前一章我们讲过如何创建一个容器,本章将继续讲解容器创建时的各类自定义参数,借助这些参数,实现我们对服务的各类需求,如端口监听、目录映射、环境变量配置等。

我们还是先看容器创建参数帮助命令:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
[root@node1 ~]# docker run --help

Usage: docker run [OPTIONS] IMAGE [COMMAND] [ARG...]

Run a command in a new container

Options:
--add-host list Add a custom host-to-IP mapping (host:ip) (default [])
-a, --attach list Attach to STDIN, STDOUT or STDERR (default [])
--blkio-weight uint16 Block IO (relative weight), between 10 and 1000, or 0 to disable (default 0)
--blkio-weight-device weighted-device Block IO weight (relative device weight) (default [])
--cap-add list Add Linux capabilities (default [])
--cap-drop list Drop Linux capabilities (default [])
--cgroup-parent string Optional parent cgroup for the container
--cidfile string Write the container ID to the file
--cpu-count int CPU count (Windows only)
--cpu-percent int CPU percent (Windows only)
--cpu-period int Limit CPU CFS (Completely Fair Scheduler) period
--cpu-quota int Limit CPU CFS (Completely Fair Scheduler) quota
--cpu-rt-period int Limit CPU real-time period in microseconds
--cpu-rt-runtime int Limit CPU real-time runtime in microseconds
-c, --cpu-shares int CPU shares (relative weight)
--cpus decimal Number of CPUs (default 0.000)
--cpuset-cpus string CPUs in which to allow execution (0-3, 0,1)
--cpuset-mems string MEMs in which to allow execution (0-3, 0,1)
--credentialspec string Credential spec for managed service account (Windows only)
-d, --detach Run container in background and print container ID
--detach-keys string Override the key sequence for detaching a container
--device list Add a host device to the container (default [])
--device-read-bps throttled-device Limit read rate (bytes per second) from a device (default [])
--device-read-iops throttled-device Limit read rate (IO per second) from a device (default [])
--device-write-bps throttled-device Limit write rate (bytes per second) to a device (default [])
--device-write-iops throttled-device Limit write rate (IO per second) to a device (default [])
--disable-content-trust Skip image verification (default true)
--dns list Set custom DNS servers (default [])
--dns-option list Set DNS options (default [])
--dns-search list Set custom DNS search domains (default [])
--entrypoint string Overwrite the default ENTRYPOINT of the image
-e, --env list Set environment variables (default [])
--env-file list Read in a file of environment variables (default [])
--expose list Expose a port or a range of ports (default [])
--group-add list Add additional groups to join (default [])
--health-cmd string Command to run to check health
--health-interval duration Time between running the check (ns|us|ms|s|m|h) (default 0s)
--health-retries int Consecutive failures needed to report unhealthy
--health-timeout duration Maximum time to allow one check to run (ns|us|ms|s|m|h) (default 0s)
--help Print usage
-h, --hostname string Container host name
--init Run an init inside the container that forwards signals and reaps processes
--init-path string Path to the docker-init binary
-i, --interactive Keep STDIN open even if not attached
--io-maxbandwidth string Maximum IO bandwidth limit for the system drive (Windows only)
--io-maxiops uint Maximum IOps limit for the system drive (Windows only)
--ip string Container IPv4 address (e.g. 172.30.100.104)
--ip6 string Container IPv6 address (e.g. 2001:db8::33)
--ipc string IPC namespace to use
--isolation string Container isolation technology
--kernel-memory string Kernel memory limit
-l, --label list Set meta data on a container (default [])
--label-file list Read in a line delimited file of labels (default [])
--link list Add link to another container (default [])
--link-local-ip list Container IPv4/IPv6 link-local addresses (default [])
--log-driver string Logging driver for the container
--log-opt list Log driver options (default [])
--mac-address string Container MAC address (e.g. 92:d0:c6:0a:29:33)
-m, --memory string Memory limit
--memory-reservation string Memory soft limit
--memory-swap string Swap limit equal to memory plus swap: '-1' to enable unlimited swap
--memory-swappiness int Tune container memory swappiness (0 to 100) (default -1)
--name string Assign a name to the container
--network string Connect a container to a network (default "default")
--network-alias list Add network-scoped alias for the container (default [])
--no-healthcheck Disable any container-specified HEALTHCHECK
--oom-kill-disable Disable OOM Killer
--oom-score-adj int Tune host's OOM preferences (-1000 to 1000)
--pid string PID namespace to use
--pids-limit int Tune container pids limit (set -1 for unlimited)
--privileged Give extended privileges to this container
-p, --publish list Publish a container's port(s) to the host (default [])
-P, --publish-all Publish all exposed ports to random ports
--read-only Mount the container's root filesystem as read only
--restart string Restart policy to apply when a container exits (default "no")
--rm Automatically remove the container when it exits
--runtime string Runtime to use for this container
--security-opt list Security Options (default [])
--shm-size string Size of /dev/shm, default value is 64MB
--sig-proxy Proxy received signals to the process (default true)
--stop-signal string Signal to stop a container, SIGTERM by default (default "SIGTERM")
--stop-timeout int Timeout (in seconds) to stop a container
--storage-opt list Storage driver options for the container (default [])
--sysctl map Sysctl options (default map[])
--tmpfs list Mount a tmpfs directory (default [])
-t, --tty Allocate a pseudo-TTY
--ulimit ulimit Ulimit options (default [])
-u, --user string Username or UID (format: <name|uid>[:<group|gid>])
--userns string User namespace to use
--uts string UTS namespace to use
-v, --volume list Bind mount a volume (default [])
--volume-driver string Optional volume driver for the container
--volumes-from list Mount volumes from the specified container(s) (default [])
-w, --workdir string Working directory inside the container

以下仅讲解常用及重要的参数配置,其它未列出的见上面帮助说明。

常用参数解析

  • –add-host:添加额外的host信息到容器的hosts表中
  • -d, --detach:后台方式运行容器
  • -e, --env:自定义容器环境变量
  • –env-file:从文件中自定义容器环境变量
  • -h, --hostname:设置容器主机名
  • -i, --interactive:保持STDIN打开,一般结合-t使用,即交互模式运行容器
  • -l, --label:为容器打标签
  • –label-file:从文件中为容器获取标签列表
  • –link:链接另一个容器(主机名之间可互通)
  • –log-driver:获取容器输出的默认日志驱动类型
  • –log-opt:日志驱动对应的参数
  • –name:容器名
  • –network:指定容器的网络连接类型,默认bridge(桥接网络),支持 bridge/host/none/container四种类型
  • –oom-kill-disable:关闭OOM Killer(OOM后杀掉容器,默认开启)
  • –privileged:分配宿主机系统的特殊权限给容器
  • -p, --publish:容器在宿主机上端口映射
  • –read-only:只读方式挂载容器的根文件系统
  • –restart:容器存在时的重启策略,默认是no
  • –rm:当容器退出时会自动删除
  • –sysctl:配置容器内的sysctl参数
  • –ulimit:配置容器内的ulimit参数
  • -t, --tty:分配TTY伪终端
  • –user:容器内命令运行用户名
  • -v, --volume:绑定卷,可映射宿主机文件或目录到容器指定路径
  • -w, --workdir:容器内默认工作目录

常用配置示例

交互方式运行

1
2
3
4
docker run -it --rm \
--name nginx \
nginx:latest \
/bin/bash

(–rm参数,方便手动退出自动删除,一般用做临时测试)

后台方式运行(常用)

1
2
3
docker run -d \
--name nginx \
nginx:latest

映射端口

1
2
3
4
5
docker run -d \
--name nginx \
-p 80:80 \
-p 443:443 \
nginx:latest

docker ps输出结果的PORTS字段可以看到端口映射信息,也可通过docker port nginx 80/443来查看。

挂载目录

1
2
3
4
5
6
7
docker run -d \
--name nginx \
-p 80:80 \
-p 443:443 \
-v /etc/nginx/nginx.conf:/etc/nginx/nginx.conf \
-v /var/log/nginx:/var/log/nginx \
nginx:latest

挂载的目录数据会持久化,不会因为容器的删除而丢失。

配置环境变量

1
2
3
4
5
6
7
8
docker run -d \
--name nginx \
-p 80:80 \
-v /etc/nginx/nginx.conf:/etc/nginx/nginx.conf \
-v /var/log/nginx:/var/log/nginx \
-e NGINX_VERSION=1.14 \
-e NGINX_LOG_PATH=/var/log/nginx \
nginx:latest

配置自动重启

1
2
3
4
5
6
7
8
9
docker run -d \
--name nginx \
-p 80:80 \
-v /etc/nginx/nginx.conf:/etc/nginx/nginx.conf \
-v /var/log/nginx:/var/log/nginx \
-e NGINX_VERSION=1.14 \
-e NGINX_LOG_PATH=/var/log/nginx \
--restart always \
nginx:latest

此参数特别适用于需要开机启动的服务(随docker服务一起启动)