{"id":2763,"date":"2019-01-25T01:12:57","date_gmt":"2019-01-24T17:12:57","guid":{"rendered":"https:\/\/damogame.cn:15443\/wordpress\/?p=2763"},"modified":"2019-01-25T01:12:57","modified_gmt":"2019-01-24T17:12:57","slug":"%e9%9d%9e%e5%b8%b8%e8%af%a6%e7%bb%86%e7%9a%84-docker-%e5%ad%a6%e4%b9%a0%e7%ac%94%e8%ae%b0","status":"publish","type":"post","link":"https:\/\/i007.cc\/wordpress\/archives\/2763","title":{"rendered":"\u975e\u5e38\u8be6\u7ec6\u7684 Docker \u5b66\u4e60\u7b14\u8bb0"},"content":{"rendered":"<div class=\"article-header-box\">\n<div class=\"article-header\">\n<div class=\"article-title-box\"><\/div>\n<div class=\"article-info-box\">\n<div class=\"operating\"><\/div>\n<\/div>\n<\/div>\n<\/div>\n<article class=\"baidu_pl\">\n<div id=\"article_content\" class=\"article_content clearfix csdn-tracking-statistics\" data-pid=\"blog\" data-mod=\"popu_307\" data-dsm=\"post\">\n<div id=\"content_views\" class=\"htmledit_views\">\n<h2 id=\"articleHeader0\">\u4e00\u3001Docker \u7b80\u4ecb<\/h2>\n<p>Docker \u4e24\u4e2a\u4e3b\u8981\u90e8\u4ef6\uff1a<\/p>\n<ul>\n<li>Docker: \u5f00\u6e90\u7684\u5bb9\u5668\u865a\u62df\u5316\u5e73\u53f0<\/li>\n<li>Docker Hub: \u7528\u4e8e\u5206\u4eab\u3001\u7ba1\u7406 Docker \u5bb9\u5668\u7684 Docker SaaS \u5e73\u53f0 &#8212;\u00a0<a href=\"https:\/\/registry.hub.docker.com\/search?q=library\" target=\"_blank\" rel=\"nofollow noopener\">Docker Hub<\/a><\/li>\n<\/ul>\n<p>Docker \u4f7f\u7528\u5ba2\u6237\u7aef-\u670d\u52a1\u5668 (C\/S) \u67b6\u6784\u6a21\u5f0f\u3002Docker \u5ba2\u6237\u7aef\u4f1a\u4e0e Docker \u5b88\u62a4\u8fdb\u7a0b\u8fdb\u884c\u901a\u4fe1\u3002Docker \u5b88\u62a4\u8fdb\u7a0b\u4f1a\u5904\u7406\u590d\u6742\u7e41\u91cd\u7684\u4efb\u52a1\uff0c\u4f8b\u5982\u5efa\u7acb\u3001\u8fd0\u884c\u3001\u53d1\u5e03\u4f60\u7684 Docker \u5bb9\u5668\u3002Docker \u5ba2\u6237\u7aef\u548c\u5b88\u62a4\u8fdb\u7a0b\u53ef\u4ee5\u8fd0\u884c\u5728\u540c\u4e00\u4e2a\u7cfb\u7edf\u4e0a\uff0c\u5f53\u7136\u4f60\u4e5f\u53ef\u4ee5\u4f7f\u7528 Docker \u5ba2\u6237\u7aef\u53bb\u8fde\u63a5\u4e00\u4e2a\u8fdc\u7a0b\u7684 Docker \u5b88\u62a4\u8fdb\u7a0b\u3002Docker \u5ba2\u6237\u7aef\u548c\u5b88\u62a4\u8fdb\u7a0b\u4e4b\u95f4\u901a\u8fc7 socket \u6216\u8005 RESTful API \u8fdb\u884c\u901a\u4fe1\u3002<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/static.open-open.com\/lib\/uploadImg\/20150212\/20150212091033_189.png\" alt=\"\u975e\u5e38\u8be6\u7ec6\u7684 Docker \u5b66\u4e60\u7b14\u8bb0\" width=\"577\" height=\"487\" \/><\/p>\n<h3 id=\"articleHeader1\"><a name=\"t1\"><\/a>1.1 Docker \u5b88\u62a4\u8fdb\u7a0b<\/h3>\n<p>\u5982\u4e0a\u56fe\u6240\u793a\uff0cDocker \u5b88\u62a4\u8fdb\u7a0b\u8fd0\u884c\u5728\u4e00\u53f0\u4e3b\u673a\u4e0a\u3002\u7528\u6237\u5e76\u4e0d\u76f4\u63a5\u548c\u5b88\u62a4\u8fdb\u7a0b\u8fdb\u884c\u4ea4\u4e92\uff0c\u800c\u662f\u901a\u8fc7 Docker \u5ba2\u6237\u7aef\u95f4\u63a5\u548c\u5176\u901a\u4fe1\u3002<\/p>\n<h3 id=\"articleHeader2\"><a name=\"t2\"><\/a>1.2 Docker \u5ba2\u6237\u7aef<\/h3>\n<p>Docker \u5ba2\u6237\u7aef\uff0c\u5b9e\u9645\u4e0a\u662f docker \u7684\u4e8c\u8fdb\u5236\u7a0b\u5e8f\uff0c\u662f\u4e3b\u8981\u7684\u7528\u6237\u4e0e Docker \u4ea4\u4e92\u65b9\u5f0f\u3002\u5b83\u63a5\u6536\u7528\u6237\u6307\u4ee4\u5e76\u4e14\u4e0e\u80cc\u540e\u7684 Docker \u5b88\u62a4\u8fdb\u7a0b\u901a\u4fe1\uff0c\u5982\u6b64\u6765\u56de\u5f80\u590d\u3002<\/p>\n<h3 id=\"articleHeader3\"><a name=\"t3\"><\/a>1.3 Docker \u5185\u90e8<\/h3>\n<p>\u8981\u7406\u89e3 Docker \u5185\u90e8\u6784\u5efa\uff0c\u9700\u8981\u7406\u89e3\u4ee5\u4e0b\u4e09\u79cd\u90e8\u4ef6\uff1a<\/p>\n<ul>\n<li>Docker \u955c\u50cf &#8211; Docker images<\/li>\n<li>Docker \u4ed3\u5e93 &#8211; Docker registeries<\/li>\n<li>Docker \u5bb9\u5668 &#8211; Docker containers<\/li>\n<\/ul>\n<h4>Docker \u955c\u50cf<\/h4>\n<p>Docker \u955c\u50cf\u662f Docker \u5bb9\u5668\u8fd0\u884c\u65f6\u7684\u53ea\u8bfb\u6a21\u677f\uff0c\u6bcf\u4e00\u4e2a\u955c\u50cf\u7531\u4e00\u7cfb\u5217\u7684\u5c42 (layers) \u7ec4\u6210\u3002Docker \u4f7f\u7528 UnionFS \u6765\u5c06\u8fd9\u4e9b\u5c42\u8054\u5408\u5230\u5355\u72ec\u7684\u955c\u50cf\u4e2d\u3002UnionFS \u5141\u8bb8\u72ec\u7acb\u6587\u4ef6\u7cfb\u7edf\u4e2d\u7684\u6587\u4ef6\u548c\u6587\u4ef6\u5939(\u79f0\u4e4b\u4e3a\u5206\u652f)\u88ab\u900f\u660e\u8986\u76d6\uff0c\u5f62\u6210\u4e00\u4e2a\u5355\u72ec\u8fde\u8d2f\u7684\u6587\u4ef6\u7cfb\u7edf\u3002\u6b63\u56e0\u4e3a\u6709\u4e86\u8fd9\u4e9b\u5c42\u7684\u5b58\u5728\uff0cDocker \u662f\u5982\u6b64\u7684\u8f7b\u91cf\u3002\u5f53\u4f60\u6539\u53d8\u4e86\u4e00\u4e2a Docker \u955c\u50cf\uff0c\u6bd4\u5982\u5347\u7ea7\u5230\u67d0\u4e2a\u7a0b\u5e8f\u5230\u65b0\u7684\u7248\u672c\uff0c\u4e00\u4e2a\u65b0\u7684\u5c42\u4f1a\u88ab\u521b\u5efa\u3002\u56e0\u6b64\uff0c\u4e0d\u7528\u66ff\u6362\u6574\u4e2a\u539f\u5148\u7684\u955c\u50cf\u6216\u8005\u91cd\u65b0\u5efa\u7acb(\u5728\u4f7f\u7528\u865a\u62df\u673a\u7684\u65f6\u5019\u4f60\u53ef\u80fd\u4f1a\u8fd9\u4e48\u505a)\uff0c\u53ea\u662f\u4e00\u4e2a\u65b0 \u7684\u5c42\u88ab\u6dfb\u52a0\u6216\u5347\u7ea7\u4e86\u3002\u73b0\u5728\u4f60\u4e0d\u7528\u91cd\u65b0\u53d1\u5e03\u6574\u4e2a\u955c\u50cf\uff0c\u53ea\u9700\u8981\u5347\u7ea7\uff0c\u5c42\u4f7f\u5f97\u5206\u53d1 Docker \u955c\u50cf\u53d8\u5f97\u7b80\u5355\u548c\u5feb\u901f\u3002<\/p>\n<h4>Docker \u4ed3\u5e93<\/h4>\n<p>Docker \u4ed3\u5e93\u7528\u6765\u4fdd\u5b58\u955c\u50cf\uff0c\u53ef\u4ee5\u7406\u89e3\u4e3a\u4ee3\u7801\u63a7\u5236\u4e2d\u7684\u4ee3\u7801\u4ed3\u5e93\u3002\u540c\u6837\u7684\uff0cDocker \u4ed3\u5e93\u4e5f\u6709\u516c\u6709\u548c\u79c1\u6709\u7684\u6982\u5ff5\u3002\u516c\u6709\u7684 Docker \u4ed3\u5e93\u540d\u5b57\u662f Docker Hub\u3002Docker Hub \u63d0\u4f9b\u4e86\u5e9e\u5927\u7684\u955c\u50cf\u96c6\u5408\u4f9b\u4f7f\u7528\u3002\u8fd9\u4e9b\u955c\u50cf\u53ef\u4ee5\u662f\u81ea\u5df1\u521b\u5efa\uff0c\u6216\u8005\u5728\u522b\u4eba\u7684\u955c\u50cf\u57fa\u7840\u4e0a\u521b\u5efa\u3002Docker \u4ed3\u5e93\u662f Docker \u7684\u5206\u53d1\u90e8\u5206\u3002<\/p>\n<h4>Docker \u5bb9\u5668<\/h4>\n<p>Docker \u5bb9\u5668\u548c\u6587\u4ef6\u5939\u5f88\u7c7b\u4f3c\uff0c\u4e00\u4e2aDocker\u5bb9\u5668\u5305\u542b\u4e86\u6240\u6709\u7684\u67d0\u4e2a\u5e94\u7528\u8fd0\u884c\u6240\u9700\u8981\u7684\u73af\u5883\u3002\u6bcf\u4e00\u4e2a Docker \u5bb9\u5668\u90fd\u662f\u4ece Docker \u955c\u50cf\u521b\u5efa\u7684\u3002Docker \u5bb9\u5668\u53ef\u4ee5\u8fd0\u884c\u3001\u5f00\u59cb\u3001\u505c\u6b62\u3001\u79fb\u52a8\u548c\u5220\u9664\u3002\u6bcf\u4e00\u4e2a Docker \u5bb9\u5668\u90fd\u662f\u72ec\u7acb\u548c\u5b89\u5168\u7684\u5e94\u7528\u5e73\u53f0\uff0cDocker \u5bb9\u5668\u662f Docker \u7684\u8fd0\u884c\u90e8\u5206\u3002<\/p>\n<h3 id=\"articleHeader4\"><a name=\"t4\"><\/a>1.4 libcontainer<\/h3>\n<p>Docker \u4ece 0.9 \u7248\u672c\u5f00\u59cb\u4f7f\u7528 libcontainer \u66ff\u4ee3 lxc\uff0clibcontainer \u548c Linux \u7cfb\u7edf\u7684\u4ea4\u4e92\u56fe\u5982\u4e0b\uff1a<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/static.open-open.com\/lib\/uploadImg\/20150212\/20150212091034_223.png\" alt=\"\u975e\u5e38\u8be6\u7ec6\u7684 Docker \u5b66\u4e60\u7b14\u8bb0\" width=\"770\" height=\"577\" \/><\/p>\n<ul>\n<li>\u56fe\u7247\u6765\u6e90:\u00a0<a href=\"http:\/\/blog.docker.com\/2014\/03\/docker-0-9-introducing-execution-drivers-and-libcontainer\/\" target=\"_blank\" rel=\"nofollow noopener\">Docker 0.9: introducing execution drivers and libcontainer<\/a><\/li>\n<\/ul>\n<h3 id=\"articleHeader5\"><a name=\"t5\"><\/a>1.5 \u547d\u540d\u7a7a\u95f4\u300cNamespaces\u300d<\/h3>\n<h4>pid namespace<\/h4>\n<p>\u4e0d\u540c\u7528\u6237\u7684\u8fdb\u7a0b\u5c31\u662f\u901a\u8fc7 pid namespace \u9694\u79bb\u5f00\u7684\uff0c\u4e14\u4e0d\u540c namespace \u4e2d\u53ef\u4ee5\u6709\u76f8\u540c PID\u3002\u5177\u6709\u4ee5\u4e0b\u7279\u5f81:<\/p>\n<ul>\n<li>\u6bcf\u4e2a namespace \u4e2d\u7684 pid \u662f\u6709\u81ea\u5df1\u7684 pid=1 \u7684\u8fdb\u7a0b(\u7c7b\u4f3c \/sbin\/init \u8fdb\u7a0b)<\/li>\n<li>\u6bcf\u4e2a namespace \u4e2d\u7684\u8fdb\u7a0b\u53ea\u80fd\u5f71\u54cd\u81ea\u5df1\u7684\u540c\u4e00\u4e2a namespace \u6216\u5b50 namespace \u4e2d\u7684\u8fdb\u7a0b<\/li>\n<li>\u56e0\u4e3a \/proc \u5305\u542b\u6b63\u5728\u8fd0\u884c\u7684\u8fdb\u7a0b\uff0c\u56e0\u6b64\u5728 container \u4e2d\u7684 pseudo-filesystem \u7684 \/proc \u76ee\u5f55\u53ea\u80fd\u770b\u5230\u81ea\u5df1 namespace \u4e2d\u7684\u8fdb\u7a0b<\/li>\n<li>\u56e0\u4e3a namespace \u5141\u8bb8\u5d4c\u5957\uff0c\u7236 namespace \u53ef\u4ee5\u5f71\u54cd\u5b50 namespace \u7684\u8fdb\u7a0b\uff0c\u6240\u4ee5\u5b50 namespace \u7684\u8fdb\u7a0b\u53ef\u4ee5\u5728\u7236 namespace \u4e2d\u770b\u5230\uff0c\u4f46\u662f\u5177\u6709\u4e0d\u540c\u7684 pid<\/li>\n<\/ul>\n<p>\u53c2\u8003\u6587\u6863\uff1a<a href=\"https:\/\/blog.jtlebi.fr\/2014\/01\/05\/introduction-to-linux-namespaces-part-3-pid\/\" target=\"_blank\" rel=\"nofollow noopener\">Introduction to Linux namespaces \u2013 Part 3: PID<\/a><\/p>\n<h4>mnt namespace<\/h4>\n<p>\u7c7b\u4f3c chroot\uff0c\u5c06\u4e00\u4e2a\u8fdb\u7a0b\u653e\u5230\u4e00\u4e2a\u7279\u5b9a\u7684\u76ee\u5f55\u6267\u884c\u3002mnt namespace \u5141\u8bb8\u4e0d\u540c namespace \u7684\u8fdb\u7a0b\u770b\u5230\u7684\u6587\u4ef6\u7ed3\u6784\u4e0d\u540c\uff0c\u8fd9\u6837\u6bcf\u4e2a namespace \u4e2d\u7684\u8fdb\u7a0b\u6240\u770b\u5230\u7684\u6587\u4ef6\u76ee\u5f55\u5c31\u88ab\u9694\u79bb\u5f00\u4e86\u3002\u540c chroot \u4e0d\u540c\uff0c\u6bcf\u4e2a namespace \u4e2d\u7684 container \u5728 \/proc\/mounts \u7684\u4fe1\u606f\u53ea\u5305\u542b\u6240\u5728 namespace \u7684 mount point\u3002<\/p>\n<h4>net namespace<\/h4>\n<p>\u7f51\u7edc\u9694\u79bb\u662f\u901a\u8fc7 net namespace \u5b9e\u73b0\u7684\uff0c \u6bcf\u4e2a net namespace \u6709\u72ec\u7acb\u7684 network devices, IP addresses, IP routing tables, \/proc\/net \u76ee\u5f55\u3002\u8fd9\u6837\u6bcf\u4e2a container \u7684\u7f51\u7edc\u5c31\u80fd\u9694\u79bb\u5f00\u6765\u3002 docker \u9ed8\u8ba4\u91c7\u7528 veth \u7684\u65b9\u5f0f\u5c06 container \u4e2d\u7684\u865a\u62df\u7f51\u5361\u540c host \u4e0a\u7684\u4e00\u4e2a docker bridge \u8fde\u63a5\u5728\u4e00\u8d77\u3002<\/p>\n<p>\u53c2\u8003\u6587\u6863\uff1a<a href=\"https:\/\/blog.jtlebi.fr\/2014\/01\/19\/introduction-to-linux-namespaces-part-5-net\/\" target=\"_blank\" rel=\"nofollow noopener\">Introduction to Linux namespaces \u2013 Part 5: NET<\/a><\/p>\n<h4>uts namespace<\/h4>\n<p>UTS (&#8220;UNIX Time-sharing System&#8221;) namespace \u5141\u8bb8\u6bcf\u4e2a container \u62e5\u6709\u72ec\u7acb\u7684 hostname \u548c domain name, \u4f7f\u5176\u5728\u7f51\u7edc\u4e0a\u53ef\u4ee5\u88ab\u89c6\u4f5c\u4e00\u4e2a\u72ec\u7acb\u7684\u8282\u70b9\u800c\u975e Host \u4e0a\u7684\u4e00\u4e2a\u8fdb\u7a0b\u3002<\/p>\n<p>\u53c2\u8003\u6587\u6863\uff1a<a href=\"https:\/\/blog.jtlebi.fr\/2013\/12\/22\/introduction-to-linux-namespaces-part-1-uts\/\" target=\"_blank\" rel=\"nofollow noopener\">Introduction to Linux namespaces \u2013 Part 1: UTS<\/a><\/p>\n<h4>ipc namespace<\/h4>\n<p>container \u4e2d\u8fdb\u7a0b\u4ea4\u4e92\u8fd8\u662f\u91c7\u7528 Linux \u5e38\u89c1\u7684\u8fdb\u7a0b\u95f4\u4ea4\u4e92\u65b9\u6cd5 (interprocess communication &#8211; IPC), \u5305\u62ec\u5e38\u89c1\u7684\u4fe1\u53f7\u91cf\u3001\u6d88\u606f\u961f\u5217\u548c\u5171\u4eab\u5185\u5b58\u3002\u7136\u800c\u540c VM \u4e0d\u540c\uff0ccontainer \u7684\u8fdb\u7a0b\u95f4\u4ea4\u4e92\u5b9e\u9645\u4e0a\u8fd8\u662f host \u4e0a\u5177\u6709\u76f8\u540c pid namespace \u4e2d\u7684\u8fdb\u7a0b\u95f4\u4ea4\u4e92\uff0c\u56e0\u6b64\u9700\u8981\u5728IPC\u8d44\u6e90\u7533\u8bf7\u65f6\u52a0\u5165 namespace \u4fe1\u606f &#8211; \u6bcf\u4e2a IPC \u8d44\u6e90\u6709\u4e00\u4e2a\u552f\u4e00\u7684 32bit ID\u3002<\/p>\n<p>\u53c2\u8003\u6587\u6863\uff1a<a href=\"https:\/\/blog.jtlebi.fr\/2013\/12\/28\/introduction-to-linux-namespaces-part-2-ipc\/\" target=\"_blank\" rel=\"nofollow noopener\">Introduction to Linux namespaces \u2013 Part 2: IPC<\/a><\/p>\n<h4>user namespace<\/h4>\n<p>\u6bcf\u4e2a container \u53ef\u4ee5\u6709\u4e0d\u540c\u7684 user \u548c group id, \u4e5f\u5c31\u662f\u8bf4\u53ef\u4ee5\u4ee5 container \u5185\u90e8\u7684\u7528\u6237\u5728 container \u5185\u90e8\u6267\u884c\u7a0b\u5e8f\u800c\u975e Host \u4e0a\u7684\u7528\u6237\u3002<\/p>\n<p>\u6709\u4e86\u4ee5\u4e0a 6 \u79cd namespace \u4ece\u8fdb\u7a0b\u3001\u7f51\u7edc\u3001IPC\u3001\u6587\u4ef6\u7cfb\u7edf\u3001UTS \u548c\u7528\u6237\u89d2\u5ea6\u7684\u9694\u79bb\uff0c\u4e00\u4e2a container \u5c31\u53ef\u4ee5\u5bf9\u5916\u5c55\u73b0\u51fa\u4e00\u4e2a\u72ec\u7acb\u8ba1\u7b97\u673a\u7684\u80fd\u529b\uff0c\u5e76\u4e14\u4e0d\u540c container \u4ece OS \u5c42\u9762\u5b9e\u73b0\u4e86\u9694\u79bb\u3002 \u7136\u800c\u4e0d\u540c namespace \u4e4b\u95f4\u8d44\u6e90\u8fd8\u662f\u76f8\u4e92\u7ade\u4e89\u7684\uff0c\u4ecd\u7136\u9700\u8981\u7c7b\u4f3c ulimit \u6765\u7ba1\u7406\u6bcf\u4e2a container \u6240\u80fd\u4f7f\u7528\u7684\u8d44\u6e90 &#8211; cgroup\u3002<\/p>\n<h4>Reference<\/h4>\n<ul>\n<li><a href=\"http:\/\/tiewei.github.io\/cloud\/Docker-Getting-Start\/\" target=\"_blank\" rel=\"nofollow noopener\">Docker Getting Start: Related Knowledge<\/a><\/li>\n<li><a href=\"https:\/\/ruby-china.org\/topics\/22004\" target=\"_blank\" rel=\"nofollow noopener\">Docker \u4ecb\u7ecd\u4ee5\u53ca\u5176\u76f8\u5173\u672f\u8bed\u3001\u5e95\u5c42\u539f\u7406\u548c\u6280\u672f<\/a><\/li>\n<\/ul>\n<h3 id=\"articleHeader6\"><a name=\"t6\"><\/a>1.6 \u8d44\u6e90\u914d\u989d\u300ccgroups\u300d<\/h3>\n<p>cgroups \u5b9e\u73b0\u4e86\u5bf9\u8d44\u6e90\u7684\u914d\u989d\u548c\u5ea6\u91cf\u3002 cgroups \u7684\u4f7f\u7528\u975e\u5e38\u7b80\u5355\uff0c\u63d0\u4f9b\u7c7b\u4f3c\u6587\u4ef6\u7684\u63a5\u53e3\uff0c\u5728 \/cgroup \u76ee\u5f55\u4e0b\u65b0\u5efa\u4e00\u4e2a\u6587\u4ef6\u5939\u5373\u53ef\u65b0\u5efa\u4e00\u4e2a group\uff0c\u5728\u6b64\u6587\u4ef6\u5939\u4e2d\u65b0\u5efa task \u6587\u4ef6\uff0c\u5e76\u5c06 pid \u5199\u5165\u8be5\u6587\u4ef6\uff0c\u5373\u53ef\u5b9e\u73b0\u5bf9\u8be5\u8fdb\u7a0b\u7684\u8d44\u6e90\u63a7\u5236\u3002\u5177\u4f53\u7684\u8d44\u6e90\u914d\u7f6e\u9009\u9879\u53ef\u4ee5\u5728\u8be5\u6587\u4ef6\u5939\u4e2d\u65b0\u5efa\u5b50 subsystem \uff0c{\u5b50\u7cfb\u7edf\u524d\u7f00}.{\u8d44\u6e90\u9879} \u662f\u5178\u578b\u7684\u914d\u7f6e\u65b9\u6cd5\uff0c \u5982 memory.usageinbytes \u5c31\u5b9a\u4e49\u4e86\u8be5 group \u5728 subsystem memory \u4e2d\u7684\u4e00\u4e2a\u5185\u5b58\u9650\u5236\u9009\u9879\u3002 \u53e6\u5916\uff0ccgroups \u4e2d\u7684 subsystem \u53ef\u4ee5\u968f\u610f\u7ec4\u5408\uff0c\u4e00\u4e2a subsystem \u53ef\u4ee5\u5728\u4e0d\u540c\u7684 group \u4e2d\uff0c\u4e5f\u53ef\u4ee5\u4e00\u4e2a group \u5305\u542b\u591a\u4e2a subsystem &#8211; \u4e5f\u5c31\u662f\u8bf4\u4e00\u4e2a subsystem\u3002<\/p>\n<ul>\n<li>memory\n<ul>\n<li>\u5185\u5b58\u76f8\u5173\u7684\u9650\u5236<\/li>\n<\/ul>\n<\/li>\n<li>cpu\n<ul>\n<li>\u5728 cgroup \u4e2d\uff0c\u5e76\u4e0d\u80fd\u50cf\u786c\u4ef6\u865a\u62df\u5316\u65b9\u6848\u4e00\u6837\u80fd\u591f\u5b9a\u4e49 CPU \u80fd\u529b\uff0c\u4f46\u662f\u80fd\u591f\u5b9a\u4e49 CPU \u8f6e\u8f6c\u7684\u4f18\u5148\u7ea7\uff0c\u56e0\u6b64\u5177\u6709\u8f83\u9ad8 CPU \u4f18\u5148\u7ea7\u7684\u8fdb\u7a0b\u4f1a\u66f4\u53ef\u80fd\u5f97\u5230 CPU \u8fd0\u7b97\u3002 \u901a\u8fc7\u5c06\u53c2\u6570\u5199\u5165 cpu.shares ,\u5373\u53ef\u5b9a\u4e49\u6539 cgroup \u7684 CPU \u4f18\u5148\u7ea7 &#8211; \u8fd9\u91cc\u662f\u4e00\u4e2a\u76f8\u5bf9\u6743\u91cd\uff0c\u800c\u975e\u7edd\u5bf9\u503c<\/li>\n<\/ul>\n<\/li>\n<li>blkio\n<ul>\n<li>block IO \u76f8\u5173\u7684\u7edf\u8ba1\u548c\u9650\u5236\uff0cbyte\/operation \u7edf\u8ba1\u548c\u9650\u5236 (IOPS \u7b49)\uff0c\u8bfb\u5199\u901f\u5ea6\u9650\u5236\u7b49\uff0c\u4f46\u662f\u8fd9\u91cc\u4e3b\u8981\u7edf\u8ba1\u7684\u90fd\u662f\u540c\u6b65 IO<\/li>\n<\/ul>\n<\/li>\n<li>devices\n<ul>\n<li>\u8bbe\u5907\u6743\u9650\u9650\u5236<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>\u53c2\u8003\u6587\u6863\uff1a<a href=\"http:\/\/tiewei.github.io\/devops\/howto-use-cgroup\/\" target=\"_blank\" rel=\"nofollow noopener\">how to use cgroup<\/a><\/p>\n<h2 id=\"articleHeader7\"><a name=\"t7\"><\/a>\u4e8c\u3001Docker \u5b89\u88c5<\/h2>\n<p>docker \u7684\u76f8\u5173\u5b89\u88c5\u65b9\u6cd5\u8fd9\u91cc\u4e0d\u4f5c\u4ecb\u7ecd\uff0c\u5177\u4f53\u5b89\u88c5\u53c2\u8003\u00a0<a href=\"https:\/\/docs.docker.com\/installation\/\" target=\"_blank\" rel=\"nofollow noopener\">\u5b98\u6863<\/a><\/p>\n<p>\u83b7\u53d6\u5f53\u524d docker \u7248\u672c<\/p>\n<div>\n<pre>$ sudo docker version\r\nClient version: 1.3.2\r\nClient API version: 1.15\r\nGo version (client): go1.3.3\r\nGit commit (client): 39fa2fa\/1.3.2\r\nOS\/Arch (client): linux\/amd64\r\nServer version: 1.3.2\r\nServer API version: 1.15\r\nGo version (server): go1.3.3\r\nGit commit (server): 39fa2fa\/1.3.2<\/pre>\n<\/div>\n<h2 id=\"articleHeader8\"><a name=\"t8\"><\/a>\u4e09\u3001Docker \u57fa\u7840\u7528\u6cd5<\/h2>\n<p><a href=\"https:\/\/registry.hub.docker.com\/\" target=\"_blank\" rel=\"nofollow noopener\">Docker HUB<\/a>\u00a0: Docker\u955c\u50cf\u9996\u9875\uff0c\u5305\u62ec\u5b98\u65b9\u955c\u50cf\u548c\u5176\u5b83\u516c\u5f00\u955c\u50cf<\/p>\n<p>\u56e0\u4e3a\u56fd\u60c5\u7684\u539f\u56e0\uff0c\u56fd\u5185\u4e0b\u8f7d Docker HUB \u5b98\u65b9\u7684\u76f8\u5173\u955c\u50cf\u6bd4\u8f83\u6162\uff0c\u53ef\u4ee5\u4f7f\u7528\u00a0<a href=\"http:\/\/opskumu.github.io\/docker.cn\" target=\"_blank\" rel=\"nofollow noopener\">docker.cn<\/a>\u00a0\u955c\u50cf\uff0c\u955c\u50cf\u4fdd\u6301\u548c\u5b98\u65b9\u4e00\u81f4\uff0c\u5173\u952e\u662f\u901f\u5ea6\u5757\uff0c\u63a8\u8350\u4f7f\u7528\u3002<\/p>\n<h3 id=\"articleHeader9\"><a name=\"t9\"><\/a>3.1 Search images<\/h3>\n<div>\n<pre>$ sudo docker search ubuntu<\/pre>\n<\/div>\n<h3 id=\"articleHeader10\"><a name=\"t10\"><\/a>3.2 Pull images<\/h3>\n<div>\n<pre>$ sudo docker pull ubuntu # \u83b7\u53d6 ubuntu \u5b98\u65b9\u955c\u50cf $ sudo docker images # \u67e5\u770b\u5f53\u524d\u955c\u50cf\u5217\u8868<\/pre>\n<\/div>\n<h3 id=\"articleHeader11\"><a name=\"t11\"><\/a>3.3 Running an interactive shell<\/h3>\n<div>\n<pre>$ sudo docker run -i -t ubuntu:14.04 \/bin\/bash<\/pre>\n<\/div>\n<ul>\n<li>docker run &#8211; \u8fd0\u884c\u4e00\u4e2a\u5bb9\u5668<\/li>\n<li>-t &#8211; \u5206\u914d\u4e00\u4e2a\uff08\u4f2a\uff09tty (link is external)<\/li>\n<li>-i &#8211; \u4ea4\u4e92\u6a21\u5f0f (so we can interact with it)<\/li>\n<li>ubuntu:14.04 &#8211; \u4f7f\u7528 ubuntu \u57fa\u7840\u955c\u50cf 14.04<\/li>\n<li>\/bin\/bash &#8211; \u8fd0\u884c\u547d\u4ee4 bash shell<\/li>\n<\/ul>\n<p>\u6ce8: ubuntu \u4f1a\u6709\u591a\u4e2a\u7248\u672c\uff0c\u901a\u8fc7\u6307\u5b9a tag \u6765\u542f\u52a8\u7279\u5b9a\u7684\u7248\u672c [image]:[tag]<\/p>\n<div>\n<pre>$ sudo docker ps # \u67e5\u770b\u5f53\u524d\u8fd0\u884c\u7684\u5bb9\u5668, ps -a \u5217\u51fa\u5f53\u524d\u7cfb\u7edf\u6240\u6709\u7684\u5bb9\u5668 CONTAINER ID        IMAGE               COMMAND             CREATED             STATUS              PORTS               NAMES\r\n6c9129e9df10        ubuntu:14.04        \/bin\/bash 6 minutes ago       Up 6 minutes                            cranky_babbage<\/pre>\n<\/div>\n<h3 id=\"articleHeader12\"><a name=\"t12\"><\/a>3.4 \u76f8\u5173\u5feb\u6377\u952e<\/h3>\n<ul>\n<li>\u9000\u51fa\uff1aCtrl-Dorexit<\/li>\n<li>detach\uff1aCtrl-P + Ctrl-Q<\/li>\n<li>attach:docker attach CONTAINER-ID<\/li>\n<\/ul>\n<h2 id=\"articleHeader13\"><a name=\"t13\"><\/a>\u56db\u3001Docker \u547d\u4ee4\u5e2e\u52a9<\/h2>\n<h3 id=\"articleHeader14\"><a name=\"t14\"><\/a>4.1 docker help<\/h3>\n<h4>docker command<\/h4>\n<div>\n<pre>$ sudo docker   # docker \u547d\u4ee4\u5e2e\u52a9\r\n\r\nCommands:\r\n    attach    Attach to a running container                 # \u5f53\u524d shell \u4e0b attach \u8fde\u63a5\u6307\u5b9a\u8fd0\u884c\u955c\u50cf\r\n    build     Build an image from a Dockerfile              # \u901a\u8fc7 Dockerfile \u5b9a\u5236\u955c\u50cf\r\n    commit    Create a new image from a container's changes # \u63d0\u4ea4\u5f53\u524d\u5bb9\u5668\u4e3a\u65b0\u7684\u955c\u50cf\r\n    cp        Copy files\/folders from the containers filesystem to the host path\r\n              # \u4ece\u5bb9\u5668\u4e2d\u62f7\u8d1d\u6307\u5b9a\u6587\u4ef6\u6216\u8005\u76ee\u5f55\u5230\u5bbf\u4e3b\u673a\u4e2d\r\n    create    Create a new container                        # \u521b\u5efa\u4e00\u4e2a\u65b0\u7684\u5bb9\u5668\uff0c\u540c run\uff0c\u4f46\u4e0d\u542f\u52a8\u5bb9\u5668\r\n    diff      Inspect changes on a container's filesystem   # \u67e5\u770b docker \u5bb9\u5668\u53d8\u5316\r\n    events    Get real time events from the server          # \u4ece docker \u670d\u52a1\u83b7\u53d6\u5bb9\u5668\u5b9e\u65f6\u4e8b\u4ef6\r\n    exec      Run a command in an existing container        # \u5728\u5df2\u5b58\u5728\u7684\u5bb9\u5668\u4e0a\u8fd0\u884c\u547d\u4ee4\r\n    export    Stream the contents of a container as a tar archive   \r\n              # \u5bfc\u51fa\u5bb9\u5668\u7684\u5185\u5bb9\u6d41\u4f5c\u4e3a\u4e00\u4e2a tar \u5f52\u6863\u6587\u4ef6[\u5bf9\u5e94 import ]\r\n    history   Show the history of an image                  # \u5c55\u793a\u4e00\u4e2a\u955c\u50cf\u5f62\u6210\u5386\u53f2\r\n    images    List images                                   # \u5217\u51fa\u7cfb\u7edf\u5f53\u524d\u955c\u50cf\r\n    import    Create a new filesystem image from the contents of a tarball  \r\n              # \u4ecetar\u5305\u4e2d\u7684\u5185\u5bb9\u521b\u5efa\u4e00\u4e2a\u65b0\u7684\u6587\u4ef6\u7cfb\u7edf\u6620\u50cf[\u5bf9\u5e94 export]\r\n    info      Display system-wide information               # \u663e\u793a\u7cfb\u7edf\u76f8\u5173\u4fe1\u606f\r\n    inspect   Return low-level information on a container   # \u67e5\u770b\u5bb9\u5668\u8be6\u7ec6\u4fe1\u606f\r\n    kill      Kill a running container                      # kill \u6307\u5b9a docker \u5bb9\u5668\r\n    load      Load an image from a tar archive              # \u4ece\u4e00\u4e2a tar \u5305\u4e2d\u52a0\u8f7d\u4e00\u4e2a\u955c\u50cf[\u5bf9\u5e94 save]\r\n    login     Register or Login to the docker registry server   \r\n              # \u6ce8\u518c\u6216\u8005\u767b\u9646\u4e00\u4e2a docker \u6e90\u670d\u52a1\u5668\r\n    logout    Log out from a Docker registry server         # \u4ece\u5f53\u524d Docker registry \u9000\u51fa\r\n    logs      Fetch the logs of a container                 # \u8f93\u51fa\u5f53\u524d\u5bb9\u5668\u65e5\u5fd7\u4fe1\u606f\r\n    port      Lookup the public-facing port which is NAT-ed to PRIVATE_PORT\r\n              # \u67e5\u770b\u6620\u5c04\u7aef\u53e3\u5bf9\u5e94\u7684\u5bb9\u5668\u5185\u90e8\u6e90\u7aef\u53e3\r\n    pause     Pause all processes within a container        # \u6682\u505c\u5bb9\u5668\r\n    ps        List containers                               # \u5217\u51fa\u5bb9\u5668\u5217\u8868\r\n    pull      Pull an image or a repository from the docker registry server\r\n              # \u4ecedocker\u955c\u50cf\u6e90\u670d\u52a1\u5668\u62c9\u53d6\u6307\u5b9a\u955c\u50cf\u6216\u8005\u5e93\u955c\u50cf\r\n    push      Push an image or a repository to the docker registry server\r\n              # \u63a8\u9001\u6307\u5b9a\u955c\u50cf\u6216\u8005\u5e93\u955c\u50cf\u81f3docker\u6e90\u670d\u52a1\u5668\r\n    restart   Restart a running container                   # \u91cd\u542f\u8fd0\u884c\u7684\u5bb9\u5668\r\n    rm        Remove one or more containers                 # \u79fb\u9664\u4e00\u4e2a\u6216\u8005\u591a\u4e2a\u5bb9\u5668\r\n    rmi       Remove one or more images                 \r\n              # \u79fb\u9664\u4e00\u4e2a\u6216\u591a\u4e2a\u955c\u50cf[\u65e0\u5bb9\u5668\u4f7f\u7528\u8be5\u955c\u50cf\u624d\u53ef\u5220\u9664\uff0c\u5426\u5219\u9700\u5220\u9664\u76f8\u5173\u5bb9\u5668\u624d\u53ef\u7ee7\u7eed\u6216 -f \u5f3a\u5236\u5220\u9664]\r\n    run       Run a command in a new container\r\n              # \u521b\u5efa\u4e00\u4e2a\u65b0\u7684\u5bb9\u5668\u5e76\u8fd0\u884c\u4e00\u4e2a\u547d\u4ee4\r\n    save      Save an image to a tar archive                # \u4fdd\u5b58\u4e00\u4e2a\u955c\u50cf\u4e3a\u4e00\u4e2a tar \u5305[\u5bf9\u5e94 load]\r\n    search    Search for an image on the Docker Hub         # \u5728 docker hub \u4e2d\u641c\u7d22\u955c\u50cf\r\n    start     Start a stopped containers                    # \u542f\u52a8\u5bb9\u5668\r\n    stop      Stop a running containers                     # \u505c\u6b62\u5bb9\u5668\r\n    tag       Tag an image into a repository                # \u7ed9\u6e90\u4e2d\u955c\u50cf\u6253\u6807\u7b7e\r\n    top       Lookup the running processes of a container   # \u67e5\u770b\u5bb9\u5668\u4e2d\u8fd0\u884c\u7684\u8fdb\u7a0b\u4fe1\u606f\r\n    unpause   Unpause a paused container                    # \u53d6\u6d88\u6682\u505c\u5bb9\u5668\r\n    version   Show the docker version information           # \u67e5\u770b docker \u7248\u672c\u53f7\r\n    wait      Block until a container stops, then print its exit code   \r\n              # \u622a\u53d6\u5bb9\u5668\u505c\u6b62\u65f6\u7684\u9000\u51fa\u72b6\u6001\u503c\r\nRun 'docker COMMAND --help' for more information on a command.<\/pre>\n<\/div>\n<h4>docker option<\/h4>\n<div>\n<pre>Usage of docker:\r\n  --api-enable-cors=false                Enable CORS headers in the remote API                      # \u8fdc\u7a0b API \u4e2d\u5f00\u542f CORS \u5934\r\n  -b, --bridge=\"\"                        Attach containers to a pre-existing network bridge         # \u6865\u63a5\u7f51\u7edc\r\n                                           use 'none' to disable container networking\r\n  --bip=\"\"                               Use this CIDR notation address for the network bridge's IP, not compatible with -b\r\n                                         # \u548c -b \u9009\u9879\u4e0d\u517c\u5bb9\uff0c\u5177\u4f53\u6ca1\u6709\u6d4b\u8bd5\u8fc7\r\n  -d, --daemon=false                     Enable daemon mode                                         # daemon \u6a21\u5f0f\r\n  -D, --debug=false                      Enable debug mode                                          # debug \u6a21\u5f0f\r\n  --dns=[]                               Force docker to use specific DNS servers                   # \u5f3a\u5236 docker \u4f7f\u7528\u6307\u5b9a dns \u670d\u52a1\u5668\r\n  --dns-search=[]                        Force Docker to use specific DNS search domains            # \u5f3a\u5236 docker \u4f7f\u7528\u6307\u5b9a dns \u641c\u7d22\u57df\r\n  -e, --exec-driver=\"native\"             Force the docker runtime to use a specific exec driver     # \u5f3a\u5236 docker \u8fd0\u884c\u65f6\u4f7f\u7528\u6307\u5b9a\u6267\u884c\u9a71\u52a8\u5668\r\n  --fixed-cidr=\"\"                        IPv4 subnet for fixed IPs (ex: 10.20.0.0\/16)\r\n                                           this subnet must be nested in the bridge subnet (which is defined by -b or --bip)\r\n  -G, --group=\"docker\"                   Group to assign the unix socket specified by -H when running in daemon mode\r\n                                           use '' (the empty string) to disable setting of a group\r\n  -g, --graph=\"\/var\/lib\/docker\"          Path to use as the root of the docker runtime              # \u5bb9\u5668\u8fd0\u884c\u7684\u6839\u76ee\u5f55\u8def\u5f84\r\n  -H, --host=[]                          The socket(s) to bind to in daemon mode                    # daemon \u6a21\u5f0f\u4e0b docker \u6307\u5b9a\u7ed1\u5b9a\u65b9\u5f0f[tcp or \u672c\u5730 socket]\r\n                                           specified using one or more tcp:\/\/host:port, unix:\/\/\/path\/to\/socket, fd:\/\/* or fd:\/\/socketfd.\r\n  --icc=true                             Enable inter-container communication                       # \u8de8\u5bb9\u5668\u901a\u4fe1\r\n  --insecure-registry=[]                 Enable insecure communication with specified registries (no certificate verification for HTTPS and enable HTTP fallback) (e.g., localhost:5000 or 10.20.0.0\/16)\r\n  --ip=\"0.0.0.0\"                         Default IP address to use when binding container ports     # \u6307\u5b9a\u76d1\u542c\u5730\u5740\uff0c\u9ed8\u8ba4\u6240\u6709 ip\r\n  --ip-forward=true                      Enable net.ipv4.ip_forward                                 # \u5f00\u542f\u8f6c\u53d1\r\n  --ip-masq=true                         Enable IP masquerading for bridge's IP range\r\n  --iptables=true                        Enable Docker's addition of iptables rules                 # \u6dfb\u52a0\u5bf9\u5e94 iptables \u89c4\u5219\r\n  --mtu=0                                Set the containers network MTU                             # \u8bbe\u7f6e\u7f51\u7edc mtu\r\n                                           if no value is provided: default to the default route MTU or 1500 if no default route is available\r\n  -p, --pidfile=\"\/var\/run\/docker.pid\"    Path to use for daemon PID file                            # \u6307\u5b9a pid \u6587\u4ef6\u4f4d\u7f6e\r\n  --registry-mirror=[]                   Specify a preferred Docker registry mirror                  \r\n  -s, --storage-driver=\"\"                Force the docker runtime to use a specific storage driver  # \u5f3a\u5236 docker \u8fd0\u884c\u65f6\u4f7f\u7528\u6307\u5b9a\u5b58\u50a8\u9a71\u52a8\r\n  --selinux-enabled=false                Enable selinux support                                     # \u5f00\u542f selinux \u652f\u6301\r\n  --storage-opt=[]                       Set storage driver options                                 # \u8bbe\u7f6e\u5b58\u50a8\u9a71\u52a8\u9009\u9879\r\n  --tls=false                            Use TLS; implied by tls-verify flags                       # \u5f00\u542f tls\r\n  --tlscacert=\"\/root\/.docker\/ca.pem\"     Trust only remotes providing a certificate signed by the CA given here\r\n  --tlscert=\"\/root\/.docker\/cert.pem\"     Path to TLS certificate file                               # tls \u8bc1\u4e66\u6587\u4ef6\u4f4d\u7f6e\r\n  --tlskey=\"\/root\/.docker\/key.pem\"       Path to TLS key file                                       # tls key \u6587\u4ef6\u4f4d\u7f6e\r\n  --tlsverify=false                      Use TLS and verify the remote (daemon: verify client, client: verify daemon) # \u4f7f\u7528 tls \u5e76\u786e\u8ba4\u8fdc\u7a0b\u63a7\u5236\u4e3b\u673a\r\n  -v, --version=false                    Print version information and quit                         # \u8f93\u51fa docker \u7248\u672c\u4fe1\u606f<\/pre>\n<\/div>\n<h3 id=\"articleHeader15\"><a name=\"t15\"><\/a>4.2 docker search<\/h3>\n<div>\n<pre>$ sudo docker search --help\r\n\r\nUsage: docker search TERM\r\n\r\nSearch the Docker Hub for images # \u4ece Docker Hub \u641c\u7d22\u955c\u50cf --automated=false Only show automated builds\r\n  --no-trunc=false Don't truncate output\r\n  -s, --stars=0 Only displays with at least xxx stars<\/pre>\n<\/div>\n<p>\u793a\u4f8b\uff1a<\/p>\n<div>\n<pre>$ sudo docker search -s 100 ubuntu # \u67e5\u627e star \u6570\u81f3\u5c11\u4e3a 100 \u7684\u955c\u50cf\uff0c\u627e\u51fa\u53ea\u6709\u5b98\u65b9\u955c\u50cf start \u6570\u8d85\u8fc7 100\uff0c\u9ed8\u8ba4\u4e0d\u52a0 s \u9009\u9879\u627e\u51fa\u6240\u6709\u76f8\u5173 ubuntu \u955c\u50cf NAME      DESCRIPTION                  STARS     OFFICIAL   AUTOMATED\r\nubuntu    Official Ubuntu base image 425 [OK]<\/pre>\n<\/div>\n<h3 id=\"articleHeader16\"><a name=\"t16\"><\/a>4.3 docker info<\/h3>\n<div>\n<pre>$ sudo docker info \r\nContainers: 1 # \u5bb9\u5668\u4e2a\u6570 Images: 22 # \u955c\u50cf\u4e2a\u6570 Storage Driver: devicemapper # \u5b58\u50a8\u9a71\u52a8 Pool Name: docker-8:17-3221225728-pool\r\n Pool Blocksize: 65.54 kB\r\n Data file: \/data\/docker\/devicemapper\/devicemapper\/data\r\n Metadata file: \/data\/docker\/devicemapper\/devicemapper\/metadata\r\n Data Space Used: 1.83 GB\r\n Data Space Total: 107.4 GB\r\n Metadata Space Used: 2.191 MB\r\n Metadata Space Total: 2.147 GB\r\n Library Version: 1.02.84-RHEL7 (2014-03-26) Execution Driver: native-0.2 # \u5b58\u50a8\u9a71\u52a8 Kernel Version: 3.10.0-123.el7.x86_64\r\nOperating System: CentOS Linux 7 (Core)<\/pre>\n<\/div>\n<h3 id=\"articleHeader17\"><a name=\"t17\"><\/a>4.4 docker pull &amp;&amp; docker push<\/h3>\n<div>\n<pre>$ sudo docker pull --help # pull \u62c9\u53d6\u955c\u50cf Usage: docker pull [OPTIONS] NAME[:TAG] Pull an image or a repository from the registry\r\n\r\n  -a, --all-tags=false Download all tagged images in the repository $ sudo docker push # push \u63a8\u9001\u6307\u5b9a\u955c\u50cf Usage: docker push NAME[:TAG] Push an image or a repository to the registry<\/pre>\n<\/div>\n<p>\u793a\u4f8b\uff1a<\/p>\n<div>\n<pre>$ sudo docker pull ubuntu # \u4e0b\u8f7d\u5b98\u65b9 ubuntu docker \u955c\u50cf\uff0c\u9ed8\u8ba4\u4e0b\u8f7d\u6240\u6709 ubuntu \u5b98\u65b9\u5e93\u955c\u50cf $ sudo docker pull ubuntu:14.04 # \u4e0b\u8f7d\u6307\u5b9a\u7248\u672c ubuntu \u5b98\u65b9\u955c\u50cf<\/pre>\n<\/div>\n<div>\n<pre>$ sudo docker push 192.168.0.100:5000\/ubuntu # \u63a8\u9001\u955c\u50cf\u5e93\u5230\u79c1\u6709\u6e90[\u53ef\u6ce8\u518c docker \u5b98\u65b9\u8d26\u6237\uff0c\u63a8\u9001\u5230\u5b98\u65b9\u81ea\u6709\u8d26\u6237] $ sudo docker push 192.168.0.100:5000\/ubuntu:14.04 # \u63a8\u9001\u6307\u5b9a\u955c\u50cf\u5230\u79c1\u6709\u6e90<\/pre>\n<\/div>\n<h3 id=\"articleHeader18\"><a name=\"t18\"><\/a>4.5 docker images<\/h3>\n<p>\u5217\u51fa\u5f53\u524d\u7cfb\u7edf\u955c\u50cf<\/p>\n<div>\n<pre>$ sudo docker images --help\r\n\r\nUsage: docker images [OPTIONS] [NAME] List images\r\n\r\n  -a, --all=false Show all images (by default filter out the intermediate image layers) # -a \u663e\u793a\u5f53\u524d\u7cfb\u7edf\u7684\u6240\u6709\u955c\u50cf\uff0c\u5305\u62ec\u8fc7\u6e21\u5c42\u955c\u50cf\uff0c\u9ed8\u8ba4 docker images \u663e\u793a\u6700\u7ec8\u955c\u50cf\uff0c\u4e0d\u5305\u62ec\u8fc7\u6e21\u5c42\u955c\u50cf -f, --filter=[] Provide filter values (i.e. 'dangling=true') --no-trunc=false Don't truncate output\r\n  -q, --quiet=false Only show numeric IDs<\/pre>\n<\/div>\n<p>\u793a\u4f8b\uff1a<\/p>\n<div>\n<pre>$ sudo docker images # \u663e\u793a\u5f53\u524d\u7cfb\u7edf\u955c\u50cf\uff0c\u4e0d\u5305\u62ec\u8fc7\u6e21\u5c42\u955c\u50cf $ sudo docker images -a # \u663e\u793a\u5f53\u524d\u7cfb\u7edf\u6240\u6709\u955c\u50cf\uff0c\u5305\u62ec\u8fc7\u6e21\u5c42\u955c\u50cf $ sudo docker images ubuntu # \u663e\u793a\u5f53\u524d\u7cfb\u7edf docker ubuntu \u5e93\u4e2d\u7684\u6240\u6709\u955c\u50cf REPOSITORY                 TAG                 IMAGE ID            CREATED             VIRTUAL SIZE\r\nubuntu                     12.04               ebe4be4dd427 4 weeks ago         210.6 MB\r\nubuntu                     14.04               e54ca5efa2e9 4 weeks ago         276.5 MB\r\nubuntu                     14.04-ssh           6334d3ac099a 7 weeks ago         383.2 MB<\/pre>\n<\/div>\n<h3 id=\"articleHeader19\"><a name=\"t19\"><\/a>4.6 docker rmi<\/h3>\n<p>\u5220\u9664\u4e00\u4e2a\u6216\u8005\u591a\u4e2a\u955c\u50cf<\/p>\n<div>\n<pre>$ sudo docker rmi --help\r\n\r\nUsage: docker rmi IMAGE [IMAGE...] Remove one or more images\r\n\r\n  -f, --force=false Force removal of the image # \u5f3a\u5236\u79fb\u9664\u955c\u50cf\u4e0d\u7ba1\u662f\u5426\u6709\u5bb9\u5668\u4f7f\u7528\u8be5\u955c\u50cf --no-prune=false Do not delete untagged parents # \u4e0d\u8981\u5220\u9664\u672a\u6807\u8bb0\u7684\u7236\u955c\u50cf<\/pre>\n<\/div>\n<h3 id=\"articleHeader20\"><a name=\"t20\"><\/a>4.7 docker run<\/h3>\n<div>\n<pre>$ sudo docker run --help\r\n\r\nUsage: docker run [OPTIONS] IMAGE [COMMAND] [ARG...] Run a command in a new container\r\n\r\n  -a, --attach=[] Attach to stdin, stdout or stderr.\r\n  -c, --cpu-shares=0 CPU shares (relative weight) # \u8bbe\u7f6e cpu \u4f7f\u7528\u6743\u91cd --cap-add=[] Add Linux capabilities\r\n  --cap-drop=[] Drop Linux capabilities\r\n  --cidfile=\"\" Write the container ID to the file # \u628a\u5bb9\u5668 id \u5199\u5165\u5230\u6307\u5b9a\u6587\u4ef6 --cpuset=\"\" CPUs in which to allow execution (0-3, 0,1) # cpu \u7ed1\u5b9a -d, --detach=false Detached mode: Run container in the background, print new container id # \u540e\u53f0\u8fd0\u884c\u5bb9\u5668 --device=[] Add a host device to the container (e.g. --device=\/dev\/sdc:\/dev\/xvdc) --dns=[] Set custom dns servers # \u8bbe\u7f6e dns --dns-search=[] Set custom dns search domains # \u8bbe\u7f6e dns \u57df\u641c\u7d22 -e, --env=[] Set environment variables # \u5b9a\u4e49\u73af\u5883\u53d8\u91cf --entrypoint=\"\" Overwrite the default entrypoint of the image # \uff1f --env-file=[] Read in a line delimited file of ENV variables # \u4ece\u6307\u5b9a\u6587\u4ef6\u8bfb\u53d6\u53d8\u91cf\u503c --expose=[] Expose a port from the container without publishing it to your host # \u6307\u5b9a\u5bf9\u5916\u63d0\u4f9b\u670d\u52a1\u7aef\u53e3 -h, --hostname=\"\" Container host name # \u8bbe\u7f6e\u5bb9\u5668\u4e3b\u673a\u540d -i, --interactive=false Keep stdin open even if not attached # \u4fdd\u6301\u6807\u51c6\u8f93\u51fa\u5f00\u542f\u5373\u4f7f\u6ca1\u6709 attached --link=[] Add link to another container (name:alias) # \u6dfb\u52a0\u94fe\u63a5\u5230\u53e6\u5916\u4e00\u4e2a\u5bb9\u5668 --lxc-conf=[] (lxc exec-driver only) Add custom lxc options --lxc-conf=\"lxc.cgroup.cpuset.cpus = 0,1\" -m, --memory=\"\" Memory limit (format: &lt;number&gt;&lt;optional unit&gt;, where unit = b, k, m or g) # \u5185\u5b58\u9650\u5236 --name=\"\" Assign a name to the container # \u8bbe\u7f6e\u5bb9\u5668\u540d --net=\"bridge\" Set the Network mode for the container # \u8bbe\u7f6e\u5bb9\u5668\u7f51\u7edc\u6a21\u5f0f 'bridge': creates a new network stack for the container on the docker bridge 'none': no networking for this container 'container:&lt;name|id&gt;': reuses another container network stack 'host': use the host network stack inside the container.  Note: the host mode gives the container full access to local system services such as D-bus and is therefore considered insecure.\r\n  -P, --publish-all=false Publish all exposed ports to the host interfaces # \u81ea\u52a8\u6620\u5c04\u5bb9\u5668\u5bf9\u5916\u63d0\u4f9b\u670d\u52a1\u7684\u7aef\u53e3 -p, --publish=[] Publish a container's port to the host             # \u6307\u5b9a\u7aef\u53e3\u6620\u5c04  format: ip:hostPort:containerPort | ip::containerPort | hostPort:containerPort  (use 'docker port' to see the actual mapping) --privileged=false Give extended privileges to this container # \u63d0\u4f9b\u66f4\u591a\u7684\u6743\u9650\u7ed9\u5bb9\u5668 --restart=\"\" Restart policy to apply when a container exits (no, on-failure[:max-retry], always) --rm=false Automatically remove the container when it exits (incompatible with -d) # \u5982\u679c\u5bb9\u5668\u9000\u51fa\u81ea\u52a8\u79fb\u9664\u548c -d \u9009\u9879\u51b2\u7a81 --security-opt=[] Security Options\r\n  --sig-proxy=true Proxify received signals to the process (even in non-tty mode). SIGCHLD is not proxied.\r\n  -t, --tty=false Allocate a pseudo-tty # \u5206\u914d\u4f2a\u7ec8\u7aef -u, --user=\"\" Username or UID # \u6307\u5b9a\u8fd0\u884c\u5bb9\u5668\u7684\u7528\u6237 uid \u6216\u8005\u7528\u6237\u540d -v, --volume=[] Bind mount a volume (e.g., from the host: -v \/host:\/container, from docker: -v \/container) # \u6302\u8f7d\u5377 --volumes-from=[] Mount volumes from the specified container(s) # \u4ece\u6307\u5b9a\u5bb9\u5668\u6302\u8f7d\u5377 -w, --workdir=\"\" Working directory inside the container # \u6307\u5b9a\u5bb9\u5668\u5de5\u4f5c\u76ee\u5f55<\/pre>\n<\/div>\n<p>\u793a\u4f8b\uff1a<\/p>\n<div>\n<pre>$ sudo docker images ubuntu\r\nREPOSITORY          TAG                 IMAGE ID            CREATED             VIRTUAL SIZE\r\nubuntu              14.04               e54ca5efa2e9 4 weeks ago         276.5 MB\r\n... ... $ sudo docker run -t -i -c 100 -m 512MB -h test1 -d --name=\"docker_test1\" ubuntu \/bin\/bash # \u521b\u5efa\u4e00\u4e2a cpu \u4f18\u5148\u7ea7\u4e3a 100\uff0c\u5185\u5b58\u9650\u5236 512MB\uff0c\u4e3b\u673a\u540d\u4e3a test1\uff0c\u540d\u4e3a docker_test1 \u540e\u53f0\u8fd0\u884c bash \u7684\u5bb9\u5668 a424ca613c9f2247cd3ede95adfbaf8d28400cbcb1d5f9b69a7b56f97b2b52e5 $ sudo docker ps \r\nCONTAINER ID        IMAGE           COMMAND         CREATED             STATUS              PORTS       NAMES\r\na424ca613c9f        ubuntu:14.04    \/bin\/bash 6 seconds ago       Up 5 seconds                    docker_test1 $ sudo docker attach docker_test1\r\nroot@test1:\/# pwd \/\r\nroot@test1:\/# exit exit<\/pre>\n<\/div>\n<p>\u5173\u4e8ecpu\u4f18\u5148\u7ea7:<\/p>\n<blockquote><p>By default all groups have 1024 shares. A group with 100 shares will get a ~10% portion of the CPU time &#8211;<a href=\"https:\/\/wiki.archlinux.org\/index.php\/cgroups\" target=\"_blank\" rel=\"nofollow noopener\">archlinux cgroups<\/a><\/p><\/blockquote>\n<h3 id=\"articleHeader21\"><a name=\"t21\"><\/a>4.8 docker start|stop|kill&#8230; &#8230;<\/h3>\n<p>dockerstart|stop|kill|restart|pause|unpause|rm|commit|inspect|logs<\/p>\n<ul>\n<li>docker start CONTAINER [CONTAINER&#8230;]\n<ul>\n<li># \u8fd0\u884c\u4e00\u4e2a\u6216\u591a\u4e2a\u505c\u6b62\u7684\u5bb9\u5668<\/li>\n<\/ul>\n<\/li>\n<li>docker stop CONTAINER [CONTAINER&#8230;]\n<ul>\n<li># \u505c\u6389\u4e00\u4e2a\u6216\u591a\u4e2a\u8fd0\u884c\u7684\u5bb9\u5668-t\u9009\u9879\u53ef\u6307\u5b9a\u8d85\u65f6\u65f6\u95f4<\/li>\n<\/ul>\n<\/li>\n<li>docker kill [OPTIONS] CONTAINER [CONTAINER&#8230;]\n<ul>\n<li># \u9ed8\u8ba4 kill \u53d1\u9001 SIGKILL \u4fe1\u53f7-s\u53ef\u4ee5\u6307\u5b9a\u53d1\u9001 kill \u4fe1\u53f7\u7c7b\u578b<\/li>\n<\/ul>\n<\/li>\n<li>docker restart [OPTIONS] CONTAINER [CONTAINER&#8230;]\n<ul>\n<li># \u91cd\u542f\u4e00\u4e2a\u6216\u591a\u4e2a\u8fd0\u884c\u7684\u5bb9\u5668-t\u9009\u9879\u53ef\u6307\u5b9a\u8d85\u65f6\u65f6\u95f4<\/li>\n<\/ul>\n<\/li>\n<li>docker pause CONTAINER\n<ul>\n<li># \u6682\u505c\u4e00\u4e2a\u5bb9\u5668\uff0c\u65b9\u4fbf commit<\/li>\n<\/ul>\n<\/li>\n<li>docker unpause CONTAINER\n<ul>\n<li># \u7ee7\u7eed\u6682\u505c\u7684\u5bb9\u5668<\/li>\n<\/ul>\n<\/li>\n<li>docker rm [OPTIONS] CONTAINER [CONTAINER&#8230;]\n<ul>\n<li># \u79fb\u9664\u4e00\u4e2a\u6216\u591a\u4e2a\u5bb9\u5668<\/li>\n<li>-f, &#8211;force=false Force removal of running container<\/li>\n<li>-l, &#8211;link=false Remove the specified link and not the underlying container<\/li>\n<li>-v, &#8211;volumes=false Remove the volumes associated with the container<\/li>\n<\/ul>\n<\/li>\n<li>docker commit [OPTIONS] CONTAINER [REPOSITORY[:TAG]]\n<ul>\n<li># \u63d0\u4ea4\u6307\u5b9a\u5bb9\u5668\u4e3a\u955c\u50cf<\/li>\n<li>-a, &#8211;author=&#8221;&#8221; Author (e.g., &#8220;John Hannibal Smith\u00a0<a href=\"mailto:hannibal@a-team.com\" target=\"_blank\" rel=\"nofollow noopener\">hannibal@a-team.com<\/a>&#8220;)<\/li>\n<li>-m, &#8211;message=&#8221;&#8221; Commit message<\/li>\n<li>-p, &#8211;pause=true Pause container during commit\n<ul>\n<li># \u9ed8\u8ba4 commit \u662f\u6682\u505c\u72b6\u6001<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<li>docker inspect CONTAINER|IMAGE [CONTAINER|IMAGE&#8230;]\n<ul>\n<li># \u67e5\u770b\u5bb9\u5668\u6216\u8005\u955c\u50cf\u7684\u8be6\u7ec6\u4fe1\u606f<\/li>\n<\/ul>\n<\/li>\n<li>docker logs CONTAINER\n<ul>\n<li># \u8f93\u51fa\u6307\u5b9a\u5bb9\u5668\u65e5\u5fd7\u4fe1\u606f<\/li>\n<li>-f, &#8211;follow=false Follow log output\n<ul>\n<li># \u7c7b\u4f3c tail -f<\/li>\n<\/ul>\n<\/li>\n<li>-t, &#8211;timestamps=false Show timestamps<\/li>\n<li>&#8211;tail=&#8221;all&#8221; Output the specified number of lines at the end of logs (defaults to all logs)<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>\u53c2\u8003\u6587\u6863\uff1a<a href=\"https:\/\/docs.docker.com\/reference\/run\/\" target=\"_blank\" rel=\"nofollow noopener\">Docker Run Reference<\/a><\/p>\n<h3 id=\"articleHeader22\"><a name=\"t22\"><\/a>4.9 Docker 1.3 \u65b0\u589e\u7279\u6027\u548c\u547d\u4ee4<\/h3>\n<h4>Digital Signature Verification<\/h4>\n<p>Docker 1.3 \u7248\u672c\u5c06\u4f7f\u7528\u6570\u5b57\u7b7e\u540d\u81ea\u52a8\u9a8c\u8bc1\u6240\u6709\u5b98\u65b9\u5e93\u7684\u6765\u6e90\u548c\u5b8c\u6574\u6027\uff0c\u5982\u679c\u4e00\u4e2a\u5b98\u65b9\u955c\u50cf\u88ab\u7be1\u6539\u6216\u8005\u88ab\u7834\u574f\uff0c\u76ee\u524d Docker \u53ea\u4f1a\u5bf9\u8fd9\u79cd\u60c5\u51b5\u53d1\u51fa\u8b66\u544a\u800c\u5e76\u4e0d\u963b\u6b62\u5bb9\u5668\u7684\u8fd0\u884c\u3002<\/p>\n<h4>Inject new processes withdocker exec<\/h4>\n<div>\n<pre>docker exec --help\r\n\r\nUsage: docker exec [OPTIONS] CONTAINER COMMAND [ARG...] Run a command in an existing container\r\n\r\n  -d, --detach=false Detached mode: run command in the background\r\n  -i, --interactive=false Keep STDIN open even if not attached\r\n  -t, --tty=false Allocate a pseudo-TTY<\/pre>\n<\/div>\n<p>\u4e3a\u4e86\u7b80\u5316\u8c03\u8bd5\uff0c\u53ef\u4ee5\u4f7f\u7528docker exec\u547d\u4ee4\u901a\u8fc7 Docker API \u548c CLI \u5728\u8fd0\u884c\u7684\u5bb9\u5668\u4e0a\u8fd0\u884c\u7a0b\u5e8f\u3002<\/p>\n<div>\n<pre>$ docker exec -it ubuntu_bash bash<\/pre>\n<\/div>\n<p>\u4e0a\u4f8b\u5c06\u5728\u5bb9\u5668 ubuntu_bash \u4e2d\u521b\u5efa\u4e00\u4e2a\u65b0\u7684 Bash \u4f1a\u8bdd\u3002<\/p>\n<h4>Tune container lifecycles withdocker create<\/h4>\n<p>\u6211\u4eec\u53ef\u4ee5\u901a\u8fc7docker run &lt;image name&gt;\u547d\u4ee4\u521b\u5efa\u4e00\u4e2a\u5bb9\u5668\u5e76\u8fd0\u884c\u5176\u4e2d\u7684\u7a0b\u5e8f\uff0c\u56e0\u4e3a\u6709\u5f88\u591a\u7528\u6237\u8981\u6c42\u521b\u5efa\u5bb9\u5668\u7684\u65f6\u5019\u4e0d\u542f\u52a8\u5bb9\u5668\uff0c\u6240\u4ee5docker create<a href=\"https:\/\/www.baidu.com\/s?wd=%E5%BA%94%E8%BF%90%E8%80%8C%E7%94%9F&amp;tn=24004469_oem_dg&amp;rsv_dl=gh_pl_sl_csd\" target=\"_blank\" rel=\"noopener\">\u5e94\u8fd0\u800c\u751f<\/a>\u4e86\u3002<\/p>\n<div>\n<pre>$ docker create -t -i fedora bash\r\n6d8af538ec541dd581ebc2a24153a28329acb5268abe5ef868c1f1a261221752<\/pre>\n<\/div>\n<p>\u4e0a\u4f8b\u521b\u5efa\u4e86\u4e00\u4e2a\u53ef\u5199\u7684\u5bb9\u5668\u5c42 (\u5e76\u4e14\u6253\u5370\u51fa\u5bb9\u5668 ID)\uff0c\u4f46\u662f\u5e76\u4e0d\u8fd0\u884c\u5b83\uff0c\u53ef\u4ee5\u4f7f\u7528\u4ee5\u4e0b\u547d\u4ee4\u8fd0\u884c\u8be5\u5bb9\u5668\uff1a<\/p>\n<div>\n<pre>$ docker start -a -i 6d8af538ec5\r\nbash-4.2#<\/pre>\n<\/div>\n<h4>Security Options<\/h4>\n<p>\u901a\u8fc7&#8211;security-opt\u9009\u9879\uff0c\u8fd0\u884c\u5bb9\u5668\u65f6\u7528\u6237\u53ef\u81ea\u5b9a\u4e49 SELinux \u548c AppArmor \u5377\u6807\u548c\u914d\u7f6e\u3002<\/p>\n<div>\n<pre>$ docker run --security-opt label:type:svirt_apache -i -t centos \\ bash<\/pre>\n<\/div>\n<p>\u4e0a\u4f8b\u53ea\u5141\u8bb8\u5bb9\u5668\u76d1\u542c\u5728 Apache \u7aef\u53e3\uff0c\u8fd9\u4e2a\u9009\u9879\u7684\u597d\u5904\u662f\u7528\u6237\u4e0d\u9700\u8981\u8fd0\u884c docker \u7684\u65f6\u5019\u6307\u5b9a&#8211;privileged\u9009\u9879\uff0c\u964d\u4f4e\u5b89\u5168\u98ce\u9669\u3002<\/p>\n<p>\u53c2\u8003\u6587\u6863\uff1a<a href=\"http:\/\/blog.docker.com\/2014\/10\/docker-1-3-signed-images-process-injection-security-options-mac-shared-directories\/\" target=\"_blank\" rel=\"nofollow noopener\">Docker 1.3: signed images, process injection, security options, Mac shared directories<\/a><\/p>\n<h3 id=\"articleHeader23\"><a name=\"t23\"><\/a>4.10 Docker 1.5 \u65b0\u7279\u6027<\/h3>\n<p>\u53c2\u8003\u6587\u6863\uff1a<a href=\"http:\/\/dockerone.com\/article\/202\" target=\"_blank\" rel=\"nofollow noopener\">Docker 1.5 \u65b0\u7279\u6027<\/a><\/p>\n<h2 id=\"articleHeader24\"><a name=\"t24\"><\/a>\u4e94\u3001Docker \u7aef\u53e3\u6620\u5c04<\/h2>\n<div>\n<pre># Find IP address of container with ID &lt;container_id&gt; \u901a\u8fc7\u5bb9\u5668 id \u83b7\u53d6 ip $ sudo docker inspect &lt;container_id&gt; | grep IPAddress | cut -d \u2019\"\u2019 -f 4<\/pre>\n<\/div>\n<p><a href=\"https:\/\/www.baidu.com\/s?wd=%E6%97%A0%E8%AE%BA%E5%A6%82%E4%BD%95&amp;tn=24004469_oem_dg&amp;rsv_dl=gh_pl_sl_csd\" target=\"_blank\" rel=\"noopener\">\u65e0\u8bba\u5982\u4f55<\/a>\uff0c\u8fd9\u4e9b ip \u662f\u57fa\u4e8e\u672c\u5730\u7cfb\u7edf\u7684\u5e76\u4e14\u5bb9\u5668\u7684\u7aef\u53e3\u975e\u672c\u5730\u4e3b\u673a\u662f\u8bbf\u95ee\u4e0d\u5230\u7684\u3002\u6b64\u5916\uff0c\u9664\u4e86\u7aef\u53e3\u53ea\u80fd\u672c\u5730\u8bbf\u95ee\u5916\uff0c\u5bf9\u4e8e\u5bb9\u5668\u7684\u53e6\u5916\u4e00\u4e2a\u95ee\u9898\u662f\u8fd9\u4e9b ip \u5728\u5bb9\u5668\u6bcf\u6b21\u542f\u52a8\u7684\u65f6\u5019\u90fd\u4f1a\u6539\u53d8\u3002<\/p>\n<p>Docker \u89e3\u51b3\u4e86\u5bb9\u5668\u7684\u8fd9\u4e24\u4e2a\u95ee\u9898\uff0c\u5e76\u4e14\u7ed9\u5bb9\u5668\u5185\u90e8\u670d\u52a1\u7684\u8bbf\u95ee\u63d0\u4f9b\u4e86\u4e00\u4e2a\u7b80\u5355\u800c\u53ef\u9760\u7684\u65b9\u6cd5\u3002Docker \u901a\u8fc7\u7aef\u53e3\u7ed1\u5b9a\u4e3b\u673a\u7cfb\u7edf\u7684\u63a5\u53e3\uff0c\u5141\u8bb8\u975e\u672c\u5730\u5ba2\u6237\u7aef\u8bbf\u95ee\u5bb9\u5668\u5185\u90e8\u8fd0\u884c\u7684\u670d\u52a1\u3002\u4e3a\u4e86\u7b80\u4fbf\u7684\u4f7f\u5f97\u5bb9\u5668\u95f4\u901a\u4fe1\uff0cDocker \u63d0\u4f9b\u4e86\u8fd9\u79cd\u8fde\u63a5\u673a\u5236\u3002<\/p>\n<h3 id=\"articleHeader25\"><a name=\"t25\"><\/a>5.1 \u81ea\u52a8\u6620\u5c04\u7aef\u53e3<\/h3>\n<p>-P\u4f7f\u7528\u65f6\u9700\u8981\u6307\u5b9a&#8211;expose\u9009\u9879\uff0c\u6307\u5b9a\u9700\u8981\u5bf9\u5916\u63d0\u4f9b\u670d\u52a1\u7684\u7aef\u53e3<\/p>\n<div>\n<pre>$ sudo docker run -t -P --expose 22 --name server  ubuntu:14.04<\/pre>\n<\/div>\n<p>\u4f7f\u7528docker run -P\u81ea\u52a8\u7ed1\u5b9a\u6240\u6709\u5bf9\u5916\u63d0\u4f9b\u670d\u52a1\u7684\u5bb9\u5668\u7aef\u53e3\uff0c\u6620\u5c04\u7684\u7aef\u53e3\u5c06\u4f1a\u4ece\u6ca1\u6709\u4f7f\u7528\u7684\u7aef\u53e3\u6c60\u4e2d (49000..49900) \u81ea\u52a8\u9009\u62e9\uff0c\u4f60\u53ef\u4ee5\u901a\u8fc7docker ps\u3001docker inspect &lt;container_id&gt;\u6216\u8005docker port &lt;container_id&gt; &lt;port&gt;\u786e\u5b9a\u5177\u4f53\u7684\u7ed1\u5b9a\u4fe1\u606f\u3002<\/p>\n<h3 id=\"articleHeader26\"><a name=\"t26\"><\/a>5.2 \u7ed1\u5b9a\u7aef\u53e3\u5230\u6307\u5b9a\u63a5\u53e3<\/h3>\n<p>\u57fa\u672c\u8bed\u6cd5<\/p>\n<div>\n<pre>$ sudo docker run -p [([&lt;host_interface&gt;:[host_port]])|(&lt;host_port&gt;):]&lt;container_port&gt;[\/udp] &lt;image&gt; &lt;cmd&gt;<\/pre>\n<\/div>\n<p>\u9ed8\u8ba4\u4e0d\u6307\u5b9a\u7ed1\u5b9a ip \u5219\u76d1\u542c\u6240\u6709\u7f51\u7edc\u63a5\u53e3\u3002<\/p>\n<h4>\u7ed1\u5b9a TCP \u7aef\u53e3<\/h4>\n<div>\n<pre># Bind TCP port 8080 of the container to TCP port 80 on 127.0.0.1 of the host machine. $ sudo docker run -p 127.0.0.1:80:8080 &lt;image&gt; &lt;cmd&gt; # Bind TCP port 8080 of the container to a dynamically allocated TCP port on 127.0.0.1 of the host machine. $ sudo docker run -p 127.0.0.1::8080 &lt;image&gt; &lt;cmd&gt; # Bind TCP port 8080 of the container to TCP port 80 on all available interfaces of the host machine. $ sudo docker run -p 80:8080 &lt;image&gt; &lt;cmd&gt; # Bind TCP port 8080 of the container to a dynamically allocated TCP port on all available interfaces $ sudo docker run -p 8080 &lt;image&gt; &lt;cmd&gt;<\/pre>\n<\/div>\n<h4>\u7ed1\u5b9a UDP \u7aef\u53e3<\/h4>\n<div>\n<pre># Bind UDP port 5353 of the container to UDP port 53 on 127.0.0.1 of the host machine. $ sudo docker run -p 127.0.0.1:53:5353\/udp &lt;image&gt; &lt;cmd&gt;<\/pre>\n<\/div>\n<h2 id=\"articleHeader27\"><a name=\"t27\"><\/a>\u516d\u3001Docker \u7f51\u7edc\u914d\u7f6e<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/static.open-open.com\/lib\/uploadImg\/20150212\/20150212091034_634.png\" alt=\"\u975e\u5e38\u8be6\u7ec6\u7684 Docker \u5b66\u4e60\u7b14\u8bb0\" width=\"518\" height=\"357\" \/><\/p>\n<p>\u56fe:\u00a0<a href=\"http:\/\/www.slideshare.net\/janghoonsim\/docker-container-and-lightweight-virtualization\" target=\"_blank\" rel=\"nofollow noopener\">Docker &#8211; container and lightweight virtualization<\/a><\/p>\n<p>Dokcer \u901a\u8fc7\u4f7f\u7528 Linux \u6865\u63a5\u63d0\u4f9b\u5bb9\u5668\u4e4b\u95f4\u7684\u901a\u4fe1\uff0cdocker0 \u6865\u63a5\u63a5\u53e3\u7684\u76ee\u7684\u5c31\u662f\u65b9\u4fbf Docker \u7ba1\u7406\u3002\u5f53 Docker daemon \u542f\u52a8\u65f6\u9700\u8981\u505a\u4ee5\u4e0b\u64cd\u4f5c\uff1a<\/p>\n<ul>\n<li>creates the docker0 bridge if not present\n<ul>\n<li># \u5982\u679c docker0 \u4e0d\u5b58\u5728\u5219\u521b\u5efa<\/li>\n<\/ul>\n<\/li>\n<li>searches for an IP address range which doesn\u2019t overlap with an existing route\n<ul>\n<li># \u641c\u7d22\u4e00\u4e2a\u4e0e\u5f53\u524d\u8def\u7531\u4e0d\u51b2\u7a81\u7684 ip \u6bb5<\/li>\n<\/ul>\n<\/li>\n<li>picks an IP in the selected range\n<ul>\n<li># \u5728\u786e\u5b9a\u7684\u8303\u56f4\u4e2d\u9009\u62e9 ip<\/li>\n<\/ul>\n<\/li>\n<li>assigns this IP to the docker0 bridge\n<ul>\n<li># \u7ed1\u5b9a ip \u5230 docker0<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h3 id=\"articleHeader28\"><a name=\"t28\"><\/a>6.1 Docker \u56db\u79cd\u7f51\u7edc\u6a21\u5f0f<\/h3>\n<p>\u56db\u79cd\u7f51\u7edc\u6a21\u5f0f\u6458\u81ea\u00a0<a href=\"http:\/\/www.infoq.com\/cn\/articles\/docker-network-and-pipework-open-source-explanation-practice\" target=\"_blank\" rel=\"nofollow noopener\">Docker \u7f51\u7edc\u8be6\u89e3\u53ca pipework \u6e90\u7801\u89e3\u8bfb\u4e0e\u5b9e\u8df5<\/a><\/p>\n<p>docker run \u521b\u5efa Docker \u5bb9\u5668\u65f6\uff0c\u53ef\u4ee5\u7528 &#8211;net \u9009\u9879\u6307\u5b9a\u5bb9\u5668\u7684\u7f51\u7edc\u6a21\u5f0f\uff0cDocker \u6709\u4ee5\u4e0b 4 \u79cd\u7f51\u7edc\u6a21\u5f0f\uff1a<\/p>\n<ul>\n<li>host \u6a21\u5f0f\uff0c\u4f7f\u7528 &#8211;net=host \u6307\u5b9a\u3002<\/li>\n<li>container \u6a21\u5f0f\uff0c\u4f7f\u7528 &#8211;net=container:NAMEorID \u6307\u5b9a\u3002<\/li>\n<li>none \u6a21\u5f0f\uff0c\u4f7f\u7528 &#8211;net=none \u6307\u5b9a\u3002<\/li>\n<li>bridge \u6a21\u5f0f\uff0c\u4f7f\u7528 &#8211;net=bridge \u6307\u5b9a\uff0c\u9ed8\u8ba4\u8bbe\u7f6e\u3002<\/li>\n<\/ul>\n<h4>host \u6a21\u5f0f<\/h4>\n<p>\u5982\u679c\u542f\u52a8\u5bb9\u5668\u7684\u65f6\u5019\u4f7f\u7528 host \u6a21\u5f0f\uff0c\u90a3\u4e48\u8fd9\u4e2a\u5bb9\u5668\u5c06\u4e0d\u4f1a\u83b7\u5f97\u4e00\u4e2a\u72ec\u7acb\u7684 Network Namespace\uff0c\u800c\u662f\u548c\u5bbf\u4e3b\u673a\u5171\u7528\u4e00\u4e2a Network Namespace\u3002\u5bb9\u5668\u5c06\u4e0d\u4f1a\u865a\u62df\u51fa\u81ea\u5df1\u7684\u7f51\u5361\uff0c\u914d\u7f6e\u81ea\u5df1\u7684 IP \u7b49\uff0c\u800c\u662f\u4f7f\u7528\u5bbf\u4e3b\u673a\u7684 IP \u548c\u7aef\u53e3\u3002<\/p>\n<p>\u4f8b\u5982\uff0c\u6211\u4eec\u5728 10.10.101.105\/24 \u7684\u673a\u5668\u4e0a\u7528 host \u6a21\u5f0f\u542f\u52a8\u4e00\u4e2a\u542b\u6709 web \u5e94\u7528\u7684 Docker \u5bb9\u5668\uff0c\u76d1\u542c tcp 80 \u7aef\u53e3\u3002\u5f53\u6211\u4eec\u5728\u5bb9\u5668\u4e2d\u6267\u884c\u4efb\u4f55\u7c7b\u4f3c ifconfig \u547d\u4ee4\u67e5\u770b\u7f51\u7edc\u73af\u5883\u65f6\uff0c\u770b\u5230\u7684\u90fd\u662f\u5bbf\u4e3b\u673a\u4e0a\u7684\u4fe1\u606f\u3002\u800c\u5916\u754c\u8bbf\u95ee\u5bb9\u5668\u4e2d\u7684\u5e94\u7528\uff0c\u5219\u76f4\u63a5\u4f7f\u7528 10.10.101.105:80 \u5373\u53ef\uff0c\u4e0d\u7528\u4efb\u4f55 NAT \u8f6c\u6362\uff0c\u5c31\u5982\u76f4\u63a5\u8dd1\u5728\u5bbf\u4e3b\u673a\u4e2d\u4e00\u6837\u3002\u4f46\u662f\uff0c\u5bb9\u5668\u7684\u5176\u4ed6\u65b9\u9762\uff0c\u5982\u6587\u4ef6\u7cfb\u7edf\u3001\u8fdb\u7a0b\u5217\u8868\u7b49\u8fd8\u662f\u548c\u5bbf\u4e3b\u673a\u9694\u79bb\u7684\u3002<\/p>\n<h4>container \u6a21\u5f0f<\/h4>\n<p>\u8fd9\u4e2a\u6a21\u5f0f\u6307\u5b9a\u65b0\u521b\u5efa\u7684\u5bb9\u5668\u548c\u5df2\u7ecf\u5b58\u5728\u7684\u4e00\u4e2a\u5bb9\u5668\u5171\u4eab\u4e00\u4e2a Network Namespace\uff0c\u800c\u4e0d\u662f\u548c\u5bbf\u4e3b\u673a\u5171\u4eab\u3002\u65b0\u521b\u5efa\u7684\u5bb9\u5668\u4e0d\u4f1a\u521b\u5efa\u81ea\u5df1\u7684\u7f51\u5361\uff0c\u914d\u7f6e\u81ea\u5df1\u7684 IP\uff0c\u800c\u662f\u548c\u4e00\u4e2a\u6307\u5b9a\u7684\u5bb9\u5668\u5171\u4eab IP\u3001\u7aef\u53e3\u8303\u56f4\u7b49\u3002\u540c\u6837\uff0c\u4e24\u4e2a\u5bb9\u5668\u9664\u4e86\u7f51\u7edc\u65b9\u9762\uff0c\u5176\u4ed6\u7684\u5982\u6587\u4ef6\u7cfb\u7edf\u3001\u8fdb\u7a0b\u5217\u8868\u7b49\u8fd8\u662f\u9694\u79bb\u7684\u3002\u4e24\u4e2a\u5bb9\u5668\u7684\u8fdb\u7a0b\u53ef\u4ee5\u901a\u8fc7 lo \u7f51\u5361\u8bbe\u5907\u901a\u4fe1\u3002<\/p>\n<h4>none\u6a21\u5f0f<\/h4>\n<p>\u8fd9\u4e2a\u6a21\u5f0f\u548c\u524d\u4e24\u4e2a\u4e0d\u540c\u3002\u5728\u8fd9\u79cd\u6a21\u5f0f\u4e0b\uff0cDocker \u5bb9\u5668\u62e5\u6709\u81ea\u5df1\u7684 Network Namespace\uff0c\u4f46\u662f\uff0c\u5e76\u4e0d\u4e3a Docker\u5bb9\u5668\u8fdb\u884c\u4efb\u4f55\u7f51\u7edc\u914d\u7f6e\u3002\u4e5f\u5c31\u662f\u8bf4\uff0c\u8fd9\u4e2a Docker \u5bb9\u5668\u6ca1\u6709\u7f51\u5361\u3001IP\u3001\u8def\u7531\u7b49\u4fe1\u606f\u3002\u9700\u8981\u6211\u4eec\u81ea\u5df1\u4e3a Docker \u5bb9\u5668\u6dfb\u52a0\u7f51\u5361\u3001\u914d\u7f6e IP \u7b49\u3002<\/p>\n<h4>bridge\u6a21\u5f0f<\/h4>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/static.open-open.com\/lib\/uploadImg\/20150212\/20150212091035_252.png\" alt=\"\u975e\u5e38\u8be6\u7ec6\u7684 Docker \u5b66\u4e60\u7b14\u8bb0\" width=\"548\" height=\"332\" \/><\/p>\n<p>\u56fe:<a href=\"http:\/\/www.wickedawesometech.us\/2014\/07\/the-container-world-part-2-networking.html\" target=\"_blank\" rel=\"nofollow noopener\">The Container World | Part 2 Networking<\/a><\/p>\n<p>bridge \u6a21\u5f0f\u662f Docker \u9ed8\u8ba4\u7684\u7f51\u7edc\u8bbe\u7f6e\uff0c\u6b64\u6a21\u5f0f\u4f1a\u4e3a\u6bcf\u4e00\u4e2a\u5bb9\u5668\u5206\u914d Network Namespace\u3001\u8bbe\u7f6e IP \u7b49\uff0c\u5e76\u5c06\u4e00\u4e2a\u4e3b\u673a\u4e0a\u7684 Docker \u5bb9\u5668\u8fde\u63a5\u5230\u4e00\u4e2a\u865a\u62df\u7f51\u6865\u4e0a\u3002\u5f53 Docker server \u542f\u52a8\u65f6\uff0c\u4f1a\u5728\u4e3b\u673a\u4e0a\u521b\u5efa\u4e00\u4e2a\u540d\u4e3a docker0 \u7684\u865a\u62df\u7f51\u6865\uff0c\u6b64\u4e3b\u673a\u4e0a\u542f\u52a8\u7684 Docker \u5bb9\u5668\u4f1a\u8fde\u63a5\u5230\u8fd9\u4e2a\u865a\u62df\u7f51\u6865\u4e0a\u3002\u865a\u62df\u7f51\u6865\u7684\u5de5\u4f5c\u65b9\u5f0f\u548c\u7269\u7406\u4ea4\u6362\u673a\u7c7b\u4f3c\uff0c\u8fd9\u6837\u4e3b\u673a\u4e0a\u7684\u6240\u6709\u5bb9\u5668\u5c31\u901a\u8fc7\u4ea4\u6362\u673a\u8fde\u5728\u4e86\u4e00\u4e2a\u4e8c\u5c42\u7f51\u7edc\u4e2d\u3002\u63a5\u4e0b\u6765\u5c31\u8981\u4e3a\u5bb9\u5668\u5206\u914d IP \u4e86\uff0cDocker \u4f1a\u4ece RFC1918 \u6240\u5b9a\u4e49\u7684\u79c1\u6709 IP \u7f51\u6bb5\u4e2d\uff0c\u9009\u62e9\u4e00\u4e2a\u548c\u5bbf\u4e3b\u673a\u4e0d\u540c\u7684IP\u5730\u5740\u548c\u5b50\u7f51\u5206\u914d\u7ed9 docker0\uff0c\u8fde\u63a5\u5230 docker0 \u7684\u5bb9\u5668\u5c31\u4ece\u8fd9\u4e2a\u5b50\u7f51\u4e2d\u9009\u62e9\u4e00\u4e2a\u672a\u5360\u7528\u7684 IP \u4f7f\u7528\u3002\u5982\u4e00\u822c Docker \u4f1a\u4f7f\u7528 172.17.0.0\/16 \u8fd9\u4e2a\u7f51\u6bb5\uff0c\u5e76\u5c06 172.17.42.1\/16 \u5206\u914d\u7ed9 docker0 \u7f51\u6865\uff08\u5728\u4e3b\u673a\u4e0a\u4f7f\u7528 ifconfig \u547d\u4ee4\u662f\u53ef\u4ee5\u770b\u5230 docker0 \u7684\uff0c\u53ef\u4ee5\u8ba4\u4e3a\u5b83\u662f\u7f51\u6865\u7684\u7ba1\u7406\u63a5\u53e3\uff0c\u5728\u5bbf\u4e3b\u673a\u4e0a\u4f5c\u4e3a\u4e00\u5757\u865a\u62df\u7f51\u5361\u4f7f\u7528\uff09<\/p>\n<h3 id=\"articleHeader29\"><a name=\"t29\"><\/a>6.2 \u5217\u51fa\u5f53\u524d\u4e3b\u673a\u7f51\u6865<\/h3>\n<div>\n<pre>$ sudo brctl show # brctl \u5de5\u5177\u4f9d\u8d56 bridge-utils \u8f6f\u4ef6\u5305 bridge name bridge id STP enabled interfaces\r\ndocker0 8000.000000000000 no<\/pre>\n<\/div>\n<h3 id=\"articleHeader30\"><a name=\"t30\"><\/a>6.3 \u67e5\u770b\u5f53\u524d docker0 ip<\/h3>\n<div>\n<pre>$ sudo ifconfig docker0\r\ndocker0 Link encap:Ethernet HWaddr xx:xx:xx:xx:xx:xx\r\ninet addr:172.17.42.1 Bcast:0.0.0.0 Mask:255.255.0.0<\/pre>\n<\/div>\n<p>\u5728\u5bb9\u5668\u8fd0\u884c\u65f6\uff0c\u6bcf\u4e2a\u5bb9\u5668\u90fd\u4f1a\u5206\u914d\u4e00\u4e2a\u7279\u5b9a\u7684\u865a\u62df\u673a\u53e3\u5e76\u6865\u63a5\u5230 docker0\u3002\u6bcf\u4e2a\u5bb9\u5668\u90fd\u4f1a\u914d\u7f6e\u540c docker0 ip \u76f8\u540c\u7f51\u6bb5\u7684\u4e13\u7528 ip \u5730\u5740\uff0cdocker0 \u7684 IP \u5730\u5740\u88ab\u7528\u4e8e\u6240\u6709\u5bb9\u5668\u7684\u9ed8\u8ba4\u7f51\u5173\u3002<\/p>\n<h3 id=\"articleHeader31\"><a name=\"t31\"><\/a>6.4 \u8fd0\u884c\u4e00\u4e2a\u5bb9\u5668<\/h3>\n<div>\n<pre>$ sudo docker run -t -i -d ubuntu \/bin\/bash\r\n52f811c5d3d69edddefc75aff5a4525fc8ba8bcfa1818132f9dc7d4f7c7e78b4 $ sudo brctl show\r\nbridge name bridge id STP enabled interfaces\r\ndocker0 8000.fef213db5a66 no vethQCDY1N<\/pre>\n<\/div>\n<p>\u4ee5\u4e0a, docker0 \u626e\u6f14\u7740 52f811c5d3d6 container \u8fd9\u4e2a\u5bb9\u5668\u7684\u865a\u62df\u63a5\u53e3 vethQCDY1N interface \u6865\u63a5\u7684\u89d2\u8272\u3002<\/p>\n<h4>\u4f7f\u7528\u7279\u5b9a\u8303\u56f4\u7684 IP<\/h4>\n<p>Docker \u4f1a\u5c1d\u8bd5\u5bfb\u627e\u6ca1\u6709\u88ab\u4e3b\u673a\u4f7f\u7528\u7684 ip \u6bb5\uff0c\u5c3d\u7ba1\u5b83\u9002\u7528\u4e8e\u5927\u591a\u6570\u60c5\u51b5\u4e0b\uff0c\u4f46\u662f\u5b83\u4e0d\u662f\u4e07\u80fd\u7684\uff0c\u6709\u65f6\u5019\u6211\u4eec\u8fd8\u662f\u9700\u8981\u5bf9 ip \u8fdb\u4e00\u6b65\u89c4\u5212\u3002Docker \u5141\u8bb8\u4f60\u7ba1\u7406 docker0 \u6865\u63a5\u6216\u8005\u901a\u8fc7-b\u9009\u9879\u81ea\u5b9a\u4e49\u6865\u63a5\u7f51\u5361\uff0c\u9700\u8981\u5b89\u88c5bridge-utils\u8f6f\u4ef6\u5305\u3002<\/p>\n<p>\u57fa\u672c\u6b65\u9aa4\u5982\u4e0b\uff1a<\/p>\n<ul>\n<li>ensure Docker is stopped\n<ul>\n<li># \u786e\u4fdd docker \u7684\u8fdb\u7a0b\u662f\u505c\u6b62\u7684<\/li>\n<\/ul>\n<\/li>\n<li>create your own bridge (bridge0 for example)\n<ul>\n<li># \u521b\u5efa\u81ea\u5b9a\u4e49\u7f51\u6865<\/li>\n<\/ul>\n<\/li>\n<li>assign a specific IP to this bridge\n<ul>\n<li># \u7ed9\u7f51\u6865\u5206\u914d\u7279\u5b9a\u7684 ip<\/li>\n<\/ul>\n<\/li>\n<li>start Docker with the -b=bridge0 parameter\n<ul>\n<li># \u4ee5 -b \u7684\u65b9\u5f0f\u6307\u5b9a\u7f51\u6865<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<div>\n<pre># Stopping Docker and removing docker0 $ sudo service docker stop $ sudo ip link set dev docker0 down $ sudo brctl delbr docker0 # Create our own bridge $ sudo brctl addbr bridge0 $ sudo ip addr add 192.168.5.1\/24 dev bridge0 $ sudo ip link set dev bridge0 up # Confirming that our bridge is up and running $ ip addr show bridge0\r\n4: bridge0: &lt;BROADCAST,MULTICAST&gt; mtu 1500 qdisc noop state UP group default\r\n    link\/ether 66:38:d0:0d:76:18 brd ff:ff:ff:ff:ff:ff\r\n    inet 192.168.5.1\/24 scope global bridge0\r\n       valid_lft forever preferred_lft forever # Tell Docker about it and restart (on Ubuntu) $ echo 'DOCKER_OPTS=\"-b=bridge0\"' &gt;&gt; \/etc\/default\/docker $ sudo service docker start<\/pre>\n<\/div>\n<p>\u53c2\u8003\u6587\u6863:\u00a0<a href=\"https:\/\/docs.docker.com\/articles\/networking\/\" target=\"_blank\" rel=\"nofollow noopener\">Network Configuration<\/a><\/p>\n<h3 id=\"articleHeader32\"><a name=\"t32\"><\/a>6.5 \u4e0d\u540c\u4e3b\u673a\u95f4\u5bb9\u5668\u901a\u4fe1<\/h3>\n<p>\u4e0d\u540c\u5bb9\u5668\u4e4b\u95f4\u7684\u901a\u4fe1\u53ef\u4ee5\u501f\u52a9\u4e8e pipework \u8fd9\u4e2a\u5de5\u5177\uff1a<\/p>\n<div>\n<pre>$ git clone https:\/\/github.com\/jpetazzo\/pipework.git\r\n$ sudo cp -rp pipework\/pipework \/usr\/local\/bin\/<\/pre>\n<\/div>\n<h4>\u5b89\u88c5\u76f8\u5e94\u4f9d\u8d56\u8f6f\u4ef6<\/h4>\n<div>\n<pre>$ sudo apt-get install iputils-arping bridge-utils -y<\/pre>\n<\/div>\n<h4>\u6865\u63a5\u7f51\u7edc<\/h4>\n<p>\u6865\u63a5\u7f51\u7edc\u53ef\u4ee5\u53c2\u8003\u00a0<a href=\"https:\/\/github.com\/opskumu\/Day\/blob\/master\/tips\/tips.md\" target=\"_blank\" rel=\"nofollow noopener\">\u65e5\u5e38\u95ee\u9898\u5904\u7406 Tips<\/a>\u00a0\u5173\u4e8e\u6865\u63a5\u7684\u914d\u7f6e\u8bf4\u660e\uff0c\u8fd9\u91cc\u4e0d\u518d\u8d58\u8ff0\u3002<\/p>\n<div>\n<pre># brctl show\r\nbridge name     bridge id               STP enabled     interfaces\r\nbr0             8000.000c291412cd       no              eth0\r\ndocker0         8000.56847afe9799       no              vetheb48029<\/pre>\n<\/div>\n<p>\u53ef\u4ee5\u5220\u9664 docker0\uff0c\u76f4\u63a5\u628a docker \u7684\u6865\u63a5\u6307\u5b9a\u4e3a br0\u3002\u4e5f\u53ef\u4ee5\u4fdd\u7559\u4f7f\u7528\u9ed8\u8ba4\u7684\u914d\u7f6e\uff0c\u8fd9\u6837\u5355\u4e3b\u673a\u5bb9\u5668\u4e4b\u95f4\u7684\u901a\u4fe1\u53ef\u4ee5\u901a\u8fc7 docker0\uff0c\u800c\u8de8\u4e3b\u673a\u4e0d\u540c\u5bb9\u5668\u4e4b\u95f4\u901a\u8fc7 pipework \u65b0\u5efa docker \u5bb9\u5668\u7684\u7f51\u5361\u6865\u63a5\u5230 br0\uff0c\u8fd9\u6837\u8de8\u4e3b\u673a\u5bb9\u5668\u4e4b\u95f4\u5c31\u53ef\u4ee5\u901a\u4fe1\u4e86\u3002<\/p>\n<ul>\n<li>ubuntu<\/li>\n<\/ul>\n<div>\n<pre>$ sudo service docker stop\r\n$ sudo ip link set dev docker0 down\r\n$ sudo brctl delbr docker0\r\n$ echo 'DOCKER_OPTS=\"-b=br0\"' &gt;&gt; \/etc\/default\/docker\r\n$ sudo service docker start<\/pre>\n<\/div>\n<ul>\n<li>CentOS 7\/RHEL 7<\/li>\n<\/ul>\n<div>\n<pre>$ sudo systemctl stop docker\r\n$ sudo ip link set dev docker0 down\r\n$ sudo brctl delbr docker0\r\n$ cat \/etc\/sysconfig\/docker | grep 'OPTIONS='\r\nOPTIONS=--selinux-enabled -b=br0 -H fd:\/\/\r\n$ sudo systemctl start docker<\/pre>\n<\/div>\n<h4>pipework<\/h4>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/static.open-open.com\/lib\/uploadImg\/20150212\/20150212091035_900.png\" alt=\"\u975e\u5e38\u8be6\u7ec6\u7684 Docker \u5b66\u4e60\u7b14\u8bb0\" width=\"670\" height=\"541\" \/><\/p>\n<p>\u4e0d\u540c\u5bb9\u5668\u4e4b\u95f4\u7684\u901a\u4fe1\u53ef\u4ee5\u501f\u52a9\u4e8e pipework \u8fd9\u4e2a\u5de5\u5177\u7ed9 docker \u5bb9\u5668\u65b0\u5efa\u865a\u62df\u7f51\u5361\u5e76\u7ed1\u5b9a IP \u6865\u63a5\u5230 br0<\/p>\n<div>\n<pre>$ git clone https:\/\/github.com\/jpetazzo\/pipework.git\r\n$ sudo cp -rp pipework\/pipework \/usr\/local\/bin\/\r\n$ pipework \r\nSyntax:\r\npipework &lt;hostinterface&gt; [-i containerinterface] &lt;guest&gt; &lt;ipaddr&gt;\/&lt;subnet&gt;[@default_gateway] [macaddr][@vlan]\r\npipework &lt;hostinterface&gt; [-i containerinterface] &lt;guest&gt; dhcp [macaddr][@vlan]\r\npipework --wait [-i containerinterface]<\/pre>\n<\/div>\n<p>\u5982\u679c\u5220\u9664\u4e86\u9ed8\u8ba4\u7684 docker0 \u6865\u63a5\uff0c\u628a docker \u9ed8\u8ba4\u6865\u63a5\u6307\u5b9a\u5230\u4e86 br0\uff0c\u5219\u6700\u597d\u5728\u521b\u5efa\u5bb9\u5668\u7684\u65f6\u5019\u52a0\u4e0a&#8211;net=none\uff0c\u9632\u6b62\u81ea\u52a8\u5206\u914d\u7684 IP \u5728\u5c40\u57df\u7f51\u4e2d\u6709\u51b2\u7a81\u3002<\/p>\n<div>\n<pre>$ sudo docker run --rm -ti --net=none ubuntu:14.04 \/bin\/bash\r\nroot@a46657528059:\/#\r\n$                  # Ctrl-P + Ctrl-Q \u56de\u5230\u5bbf\u4e3b\u673a shell\uff0c\u5bb9\u5668 detach \u72b6\u6001\r\n$ sudo docker  ps\r\nCONTAINER ID    IMAGE          COMMAND       CREATED         STATUS          PORTS      NAMES\r\na46657528059    ubuntu:14.04   \"\/bin\/bash\"   4 minutes ago   Up 4 minutes               hungry_lalande\r\n$ sudo pipework br0 -i eth0 a46657528059 192.168.115.10\/24@192.168.115.2 \r\n# \u9ed8\u8ba4\u4e0d\u6307\u5b9a\u7f51\u5361\u8bbe\u5907\u540d\uff0c\u5219\u9ed8\u8ba4\u6dfb\u52a0\u4e3a eth1\r\n# \u53e6\u5916 pipework \u4e0d\u80fd\u6dfb\u52a0\u9759\u6001\u8def\u7531\uff0c\u5982\u679c\u6709\u9700\u6c42\u5219\u53ef\u4ee5\u5728 run \u7684\u65f6\u5019\u52a0\u4e0a --privileged=true \u6743\u9650\u5728\u5bb9\u5668\u4e2d\u624b\u52a8\u6dfb\u52a0\uff0c\r\n# \u4f46\u8fd9\u79cd\u5b89\u5168\u6027\u6709\u7f3a\u9677\uff0c\u53ef\u4ee5\u901a\u8fc7 ip netns \u64cd\u4f5c\r\n$ sudo docker attach a46657528059\r\nroot@a46657528059:\/# ifconfig eth0\r\neth0      Link encap:Ethernet  HWaddr 86:b6:6b:e8:2e:4d  \r\n          inet addr:192.168.115.10  Bcast:0.0.0.0  Mask:255.255.255.0\r\n          inet6 addr: fe80::84b6:6bff:fee8:2e4d\/64 Scope:Link\r\n          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1\r\n          RX packets:8 errors:0 dropped:0 overruns:0 frame:0\r\n          TX packets:9 errors:0 dropped:0 overruns:0 carrier:0\r\n          collisions:0 txqueuelen:1000 \r\n          RX bytes:648 (648.0 B)  TX bytes:690 (690.0 B)\r\n\r\nroot@a46657528059:\/# route -n\r\nKernel IP routing table\r\nDestination     Gateway         Genmask         Flags Metric Ref    Use Iface\r\n0.0.0.0         192.168.115.2   0.0.0.0         UG    0      0        0 eth0\r\n192.168.115.0   0.0.0.0         255.255.255.0   U     0      0        0 eth0<\/pre>\n<\/div>\n<p>\u4f7f\u7528ip netns\u6dfb\u52a0\u9759\u6001\u8def\u7531\uff0c\u907f\u514d\u521b\u5efa\u5bb9\u5668\u4f7f\u7528&#8211;privileged=true\u9009\u9879\u9020\u6210\u4e00\u4e9b\u4e0d\u5fc5\u8981\u7684\u5b89\u5168\u95ee\u9898\uff1a<\/p>\n<div>\n<pre>$ docker inspect --format=\"{{ .State.Pid }}\" a46657528059 # \u83b7\u53d6\u6307\u5b9a\u5bb9\u5668 pid\r\n6350\r\n$ sudo ln -s \/proc\/6350\/ns\/net \/var\/run\/netns\/6350\r\n$ sudo ip netns exec 6350 ip route add 192.168.0.0\/16 dev eth0 via 192.168.115.2\r\n$ sudo ip netns exec 6350 ip route    # \u6dfb\u52a0\u6210\u529f\r\n192.168.0.0\/16 via 192.168.115.2 dev eth0 \r\n... ...<\/pre>\n<\/div>\n<p>\u5728\u5176\u5b83\u5bbf\u4e3b\u673a\u8fdb\u884c\u76f8\u5e94\u7684\u914d\u7f6e\uff0c\u65b0\u5efa\u5bb9\u5668\u5e76\u4f7f\u7528 pipework \u6dfb\u52a0\u865a\u62df\u7f51\u5361\u6865\u63a5\u5230 br0\uff0c\u6d4b\u8bd5\u901a\u4fe1\u60c5\u51b5\u5373\u53ef\u3002<\/p>\n<p>\u53e6\u5916\uff0cpipework \u53ef\u4ee5\u521b\u5efa\u5bb9\u5668\u7684 vlan \u7f51\u7edc\uff0c\u8fd9\u91cc\u4e0d\u4f5c\u8fc7\u591a\u7684\u4ecb\u7ecd\u4e86\uff0c\u5b98\u65b9\u6587\u6863\u5df2\u7ecf\u5199\u7684\u5f88\u6e05\u695a\u4e86\uff0c\u53ef\u4ee5\u67e5\u770b\u4ee5\u4e0b\u4e24\u7bc7\u6587\u7ae0\uff1a<\/p>\n<ul>\n<li><a href=\"https:\/\/github.com\/jpetazzo\/pipework\" target=\"_blank\" rel=\"nofollow noopener\">Pipework \u5b98\u65b9\u6587\u6863<\/a><\/li>\n<li><a href=\"http:\/\/www.infoq.com\/cn\/articles\/docker-network-and-pipework-open-source-explanation-practice\" target=\"_blank\" rel=\"nofollow noopener\">Docker \u7f51\u7edc\u8be6\u89e3\u53ca pipework \u6e90\u7801\u89e3\u8bfb\u4e0e\u5b9e\u8df5<\/a><\/li>\n<\/ul>\n<h2 id=\"articleHeader33\"><a name=\"t33\"><\/a>\u4e03\u3001Dockerfile<\/h2>\n<p>Docker \u53ef\u4ee5\u901a\u8fc7 Dockerfile \u7684\u5185\u5bb9\u6765\u81ea\u52a8\u6784\u5efa\u955c\u50cf\u3002Dockerfile \u662f\u4e00\u4e2a\u5305\u542b\u521b\u5efa\u955c\u50cf\u6240\u6709\u547d\u4ee4\u7684\u6587\u672c\u6587\u4ef6\uff0c\u901a\u8fc7docker build\u547d\u4ee4\u53ef\u4ee5\u6839\u636e Dockerfile \u7684\u5185\u5bb9\u6784\u5efa\u955c\u50cf\uff0c\u5728\u4ecb\u7ecd\u5982\u4f55\u6784\u5efa\u4e4b\u524d\u5148\u4ecb\u7ecd\u4e0b Dockerfile \u7684\u57fa\u672c\u8bed\u6cd5\u7ed3\u6784\u3002<\/p>\n<p>Dockerfile \u6709\u4ee5\u4e0b\u6307\u4ee4\u9009\u9879:<\/p>\n<ul>\n<li>FROM<\/li>\n<li>MAINTAINER<\/li>\n<li>RUN<\/li>\n<li>CMD<\/li>\n<li>EXPOSE<\/li>\n<li>ENV<\/li>\n<li>ADD<\/li>\n<li>COPY<\/li>\n<li>ENTRYPOINT<\/li>\n<li>VOLUME<\/li>\n<li>USER<\/li>\n<li>WORKDIR<\/li>\n<li>ONBUILD<\/li>\n<\/ul>\n<h3 id=\"articleHeader34\"><a name=\"t34\"><\/a>7.1 FROM<\/h3>\n<p>\u7528\u6cd5:<\/p>\n<div>\n<pre>FROM &lt;image&gt;<\/pre>\n<\/div>\n<p>\u6216\u8005<\/p>\n<div>\n<pre>FROM &lt;image&gt;<\/pre>\n<\/div>\n<ul>\n<li>FROM\u6307\u5b9a\u6784\u5efa\u955c\u50cf\u7684\u57fa\u7840\u6e90\u955c\u50cf\uff0c\u5982\u679c\u672c\u5730\u6ca1\u6709\u6307\u5b9a\u7684\u955c\u50cf\uff0c\u5219\u4f1a\u81ea\u52a8\u4ece Docker \u7684\u516c\u5171\u5e93 pull \u955c\u50cf\u4e0b\u6765\u3002<\/li>\n<li>FROM\u5fc5\u987b\u662f Dockerfile \u4e2d\u975e\u6ce8\u91ca\u884c\u7684\u7b2c\u4e00\u4e2a\u6307\u4ee4\uff0c\u5373\u4e00\u4e2a Dockerfile \u4eceFROM\u8bed\u53e5\u5f00\u59cb\u3002<\/li>\n<li>FROM\u53ef\u4ee5\u5728\u4e00\u4e2a Dockerfile \u4e2d\u51fa\u73b0\u591a\u6b21\uff0c\u5982\u679c\u6709\u9700\u6c42\u5728\u4e00\u4e2a Dockerfile \u4e2d\u521b\u5efa\u591a\u4e2a\u955c\u50cf\u3002<\/li>\n<li>\u5982\u679cFROM\u8bed\u53e5\u6ca1\u6709\u6307\u5b9a\u955c\u50cf\u6807\u7b7e\uff0c\u5219\u9ed8\u8ba4\u4f7f\u7528latest\u6807\u7b7e\u3002<\/li>\n<\/ul>\n<h3 id=\"articleHeader35\"><a name=\"t35\"><\/a>7.2 MAINTAINER<\/h3>\n<p>\u7528\u6cd5:<\/p>\n<div>\n<pre>MAINTAINER &lt;name&gt;<\/pre>\n<\/div>\n<p>\u6307\u5b9a\u521b\u5efa\u955c\u50cf\u7684\u7528\u6237<\/p>\n<p>RUN \u6709\u4e24\u79cd\u4f7f\u7528\u65b9\u5f0f<\/p>\n<ul>\n<li>RUN<\/li>\n<li>RUN\u00a0<a href=\"http:\/\/opskumu.github.io\/exec%20form\" target=\"_blank\" rel=\"nofollow noopener\">&#8220;executable&#8221;, &#8220;param1&#8221;, &#8220;param2&#8221;<\/a><\/li>\n<\/ul>\n<p>\u6bcf\u6761RUN\u6307\u4ee4\u5c06\u5728\u5f53\u524d\u955c\u50cf\u57fa\u7840\u4e0a\u6267\u884c\u6307\u5b9a\u547d\u4ee4\uff0c\u5e76\u63d0\u4ea4\u4e3a\u65b0\u7684\u955c\u50cf\uff0c\u540e\u7eed\u7684RUN\u90fd\u5728\u4e4b\u524dRUN\u63d0\u4ea4\u540e\u7684\u955c\u50cf\u4e3a\u57fa\u7840\uff0c\u955c\u50cf\u662f\u5206\u5c42\u7684\uff0c\u53ef\u4ee5\u901a\u8fc7\u4e00\u4e2a\u955c\u50cf\u7684\u4efb\u4f55\u4e00\u4e2a\u5386\u53f2\u63d0\u4ea4\u70b9\u6765\u521b\u5efa\uff0c\u7c7b\u4f3c\u6e90\u7801\u7684\u7248\u672c\u63a7\u5236\u3002<\/p>\n<p>exec \u65b9\u5f0f\u4f1a\u88ab\u89e3\u6790\u4e3a\u4e00\u4e2a JSON \u6570\u7ec4\uff0c\u6240\u4ee5\u5fc5\u987b\u4f7f\u7528\u53cc\u5f15\u53f7\u800c\u4e0d\u662f\u5355\u5f15\u53f7\u3002exec \u65b9\u5f0f\u4e0d\u4f1a\u8c03\u7528\u4e00\u4e2a\u547d\u4ee4 shell\uff0c\u6240\u4ee5\u4e5f\u5c31\u4e0d\u4f1a\u7ee7\u627f\u76f8\u5e94\u7684\u53d8\u91cf\uff0c\u5982\uff1a<\/p>\n<div>\n<pre>RUN [ \"echo\", \"$HOME\" ]<\/pre>\n<\/div>\n<p>\u8fd9\u79cd\u65b9\u5f0f\u662f\u4e0d\u4f1a\u8fbe\u5230\u8f93\u51fa HOME \u53d8\u91cf\u7684\uff0c\u6b63\u786e\u7684\u65b9\u5f0f\u5e94\u8be5\u662f\u8fd9\u6837\u7684<\/p>\n<div>\n<pre>RUN [ \"sh\", \"-c\", \"echo\", \"$HOME\" ]<\/pre>\n<\/div>\n<p>RUN\u4ea7\u751f\u7684\u7f13\u5b58\u5728\u4e0b\u4e00\u6b21\u6784\u5efa\u7684\u65f6\u5019\u662f\u4e0d\u4f1a\u5931\u6548\u7684\uff0c\u4f1a\u88ab\u91cd\u7528\uff0c\u53ef\u4ee5\u4f7f\u7528&#8211;no-cache\u9009\u9879\uff0c\u5373docker build &#8211;no-cache\uff0c\u5982\u6b64\u4fbf\u4e0d\u4f1a\u7f13\u5b58\u3002<\/p>\n<h3 id=\"articleHeader36\"><a name=\"t36\"><\/a>7.3 CMD<\/h3>\n<p>CMD\u6709\u4e09\u79cd\u4f7f\u7528\u65b9\u5f0f:<\/p>\n<ul>\n<li>CMD\u00a0<a href=\"http:\/\/opskumu.github.io\/exec%20form,%20this%20is%20the%20preferred%20form,%20%E4%BC%98%E5%85%88%E9%80%89%E6%8B%A9\" target=\"_blank\" rel=\"nofollow noopener\">&#8220;executable&#8221;,&#8221;param1&#8243;,&#8221;param2&#8243;<\/a><\/li>\n<li>CMD\u00a0<a href=\"http:\/\/opskumu.github.io\/as%20default%20parameters%20to%20%60ENTRYPOINT%60\" target=\"_blank\" rel=\"nofollow noopener\">&#8220;param1&#8243;,&#8221;param2&#8221;<\/a><\/li>\n<li>CMD command param1 param2 (shell form)<\/li>\n<\/ul>\n<p>CMD\u6307\u5b9a\u5728 Dockerfile \u4e2d\u53ea\u80fd\u4f7f\u7528\u4e00\u6b21\uff0c\u5982\u679c\u6709\u591a\u4e2a\uff0c\u5219\u53ea\u6709\u6700\u540e\u4e00\u4e2a\u4f1a\u751f\u6548\u3002<\/p>\n<p>CMD\u7684\u76ee\u7684\u662f\u4e3a\u4e86\u5728\u542f\u52a8\u5bb9\u5668\u65f6\u63d0\u4f9b\u4e00\u4e2a\u9ed8\u8ba4\u7684\u547d\u4ee4\u6267\u884c\u9009\u9879\u3002\u5982\u679c\u7528\u6237\u542f\u52a8\u5bb9\u5668\u65f6\u6307\u5b9a\u4e86\u8fd0\u884c\u7684\u547d\u4ee4\uff0c\u5219\u4f1a\u8986\u76d6\u6389CMD\u6307\u5b9a\u7684\u547d\u4ee4\u3002<\/p>\n<blockquote><p>CMD\u4f1a\u5728\u542f\u52a8\u5bb9\u5668\u7684\u65f6\u5019\u6267\u884c\uff0cbuild \u65f6\u4e0d\u6267\u884c\uff0c\u800cRUN\u53ea\u662f\u5728\u6784\u5efa\u955c\u50cf\u7684\u65f6\u5019\u6267\u884c\uff0c\u540e\u7eed\u955c\u50cf\u6784\u5efa\u5b8c\u6210\u4e4b\u540e\uff0c\u542f\u52a8\u5bb9\u5668\u5c31\u4e0eRUN\u65e0\u5173\u4e86\uff0c\u8fd9\u4e2a\u521d\u5b66\u8005\u5bb9\u6613\u5f04\u6df7\u8fd9\u4e2a\u6982\u5ff5\uff0c\u8fd9\u91cc\u7b80\u5355\u6ce8\u89e3\u4e00\u4e0b\u3002<\/p><\/blockquote>\n<h3 id=\"articleHeader37\"><a name=\"t37\"><\/a>7.4 EXPOSE<\/h3>\n<div>\n<pre>EXPOSE &lt;port&gt; [&lt;port&gt;...]<\/pre>\n<\/div>\n<p>\u544a\u8bc9 Docker \u670d\u52a1\u7aef\u5bb9\u5668\u5bf9\u5916\u6620\u5c04\u7684\u672c\u5730\u7aef\u53e3\uff0c\u9700\u8981\u5728 docker run \u7684\u65f6\u5019\u4f7f\u7528-p\u6216\u8005-P\u9009\u9879\u751f\u6548\u3002<\/p>\n<h3 id=\"articleHeader38\"><a name=\"t38\"><\/a>7.5 ENV<\/h3>\n<div>\n<pre>ENV &lt;key&gt; &lt;value&gt;       # \u53ea\u80fd\u8bbe\u7f6e\u4e00\u4e2a\u53d8\u91cf\r\nENV &lt;key&gt;=&lt;value&gt; ...   # \u5141\u8bb8\u4e00\u6b21\u8bbe\u7f6e\u591a\u4e2a\u53d8\u91cf<\/pre>\n<\/div>\n<p>\u6307\u5b9a\u4e00\u4e2a\u73af\u8282\u53d8\u91cf\uff0c\u4f1a\u88ab\u540e\u7eedRUN\u6307\u4ee4\u4f7f\u7528\uff0c\u5e76\u5728\u5bb9\u5668\u8fd0\u884c\u65f6\u4fdd\u7559\u3002<\/p>\n<p>\u4f8b\u5b50:<\/p>\n<div>\n<pre>ENV myName=\"John Doe\" myDog=Rex\\ The\\ Dog \\\r\n    myCat=fluffy<\/pre>\n<\/div>\n<p>\u7b49\u540c\u4e8e<\/p>\n<div>\n<pre>ENV myName John Doe\r\nENV myDog Rex The Dog\r\nENV myCat fluffy<\/pre>\n<\/div>\n<h3 id=\"articleHeader39\"><a name=\"t39\"><\/a>7.6 ADD<\/h3>\n<div>\n<pre>ADD &lt;src&gt;... &lt;dest&gt;<\/pre>\n<\/div>\n<p>ADD\u590d\u5236\u672c\u5730\u4e3b\u673a\u6587\u4ef6\u3001\u76ee\u5f55\u6216\u8005\u8fdc\u7a0b\u6587\u4ef6 URLS \u4ece \u5e76\u4e14\u6dfb\u52a0\u5230\u5bb9\u5668\u6307\u5b9a\u8def\u5f84\u4e2d \u3002<\/p>\n<p>\u652f\u6301\u901a\u8fc7 GO \u7684\u6b63\u5219\u6a21\u7cca\u5339\u914d\uff0c\u5177\u4f53\u89c4\u5219\u53ef\u53c2\u89c1\u00a0<a href=\"http:\/\/golang.org\/pkg\/path\/filepath\/#Match\" target=\"_blank\" rel=\"nofollow noopener\">Go filepath.Match<\/a><\/p>\n<div>\n<pre>ADD hom* \/mydir\/        # adds all files starting with \"hom\"\r\nADD hom?.txt \/mydir\/    # ? is replaced with any single character<\/pre>\n<\/div>\n<ul>\n<li>\u8def\u5f84\u5fc5\u987b\u662f\u7edd\u5bf9\u8def\u5f84\uff0c\u5982\u679c \u4e0d\u5b58\u5728\uff0c\u4f1a\u81ea\u52a8\u521b\u5efa\u5bf9\u5e94\u76ee\u5f55<\/li>\n<li>\u8def\u5f84\u5fc5\u987b\u662f Dockerfile \u6240\u5728\u8def\u5f84\u7684\u76f8\u5bf9\u8def\u5f84<\/li>\n<li>\u5982\u679c\u662f\u4e00\u4e2a\u76ee\u5f55\uff0c\u53ea\u4f1a\u590d\u5236\u76ee\u5f55\u4e0b\u7684\u5185\u5bb9\uff0c\u800c\u76ee\u5f55\u672c\u8eab\u5219\u4e0d\u4f1a\u88ab\u590d\u5236<\/li>\n<\/ul>\n<h3 id=\"articleHeader40\"><a name=\"t40\"><\/a>7.7 COPY<\/h3>\n<div>\n<pre>COPY &lt;src&gt;... &lt;dest&gt;<\/pre>\n<\/div>\n<p>COPY\u590d\u5236\u65b0\u6587\u4ef6\u6216\u8005\u76ee\u5f55\u4ece \u5e76\u4e14\u6dfb\u52a0\u5230\u5bb9\u5668\u6307\u5b9a\u8def\u5f84\u4e2d \u3002\u7528\u6cd5\u540cADD\uff0c\u552f\u4e00\u7684\u4e0d\u540c\u662f\u4e0d\u80fd\u6307\u5b9a\u8fdc\u7a0b\u6587\u4ef6 URLS\u3002<\/p>\n<h3 id=\"articleHeader41\"><a name=\"t41\"><\/a>7.8 ENTRYPOINT<\/h3>\n<ul>\n<li>ENTRYPOINT\u00a0<a href=\"http:\/\/opskumu.github.io\/the%20preferred%20exec%20form%EF%BC%8C%E4%BC%98%E5%85%88%E9%80%89%E6%8B%A9\" target=\"_blank\" rel=\"nofollow noopener\">&#8220;executable&#8221;, &#8220;param1&#8221;, &#8220;param2&#8221;<\/a><\/li>\n<li>ENTRYPOINT command param1 param2 (shell form)<\/li>\n<\/ul>\n<p>\u914d\u7f6e\u5bb9\u5668\u542f\u52a8\u540e\u6267\u884c\u7684\u547d\u4ee4\uff0c\u5e76\u4e14\u4e0d\u53ef\u88ab docker run \u63d0\u4f9b\u7684\u53c2\u6570\u8986\u76d6\uff0c\u800cCMD\u662f\u53ef\u4ee5\u88ab\u8986\u76d6\u7684\u3002\u5982\u679c\u9700\u8981\u8986\u76d6\uff0c\u5219\u53ef\u4ee5\u4f7f\u7528docker run &#8211;entrypoint\u9009\u9879\u3002<\/p>\n<p>\u6bcf\u4e2a Dockerfile \u4e2d\u53ea\u80fd\u6709\u4e00\u4e2aENTRYPOINT\uff0c\u5f53\u6307\u5b9a\u591a\u4e2a\u65f6\uff0c\u53ea\u6709\u6700\u540e\u4e00\u4e2a\u751f\u6548\u3002<\/p>\n<h4>Exec form ENTRYPOINT \u4f8b\u5b50<\/h4>\n<p>\u901a\u8fc7ENTRYPOINT\u4f7f\u7528 exec form \u65b9\u5f0f\u8bbe\u7f6e\u7a33\u5b9a\u7684\u9ed8\u8ba4\u547d\u4ee4\u548c\u9009\u9879\uff0c\u800c\u4f7f\u7528CMD\u6dfb\u52a0\u9ed8\u8ba4\u4e4b\u5916\u7ecf\u5e38\u88ab\u6539\u52a8\u7684\u9009\u9879\u3002<\/p>\n<div>\n<pre>FROM ubuntu\r\nENTRYPOINT [\"top\", \"-b\"]\r\nCMD [\"-c\"]<\/pre>\n<\/div>\n<p>\u901a\u8fc7 Dockerfile \u4f7f\u7528ENTRYPOINT\u5c55\u793a\u524d\u53f0\u8fd0\u884c Apache \u670d\u52a1<\/p>\n<div>\n<pre>FROM debian:stable\r\nRUN apt-get update &amp;&amp; apt-get install -y --force-yes apache2\r\nEXPOSE 80 443\r\nVOLUME [\"\/var\/www\", \"\/var\/log\/apache2\", \"\/etc\/apache2\"]\r\nENTRYPOINT [\"\/usr\/sbin\/apache2ctl\", \"-D\", \"FOREGROUND\"]<\/pre>\n<\/div>\n<h4>Shell form ENTRYPOINT \u4f8b\u5b50<\/h4>\n<p>\u8fd9\u79cd\u65b9\u5f0f\u4f1a\u5728\/bin\/sh -c\u4e2d\u6267\u884c\uff0c\u4f1a\u5ffd\u7565\u4efb\u4f55CMD\u6216\u8005docker run\u547d\u4ee4\u884c\u9009\u9879\uff0c\u4e3a\u4e86\u786e\u4fdddocker stop\u80fd\u591f\u505c\u6b62\u957f\u65f6\u95f4\u8fd0\u884cENTRYPOINT\u7684\u5bb9\u5668\uff0c\u786e\u4fdd\u6267\u884c\u7684\u65f6\u5019\u4f7f\u7528exec\u9009\u9879\u3002<\/p>\n<div>\n<pre>FROM ubuntu\r\nENTRYPOINT exec top -b<\/pre>\n<\/div>\n<p>\u5982\u679c\u5728ENTRYPOINT\u5fd8\u8bb0\u4f7f\u7528exec\u9009\u9879\uff0c\u5219\u53ef\u4ee5\u4f7f\u7528CMD\u8865\u4e0a:<\/p>\n<div>\n<pre>FROM ubuntu\r\nENTRYPOINT top -b\r\nCMD --ignored-param1 # --ignored-param2 ... --ignored-param3 ... \u4f9d\u6b64\u7c7b\u63a8<\/pre>\n<\/div>\n<h3 id=\"articleHeader42\"><a name=\"t42\"><\/a>7.9 VOLUME<\/h3>\n<div>\n<pre>VOLUME [\"\/data\"]<\/pre>\n<\/div>\n<p>\u521b\u5efa\u4e00\u4e2a\u53ef\u4ee5\u4ece\u672c\u5730\u4e3b\u673a\u6216\u5176\u4ed6\u5bb9\u5668\u6302\u8f7d\u7684\u6302\u8f7d\u70b9\uff0c\u540e\u7eed\u5177\u4f53\u4ecb\u7ecd\u3002<\/p>\n<h3 id=\"articleHeader43\"><a name=\"t43\"><\/a>7.10 USER<\/h3>\n<div>\n<pre>USER daemon<\/pre>\n<\/div>\n<p>\u6307\u5b9a\u8fd0\u884c\u5bb9\u5668\u65f6\u7684\u7528\u6237\u540d\u6216 UID\uff0c\u540e\u7eed\u7684RUN\u3001CMD\u3001ENTRYPOINT\u4e5f\u4f1a\u4f7f\u7528\u6307\u5b9a\u7528\u6237\u3002<\/p>\n<h3 id=\"articleHeader44\"><a name=\"t44\"><\/a>7.11 WORKDIR<\/h3>\n<div>\n<pre>WORKDIR \/path\/to\/workdir<\/pre>\n<\/div>\n<p>\u4e3a\u540e\u7eed\u7684RUN\u3001CMD\u3001ENTRYPOINT\u6307\u4ee4\u914d\u7f6e\u5de5\u4f5c\u76ee\u5f55\u3002\u53ef\u4ee5\u4f7f\u7528\u591a\u4e2aWORKDIR\u6307\u4ee4\uff0c\u540e\u7eed\u547d\u4ee4\u5982\u679c\u53c2\u6570\u662f\u76f8\u5bf9\u8def\u5f84\uff0c\u5219\u4f1a\u57fa\u4e8e\u4e4b\u524d\u547d\u4ee4\u6307\u5b9a\u7684\u8def\u5f84\u3002<\/p>\n<div>\n<pre>WORKDIR \/a\r\nWORKDIR b\r\nWORKDIR c\r\nRUN pwd<\/pre>\n<\/div>\n<p>\u6700\u7ec8\u8def\u5f84\u662f\/a\/b\/c\u3002<\/p>\n<p>WORKDIR\u6307\u4ee4\u53ef\u4ee5\u5728ENV\u8bbe\u7f6e\u53d8\u91cf\u4e4b\u540e\u8c03\u7528\u73af\u5883\u53d8\u91cf:<\/p>\n<div>\n<pre>ENV DIRPATH \/path\r\nWORKDIR $DIRPATH\/$DIRNAME<\/pre>\n<\/div>\n<p>\u6700\u7ec8\u8def\u5f84\u5219\u4e3a \/path\/$DIRNAME\u3002<\/p>\n<h3 id=\"articleHeader45\"><a name=\"t45\"><\/a>7.12 ONBUILD<\/h3>\n<div>\n<pre>ONBUILD [INSTRUCTION]<\/pre>\n<\/div>\n<p>\u914d\u7f6e\u5f53\u6240\u521b\u5efa\u7684\u955c\u50cf\u4f5c\u4e3a\u5176\u5b83\u65b0\u521b\u5efa\u955c\u50cf\u7684\u57fa\u7840\u955c\u50cf\u65f6\uff0c\u6240\u6267\u884c\u7684\u64cd\u4f5c\u6307\u4ee4\u3002<\/p>\n<p>\u4f8b\u5982\uff0cDockerfile \u4f7f\u7528\u5982\u4e0b\u7684\u5185\u5bb9\u521b\u5efa\u4e86\u955c\u50cf image-A\uff1a<\/p>\n<div>\n<pre>[...]\r\nONBUILD ADD . \/app\/src\r\nONBUILD RUN \/usr\/local\/bin\/python-build --dir \/app\/src\r\n[...]<\/pre>\n<\/div>\n<p>\u5982\u679c\u57fa\u4e8e image-A \u521b\u5efa\u65b0\u7684\u955c\u50cf\u65f6\uff0c\u65b0\u7684 Dockerfile \u4e2d\u4f7f\u7528 FROM image-A \u6307\u5b9a\u57fa\u7840\u955c\u50cf\u65f6\uff0c\u4f1a\u81ea\u52a8\u6267\u884c ONBUILD \u6307\u4ee4\u5185\u5bb9\uff0c\u7b49\u4ef7\u4e8e\u5728\u540e\u9762\u6dfb\u52a0\u4e86\u4e24\u6761\u6307\u4ee4\u3002<\/p>\n<div>\n<pre># Automatically run the following\r\nADD . \/app\/src\r\nRUN \/usr\/local\/bin\/python-build --dir \/app\/src<\/pre>\n<\/div>\n<p>\u4f7f\u7528ONBUILD\u6307\u4ee4\u7684\u955c\u50cf\uff0c\u63a8\u8350\u5728\u6807\u7b7e\u4e2d\u6ce8\u660e\uff0c\u4f8b\u5982 ruby:1.9-onbuild\u3002<\/p>\n<h3 id=\"articleHeader46\"><a name=\"t46\"><\/a>7.13 Dockerfile Examples<\/h3>\n<div>\n<pre># Nginx\r\n#\r\n# VERSION               0.0.1\r\n\r\nFROM      ubuntu\r\nMAINTAINER Victor Vieux &lt;victor@docker.com&gt;\r\n\r\nRUN apt-get update &amp;&amp; apt-get install -y inotify-tools nginx apache2 openssh-server\r\n\r\n# Firefox over VNC\r\n#\r\n# VERSION               0.3\r\n\r\nFROM ubuntu\r\n\r\n# Install vnc, xvfb in order to create a 'fake' display and firefox\r\nRUN apt-get update &amp;&amp; apt-get install -y x11vnc xvfb firefox\r\nRUN mkdir ~\/.vnc\r\n# Setup a password\r\nRUN x11vnc -storepasswd 1234 ~\/.vnc\/passwd\r\n# Autostart firefox (might not be the best way, but it does the trick)\r\nRUN bash -c 'echo \"firefox\" &gt;&gt; \/.bashrc'\r\n\r\nEXPOSE 5900\r\nCMD    [\"x11vnc\", \"-forever\", \"-usepw\", \"-create\"]\r\n\r\n# Multiple images example\r\n#\r\n# VERSION               0.1\r\n\r\nFROM ubuntu\r\nRUN echo foo &gt; bar\r\n# Will output something like ===&gt; 907ad6c2736f\r\n\r\nFROM ubuntu\r\nRUN echo moo &gt; oink\r\n# Will output something like ===&gt; 695d7793cbe4\r\n\r\n# You\u1fbfll now have two images, 907ad6c2736f with \/bar, and 695d7793cbe4 with\r\n# \/oink.<\/pre>\n<\/div>\n<h3 id=\"articleHeader47\"><a name=\"t47\"><\/a>7.14 docker build<\/h3>\n<div>\n<pre>$ docker build --help\r\n\r\nUsage: docker build [OPTIONS] PATH | URL | -\r\n\r\nBuild a new image from the source code at PATH\r\n\r\n  --force-rm=false     Always remove intermediate containers, even after unsuccessful builds # \u79fb\u9664\u8fc7\u6e21\u5bb9\u5668\uff0c\u5373\u4f7f\u6784\u5efa\u5931\u8d25\r\n  --no-cache=false     Do not use cache when building the image                              # \u4e0d\u5b9e\u7528 cache        \r\n  -q, --quiet=false    Suppress the verbose output generated by the containers               \r\n  --rm=true            Remove intermediate containers after a successful build               # \u6784\u5efa\u6210\u529f\u540e\u79fb\u9664\u8fc7\u6e21\u5c42\u5bb9\u5668\r\n  -t, --tag=\"\"         Repository name (and optionally a tag) to be applied to the resulting image in case of success<\/pre>\n<\/div>\n<p>\u53c2\u8003\u6587\u6863:<a href=\"https:\/\/docs.docker.com\/reference\/builder\/\" target=\"_blank\" rel=\"nofollow noopener\">Dockerfile Reference<\/a><\/p>\n<h3 id=\"articleHeader48\"><a name=\"t48\"><\/a>7.15 dockerfile \u6700\u4f73\u5b9e\u8df5<\/h3>\n<ul>\n<li>\u4f7f\u7528.dockerignore\u6587\u4ef6<\/li>\n<\/ul>\n<p>\u4e3a\u4e86\u5728docker build\u8fc7\u7a0b\u4e2d\u66f4\u5feb\u4e0a\u4f20\u548c\u66f4\u52a0\u9ad8\u6548\uff0c\u5e94\u8be5\u4f7f\u7528\u4e00\u4e2a.dockerignore\u6587\u4ef6\u7528\u6765\u6392\u9664\u6784\u5efa\u955c\u50cf\u65f6\u4e0d\u9700\u8981\u7684\u6587\u4ef6\u6216\u76ee\u5f55\u3002\u4f8b\u5982,\u9664\u975e.git\u5728\u6784\u5efa\u8fc7\u7a0b\u4e2d\u9700\u8981\u7528\u5230\uff0c\u5426\u5219\u4f60\u5e94\u8be5\u5c06\u5b83\u6dfb\u52a0\u5230.dockerignore\u6587\u4ef6\u4e2d\uff0c\u8fd9\u6837\u53ef\u4ee5\u8282\u7701\u5f88\u591a\u65f6\u95f4\u3002<\/p>\n<ul>\n<li>\u907f\u514d\u5b89\u88c5\u4e0d\u5fc5\u8981\u7684\u8f6f\u4ef6\u5305<\/li>\n<\/ul>\n<p>\u4e3a\u4e86\u964d\u4f4e\u590d\u6742\u6027\u3001\u4f9d\u8d56\u6027\u3001\u6587\u4ef6\u5927\u5c0f\u4ee5\u53ca\u6784\u5efa\u65f6\u95f4\uff0c\u5e94\u8be5\u907f\u514d\u5b89\u88c5\u989d\u5916\u7684\u6216\u4e0d\u5fc5\u8981\u7684\u5305\u3002\u4f8b\u5982\uff0c\u4e0d\u9700\u8981\u5728\u4e00\u4e2a\u6570\u636e\u5e93\u955c\u50cf\u4e2d\u5b89\u88c5\u4e00\u4e2a\u6587\u672c\u7f16\u8f91\u5668\u3002<\/p>\n<ul>\n<li>\u6bcf\u4e2a\u5bb9\u5668\u90fd\u8dd1\u4e00\u4e2a\u8fdb\u7a0b<\/li>\n<\/ul>\n<p>\u5728\u5927\u591a\u6570\u60c5\u51b5\u4e0b\uff0c\u4e00\u4e2a\u5bb9\u5668\u5e94\u8be5\u53ea\u5355\u72ec\u8dd1\u4e00\u4e2a\u7a0b\u5e8f\u3002\u89e3\u8026\u5e94\u7528\u5230\u591a\u4e2a\u5bb9\u5668\u4f7f\u5176\u66f4\u5bb9\u6613\u6a2a\u5411\u6269\u5c55\u548c\u91cd\u7528\u3002\u5982\u679c\u4e00\u4e2a\u670d\u52a1\u4f9d\u8d56\u53e6\u5916\u4e00\u4e2a\u670d\u52a1\uff0c\u53ef\u4ee5\u53c2\u8003\u00a0<a href=\"https:\/\/docs.docker.com\/userguide\/dockerlinks\/\" target=\"_blank\" rel=\"nofollow noopener\">Linking Containers Together<\/a>\u3002<\/p>\n<ul>\n<li>\u6700\u5c0f\u5316\u5c42<\/li>\n<\/ul>\n<p>\u6211\u4eec\u77e5\u9053\u6bcf\u6267\u884c\u4e00\u4e2a\u6307\u4ee4\uff0c\u90fd\u4f1a\u6709\u4e00\u6b21\u955c\u50cf\u7684\u63d0\u4ea4\uff0c\u955c\u50cf\u662f\u5206\u5c42\u7684\u7ed3\u6784\uff0c\u5bf9\u4e8eDockerfile\uff0c\u5e94\u8be5\u627e\u5230\u53ef\u8bfb\u6027\u548c\u6700\u5c0f\u5316\u5c42\u4e4b\u95f4\u7684\u5e73\u8861\u3002<\/p>\n<ul>\n<li>\u591a\u884c\u53c2\u6570\u6392\u5e8f<\/li>\n<\/ul>\n<p>\u5982\u679c\u53ef\u80fd\uff0c\u901a\u8fc7\u5b57\u6bcd\u987a\u5e8f\u6765\u6392\u5e8f\uff0c\u8fd9\u6837\u53ef\u4ee5\u907f\u514d\u5b89\u88c5\u5305\u7684\u91cd\u590d\u5e76\u4e14\u66f4\u5bb9\u6613\u66f4\u65b0\u5217\u8868\uff0c\u53e6\u5916\u53ef\u8bfb\u6027\u4e5f\u4f1a\u66f4\u5f3a\uff0c\u6dfb\u52a0\u4e00\u4e2a\u7a7a\u884c\u4f7f\u7528\\\u6362\u884c:<\/p>\n<div>\n<pre>RUN apt-get update &amp;&amp; apt-get install -y \\\r\n  bzr \\\r\n  cvs \\\r\n  git \\\r\n  mercurial \\\r\n  subversion<\/pre>\n<\/div>\n<ul>\n<li>\u521b\u5efa\u7f13\u5b58<\/li>\n<\/ul>\n<p>\u955c\u50cf\u6784\u5efa\u8fc7\u7a0b\u4e2d\u4f1a\u6309\u7167Dockerfile\u7684\u987a\u5e8f\u4f9d\u6b21\u6267\u884c\uff0c\u6bcf\u6267\u884c\u4e00\u6b21\u6307\u4ee4 Docker \u4f1a\u5bfb\u627e\u662f\u5426\u6709\u5b58\u5728\u7684\u955c\u50cf\u7f13\u5b58\u53ef\u590d\u7528\uff0c\u5982\u679c\u6ca1\u6709\u5219\u521b\u5efa\u65b0\u7684\u955c\u50cf\u3002\u5982\u679c\u4e0d\u60f3\u4f7f\u7528\u7f13\u5b58\uff0c\u5219\u53ef\u4ee5\u5728docker build\u65f6\u6dfb\u52a0&#8211;no-cache=true\u9009\u9879\u3002<\/p>\n<p>\u4ece\u57fa\u7840\u955c\u50cf\u5f00\u59cb\u5c31\u5df2\u7ecf\u5728\u7f13\u5b58\u4e2d\u4e86\uff0c\u4e0b\u4e00\u4e2a\u6307\u4ee4\u4f1a\u5bf9\u6bd4\u6240\u6709\u7684\u5b50\u955c\u50cf\u5bfb\u627e\u662f\u5426\u6267\u884c\u76f8\u540c\u7684\u6307\u4ee4\uff0c\u5982\u679c\u6ca1\u6709\u5219\u7f13\u5b58\u5931\u6548\u3002\u5728\u5927\u591a\u6570\u60c5\u51b5\u4e0b\u53ea\u5bf9\u6bd4Dockerfile\u6307\u4ee4\u548c\u5b50\u955c\u50cf\u5c31\u8db3\u591f\u4e86\u3002ADD\u548cCOPY\u6307\u4ee4\u9664\u5916\uff0c\u6267\u884cADD\u548cCOPY\u65f6\u5b58\u653e\u5230\u955c\u50cf\u7684\u6587\u4ef6\u4e5f\u662f\u9700\u8981\u68c0\u67e5\u7684\uff0c\u5b8c\u6210\u4e00\u4e2a\u6587\u4ef6\u7684\u6821\u9a8c\u4e4b\u540e\u518d\u5229\u7528\u8fd9\u4e2a\u6821\u9a8c\u5728\u7f13\u5b58\u4e2d\u67e5\u627e\uff0c\u5982\u679c\u68c0\u6d4b\u7684\u6587\u4ef6\u6539\u53d8\u5219\u7f13\u5b58\u5931\u6548\u3002RUN apt-get -y update\u547d\u4ee4\u53ea\u68c0\u67e5\u547d\u4ee4\u662f\u5426\u5339\u914d\uff0c\u5982\u679c\u5339\u914d\u5c31\u4e0d\u4f1a\u518d\u6267\u884c\u66f4\u65b0\u4e86\u3002<\/p>\n<blockquote><p>\u4e3a\u4e86\u6709\u6548\u5730\u5229\u7528\u7f13\u5b58\uff0c\u4f60\u9700\u8981\u4fdd\u6301\u4f60\u7684 Dockerfile \u4e00\u81f4\uff0c\u5e76\u4e14\u5c3d\u91cf\u5728\u672b\u5c3e\u4fee\u6539\u3002<\/p><\/blockquote>\n<h4>Dockerfile \u6307\u4ee4<\/h4>\n<ul>\n<li>FROM: \u53ea\u8981\u53ef\u80fd\u5c31\u4f7f\u7528\u5b98\u65b9\u955c\u50cf\u5e93\u4f5c\u4e3a\u57fa\u7840\u955c\u50cf<\/li>\n<li>RUN: \u4e3a\u4fdd\u6301\u53ef\u8bfb\u6027\u3001\u65b9\u4fbf\u7406\u89e3\u3001\u53ef\u7ef4\u62a4\u6027\uff0c\u628a\u957f\u6216\u8005\u590d\u6742\u7684RUN\u8bed\u53e5\u4f7f\u7528\\\u5206\u9694\u7b26\u5206\u6210\u591a\u884c\n<ul>\n<li>\u4e0d\u5efa\u8baeRUN apt-get update\u72ec\u7acb\u6210\u884c\uff0c\u5426\u5219\u5982\u679c\u540e\u7eed\u5305\u6709\u66f4\u65b0\uff0c\u90a3\u4e48\u4e5f\u4e0d\u4f1a\u518d\u6267\u884c\u66f4\u65b0<\/li>\n<li>\u907f\u514d\u4f7f\u7528RUN apt-get upgrade\u6216\u8005dist-upgrade\uff0c\u5f88\u591a\u5fc5\u8981\u7684\u5305\u5728\u4e00\u4e2a\u975eprivileged\u6743\u9650\u7684\u5bb9\u5668\u91cc\u662f\u65e0\u6cd5\u5347\u7ea7\u7684\u3002\u5982\u679c\u77e5\u9053\u67d0\u4e2a\u5305\u66f4\u65b0\uff0c\u4f7f\u7528apt-get install -y xxx<\/li>\n<li>\u6807\u51c6\u5199\u6cd5\n<ul>\n<li>RUN apt-get update &amp;&amp; apt-get install -y package-bar package-foo<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>\u4f8b\u5b50:<\/p>\n<div>\n<pre>RUN apt-get update &amp;&amp; apt-get install -y \\\r\n    aufs-tools \\\r\n    automake \\\r\n    btrfs-tools \\\r\n    build-essential \\\r\n    curl \\\r\n    dpkg-sig \\\r\n    git \\\r\n    iptables \\\r\n    libapparmor-dev \\\r\n    libcap-dev \\\r\n    libsqlite3-dev \\\r\n    lxc=1.0* \\\r\n    mercurial \\\r\n    parallel \\\r\n    reprepro \\\r\n    ruby1.9.1 \\\r\n    ruby1.9.1-dev \\\r\n    s3cmd=1.1.0*<\/pre>\n<\/div>\n<ul>\n<li>CMD: \u63a8\u8350\u4f7f\u7528CMD [\u201cexecutable\u201d, \u201cparam1\u201d, \u201cparam2\u201d\u2026]\u8fd9\u79cd\u683c\u5f0f\uff0cCMD [\u201cparam\u201d, \u201cparam\u201d]\u5219\u914d\u5408ENTRYPOINT\u4f7f\u7528<\/li>\n<li>EXPOSE: Dockerfile \u6307\u5b9a\u8981\u516c\u5f00\u7684\u7aef\u53e3\uff0c\u4f7f\u7528docker run\u65f6\u6307\u5b9a\u6620\u5c04\u5230\u5bbf\u4e3b\u673a\u7684\u7aef\u53e3\u5373\u53ef<\/li>\n<li>ENV: \u4e3a\u4e86\u4f7f\u65b0\u7684\u8f6f\u4ef6\u66f4\u5bb9\u6613\u8fd0\u884c\uff0c\u53ef\u4ee5\u4f7f\u7528ENV\u66f4\u65b0PATH\u53d8\u91cf\u3002\u5982ENV PATH \/usr\/local\/nginx\/bin:$PATH\u786e\u4fddCMD [&#8220;nginx&#8221;]\u5373\u53ef\u8fd0\u884c<\/li>\n<\/ul>\n<p>ENV\u4e5f\u53ef\u4ee5\u8fd9\u6837\u5b9a\u4e49\u53d8\u91cf\uff1a<\/p>\n<div>\n<pre>ENV PG_MAJOR 9.3\r\nENV PG_VERSION 9.3.4\r\nRUN curl -SL http:\/\/example.com\/postgres-$PG_VERSION.tar.xz | tar -xJC \/usr\/src\/postgress &amp;&amp; \u2026\r\nENV PATH \/usr\/local\/postgres-$PG_MAJOR\/bin:$PATH<\/pre>\n<\/div>\n<ul>\n<li>ADDorCOPY:ADD\u6bd4COPY\u591a\u4e00\u4e9b\u7279\u6027\u300ctar \u6587\u4ef6\u81ea\u52a8\u89e3\u5305\u548c\u652f\u6301\u8fdc\u7a0b URL\u300d\uff0c\u4e0d\u63a8\u8350\u6dfb\u52a0\u8fdc\u7a0b URL<\/li>\n<\/ul>\n<p>\u5982\u4e0d\u63a8\u8350\u8fd9\u79cd\u65b9\u5f0f:<\/p>\n<div>\n<pre>ADD http:\/\/example.com\/big.tar.xz \/usr\/src\/things\/\r\nRUN tar -xJf \/usr\/src\/things\/big.tar.xz -C \/usr\/src\/things\r\nRUN make -C \/usr\/src\/things all<\/pre>\n<\/div>\n<p>\u63a8\u8350\u4f7f\u7528 curl \u6216\u8005 wget \u66ff\u6362\uff0c\u4f7f\u7528\u5982\u4e0b\u65b9\u5f0f:<\/p>\n<div>\n<pre>RUN mkdir -p \/usr\/src\/things \\\r\n    &amp;&amp; curl -SL http:\/\/example.com\/big.tar.gz \\\r\n    | tar -xJC \/usr\/src\/things \\\r\n    &amp;&amp; make -C \/usr\/src\/things all<\/pre>\n<\/div>\n<p>\u5982\u679c\u4e0d\u9700\u8981\u6dfb\u52a0 tar \u6587\u4ef6\uff0c\u63a8\u8350\u4f7f\u7528COPY\u3002<\/p>\n<p>\u53c2\u8003\u6587\u6863:<\/p>\n<ul>\n<li><a href=\"https:\/\/docs.docker.com\/articles\/dockerfile_best-practices\/\" target=\"_blank\" rel=\"nofollow noopener\">Best practices for writing Dockerfiles<\/a><\/li>\n<li><a href=\"http:\/\/dockerone.com\/article\/131\" target=\"_blank\" rel=\"nofollow noopener\">Dockerfile\u6700\u4f73\u5b9e\u8df5\uff08\u4e00\uff09<\/a><\/li>\n<li><a href=\"http:\/\/dockerone.com\/article\/132\" target=\"_blank\" rel=\"nofollow noopener\">Dockerfile\u6700\u4f73\u5b9e\u8df5\uff08\u4e8c\uff09<\/a><\/li>\n<\/ul>\n<h2 id=\"articleHeader49\"><a name=\"t49\"><\/a>\u516b\u3001\u5bb9\u5668\u6570\u636e\u7ba1\u7406<\/h2>\n<p>docker\u7ba1\u7406\u6570\u636e\u7684\u65b9\u5f0f\u6709\u4e24\u79cd\uff1a<\/p>\n<ul>\n<li>\u6570\u636e\u5377<\/li>\n<li>\u6570\u636e\u5377\u5bb9\u5668<\/li>\n<\/ul>\n<h3 id=\"articleHeader50\"><a name=\"t50\"><\/a>8.1 \u6570\u636e\u5377<\/h3>\n<p>\u6570\u636e\u5377\u662f\u4e00\u4e2a\u6216\u591a\u4e2a\u5bb9\u5668\u4e13\u95e8\u6307\u5b9a\u7ed5\u8fc7Union File System\u7684\u76ee\u5f55\uff0c\u4e3a\u6301\u7eed\u6027\u6216\u5171\u4eab\u6570\u636e\u63d0\u4f9b\u4e00\u4e9b\u6709\u7528\u7684\u529f\u80fd\uff1a<\/p>\n<ul>\n<li>\u6570\u636e\u5377\u53ef\u4ee5\u5728\u5bb9\u5668\u95f4\u5171\u4eab\u548c\u91cd\u7528<\/li>\n<li>\u6570\u636e\u5377\u6570\u636e\u6539\u53d8\u662f\u76f4\u63a5\u4fee\u6539\u7684<\/li>\n<li>\u6570\u636e\u5377\u6570\u636e\u6539\u53d8\u4e0d\u4f1a\u88ab\u5305\u62ec\u5728\u5bb9\u5668\u4e2d<\/li>\n<li>\u6570\u636e\u5377\u662f\u6301\u7eed\u6027\u7684\uff0c\u76f4\u5230\u6ca1\u6709\u5bb9\u5668\u4f7f\u7528\u5b83\u4eec<\/li>\n<\/ul>\n<h4>\u6dfb\u52a0\u4e00\u4e2a\u6570\u636e\u5377<\/h4>\n<p>\u4f60\u53ef\u4ee5\u4f7f\u7528-v\u9009\u9879\u6dfb\u52a0\u4e00\u4e2a\u6570\u636e\u5377\uff0c\u6216\u8005\u53ef\u4ee5\u4f7f\u7528\u591a\u6b21-v\u9009\u9879\u4e3a\u4e00\u4e2a docker \u5bb9\u5668\u8fd0\u884c\u6302\u8f7d\u591a\u4e2a\u6570\u636e\u5377\u3002<\/p>\n<div>\n<pre>$ sudo docker run --name data -v \/data -t -i ubuntu:14.04 \/bin\/bash # \u521b\u5efa\u6570\u636e\u5377\u7ed1\u5b9a\u5230\u5230\u65b0\u5efa\u5bb9\u5668\uff0c\u65b0\u5efa\u5bb9\u5668\u4e2d\u4f1a\u521b\u5efa \/data \u6570\u636e\u5377 bash-4.1# ls -ld \/data\/\r\ndrwxr-xr-x 2 root root 4096 Jul 23 06:59 \/data\/\r\nbash-4.1# df -Th\r\nFilesystem    Type    Size  Used Avail Use% Mounted on\r\n... ...\r\n              ext4     91G  4.6G   82G   6% \/data<\/pre>\n<\/div>\n<p>\u521b\u5efa\u7684\u6570\u636e\u5377\u53ef\u4ee5\u901a\u8fc7docker inspect\u83b7\u53d6\u5bbf\u4e3b\u673a\u5bf9\u5e94\u8def\u5f84<\/p>\n<div>\n<pre>$ sudo docker inspect data\r\n... ... \"Volumes\": { \"\/data\": \"\/var\/lib\/docker\/vfs\/dir\/151de401d268226f96d824fdf444e77a4500aed74c495de5980c807a2ffb7ea9\" }, # \u53ef\u4ee5\u770b\u5230\u521b\u5efa\u7684\u6570\u636e\u5377\u5bbf\u4e3b\u673a\u8def\u5f84 ... ...<\/pre>\n<\/div>\n<p>\u6216\u8005\u76f4\u63a5\u6307\u5b9a\u83b7\u53d6<\/p>\n<div>\n<pre>$ sudo docker inspect --format=\"{{ .Volumes }}\" data\r\nmap[\/data: \/var\/lib\/docker\/vfs\/dir\/151de401d268226f96d824fdf444e77a4500aed74c495de5980c807a2ffb7ea9]<\/pre>\n<\/div>\n<h4>\u6302\u8f7d\u5bbf\u4e3b\u673a\u76ee\u5f55\u4e3a\u4e00\u4e2a\u6570\u636e\u5377<\/h4>\n<p>-v\u9009\u9879\u9664\u4e86\u53ef\u4ee5\u521b\u5efa\u5377\uff0c\u4e5f\u53ef\u4ee5\u6302\u8f7d\u5f53\u524d\u4e3b\u673a\u7684\u4e00\u4e2a\u76ee\u5f55\u5230\u5bb9\u5668\u4e2d\u3002<\/p>\n<div>\n<pre>$ sudo docker run --name web -v \/source\/:\/web -t -i ubuntu:14.04 \/bin\/bash\r\nbash-4.1# ls -ld \/web\/\r\ndrwxr-xr-x 2 root root 4096 Jul 23 06:59 \/web\/\r\nbash-4.1# df -Th\r\n... ...\r\n              ext4     91G  4.6G   82G   6% \/web\r\nbash-4.1# exit<\/pre>\n<\/div>\n<p>\u9ed8\u8ba4\u6302\u8f7d\u5377\u662f\u53ef\u8bfb\u5199\u7684\uff0c\u53ef\u4ee5\u5728\u6302\u8f7d\u65f6\u6307\u5b9a\u53ea\u8bfb<\/p>\n<div>\n<pre>$ sudo docker run --rm --name test -v \/source\/:\/test:ro -t -i ubuntu:14.04 \/bin\/bash<\/pre>\n<\/div>\n<h3 id=\"articleHeader51\"><a name=\"t51\"><\/a>8.2 \u521b\u5efa\u548c\u6302\u8f7d\u4e00\u4e2a\u6570\u636e\u5377\u5bb9\u5668<\/h3>\n<p>\u5982\u679c\u4f60\u6709\u4e00\u4e9b\u6301\u4e45\u6027\u7684\u6570\u636e\u5e76\u4e14\u60f3\u5728\u5bb9\u5668\u95f4\u5171\u4eab\uff0c\u6216\u8005\u60f3\u7528\u5728\u975e\u6301\u4e45\u6027\u7684\u5bb9\u5668\u4e0a\uff0c\u6700\u597d\u7684\u65b9\u6cd5\u662f\u521b\u5efa\u4e00\u4e2a\u6570\u636e\u5377\u5bb9\u5668\uff0c\u7136\u540e\u4ece\u6b64\u5bb9\u5668\u4e0a\u6302\u8f7d\u6570\u636e\u3002<\/p>\n<p>\u521b\u5efa\u6570\u636e\u5377\u5bb9\u5668<\/p>\n<div>\n<pre>$ sudo docker run -t -i -d -v \/test --name test ubuntu:14.04 echo hello<\/pre>\n<\/div>\n<p>\u4f7f\u7528&#8211;volumes-from\u9009\u9879\u5728\u53e6\u4e00\u4e2a\u5bb9\u5668\u4e2d\u6302\u8f7d \/test \u5377\u3002\u4e0d\u7ba1 test \u5bb9\u5668\u662f\u5426\u8fd0\u884c\uff0c\u5176\u5b83\u5bb9\u5668\u90fd\u53ef\u4ee5\u6302\u8f7d\u8be5\u5bb9\u5668\u6570\u636e\u5377\uff0c\u5f53\u7136\u5982\u679c\u53ea\u662f\u5355\u72ec\u7684\u6570\u636e\u5377\u662f\u6ca1\u5fc5\u8981\u8fd0\u884c\u5bb9\u5668\u7684\u3002<\/p>\n<div>\n<pre>$ sudo docker run -t -i -d --volumes-from test --name test1 ubuntu:14.04 \/bin\/bash<\/pre>\n<\/div>\n<p>\u6dfb\u52a0\u53e6\u4e00\u4e2a\u5bb9\u5668<\/p>\n<div>\n<pre>$ sudo docker run -t -i -d --volumes-from test --name test2 ubuntu:14.04 \/bin\/bash<\/pre>\n<\/div>\n<p>\u4e5f\u53ef\u4ee5\u7ee7\u627f\u5176\u5b83\u6302\u8f7d\u6709 \/test \u5377\u7684\u5bb9\u5668<\/p>\n<div>\n<pre>$ sudo docker run -t -i -d --volumes-from test1 --name test3 ubuntu:14.04 \/bin\/bash<\/pre>\n<\/div>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/static.open-open.com\/lib\/uploadImg\/20150212\/20150212091035_912.png\" alt=\"\u975e\u5e38\u8be6\u7ec6\u7684 Docker \u5b66\u4e60\u7b14\u8bb0\" width=\"652\" height=\"209\" \/><\/p>\n<h3 id=\"articleHeader52\"><a name=\"t52\"><\/a>8.3 \u5907\u4efd\u3001\u6062\u590d\u6216\u8fc1\u79fb\u6570\u636e\u5377<\/h3>\n<h4>\u5907\u4efd<\/h4>\n<div>\n<pre>$ sudo docker run --rm --volumes-from test -v $(pwd):\/backup ubuntu:14.04 tar cvf \/backup\/test.tar \/test\r\ntar: Removing leading `\/' from member names\r\n\/test\/\r\n\/test\/b\r\n\/test\/d\r\n\/test\/c\r\n\/test\/a<\/pre>\n<\/div>\n<p>\u542f\u52a8\u4e00\u4e2a\u65b0\u7684\u5bb9\u5668\u5e76\u4e14\u4ecetest\u5bb9\u5668\u4e2d\u6302\u8f7d\u5377\uff0c\u7136\u540e\u6302\u8f7d\u5f53\u524d\u76ee\u5f55\u5230\u5bb9\u5668\u4e2d\u4e3a backup\uff0c\u5e76\u5907\u4efd test \u5377\u4e2d\u6240\u6709\u7684\u6570\u636e\u4e3a test.tar\uff0c\u6267\u884c\u5b8c\u6210\u4e4b\u540e\u5220\u9664\u5bb9\u5668&#8211;rm\uff0c\u6b64\u65f6\u5907\u4efd\u5c31\u5728\u5f53\u524d\u7684\u76ee\u5f55\u4e0b\uff0c\u540d\u4e3atest.tar\u3002<\/p>\n<div>\n<pre>$ ls # \u5bbf\u4e3b\u673a\u5f53\u524d\u76ee\u5f55\u4e0b\u4ea7\u751f\u4e86 test \u5377\u7684\u5907\u4efd\u6587\u4ef6 test.tar test.tar<\/pre>\n<\/div>\n<h4>\u6062\u590d<\/h4>\n<p>\u4f60\u53ef\u4ee5\u6062\u590d\u7ed9\u540c\u4e00\u4e2a\u5bb9\u5668\u6216\u8005\u53e6\u5916\u7684\u5bb9\u5668\uff0c\u65b0\u5efa\u5bb9\u5668\u5e76\u89e3\u538b\u5907\u4efd\u6587\u4ef6\u5230\u65b0\u7684\u5bb9\u5668\u6570\u636e\u5377<\/p>\n<div>\n<pre>$ sudo docker run -t -i -d -v \/test --name test4 ubuntu:14.04  \/bin\/bash $ sudo docker run --rm --volumes-from test4 -v $(pwd):\/backup ubuntu:14.04 tar xvf \/backup\/test.tar -C \/ # \u6062\u590d\u4e4b\u524d\u7684\u6587\u4ef6\u5230\u65b0\u5efa\u5377\u4e2d\uff0c\u6267\u884c\u5b8c\u540e\u81ea\u52a8\u5220\u9664\u5bb9\u5668 test\/ test\/b test\/d test\/c test\/a<\/pre>\n<\/div>\n<h3 id=\"articleHeader53\"><a name=\"t53\"><\/a>8.4 \u5220\u9664 Volumes<\/h3>\n<p>Volume \u53ea\u6709\u5728\u4e0b\u5217\u60c5\u51b5\u4e0b\u624d\u80fd\u88ab\u5220\u9664\uff1a<\/p>\n<ul>\n<li>docker rm -v\u5220\u9664\u5bb9\u5668\u65f6\u6dfb\u52a0\u4e86-v\u9009\u9879<\/li>\n<li>docker run &#8211;rm\u8fd0\u884c\u5bb9\u5668\u65f6\u6dfb\u52a0\u4e86&#8211;rm\u9009\u9879<\/li>\n<\/ul>\n<p>\u5426\u5219\uff0c\u4f1a\u5728\/var\/lib\/docker\/vfs\/dir\u76ee\u5f55\u4e2d\u9057\u7559\u5f88\u591a\u4e0d\u660e\u76ee\u5f55\u3002<\/p>\n<p>\u53c2\u8003\u6587\u6863\uff1a<\/p>\n<ul>\n<li><a href=\"http:\/\/docs.docker.com\/userguide\/dockervolumes\/#data-volumes\" target=\"_blank\" rel=\"nofollow noopener\">Managing Data in Containers<\/a><\/li>\n<li><a href=\"http:\/\/dockerone.com\/article\/128\" target=\"_blank\" rel=\"nofollow noopener\">\u6df1\u5165\u7406\u89e3Docker Volume\uff08\u4e00\uff09<\/a><\/li>\n<li><a href=\"http:\/\/dockerone.com\/article\/129\" target=\"_blank\" rel=\"nofollow noopener\">\u6df1\u5165\u7406\u89e3Docker Volume\uff08\u4e8c\uff09<\/a><\/li>\n<\/ul>\n<h2 id=\"articleHeader54\"><a name=\"t54\"><\/a>\u4e5d\u3001\u94fe\u63a5\u5bb9\u5668<\/h2>\n<p>docker \u5141\u8bb8\u628a\u591a\u4e2a\u5bb9\u5668\u8fde\u63a5\u5728\u4e00\u8d77\uff0c\u76f8\u4e92\u4ea4\u4e92\u4fe1\u606f\u3002docker \u94fe\u63a5\u4f1a\u521b\u5efa\u4e00\u79cd\u5bb9\u5668\u7236\u5b50\u7ea7\u522b\u7684\u5173\u7cfb\uff0c\u5176\u4e2d\u7236\u5bb9\u5668\u53ef\u4ee5\u770b\u5230\u5176\u5b50\u5bb9\u5668\u63d0\u4f9b\u7684\u4fe1\u606f\u3002<\/p>\n<h3 id=\"articleHeader55\"><a name=\"t55\"><\/a>9.1 \u5bb9\u5668\u547d\u540d<\/h3>\n<p>\u5728\u521b\u5efa\u5bb9\u5668\u65f6\uff0c\u5982\u679c\u4e0d\u6307\u5b9a\u5bb9\u5668\u7684\u540d\u5b57\uff0c\u5219\u9ed8\u8ba4\u4f1a\u81ea\u52a8\u521b\u5efa\u4e00\u4e2a\u540d\u5b57\uff0c\u8fd9\u91cc\u63a8\u8350\u7ed9\u5bb9\u5668\u547d\u540d\uff1a<\/p>\n<ul>\n<li>1\u3001\u7ed9\u5bb9\u5668\u547d\u540d\u65b9\u4fbf\u8bb0\u5fc6\uff0c\u5982\u547d\u540d\u8fd0\u884c web \u5e94\u7528\u7684\u5bb9\u5668\u4e3a web<\/li>\n<li>2\u3001\u4e3a docker \u5bb9\u5668\u63d0\u4f9b\u4e00\u4e2a\u53c2\u8003\uff0c\u5141\u8bb8\u65b9\u4fbf\u5176\u4ed6\u5bb9\u5668\u8c03\u7528\uff0c\u5982\u628a\u5bb9\u5668 web \u94fe\u63a5\u5230\u5bb9\u5668 db<\/li>\n<\/ul>\n<p>\u53ef\u4ee5\u901a\u8fc7&#8211;name\u9009\u9879\u7ed9\u5bb9\u5668\u81ea\u5b9a\u4e49\u547d\u540d\uff1a<\/p>\n<div>\n<pre>$ sudo docker run -d -t -i --name test ubuntu:14.04 bash              \r\n$ sudo docker  inspect --format=\"{{ .Nmae }}\" test\r\n\/test<\/pre>\n<\/div>\n<blockquote><p>\u6ce8\uff1a\u5bb9\u5668\u540d\u79f0\u5fc5\u987b\u552f\u4e00\uff0c\u5373\u4f60\u53ea\u80fd\u547d\u540d\u4e00\u4e2a\u53ebtest\u7684\u5bb9\u5668\u3002\u5982\u679c\u4f60\u60f3\u590d\u7528\u5bb9\u5668\u540d\uff0c\u5219\u5fc5\u987b\u5728\u521b\u5efa\u65b0\u7684\u5bb9\u5668\u524d\u901a\u8fc7docker rm\u5220\u9664\u65e7\u7684\u5bb9\u5668\u6216\u8005\u521b\u5efa\u5bb9\u5668\u65f6\u6dfb\u52a0&#8211;rm\u9009\u9879\u3002<\/p><\/blockquote>\n<h3 id=\"articleHeader56\"><a name=\"t56\"><\/a>9.2 \u94fe\u63a5\u5bb9\u5668<\/h3>\n<p>\u94fe\u63a5\u5141\u8bb8\u5bb9\u5668\u95f4\u5b89\u5168\u901a\u4fe1\uff0c\u4f7f\u7528&#8211;link\u9009\u9879\u521b\u5efa\u94fe\u63a5\u3002<\/p>\n<div>\n<pre>$ sudo docker run -d --name db training\/postgres<\/pre>\n<\/div>\n<p>\u57fa\u4e8e training\/postgres \u955c\u50cf\u521b\u5efa\u4e00\u4e2a\u540d\u4e3a db \u7684\u5bb9\u5668\uff0c\u7136\u540e\u4e0b\u9762\u521b\u5efa\u4e00\u4e2a\u53eb\u505a web \u7684\u5bb9\u5668\uff0c\u5e76\u4e14\u5c06\u5b83\u4e0e db \u76f8\u4e92\u8fde\u63a5\u5728\u4e00\u8d77<\/p>\n<div>\n<pre>$ sudo docker run -d -P --name web --link db:db training\/webapp python app.py<\/pre>\n<\/div>\n<p>&#8211;link &lt;name or id&gt;:alias\u9009\u9879\u6307\u5b9a\u94fe\u63a5\u5230\u7684\u5bb9\u5668\u3002<\/p>\n<p>\u67e5\u770b web \u5bb9\u5668\u7684\u94fe\u63a5\u5173\u7cfb:<\/p>\n<div>\n<pre>$ sudo docker inspect -f \"{{ .HostConfig.Links }}\" web\r\n[\/db:\/web\/db]<\/pre>\n<\/div>\n<p>\u53ef\u4ee5\u770b\u5230 web \u5bb9\u5668\u88ab\u94fe\u63a5\u5230 db \u5bb9\u5668\u4e3a\/web\/db\uff0c\u8fd9\u5141\u8bb8 web \u5bb9\u5668\u8bbf\u95ee db \u5bb9\u5668\u7684\u4fe1\u606f\u3002<\/p>\n<p>\u5bb9\u5668\u4e4b\u95f4\u7684\u94fe\u63a5\u5b9e\u9645\u505a\u4e86\u4ec0\u4e48\uff1f\u4e00\u4e2a\u94fe\u63a5\u5141\u8bb8\u4e00\u4e2a\u6e90\u5bb9\u5668\u63d0\u4f9b\u4fe1\u606f\u8bbf\u95ee\u7ed9\u4e00\u4e2a\u63a5\u6536\u5bb9\u5668\u3002\u5728\u672c\u4f8b\u4e2d\uff0cweb \u5bb9\u5668\u4f5c\u4e3a\u4e00\u4e2a\u63a5\u6536\u8005\uff0c\u5141\u8bb8\u8bbf\u95ee\u6e90\u5bb9\u5668 db \u7684\u76f8\u5173\u670d\u52a1\u4fe1\u606f\u3002Docker \u521b\u5efa\u4e86\u4e00\u4e2a\u5b89\u5168\u96a7\u9053\u800c\u4e0d\u9700\u8981\u5bf9\u5916\u516c\u5f00\u4efb\u4f55\u7aef\u53e3\u7ed9\u5916\u90e8\u5bb9\u5668\uff0c\u56e0\u6b64\u4e0d\u9700\u8981\u5728\u521b\u5efa\u5bb9\u5668\u7684\u65f6\u5019\u6dfb\u52a0-p\u6216-P\u6307\u5b9a\u5bf9\u5916\u516c\u5f00\u7684\u7aef\u53e3\uff0c\u8fd9\u4e5f\u662f\u94fe\u63a5\u5bb9\u5668\u7684\u6700\u5927\u597d\u5904\uff0c\u672c\u4f8b\u4e3a PostgreSQL \u6570\u636e\u5e93\u3002<\/p>\n<p>Docker \u4e3b\u8981\u901a\u8fc7\u4ee5\u4e0b\u4e24\u4e2a\u65b9\u5f0f\u63d0\u4f9b\u8fde\u63a5\u4fe1\u606f\u7ed9\u63a5\u6536\u5bb9\u5668\uff1a<\/p>\n<ul>\n<li>\u73af\u5883\u53d8\u91cf<\/li>\n<li>\u66f4\u65b0\/etc\/hosts\u6587\u4ef6<\/li>\n<\/ul>\n<h4>\u73af\u5883\u53d8\u91cf<\/h4>\n<p>\u5f53\u4e24\u4e2a\u5bb9\u5668\u94fe\u63a5\uff0cDocker \u4f1a\u5728\u76ee\u6807\u5bb9\u5668\u4e0a\u8bbe\u7f6e\u4e00\u4e9b\u73af\u5883\u53d8\u91cf\uff0c\u4ee5\u83b7\u53d6\u6e90\u5bb9\u5668\u7684\u76f8\u5173\u4fe1\u606f\u3002<\/p>\n<p>\u9996\u5148\uff0cDocker \u4f1a\u5728\u6bcf\u4e2a\u901a\u8fc7&#8211;link\u9009\u9879\u6307\u5b9a\u522b\u540d\u7684\u76ee\u6807\u5bb9\u5668\u4e0a\u8bbe\u7f6e\u4e00\u4e2a&lt;alias&gt;_NAME\u73af\u5883\u53d8\u91cf\u3002\u5982\u679c\u4e00\u4e2a\u540d\u4e3a web \u7684\u5bb9\u5668\u901a\u8fc7&#8211;link db:webdb\u88ab\u94fe\u63a5\u5230\u4e00\u4e2a\u540d\u4e3a db \u7684\u6570\u636e\u5e93\u5bb9\u5668\uff0c\u90a3\u4e48 web \u5bb9\u5668\u4e0a\u4f1a\u8bbe\u7f6e\u4e00\u4e2a\u73af\u5883\u53d8\u91cf\u4e3aWEBDB_NAME=\/web\/webdb.<\/p>\n<p>\u4ee5\u4e4b\u524d\u7684\u4e3a\u4f8b\uff0cDocker \u8fd8\u4f1a\u8bbe\u7f6e\u7aef\u53e3\u53d8\u91cf:<\/p>\n<div>\n<pre>$ sudo docker run --rm --name web2 --link db:db training\/webapp env\r\n. . .\r\nDB_NAME=\/web2\/db\r\nDB_PORT=tcp:\/\/172.17.0.5:5432           \r\nDB_PORT_5432_TCP=tcp:\/\/172.17.0.5:5432  # &lt;name&gt;_PORT_&lt;port&gt;_&lt;protocol&gt; \u534f\u8bae\u53ef\u4ee5\u662f TCP \u6216 UDP\r\nDB_PORT_5432_TCP_PROTO=tcp\r\nDB_PORT_5432_TCP_PORT=5432\r\nDB_PORT_5432_TCP_ADDR=172.17.0.5\r\n. . .<\/pre>\n<\/div>\n<blockquote><p>\u6ce8\uff1a\u8fd9\u4e9b\u73af\u5883\u53d8\u91cf\u53ea\u8bbe\u7f6e\u7ed9\u5bb9\u5668\u4e2d\u7684\u7b2c\u4e00\u4e2a\u8fdb\u7a0b\uff0c\u7c7b\u4f3c\u4e00\u4e9b\u5b88\u62a4\u8fdb\u7a0b (\u5982 sshd ) \u5f53\u4ed6\u4eec\u6d3e\u751f shells \u65f6\u4f1a\u6e05\u9664\u8fd9\u4e9b\u53d8\u91cf<\/p><\/blockquote>\n<h4>\u66f4\u65b0\/etc\/hosts\u6587\u4ef6<\/h4>\n<p>\u9664\u4e86\u73af\u5883\u53d8\u91cf\uff0cDocker \u4f1a\u5728\u76ee\u6807\u5bb9\u5668\u4e0a\u6dfb\u52a0\u76f8\u5173\u4e3b\u673a\u6761\u76ee\u5230\/etc\/hosts\u4e2d\uff0c\u4e0a\u4f8b\u4e2d\u5c31\u662f web \u5bb9\u5668\u3002<\/p>\n<div>\n<pre>$ sudo docker run -t -i --rm --link db:db training\/webapp \/bin\/bash\r\nroot@aed84ee21bde:\/opt\/webapp# cat \/etc\/hosts\r\n172.17.0.7  aed84ee21bde\r\n. . .\r\n172.17.0.5  db<\/pre>\n<\/div>\n<blockquote><p>\/etc\/host\u6587\u4ef6\u5728\u6e90\u5bb9\u5668\u88ab\u91cd\u542f\u4e4b\u540e\u4f1a\u81ea\u52a8\u66f4\u65b0 IP \u5730\u5740\uff0c\u800c\u73af\u5883\u53d8\u91cf\u4e2d\u7684 IP \u5730\u5740\u5219\u4e0d\u4f1a\u81ea\u52a8\u66f4\u65b0\u7684\u3002<\/p><\/blockquote>\n<h2 id=\"articleHeader57\"><a name=\"t57\"><\/a>\u5341\u3001\u6784\u5efa\u79c1\u6709\u5e93<\/h2>\n<p>Docker \u5b98\u65b9\u63d0\u4f9b\u4e86 docker registry \u7684\u6784\u5efa\u65b9\u6cd5\u00a0<a href=\"https:\/\/github.com\/docker\/docker-registry\" target=\"_blank\" rel=\"nofollow noopener\">docker-registry<\/a><\/p>\n<h3 id=\"articleHeader58\"><a name=\"t58\"><\/a>10.1 \u5feb\u901f\u6784\u5efa<\/h3>\n<p>\u5feb\u901f\u6784\u5efa docker registry \u901a\u8fc7\u4ee5\u4e0b\u4e24\u6b65:<\/p>\n<ul>\n<li>\u5b89\u88c5 docker<\/li>\n<li>\u8fd0\u884c registry:docker run -p 5000:5000 registry<\/li>\n<\/ul>\n<p>\u8fd9\u79cd\u65b9\u6cd5\u901a\u8fc7 Docker hub \u4f7f\u7528\u5b98\u65b9\u955c\u50cf\u00a0<a href=\"https:\/\/registry.hub.docker.com\/_\/registry\/\" target=\"_blank\" rel=\"nofollow noopener\">official image from the Docker hub<\/a><\/p>\n<h3 id=\"articleHeader59\"><a name=\"t59\"><\/a>10.2 \u4e0d\u4f7f\u7528\u5bb9\u5668\u6784\u5efa registry<\/h3>\n<h4>\u5b89\u88c5\u5fc5\u8981\u7684\u8f6f\u4ef6<\/h4>\n<div>\n<pre>$ sudo apt-get install build-essential python-dev libevent-dev python-pip liblzma-dev<\/pre>\n<\/div>\n<h4>\u914d\u7f6e docker-registry<\/h4>\n<div>\n<pre>sudo pip install docker-registry<\/pre>\n<\/div>\n<p>\u6216\u8005 \u4f7f\u7528 github clone \u624b\u52a8\u5b89\u88c5<\/p>\n<div>\n<pre>$ git clone https:\/\/github.com\/dotcloud\/docker-registry.git\r\n$ cd docker-registry\/\r\n$ cp config\/config_sample.yml config\/config.yml\r\n$ mkdir \/data\/registry -p\r\n$ pip install .<\/pre>\n<\/div>\n<h4>\u8fd0\u884c<\/h4>\n<div>\n<pre>docker-registry<\/pre>\n<\/div>\n<h4>\u9ad8\u7ea7\u542f\u52a8\u65b9\u5f0f [\u4e0d\u63a8\u8350]<\/h4>\n<p>\u4f7f\u7528gunicorn\u63a7\u5236:<\/p>\n<div>\n<pre>gunicorn -c contrib\/gunicorn_config.py docker_registry.wsgi:application<\/pre>\n<\/div>\n<p>\u6216\u8005\u5bf9\u5916\u76d1\u542c\u5f00\u653e<\/p>\n<div>\n<pre>gunicorn --access-logfile - --error-logfile - -k gevent -b 0.0.0.0:5000 -w 4 --max-requests 100 docker_registry.wsgi:application<\/pre>\n<\/div>\n<h3 id=\"articleHeader60\"><a name=\"t60\"><\/a>10.3 \u63d0\u4ea4\u6307\u5b9a\u5bb9\u5668\u5230\u79c1\u6709\u5e93<\/h3>\n<div>\n<pre>$ docker tag ubuntu:12.04 \u79c1\u6709\u5e93IP:5000\/ubuntu:12.04\r\n$ docker push \u79c1\u6709\u5e93IP:5000\/ubuntu<\/pre>\n<\/div>\n<p>\u66f4\u591a\u7684\u914d\u7f6e\u9009\u9879\u63a8\u8350\u9605\u8bfb\u5b98\u65b9\u6587\u6863:<\/p>\n<ul>\n<li><a href=\"https:\/\/github.com\/docker\/docker-registry\/blob\/master\/README.md\" target=\"_blank\" rel=\"nofollow noopener\">Docker-Registry README<\/a><\/li>\n<\/ul>\n<ul>\n<li><a href=\"https:\/\/github.com\/docker\/docker-registry\/blob\/master\/ADVANCED.md\" target=\"_blank\" rel=\"nofollow noopener\">Docker-Registry advanced use<\/a><\/li>\n<li>\u6765\u81ea\uff1a<a href=\"http:\/\/opskumu.github.io\/docker.html\" target=\"_blank\" rel=\"nofollow noopener\">http:\/\/opskumu.github.io\/docker.html<\/a><\/li>\n<\/ul>\n<\/div>\n<\/div>\n<\/article>\n","protected":false},"excerpt":{"rendered":"<p>\u4e00\u3001Docker \u7b80\u4ecb Docker \u4e24<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[],"tags":[122],"class_list":["post-2763","post","type-post","status-publish","format-standard","hentry","tag-06-godocker"],"_links":{"self":[{"href":"https:\/\/i007.cc\/wordpress\/wp-json\/wp\/v2\/posts\/2763","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/i007.cc\/wordpress\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/i007.cc\/wordpress\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/i007.cc\/wordpress\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/i007.cc\/wordpress\/wp-json\/wp\/v2\/comments?post=2763"}],"version-history":[{"count":0,"href":"https:\/\/i007.cc\/wordpress\/wp-json\/wp\/v2\/posts\/2763\/revisions"}],"wp:attachment":[{"href":"https:\/\/i007.cc\/wordpress\/wp-json\/wp\/v2\/media?parent=2763"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/i007.cc\/wordpress\/wp-json\/wp\/v2\/categories?post=2763"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/i007.cc\/wordpress\/wp-json\/wp\/v2\/tags?post=2763"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}