You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Mac环境下Minikube中Docker挂载.aws凭证目录失败问题排查

问题:Mac下Minikube作为Docker守护进程时,容器无法访问宿主机AWS凭证文件

背景配置

使用以下Docker Compose配置,期望让容器访问宿主机的~/.aws/credentials:

services:
  run_program:
    image: image:1
    entrypoint: python main.py
    environment:
      - HOME=/home
    volumes:
      - $HOME/.aws:/home/.aws:ro

错误现象

boto3抛出配置文件找不到的错误:

botocore.exceptions.ProfileNotFound: The config profile (default) could not be found

交互式排查结果

通过以下命令启动交互式容器:

docker run -e "HOME=/home" -v $HOME/.aws:/home/.aws -it --entrypoint bash image:1

查看/home/.aws时显示有credentials,但执行cat /home/.aws/credentials提示:

cat: /home/.aws/credentials: Is a directory

且该目录为空。宿主机~/.aws下所有文件均有读取权限,且~/.aws/credentials已配置default配置文件。

Minikube挂载尝试的错误

尝试将宿主机目录挂载到Minikube虚拟机:

minikube mount ~/.aws/:/host/.aws

出现以下错误:

Exiting due to GUEST_MOUNT: mount with cmd /bin/bash -c "sudo mount -t 9p -o dfltgid=$(grep ^docker: /etc/group | cut -d: -f3),dfltuid=$(id -u docker),msize=262144,port=55424,trans=tcp,version=9p2000.L 192.168.64.1 /host/.aws" : /bin/bash -c "sudo mount -t 9p -o dfltgid=$(grep ^docker: /etc/group | cut -d: -f3),dfltuid=$(id -u docker),msize=262144,port=55424,trans=tcp,version=9p2000.L 192.168.64.1 /host/.aws": Process exited with status 32
stdout:

stderr:
mount: /host/.aws: mount(2) system call failed: Connection refused.

解决方案

方案1:启动Minikube时直接挂载宿主机目录

停止当前Minikube实例,通过--mount参数启动并绑定宿主机目录:

minikube stop
minikube start --mount --mount-string "~/.aws:/host/.aws"

然后修改Docker Compose的volumes配置,指向Minikube内的挂载路径:

volumes:
  - /host/.aws:/home/.aws:ro

方案2:将宿主机AWS凭证复制到Minikube虚拟机

直接把宿主机的AWS凭证文件复制到Minikube虚拟机的对应目录:

minikube cp ~/.aws/credentials minikube:/home/docker/.aws/credentials
minikube cp ~/.aws/config minikube:/home/docker/.aws/config

之后保持原Docker Compose配置不变,容器即可访问到凭证文件。

方案3:调整Minikube挂载参数解决连接拒绝问题

如果坚持使用minikube mount命令,可指定UID/GID并检查网络连通性:

# 先在Minikube内创建挂载目录并设置权限
minikube ssh "sudo mkdir -p /host/.aws && sudo chown docker:docker /host/.aws"
# 执行挂载命令,指定UID和GID为Minikube内docker用户的ID
minikube mount ~/.aws:/host/.aws --uid 1000 --gid 1000

执行后保持终端窗口打开(挂载为前台进程),再启动Docker Compose容器。


内容的提问来源于stack exchange,提问作者Amuoeba

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.05 09:35:33