and provide secretName and shareName to create an explicit PV backed by an Azure File Share.

8.4 Embedded PostgreSQL SSL (CastStorageService.ssl)

Option Behavior
CastStorageService.ssl: false (default) No SSL enforcement on the embedded PostgreSQL server.
CastStorageService.ssl: true A generate-ssl-cert init container generates a self-signed certificate into the postgres-ssl EmptyDir; PostgreSQL is started with ssl=on and hba_file pointed at the pghbaconf ConfigMap requiring SSL connections.

This is independent of CreatePostgresLoadBalancer, which exposes the embedded PostgreSQL service externally.

8.5 Optional Components

Component Controlling Value PVC Created
Extend Proxy ExtendProxy.enable: true pvc-extendproxy-data (10Gi)
MCP Server McpServer.enable: true pvc-mcpserver-logs (2Gi)

8.6 Storage Class Creation

Set CreateStorageClass: false to skip storage class creation (e.g., if the cluster admin has pre-provisioned them). The DiskClassName and FileClassName values must still match the names of the existing storage classes.


9. Downloading Logs

There are 2 types of logs:

  • Standard output logs: correspond to the log avialable from kubernetes and containing anything services are writing to the standard output.
  • Specific log files: some services have addtional logs available, stored in persistent files: console-postgres, console-analysis-node, viewer-neo4j, viewer-server, viewer-etl and, since 3.6.8, console-control-panel, console-gateway-service, console-authentication-service, console-service, console-sso-service, console-dashboards


The following commands can be used to download those logs. Run them from the machine where kubectl is configured and authenticated against your cluster.


Standard output logs (from all pods)

kubectl logs -l app=castimaging --all-containers=true --prefix=true --tail=-1 -n castimaging-v3 > all-pods-std-output.log

Specific log files stored inside pods

Postgres — postgres database logs stored in the db-data volume:
Adjust the console-postgres pod name if needed.
Linux:

kubectl cp -n castimaging-v3 \
  console-postgres-0:/var/lib/postgresql/data/log \
  ./Logs/postgres

Windows (PowerShell):

kubectl cp -n castimaging-v3 `
  console-postgres-0:/var/lib/postgresql/data/log `
  ./Logs/postgres

Analysis Node — CAST engine logs stored in the castdir volume:

Linux:

kubectl cp -n castimaging-v3 \
  console-analysis-node-core-0:/usr/share/CAST/CAST/Logs \
  ./Logs/console-analysis-node

Windows (PowerShell):

kubectl cp -n castimaging-v3 `
  console-analysis-node-core-0:/usr/share/CAST/CAST/Logs `
  ./Logs/console-analysis-node

Neo4j — graph database logs stored in the neo4jdata volume:

Linux:

kubectl cp -n castimaging-v3 \
  viewer-neo4j-core-0:/var/lib/neo4j/logs \
  ./Logs/viewer-neo4j

Windows (PowerShell):

kubectl cp -n castimaging-v3 `
  viewer-neo4j-core-0:/var/lib/neo4j/logs `
  ./Logs/viewer-neo4j

Viewer Server — Nginx access/error logs and application logs:

Linux:

POD=$(kubectl get pod -n castimaging-v3 -l imaging.service=viewer-server -o jsonpath='{.items[0].metadata.name}')
kubectl cp -n castimaging-v3 $POD:/opt/imaging/imaging-service/logs ./Logs/viewer-server

Windows (PowerShell):

$POD = kubectl get pod -n castimaging-v3 -l imaging.service=viewer-server -o jsonpath='{.items[0].metadata.name}'
kubectl cp -n castimaging-v3 "${POD}:/opt/imaging/imaging-service/logs" ./Logs/viewer-server

Viewer ETL — ETL service operational logs:

Linux:

POD=$(kubectl get pod -n castimaging-v3 -l imaging.service=viewer-etl -o jsonpath='{.items[0].metadata.name}')
kubectl cp -n castimaging-v3 $POD:/opt/imaging/imaging-etl/logs ./Logs/viewer-etl

Windows (PowerShell):

$POD = kubectl get pod -n castimaging-v3 -l imaging.service=viewer-etl -o jsonpath='{.items[0].metadata.name}'
kubectl cp -n castimaging-v3 "${POD}:/opt/imaging/imaging-etl/logs" ./Logs/viewer-etl

Console services (3.6.8 and later) — logs stored in the dedicated log volumes:

Service (imaging.service label) Log path
console-control-panel /opt/cast/imaging-services/logs/control-panel
console-gateway-service /opt/cast/imaging-services/logs/gateway
console-authentication-service /opt/cast/imaging-services/logs/auth-service
console-service /opt/cast/imaging-services/logs/console
console-sso-service /opt/cast/imaging-services/logs/sso
console-dashboards /opt/cast/imaging-dashboards/logs

Example for console-control-panel (replace the label and path for the other services):

Linux:

POD=$(kubectl get pod -n castimaging-v3 -l imaging.service=console-control-panel -o jsonpath='{.items[0].metadata.name}')
kubectl cp -n castimaging-v3 $POD:/opt/cast/imaging-services/logs/control-panel ./Logs/console-control-panel

Windows (PowerShell):

$POD = kubectl get pod -n castimaging-v3 -l imaging.service=console-control-panel -o jsonpath='{.items[0].metadata.name}'
kubectl cp -n castimaging-v3 "${POD}:/opt/cast/imaging-services/logs/control-panel" ./Logs/console-control-panel

Collect all logs in one shot

Use the Util-CollectLogs.sh / Util-CollectLogs.ps1 utilities provided with the Helm chart.


10. Checking disk usage of volumes

The following commands check the disk usage of main volumes. Run them from the machine where kubectl is configured and authenticated against your cluster.

kubectl exec -it console-analysis-node-core-0 -n castimaging-v3 -- df -h /opt/cast/shared
kubectl exec -it console-analysis-node-core-0 -n castimaging-v3 -- df -h /usr/share/CAST
kubectl exec -it console-postgres-0           -n castimaging-v3 -- df -h /var/lib/postgresql/data
kubectl exec -it viewer-neo4j-core-0          -n castimaging-v3 -- df -h /var/lib/neo4j/config/neo4j5_data
kubectl exec -it viewer-etl-xxxxx             -n castimaging-v3 -- df -h /opt/imaging/imaging-etl/logs
kubectl exec -it viewer-etl-xxxxx             -n castimaging-v3 -- df -h /opt/imaging/imaging-etl/upload/archive
kubectl exec -it extendproxy-xxxxx            -n castimaging-v3 -- df -h /opt/cast_extend_proxy/data

11. Storage Summary Table

Container PVC(s) VolumeClaimTemplate(s) ConfigMap Files Secret Files EmptyDir
console-postgres db-data ¹ — postgresql.conf.sample, init-db.sh /opt/secrets (all DB passwords) /dev/shm (4G)
console-control-panel pvc-shared-datadir (shared), pvc-controlpanel-logs ⁵ — SQL update scripts (init containers) — —
console-authentication-service pvc-authenticationservice-logs ⁵ — — — —
console-gateway-service pvc-gatewayservice-logs ⁵ — — — —
console-sso-service pvc-ssoservice-logs ⁵ — — — —
console-dashboards pvc-dashboards-logs ⁵ — — — —
keycloak-init-job (one-time Job) — — init-keycloak.sh — —
console-service pvc-shared-datadir (shared), pvc-consoleservice-logs ⁵ — SQL update scripts (init containers) — —
proxy-exclusions-cronjob (manual trigger) — — proxy-exclusions-update-script.sh — —
console-analysis-node pvc-shared-datadir castdir (100Gi) SQL upgrade script (init container) — /dev/shm (1G)
viewer-neo4j — neo4jdata (100Gi) — — —
viewer-server pvc-imagingviewer-v3-server-log — nginx.conf — —
viewer-etl pvc-imagingviewer-v3-etl-logs, pvc-imagingviewer-v3-etl-csvarchive — — — —
viewer-aimanager pvc-imagingviewer-v3-aimanager-logs — — — —
viewer-api pvc-imagingviewer-v3-api-logs — — — —
mcp-server ² pvc-mcpserver-logs — app.config — —
extendproxy ³ pvc-extendproxy-data — — — —

Notes:

  1. db-data PVC only exists when CastStorageService.enable: true.
  2. mcp-server and its PVC only deployed when McpServer.enable: true.
  3. extendproxy and its PVC only deployed when ExtendProxy.enable: true.
  4. Apart from their log volumes, console-control-panel and console-service do not have dedicated PVCs. They mount the shared pvc-shared-datadir volume also used by console-analysis-node (Section 3).
  5. Console log PVCs are only present in 3.6.8 and later.