在AKS集群中实现外部Pod执行Notebook Pod内Python脚本的方法
To automate running your Python script inside the my-notebook-deployment Pod, you can create a Kubernetes Job (purpose-built for one-time, batch tasks) that uses kubectl to execute the script in your target Pod. Here's a step-by-step implementation:
1. Set Up RBAC Permissions
First, we need to grant the Job's service account permission to run commands in the spark namespace.
Create a Service Account
Save this as spark-executor-sa.yaml:
apiVersion: v1 kind: ServiceAccount metadata: name: spark-script-executor namespace: spark
Create a Role with Exec Permissions
Save this as pod-exec-role.yaml:
apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: name: pod-exec-role namespace: spark rules: - apiGroups: [""] resources: ["pods", "pods/exec"] verbs: ["get", "list", "create"]
Bind the Role to the Service Account
Save this as spark-executor-rolebinding.yaml:
apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata: name: spark-script-executor-binding namespace: spark subjects: - kind: ServiceAccount name: spark-script-executor namespace: spark roleRef: kind: Role name: pod-exec-role apiGroup: rbac.authorization.k8s.io
Apply these resources with:
kubectl apply -f spark-executor-sa.yaml -f pod-exec-role.yaml -f spark-executor-rolebinding.yaml
2. Create the Execution Job
This Job will run a container with kubectl pre-installed, execute your script in the target Pod, and exit once complete. We use a label selector (-l app=my-notebook) instead of hardcoding the Pod name to handle Pod restarts or deployment rollouts automatically.
Save this as spark-script-job.yaml:
apiVersion: batch/v1 kind: Job metadata: name: spark-script-job namespace: spark spec: template: spec: serviceAccountName: spark-script-executor containers: - name: kubectl-runner image: k8s.gcr.io/kubectl:latest command: ["/bin/sh", "-c"] args: - kubectl exec -n spark -l app=my-notebook --container my-notebook -- python3 myscript.py restartPolicy: OnFailure backoffLimit: 3 # Retry up to 3 times if the command fails
Apply the Job with:
kubectl apply -f spark-script-job.yaml
3. Monitor the Job
Check if the Job is running or completed:
kubectl get jobs -n spark
View logs to confirm the script executed successfully:
kubectl logs -n spark $(kubectl get pods -n spark -l job-name=spark-script-job -o name)
Key Notes
- Resilience: Using the label selector (
app=my-notebook) ensures the Job targets any active Pod from your deployment, even if the Pod name changes after a rollout or restart. - Cleanup: Once the Job completes successfully, you can delete it with
kubectl delete job spark-script-job -n spark. - Customization: Adjust the
backoffLimitfor more/fewer retries, or modify the command in the Job to pass arguments to your script if needed.
内容的提问来源于stack exchange,提问作者J.C Guzman

