3

我在 jenkins 的官方 docker 容器中运行 jenkins。我按照https://docs.docker.com/engine/installation/linux/debian/dockerfile上的说明进行了以下操作

FROM jenkins:2.32.1

# install docker inside this container
USER root
    # Install Docker inside Jenkins
    RUN apt-get update
    RUN apt-get purge "docker.io*"
    RUN apt-get update
    RUN apt-get install -y apt-transport-https ca-certificates gnupg2
    RUN apt-key adv \
       --keyserver hkp://ha.pool.sks-keyservers.net:80 \
       --recv-keys 58118E89F3A912897C070ADBF76221572C52609D
    RUN echo "deb https://apt.dockerproject.org/repo debian-jessie main" > /etc/apt/sources.list.d/docker.list
    RUN apt-get update
    RUN apt-cache policy docker-engine
    RUN apt-get update
    RUN apt-get install -y docker-engine
    RUN gpasswd -a jenkins docker
    USER jenkins

然后我执行以下操作:

  • 从这个 dockerfile 构建一个图像
  • 从镜像运行容器
  • 以root 用户身份在容器中执行 bash
  • sudo docker service start在容器内的 bash 中运行

这是我得到的:

root@1e0f4b325d58:/# sudo service docker start
mount: permission denied
rmdir: failed to remove ‘cpu’: Read-only file system
mount: permission denied
rmdir: failed to remove ‘cpuacct’: Read-only file system
mount: permission denied
rmdir: failed to remove ‘net_cls’: Read-only file system
mount: permission denied
rmdir: failed to remove ‘net_prio’: Read-only file system
/etc/init.d/docker: 96: ulimit: error setting limit (Operation not permitted)
4

1 回答 1

5

如果要在 docker 中运行 docker,则需要将容器作为特权容器运行。

所以需要这样的1):

docker run --privileged your_image:tag

您还需要小心使用 iptables 和 App Armour,但这需要经过一些修改。


另一种方法是允许访问容器内的 docker 守护进程,如下所示2):

docker run -v /var/run/docker.sock:/var/run/docker.sock your_image:tag

参考:

1 https://blog.docker.com/2013/09/docker-can-now-run-within-docker/

2 https://jpetazzo.github.io/2015/09/03/do-not-use-docker-in-docker-for-ci/

于 2017-01-19T13:04:57.013 回答