You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

关于在K8s同一Pod双容器中跨容器使用Helm配置的可行性咨询

可行方案:在多容器Pod中共享Helm配置完成Chart部署

完全可以实现你的需求,核心思路是通过共享存储卷让两个容器复用Helm的配置文件,具体实现步骤如下:

1. 配置Pod内的共享存储

在Pod定义中添加一个emptyDir类型的存储卷(如果需要持久化可替换为PVC),将其挂载到两个容器的Helm配置目录(Helm3默认路径为/root/.config/helm,Helm2为/root/.helm),同时确保K8s集群访问配置(kubeconfig)能被两个容器共享:

apiVersion: v1
kind: Pod
metadata:
  name: helm-deploy-pod
spec:
  volumes:
  - name: helm-config
    emptyDir: {}
  containers:
  - name: helm-init-container
    image: alpine/helm:3.12.0
    command: ["sh", "-c"]
    args:
    - |
      # 初始化Helm配置:添加仓库、更新索引
      helm repo add stable https://charts.helm.sh/stable
      helm repo update
      # 保持容器运行(可选,方便调试)
      sleep infinity
    volumeMounts:
    - name: helm-config
      mountPath: /root/.config/helm
    # 挂载Pod默认的service account配置,用于访问K8s集群
    - name: kube-api-access
      mountPath: /var/run/secrets/kubernetes.io/serviceaccount
  - name: helm-deploy-container
    image: alpine/helm:3.12.0
    command: ["sh", "-c"]
    args:
    - |
      # 直接使用共享的Helm配置部署Chart
      helm install my-nginx stable/nginx-ingress --namespace default
      sleep infinity
    volumeMounts:
    - name: helm-config
      mountPath: /root/.config/helm
    - name: kube-api-access
      mountPath: /var/run/secrets/kubernetes.io/serviceaccount

2. 关键注意事项

  • Helm版本差异:Helm3已移除Tiller服务端,仅需客户端即可直接与K8s API交互,推荐使用Helm3简化架构;若使用Helm2,需在第一个容器部署Tiller服务端。
  • 权限一致性:确保两个容器的运行用户对共享存储卷有读写权限,避免出现配置文件无法读取的问题。
  • Service Account权限:为Pod绑定的Service Account分配足够的RBAC权限(如目标命名空间的编辑权限或cluster-admin),否则Helm客户端会因权限不足无法完成Chart部署。
  • 配置持久化:若需长期保留Helm配置,可将emptyDir替换为PersistentVolumeClaim,避免Pod重启后配置丢失。

内容的提问来源于stack exchange,提问作者Dhananjay Gahiwade

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.25 18:54:19