You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kubernetes部署Mongo遇挂载错误:只读文件系统问题求助

解决Mongo Kubernetes部署中resolv.conf挂载只读文件系统错误

核心原因

当Deployment启用了readOnlyRootFilesystem: true时,K8s kubelet自动挂载/etc/resolv.conf的操作会被阻止——因为目标路径所在的根文件系统处于只读状态。

解决方案

选项1:关闭只读根文件系统(最简单)

如果业务场景不需要强制开启只读根文件系统,直接删除Deployment中securityContext下的readOnlyRootFilesystem: true配置,重新部署即可:

spec:
  template:
    spec:
      # 移除以下配置块
      # securityContext:
      #   readOnlyRootFilesystem: true

选项2:保留只读根文件系统,添加临时卷挂载

若必须启用只读根文件系统,需要为/etc/resolv.conf添加emptyDir临时卷,让该路径具备可写权限:

spec:
  template:
    spec:
      securityContext:
        readOnlyRootFilesystem: true
      volumes:
        # 新增临时卷用于承载resolv.conf
        - name: resolv-conf
          emptyDir: {}
        # 你的Mongo数据卷、SSL证书Secret卷保持不变
        - name: mongo-ssl-secrets
          secret:
            secretName: mongo-ssl-secret
      containers:
        - name: mongo
          image: mongo:latest
          volumeMounts:
            # 将临时卷挂载到/etc/resolv.conf
            - name: resolv-conf
              mountPath: /etc/resolv.conf
              subPath: resolv.conf
            # SSL证书挂载配置
            - name: mongo-ssl-secrets
              mountPath: /etc/ssl/mongo
              readOnly: true
          command: ["mongod", "--sslMode", "requireSSL", "--sslPEMKeyFile", "/etc/ssl/mongo/server.pem"]

验证Secret配置正确性

确保SSL证书Secret已正确创建,其中的证书内容为base64编码格式:

apiVersion: v1
kind: Secret
metadata:
  name: mongo-ssl-secret
type: Opaque
data:
  server.pem: <你的PEM文件base64编码内容>

Docker Compose与K8s的差异说明

Docker Compose默认不启用只读根文件系统,因此不会遇到此问题。迁移到K8s时若手动添加了readOnlyRootFilesystem: true,就必须处理resolv.conf的挂载兼容问题。


内容的提问来源于stack exchange,提问作者Onigiri

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.19 22:27:01