apiVersion: v1
kind: Pod
metadata:
name: myapp
spec:
volumes:
- name: sec-ctx-vol
emptyDir: {}
containers:
- name: myapp
image: busybox
command: [ "sh", "-c", "sleep 1h" ]
volumeMounts:
- name: sec-ctx-vol
mountPath: /data/demo
securityContext:
allowPrivilegeEscalation: false
emptyDir: {} 宿主机上挂在随机的空目录:
[root@master ~]# kubectl get pod myapp
NAME READY STATUS RESTARTS AGE
myapp 1/1 Running 0 31s
Events:
Type Reason Age From Message
---- ------ ---- ---- -------
Normal Scheduled 53s default-scheduler Successfully assigned default/myapp to node2
Normal Pulling 51s kubelet Pulling image "busybox"
Normal Pulled 25s kubelet