You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kubernetes部署dorowu/ubuntu-desktop-lxde-vnc如何引用本地SSL实现noVNC访问

问题解答

可以通过Kubernetes Pod使用noVNC访问该Ubuntu容器,你当前配置缺少**/dev/shm挂载和SSL证书挂载**两项配置,按以下步骤调整即可正常使用:


操作步骤

1. 本地SSL证书导入Kubernetes集群

Kubernetes中使用Secret存储证书类敏感信息,在你本地证书存放目录的上级路径执行以下命令,将ssl目录下的所有证书文件创建为对应命名空间下的Secret:

kubectl create secret generic ubuntu-vnc-ssl \
  --from-file=./ssl \
  --namespace=test

执行完成后证书会存储在集群内,无需再挂载本地文件。

2. 更新Deployment配置

你需要在原配置的基础上添加两项挂载配置:一是/dev/shm的内存挂载,二是SSL证书Secret的挂载,完整配置如下:

apiVersion: apps/v1
kind: Deployment
metadata:
  name: test
  namespace: test
spec:
  selector:
    matchLabels:
      app: test
  replicas: 1
  template:
    metadata:
      labels:
        app: test
    spec:
      containers:
      - name: test
        image: dorowu/ubuntu-desktop-lxde-vnc 
        imagePullPolicy: Always
        ports:
        - containerPort: 443
        env:
        - name: RESOLUTION
          value: "1920x1080"
        - name: SSL_PORT
          value: "443"
        # 新增挂载配置
        volumeMounts:
        # 挂载/dev/shm
        - mountPath: /dev/shm
          name: shm-volume
        # 挂载SSL证书
        - mountPath: /etc/nginx/ssl
          name: ssl-volume
          readOnly: true
      # 新增卷定义
      volumes:
      # /dev/shm对应内存卷
      - name: shm-volume
        emptyDir:
          medium: Memory
      # SSL证书对应之前创建的Secret
      - name: ssl-volume
        secret:
          secretName: ubuntu-vnc-ssl

3. 验证访问

部署完成后,你可以通过端口转发临时测试访问:

kubectl port-forward deployment/test 6081:443 -n test

执行后访问https://localhost:6081即可正常访问加密的noVNC桌面,和本地Docker运行效果一致。如果需要对外提供服务,可配置NodePort、LoadBalancer或Ingress暴露443端口即可。


内容的提问来源于stack exchange,提问作者shaharnakash

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.03 05:36:00