Kubernetes部署dorowu/ubuntu-desktop-lxde-vnc如何引用本地SSL实现noVNC访问
问题解答
可以通过Kubernetes Pod使用noVNC访问该Ubuntu容器,你当前配置缺少**/dev/shm挂载和SSL证书挂载**两项配置,按以下步骤调整即可正常使用:
操作步骤
1. 本地SSL证书导入Kubernetes集群
Kubernetes中使用Secret存储证书类敏感信息,在你本地证书存放目录的上级路径执行以下命令,将ssl目录下的所有证书文件创建为对应命名空间下的Secret:
kubectl create secret generic ubuntu-vnc-ssl \ --from-file=./ssl \ --namespace=test
执行完成后证书会存储在集群内,无需再挂载本地文件。
2. 更新Deployment配置
你需要在原配置的基础上添加两项挂载配置:一是/dev/shm的内存挂载,二是SSL证书Secret的挂载,完整配置如下:
apiVersion: apps/v1 kind: Deployment metadata: name: test namespace: test spec: selector: matchLabels: app: test replicas: 1 template: metadata: labels: app: test spec: containers: - name: test image: dorowu/ubuntu-desktop-lxde-vnc imagePullPolicy: Always ports: - containerPort: 443 env: - name: RESOLUTION value: "1920x1080" - name: SSL_PORT value: "443" # 新增挂载配置 volumeMounts: # 挂载/dev/shm - mountPath: /dev/shm name: shm-volume # 挂载SSL证书 - mountPath: /etc/nginx/ssl name: ssl-volume readOnly: true # 新增卷定义 volumes: # /dev/shm对应内存卷 - name: shm-volume emptyDir: medium: Memory # SSL证书对应之前创建的Secret - name: ssl-volume secret: secretName: ubuntu-vnc-ssl
3. 验证访问
部署完成后,你可以通过端口转发临时测试访问:
kubectl port-forward deployment/test 6081:443 -n test
执行后访问https://localhost:6081即可正常访问加密的noVNC桌面,和本地Docker运行效果一致。如果需要对外提供服务,可配置NodePort、LoadBalancer或Ingress暴露443端口即可。
内容的提问来源于stack exchange,提问作者shaharnakash
相关产品推荐
相关产品推荐

