華為鯤鵬+麒麟系統安裝docker
阿新 • • 發佈:2021-10-16
華為鯤鵬麒麟安裝docker
安裝 Docker-ce
下載二進位制docker
官網下載地址:https://download.docker.com/linux/static/stable/aarch64/
解壓下載好的壓縮包
tar -zxvf docker-20.10.9.tgz
移動解壓出來的二進位制檔案到 /usr/bin
目錄中
mv docker/* /usr/bin/
測試啟動
dockerd
新增 systemd
新增 docker 的 systemd
服務指令碼至 /usr/lib/systemd/system/
指令碼參考自 https://github.com/docker/docker-ce
cat > /usr/lib/systemd/system/docker.service <<'EOF' [Unit] Description=Docker Application Container Engine Documentation=https://docs.docker.com After=network-online.target docker.socket firewalld.service containerd.service Wants=network-online.target containerd.service Requires=docker.socket [Service] Type=notify # the default is not to use systemd for cgroups because the delegate issues still # exists and systemd currently does not support the cgroup feature set required # for containers run by docker ExecStart=/usr/bin/dockerd -H fd:// --containerd=/run/containerd/containerd.sock ExecReload=/bin/kill -s HUP $MAINPID TimeoutStartSec=0 RestartSec=2 Restart=always # Note that StartLimit* options were moved from "Service" to "Unit" in systemd 229. # Both the old, and new location are accepted by systemd 229 and up, so using the old location # to make them work for either version of systemd. StartLimitBurst=3 # Note that StartLimitInterval was renamed to StartLimitIntervalSec in systemd 230. # Both the old, and new name are accepted by systemd 230 and up, so using the old name to make # this option work for either version of systemd. StartLimitInterval=60s # Having non-zero Limit*s causes performance problems due to accounting overhead # in the kernel. We recommend using cgroups to do container-local accounting. LimitNOFILE=infinity LimitNPROC=infinity LimitCORE=infinity # Comment TasksMax if your systemd version does not support it. # Only systemd 226 and above support this option. TasksMax=infinity # set delegate yes so that systemd does not reset the cgroups of docker containers Delegate=yes # kill only the docker process, not all processes in the cgroup KillMode=process OOMScoreAdjust=-500 [Install] WantedBy=multi-user.target EOF
# 使用這個才能啟動成功 cat > /usr/lib/systemd/system/docker.service <<'EOF' [Unit] Description=Docker Application Container Engine Documentation=https://docs.docker.com After=network-online.target firewalld.service Wants=network-online.target [Service] Type=notify EnvironmentFile=-/etc/sysconfig/docker EnvironmentFile=-/etc/sysconfig/docker-storage EnvironmentFile=-/etc/sysconfig/docker-network Environment=GOTRACEBACK=crash ExecStart=/usr/bin/dockerd $OPTIONS \ $DOCKER_STORAGE_OPTIONS \ $DOCKER_NETWORK_OPTIONS \ $INSECURE_REGISTRY ExecReload=/bin/kill -s HUP $MAINPID LimitNOFILE=1048576 LimitNPROC=1048576 LimitCORE=infinity # set delegate yes so that systemd does not reset the cgroups of docker containers Delegate=yes # kill only the docker process, not all processes in the cgroup KillMode=process [Install] WantedBy=multi-user.target EOF #============================================ cat > /etc/sysconfig/docker <<'EOF' # /etc/sysconfig/docker # Modify these options if you want to change the way the docker daemon runs OPTIONS='--live-restore' DOCKER_CERT_PATH=/etc/docker # If you have a registry secured with https but do not have proper certs # distributed, you can tell docker to not look for full authorization by # adding the registry to the INSECURE_REGISTRY line and uncommenting it. # INSECURE_REGISTRY='--insecure-registry' # Location used for temporary files, such as those created by # docker load and build operations. Default is /var/lib/docker/tmp # Can be overridden by setting the following environment variable. # DOCKER_TMPDIR=/var/tmp EOF #======================================================== cat > /etc/sysconfig/docker-storage <<'EOF' # This file may be automatically generated by an installation program. # By default, Docker uses a loopback-mounted sparse file in # /var/lib/docker. The loopback makes it slower, and there are some # restrictive defaults, such as 100GB max storage. # If your installation did not set a custom storage for Docker, you # may do it below. # Example: Use a custom pair of raw logical volumes (one for metadata, # one for data). # DOCKER_STORAGE_OPTIONS = --storage-opt dm.metadatadev=/dev/mylogvol/my-docker-metadata --storage-opt dm.datadev=/dev/mylogvol/my-docker-data DOCKER_STORAGE_OPTIONS= EOF #====================================================== cat > /etc/sysconfig/docker-network <<'EOF' # /etc/sysconfig/docker-network DOCKER_NETWORK_OPTIONS= EOF
下面的不需要,在鯤鵬麒麟系統走不通
################################
根據 docker.service
中 Unit.After
需求新增 docker.socket
指令碼至 /usr/lib/systemd/system/
指令碼參考自 https://github.com/docker/docker-ce
cat > /usr/lib/systemd/system/docker.socket <<'EOF' [Unit] Description=Docker Socket for the API [Socket] # If /var/run is not implemented as a symlink to /run, you may need to # specify ListenStream=/var/run/docker.sock instead. ListenStream=/run/docker.sock SocketMode=0660 SocketUser=root SocketGroup=docker [Install] WantedBy=sockets.target EOF
如果缺少該檔案,啟動 docker 時會報如下錯誤:
systemctl start docker
Failed to start docker.service: Unit docker.socket not found.
根據 docker.service
中 Unit.After
需求新增 containerd.service
指令碼至 /usr/lib/systemd/system/
指令碼參考自 https://github.com/containerd/containerd
cat > /usr/lib/systemd/system/containerd.service <<'EOF'
[Unit]
Description=containerd container runtime
Documentation=https://containerd.io
After=network.target local-fs.target
[Service]
ExecStartPre=-/sbin/modprobe overlay
ExecStart=/usr/bin/containerd
Type=notify
Delegate=yes
KillMode=process
Restart=always
RestartSec=5
# Having non-zero Limit*s causes performance problems due to accounting overhead
# in the kernel. We recommend using cgroups to do container-local accounting.
LimitNPROC=infinity
LimitCORE=infinity
LimitNOFILE=infinity
# Comment TasksMax if your systemd version does not supports it.
# Only systemd 226 and above support this version.
TasksMax=infinity
OOMScoreAdjust=-999
[Install]
WantedBy=multi-user.target
EOF
注意:如果缺少該檔案,啟動 docker 時會報如下錯誤:
systemctl restart docker
Failed to restart docker.service: Unit containerd.service not found.
##################################
過載 systemd
配置檔案
systemctl daemon-reload
建立 docker 組
groupadd docker
如不建立 docker 組在通過 systemctl
啟動時會報錯如下
Dependency failed for Docker Application Container Engine.
Job docker.service/start failed with result 'dependency'.
啟動 docker
服務
systemctl start docker
systemctl enable docker
修改 docker 配置檔案並檢視安裝好的 docker 基本資訊
mkdir -p /etc/docker/
cat > /etc/docker/daemon.json <<'EOF'
{
"registry-mirrors": ["https://xxxxxxxxxxxxxxxxxxxxxx.mirror.swr.myhuaweicloud.com"]
}
EOF
重啟 docker 服務
systemctl restart docker
檢視 docker info
docker info