【问题标题】:How to disable and enable internet connection from within Docker container?如何从 Docker 容器中禁用和启用互联网连接?
【发布时间】:2018-11-27 03:48:00
【问题描述】:

我正在清除 /etc/resolv.conf 以禁用网络:

sudo mv /etc/resolv.conf /etc/resolv_backup.conf
sudo touch /etc/resolv.conf

然后启用网络:

sudo mv /etc/resolv_backup.conf /etc/resolv.conf

但是资源很忙,我无法执行这些命令。

我想从容器内禁用互联网而不是使用:

docker network disconnect [OPTIONS] NETWORK CONTAINER

从部署容器的服务器执行此操作。 我正在使用 Alpine。

【问题讨论】:

    标签: shell docker alpine docker-container resolv


    【解决方案1】:

    从容器内部,通常禁止您更改网络状态:

    $ docker run -it --rm alpine:latest /bin/sh
    / # ip a
    1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN qlen 1
        link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
        inet 127.0.0.1/8 scope host lo
           valid_lft forever preferred_lft forever
    929: eth0@if930: <BROADCAST,MULTICAST,UP,LOWER_UP,M-DOWN> mtu 1500 qdisc noqueue state UP
        link/ether 02:42:ac:11:00:03 brd ff:ff:ff:ff:ff:ff
        inet 172.17.0.3/16 brd 172.17.255.255 scope global eth0
           valid_lft forever preferred_lft forever
    / # ip link set eth0 down
    ip: ioctl 0x8914 failed: Operation not permitted
    

    为了安全起见,这是为了防止应用程序逃离容器沙箱。 如果您不需要容器的安全性(因此我建议您不要这样做),您可以使用额外的网络功能运行您的容器:

    $ docker run -it --rm --cap-add NET_ADMIN alpine:latest /bin/sh
    / # netstat -nr
    Kernel IP routing table
    Destination     Gateway         Genmask         Flags   MSS Window  irtt Iface
    0.0.0.0         172.17.0.1      0.0.0.0         UG        0 0          0 eth0
    172.17.0.0      0.0.0.0         255.255.0.0     U         0 0          0 eth0
    / # ip a
    1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN qlen 1
        link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
        inet 127.0.0.1/8 scope host lo
           valid_lft forever preferred_lft forever
    933: eth0@if934: <BROADCAST,MULTICAST,UP,LOWER_UP,M-DOWN> mtu 1500 qdisc noqueue state UP
        link/ether 02:42:ac:11:00:03 brd ff:ff:ff:ff:ff:ff
        inet 172.17.0.3/16 brd 172.17.255.255 scope global eth0
           valid_lft forever preferred_lft forever
    / # ip link set eth0 down
    / # ping 8.8.8.8
    PING 8.8.8.8 (8.8.8.8): 56 data bytes
    ping: sendto: Network unreachable
    

    当您尝试恢复网络时,您还需要再次设置默认路由才能连接到外部网络:

    / # ip link set eth0 up
    / # ping 8.8.8.8
    PING 8.8.8.8 (8.8.8.8): 56 data bytes
    ping: sendto: Network unreachable
    / # netstat -nr
    Kernel IP routing table
    Destination     Gateway         Genmask         Flags   MSS Window  irtt Iface
    172.17.0.0      0.0.0.0         255.255.0.0     U         0 0          0 eth0
    / # route add default gw 172.17.0.1
    / # ping 8.8.8.8
    PING 8.8.8.8 (8.8.8.8): 56 data bytes
    64 bytes from 8.8.8.8: seq=0 ttl=58 time=12.518 ms
    64 bytes from 8.8.8.8: seq=1 ttl=58 time=11.481 ms
    ^C
    --- 8.8.8.8 ping statistics ---
    2 packets transmitted, 2 packets received, 0% packet loss
    round-trip min/avg/max = 11.481/11.999/12.518 ms
    

    【讨论】:

    • 通过使用ip link set eth0 down,您是否也会失去与同一网络的其他容器的连接(除了互联网访问)?
    • 是的,容器失去了除环回接口之外的所有网络访问。配置更细粒度的容器网络访问的更好位置是在具有入口/出口策略的容器之外。这些可以在 Istio/Envoy 等工具中看到,也可以在其他网络驱动程序中找到。作为一个快速破解,您可以尝试手动调整路由表并删除默认路由。
    • 感谢您的澄清!
    • 我不想失去与其他容器的连接,因为我想连接到数据库容器。
    【解决方案2】:

    首先,清除 resolv.conf 不是为容器禁用网络的正确方法。这只是避免了名称解析,但您仍然可以使用 IP 连接。

    要禁用网络,您应该使用正确的脚本,具体取决于您使用的是 systemd 还是 sysV。与此类似的东西应该可以工作(这取决于您的发行版):

    # /etc/init.d/networking stop
    # systemctl stop networking
    

    希望这会有所帮助! :-)

    【讨论】:

      猜你喜欢
      • 2021-07-13
      • 2021-01-12
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 2017-04-09
      • 1970-01-01
      相关资源
      最近更新 更多