代码之家  ›  专栏  ›  技术社区  ›  Evan R.

两个kubernetes卷可以装载到同一个位置吗

  •  1
  • Evan R.  · 技术社区  · 8 年前

    我对库伯内特斯还很陌生,想弄清楚。我还没能用谷歌搜索这个答案,所以我被难住了。库伯内特斯能在同一条路上隐藏两个秘密吗?假设给定以下部署:

    apiVersion: apps/v1 # for versions before 1.9.0 use apps/v1beta2
    kind: Deployment
    metadata:
      name: nginx-deployment
      labels:
        app: nginx-deployment
        version: v1
    spec:
      selector:
        matchLabels:
          app: nginx
      replicas: 1
      template:
        metadata:
          labels:
            app: nginx
            version: v1
        spec:
          volumes:
          - name: nginxlocal
            hostPath:
              path: /srv/docker/nginx
          - name: requestcert
            secret:
              secretName: requests-certificate
          - name: mysitecert
            secret:
              secretName: mysitecert
          containers:
          - name: nginx
            image: nginx:mainline-alpine # Use 1.15.0
            volumeMounts:
            - name: nginxlocal
              subPath: config/nginx.conf
              mountPath: /etc/nginx/nginx.conf
            - name: requestcert
              mountPath: /etc/nginx/ssl
            - name: mysitecert
              mountPath: /etc/nginx/ssl
            - name: nginxlocal
              subPath: logs
              mountPath: /etc/nginx/logs
            ports:
            - containerPort: 443
    

    是否可以将两个SSL证书装载到同一目录(/etc/nginx/SSL/*)?

    谢谢!

    1 回复  |  直到 8 年前
        1
  •  5
  •   mdaniel    8 年前

    是否可以将两个SSL证书装载到同一目录(/etc/nginx/SSL/*)?

    mount -t ext4 /dev/something /path/something 在那里面 /path/something

    然而,你只有一个轻微的臭味工作可供你:秘密山 requestcert 作为 /etc/nginx/.reqcert (或类似),秘密山 mysitecert /etc/nginx/.sitecert ,然后取代 entrypoint 并在委派到实际入口点之前将文件复制到位:

    containers:
    - name: nginx
      image: etc etc
      command:
      - bash
      - -c
      - |
        mkdir -p /etc/nginx/ssl
        cp /etc/nginx/.*cert/* /etc/nginx/ssl/
        # or whatever initialization you'd like
    
        # then whatever the entrypoint is for your image
        /usr/local/sbin/nginx -g "daemon off;"
    

    或者,如果这看起来不是一个好主意,您可以利用一个一次性的、特定于Pod的目录与 initContainers: :

    spec:
      volumes:
      # all the rest of them, as you had them
      - name: temp-config
        emptyDir: {}
      initContainers:
      - name: setup-config
        image: busybox  # or whatever
        command:
        - sh
        - -c
        - |
           # "stage" all the config files, including certs
           # into /nginx-config which will evaporate on Pod destruction
        volumeMounts:
        - name: temp-config
          mountPath: /nginx-config
        # and the rest
    
      containers:
      - name: nginx
        # ...
        volumeMounts:
        - name: temp-config
          mountPath: /etc/nginx
    

    它们在复杂度上有所不同,这取决于您是否要处理跟踪上游映像的入口点命令,而不是保持上游映像不变,但要花费更多的初始化能量