ÔõÑùʹÓÃDocker¾ÙÐÐÍøÂçÉèÖúÍÇå¾²ÖÎÀí
ÔõÑùʹÓÃDocker¾ÙÐÐÍøÂçÉèÖúÍÇå¾²ÖÎÀí
Ëæ×ÅÔÆÅÌËãºÍÈÝÆ÷»¯ÊÖÒÕµÄÉú³¤£¬DockerÒѳÉΪÁËÒ»ÖÖÆÕ±éʹÓõÄÈÝÆ÷»¯Æ½Ì¨¡£Í¨¹ýʹÓÃDocker£¬ÎÒÃÇ¿ÉÒÔÀû±ãµØ½¨Éè¡¢°²ÅźÍÖÎÀíÖÖÖÖÓ¦Óá£È»¶ø£¬ÍøÂçÉèÖúÍÇå¾²ÖÎÀíÒ²ÊÇʹÓÃDockerµÄÒªº¦·½Ãæ¡£±¾ÎĽ«ÏÈÈÝÔõÑùʹÓÃDocker¾ÙÐÐÍøÂçÉèÖúÍÇå¾²ÖÎÀí£¬²¢ÌṩһЩÏêϸµÄ´úÂëʾÀý¡£
Ò»¡¢ÍøÂçÉèÖÃ
½¨ÉèÍøÂç
ÔÚDockerÖУ¬ÎÒÃÇ¿ÉÒÔʹÓÃÒÔÏÂÏÂÁÉèÒ»¸ö×Ô½ç˵µÄÍøÂ磺
docker network create mynetwork
µÇ¼ºó¸´ÖÆ
Õâ¸öÏÂÁ½¨ÉèÒ»¸öÃûΪmynetworkµÄÐÂÍøÂç¡£
ÅþÁ¬ÈÝÆ÷µ½ÍøÂç
Òª½«ÈÝÆ÷ÅþÁ¬µ½Ìض¨ÍøÂ磬¿ÉÒÔʹÓÃÒÔÏÂÏÂÁ
docker network connect mynetwork container_name
µÇ¼ºó¸´ÖÆ
Õâ¸öÏÂÁÈÝÆ÷ÅþÁ¬µ½ÃûΪmynetworkµÄÍøÂç¡£
¼ì²éÍøÂçÅþÁ¬
Òª¼ì²éÈÝÆ÷ÊÇ·ñÅþÁ¬µ½Ìض¨ÍøÂ磬¿ÉÒÔʹÓÃÒÔÏÂÏÂÁ
docker network inspect mynetwork
µÇ¼ºó¸´ÖÆ
Õâ¸öÏÂÁÏÔʾÓëÍøÂçÏà¹ØµÄÏêϸÐÅÏ¢£¬°üÀ¨ÅþÁ¬µ½¸ÃÍøÂçµÄÈÝÆ÷ÁÐ±í¡£
¶þ¡¢Çå¾²ÖÎÀí
ʹÓûá¼û¿ØÖÆÁÐ±í£¨ACL£©
DockerÔÊÐíÎÒÃÇʹÓÃACLÀ´¿ØÖÆÈÝÆ÷µÄ»á¼ûȨÏÞ¡£ÎÒÃÇ¿ÉÒÔͨ¹ý±à¼DockerµÄÉèÖÃÎļþ£¨Í¨³£ÊÇ/etc/docker/daemon.json£©À´ÆôÓÃACL£¬²¢½ç˵»á¼û¹æÔò¡£ÒÔÏÂÊÇÒ»¸öʾÀýÉèÖãº
{ "authorization-plugins": ["acl"], "acl": [ { "name": "allow_admin", "source": {"type": "user", "name": "admin"}, "target": {"type": "container"} }, { "name": "deny_guest", "source": {"type": "user", "name": "guest"}, "target": {"type": "container"} } ] }
µÇ¼ºó¸´ÖÆ
ÔÚÕâ¸öÉèÖÃÖУ¬ÎÒÃǽç˵ÁËÁ½¸öACL¹æÔò¡£µÚÒ»¸ö¹æÔòÔÊÐíÃûΪadminµÄÓû§»á¼ûËùÓÐÈÝÆ÷£¬¶øµÚ¶þ¸ö¹æÔòեȡÃûΪguestµÄÓû§»á¼ûÈÝÆ÷¡£ÕâÑù£¬ÎÒÃÇ¿ÉÒÔͨ¹ýACLÀ´ÏÞÖÆË¿ÉÒÔ»á¼ûÈÝÆ÷¡£
ʹÓÃÇå¾²¾µÏñ
Docker¾µÏñÊÇÈÝÆ÷µÄ»ù´¡£¬Òò´ËÇå¾²¾µÏñÊÇʵÏÖÈÝÆ÷Çå¾²µÄÖ÷Òª×é³É²¿·Ö¡£ÎÒÃÇ¿ÉÒÔÑ¡ÔñʹÓÃÇå¾²µÄ»ù´¡¾µÏñ£¬»òÕßͨ¹ýÔÚ¹¹½¨¾µÏñʱ¸üкÍÐÞ¸´Îó²îÀ´È·±£¾µÏñµÄÇå¾²ÐÔ¡£ÒÔÏÂÊÇһЩÏêϸµÄʾÀý´úÂ룺
ʹÓÃÇå¾²µÄ»ù´¡¾µÏñ£º
FROM ubuntu:20.04
µÇ¼ºó¸´ÖÆ
ÔÚÕâ¸öÀý×ÓÖУ¬ÎÒÃÇÑ¡ÔñÁËÒ»¸ö¹Ù·½µÄUbuntu 20.04¾µÏñ×÷Ϊ»ù´¡¾µÏñ¡£Õâ¸ö¾µÏñÒѾÓɹٷ½ÑéÖ¤²¢°´ÆÚ¸üУ¬Òò´Ë¾ßÓнϸߵÄÇå¾²ÐÔ¡£
¸üкÍÐÞ¸´Îó²î£º
FROM ubuntu:20.04 RUN apt-get update && apt-get upgrade -y
µÇ¼ºó¸´ÖÆ
ÔÚÕâ¸öÀý×ÓÖУ¬ÎÒÃÇÔÚ¹¹½¨¾µÏñʱʹÓÃapt-getÏÂÁî¸üкÍÉý¼¶²Ù×÷ϵͳÖеÄÈí¼þ°ü£¬ÒÔÐÞ¸´ÒÑÖªµÄÎó²î¡£
ͨ¹ýÑ¡ÔñÇå¾²µÄ»ù´¡¾µÏñºÍʵʱ¸üкÍÐÞ¸´¾µÏñÖеÄÎó²î£¬ÎÒÃÇ¿ÉÒÔÌá¸ßÈÝÆ÷µÄÇå¾²ÐÔ¡£
Èý¡¢×ܽá
ʹÓÃDocker¾ÙÐÐÍøÂçÉèÖúÍÇå¾²ÖÎÀíÊÇÈÝÆ÷»¯Ó¦Óð²ÅŵÄÖ÷Òª·½Ãæ¡£ÎÒÃÇ¿ÉÒÔͨ¹ý½¨ÉèÍøÂç¡¢ÅþÁ¬ÈÝÆ÷µ½Ìض¨ÍøÂçºÍ¼ì²éÍøÂçÅþÁ¬À´¾ÙÐÐÍøÂçÉèÖ᣶øͨ¹ýʹÓÃACLºÍÇå¾²¾µÏñ£¬ÎÒÃÇ¿ÉÒÔʵÑé»á¼û¿ØÖƺÍÌá¸ßÈÝÆ÷µÄÇå¾²ÐÔ¡£
ͨ¹ýÉÏÊöÏÈÈݵÄÒªÁìºÍʾÀý´úÂ룬ϣÍûÄܹ»×ÊÖú¶ÁÕ߸üºÃµØʹÓÃDocker¾ÙÐÐÍøÂçÉèÖúÍÇå¾²ÖÎÀí¡£Ê¹ÓÃÕâЩҪÁ죬ÎÒÃÇ¿ÉÒÔ¸üºÃµØÖÎÀíºÍ±£»¤ÈÝÆ÷»¯Ó¦Óã¬Ìá¸ßϵͳµÄ¿ÉÓÃÐÔºÍÇå¾²ÐÔ¡£
ÒÔÉϾÍÊÇÔõÑùʹÓÃDocker¾ÙÐÐÍøÂçÉèÖúÍÇå¾²ÖÎÀíµÄÏêϸÄÚÈÝ£¬¸ü¶àÇë¹Ø×¢±¾ÍøÄÚÆäËüÏà¹ØÎÄÕ£¡