在Argo-Workflows中使用K6镜像时无法写入挂载卷
解决Argo Workflows中K6写入挂载卷的权限拒绝问题
问题原因
Grafana K6官方镜像默认以UID 1000的非root用户运行,而Argo Workflows创建的PVC挂载到容器后,目录默认属于root用户,导致K6进程没有写入权限,触发permission denied错误。
解决方案
方案1:以root用户运行K6步骤
在Argo的Workflow模板中,通过securityContext指定K6步骤以root用户(UID 0)运行,直接获取目录写入权限。
修改run-load-test模板,添加securityContext配置:
- name: run-load-test script: volumeMounts: - name: workdir mountPath: /mnt/app image: grafana/k6:latest command: ["k6"] args: ["run"] # 添加以下securityContext配置 securityContext: runAsUser: 0 runAsGroup: 0 source: | # 原K6脚本内容保持不变 import http from "k6/http"; import { sleep } from "k6"; export const options = { vus: 10, duration: "3s", }; export default function () { http.get("http://test.k6.io"); sleep(1); } export function handleSummary(data) { return { "/mnt/app/summary.json": JSON.stringify(data.metrics.iteration_duration.values), }; }
方案2:提前设置挂载目录权限(最小权限原则)
先通过一个初始化步骤修改挂载目录的所有者为K6默认用户(UID 1000),避免使用root用户,符合安全最佳实践。
修改Workflow的main步骤,增加一个prepare-workdir前置步骤:
- name: main steps: - - name: prepare-workdir template: prepare-workdir - - name: run-load-test template: run-load-test - - name: print-results template: print-results # 新增prepare-workdir模板 - name: prepare-workdir script: volumeMounts: - name: workdir mountPath: /mnt/app image: busybox command: [sh] source: | chown 1000:1000 /mnt/app
方案3:使用InitContainer预处理目录权限
在run-load-test模板中添加initContainers,让初始化容器提前修改目录权限,无需额外步骤:
- name: run-load-test script: volumeMounts: - name: workdir mountPath: /mnt/app # 添加InitContainer预处理权限 initContainers: - name: prepare-dir image: busybox command: ["chown", "1000:1000", "/mnt/app"] volumeMounts: - name: workdir mountPath: /mnt/app image: grafana/k6:latest command: ["k6"] args: ["run"] source: | # 原K6脚本内容保持不变 import http from "k6/http"; import { sleep } from "k6"; export const options = { vus: 10, duration: "3s", }; export default function () { http.get("http://test.k6.io"); sleep(1); } export function handleSummary(data) { return { "/mnt/app/summary.json": JSON.stringify(data.metrics.iteration_duration.values), }; }
完整可运行Workflow示例(方案1)
apiVersion: argoproj.io/v1alpha1 kind: Workflow metadata: generateName: permission-denied-for-k6-image- spec: volumeClaimTemplates: - metadata: name: workdir spec: accessModes: [ "ReadWriteOnce" ] resources: requests: storage: 1Gi entrypoint: main templates: - name: main steps: - - name: run-load-test template: run-load-test - - name: print-results template: print-results - name: run-load-test script: volumeMounts: - name: workdir mountPath: /mnt/app image: grafana/k6:latest command: ["k6"] args: ["run"] securityContext: runAsUser: 0 runAsGroup: 0 source: | import http from "k6/http"; import { sleep } from "k6"; export const options = { vus: 10, duration: "3s", }; export default function () { http.get("http://test.k6.io"); sleep(1); } export function handleSummary(data) { return { "/mnt/app/summary.json": JSON.stringify(data.metrics.iteration_duration.values), }; } - name: print-results script: volumeMounts: - name: workdir mountPath: /mnt/app image: busybox command: [sh] source: | ls -l /mnt/app/ volumes: - name: shared-volume emptyDir: {}
内容的提问来源于stack exchange,提问作者Alechko
相关产品推荐
相关产品推荐

