Chuyển đến nội dung chính

第1課: Multi-container Pods 與 Init Containers

Multi-container Pod 設計模式: Sidecar、Ambassador、Adapter。Init Containers 的使用場景與 YAML 配置。Init Containers 與一般 Containers 的差異。

Multi-container Pod 模式 — Sidecar、Ambassador、Adapter

1. Multi-container Pod 模式

同一 Pod 中的容器共享網路(localhost)和儲存(volumes)。以下是三種設計模式:

模式用途範例
Sidecar輔助或增強主容器Log collector、sync agent
Ambassador代理外部連線本地 proxy → remote DB
Adapter統一主容器的輸出格式Log 格式轉換器
┌──────────────────── Pod ────────────────────┐
│                                             │
│  ┌─────────────┐    ┌──────────────────┐    │
│  │  app (主)    │    │  log-agent       │    │
│  │  port: 8080  │    │  (Sidecar)       │    │
│  └──────┬───────┘    └────────┬─────────┘    │
│         │    共享 Volume      │              │
│         └────────────────────┘              │
│  共享 localhost 網路                         │
└─────────────────────────────────────────────┘

2. Multi-container Pod YAML

apiVersion: v1
kind: Pod
metadata:
  name: multi-container-pod
spec:
  containers:
  - name: app
    image: nginx
    ports:
    - containerPort: 80
    volumeMounts:
    - name: shared-logs
      mountPath: /var/log/nginx

  - name: log-agent             # Sidecar 容器
    image: busybox
    command: ["sh", "-c", "tail -f /logs/access.log"]
    volumeMounts:
    - name: shared-logs
      mountPath: /logs

  volumes:
  - name: shared-logs
    emptyDir: {}                # Pod 的生命週期內存在

3. Init Containers

Init Containers 在主容器啟動之前依序執行。全部成功後主容器才會啟動。

apiVersion: v1
kind: Pod
metadata:
  name: init-demo
spec:
  initContainers:
  - name: wait-for-db
    image: busybox
    command: ['sh', '-c', 'until nc -z mysql-svc 3306; do sleep 2; done']

  - name: init-config
    image: busybox
    command: ['sh', '-c', 'echo "config ready" > /work/status']
    volumeMounts:
    - name: workdir
      mountPath: /work

  containers:
  - name: app
    image: myapp:1.0
    volumeMounts:
    - name: workdir
      mountPath: /app/config

  volumes:
  - name: workdir
    emptyDir: {}

4. Init Containers vs 一般 Containers

特性Init Container一般 Container
執行順序依序執行(一個接一個)並行執行
必須完成是 — 必須成功退出否 — 持續運行
Probes不支援支援(liveness、readiness、startup)
Ports不在 Service endpoints 中可暴露 Service
Resources影響 Pod 排程(有效 requests)累加計算

考試重點: Init Containers 的常見考題包含:「建立一個 Pod,在主容器啟動前等待 Service 可用」或「使用 Init Container 下載設定檔」。記住 Init Containers 的 YAML 位於 spec.initContainers,與 spec.containers 同層級。

5. 速查表

任務指令 / YAML
查看特定容器的 logskubectl logs pod -c container-name
進入特定容器kubectl exec -it pod -c container -- sh
檢查 init container 狀態kubectl describe pod name → Init Containers 區段
共享檔案系統使用 emptyDir volume + volumeMounts
容器間通訊localhost:port(同一 Pod 共享網路)

6. 練習題

Q1: 一個 Pod 有兩個容器:app(port 8080)和 log-agent。log-agent 需要讀取 app 產生的日誌檔。最適合的共享機制是什麼?

  • A) ConfigMap volume
  • B) emptyDir volume ✓
  • C) hostPath volume
  • D) PersistentVolumeClaim

解析: emptyDir 在 Pod 生命週期內建立臨時儲存,適合同一 Pod 中容器間共享暫存資料。ConfigMap 用於組態、hostPath 有安全顧慮、PVC 用於持久化資料。

Q2: 一個 Pod 有 2 個 Init Containers:init-a 和 init-b,以及 1 個主容器 app。init-a 失敗了。後續行為是什麼?

  • A) init-b 和 app 正常啟動
  • B) 僅 init-b 執行,app 不啟動
  • C) init-a 按 restartPolicy 重試;init-b 和 app 不會啟動 ✓
  • D) Pod 直接被刪除

解析: Init Containers 依序執行。如果某個失敗,Kubernetes 根據 Pod 的 restartPolicy 重試。只有當 init-a 成功後,init-b 才會執行。所有 Init Containers 成功後,主容器才啟動。

Q3: 下列哪個是 Sidecar 模式的正確使用場景?

  • A) 啟動前執行一次性初始化腳本
  • B) 與主容器並行運行,收集並轉發日誌 ✓
  • C) 將流量代理至外部資料庫叢集
  • D) 將 Prometheus 指標格式轉換為統一格式

解析: Sidecar 模式是輔助/增強主容器功能的容器,與主容器並行運行。日誌收集是典型 Sidecar 場景。C 是 Ambassador 模式、D 是 Adapter 模式、A 是 Init Container。