You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

通过Pod在Kubernetes节点安装nfs-common包遇DNS解析问题

问题描述

免责声明

我知晓此操作不符合Kubernetes集群规范,且存在安全风险

背景

同事休假未记录集群节点root密码,我需在节点安装nfs-common以挂载NFS卷。

尝试的操作

我尝试挂载主机文件系统后执行chroot来安装包,为此创建了如下Pod:

apiVersion: v1
kind: Pod
metadata:
  name: ubuntu-pod
spec:
  containers:
  - name: ubuntu-container
    image: ubuntu:24.04
    command: ["/bin/bash", "-c", "while true; do sleep 30; done;"]
    volumeMounts:
    - name: host-root
      mountPath: /hostfs
    securityContext:
      privileged: true
      capabilities:
        add:
          - SYS_ADMIN
          - SYS_RESOURCE
          - SYS_NICE
          - SYS_PTRACE
          - SYS_BOOT
          - SYS_MODULE
          - SYS_RAWIO
          - SYS_PACCT
          - SYS_NICE
          - SYS_TIME
          - SYS_TTY_CONFIG
          - SYSLOG
          - NET_ADMIN
  hostPID: true
  volumes:
  - name: host-root
    hostPath:
      path: /
  restartPolicy: Never

Pod启动后,我进入其shell并执行chroot /hostfs /bin/bash,但运行apt update && apt install -y nfs-common时失败,报错如下:

Ign:1 http://archive.ubuntu.com/ubuntu jammy InRelease
Ign:2 http://archive.ubuntu.com/ubuntu jammy-updates InRelease
Ign:3 http://archive.ubuntu.com/ubuntu jammy-backports InRelease
Ign:4 http://archive.ubuntu.com/ubuntu jammy-security InRelease
Ign:1 http://archive.ubuntu.com/ubuntu jammy InRelease
Ign:2 http://archive.ubuntu.com/ubuntu jammy-updates InRelease
Ign:3 http://archive.ubuntu.com/ubuntu jammy-backports InRelease
Ign:4 http://archive.ubuntu.com/ubuntu jammy-security InRelease
Ign:1 http://archive.ubuntu.com/ubuntu jammy InRelease
Ign:2 http://archive.ubuntu.com/ubuntu jammy-updates InRelease
Ign:3 http://archive.ubuntu.com/ubuntu jammy-backports InRelease
Ign:4 http://archive.ubuntu.com/ubuntu jammy-security InRelease
Err:1 http://archive.ubuntu.com/ubuntu jammy InRelease
  Temporary failure resolving 'archive.ubuntu.com'
Err:2 http://archive.ubuntu.com/ubuntu jammy-updates InRelease
  Temporary failure resolving 'archive.ubuntu.com'
Err:3 http://archive.ubuntu.com/ubuntu jammy-backports InRelease
  Temporary failure resolving 'archive.ubuntu.com'
Err:4 http://archive.ubuntu.com/ubuntu jammy-security InRelease
  Temporary failure resolving 'archive.ubuntu.com'
Reading package lists... Done
Building dependency tree... Done
Reading state information... Done
29 packages can be upgraded. Run 'apt list --upgradable' to see them.

我认为缺少某种权限,但无法确定具体项,请求协助解决。


解决方案

报错核心是DNS解析失败,并非权限问题。chroot到主机文件系统后,容器的DNS配置未被继承到chroot环境,且容器与主机的网络命名空间独立,导致无法正常解析域名。以下两种方式可解决:

方式一:复制容器DNS配置到主机挂载目录

进入Pod shell后,先执行:

cp /etc/resolv.conf /hostfs/etc/resolv.conf

再执行chroot /hostfs /bin/bash,之后运行apt update即可正常解析域名。

方式二:让Pod直接使用主机网络命名空间

修改Pod的spec,添加hostNetwork: true,让容器直接复用主机的网络与DNS配置,chroot后无需额外配置即可访问网络:

apiVersion: v1
kind: Pod
metadata:
  name: ubuntu-pod
spec:
  hostNetwork: true # 添加此行
  containers:
  - name: ubuntu-container
    image: ubuntu:24.04
    command: ["/bin/bash", "-c", "while true; do sleep 30; done;"]
    volumeMounts:
    - name: host-root
      mountPath: /hostfs
    securityContext:
      privileged: true
      capabilities:
        add:
          - SYS_ADMIN
          - SYS_RESOURCE
          - SYS_NICE
          - SYS_PTRACE
          - SYS_BOOT
          - SYS_MODULE
          - SYS_RAWIO
          - SYS_PACCT
          - SYS_NICE
          - SYS_TIME
          - SYS_TTY_CONFIG
          - SYSLOG
          - NET_ADMIN
  hostPID: true
  volumes:
  - name: host-root
    hostPath:
      path: /
  restartPolicy: Never

重新创建Pod后,chroot进去执行apt update && apt install -y nfs-common即可成功。

注:虽已知晓风险,但此类操作会破坏集群节点一致性,后续建议记录节点root密码或采用标准化节点初始化流程规避此类问题。

内容的提问来源于stack exchange,提问作者E. Jaep

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 12:03:28