Azure容器挂载Azure文件共享异常:仅存储账户公网访问开启时可用
问题背景
我有一个运行Nginx的Azure Docker容器,原本已成功将Azure文件共享挂载为卷。但在将存储账户的网络设置改为允许从选定虚拟网络和IP地址访问后,容器启动时出现Host is down错误,无法正常挂载该卷。
已配置/尝试的操作
- 已将容器IP地址添加至存储账户的允许IP列表
- 通过
az container create --resource-group xxxx --f file.yaml命令创建容器,卷配置如下:
volumeMounts: - mountPath: /etc/nginx/conf name: myvolname volumes: - name: myvolname azureFile: sharename: mysharename storageAccountName: myaccountname storageAccountKey: myaccountkey
- 已为容器创建系统分配身份,并通过访问控制为其赋予存储账户的相关角色
- 尝试将存储账户防火墙允许地址设为
0.0.0.0/0,并为系统分配身份赋予Owner角色,问题仍未解决
错误日志
当存储账户公网访问受限时,执行yaml创建容器时出现以下错误:
"Error: Failed to start container mycontainer, Error response: to
create containerd task: failed to create shim task: failed to create
container xxxx: guest RPC failure: failed to create container: failed
to run runc create/exec call for container xxxxx with exit status 1:
container_linux.go:380: starting container process caused:
process_linux.go:545: container init caused: rootfs_linux.go:76:
mounting
"/run/gcs/c/xxxx/sandboxMounts/tmp/atlas/azureFileVolume/caas-xxxx/myshare/mnt"
to rootfs at "/etc/nginx/conf" caused: stat
/run/gcs/c/xxxxx/sandboxMounts/tmp/atlas/azureFileVolume/caas-xxxx/myshare/mnt:
host is down: unknown",
"name": "Failed",
"type": "Warning"
额外验证信息
- 存储账户公网访问开启时,容器内执行
az storage share list可正常列出共享;改为受限模式时出现授权错误,确认存在权限问题 - 已验证容器IP在存储账户的允许IP列表内,且系统分配身份已获多项权限
疑问
- 为实现文件共享的基础访问,需为容器的系统分配身份分配哪些具体角色?
- 为何即使设置允许所有IP(0.0.0.0/0)并赋予Owner角色,仍无法挂载卷,仅当公网访问完全开启时才可正常挂载?
内容的提问来源于stack exchange,提问作者ibeme99

