【问题标题】:iptables rules break communication between Docker containersiptables 规则破坏了 Docker 容器之间的通信
【发布时间】:2016-02-23 08:13:17
【问题描述】:

nginx-proxy 是一个 Docker 容器,充当其他容器的反向代理。它使用 Docker API 来检测其他容器并自动代理到它们的流量。

我有一个简单的 nginx-proxy 设置:(其中 subdomain.example.com 被我的域替换)

docker run -d -p 80:80 -v /var/run/docker.sock:/tmp/docker.sock:ro jwilder/nginx-proxy
docker run -e VIRTUAL_HOST=subdomain.example.com kdelfour/cloud9-docker

当我关闭防火墙时,它可以正常工作。当我打开防火墙时,我从 nginx 收到 504 Gateway Time-out 错误。这意味着我可以在端口 80 上看到 nginx,但我的防火墙规则似乎限制了容器到容器和/或 Docker API 流量。

我创建了a GitHub issue,但是 nginx-proxy 的创建者说他从来没有遇到过这个问题。

这些是“防火墙关闭”规则:(这些工作)

iptables -F
iptables -P INPUT ACCEPT
iptables -P FORWARD ACCEPT
iptables -P OUTPUT ACCEPT

这些是我的“防火墙开启”规则:(这些不起作用)

# Based on tutorial from http://www.thegeekstuff.com/scripts/iptables-rules / http://www.thegeekstuff.com/2011/06/iptables-rules-examples/

# Delete existing rules
iptables -F

# Set default chain policies
iptables -P INPUT DROP
iptables -P FORWARD DROP
iptables -P OUTPUT DROP

# Allow loopback access
iptables -A INPUT -i lo -j ACCEPT
iptables -A OUTPUT -o lo -j ACCEPT

# Allow inbound/outbound SSH
iptables -A INPUT -i eth0 -p tcp --dport 22 -m state --state NEW,ESTABLISHED -j ACCEPT
iptables -A OUTPUT -o eth0 -p tcp --sport 22 -m state --state ESTABLISHED -j ACCEPT
iptables -A OUTPUT -o eth0 -p tcp --dport 22 -m state --state NEW,ESTABLISHED -j ACCEPT
iptables -A INPUT -i eth0 -p tcp --sport 22 -m state --state ESTABLISHED -j ACCEPT

# Allow inbound/outbound HTTP
iptables -A INPUT -i eth0 -p tcp --dport 80 -m state --state NEW,ESTABLISHED -j ACCEPT
iptables -A OUTPUT -o eth0 -p tcp --sport 80 -m state --state ESTABLISHED -j ACCEPT
iptables -A OUTPUT -o eth0 -p tcp --dport 80 -m state --state NEW,ESTABLISHED -j ACCEPT
iptables -A INPUT -i eth0 -p tcp --sport 80 -m state --state ESTABLISHED -j ACCEPT

# Allow inbound/outbound HTTPS
iptables -A INPUT -i eth0 -p tcp --dport 443 -m state --state NEW,ESTABLISHED -j ACCEPT
iptables -A OUTPUT -o eth0 -p tcp --sport 443 -m state --state ESTABLISHED -j ACCEPT
iptables -A OUTPUT -o eth0 -p tcp --dport 443 -m state --state NEW,ESTABLISHED -j ACCEPT
iptables -A INPUT -i eth0 -p tcp --sport 443 -m state --state ESTABLISHED -j ACCEPT

# Ping from inside to outside
iptables -A OUTPUT -p icmp --icmp-type echo-request -j ACCEPT
iptables -A INPUT -p icmp --icmp-type echo-reply -j ACCEPT
# Ping from outside to inside
iptables -A INPUT -p icmp --icmp-type echo-request -j ACCEPT
iptables -A OUTPUT -p icmp --icmp-type echo-reply -j ACCEPT

# Allow outbound DNS
iptables -A OUTPUT -p udp -o eth0 --dport 53 -j ACCEPT
iptables -A INPUT -p udp -i eth0 --sport 53 -j ACCEPT

# Allow outbound NTP
iptables -A OUTPUT -p udp -o eth0 --dport 123 -j ACCEPT
iptables -A INPUT -p udp -i eth0 --sport 123 -j ACCEPT

# This bit is from https://blog.andyet.com/2014/09/11/docker-host-iptables-forwarding
# Docker Rules: Forward chain between docker0 and eth0.
iptables -A FORWARD -i docker0 -o eth0 -j ACCEPT
iptables -A FORWARD -i eth0 -o docker0 -j ACCEPT
ip6tables -A FORWARD -i docker0 -o eth0 -j ACCEPT
ip6tables -A FORWARD -i eth0 -o docker0 -j ACCEPT

iptables-save > /etc/network/iptables.rules

为什么打开防火墙后代理无法工作?

【问题讨论】:

  • 您可以尝试在末尾添加iptables -P FORWARD ACCEPT 吗?如果可行,则问题出在 FORWARD 链中。如果它不起作用,您知道查看 INPUT 或 OUTPUT。
  • 好主意。我按照你的建议做了,它有效(即问题出在 FORWARD 链中)。我将开始研究这个,但如果解决方案突然出现在任何人面前,一定要说出来。
  • 我认为这是一个很好的解决方案:iptables -A FORWARD -i docker0 -j ACCEPT

标签: nginx proxy docker iptables


【解决方案1】:

感谢 Joel C 的建议(参见上面的 cmets),我修复了 FORWARD 链上的问题:

iptables -A FORWARD -i docker0 -j ACCEPT

【讨论】:

    猜你喜欢
    • 1970-01-01
    • 1970-01-01
    • 2017-10-17
    • 1970-01-01
    • 1970-01-01
    • 2018-10-09
    • 2018-04-30
    • 2020-09-13
    • 2021-05-03
    相关资源
    最近更新 更多