# Why PVCs are being deleted and how to create role mappings with OIDC

**URL:** <https://discuss.elastic.co/t/why-pvcs-are-being-deleted-and-how-to-create-role-mappings-with-oidc/250053>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [September 26, 2020, 11:20am UTC](https://discuss.elastic.co/t/why-pvcs-are-being-deleted-and-how-to-create-role-mappings-with-oidc/250053 "2020-09-26T11:20:47Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![cccs-eric](https://avatars.discourse-cdn.com/v4/letter/c/0ea827/32.png) [@cccs-eric](https://discuss.elastic.co/u/cccs-eric)\
**Post date:** [September 26, 2020, 11:20am UTC](https://discuss.elastic.co/t/why-pvcs-are-being-deleted-and-how-to-create-role-mappings-with-oidc/250053/1 "2020-09-26T11:20:47Z")

</div>

Hi,

I am setting up a new ECK instance using the Operator and I have two questions that I can’t find an answer for.

1- on this documentation page [https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-volume-claim-templates.html](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-volume-claim-templates.html), there is a paragraph that says:

_ECK automatically deletes PersistentVolumeClaim resources if they are not required for any Elasticsearch node. The corresponding PersistentVolume may be preserved, depending on the configured [storage class reclaim policy](https://kubernetes.io/docs/concepts/storage/storage-classes/#reclaim-policy)._

I don’t understand the reason behind this. I have defined a storageClass with a retain policy, so my PVs are never deleted. But as the doc says, when I bring down my instance, the PVCs are deleted even though ECK is using statefullsets. It is common practice to leave those PVCs and you manually have to delete them. By not deleting them, you can recreate your instance and it will reuse those PVCs and obviously also the same PVs. So I can I reuse the same PVs in a shutdown-restart scenario?

2- I am using Azure AD as an OpenID connect authenticator and that works. But I need to define a role mapping in order to give data access to my user. According to this page [https://www.elastic.co/guide/en/elasticsearch/reference/current/oidc-role-mapping.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/oidc-role-mapping.html), the only way to add a role mapping with OIDC is to use the API:

- Your OpenID Connect users cannot do anything until they are assigned roles. This can be done through either the [add role mapping API](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-put-role-mapping.html) or with [authorization realms](https://www.elastic.co/guide/en/elasticsearch/reference/current/realm-chains.html#authorization_realms).  
You cannot use [role mapping files](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-roles.html#mapping-roles-file) to grant roles to users authenticating via OpenID Connect.\*

Is there a way to do this in an automated fashion, once the pods are running? I am using Helm to generate the various yaml files and apply them...

Thank you

---

<div class="post-metadata">

**Author:** ![sebgl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sebgl/32/48702_2.png) [@sebgl](https://discuss.elastic.co/u/sebgl)\
**Post date:** [October 2, 2020, 10:10am UTC](https://discuss.elastic.co/t/why-pvcs-are-being-deleted-and-how-to-create-role-mappings-with-oidc/250053/2 "2020-10-02T10:10:22Z")

</div>

Hello!  
Please open 2 different threads for those different questions 🙂

For the PVC question:

- Indeed, we delete PVCs by default because it matches what most people want to do. You can watch this Github issue that describes a potential setting to change that behaviour: [https://github.com/elastic/cloud-on-k8s/issues/2328](https://github.com/elastic/cloud-on-k8s/issues/2328).
- In the meantime, for the shutdown/restart use case we also put together [a script](https://github.com/elastic/cloud-on-k8s/tree/master/hack/reattach-pv) that recreates a cluster from existing retained PVs, even though there are no PVCs anymore.

For question 2 and automating API calls:

- This is not currently possible. One way would be to spin up your own Kubernetes Job alongside the Elasticsearch resource, that would wait until the cluster is available then perform the required API calls. We're thinking about making this an ECK feature but it's not available yet.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:14am UTC](https://discuss.elastic.co/t/why-pvcs-are-being-deleted-and-how-to-create-role-mappings-with-oidc/250053/3 "2022-11-04T08:14:04Z")

</div>


