You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GKE集群中Istio Sidecar部署NFS-server挂载失败求助

问题描述

在GKE集群中部署NFS-server时,添加Istio Sidecar代理容器后出现磁盘挂载失败,日志仅显示:

Mount system call failed

移除Sidecar后,NFS磁盘挂载一切正常。需配置Istio以允许内部访问NFS-server服务,相关配置如下:

apiVersion: apps/v1
kind: Deployment
metadata:
  name: nfs-server
spec:
  replicas: 1
  selector:
    matchLabels:
      role: nfs-server
  template:
    metadata:
      labels:
        role: nfs-server
      containers:
      - name: nfs-server
        image: gcr.io/google_containers/volume-nfs:0.8
        ports:
          - name: nfs
            containerPort: 2049
          - name: mountd
            containerPort: 20048
          - name: rpcbind
            containerPort: 111
        securityContext:
          privileged: true
        volumeMounts:
          - mountPath: /exports
            name: nfs-pvc
      volumes:
        - name: nfs-pvc
          gcePersistentDisk:
            pdName: storage-nfs
            fsType: ext4
---
apiVersion: v1
kind: Service
metadata:
  name: nfs-server
spec:
  ports:
    - name: nfs
      port: 2049
    - name: mountd
      port: 20048
    - name: rpcbind
      port: 111
  selector:
    role: nfs-server
---
apiVersion: v1
kind: PersistentVolume
metadata:
  name: nfs-pv-1
spec:
  capacity:
    storage: 1Gi
  accessModes:
    - ReadWriteMany
  nfs:
    server: nfs-server.default.svc.cluster.local
    path: "/"

---
kind: PersistentVolumeClaim
apiVersion: v1
metadata:
  name: nfs-pvc-1
spec:
  accessModes:
    - ReadWriteMany
  storageClassName: ""
  resources:
    requests:
      storage: 1Gi
---
apiVersion: extensions/v1beta1
kind: Deployment
metadata:
  name: nfs-pv-demo-depl
spec:
  replicas: 1
  selector:
    matchLabels:
      app: nfs-pv-demo
  template:
    metadata:
      name: nfs-pv-pod
      labels:
        app: nfs-pv-demo
    spec:
      containers:
      - image: busybox
        name: nfs-pv-multi
        imagePullPolicy: Always
        name: busybox
        volumeMounts:
          # name should match from volumes section
          - name: nfs-volume-1
            mountPath: "/disk1"
      volumes:
      - name: nfs-volume-1
        persistentVolumeClaim:
          claimName: nfs-pvc
解决方案

1. 豁免NFS-server Pod的Sidecar注入

NFS挂载操作需要直接访问Pod网络栈,Istio Sidecar的流量拦截会干扰这一过程。给NFS-server的Deployment添加注解,跳过Sidecar注入:

metadata:
  name: nfs-server
  annotations:
    sidecar.istio.io/inject: "false"

2. 配置Istio放行NFS相关端口流量(若需保留Sidecar)

如果必须保留Sidecar,创建Istio规则放行NFS依赖的端口(111、2049、20048):

ServiceEntry配置

apiVersion: networking.istio.io/v1alpha3
kind: ServiceEntry
metadata:
  name: nfs-server-entry
spec:
  hosts:
  - nfs-server.default.svc.cluster.local
  ports:
  - number: 111
    name: tcp-rpcbind
    protocol: TCP
  - number: 2049
    name: tcp-nfs
    protocol: TCP
  - number: 20048
    name: tcp-mountd
    protocol: TCP
  resolution: DNS
  location: MESH_INTERNAL

DestinationRule配置

apiVersion: networking.istio.io/v1alpha3
kind: DestinationRule
metadata:
  name: nfs-server-dr
spec:
  host: nfs-server.default.svc.cluster.local
  trafficPolicy:
    tls:
      mode: DISABLE

3. 强化NFS-server Pod的权限

Istio Sidecar可能限制挂载操作,给NFS-server Pod添加更高权限:

securityContext:
  privileged: true
  capabilities:
    add: ["SYS_ADMIN"]

4. 验证配置

应用配置后,重新部署组件并检查挂载状态:

kubectl apply -f nfs-server-deployment.yaml
kubectl apply -f istio-nfs-config.yaml
kubectl exec -it <nfs-pv-demo-pod-name> -- mount | grep /disk1

内容的提问来源于stack exchange,提问作者Dominik

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.01 12:50:10