通过Pod在Kubernetes节点安装nfs-common包遇DNS解析问题
问题描述
免责声明
我知晓此操作不符合Kubernetes集群规范,且存在安全风险
背景
同事休假未记录集群节点root密码,我需在节点安装nfs-common以挂载NFS卷。
尝试的操作
我尝试挂载主机文件系统后执行chroot来安装包,为此创建了如下Pod:
apiVersion: v1 kind: Pod metadata: name: ubuntu-pod spec: containers: - name: ubuntu-container image: ubuntu:24.04 command: ["/bin/bash", "-c", "while true; do sleep 30; done;"] volumeMounts: - name: host-root mountPath: /hostfs securityContext: privileged: true capabilities: add: - SYS_ADMIN - SYS_RESOURCE - SYS_NICE - SYS_PTRACE - SYS_BOOT - SYS_MODULE - SYS_RAWIO - SYS_PACCT - SYS_NICE - SYS_TIME - SYS_TTY_CONFIG - SYSLOG - NET_ADMIN hostPID: true volumes: - name: host-root hostPath: path: / restartPolicy: Never
Pod启动后,我进入其shell并执行chroot /hostfs /bin/bash,但运行apt update && apt install -y nfs-common时失败,报错如下:
Ign:1 http://archive.ubuntu.com/ubuntu jammy InRelease Ign:2 http://archive.ubuntu.com/ubuntu jammy-updates InRelease Ign:3 http://archive.ubuntu.com/ubuntu jammy-backports InRelease Ign:4 http://archive.ubuntu.com/ubuntu jammy-security InRelease Ign:1 http://archive.ubuntu.com/ubuntu jammy InRelease Ign:2 http://archive.ubuntu.com/ubuntu jammy-updates InRelease Ign:3 http://archive.ubuntu.com/ubuntu jammy-backports InRelease Ign:4 http://archive.ubuntu.com/ubuntu jammy-security InRelease Ign:1 http://archive.ubuntu.com/ubuntu jammy InRelease Ign:2 http://archive.ubuntu.com/ubuntu jammy-updates InRelease Ign:3 http://archive.ubuntu.com/ubuntu jammy-backports InRelease Ign:4 http://archive.ubuntu.com/ubuntu jammy-security InRelease Err:1 http://archive.ubuntu.com/ubuntu jammy InRelease Temporary failure resolving 'archive.ubuntu.com' Err:2 http://archive.ubuntu.com/ubuntu jammy-updates InRelease Temporary failure resolving 'archive.ubuntu.com' Err:3 http://archive.ubuntu.com/ubuntu jammy-backports InRelease Temporary failure resolving 'archive.ubuntu.com' Err:4 http://archive.ubuntu.com/ubuntu jammy-security InRelease Temporary failure resolving 'archive.ubuntu.com' Reading package lists... Done Building dependency tree... Done Reading state information... Done 29 packages can be upgraded. Run 'apt list --upgradable' to see them.
我认为缺少某种权限,但无法确定具体项,请求协助解决。
解决方案
报错核心是DNS解析失败,并非权限问题。chroot到主机文件系统后,容器的DNS配置未被继承到chroot环境,且容器与主机的网络命名空间独立,导致无法正常解析域名。以下两种方式可解决:
方式一:复制容器DNS配置到主机挂载目录
进入Pod shell后,先执行:
cp /etc/resolv.conf /hostfs/etc/resolv.conf
再执行chroot /hostfs /bin/bash,之后运行apt update即可正常解析域名。
方式二:让Pod直接使用主机网络命名空间
修改Pod的spec,添加hostNetwork: true,让容器直接复用主机的网络与DNS配置,chroot后无需额外配置即可访问网络:
apiVersion: v1 kind: Pod metadata: name: ubuntu-pod spec: hostNetwork: true # 添加此行 containers: - name: ubuntu-container image: ubuntu:24.04 command: ["/bin/bash", "-c", "while true; do sleep 30; done;"] volumeMounts: - name: host-root mountPath: /hostfs securityContext: privileged: true capabilities: add: - SYS_ADMIN - SYS_RESOURCE - SYS_NICE - SYS_PTRACE - SYS_BOOT - SYS_MODULE - SYS_RAWIO - SYS_PACCT - SYS_NICE - SYS_TIME - SYS_TTY_CONFIG - SYSLOG - NET_ADMIN hostPID: true volumes: - name: host-root hostPath: path: / restartPolicy: Never
重新创建Pod后,chroot进去执行apt update && apt install -y nfs-common即可成功。
注:虽已知晓风险,但此类操作会破坏集群节点一致性,后续建议记录节点root密码或采用标准化节点初始化流程规避此类问题。
内容的提问来源于stack exchange,提问作者E. Jaep
相关产品推荐
相关产品推荐

