本指南详细介绍了在无网络连接环境下,如何使用二进制包部署Docker运行环境。虽然Docker官方并不推荐在生产环境中采用此方法,但在某些特定情境下,例如在没有互联网接入的环境中,这可能是唯一的解决方案。

本文把系统基础环境配置和 Docker 二进制安装合并成一条完整路径:先把系统准备好,再装 Docker,最后配 Compose。所有步骤都不依赖外网,适合内网、政务云等隔离环境。

一、系统基础环境配置

主机名设置

设置主机名以便于识别和管理服务器。

hostnamectl set-hostname <你的主机名>

防火墙设置

确保防火墙服务启动并设置为开机自启,以增强系统安全性。

systemctl start firewalld
systemctl enable firewalld

SELinux设置

根据需要配置SELinux策略。如果选择禁用SELinux,请谨慎操作,并了解潜在的安全风险。

# 禁用SELinux(不推荐,除非您了解相关风险)
sed -i 's/SELINUX=enforcing/SELINUX=disabled/g' /etc/selinux/config
setenforce 0

DNS设置

配置DNS确保系统可以正确解析域名。

注意:DNS设置有一定的优先级。 /etc/sysconfig/network-scripts/ifcfg-xxxxxx > /etc/resolve.conf 因此,在配置DNS时请注意。

编辑 /etc/resolv.conf 文件,添加你的 DNS 服务器:

vi /etc/resolv.conf

增加以下行, DNS服务器地址根据实际要求选择私有DNS或公共DNS

nameserver 223.5.5.5
nameserver 223.6.6.6

交换分区设置

根据系统内存大小和使用情况,决定是否禁用交换分区。禁用交换分区可以提高系统性能,但对内存不足的系统可能造成影响。

swapoff -a

修改 /etc/fstab 文件,防止系统启动时自动挂载 swap 分区:

sed -ri 's/.*swap.*/#&/' /etc/fstab

检查配置

cat /etc/fstab
/dev/mapper/cl-root     /                       xfs     defaults        0 0
UUID=6cf7f17e-04a4-4296-ab20-557e7447bd98 /boot                   ext4    defaults        1 2
UUID=8F29-961F          /boot/efi               vfat    umask=0077,shortname=winnt 0 2
#/dev/mapper/cl-swap     swap                    swap    defaults        0 0

时区设置

设置正确的时区,确保系统时间的准确性。

timedatectl set-timezone Asia/Shanghai

时间同步设置

配置时间同步服务以确保系统时间与标准时间同步。可以选择NTP或Chrony等服务。 - 使用 NTP 详细配置,请参考 基于NTP实现时间同步服务 - 使用 Chrony 详细配置,请参考 基于Chrony实现时间同步服务

常用软件安装

安装常用的系统管理软件,以便于日常运维工作。

# 安装常用软件(具体软件包名称根据系统发行版而定)
# 例如,在基于RPM的系统中可能使用以下命令:
yum install lrzsz zip unzip tree vim net-tools telnet rsync

离线环境需要先在一台有网络的同版本机器上把 rpm 包拉下来,再拷贝到目标服务器安装:

```bash

有网机器:只下载不安装

yum --downloadonly --downloaddir=./pkg/ install -y ntp lrzsz zip unzip tree vim net-tools telnet rsync ```

拷贝到目标服务器后用 rpm -ivh --force 安装。

二、Docker 离线安装与配置

step1: 软件下载

您可以通过以下链接下载所需的二进制软件包,并自行判断 docker 不同版本之间的兼容性问题。 - docker: 下载链接

step2: 上传与解压软件包

将下载的二进制软件包上传到服务器指定位置 /path/software/。

tar -xvf docker-26.1.4.tgz
chmod +x docker/*

step3: 复制文件至系统目录

将解压后的文件复制到系统目录。

sudo cp docker/* /usr/bin/

step4: 配置文件

创建并编辑 /etc/docker/daemon.json 文件,设置镜像仓库、DNS、日志策略等。

mkdir /etc/docker

cat << EOF > /etc/docker/daemon.json
{  "registry-mirrors": [
    "https://registry.docker-cn.com",
    "http://hub-mirror.c.163.com",
    "https://almtd3fa.mirror.aliyuncs.com",
    "https://docker.mirrors.ustc.edu.cn"
  ],
 "dns": ["223.5.5.5", "223.6.6.6"],
 "exec-opts": ["native.cgroupdriver=systemd"],
 "max-concurrent-downloads": 10,
 "max-concurrent-uploads": 5,
 "log-opts": {
    "max-size": "100m",
    "max-file": "5"
    },
    "live-restore": true
}
EOF

step5: 创建 docker 数据目录

选择空闲空间最大的路径作为数据目录,此处示例为 /opt/docker。

mkdir -p /opt/docker

链接到默认数据目录

ln -s /opt/docker /var/lib/docker

step6: 创建docker用户组

创建 docker 用户组

sudo groupadd docker

添加当前用户到此用户组

sudo usermod -aG docker $USER

注销并重新登录,以便重新评估您的组成员身份。

如果您在虚拟机中运行 Linux,可能需要重新启动虚拟机以使更改生效。

或者,你也可以使用以下命令来激活组更改:

newgrp docker

确认您可以在无需 sudo 的情况下运行 docker 命令。

$ docker run hello-world

step7: 配置systemd管理服务

配置文件 docker.service

执行以下命令创建配置文件:

cat << EOF > /etc/systemd/system/docker.service
[Unit]
Description=Docker Application Container Engine
Documentation=https://docs.docker.com
BindsTo=containerd.service
After=network-online.target firewalld.service containerd.service
Wants=network-online.target
Requires=docker.socket

[Service]
Type=notify
# the default is not to use systemd for cgroups because the delegate issues still
# exists and systemd currently does not support the cgroup feature set required
# for containers run by docker
ExecStart=/usr/bin/dockerd -H fd:// --containerd=/run/containerd/containerd.sock
ExecReload=/bin/kill -s HUP $MAINPID
TimeoutSec=0
RestartSec=2
Restart=always

# Note that StartLimit* options were moved from "Service" to "Unit" in systemd 229.
# Both the old, and new location are accepted by systemd 229 and up, so using the old location
# to make them work for either version of systemd.
StartLimitBurst=3

# Note that StartLimitInterval was renamed to StartLimitIntervalSec in systemd 230.
# Both the old, and new name are accepted by systemd 230 and up, so using the old name to make
# this option work for either version of systemd.
StartLimitInterval=60s

# Having non-zero Limit*s causes performance problems due to accounting overhead
# in the kernel. We recommend using cgroups to do container-local accounting.
LimitNOFILE=infinity
LimitNPROC=infinity
LimitCORE=infinity

# Comment TasksMax if your systemd version does not support it.
# Only systemd 226 and above support this option.
TasksMax=infinity

# set delegate yes so that systemd does not reset the cgroups of docker containers
Delegate=yes

# kill only the docker process, not all processes in the cgroup
KillMode=process

[Install]
WantedBy=multi-user.target
EOF

配置文件docker.socket

执行以下命令创建配置文件:

cat << EOF > /usr/lib/systemd/system/docker.socket
[Unit]
Description=Docker Socket for the API

[Socket]
# If /var/run is not implemented as a symlink to /run, you may need to
# specify ListenStream=/var/run/docker.sock instead.
ListenStream=/run/docker.sock
SocketMode=0660
SocketUser=root
SocketGroup=docker

[Install]
WantedBy=sockets.target
EOF

配置文件 containerd.service

执行以下命令创建配置文件:

cat << EOF > /usr/lib/systemd/system/containerd.service
[Unit]
Description=containerd container runtime
Documentation=https://containerd.io
After=network.target local-fs.target

[Service]
ExecStartPre=-/sbin/modprobe overlay
ExecStart=/usr/bin/containerd

Type=notify
Delegate=yes
KillMode=process
Restart=always
RestartSec=5
# Having non-zero Limit*s causes performance problems due to accounting overhead
# in the kernel. We recommend using cgroups to do container-local accounting.
LimitNPROC=infinity
LimitCORE=infinity
LimitNOFILE=infinity
# Comment TasksMax if your systemd version does not supports it.
# Only systemd 226 and above support this version.
TasksMax=infinity
OOMScoreAdjust=-999

[Install]
WantedBy=multi-user.target
EOF

加载 systemd 配置

systemctl daemon-reload

启动 Docker 服务

systemctl start containerd.service
systemctl start docker.socket
systemctl start docker.service

设置 Docker 开机启动

systemctl enable containerd.service
systemctl enable docker.socket
systemctl enable docker.service

step8: 查看 Docker 服务状态

使用以下命令,如果能够正确输出Docker版本信息,则表示安装配置成功。

docker info

输出版本信息参考如下:

[root@localhost ~]# docker info
Client:
 Version:    26.1.4
 Context:    default
 Debug Mode: false

Server:
 Containers: 0
  Running: 0
  Paused: 0
  Stopped: 0
 Images: 0
 Server Version: 26.1.4
 Storage Driver: overlay2
  Backing Filesystem: xfs
  Supports d_type: true
  Using metacopy: false
  Native Overlay Diff: false
  userxattr: false
 Logging Driver: json-file
 Cgroup Driver: systemd
 Cgroup Version: 1
 Plugins:
  Volume: local
  Network: bridge host ipvlan macvlan null overlay
  Log: awslogs fluentd gcplogs gelf journald json-file local splunk syslog
 Swarm: inactive
 Runtimes: io.containerd.runc.v2 runc
 Default Runtime: runc
 Init Binary: docker-init
 containerd version: ae71819c4f5e67bb4d5ae76a6b735f29cc25774e
 runc version: v1.1.12-0-g51d5e94
 init version: de40ad0
 Security Options:
  seccomp
   Profile: builtin
 Kernel Version: 5.10.134-16.2.an8.x86_64
 Operating System: Anolis OS 8.9
 OSType: linux
 Architecture: x86_64
 CPUs: 4
 Total Memory: 7.54GiB
 Name: localhost.localdomain
 ID: 3dad7203-bbc3-4b0c-ab44-e8a75c4d15fd
 Docker Root Dir: /opt/docker
 Debug Mode: false
 Experimental: false
 Insecure Registries:
  127.0.0.0/8
 Registry Mirrors:
  https://registry.docker-cn.com/
  http://hub-mirror.c.163.com/
  https://almtd3fa.mirror.aliyuncs.com/
  https://docker.mirrors.ustc.edu.cn/
 Live Restore Enabled: true
 Product License: Community Engine

三、Docker Compose 安装

step1: 软件下载

可以通过以下链接下载 Docker Compose 的二进制软件包,并确保与您的 Docker 版本兼容: - docker-compose: 下载链接

上传并拷贝文件

sudo cp /path/software/docker-compose-linux-x86_64  /usr/local/bin/docker-compose

赋予执行权限

sudo chmod +x /usr/local/bin/docker-compose

创建软链接

sudo ln -s /usr/local/bin/docker-compose /usr/bin/docker-compose

setp2: 服务验证

使用以下命令,如可以正确输出 Docker Compose 版本信息表示安装配置成功。

docker-compose -v
Docker Compose version v2.27.1

四、最佳实践

在生产环境中,请注意以下要点: - 选择Docker数据目录时,应预留充足的磁盘空间,以应对运行过程中产生的大量数据。 - 合理配置 Docker 运行参数,特别是日志管理,避免磁盘空间不足问题的发生。 - 在执行任何配置更改之前,建议备份当前的配置文件。 - 禁用SELinux之前,请确保了解其对系统安全的影响,并考虑配置SELinux为宽松模式而非完全禁用。 - 交换分区的禁用应根据系统的实际内存使用情况和性能要求来决定。 - 保持系统软件和安全补丁的最新状态,定期进行系统更新。

五、总结

通过上述步骤,您可以在无互联网连接的环境中成功部署Docker运行环境。这适用于需要在隔离网络中运行容器化应用的场景。

参考