Kubernetes 1.7.x+ / Openshift 3.7+ ( rhel 7.x ) SELinux enabled DC seLinuxContext privileged: true
10K+
Tested and working on kubernetes 1.7.x and 1.11.x / Openshift 3.7 and 3.11 ( rhel 7.x ) with SELinux enabled. Needs DC with privileged: true at seLinuxContext.
Provide a Kubernetes cifs for CoreOS/Ubuntu/Fedora.. (for example) to use, optimized for speed.
Kubernetes:
docker run -it --rm -v /etc/kubernetes/volumeplugins/phlbrz~cifs:/target phlbrz/cifs_k8s_plugin /target
Openshift:
docker run -it --rm -v /usr/libexec/kubernetes/kubelet-plugins/volume/exec/phlbrz~cifs:/target phlbrz/cifs_k8s_plugin /target
After installing the plugin, restart the kubelet or the origin-node service so that the plugin is detected.
generated from a fork of -> https://github.com/fvigotti/cifs_k8s_plugin
getvolumename is not implemented because there is a bug in kube 1.6.x https://github.com/kubernetes/kubernetes/issues/44737
kubelet flags :
controller manager flags:
not sure if it's really true but seems that after the creation of the plugin directory (/etc/kubernetes/volumeplugins/phlbrz) kubelet needed a restart, hot-changes to plugin source can be done in place without further restarts
Assuming a //192.168.56.101/TEST cifs share, accessible by a TESTER user with a SECRET password.
kubectl create secret generic cifscreds --from-literal username=TESTER --from-literal password=SECRET
cat <<EOF | tee pod.yml
apiVersion: v1
kind: Pod
metadata:
name: cc
spec:
containers:
- name: cc
image: nginx
volumeMounts:
- name: test
mountPath: /data
ports:
- containerPort: 80
volumes:
- name: test
flexVolume:
driver: "phlbrz/cifs"
secretRef:
name: cifscreds
readOnly: true
options:
source: "//192.168.56.101/TEST"
mountOptions: "dir_mode=0700,file_mode=0600"
EOF
generate the secret file, nb: the type is mandatory
cat <<EOF | tee secret.yml
apiVersion: v1
data:
password: bas64pwd
username: bas64user
kind: Secret
metadata:
name: cifscreds
namespace: default
type: "phlbrz/cifs"
EOF
Feel free to edit the flexVolume specification to match your needs.
kubectl create -f pod.yml
kubectl get pod cc
kubectl exec cc -- df ; ls -l /data
Content type
Image
Digest
Size
3.3 MB
Last updated
over 6 years ago
docker pull phlbrz/cifs_k8s_plugin