真题环境模拟
gVisor 的安装、Containerd 的配置所有节点都要操作
安装 gVisor
安装依赖
sudo apt-get update && \
sudo apt-get install -y \
apt-transport-https \
ca-certificates \
curl \
gnupg安装 key
curl -fsSL https://gvisor.dev/archive.key | sudo gpg --dearmor -o /usr/share/keyrings/gvisor-archive-keyring.gpg
echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/gvisor-archive-keyring.gpg] https://storage.googleapis.com/gvisor/releases release main" | sudo tee /etc/apt/sources.list.d/gvisor.list > /dev/null安装 runsc
sudo apt-get update && sudo apt-get install -y runsc配置 Containerd
vim /etc/containerd/config.toml
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes]
# 下级添加
[plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runsc]
runtime_type = "io.contaiherd.runsc.v1"

重启 Containerd
systemctl daemon-reload
systemctl restart containerd创建模拟程序
kubectl create ns client
kubectl run nginx --image=nginx -n clientLast updated