本指南详细介绍了在无网络连接环境下,如何使用二进制包部署Docker运行环境。虽然Docker官方并不推荐在生产环境中采用此方法,但在某些特定情境下,例如在没有互联网接入的环境中,这可能是唯一的解决方案。
本文把系统基础环境配置和 Docker 二进制安装合并成一条完整路径:先把系统准备好,再装 Docker,最后配 Compose。所有步骤都不依赖外网,适合内网、政务云等隔离环境。
一、系统基础环境配置
主机名设置
设置主机名以便于识别和管理服务器。
hostnamectl set-hostname <你的主机名>
防火墙设置
确保防火墙服务启动并设置为开机自启,以增强系统安全性。
systemctl start firewalld
systemctl enable firewalld
SELinux设置
根据需要配置SELinux策略。如果选择禁用SELinux,请谨慎操作,并了解潜在的安全风险。
# 禁用SELinux(不推荐,除非您了解相关风险)
sed -i 's/SELINUX=enforcing/SELINUX=disabled/g' /etc/selinux/config
setenforce 0
DNS设置
配置DNS确保系统可以正确解析域名。
注意:DNS设置有一定的优先级。
/etc/sysconfig/network-scripts/ifcfg-xxxxxx>/etc/resolve.conf因此,在配置DNS时请注意。
编辑 /etc/resolv.conf 文件,添加你的 DNS 服务器:
vi /etc/resolv.conf
增加以下行, DNS服务器地址根据实际要求选择私有DNS或公共DNS
nameserver 223.5.5.5
nameserver 223.6.6.6
交换分区设置
根据系统内存大小和使用情况,决定是否禁用交换分区。禁用交换分区可以提高系统性能,但对内存不足的系统可能造成影响。
swapoff -a
修改 /etc/fstab 文件,防止系统启动时自动挂载 swap 分区:
sed -ri 's/.*swap.*/#&/' /etc/fstab
检查配置
cat /etc/fstab
/dev/mapper/cl-root / xfs defaults 0 0
UUID=6cf7f17e-04a4-4296-ab20-557e7447bd98 /boot ext4 defaults 1 2
UUID=8F29-961F /boot/efi vfat umask=0077,shortname=winnt 0 2
#/dev/mapper/cl-swap swap swap defaults 0 0
时区设置
设置正确的时区,确保系统时间的准确性。
timedatectl set-timezone Asia/Shanghai
时间同步设置
配置时间同步服务以确保系统时间与标准时间同步。可以选择NTP或Chrony等服务。 - 使用 NTP 详细配置,请参考 基于NTP实现时间同步服务 - 使用 Chrony 详细配置,请参考 基于Chrony实现时间同步服务
常用软件安装
安装常用的系统管理软件,以便于日常运维工作。
# 安装常用软件(具体软件包名称根据系统发行版而定)
# 例如,在基于RPM的系统中可能使用以下命令:
yum install lrzsz zip unzip tree vim net-tools telnet rsync
离线环境需要先在一台有网络的同版本机器上把 rpm 包拉下来,再拷贝到目标服务器安装:
```bash
有网机器:只下载不安装
yum --downloadonly --downloaddir=./pkg/ install -y ntp lrzsz zip unzip tree vim net-tools telnet rsync ```
拷贝到目标服务器后用
rpm -ivh --force安装。
二、Docker 离线安装与配置
step1: 软件下载
您可以通过以下链接下载所需的二进制软件包,并自行判断 docker 不同版本之间的兼容性问题。 - docker: 下载链接
step2: 上传与解压软件包
将下载的二进制软件包上传到服务器指定位置 /path/software/。
tar -xvf docker-26.1.4.tgz
chmod +x docker/*
step3: 复制文件至系统目录
将解压后的文件复制到系统目录。
sudo cp docker/* /usr/bin/
step4: 配置文件
创建并编辑 /etc/docker/daemon.json 文件,设置镜像仓库、DNS、日志策略等。
mkdir /etc/docker
cat << EOF > /etc/docker/daemon.json
{ "registry-mirrors": [
"https://registry.docker-cn.com",
"http://hub-mirror.c.163.com",
"https://almtd3fa.mirror.aliyuncs.com",
"https://docker.mirrors.ustc.edu.cn"
],
"dns": ["223.5.5.5", "223.6.6.6"],
"exec-opts": ["native.cgroupdriver=systemd"],
"max-concurrent-downloads": 10,
"max-concurrent-uploads": 5,
"log-opts": {
"max-size": "100m",
"max-file": "5"
},
"live-restore": true
}
EOF
step5: 创建 docker 数据目录
选择空闲空间最大的路径作为数据目录,此处示例为 /opt/docker。
mkdir -p /opt/docker
链接到默认数据目录
ln -s /opt/docker /var/lib/docker
step6: 创建docker用户组
创建 docker 用户组
sudo groupadd docker
添加当前用户到此用户组
sudo usermod -aG docker $USER
注销并重新登录,以便重新评估您的组成员身份。
如果您在虚拟机中运行 Linux,可能需要重新启动虚拟机以使更改生效。
或者,你也可以使用以下命令来激活组更改:
newgrp docker
确认您可以在无需 sudo 的情况下运行 docker 命令。
$ docker run hello-world
step7: 配置systemd管理服务
配置文件 docker.service
执行以下命令创建配置文件:
cat << EOF > /etc/systemd/system/docker.service
[Unit]
Description=Docker Application Container Engine
Documentation=https://docs.docker.com
BindsTo=containerd.service
After=network-online.target firewalld.service containerd.service
Wants=network-online.target
Requires=docker.socket
[Service]
Type=notify
# the default is not to use systemd for cgroups because the delegate issues still
# exists and systemd currently does not support the cgroup feature set required
# for containers run by docker
ExecStart=/usr/bin/dockerd -H fd:// --containerd=/run/containerd/containerd.sock
ExecReload=/bin/kill -s HUP $MAINPID
TimeoutSec=0
RestartSec=2
Restart=always
# Note that StartLimit* options were moved from "Service" to "Unit" in systemd 229.
# Both the old, and new location are accepted by systemd 229 and up, so using the old location
# to make them work for either version of systemd.
StartLimitBurst=3
# Note that StartLimitInterval was renamed to StartLimitIntervalSec in systemd 230.
# Both the old, and new name are accepted by systemd 230 and up, so using the old name to make
# this option work for either version of systemd.
StartLimitInterval=60s
# Having non-zero Limit*s causes performance problems due to accounting overhead
# in the kernel. We recommend using cgroups to do container-local accounting.
LimitNOFILE=infinity
LimitNPROC=infinity
LimitCORE=infinity
# Comment TasksMax if your systemd version does not support it.
# Only systemd 226 and above support this option.
TasksMax=infinity
# set delegate yes so that systemd does not reset the cgroups of docker containers
Delegate=yes
# kill only the docker process, not all processes in the cgroup
KillMode=process
[Install]
WantedBy=multi-user.target
EOF
配置文件docker.socket
执行以下命令创建配置文件:
cat << EOF > /usr/lib/systemd/system/docker.socket
[Unit]
Description=Docker Socket for the API
[Socket]
# If /var/run is not implemented as a symlink to /run, you may need to
# specify ListenStream=/var/run/docker.sock instead.
ListenStream=/run/docker.sock
SocketMode=0660
SocketUser=root
SocketGroup=docker
[Install]
WantedBy=sockets.target
EOF
配置文件 containerd.service
执行以下命令创建配置文件:
cat << EOF > /usr/lib/systemd/system/containerd.service
[Unit]
Description=containerd container runtime
Documentation=https://containerd.io
After=network.target local-fs.target
[Service]
ExecStartPre=-/sbin/modprobe overlay
ExecStart=/usr/bin/containerd
Type=notify
Delegate=yes
KillMode=process
Restart=always
RestartSec=5
# Having non-zero Limit*s causes performance problems due to accounting overhead
# in the kernel. We recommend using cgroups to do container-local accounting.
LimitNPROC=infinity
LimitCORE=infinity
LimitNOFILE=infinity
# Comment TasksMax if your systemd version does not supports it.
# Only systemd 226 and above support this version.
TasksMax=infinity
OOMScoreAdjust=-999
[Install]
WantedBy=multi-user.target
EOF
加载 systemd 配置
systemctl daemon-reload
启动 Docker 服务
systemctl start containerd.service
systemctl start docker.socket
systemctl start docker.service
设置 Docker 开机启动
systemctl enable containerd.service
systemctl enable docker.socket
systemctl enable docker.service
step8: 查看 Docker 服务状态
使用以下命令,如果能够正确输出Docker版本信息,则表示安装配置成功。
docker info
输出版本信息参考如下:
[root@localhost ~]# docker info
Client:
Version: 26.1.4
Context: default
Debug Mode: false
Server:
Containers: 0
Running: 0
Paused: 0
Stopped: 0
Images: 0
Server Version: 26.1.4
Storage Driver: overlay2
Backing Filesystem: xfs
Supports d_type: true
Using metacopy: false
Native Overlay Diff: false
userxattr: false
Logging Driver: json-file
Cgroup Driver: systemd
Cgroup Version: 1
Plugins:
Volume: local
Network: bridge host ipvlan macvlan null overlay
Log: awslogs fluentd gcplogs gelf journald json-file local splunk syslog
Swarm: inactive
Runtimes: io.containerd.runc.v2 runc
Default Runtime: runc
Init Binary: docker-init
containerd version: ae71819c4f5e67bb4d5ae76a6b735f29cc25774e
runc version: v1.1.12-0-g51d5e94
init version: de40ad0
Security Options:
seccomp
Profile: builtin
Kernel Version: 5.10.134-16.2.an8.x86_64
Operating System: Anolis OS 8.9
OSType: linux
Architecture: x86_64
CPUs: 4
Total Memory: 7.54GiB
Name: localhost.localdomain
ID: 3dad7203-bbc3-4b0c-ab44-e8a75c4d15fd
Docker Root Dir: /opt/docker
Debug Mode: false
Experimental: false
Insecure Registries:
127.0.0.0/8
Registry Mirrors:
https://registry.docker-cn.com/
http://hub-mirror.c.163.com/
https://almtd3fa.mirror.aliyuncs.com/
https://docker.mirrors.ustc.edu.cn/
Live Restore Enabled: true
Product License: Community Engine
三、Docker Compose 安装
step1: 软件下载
可以通过以下链接下载 Docker Compose 的二进制软件包,并确保与您的 Docker 版本兼容: - docker-compose: 下载链接
上传并拷贝文件
sudo cp /path/software/docker-compose-linux-x86_64 /usr/local/bin/docker-compose
赋予执行权限
sudo chmod +x /usr/local/bin/docker-compose
创建软链接
sudo ln -s /usr/local/bin/docker-compose /usr/bin/docker-compose
setp2: 服务验证
使用以下命令,如可以正确输出 Docker Compose 版本信息表示安装配置成功。
docker-compose -v
Docker Compose version v2.27.1
四、最佳实践
在生产环境中,请注意以下要点: - 选择Docker数据目录时,应预留充足的磁盘空间,以应对运行过程中产生的大量数据。 - 合理配置 Docker 运行参数,特别是日志管理,避免磁盘空间不足问题的发生。 - 在执行任何配置更改之前,建议备份当前的配置文件。 - 禁用SELinux之前,请确保了解其对系统安全的影响,并考虑配置SELinux为宽松模式而非完全禁用。 - 交换分区的禁用应根据系统的实际内存使用情况和性能要求来决定。 - 保持系统软件和安全补丁的最新状态,定期进行系统更新。
五、总结
通过上述步骤,您可以在无互联网连接的环境中成功部署Docker运行环境。这适用于需要在隔离网络中运行容器化应用的场景。
评论