Argo Workflows报psp-readonlyrootfilesystem错误,如何解决?
问题
配置了带有securityContext的Argo Workflow后运行出现ReadOnlyRootFileSystem错误,请问是否是securityContext位置错误或遗漏配置?该如何修复?
Workflow YAML配置:
apiVersion: argoproj.io/v1alpha1 kind: Workflow metadata: generateName: hello-world- spec: entrypoint: whalesay templates: - name: whalesay container: image: docker/whalesay:latest command: [cowsay] args: ["hello world"] securityContext: readOnlyRootFilesystem: true
报错信息:
Warning WorkflowNodeError 17s workflow-controller Error node hello-world-tcdbg: admission webhook "validation.gatekeeper.sh" denied the request: [psp-readonlyrootfilesystem] only read-only root filesystem container is allowed: wait [psp-readonlyrootfilesystem] only read-only root filesystem container is allowed: init
解决方案
- 问题根源:你仅为业务容器配置了只读根文件系统,但Argo Workflow运行时会自动创建
init初始化容器和wait等待容器,这两个容器未继承你设置的securityContext,违反了PSP(Pod安全策略)要求所有容器必须使用只读根文件系统的规则。 - 修复方式:在Workflow的
spec层级配置全局securityContext,让所有容器(业务容器、init容器、wait容器)统一应用只读根文件系统设置;或者在模板层级配置securityContext,作用于该模板下的所有容器。
修改后的配置示例1(全局配置)
apiVersion: argoproj.io/v1alpha1 kind: Workflow metadata: generateName: hello-world- spec: entrypoint: whalesay # 全局配置,所有容器自动继承该securityContext securityContext: readOnlyRootFilesystem: true templates: - name: whalesay container: image: docker/whalesay:latest command: [cowsay] args: ["hello world"] # 若需给业务容器单独配置,可保留此处securityContext,会覆盖全局设置 # securityContext: # readOnlyRootFilesystem: true
修改后的配置示例2(模板层级配置)
apiVersion: argoproj.io/v1alpha1 kind: Workflow metadata: generateName: hello-world- spec: entrypoint: whalesay templates: - name: whalesay # 模板层级配置,该模板下的所有容器都会继承 securityContext: readOnlyRootFilesystem: true container: image: docker/whalesay:latest command: [cowsay] args: ["hello world"]
内容的提问来源于stack exchange,提问作者Karamchand
相关产品推荐
相关产品推荐

