You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

挂载HostPath PV至Pod目录时保留容器原有文件的技术问询

How to Preserve Container's Original Files When Mounting a HostPath PV to /usr/share/nginx/html in Kubernetes

Absolutely, you can keep your container's original files while using a HostPath PV—let's fix that 403 error and get things working as expected.

Why You're Seeing the 403

When you mount a volume directly to /usr/share/nginx/html, Kubernetes replaces the entire contents of that directory with whatever's in the HostPath volume. Since your /mnt/2/data/ directory is empty (I'm guessing), Nginx can't find the index.html it needs, hence the Forbidden error.

The cleanest way to handle this is to use an init container to copy the default files from your Nginx image into the HostPath volume before the main container starts. This ensures the volume has your base index.html, and any future changes to files in /usr/share/nginx/html will persist to the node's HostPath.

Here's your updated pod.yaml:

kind: Pod
apiVersion: v1
metadata:
  labels:
    app: nginx
  name: task-pv-pod23
spec:
  volumes:
    - name: task-pv-storage2
      persistentVolumeClaim:
        claimName: task-pv-claim2
  # Init container to copy default files to the volume
  initContainers:
    - name: copy-default-content
      image: meysambbb/nginx:2
      command: ["sh", "-c", "cp -r /usr/share/nginx/html/. /mnt/volume/"]
      volumeMounts:
        - name: task-pv-storage2
          mountPath: /mnt/volume
  containers:
    - name: task-pv-container
      image: meysambbb/nginx:2
      ports:
        - containerPort: 80
          name: "http-server"
      volumeMounts:
        - name: task-pv-storage2
          mountPath: /usr/share/nginx/html/

How This Works:

  1. The init container runs first, using your custom Nginx image (so it has the original index.html).
  2. It copies all files from /usr/share/nginx/html/ into the mounted HostPath volume at /mnt/volume.
  3. Once the init container finishes, the main Nginx container starts and mounts the volume (now with your base files) to /usr/share/nginx/html/.

Pro Tip: If you ever update your image with new default files, modify the init container command to only copy if the volume is empty (to avoid overwriting existing changes):

if [ ! -f /mnt/volume/index.html ]; then cp -r /usr/share/nginx/html/. /mnt/volume/; fi

Solution 2: Adjust Access Modes (If You Need Write Access)

I noticed your PV and PVC are set to ReadOnlyMany. If you want to modify files in /usr/share/nginx/html/ and have those changes persist to the HostPath, you'll need to update the access modes to ReadWriteOnce (HostPath volumes don't support ReadWriteMany since they're node-local):

Updated pv.yaml:

kind: PersistentVolume
apiVersion: v1
metadata:
  name: task-pv-volume2
  labels:
    type: local
spec:
  capacity:
    storage: 10Gi
  accessModes:
    - ReadWriteOnce  # Changed from ReadOnlyMany
  hostPath:
    path: "/mnt/2/data/"

Updated pvc.yaml:

kind: PersistentVolumeClaim
apiVersion: v1
metadata:
  name: task-pv-claim2
spec:
  accessModes:
    - ReadWriteOnce  # Changed from ReadOnlyMany
  resources:
    requests:
      storage: 3Gi

Testing It Out

After applying these changes:

  1. Delete the old pod: kubectl delete pod task-pv-pod23
  2. Apply the updated manifests: kubectl apply -f pod.yaml -f pv.yaml -f pvc.yaml
  3. Wait for the pod to start, then curl the pod IP—you should see your original index.html content, and any changes you make to the files in /usr/share/nginx/html will persist to /mnt/2/data/ on the node.

内容的提问来源于stack exchange,提问作者meisam bahrami

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.13 07:43:35