You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

OpenShift Exec命令式存活探针无报错但未按预期工作求助

OpenShift Exec存活探针失效问题解决

问题现象

配置的Exec命令式存活探针始终判定为成功状态,未触发预期的容器重启。该探针旨在检查证书剩余过期天数,当满足条件时(脚本中为剩余天数>25天)应返回失败,但单独运行脚本时逻辑正常,配置为探针后失效。探针配置如下:

livenessProbe:
    exec:
      command:
      - /bin/sh
      - -c
      - |-
        cutoff_days=25;
        end_date=$(keytool -printcert -file /ama/conf_external/secret/tls.crt|grep "until:"|head -1|sed -n -e 's/^.*until: //p');
        end_epoch=$(date +%s -d "$end_date");
        epoch_now=$(date +%s);
        seconds_to_expire=`expr $end_epoch - $epoch_now`;
        days_to_expire=`expr $seconds_to_expire / 86400`;
        if [ ${days_to_expire} -gt ${cutoff_days} ]; then exit 1; fi

可能原因及修复方案

1. 逻辑方向错误(最可能)

从常规业务逻辑看,通常是证书剩余过期天数小于等于阈值时触发重启,但当前脚本逻辑是剩余天数>25天时返回失败(exit 1),这与常规需求相悖。如果你的真实需求是证书快过期(剩余≤25天)时重启容器,需将条件改为:

if [ ${days_to_expire} -le ${cutoff_days} ]; then exit 1; fi

2. Shell脚本兼容性问题

容器内的sh可能是dash而非bash,部分语法或命令行为有差异:

  • 替换expr为更兼容的算术表达式:
    seconds_to_expire=$(( end_epoch - epoch_now ))
    days_to_expire=$(( seconds_to_expire / 86400 ))
    
  • 确保date命令支持-d参数:部分轻量镜像(如alpine)的date是busybox版本,需根据keytool输出的日期格式调整,比如:
    end_epoch=$(date -D "%b %d %H:%M:%S %Y %Z" +%s -d "$end_date")
    

3. Keytool输出解析问题

keytool的until:字段格式可能因JDK版本、系统 locale不同而变化,导致sed无法正确提取日期。可改用更可靠的提取方式:

end_date=$(keytool -printcert -file /ama/conf_external/secret/tls.crt | awk '/until:/{sub(/.*until: /,"",$0);print;exit}')

4. 探针执行环境权限问题

确保容器内进程有权限读取/ama/conf_external/secret/tls.crt文件,可在脚本开头添加权限检查:

if [ ! -r /ama/conf_external/secret/tls.crt ]; then exit 1; fi

5. 探针配置补充优化

建议添加探针的超时、周期等参数,避免因脚本执行超时被误判:

livenessProbe:
    exec:
      command:
      - /bin/sh
      - -c
      - |-
        cutoff_days=25;
        if [ ! -r /ama/conf_external/secret/tls.crt ]; then exit 1; fi
        end_date=$(keytool -printcert -file /ama/conf_external/secret/tls.crt | awk '/until:/{sub(/.*until: /,"",$0);print;exit}');
        end_epoch=$(date +%s -d "$end_date");
        epoch_now=$(date +%s);
        seconds_to_expire=$(( end_epoch - epoch_now ));
        days_to_expire=$(( seconds_to_expire / 86400 ));
        if [ ${days_to_expire} -le ${cutoff_days} ]; then exit 1; fi
    initialDelaySeconds: 30
    periodSeconds: 3600  # 每小时检查一次即可
    timeoutSeconds: 10

内容的提问来源于stack exchange,提问作者DevOps_Enthusiast

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.20 23:15:45