Skip to content

FAQ

What operating systems does flexFS support?

Section titled “What operating systems does flexFS support?”

FlexFS runs on Linux. The only hard kernel requirement is FUSE wire protocol version 7.18 or newer, which any current Linux distribution provides. Older kernels simply run with a reduced feature set or lower performance (for example, POSIX ACLs are enforced on any kernel, but before kernel 4.9 the mount client enforces them itself, which is slower; see Access Control). Both amd64 and arm64 (aarch64) architectures are supported.

FlexFS has no per-file size limit, but a file cannot exceed its volume’s capacity: 5 TiB in the Community edition, or the volume’s block quota, if one is set, in the Enterprise edition. Files are split into blocks (2 MiB in the Community edition; configurable per volume from 256 KiB to 8 MiB in the Enterprise edition), so without a quota the maximum is bounded only by the metadata server’s capacity and the object storage backend.

How many concurrent mounts can a single metadata server handle?

Section titled “How many concurrent mounts can a single metadata server handle?”

A metadata server can handle hundreds to thousands of concurrent mount sessions depending on the workload and hardware. Each mount client maintains a persistent RPC connection. See the Scaling to 1000+ Mounts guide for tuning recommendations.

What cloud storage backends are supported?

Section titled “What cloud storage backends are supported?”

FlexFS supports Amazon S3, Google Cloud Storage, Azure Blob Storage, and Oracle Cloud Infrastructure Object Storage. Any S3-compatible storage (MinIO, Wasabi, Ceph RGW, etc.) also works using the s3 block API.

Can I use flexFS with on-premises object storage?

Section titled “Can I use flexFS with on-premises object storage?”

Yes. Any S3-compatible object storage can be used by specifying a custom endpoint address when creating a block store.

What is the difference between Enterprise and Community?

Section titled “What is the difference between Enterprise and Community?”

The Community edition supports a single volume with all core filesystem features. The Enterprise edition adds unlimited volumes, configure.flexfs, proxy groups, end-to-end encryption, volume quotas, mount-path scoped tokens, and dynamic CSI provisioning. See the Editions page for the full comparison.

Can I upgrade from Community to Enterprise?

Section titled “Can I upgrade from Community to Enterprise?”

Yes. Run the Enterprise installer on the Community server and choose upgrade. The volume, its data, and its tokens are kept, and existing mounts keep running.

File data is stored as blocks in your cloud object storage bucket. Metadata (directory structure, file attributes, permissions) is stored on the metadata server’s local disk. You retain full ownership and control of both.

What happens if the metadata server goes down?

Section titled “What happens if the metadata server goes down?”

Active mounts will continue to serve cached data for a short period but will eventually become unresponsive for new operations. When the metadata server comes back, mounts reconnect automatically. The metadata database should be backed up regularly.

A mount client whose proxy request still fails after 15 seconds of retries reads or writes that block directly in object storage and sends all block requests directly for the next five minutes. It then probes the proxy groups again in the background and returns to one only if all of its servers answer; until a group does, it stays direct and probes again every five minutes. Performance may degrade but data remains fully accessible.

Does flexFS support point-in-time recovery?

Section titled “Does flexFS support point-in-time recovery?”

Yes. The --atTime flag on mount.flexfs mounts a read-only snapshot of the filesystem at any point within the volume’s retention window (default: 604800 seconds / 7 days). Both metadata and block data are preserved for the retention period — no separate snapshot infrastructure is needed.

Yes. All communication between flexFS components (mount clients, metadata servers, proxy servers, admin server) uses TLS by default with auto-generated certificates.

With Enterprise end-to-end encryption enabled, blocks and metadata are encrypted with AES-256 before leaving the mount client. The encryption key is derived from a user-provided secret using Argon2id and never leaves the client. Additionally, S3 server-side encryption (SSE) can be enabled for an extra layer of at-rest protection.

Mount clients authenticate using volume tokens (UUIDs). Each volume token grants access to a specific volume and can optionally restrict the mount to a subdirectory (mount path). The configure.flexfs tool authenticates using account tokens.

Does the CSI driver require privileged mode?

Section titled “Does the CSI driver require privileged mode?”

Yes. The node DaemonSet runs the CSI driver container in privileged mode, with Bidirectional mount propagation into the kubelet directory, so that its FUSE mounts reach application pods. There is no option to run it with only the SYS_ADMIN capability. See Privileged mode denied if your cluster restricts privileged pods.

Does the CSI driver support dynamic provisioning?

Section titled “Does the CSI driver support dynamic provisioning?”

Dynamic provisioning is available in the Enterprise edition. Community edition supports static provisioning only.

FlexFS provides a POSIX filesystem interface. You can export a flexFS mount point via NFS or Samba to other machines, though this adds a layer of indirection. For multi-machine access, it is generally better to mount flexFS directly on each machine.

Yes. POSIX advisory locks (fcntl), open file description locks (fcntl(F_OFD_SETLK)), and BSD locks (flock) are all supported, and all are coordinated through the metadata server so they hold across every mount of the volume.

Section titled “Does flexFS support hard links and symlinks?”

Yes. Hard links, symbolic links, and special files (named pipes, sockets, block/character devices) are all supported.

Does flexFS support chattr immutable and append-only flags?

Section titled “Does flexFS support chattr immutable and append-only flags?”

Yes. chattr +i (immutable) and chattr +a (append-only) work as they do on ext4 or xfs, on both files and directories, with no mount option required, and lsattr reads them back. Only those two flags are implemented; any other is rejected with EOPNOTSUPP rather than silently ignored. Setting a flag requires root as the mount sees it, so it is not possible on a --rootSquash or --allSquash mount, and enforcement is performed by the mount client rather than the metadata server. See Inode flags for the full behavior and limits.

The mount client periodically polls the admin server’s deploy endpoint for newer binaries. When an update is available, it downloads the new binary, performs a FUSE session handoff to the new process, and the old process exits. The mount remains active throughout — no unmount or remount is needed.

Run manage.flexfs upgrade on each server host to download and install new versions of the flexFS binaries installed there and restart their services. Mount clients update themselves unless auto-update is disabled; see Manual updates.

By default, the installers configure the admin or free server on port 443, the metadata server on port 8443, and the proxy server on port 9443; each is a prompted default you can change during installation. A server started without --bindAddr listens on port 443. The CSI driver uses a Unix socket. Change a server’s port with --bindAddr.