【问题标题】:What are AccessModes in Kubernetes VolumesKubernetes 卷中的 AccessMode 是什么
【发布时间】:2021-03-15 08:53:43
【问题描述】:

我正在尝试了解 Kubernetes PersistentVolumes 的访问模式。

根据 Kubernetes 文档,访问模式是:

ReadWriteOnce -- the volume can be mounted as read-write by a single node
ReadOnlyMany -- the volume can be mounted read-only by many nodes
ReadWriteMany -- the volume can be mounted as read-write by many nodes

音量插件HostPath支持ReadWriteOnce

我有一个 1 controlplane and 1 worker1 node 的 K8s 集群,我根据以下配置在同一 namespace 中部署了两个 Pod,每个节点、pv、pvc。运行在不同节点上的两个 pod 都可以对本地路径 /tmp/test 进行读写。

根据我的理解,这不应该发生。只有一个节点应该能够读写,而另一个节点应该只能读取。

有人能解释一下这里发生了什么吗,如果可能的话,请给我提供例子/博客来看看RWO, RWX, ROX之间的区别?大部分的博客,只是简单的说一下PV、PVC和访问方式。

apiVersion: v1
kind: Pod
metadata:
  name: pod2
spec:
  nodeName: controlplane
  containers:
  - image: nginx
    name: pod2
    volumeMounts:
      - name: vol
        mountPath: /usr/share/nginx/html
  volumes:
  - name: vol
    persistentVolumeClaim:
      claimName: pvc
---
apiVersion: v1
kind: Pod
metadata:
  name: pod1
spec:
  nodeName: worker1
  containers:
  - image: nginx
    name: pod1
    volumeMounts:
      - name: vol
        mountPath: /usr/share/nginx/html
  volumes:
  - name: vol
    persistentVolumeClaim:
      claimName: pvc
---
apiVersion: v1
kind: PersistentVolume
metadata:
  name: pv
spec:
  capacity:
    storage: 5Gi
  accessModes:
    - ReadWriteOnce
  hostPath:
    path: /tmp/test
---
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
  name: pvc
spec:
  accessModes:
    - ReadWriteOnce
  resources:
    requests:
      storage: 5Gi

【问题讨论】:

    标签: kubernetes google-kubernetes-engine persistent-volumes persistent-volume-claims


    【解决方案1】:
    1. 请注意,您不应在控制平面上运行 pod,因此您应该在 yaml 文件中将 nodeName: controlplane 替换为 nodeName: worker2。通常你需要使用toleration 在控制平面上运行 pod,因为它有一个 taint 防止在其上运行常规 pod...

    2. 我在 Google Kubernetes Engine (gke) 上尝试了您的 yaml,我必须替换 nodeName 字段才能使其正常工作:

    diff example.yaml example-gke.yaml 
    6c6
    <   nodeName: controlplane
    ---
    >   nodeName: gke-qserv-dev-worker-pool-a64a-01bc5238-3zl9 
    23c23
    <   nodeName: worker1
    ---
    >   nodeName: gke-qserv-dev-worker-pool-a64a-01bc5238-23t3 
    

    如你所见,k8s 拒绝创建pod2:

    kubectl get pods
    NAME                                   READY   STATUS              RESTARTS   AGE
    pod1                                   1/1     Running             0          6m27s
    pod2                                   0/1     ContainerCreating   0          6m27s
    

    这是我收到的消息:

    kubectl describe pod pod2 | tail -n 1
      Warning  FailedAttachVolume  7m28s                 attachdetach-controller                                Multi-Attach error for volume "pvc-2fb657ce-4678-4e92-9f64-e4b46b9a3ec7" Volume is already used by pod(s) pod1
    

    因此,如您所见,您无法将 PV 安装在两个不同节点上运行的两个不同 pod 上。所以你得到的不是常规的 k8s 行为。这可能是您的存储类的副作用,特别是如果您使用minikube 或kind。

    【讨论】:

    • 我知道容忍/污点。我清理了我的controlplane 只是为了测试目的。顺便说一句,我使用kubeadm 来运行这个集群以进行学习。感谢您的回答,我想我的集群本身有问题。我没有 GKE,将尝试使用 AKS 并更新。
    猜你喜欢
    • 2017-10-25
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2021-05-17
    • 1970-01-01
    • 2019-03-22
    相关资源
    最近更新 更多