You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Docker Desktop Kubernetes中使用ASP.NET Core开发证书?

在Docker Desktop Kubernetes中实现用户机密与开发证书的容器访问

Visual Studio通过Docker Compose的卷绑定,让容器能访问本地的用户机密和开发证书。在Docker Desktop Kubernetes中,你可以通过hostPath卷实现相同效果,具体步骤如下:

1. 确定本地APPDATA路径

Windows系统下,${APPDATA}默认指向C:\Users\<你的用户名>\AppData\Roaming,比如C:\Users\Parsa\AppData\Roaming,后续配置需要替换为你的实际路径。

2. 编写Kubernetes资源配置(Deployment示例)

在Deployment或Pod的YAML配置中,定义volumes和volumeMounts,对应Docker Compose中的卷绑定规则:

apiVersion: apps/v1
kind: Deployment
metadata:
  name: your-app-deployment
spec:
  replicas: 1
  selector:
    matchLabels:
      app: your-app
  template:
    metadata:
      labels:
        app: your-app
    spec:
      containers:
      - name: your-app-container
        image: your-app-image:latest
        # 配置容器内的挂载点
        volumeMounts:
        - name: user-secrets-home
          mountPath: /home/app/.microsoft/usersecrets
          readOnly: true
        - name: user-secrets-root
          mountPath: /root/.microsoft/usersecrets
          readOnly: true
        - name: aspnet-https-home
          mountPath: /home/app/.aspnet/https
          readOnly: true
        - name: aspnet-https-root
          mountPath: /root/.aspnet/https
          readOnly: true
      # 定义hostPath卷,指向本地APPDATA下的对应目录
      volumes:
      - name: user-secrets-home
        hostPath:
          path: C:\Users\<你的用户名>\AppData\Roaming\Microsoft\UserSecrets
          type: Directory
      - name: user-secrets-root
        hostPath:
          path: C:\Users\<你的用户名>\AppData\Roaming\Microsoft\UserSecrets
          type: Directory
      - name: aspnet-https-home
        hostPath:
          path: C:\Users\<你的用户名>\AppData\Roaming\ASP.NET\Https
          type: Directory
      - name: aspnet-https-root
        hostPath:
          path: C:\Users\<你的用户名>\AppData\Roaming\ASP.NET\Https
          type: Directory

3. 部署配置并验证

将上述YAML保存为deployment.yaml,执行命令部署:

kubectl apply -f deployment.yaml

部署完成后,可进入容器验证挂载是否生效:

kubectl exec -it <pod-name> -- ls /home/app/.microsoft/usersecrets
kubectl exec -it <pod-name> -- ls /home/app/.aspnet/https

注意事项

  • 务必替换配置中的<你的用户名>为实际Windows用户名,保证路径准确
  • hostPath卷依赖节点本地文件,仅适用于Docker Desktop这种单节点Kubernetes环境;多节点集群需改用Secret或VolumeClaim等分布式存储方案
  • 确保容器内的目标目录(如/home/app、/root)具备读取挂载文件的权限

内容的提问来源于stack exchange,提问作者Parsa99

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 01:11:08