【问题标题】:Inter-container communication in azure container instancesazure 容器实例中的容器间通信
【发布时间】:2020-07-15 15:25:00
【问题描述】:

我正在尝试在 azure 容器实例中创建容器实例组。我有两个 docker 映像:一个在暴露的端口 8000 上侦听的 guincorn Web 应用程序服务器和一个 nginx 代理服务器。我能够部署到 azure 容器实例,但在代理容器中出现以下错误。

> nginx: [emerg] host not found in upstream "web:8000" in /etc/nginx/conf.d/nginx.conf:7

似乎我没有正确配置容器网络。有人可以提示我应该如何在 azure 容器实例上配置容器间网络吗?我在本地机器上构建镜像,然后将它们推送到 docker hub,然后将容器组构建在 ACI YAML file

我可以使用以下配置文件让这个组在我的本地机器上工作 → ACI .yml 配置:

name: webapp-containers
apiVersion: '2018-10-01'
location: eastus
properties: # Properties of a container group
    containers: # Array of container instances in group

    - name: web # Instance name
      properties: # Instance properties
        image: johnvorsten/my_site_web:1.08
        environmentVariables: 
              [shortened...]
            - name: WEBAPP_INTERNAL_PORT
              value: '8000'
        resources:
            requests: 
                cpu: 1
                memoryInGb: 1
        ports: # Exposed on the container instance
            - protocol: tcp
              port: '8000'

    - name: webapp-proxy
      properties:
        image: johnvorsten/my_site_nginx:1.02
        resources:
            requests:
                cpu: 1
                memoryInGb: 0.5
        environmentVariables: 
            - name: PROXY_EXTERNAL_PORT
              value: '80' # Exposed on container
            - name: PROXY_EXTERNAL_PORT_HTTPS
              value: '443' # Exposed on container
            - name: WEBAPP_INTERNAL_PORT
              value: '8000'
            - name: WEBAPP_HOSTNAME_AZURE
              value: web

        ports: # Exposed on instance
            - protocol: tcp
              port: '80'
            - protocol: tcp
              port: '443'
        volumeMounts:
        - mountPath: /home/apps/web/static-serve
          name: static-serve

    imageRegistryCredentials:
    - server: index.docker.io
      username: username
      password: password

    osType: Linux
    ipAddress:
        type: Public
        dnsNameLabel: jv-webapp-group
        ports: # Exposed in container group (external)
            - protocol: tcp
              port: '80'
            - protocol: tcp
              port: '443'

    volumes: 
    - name: static-serve
      emptyDir: {}
tags: {}
type: Microsoft.ContainerInstance/containerGroups

我的 nginx 配置文件:

upstream upstream_server {
    server web:8000;
}

server {
    listen 80;
    listen [::]:443 ssl;
    listen 443 ssl;

    server_name localhost; # Change when deploying to production

    ssl_protocols TLSv1.2;

    ssl_ciphers [...]
    ssl_prefer_server_ciphers  on;

    ssl_session_cache    shared:SSL:1m;
    ssl_session_timeout  24h;

    keepalive_timeout 300; # up from 75 secs default

    add_header Strict-Transport-Security 'max-age=31536000; includeSubDomains';

    ssl_certificate      /etc/nginx/ssl.crt;
    ssl_certificate_key  /etc/nginx/ssl.key;

    access_log /var/log/nginx/access.log;
    error_log /var/log/nginx/error.log;

    location / {
        proxy_pass http://upstream_server;
        proxy_set_header Connection "";

        # See ip address of client (not proxy)
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;

        proxy_set_header Host $host;

        # Not sure what this is useful for
        proxy_set_header X-Forwarded-Host $server_name;
        proxy_redirect off;

        error_log  /var/log/nginx/proxy_pass_log.log;
    }

    location /static-serve/ {
        alias /home/app/web/static-serve/;
    }

} # End server

【问题讨论】:

    标签: docker nginx azure-container-instances


    【解决方案1】:

    来自MSDN :

    在一个容器组内,容器实例可以通过任何端口上的 localhost 相互访问,即使这些端口没有暴露在组的 IP 地址或容器外部

    【讨论】:

      【解决方案2】:

      J.Vo 提供的答案是正确的,但为了更好地理解, 容器组是运行在同一主机上并共享相同资源和生命周期的容器的集合。这个概念更像 Kubernetes 中的 pod,而不像 docker-compose 中的容器。

      因此,如果您想请求在 8000 端口上运行/公开的任何应用容器,您可以将 URI 设为 localhost:8000,而不是 web:8000

      【讨论】:

      • 这很有趣,因为如果您进入容器,您可以 ping 容器别名,但由于某种原因,nginx 无法解析容器别名...
      猜你喜欢
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 2022-09-28
      • 1970-01-01
      • 1970-01-01
      • 2021-11-26
      相关资源
      最近更新 更多