You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AKS中PV已绑定但Pod无法挂载Azure文件共享求助

AKS集群PV/PVC绑定成功但Azure文件共享挂载失败排查

我在部署Pod并挂载Azure文件共享时,PV与PVC已成功绑定,但容器始终无法完成挂载,请求协助解决。


创建Secret命令

kubectl create secret generic azstorage-secret --from-literal=azurestorageaccountname=$AKS_PERS_STORAGE_ACCOUNT_NAME --from-literal=azurestorageaccountkey=$STORAGE_KEY -n large-agents

StatefulSet配置

apiVersion: apps/v1
kind: StatefulSet
metadata:
  name: linuxbuildagent-large 
  namespace: agents-large
spec:
  replicas: 3
  serviceName: "azdevops-agent-sv"
  selector:
    matchLabels:
      app: azdevops-agent
  template:
    metadata:
      labels:
        app: azdevops-agent
    spec:
      containers:
        - name: selfhosted-agents
          ...
          volumeMounts:
          - name: azurefileshare
            mountPath: /angular-cache  
          securityContext:
            privileged: true  
      volumes:
      - name: azurefileshare
        persistentVolumeClaim:
          claimName: pvc-azurefile

Persistent Volume配置

apiVersion: v1
kind: PersistentVolume
metadata:
  name: pv-azurefile
  namespace: agents-large
spec:
  capacity:
    storage: 10Gi
  accessModes:
    - ReadWriteMany
  persistentVolumeReclaimPolicy: Retain  # 若设置为"Delete",PVC删除时文件共享会被移除
  storageClassName: azurefile-csi
  csi:
    driver: file.csi.azure.com
    readOnly: false
    volumeHandle: azureBuildClient  # 确保此volumeid在集群中唯一
    volumeAttributes:
      storageAccount: EXISTING_STORAGE_ACCOUNT_NAME
      shareName: longtestshare
    nodeStageSecretRef:
      name: azstorage-secret
      namespace: agents-large

Persistent Volume Claim配置

apiVersion: v1
kind: PersistentVolumeClaim
metadata:
  name: pvc-azurefile
  namespace: agents-large
spec:
  accessModes:
    - ReadWriteMany
  storageClassName: azurefile-csi
  volumeName: pv-azurefile
  resources:
    requests:
      storage: 10Gi

当前状态与错误事件

AKS集群中PV与PVC已成功绑定。

Pod描述中的事件

node.kubernetes.io/unreachable:NoExecute op=Exists for 300s
Events:
  Type     Reason       Age                 From     Message
  ----     ------       ----                ----     -------
  Warning  FailedMount  38m (x19 over 88m)  kubelet  Unable to attach or mount volumes: unmounted volumes=[azurefileshare], unattached volumes=[docker-graph-storage azurefileshare kube-api-access-cx6tn]: timed out waiting for the condition
  Warning  FailedMount  24m (x6 over 66m)   kubelet  MountVolume.MountDevice failed for volume "pv-azurefile" : rpc error: code = Internal desc = volume(azureBuildClient) mount //crbbroakspersistentstg.file.core.windows.net/longtestshare on /var/lib/kubelet/plugins/kubernetes.io/csi/pv/pv-azurefile/globalmount failed with mount failed: exit status 32
Mounting command: mount
Mounting arguments: -t cifs -o dir_mode=0777,actimeo=30,mfsymlinks,file_mode=0777,<masked> //crbbroakspersistentstg.file.core.windows.net/longtestshare /var/lib/kubelet/plugins/kubernetes.io/csi/pv/pv-azurefile/globalmount
Output: mount error(2): No such file or directory
Refer to the mount.cifs(8) manual page (e.g. man mount.cifs) and kernel log messages (dmesg)
  Warning  FailedMount  20m (x5 over 86m)    kubelet  Unable to attach or mount volumes: unmounted volumes=[azurefileshare], unattached volumes=[azurefileshare kube-api-access-cx6tn docker-graph-storage]: timed out waiting for the condition
  Warning  FailedMount  5m3s (x31 over 90m)  kubelet  MountVolume.MountDevice failed for volume "pv-azurefile" : rpc error: code = Internal desc = volume(azureBuildClient) mount //crbbroakspersistentstg.file.core.windows.net/longtestshare on /var/lib/kubelet/plugins/kubernetes.io/csi/pv/pv-azurefile/globalmount failed with mount failed: exit status 32
Mounting command: mount
Mounting arguments: -t cifs -o file_mode=0777,dir_mode=0777,actimeo=30,mfsymlinks,<masked> //crbbroakspersistentstg.file.core.windows.net/longtestshare /var/lib/kubelet/plugins/kubernetes.io/csi/pv/pv-azurefile/globalmount
Output: mount error(2): No such file or directory
Refer to the mount.cifs(8) manual page (e.g. man mount.cifs) and kernel log messages (dmesg)

命名空间中的kubectl事件

28m         Warning   FailedMount   pod/linuxbuildagent-large-0   MountVolume.MountDevice failed for volume "pv-azurefile" : rpc error: code = Internal desc = volume(azureBuildClient) mount //crbbroakspersistentstg.file.core.windows.net/longtestshare on /var/lib/kubelet/plugins/kubernetes.io/csi/pv/pv-azurefile/globalmount failed with mount failed: exit status 32...
2m46s       Warning   FailedMount   pod/linuxbuildagent-large-0   Unable to attach or mount volumes: unmounted volumes=[azurefileshare], unattached volumes=[docker-graph-storage azurefileshare kube-api-access-cx6tn]: timed out waiting for the condition
13m         Warning   FailedMount   pod/linuxbuildagent-large-0   MountVolume.MountDevice failed for volume "pv-azurefile" : rpc error: code = Internal desc = volume(azureBuildClient) mount //crbbroakspersistentstg.file.core.windows.net/longtestshare on /var/lib/kubelet/plugins/kubernetes.io/csi/pv/pv-azurefile/globalmount failed with mount failed: exit status 32...
7m19s       Warning   FailedMount   pod/linuxbuildagent-large-0   Unable to attach or mount volumes: unmounted volumes=[azurefileshare], unattached volumes=[azurefileshare kube-api-access-cx6tn docker-graph-storage]: timed out waiting for the condition

排查与解决方案

从错误信息mount error(2): No such file or directory来看,核心问题是节点无法找到目标Azure文件共享或存储账户,按以下步骤排查:

  1. 修正存储账户名配置
    PV配置中volumeAttributes.storageAccount字段填写的是占位符EXISTING_STORAGE_ACCOUNT_NAME,需替换为实际的存储账户名crbbroakspersistentstg,重新应用PV配置:

    kubectl apply -f pv-azurefile.yaml
    
  2. 对齐Secret的命名空间
    当前Secret创建在large-agents命名空间,但PV/PVC使用的是agents-large命名空间,需在目标命名空间重新创建Secret:

    kubectl create secret generic azstorage-secret --from-literal=azurestorageaccountname=crbbroakspersistentstg --from-literal=azurestorageaccountkey=$STORAGE_KEY -n agents-large
    

    验证Secret内容正确性:

    kubectl get secret azstorage-secret -n agents-large -o jsonpath='{.data.azurestorageaccountname}' | base64 -d
    kubectl get secret azstorage-secret -n agents-large -o jsonpath='{.data.azurestorageaccountkey}' | base64 -d
    
  3. 验证存储资源存在性
    登录Azure门户确认:

    • 存储账户crbbroakspersistentstg已存在
    • 文件共享longtestshare已在该存储账户下创建
  4. 测试节点网络连通性
    在AKS节点上手动执行挂载命令,测试是否能连接到文件共享:

    mount -t cifs //crbbroakspersistentstg.file.core.windows.net/longtestshare /tmp/testmount -o username=crbbroakspersistentstg,password=$STORAGE_KEY,dir_mode=0777,file_mode=0777
    

    若挂载失败,检查节点NSG规则、存储账户防火墙是否允许445端口访问,AKS集群是否配置了存储服务端点或私有链接。

  5. 确认CSI驱动状态
    检查Azure File CSI驱动是否正常运行:

    kubectl get pods -n kube-system -l app=azurefile-csi-controller
    kubectl get pods -n kube-system -l app=azurefile-csi-node
    

    若驱动未部署,按Azure官方文档完成安装。


内容的提问来源于stack exchange,提问作者lbpoundz

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.08 09:05:16