docker之点到点的容器网络的配置
一、搭建容器之间的网络
1.查看目前的网络环境
[root@liuxin-test01~]#ipa 1:lo:mtu65536qdiscnoqueuestateUNKNOWNqlen1 link/loopback00:00:00:00:00:00brd00:00:00:00:00:00 inet127.0.0.1/8scopehostlo valid_lftforeverpreferred_lftforever inet6::1/128scopehost valid_lftforeverpreferred_lftforever 2:eth0: mtu1500qdiscpfifo_faststateUPqlen1000 link/ether00:0c:29:ca:41:84brdff:ff:ff:ff:ff:ff inet192.168.8.192/24brd192.168.8.255scopeglobaleth0 valid_lftforeverpreferred_lftforever inet6fe80::20c:29ff:feca:4184/64scopelink valid_lftforeverpreferred_lftforever 3:eth1: mtu1500qdiscnoopstateDOWNqlen1000 link/ether00:0c:29:ca:41:8ebrdff:ff:ff:ff:ff:ff 4:docker0: mtu1500qdiscnoqueuestateDOWN link/ether02:42:a3:f4:2f:40brdff:ff:ff:ff:ff:ff inet172.17.0.1/16scopeglobaldocker0 valid_lftforeverpreferred_lftforever inet6fe80::42:a3ff:fef4:2f40/64scopelink valid_lftforeverpreferred_lftforever
2.创建两个无网络的容器
--rm参数讲解一下:
在Docker容器退出时,默认容器内部的文件系统仍然被保留,以方便调试并保留用户数据。
但是,对于foreground容器,由于其只是在开发调试过程中短期运行,其用户数据并无保留的必要,因而可以在容器启动时设置--rm选项,这样在容器退出时就能够自动清理容器内部的文件系统。
- --net=none无网络环境
- --net=bridge默认的参数,通过网桥(docker0)来设置容器的网络。也可以通过DOCKER_OPTS选项的-b参数来指定默认网桥
- --net=host共享主机的网络环境,不推荐这么设置
- --net=container两个容器共享IP地址和端口号等网络资源
下面两个容器是在两个终端中创建的
[root@liuxin-test01~]#dockerrun--rm-it--net=none--name='centos01'centos:7.4.1708 [root@f64cdc7ffff1/]#
[root@liuxin-test01~]#dockerrun--rm-it--net=none--name='centos02'centos:7.4.1708 [root@cd4df383b68e/]#
3.查看这两个容器的进程ID
[root@liuxin-test01~]#dockerinspect-f'{{.State.Pid}}'f64 21682 [root@liuxin-test01~]#dockerinspect-f'{{.State.Pid}}'cd4 21832
4.为这两个容器创建虚拟的网络空间
[root@liuxin-test01~]#mkdir-p/var/run/netns [root@liuxin-test01~]#ln-s/proc/21682/ns/net/var/run/netns/21682 [root@liuxin-test01~]#ln-s/proc/21832/ns/net/var/run/netns/21832 [root@liuxin-test01~]#
5.创建一对veth,两端命名为A、B
veth是虚拟的以太设备,类似于网卡设备。这个是linux容器技术引进的,要求必须成对出现
[root@liuxin-test01~]#iplinkaddAtypevethpeernameB [root@liuxin-test01~]#ipa 1:lo:mtu65536qdiscnoqueuestateUNKNOWNqlen1 link/loopback00:00:00:00:00:00brd00:00:00:00:00:00 inet127.0.0.1/8scopehostlo valid_lftforeverpreferred_lftforever inet6::1/128scopehost valid_lftforeverpreferred_lftforever 2:eth0: mtu1500qdiscpfifo_faststateUPqlen1000 link/ether00:0c:29:ca:41:84brdff:ff:ff:ff:ff:ff inet192.168.8.192/24brd192.168.8.255scopeglobaleth0 valid_lftforeverpreferred_lftforever inet6fe80::20c:29ff:feca:4184/64scopelink valid_lftforeverpreferred_lftforever 3:eth1: mtu1500qdiscnoopstateDOWNqlen1000 link/ether00:0c:29:ca:41:8ebrdff:ff:ff:ff:ff:ff 4:docker0: mtu1500qdiscnoqueuestateDOWN link/ether02:42:a3:f4:2f:40brdff:ff:ff:ff:ff:ff inet172.17.0.1/16scopeglobaldocker0 valid_lftforeverpreferred_lftforever inet6fe80::42:a3ff:fef4:2f40/64scopelink valid_lftforeverpreferred_lftforever 157:B@A: mtu1500qdiscnoopstateDOWNqlen1000 link/etherde:f7:3b:24:a5:0ebrdff:ff:ff:ff:ff:ff 158:A@B: mtu1500qdiscnoopstateDOWNqlen1000 link/ether9a:65:96:de:04:90brdff:ff:ff:ff:ff:ff
6.将两端分别放到两个容器中
我们可以看到,加入到容器之后,再次执行ipa已经看不到这两个设备了
[root@liuxin-test01~]#iplinksetAnetns21682 [root@liuxin-test01~]#iplinksetBnetns21832 [root@liuxin-test01~]#ipa 1:lo:mtu65536qdiscnoqueuestateUNKNOWNqlen1 link/loopback00:00:00:00:00:00brd00:00:00:00:00:00 inet127.0.0.1/8scopehostlo valid_lftforeverpreferred_lftforever inet6::1/128scopehost valid_lftforeverpreferred_lftforever 2:eth0: mtu1500qdiscpfifo_faststateUPqlen1000 link/ether00:0c:29:ca:41:84brdff:ff:ff:ff:ff:ff inet192.168.8.192/24brd192.168.8.255scopeglobaleth0 valid_lftforeverpreferred_lftforever inet6fe80::20c:29ff:feca:4184/64scopelink valid_lftforeverpreferred_lftforever 3:eth1: mtu1500qdiscnoopstateDOWNqlen1000 link/ether00:0c:29:ca:41:8ebrdff:ff:ff:ff:ff:ff 4:docker0: mtu1500qdiscnoqueuestateDOWN link/ether02:42:a3:f4:2f:40brdff:ff:ff:ff:ff:ff inet172.17.0.1/16scopeglobaldocker0 valid_lftforeverpreferred_lftforever inet6fe80::42:a3ff:fef4:2f40/64scopelink valid_lftforeverpreferred_lftforever
7.设置两个容器网络空间的ip
[root@liuxin-test01~]#ipnetnsexec21682ipaddradd192.168.99.1/32devA [root@liuxin-test01~]#ipnetnsexec21832ipaddradd192.168.99.2/32devB
8.启动两个容器的网络
[root@liuxin-test01~]#ipnetnsexec21682iplinksetAup [root@liuxin-test01~]#ipnetnsexec21832iplinksetBup
9.给这两个容器设置一下网关
[root@liuxin-test01~]#ipnetnsexec21682iprouteadd192.168.99.2/32devA [root@liuxin-test01~]#ipnetnsexec21832iprouteadd192.168.99.1/32devB
10.测试
[root@f64cdc7ffff1/]#ping192.168.99.2 PING192.168.99.2(192.168.99.2)56(84)bytesofdata. 64bytesfrom192.168.99.2:icmp_seq=1ttl=64time=0.095ms
[root@cd4df383b68e/]#ping192.168.99.1 PING192.168.99.1(192.168.99.1)56(84)bytesofdata. 64bytesfrom192.168.99.1:icmp_seq=1ttl=64time=0.057ms
以上就是本文的全部内容,希望对大家的学习有所帮助,也希望大家多多支持毛票票。
声明:本文内容来源于网络,版权归原作者所有,内容由互联网用户自发贡献自行上传,本网站不拥有所有权,未作人工编辑处理,也不承担相关法律责任。如果您发现有涉嫌版权的内容,欢迎发送邮件至:czq8825#qq.com(发邮件时,请将#更换为@)进行举报,并提供相关证据,一经查实,本站将立刻删除涉嫌侵权内容。