K8s中如何正确挂载PVC已存在的指定子目录?
Let's break down what's causing your empty mount issue and fix it step by step:
Key Issues in Your Current Setup
Git-sync isn't writing files to the PVC
Your git-sync container is syncing files to its default root directory/tmp/git, but your PVC is mounted at/config. These are separate paths, so the synced files never make it into the PVC at all. That's why your second pod sees an empty directory.PVC name mismatch
Your first Deployment references a PVC namedcus-config, but your actual PVC is namedconfig. This means the first pod isn't even mounting the correct PVC.Incorrect subPath in the second Deployment
Even if files were in the PVC, your subPathtmp/git/conf/subdirApoints to a location that doesn't exist in the PVC (since git-sync wasn't writing there).Outdated PVC storage class annotation
You're using the beta annotationvolume.beta.kubernetes.io/storage-class; for modern Kubernetes versions, you should use thestorageClassNamefield in the PVC spec instead.
Corrected Configurations
1. Fixed Git-sync Deployment
We'll update git-sync to write directly to the PVC-mounted directory by setting the -root flag to /config, and fix the PVC claim name:
kind: Deployment metadata: name: config namespace: test spec: replicas: 1 selector: matchLabels: demo: config template: metadata: labels: demo: config spec: containers: - args: - '-ssh' - '-repo=git@domain.com:org/repo.git' - '-dest=conf' - '-branch=master' - '-depth=1' - '-root=/config' # Add this to point git-sync's root to the PVC mount image: 'k8s.gcr.io/git-sync:v3.1.1' name: git-sync securityContext: runAsUser: 65533 volumeMounts: - mountPath: /etc/git-secret name: git-secret readOnly: true - mountPath: /config name: cus-config securityContext: fsGroup: 65533 volumes: - name: git-secret secret: defaultMode: 256 secretName: git-creds - name: cus-config persistentVolumeClaim: claimName: config # Fix to match your actual PVC name
2. Updated PVC Configuration
Replace the beta annotation with the standard storageClassName field, and remove the namespace from the StorageClass (they're cluster-scoped resources):
kind: PersistentVolumeClaim metadata: name: config namespace: test spec: accessModes: - ReadWriteMany storageClassName: conf # Use this instead of the beta annotation resources: requests: storage: 10Mi --- apiVersion: storage.k8s.io/v1 kind: StorageClass metadata: name: conf provisioner: spdbyz reclaimPolicy: Retain
3. Fixed Second Deployment
Update the subPath to point to the correct location in the PVC (now conf/subdirA since git-sync writes to /config/conf):
kind: Deployment metadata: name: test-mount-config namespace: test spec: replicas: 1 selector: matchLabels: app: nginx template: metadata: labels: app: nginx spec: containers: - image: 'nginx:1.7.9' name: nginx ports: - containerPort: 80 volumeMounts: - mountPath: /root/conf name: config subPath: conf/subdirA # Corrected subPath volumes: - name: config persistentVolumeClaim: claimName: config
Verification Steps
- Deploy the corrected git-sync Deployment:
kubectl apply -f git-sync-deployment.yaml -n test - Check if files are written to the PVC:
You should see yourkubectl exec -it <git-sync-pod-name> -n test -- ls /config/conf/subdirAsome.Fileshere. - Deploy the second Deployment:
kubectl apply -f nginx-deployment.yaml -n test - Verify the mount in the nginx pod:
You should now see the synced files fromkubectl exec -it <nginx-pod-name> -n test -- ls /root/confsubdirA.
Additional Notes
- Ensure your StorageClass's provisioner (
spdbyz) supports ReadWriteMany access mode, as both pods need to access the PVC simultaneously. - Double-check the git-sync security context settings (
runAsUserandfsGroup) to make sure the container has permission to write to the PVC directory.
内容的提问来源于stack exchange,提问作者Spadaboyz

