You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何将Azure存储文件共享挂载到本地集群并创建可用Secret

将Azure文件共享挂载到本地Kubernetes集群并创建对应Secret

一、创建Azure文件共享专用Secret

本地集群没有AKS的Azure集成能力,需手动创建包含存储账户凭据的Secret:

  1. 获取Azure存储账户访问密钥
    用Azure CLI提取密钥(已有密钥可跳过此步):

    az storage account keys list --resource-group <你的资源组名> --account-name <你的存储账户名> --query "[0].value" -o tsv
    
  2. 快速创建Secret
    直接通过kubectl传入明文凭据创建,无需手动做base64编码:

    kubectl create secret generic azure-file-secret \
      --from-literal=azurestorageaccountname=<你的存储账户名> \
      --from-literal=azurestorageaccountkey=<你的存储账户密钥>
    
  3. 验证Secret有效性

    kubectl get secret azure-file-secret -o yaml
    

    确认输出的data字段包含编码后的账户名与密钥即可。

二、挂载Azure文件共享到本地Pod

创建测试Pod的YAML配置(示例文件名azure-file-pod.yaml),将文件共享挂载到Pod内部路径:

apiVersion: v1
kind: Pod
metadata:
  name: azure-file-test-pod
spec:
  containers:
  - name: test-container
    image: nginx
    volumeMounts:
    - name: azure-file-share
      mountPath: /mnt/azurefile
  volumes:
  - name: azure-file-share
    azureFile:
      secretName: azure-file-secret
      shareName: <你的文件共享名>
      readOnly: false  # 需只读挂载可改为true

应用配置并验证:

kubectl apply -f azure-file-pod.yaml
# 检查挂载是否成功
kubectl exec -it azure-file-test-pod -- ls /mnt/azurefile

若能列出文件共享内的内容,说明挂载生效。

关键注意事项

  • 本地集群节点需具备访问Azure存储服务的公网权限(或已配置Azure私有链接)
  • 所有占位符(资源组名、存储账户名等)需替换为你的实际信息
  • 挂载失败时,可通过kubectl describe pod azure-file-test-pod查看事件排查问题

内容的提问来源于stack exchange,提问作者meet soni

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.10 21:07:41