环境信息
- 处理器架构:鲲鹏920 aarch64
- 操作系统版本:openEuler 20.03 (LTS)
- docker 版本:docker-ce-18.06.3.ce-3.el7
- docker-compose 版本:docker-compose-linux-aarch64 v2.27.0
容器镜像
| 序号 | 服务 | 原镜像 | 现镜像 | 备注 |
|---|---|---|---|---|
| 01 | 数据库MySQL | mysql:8.0.21 | arm64v8/mysql:8.0.29 | |
| 02 | 对象存储MinIO | minio/minio:RELEASE.2021-01-30T00-20-58Z | minio/minio:RELEASE.2020-11-25T22-36-25Z-arm64 | |
| 03 | Redis | redis:6.2.1 | arm64v8/redis:7.2.4-alpine | |
| 04 | Nginx | nginx:1.19.8 | arm64v8/nginx:1.19.8-alpine | |
| 05 | OpenJDK | openjdk:8u181-jdk-alpine | arm64v8/openjdk:8u181-alpine |
构建特殊镜像
Dockerfile ,修改基础镜像为Arm版本
FROM arm64v8/openjdk:8u181-alpine
RUN echo "http://mirrors.aliyun.com/alpine/v3.8/main" > /etc/apk/repositories && echo "http://mirrors.aliyun.com/alpine/v3.8/community" >> /etc/apk/repositories
RUN apk update
RUN apk add yasm && apk add ffmpeg && apk add curl
- 执行构建
# docker build -t arm64v8/openjdk:8u181-alpine-ffmpeg-curl .
[+] Building 28.8s (8/8) FINISHED docker:default
=> [internal] load build definition from Dockerfile 0.0s
=> => transferring dockerfile: 301B 0.0s
=> [internal] load metadata for docker.io/arm64v8/openjdk:8u181-alpine 0.0s
=> [internal] load .dockerignore 0.0s
=> => transferring context: 2B 0.0s
=> [1/4] FROM docker.io/arm64v8/openjdk:8u181-alpine 0.0s
=> [2/4] RUN echo "http://mirrors.aliyun.com/alpine/v3.8/main" > /etc/apk/repositories && echo "http://mirrors.aliyun.com/alpine/v3.8/community" >> /etc/apk/reposito 0.4s
=> [3/4] RUN apk update 2.1s
=> [4/4] RUN apk add yasm && apk add ffmpeg && apk add curl 25.9s
=> exporting to image 0.3s
=> => exporting layers 0.3s
=> => writing image sha256:804f144aa80e2f8cd31241998806ca12e3977d033b4ba969d29093371118c4d4 0.0s
=> => naming to docker.io/arm64v8/openjdk:8u181-alpine-ffmpeg-curl
查看系统信息
[root@DC1-06-002 ~]# hostnamectl
Static hostname: DC1-06-002
Icon name: computer-server
Chassis: server
Machine ID: d4969423b22a495aa39ee1f62425b7c8
Boot ID: 0ff3fe16b12c4be684302ea368842b23
Operating System: openEuler 20.03 (LTS)
Kernel: Linux 4.19.90-2003.4.0.0036.oe1.aarch64
Architecture: arm64
配置系统源
提示 配置时要注意当前系统的架构与当前系统要保持一致,可以参考上一步命令输出的信息。
- 查看当前配置
[OS]
name=OS
baseurl=https://repo.huaweicloud.com/openeuler/openEuler-20.03-LTS/OS/aarch64/
enabled=1
gpgcheck=1
gpgkey=https://repo.huaweicloud.com/openeuler/openEuler-20.03-LTS/OS/aarch64/RPM-GPG-KEY-openEuler
[everything]
name=everything
baseurl=https://repo.huaweicloud.com/openeuler/openEuler-20.03-LTS/everything/aarch64/
enabled=1
gpgcheck=1
gpgkey=https://repo.huaweicloud.com/openeuler/openEuler-20.03-LTS/everything/aarch64/RPM-GPG-KEY-openEuler
[EPOL]
name=EPOL
baseurl=https://repo.huaweicloud.com/openeuler/openEuler-20.03-LTS/EPOL/aarch64/
enabled=1
gpgcheck=1
gpgkey=https://repo.huaweicloud.com/openeuler/openEuler-20.03-LTS/OS/aarch64/RPM-GPG-KEY-openEuler
[debuginfo]
name=debuginfo
baseurl=https://repo.huaweicloud.com/openeuler/openEuler-20.03-LTS/debuginfo/aarch64/
enabled=1
gpgcheck=1
gpgkey=https://repo.huaweicloud.com/openeuler/openEuler-20.03-LTS/debuginfo/aarch64/RPM-GPG-KEY-openEuler
[source]
name=source
baseurl=https://repo.huaweicloud.com/openeuler/openEuler-20.03-LTS/source/
enabled=1
gpgcheck=1
gpgkey=https://repo.huaweicloud.com/openeuler/openEuler-20.03-LTS/source/RPM-GPG-KEY-openEuler
[update]
name=update
baseurl=https://repo.huaweicloud.com/openeuler/openEuler-20.03-LTS/update/aarch64/
enabled=1
gpgcheck=1
gpgkey=https://repo.huaweicloud.com/openeuler/openEuler-20.03-LTS/OS/aarch64/RPM-GPG-KEY-openEuler
yum clean all
yum makecache
yum update
移除旧版本
yum remove docker docker-client docker-client-latest docker-common docker-latest docker-latest-logrotate docker-logrotate docker-engine
配置 docker 源
[root@DC1-06-002 ~]# yum install -y yum-utils device-mapper-persistent-data lvm2
Last metadata expiration check: 0:00:12 ago on 2024年05月16日 星期四 05时32分14秒.
No match for argument: yum-utils
Package thin-provisioning-tools-0.7.6-5.oe1.aarch64 is already installed.
Package lvm2-8:2.02.181-8.oe1.aarch64 is already installed.
Error: Unable to find a match: yum-utils
[root@DC1-06-002 ~]# yum-config-manager --add-repo https://mirrors.aliyun.com/docker-ce/linux/centos/docker-ce.repo
添加仓库自:https://mirrors.aliyun.com/docker-ce/linux/centos/docker-ce.repo
[root@DC1-06-002 ~]# yum makecache
Docker CE Stable - aarch64 8.9 kB/s | 2.3 kB 00:00
Error: Failed to download metadata for repo 'docker-ce-stable': Cannot download repomd.xml: Cannot download repodata/repomd.xml: All mirrors were tried
curl -O https://mirrors.aliyun.com/docker-ce/linux/centos/7/aarch64/stable/repodata/repomd.xml
替换docker-ce.repo 文件中 $releaserver 为 8 这里必须这么该,因为OpenEuler默认的跟CentOS的不一样,官方没有给OpenEuler专用的,这里套用了CentOS 8的Docker CE源。
# 再次执行生成缓存
[root@DC1-06-002 yum.repos.d]# yum clean all
40 files removed
[root@DC1-06-002 yum.repos.d]# yum makecache
Docker CE Stable - aarch64 189 kB/s | 62 kB 00:00
OS 13 MB/s | 3.2 MB 00:00
everything 32 MB/s | 9.0 MB 00:00
EPOL 4.0 MB/s | 891 kB 00:00
debuginfo 10 MB/s | 2.7 MB 00:00
source 3.7 MB/s | 816 kB 00:00
update 43 MB/s | 16 MB 00:00
Metadata cache created.
# 成功了
安装docker依赖
yum install -y python3-policycoreutils policycoreutils policycoreutils-python-utils selinux-policy selinux-policy-base selinux-policy-targeted
......
Upgraded:
libselinux-3.1-1.oe1.aarch64 libsemanage-3.1-1.oe1.aarch64 libsepol-3.1-1.oe1.aarch64 policycoreutils-3.1-6.oe1.aarch64
python3-libselinux-3.1-1.oe1.aarch64 selinux-policy-3.14.2-66.oe1.noarch selinux-policy-targeted-3.14.2-66.oe1.noarch
Installed:
policycoreutils-python-utils-3.1-6.oe1.noarch python3-policycoreutils-3.1-6.oe1.noarch python3-audit-3.0-5.oe1.aarch64 checkpolicy-3.1-1.oe1.aarch64
python3-IPy-1.00-1.oe1.noarch python3-libsemanage-3.1-1.oe1.aarch64 python3-setools-4.3.0-3.oe1.aarch64
Complete!
yum install -y container-selinux
# 部分Euler OS可能需要手动下载container-selinux
# wget https://mirrors.huaweicloud.com/centos-altarch/7/extras/aarch64/Packages/container-selinux-2.119.2-1.911c772.el7_8.noarch.rpm
# dnf install -y https://mirrors.huaweicloud.com/centos-altarch/8.1.1911/AppStream/armhfp/os/Packages/container-selinux-2.94-1.git1e99f1d.module_el8.1.0+132+34fc7673.noarch.rpm
安装高版本docker
查看当前可以支持的版本信息
yum list available container-selinux
# 由于需要高版本 container-selinux,需要先升级该包版本
# 先下载包
wget https://mirrors.huaweicloud.com/centos-altarch/7/extras/aarch64/Packages/container-selinux-2.119.2-1.911c772.el7_8.noarch.rpm
# yum 安装解决依赖关系
yum install container-selinux-2.119.2-1.911c772.el7_8.noarch.rpm
# 安装docker-ce
yum install docker-ce-3:19.03.15-3.el8
安装 docker-ce
切记这里不要直接yum install docker-ce,会报错的
# yum install docker-ce docker-ce-cli containerd.io
[root@DC1-06-002 yum.repos.d]# yum install docker-ce docker-ce-cli containerd.io
Last metadata expiration check: 0:03:29 ago on 2024年05月16日 星期四 05时48分22秒.
Error:
Problem 1: cannot install the best candidate for the job
- nothing provides container-selinux >= 2:2.74 needed by docker-ce-3:26.1.2-1.el7.aarch64
Problem 2: cannot install the best candidate for the job
- nothing provides container-selinux >= 2:2.74 needed by containerd.io-1.6.31-3.1.el7.aarch64
(try to add '--skip-broken' to skip uninstallable packages or '--nobest' to use not only best candidate packages)
通过制定安装版本,有测试以下两个版本可以安装成功,可以根据自己情况选择
yum install docker-ce-18.06.3.ce-3.el7yum install docker-ce-3:19.03.15-3.el8yum install docker-ce-3:26.1.2-1.el8
```bash
yum install docker-ce-18.06.3.ce-3.el7
# 中间可能会弹出交互,直接y确认
[root@DC1-06-002 yum.repos.d]# yum install docker-ce-18.06.3.ce-3.el7
Last metadata expiration check: 0:04:09 ago on 2024年05月16日 星期四 05时48分22秒.
Dependencies resolved.
=============================================================================================================================================================================
Package Architecture Version Repository Size
=============================================================================================================================================================================
Installing:
docker-ce aarch64 18.06.3.ce-3.el7 docker-ce-stable 31 M
Installing dependencies:
container-selinux noarch 2:2.73-3.gitd7a3f33.oe1 OS 37 k
libcgroup aarch64 0.41-23.oe1 OS 94 k
Transaction Summary
=============================================================================================================================================================================
Install 3 Packages
Total download size: 31 M
Installed size: 141 M
Is this ok [y/N]: y
Downloading Packages:
(1/3): libcgroup-0.41-23.oe1.aarch64.rpm 756 kB/s | 94 kB 00:00
(2/3): container-selinux-2.73-3.gitd7a3f33.oe1.noarch.rpm 66 kB/s | 37 kB 00:00
(3/3): docker-ce-18.06.3.ce-3.el7.aarch64.rpm 14 MB/s | 31 MB 00:02
-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------
Total 14 MB/s | 31 MB 00:02
警告:/var/cache/dnf/docker-ce-stable-b401a908f39b682f/packages/docker-ce-18.06.3.ce-3.el7.aarch64.rpm: 头V4 RSA/SHA512 Signature, 密钥 ID 621e9f35: NOKEY
Docker CE Stable - aarch64 16 kB/s | 1.6 kB 00:00
Importing GPG key 0x621E9F35:
Userid : "Docker Release (CE rpm) <docker@docker.com>"
Fingerprint: 060A 61C5 1B55 8A7F 742B 77AA C52F EB6B 621E 9F35
From : https://mirrors.aliyun.com/docker-ce/linux/centos/gpg
Is this ok [y/N]: y
Key imported successfully
Running transaction check
Transaction check succeeded.
Running transaction test
Transaction test succeeded.
Running transaction
Preparing : 1/1
Running scriptlet: libcgroup-0.41-23.oe1.aarch64 1/3
Installing : libcgroup-0.41-23.oe1.aarch64 1/3
Running scriptlet: libcgroup-0.41-23.oe1.aarch64 1/3
Installing : container-selinux-2:2.73-3.gitd7a3f33.oe1.noarch 2/3
Running scriptlet: container-selinux-2:2.73-3.gitd7a3f33.oe1.noarch 2/3
Deprecated, use selabel_lookup
Running scriptlet: docker-ce-18.06.3.ce-3.el7.aarch64 3/3
Installing : docker-ce-18.06.3.ce-3.el7.aarch64 3/3
Running scriptlet: docker-ce-18.06.3.ce-3.el7.aarch64 3/3
Verifying : docker-ce-18.06.3.ce-3.el7.aarch64 1/3
Verifying : container-selinux-2:2.73-3.gitd7a3f33.oe1.noarch 2/3
Verifying : libcgroup-0.41-23.oe1.aarch64 3/3
Installed:
docker-ce-18.06.3.ce-3.el7.aarch64 container-selinux-2:2.73-3.gitd7a3f33.oe1.noarch libcgroup-0.41-23.oe1.aarch64
Complete!
配置docker启动
systemctl enable docker && systemctl start docker
配置 docker 加速
创建配置目录
mkdir /etc/docker
添加配置文件
/etc/docker/daemon.json
{
"registry-mirrors": ["https://ccr.ccs.tencentyun.com/","https://docker.mirrors.ustc.edu.cn/"],
"insecure-registries":["docker.rockylinux.cn"],
"exec-opts": ["native.cgroupdriver=systemd"],
"log-driver": "json-file",
"log-opts": {
"max-size": "100m",
"max-file": "10"
},
"storage-driver": "overlay2",
"live-restore": true,
"default-shm-size": "128M",
"max-concurrent-downloads": 10,
"max-concurrent-uploads": 10,
"debug": false
}
重启服务
systemctl restart docker
docker 服务状态查看
# 查看docker版本信息
[root@DC1-06-002 local]# docker version
Client:
Version: 18.06.3-ce
API version: 1.38
Go version: go1.10.3
Git commit: d7080c1
Built: Wed Feb 20 02:24:54 2019
OS/Arch: linux/arm64
Experimental: false
Server:
Engine:
Version: 18.06.3-ce
API version: 1.38 (minimum version 1.12)
Go version: go1.10.3
Git commit: d7080c1
Built: Wed Feb 20 02:28:12 2019
OS/Arch: linux/arm64
Experimental: false
docker-compose 安装
yum -y install python3-devel libffi-devel openssl-devel
pip3 install docker-compose
独立文件方式安装 下载docker-Compose,可以根据情况下载相应的版本,这里选择当前日期(2024年05月16日)最新版本v2.27.0
下载文件
curl -L https://github.com/docker/compose/releases/download/v2.27.0/docker-compose-Linux-aarch64 -o /usr/local/bin/docker-compose
添加执行权限
chmod +x /usr/local/bin/docker-compose
创建软链接
ln -s /usr/local/bin/docker-compose /usr/bin/docker-compose
docker-compose 执行状态
docker-compose -v
Docker Compose version v2.27.0
导出镜像
docker save -o arm64v8-mysql-8.0.29.tar.gz arm64v8/mysql:8.0.29
docker save -o arm64v8-redis-7.2.4-alpine.tar.gz arm64v8/redis:7.2.4-alpine
docker save -o minio-RELEASE.2020-11-25T22-36-25Z-arm64.tar.gz minio/minio:RELEASE.2020-11-25T22-36-25Z-arm64
docker save -o arm64v8-openjdk-8u181-alpine.tar.gz arm64v8/openjdk:8u181-alpine
docker save -o arm64v8-openjdk-8u181-alpine-ffmpeg-curl.tar.gz arm64v8/openjdk:8u181-alpine-ffmpeg-curl
docker save -o arm64v8-nginx-1.19.8-alpine.tar.gz arm64v8/nginx:1.19.8-alpine
报错处理
问题1:Redis ARM64-COW-BUG 警告导致Redis容器无法启动
原因
警告提示内核存在 bug,可能会在进行后台存储操作时导致数据损坏。解决这个问题的推荐方法是更新到最新稳定版本的内核。如果你已经在使用最新的稳定内核但问题仍然存在,可能需要检查是否有特定于你的硬件或特定内核版本的已知问题。
处理
有两种方式: - 升级内核:确保你的操作系统使用的是支持你硬件架构的最新稳定内核。 - 忽略警告:如果你确认当前环境的稳定性,并接受潜在的风险,可以在 Redis 的配置文件 (
redis.conf) 中添加以下行来忽略这个特定警告:
ignore-warnings "ARM64-COW-BUG"
相关资料
https://www.cnblogs.com/lee-li/p/17712160.html
评论