1. Multi-container Pod 模式
同一 Pod 中的容器共享網路(localhost)和儲存(volumes)。以下是三種設計模式:
| 模式 | 用途 | 範例 |
|---|---|---|
| Sidecar | 輔助或增強主容器 | Log collector、sync agent |
| Ambassador | 代理外部連線 | 本地 proxy → remote DB |
| Adapter | 統一主容器的輸出格式 | Log 格式轉換器 |
┌──────────────────── Pod ────────────────────┐
│ │
│ ┌─────────────┐ ┌──────────────────┐ │
│ │ app (主) │ │ log-agent │ │
│ │ port: 8080 │ │ (Sidecar) │ │
│ └──────┬───────┘ └────────┬─────────┘ │
│ │ 共享 Volume │ │
│ └────────────────────┘ │
│ 共享 localhost 網路 │
└─────────────────────────────────────────────┘
2. Multi-container Pod YAML
apiVersion: v1
kind: Pod
metadata:
name: multi-container-pod
spec:
containers:
- name: app
image: nginx
ports:
- containerPort: 80
volumeMounts:
- name: shared-logs
mountPath: /var/log/nginx
- name: log-agent # Sidecar 容器
image: busybox
command: ["sh", "-c", "tail -f /logs/access.log"]
volumeMounts:
- name: shared-logs
mountPath: /logs
volumes:
- name: shared-logs
emptyDir: {} # Pod 的生命週期內存在
3. Init Containers
Init Containers 在主容器啟動之前依序執行。全部成功後主容器才會啟動。
apiVersion: v1
kind: Pod
metadata:
name: init-demo
spec:
initContainers:
- name: wait-for-db
image: busybox
command: ['sh', '-c', 'until nc -z mysql-svc 3306; do sleep 2; done']
- name: init-config
image: busybox
command: ['sh', '-c', 'echo "config ready" > /work/status']
volumeMounts:
- name: workdir
mountPath: /work
containers:
- name: app
image: myapp:1.0
volumeMounts:
- name: workdir
mountPath: /app/config
volumes:
- name: workdir
emptyDir: {}
4. Init Containers vs 一般 Containers
| 特性 | Init Container | 一般 Container |
|---|---|---|
| 執行順序 | 依序執行(一個接一個) | 並行執行 |
| 必須完成 | 是 — 必須成功退出 | 否 — 持續運行 |
| Probes | 不支援 | 支援(liveness、readiness、startup) |
| Ports | 不在 Service endpoints 中 | 可暴露 Service |
| Resources | 影響 Pod 排程(有效 requests) | 累加計算 |
考試重點: Init Containers 的常見考題包含:「建立一個 Pod,在主容器啟動前等待 Service 可用」或「使用 Init Container 下載設定檔」。記住 Init Containers 的 YAML 位於
spec.initContainers,與spec.containers同層級。
5. 速查表
| 任務 | 指令 / YAML |
|---|---|
| 查看特定容器的 logs | kubectl logs pod -c container-name |
| 進入特定容器 | kubectl exec -it pod -c container -- sh |
| 檢查 init container 狀態 | kubectl describe pod name → Init Containers 區段 |
| 共享檔案系統 | 使用 emptyDir volume + volumeMounts |
| 容器間通訊 | localhost:port(同一 Pod 共享網路) |
6. 練習題
Q1: 一個 Pod 有兩個容器:app(port 8080)和 log-agent。log-agent 需要讀取 app 產生的日誌檔。最適合的共享機制是什麼?
- A) ConfigMap volume
- B) emptyDir volume ✓
- C) hostPath volume
- D) PersistentVolumeClaim
解析: emptyDir 在 Pod 生命週期內建立臨時儲存,適合同一 Pod 中容器間共享暫存資料。ConfigMap 用於組態、hostPath 有安全顧慮、PVC 用於持久化資料。
Q2: 一個 Pod 有 2 個 Init Containers:init-a 和 init-b,以及 1 個主容器 app。init-a 失敗了。後續行為是什麼?
- A) init-b 和 app 正常啟動
- B) 僅 init-b 執行,app 不啟動
- C) init-a 按 restartPolicy 重試;init-b 和 app 不會啟動 ✓
- D) Pod 直接被刪除
解析: Init Containers 依序執行。如果某個失敗,Kubernetes 根據 Pod 的 restartPolicy 重試。只有當 init-a 成功後,init-b 才會執行。所有 Init Containers 成功後,主容器才啟動。
Q3: 下列哪個是 Sidecar 模式的正確使用場景?
- A) 啟動前執行一次性初始化腳本
- B) 與主容器並行運行,收集並轉發日誌 ✓
- C) 將流量代理至外部資料庫叢集
- D) 將 Prometheus 指標格式轉換為統一格式
解析: Sidecar 模式是輔助/增強主容器功能的容器,與主容器並行運行。日誌收集是典型 Sidecar 場景。C 是 Ambassador 模式、D 是 Adapter 模式、A 是 Init Container。