You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kubernetes重新部署时CIFS卷挂载失败的自动挂载方案咨询

Kubernetes Deployment CIFS挂载问题解决方案

问题根源分析

首次部署时CIFS卷挂载正常,但重新部署后挂载失效,核心原因通常是:

  • 容器重启后,手动建立的挂载点会被清空,且无自动触发的重新挂载逻辑
  • 若未使用Kubernetes原生卷挂载机制,Deployment滚动更新时,Pod初始化流程未包含挂载操作

推荐方案:使用Kubernetes原生CIFS卷挂载

优先采用Kubernetes原生CIFS CSI驱动实现自动挂载,彻底解决重新部署挂载失效问题,无需手动执行命令。

步骤1:创建存储凭据的Secret

将CIFS用户名密码存入Secret,避免硬编码泄露:

kubectl create secret generic cifs-creds --from-literal=username=${BUILD_USER} --from-literal=password=${BUILD_USER_PASSWORD}

步骤2:修改Deployment配置

在Deployment中配置CIFS卷和挂载规则:

apiVersion: apps/v1
kind: Deployment
metadata:
  name: your-deployment-name
spec:
  replicas: 1
  selector:
    matchLabels:
      app: your-app-label
  template:
    metadata:
      labels:
        app: your-app-label
    spec:
      volumes:
        - name: cifs-shared-volume
          csi:
            driver: cifs.csi.k8s.io
            volumeAttributes:
              source: "<你的网络驱动器路径>"
              mountOptions: "vers=3.0,sec=ntlmv2,uid=0,gid=0,file_mode=0664,dir_mode=0775"
            nodePublishSecretRef:
              name: cifs-creds # 关联之前创建的凭据Secret
      containers:
        - name: your-container-name
          image: your-image:tag
          volumeMounts:
            - name: cifs-shared-volume
              mountPath: "<容器内的目标目录>"

配置完成后,Kubernetes会在Pod启动(包括重新部署、滚动更新)时自动完成CIFS卷挂载,无需任何手动操作。

备选方案:通过启动命令自动执行挂载

如果无法使用原生CSI驱动,可通过容器启动命令自动执行挂载操作,同时保证主进程正常运行。

直接在Deployment中配置command/args

假设容器主进程为/usr/bin/your-main-process,配置如下:

apiVersion: apps/v1
kind: Deployment
metadata:
  name: your-deployment-name
spec:
  replicas: 1
  selector:
    matchLabels:
      app: your-app-label
  template:
    metadata:
      labels:
        app: your-app-label
    spec:
      containers:
        - name: your-container-name
          image: your-image:tag
          env:
            - name: BUILD_USER
              valueFrom:
                secretKeyRef:
                  name: cifs-creds
                  key: username
            - name: BUILD_USER_PASSWORD
              valueFrom:
                secretKeyRef:
                  name: cifs-creds
                  key: password
          command: ["/bin/sh", "-c"]
          args:
            - |
              # 执行CIFS挂载命令
              mount -t cifs "<你的网络驱动器路径>" "<容器内的目标目录>" -o username=${BUILD_USER},password=${BUILD_USER_PASSWORD},vers=3.0,sec=ntlmv2,uid=0,gid=0,file_mode=0664,dir_mode=0775;
              # 启动主进程,用exec保证主进程为PID 1,避免Pod异常退出
              exec /usr/bin/your-main-process
          securityContext:
            privileged: true # mount操作需要容器拥有特权权限

关键注意事项

  • 必须开启privileged: true,否则容器无权限执行mount系统调用
  • 用户名密码务必通过Secret注入,禁止硬编码在配置文件中
  • 用exec启动主进程,确保主进程成为容器的PID 1,保证Pod持续运行

排查建议

如果采用原生挂载仍出现问题,可通过以下方式定位:

  • 查看Pod事件:kubectl describe pod <pod-name>,检查挂载阶段是否有错误日志
  • 查看CIFS服务器日志,确认是否存在连接拒绝或权限验证问题
  • 检查节点上的CIFS客户端版本,确保与服务器版本兼容

内容的提问来源于stack exchange,提问作者Rebit

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.24 02:57:46