ããã¯ãUbuntu OnlineãFedora OnlineãWindows ãªã³ã©ã€ã³ ãšãã¥ã¬ãŒã¿ãŒãMAC OS ãªã³ã©ã€ã³ ãšãã¥ã¬ãŒã¿ãŒãªã©ã®è€æ°ã®ç¡æãªã³ã©ã€ã³ ã¯ãŒã¯ã¹ããŒã·ã§ã³ã® XNUMX ã€ã䜿çšããŠãOnWorks ç¡æãã¹ãã£ã³ã° ãããã€ããŒã§å®è¡ã§ããã³ãã³ã docker-run ã§ãã
ããã°ã©ã ïŒ
NAME
docker-run - æ°ããã³ã³ããã§ã³ãã³ããå®è¡ããŸã
SYNOPSIS
ããã«ãŒ ã©ã³ [-a|-æ·»ä»[=[]]][-- ãã¹ãã®è¿œå [=[]]][--blkio-weight[=[BLKIO-éé]]]
[--blkio-weight-device[=[]]][--cpu-shares[=0]][--cap-add[=[]]][--ãã£ãããããã[=[]]]
[--cgroup-芪[=CGã°ã«ãŒããã¹]][--cidfile[=CIDFãã¡ã€ã«]][--cpu-æé[=0]][--cpu ã¯ã©ãŒã¿[=0]]
[--cpuset-cpus[=CPUSET-CPUS]][--cpuset-mems[=CPUSET-MEMS]][-d|-ãã¿ãã]
[--ãã¿ããããŒ[=[]]][- 端æ«[=[]]][--device-read-bps[=[]]][--device-read-iops[=[]]]
[--device-write-bps[=[]]][--device-write-iops[=[]]][--DNS[=[]]][--dns-opt[=[]]]
[--dns-æ€çŽ¢[=[]]][-e|--env[=[]]][- ãšã³ããªãŒãã€ã³ã[=ãšã³ããªãŒãã€ã³ã]][--env ãã¡ã€ã«[=[]]]
[- ããã[=[]]][--ã°ã«ãŒãè¿œå [=[]]][-h|-ãã¹ãå[=ãã¹ãå]][ - å©ããŠ] [-i|- çžäºã®äœçš]
[--ip[=IPv4ã¢ãã¬ã¹]][--ip6[=IPv6ã¢ãã¬ã¹]][--ipc[=IPC]][- åé¢[=ããã©ã«ã]]
[--ã«ãŒãã«ã¡ã¢ãª[=ã«ãŒãã«ã¡ã¢ãª]][-l|- ã©ãã«[=[]]][--ã©ãã«ãã¡ã€ã«[=[]]][- ãªã³ã¯[=[]]]
[--ãã°ãã©ã€ããŒ[=[]]][--log-opt[=[]]][-m|- ã¡ã¢ãªãŒ[=MEMORY]][- Macã¢ãã¬ã¹[=MACã¢ãã¬ã¹]]
[--ã¡ã¢ãªäºçŽ[=ã¡ã¢ãªäºçŽ]][--ã¡ã¢ãªãŒã¹ã¯ãã[=LIMIT]]
[--ã¡ã¢ãªã¹ã¯ãããã¹[=ã¡ã¢ãªã¹ã¯ãããã¹]][- åå[=NAME]][- ããã[="æ©"]]
[--net-alias[=[]]][--oom-kill-disable] [--oom-ã¹ã³ã¢-調æŽ[=0]][-P|--ãã¹ãŠå ¬é]
[-p|- å ¬é[=[]]][--pid[=[]]][-ç¹æš©] [-èªã¿åãå°çš] [- åèµ·å[=åèµ·å]][--rm]
[--ã»ãã¥ãªãã£ãªãã[=[]]][--åæ¢ä¿¡å·[=SIGNAL]][--shm ãµã€ãº[=[]]][--sig-proxy[=true]]
[-t|--tty] [--tmpfs[=[ã³ã³ãããã£ã¬ã¯ããª[: ã]][-u|- ãŠãŒã¶ãŒ[=USER]][--ulimit[=[]]]
[--uts[=[]]][-v|- é³é[=[[ãã¹ããã£ã¬ã¯ããª:]ã³ã³ãããã£ã¬ã¯ããª[:ãªãã·ã§ã³]]]]
[--ããªã¥ãŒã ãã©ã€ããŒ[=DRIVER]][--ããªã¥ãŒã -å [=[]]][-w|--workdir[=äœæ¥ãã£ã¬ã¯ããª]] ç»å [ã³ãã³ã]
[ARG...]
DESCRIPTION
æ°ããã³ã³ããã§ããã»ã¹ãå®è¡ããŸãã ããã«ãŒ ã©ã³ ç¬èªã®ãã¡ã€ã« ã·ã¹ãã ã䜿çšããŠããã»ã¹ãéå§ããŸãã
ç¬èªã®ãããã¯ãŒã¯ãšç¬èªã®åé¢ãããããã»ã¹ ããªãŒã ããã»ã¹ãéå§ããIMAGE
ã³ã³ããå ã§å®è¡ãããããã»ã¹ã«é¢é£ããããã©ã«ããå®çŸ©ã§ããŸãã
å ¬éãããããã¯ãŒã¯ãªã©ãããã ããã«ãŒ ã©ã³ æçµçãªå¶åŸ¡ããªãã¬ãŒã¿ãŒã«äžãããã
ã€ã¡ãŒãžããã³ã³ãããèµ·åãã管çè ã ãã®ãã ããã«ãŒ ã©ã³ ãã£ãšãããŸã
ä»ã® Docker ã³ãã³ãããããªãã·ã§ã³ãè±å¯ã§ãã
ç»åããŸã ããŒããããŠããªãå Žåã¯ã ããã«ãŒ ã©ã³ IMAGE ãšãã¹ãŠã®ã€ã¡ãŒãžããã«ããŸã
å®è¡äžã®åãæ¹æ³ã§ãªããžããªããäŸåé¢ä¿ãååŸããŸã ããã«ãŒ ãã« ç»åããã®åã«
ãã®ã€ã¡ãŒãžããã³ã³ãããéå§ããŸãã
OPTIONS
-a, -æ·»ä»= []
STDINãSTDOUTããŸã㯠STDERR ã«æ¥ç¶ããŸãã
ãã©ã¢ã°ã©ãŠã³ã ã¢ãŒã (ããã©ã«ãã®å Žå) -d ã¯æå®ãããŠããŸããïŒã ããã«ãŒ ã©ã³ éå§ã§ããŸã
ã³ã³ããå ã§ããã»ã¹ãå®è¡ããã³ã³ãœãŒã«ãããã»ã¹ã®æšæºå ¥åãåºåã
ãããŠæšæºèª€å·®ã TTY ã®ãµããããããšãã§ããŸã (ããã¯ã»ãšãã©ã®ã³ãã³ãã©ã€ã³ã§è¡ãããŸã)
å®è¡å¯èœãã¡ã€ã«ã¯æåŸ ãããŸã)ãã·ã°ãã«ãæž¡ããŸãã ã® -a ãªãã·ã§ã³ã¯æšæºå ¥åããšã«èšå®ã§ããŸãã
æšæºåºåãšæšæºãšã©ãŒåºåã
-- ãã¹ãã®è¿œå = []
ã«ã¹ã¿ã ã®ãã¹ããã IP ãžã®ãããã³ã° (host:ip) ãè¿œå ããŸãã
/etc/hosts ã«è¡ãè¿œå ããŸãã 圢åŒã¯ãã¹ãå:ip ã§ãã ã® -- ãã¹ãã®è¿œå ãªãã·ã§ã³èšå®å¯èœ
è€æ°åã
--blkio-weight=0
ããã㯠IO ã®éã¿ (çžå¯Ÿéã¿) ã¯ã10 ïœ 1000 ã®éã¿å€ãåãå ¥ããŸãã
--blkio-weight-device= []
ããã㯠IO ã®éã¿ (çžå¯Ÿçãªããã€ã¹ã®éã¿ã圢åŒ: DEVICE_NAME:äœé).
--cpu-shares=0
CPU ã·ã§ã¢ (çžå¯Ÿçãªéã¿)
ããã©ã«ãã§ã¯ããã¹ãŠã®ã³ã³ãããŒã¯åãå²åã® CPU ãµã€ã¯ã«ãååŸããŸãã ãã®å²åã¯æ¬¡ã®ããã«ãªããŸãã
ãã¹ãŠã®éã¿ä»ãã«å¯Ÿããã³ã³ãããŒã® CPU ã·ã§ã¢ã®éã¿ä»ããå€æŽããããšã§å€æŽãããŸãã
ä»ã®å®è¡äžã®ã³ã³ããã
æ¯çãããã©ã«ãã® 1024 ããå€æŽããã«ã¯ã --cpu-shares ãèšå®ãããã©ã°
éã¿ä»ãã 2 以äžã«ããŸãã
ãã®å²åã¯ãCPU éäžåã®ããã»ã¹ãå®è¡ãããŠããå Žåã«ã®ã¿é©çšãããŸãã ã¿ã¹ã¯ãå ¥ã£ãŠãããšã
XNUMX ã€ã®ã³ã³ãããŒãã¢ã€ãã«ç¶æ ã§ããã°ãä»ã®ã³ã³ãããŒã¯æ®ãã® CPU æéã䜿çšã§ããŸãã å®éã®éé¡
CPU æéã¯ãã·ã¹ãã äžã§å®è¡ãããŠããã³ã³ããã®æ°ã«ãã£ãŠç°ãªããŸãã
ããšãã°ã1024 ã€ã®ã³ã³ããããããXNUMX ã€ã¯ CPU ã·ã§ã¢ã XNUMX ã§ãä»ã® XNUMX ã€ã¯ CPU ã·ã§ã¢ã XNUMX ã§ãããšããŸãã
CPU å ±æèšå®ã¯ 512ã100 ã€ã®ã³ã³ãããŒãã¹ãŠã®ããã»ã¹ã XNUMX% ã® CPU å ±æã䜿çšããããšãããšã
CPU ã®å Žåãæåã®ã³ã³ãããŒã¯åèš CPU æéã® 50% ãåãåããŸãã XNUMXã€ç®ãè¿œå ãããš
CPU ã·ã§ã¢ã 1024 ã®ã³ã³ããã®å Žåãæåã®ã³ã³ãã㯠CPU ã® 33% ããååŸããŸããã ã®
æ®ãã®ã³ã³ãã㯠CPU ã® 16.5%ã16.5%ã33% ãåãåããŸãã
ãã«ãã³ã¢ ã·ã¹ãã ã§ã¯ãCPU æéã®ã·ã§ã¢ã¯ãã¹ãŠã® CPU ã³ã¢ã«åæ£ãããŸãã ããšã
ã³ã³ãããŒã¯ CPU æéã® 100% æªæºã«å¶éãããŠãããåã³ã³ãããŒã® CPU æé㯠100% 䜿çšã§ããŸãã
CPUã³ã¢ã
ããšãã°ãXNUMX ã€ä»¥äžã®ã³ã¢ãæã€ã·ã¹ãã ãèããŠã¿ãŸãããã XNUMXã€ã®ã³ã³ãããèµ·åãããš {C0}
ã -c=512 XNUMX ã€ã®ããã»ã¹ãšå¥ã®ã³ã³ãããå®è¡ãã {C1} ã -c=1024 XNUMX人ãå®è¡ããŠããŸã
ããã«ãããCPU ã·ã§ã¢ã次ã®ããã«åå²ãããå¯èœæ§ããããŸãã
PID ã³ã³ãã CPU CPU ã·ã§ã¢
100 {C0} 0 CPU100 ã® 0%
101 {C1} 1 CPU100 ã® 1%
102 {C1} 2 CPU100 ã® 2%
--cap-add= []
Linux æ©èœãè¿œå ãã
--ãã£ãããããã= []
Linux æ©èœãåé€ãã
--cgroup-芪=""
ã³ã³ãããŒã® cgroup ãäœæããã cgroup ãžã®ãã¹ã ãã¹ã®å Žå
ã¯çµ¶å¯Ÿã§ã¯ãããŸããããã¹ã¯ init ã® cgroups ãã¹ã«å¯Ÿããçžå¯Ÿãã¹ã§ãããšèŠãªãããŸãã
ããã»ã¹ã Cgroup ãååšããªãå Žåã¯äœæãããŸãã
--cidfile=""
ã³ã³ããIDããã¡ã€ã«ã«æžã蟌ã¿ãŸã
--cpu-æé=0
CPU CFS (Completely Fair Scheduler) æéãå¶éãã
ã³ã³ãããŒã® CPU 䜿çšçãå¶éããŸãã ãã®ãã©ã°ã¯ãã³ã³ããã® CPU ãå¶éããããã«ã«ãŒãã«ã«æ瀺ããŸãã
æå®ããæéãŸã§äœ¿çšã§ããŸãã
--cpuset-cpus=""
å®è¡ãèš±å¯ãã CPU (0 ïœ 3ã0,1ãXNUMX)
--cpuset-mems=""
å®è¡ãèš±å¯ããã¡ã¢ãª ããŒã (MEM) (0 ïœ 3ã0,1ãXNUMX)ã NUMA ã§ã®ã¿æå¹
ã·ã¹ãã ã
ã·ã¹ãã äžã« 0 ã€ã®ã¡ã¢ãª ããŒã (3 ïœ XNUMX) ãããå Žåã¯ã次ã䜿çšããŸãã --cpuset-mems=0,1 ãã®åŸãããã»ã¹ãå®è¡ããŸã
Docker ã³ã³ããå ã® ã¯ãæåã® XNUMX ã€ã®ã¡ã¢ãª ããŒãããã®ã¡ã¢ãªã®ã¿ã䜿çšããŸãã
--cpu ã¯ã©ãŒã¿=0
CPU CFS (Completely Fair Scheduler) ã¯ã©ãŒã¿ãå¶éãã
ã³ã³ãããŒã® CPU 䜿çšçãå¶éããŸãã ããã©ã«ãã§ã¯ãã³ã³ãããŒã¯ CPU ãªãœãŒã¹ããã¹ãŠäœ¿çšããŠå®è¡ãããŸãã
ãã®ãã©ã°ã¯ãã³ã³ããã® CPU 䜿çšçãæå®ããã¯ã©ãŒã¿ã«å¶éããããã«ã«ãŒãã«ã«æ瀺ããŸãã
-d, -ãã¿ãã=true|false
åé¢ã¢ãŒã: ã³ã³ãããŒãããã¯ã°ã©ãŠã³ãã§å®è¡ããæ°ããã³ã³ãã㌠ID ãåºåããŸãã ã®
ããã©ã«ã㯠false.
ãã€ã§ãå®è¡ã§ããŸã ããã«ãŒ ps ä»ã®ã·ã§ã«ã§ãå®è¡äžã®ã·ã§ã«ã®ãªã¹ãã衚瀺ããŸãã
ã³ã³ããã åãé¢ãããã³ã³ããã«åæ¥ç¶ããã«ã¯ã ããã«ãŒ ã¢ã¿ããã éžæããå Žå
ã³ã³ããããã¿ããã¢ãŒãã§å®è¡ãããšã -rm ãªãã·ã§ã³ãéžæããŸãã
tty ã¢ãŒãã§æ¥ç¶ãããŠããå Žåã¯ãã³ã³ãããŒããåãé¢ãããšãã§ããŸã (å®è¡ãããŸãŸã«ããããšãã§ããŸã)ã
æ§æå¯èœãªã㌠ã·ãŒã±ã³ã¹ã䜿çšããŸãã ããã©ã«ãã®ã·ãŒã±ã³ã¹ã¯æ¬¡ã®ãšããã§ã CTRL-p CTRL-qã ããªããèšå®ããŸã
ã䜿çšããã㌠ã·ãŒã±ã³ã¹ --ãã¿ããã㌠ãªãã·ã§ã³ãŸãã¯èšå®ãã¡ã€ã«ã èŠã
èšå®-json(5) æ§æãã¡ã€ã«ã®äœ¿çšã«é¢ããããã¥ã¡ã³ããåç §ããŠãã ããã
--ãã¿ããããŒ=""
ã³ã³ããããã¿ããããããã®ããŒã·ãŒã±ã³ã¹ãäžæžãããŸãã ãã©ãŒãããã¯XNUMXæåã§ã [aZ]
or NS- ã³ã©ãã¬ãŒ ã®äžã€ã§ãããŸãïŒ AZ, @, ^, [, , or _.
- 端æ«= []
ãã¹ãããã€ã¹ãã³ã³ããã«è¿œå ããŸã (äŸ: --device=/dev/sdc:/dev/xvdc:rwm)
--device-read-bps= []
ããã€ã¹ããã®èªã¿åãé床ãå¶éãã (äŸ: --device-read-bps=/dev/sda:1mb)
--device-read-iops= []
ããã€ã¹ããã®èªã¿åãé床ãå¶éãã (äŸ: --device-read-iops=/dev/sda:1000)
--device-write-bps= []
ããã€ã¹ãžã®æžã蟌ã¿é床ãå¶éããŸã (äŸ: --device-write-bps=/dev/sda:1mb)
--device-write-iops= []
ããã€ã¹ã®æžã蟌ã¿é床ãå¶éãã (äŸ: --device-write-iops=/dev/sda:1000)
--dns-æ€çŽ¢= []
ã«ã¹ã¿ã DNS æ€çŽ¢ãã¡ã€ã³ãèšå®ããŸã (æ€çŽ¢ãèšå®ããããªãå Žåã¯ã--dns-search= ã䜿çšããŸã)
ãã¡ã€ã³ïŒ
--dns-opt= []
ã«ã¹ã¿ã DNS ãªãã·ã§ã³ãèšå®ãã
--DNS= []
ã«ã¹ã¿ã DNSãµãŒããŒãèšå®ãã
ãã®ãªãã·ã§ã³ã䜿çšãããšãã³ã³ããã«æž¡ããã DNS æ§æããªãŒããŒã©ã€ãã§ããŸãã
éåžžãããã¯ãã¹ãã® DNS æ§æãã³ã³ããã«å¯ŸããŠç¡å¹ãªå Žåã«å¿ èŠã§ãã
(äŸ: 127.0.0.1)ã ãã®ãããªå Žåã --DNS flags ã¯å®è¡ããšã«å¿ èŠã§ãã
-e, --env= []
ç°å¢å€æ°ãèšå®ãã
ãã®ãªãã·ã§ã³ã䜿çšãããšã䜿çšå¯èœãªä»»æã®ç°å¢å€æ°ãæå®ã§ããŸãã
ã³ã³ããå ã§èµ·åãããããã»ã¹ã
- ãšã³ããªãŒãã€ã³ã=""
ç»åã®ããã©ã«ãã®ENTRYPOINTãäžæžãããŸã
ãã®ãªãã·ã§ã³ã䜿çšãããšã
ããã«ãŒãã¡ã€ã«ã ç»åã® ENTRYPOINT ã¯ãäœãæå®ããã®ããæå®ãããããCOMMAND ã«äŒŒãŠããŸãã
ã³ã³ããã®èµ·åæã«å®è¡ããããã®å®è¡å¯èœãã¡ã€ã«ã§ããã(æå³çã«) ããå°é£ã«ãªããŸãã
ãªãŒããŒã©ã€ãã ENTRYPOINT ã¯ã³ã³ããã«ããã©ã«ãã®æ§è³ªãŸãã¯åäœãäžããŸãã
ENTRYPOINT ãèšå®ãããšããã®ãã€ããªã§ãããã®ããã«ã³ã³ãããå®è¡ã§ããŸãã
ããã©ã«ãã®ãªãã·ã§ã³ã®ã»ããCOMMAND çµç±ã§ããã«ãªãã·ã§ã³ãæž¡ãããšãã§ããŸãã ããããæã ã
ãªãã¬ãŒã¿ã¯ã³ã³ããå ã§äœãä»ã®ãã®ãå®è¡ãããå Žåãããããã
ã䜿çšããŠå®è¡æã«ããã©ã«ãã® ENTRYPOINT - ãšã³ããªãŒãã€ã³ã æ°ãããã®ãæå®ããæåå
ãšã³ããªãŒãã€ã³ãã
--env ãã¡ã€ã«= []
ç°å¢å€æ°ã®è¡åºåããã¡ã€ã«ãèªã¿èŸŒã¿ãŸã
- ããã= []
ããŒããŸãã¯ããŒãç¯å² (äŸ: --expose=3300-3310) ãå ¬éãããšãDocker ã«æ¬¡ã®ããšãéç¥ãããŸãã
ã³ã³ãããŒã¯å®è¡æã«æå®ããããããã¯ãŒã¯ ããŒãããªãã¹ã³ããŸãã Docker ã¯ãã®æ å ±ã䜿çšããŸã
ãªã³ã¯ã䜿çšããŠã³ã³ãããçžäºæ¥ç¶ãããã¹ã ã·ã¹ãã äžã§ããŒã ãªãã€ã¬ã¯ããèšå®ããŸãã
--ã°ã«ãŒãè¿œå = []
å®è¡ããã°ââã«ãŒããè¿œå ãã
-h, -ãã¹ãå=""
ã³ã³ããã®ãã¹ãå
ã³ã³ããå ã§äœ¿çšã§ããã³ã³ããã®ãã¹ãåãèšå®ããŸãã
- å©ããŠ
䜿çšç¶æ³ã¹ããŒãã¡ã³ããå°å·ãã
-i, - çžäºã®äœçš=true|false
åãä»ããããŠããªãå Žåã§ããSTDINãéãããŸãŸã«ããŸãã ããã©ã«ã㯠false.
true ã«èšå®ãããšãæ¥ç¶ãããŠããªãå Žåã§ã stdin ãéãããŸãŸã«ããŸãã ããã©ã«ã㯠false ã§ãã
--ip=""
ã³ã³ããã®ã€ã³ã¿ãŒãã§ãŒã¹IPv4ã¢ãã¬ã¹ãèšå®ããŸã(äŸ: 172.23.0.9)
ãšçµã¿åãããŠã®ã¿äœ¿çšã§ããŸã - ããã ãŠãŒã¶ãŒå®çŸ©ãããã¯ãŒã¯çš
--ip6=""
ã³ã³ããã®ã€ã³ã¿ãŒãã§ãŒã¹IPv6ã¢ãã¬ã¹ãèšå®ããŸã(äŸ: 2001:db8::1b99)
ãšçµã¿åãããŠã®ã¿äœ¿çšã§ããŸã - ããã ãŠãŒã¶ãŒå®çŸ©ãããã¯ãŒã¯çš
--ipc=""
ããã©ã«ãã§ã¯ãã³ã³ãããŒã®ãã©ã€ããŒã IPC åå空é (POSIX SysV IPC) ãäœæãããŸãã
'容åšïŒ ': å ±æãããŠããå¥ã®ã³ã³ãããåå©çšããŸã
ã¡ã¢ãªãã»ããã©ãã¡ãã»ãŒãžãã¥ãŒ
'host': ãã¹ãã®å ±æã¡ã¢ãªãã»ããã©ãã¡ãã»ãŒãžã䜿çšããŸãã
ã³ã³ããå ã®ãã¥ãŒã 泚: ãã¹ã ã¢ãŒãã§ã¯ãã³ã³ããã«ããŒã«ã«ãžã®å®å šãªã¢ã¯ã»ã¹æš©ãäžããããŸãã
å ±æã¡ã¢ãªã§ãããããå®å šã§ã¯ãªããšèããããŸãã
- åé¢="ããã©ã«ã"
åé¢ã¯ãã³ã³ãããŒã§äœ¿çšãããåé¢ãã¯ãããžãŒã®ã¿ã€ããæå®ããŸãã
-l, - ã©ãã«= []
ã³ã³ããã«ã¡ã¿ããŒã¿ãèšå®ããŸã (äŸ: --label com.example.key=value)
--ã«ãŒãã«ã¡ã¢ãª=""
ã«ãŒãã« ã¡ã¢ãªå¶é (圢åŒ: [ ]ãåäœ = bãkãmããŸã㯠g)
ã³ã³ããã䜿çšã§ããã«ãŒãã« ã¡ã¢ãªãå¶éããŸãã å¶é 0 ãæå®ãããŠããå Žå (ããã§ãªãå Žå)
--ã«ãŒãã«ã¡ã¢ãª)ãã³ã³ãããŒã®ã«ãŒãã« ã¡ã¢ãªã¯å¶éãããŸããã ãæå®ãããšã
å¶éã«éããå Žåããªãã¬ãŒãã£ã³ã° ã·ã¹ãã ã®ããŒãž ãµã€ãºã®åæ°ã«åãäžããããå ŽåããããŸãã
䟡å€ã¯éåžžã«å€§ãããªããæ°çŸäžå ã«ãªãå¯èœæ§ããããŸãã
--ã©ãã«ãã¡ã€ã«= []
è¡åºåãã®ã©ãã«ãã¡ã€ã«ãèªã¿åã
- ãªã³ã¯= []
次ã®åœ¢åŒã§å¥ã®ã³ã³ãããžã®ãªã³ã¯ãè¿œå ããŸãã :ãšã€ãªã¢ã¹ãŸãã¯åã«ã§
ãã®å Žåããšã€ãªã¢ã¹ã¯ååãšäžèŽããŸã
ãªãã¬ãŒã¿ãŒã䜿çšããå Žå - ãªã³ã¯ æ°ããã¯ã©ã€ã¢ã³ãã³ã³ãããèµ·åãããšãã«ãã¯ã©ã€ã¢ã³ã
ã³ã³ããã¯ãã©ã€ããŒã ãããã¯ãŒã¯ ã€ã³ã¿ãŒãã§ã€ã¹çµç±ã§å ¬éããŒãã«ã¢ã¯ã»ã¹ã§ããŸãã Docker ãèšå®ããŸã
ã¯ã©ã€ã¢ã³ã ã³ã³ããå ã®ããã€ãã®ç°å¢å€æ°ã¯ãã©ã®ã€ã³ã¿ãŒãã§ã€ã¹ãš
䜿çšããããŒãã
--ãã°ãã©ã€ããŒ="json ãã¡ã€ã«|syslog|ãžã£ãŒãã«|ã²ã«ã|æµæ¢|awslog|é£ã³æ£ã|ãªã"
ã³ã³ãããŒçšã®ãã®ã³ã°ãã©ã€ããŒã ããã©ã«ãã¯ããŒã¢ã³ã«ãã£ãŠå®çŸ©ãããŸã --ãã°ãã©ã€ã㌠ãã©ã°ã
èŠåïŒ ããã«ãŒ ãã° ã³ãã³ãã¯ã json ãã¡ã€ã« &
ãžã£ãŒãã« ãã®ã³ã°ãã©ã€ããŒã
--log-opt= []
ãã®ã³ã°ãã©ã€ããŒåºæã®ãªãã·ã§ã³ã
-m, - ã¡ã¢ãªãŒ=""
ã¡ã¢ãªå¶é (圢åŒ: [ ]ãåäœ = bãkãmããŸã㯠g)
ã³ã³ãããŒã§äœ¿çšã§ããã¡ã¢ãªãå¶éã§ããŸãã ãã¹ããã¹ã¯ããããµããŒãããŠããå Žå
èšæ¶ããã㊠-m ã¡ã¢ãªèšå®ã¯ç©ç RAM ãã倧ãããªãå¯èœæ§ããããŸãã å¶éã 0 ã®å Žåã
æå®ïŒäœ¿çšããªãïŒ -m)ãã³ã³ãããŒã®ã¡ã¢ãªã«ã¯å¶éããããŸããã å®éã®å¶éã¯æ¬¡ã®ãšããã§ãã
ãªãã¬ãŒãã£ã³ã° ã·ã¹ãã ã®ããŒãž ãµã€ãºã®åæ°ã«åãäžããããŸã (å€ã¯éåžžã«å€§ãããªããŸã)
倧ãããããã¯äœçŸäžå ã«ããªããŸãïŒã
--ã¡ã¢ãªäºçŽ=""
ã¡ã¢ãªã®ãœãããªããã (圢åŒ: [ ]ãåäœ = bãkãmããŸã㯠g)
ã¡ã¢ãªäºçŽãèšå®ããåŸãã·ã¹ãã ãã¡ã¢ãªç«¶åãŸãã¯ã¡ã¢ãªäžè¶³ãæ€åºãããšã
ã³ã³ããã¯ããã®æ¶è²»ãäºçŽãããç¯å²å ã«å¶éããããšãäœåãªããããŸãã ããã§ãããªãã¯ãã¹ãã§ã
åžžã«ä»¥äžã®å€ãèšå®ããŠãã ãã - ã¡ã¢ãªãŒããã§ãªãå Žåã¯ãããŒãå¶éãåªå ãããŸãã ã«ãã
ããã©ã«ãã§ã¯ãã¡ã¢ãªäºçŽã¯ã¡ã¢ãªå¶éãšåãã«ãªããŸãã
--ã¡ã¢ãªãŒã¹ã¯ããïŒãéçã
ã¡ã¢ãªãšã¹ã¯ããã«çããå¶éå€ã ãšäžç·ã«äœ¿çšããå¿ èŠããããŸã -m (- ã¡ã¢ãªãŒïŒ ãã©ã°ã ã®
swap LIMIT åžžã«ãã倧ããå¿ èŠããããŸã -m (- ã¡ã¢ãªãŒïŒ 䟡å€ã
ã®åœ¢åŒ LIMIT is [ ]ã åäœã¯æ¬¡ã®ãšããã§ã b (ãã€ã)ã k (ãããã€ã)ã m
(ã¡ã¬ãã€ã)ããŸã㯠g (ã®ã¬ãã€ã)ã åäœãæå®ããªãå Žåã¯ã b 䜿çšãããŠããã ãªãããã次ã®ããã«èšå®ããŸã -1 ããž
ç¡å¶éã®ã¹ã¯ãããæå¹ã«ããŸãã
- Macã¢ãã¬ã¹=""
ã³ã³ããã® MAC ã¢ãã¬ã¹ (äŸ: 92:d0:c6:0a:29:33)
ã€ãŒãµããã ãããã¯ãŒã¯å ã® MAC ã¢ãã¬ã¹ã¯äžæã§ããå¿ èŠãããããšã«æ³šæããŠãã ããã IPv6 ãªã³ã¯ããŒã«ã«
ã¢ãã¬ã¹ã¯ãRFC4862 ã«åŸã£ãŠããã€ã¹ã® MAC ã¢ãã¬ã¹ã«åºã¥ããŸãã
- åå=""
ã³ã³ããã«ååãä»ãã
ãªãã¬ãŒã¿ãŒã¯æ¬¡ã® XNUMX ã€ã®æ¹æ³ã§ã³ã³ãããèå¥ã§ããŸãã
UUID ã®é·ãèå¥å
(âf78375b1c487e03c9438c729345e54db9d20cfa2ac1fc3494b6eb60872e74778â)
UUID çãèå¥å (ãf78375b1c487ã)
ååïŒããšããïŒ
UUID èå¥å㯠Docker ããŒã¢ã³ããååŸãããååãå²ãåœãŠãããŠããªãå Žåã¯ã
å ¥ã£ãå®¹åš - åå ãã®åŸãããŒã¢ã³ã¯ã©ã³ãã ãªæåååãçæããŸãã ååã¯
ãªã³ã¯ãå®çŸ©ãããšãã«äŸ¿å©ã§ã (ã - ãªã³ã¯) (ãŸãã¯ãç¹å®ããå¿ èŠããããã®ä»ã®å Žæ
容åšïŒã ããã¯ãããã¯ã°ã©ãŠã³ããšãã©ã¢ã°ã©ãŠã³ãã®äž¡æ¹ã® Docker ã³ã³ãããŒã§æ©èœããŸãã
- ããã="ããªããž"
ã³ã³ããã®ãããã¯ãŒã¯ã¢ãŒããèšå®ããŸãã
'bridge': ããã©ã«ãã® Docker äžã«ãããã¯ãŒã¯ ã¹ã¿ãã¯ãäœæããŸãã
ããªããž
'none': ãããã¯ãŒã¯ãªã
'容åšïŒ ': å¥ã®ã³ã³ããã®ãããã¯ãŒã¯ãåå©çšããŸã
ã¹ã¿ãã¯
'host': Docker ãã¹ã ãããã¯ãŒã¯ ã¹ã¿ãã¯ã䜿çšããŸãã 泚: ãã¹ã
ãã®ã¢ãŒãã§ã¯ãã³ã³ããã« D-bus ãªã©ã®ããŒã«ã« ã·ã¹ãã ãµãŒãã¹ãžã®ãã« ã¢ã¯ã»ã¹ãäžããããŸãã
ãããã£ãŠãå®å šã§ã¯ãªããšèããããŸãã
' | ': ãŠãŒã¶ãŒå®çŸ©ã«æ¥ç¶ããŸã
ãããã¯ãŒã¯
--net-alias= []
ã³ã³ããã«ãããã¯ãŒã¯ã¹ã³ãŒãã®ãšã€ãªã¢ã¹ãè¿œå ãã
--oom-kill-disable=true|false
ã³ã³ãããŒã® OOM Killer ãç¡å¹ã«ãããã©ããã
--oom-ã¹ã³ã¢-調æŽ=""
ã³ã³ããã«å¯Ÿãããã¹ãã® OOM èšå®ã調æŽããŸã (-1000 ïœ 1000 ãåãå ¥ããŸã)
-P, --ãã¹ãŠå ¬é=true|false
å ¬éãããŠãããã¹ãŠã®ããŒãããã¹ã ã€ã³ã¿ãŒãã§ã€ã¹äžã®ã©ã³ãã ãªããŒãã«å ¬éããŸãã ããã©ã«ã㯠false.
true ã«èšå®ãããšãå ¬éããããã¹ãŠã®ããŒãããã¹ã ã€ã³ã¿ãŒãã§ã€ã¹ã«å ¬éãããŸãã ããã©ã«ã㯠false ã§ãã
ãªãã¬ãŒã¿ãŒã -P (ãŸã㯠-p) ã䜿çšãããšãDocker ã¯å ¬éããŒãã«ã¢ã¯ã»ã¹ã§ããããã«ããŸãã
ãã¹ããšããŒãã¯ããã¹ãã«å°éã§ãããã¹ãŠã®ã¯ã©ã€ã¢ã³ãã䜿çšã§ããããã«ãªããŸãã -P ã䜿çšããå Žåã
Docker ã¯ãå ¬éãããããŒãããã¹ãäžã®ã©ã³ãã ãªããŒãã«ãã€ã³ãããŸãã ã¯ããªã ããŒã
ç¯å² ã«ãã£ãŠå®çŸ©ãããŸã /proc/sys/net/ipv4/ip_local_port_rangeã éã®ãããã³ã°ãèŠã€ããã«ã¯ã
ãã¹ãããŒããšå ¬éããŒãã䜿çšããã«ã¯ã ããã«ãŒ ããŒã.
-p, - å ¬é= []
ã³ã³ããã®ããŒããŸãã¯ããŒãã®ç¯å²ããã¹ãã«å ¬éããŸãã
ãã©ãŒãããïŒ ip:ãã¹ãããŒã:ã³ã³ããããŒã | ip::ã³ã³ããããŒã | ãã¹ãããŒã:ã³ã³ããããŒã |
ã³ã³ããããŒã hostPort ãšcontainerPort ã¯ã©ã¡ããããŒãã®ç¯å²ãšããŠæå®ã§ããŸãã ãã€
äž¡æ¹ã®ç¯å²ãæå®ããå Žåãç¯å²å ã®ã³ã³ãã ããŒãã®æ°ã¯ã
ç¯å²å ã®ãã¹ã ããŒãã®æ°ã ïŒäŸãã°ã ããã«ãŒ ã©ã³ -p 1234-1236ïŒ1222-1224 - åå
ãã®äœå -t ããžãŒããã¯ã¹ ã¯ãªãã ããã«ãŒ ã©ã³ -p 1230-1236ïŒ1230-1240 - åå
ç¯å²ã³ã³ããããŒãç¯å²ãã倧ãããã¹ãããŒã -t ããžãŒããã¯ã¹) IP ã®å Žå: ããã«ãŒ ã©ã³ -p
127.0.0.1:$HOSTPORT:$CONTAINERPORT - åå ã³ã³ãã -t ããã€ãã®ç»å ã ããã«ãŒ ããŒã 確èªããŠãã ãã
å®éã®ãããã³ã°: ããã«ãŒ ããŒã ã³ã³ãã $ã³ã³ããããŒã
--pid=host
ã³ã³ããã® PID ã¢ãŒããèšå®ãã
host: ã³ã³ããå ã®ãã¹ãã® PID åå空éã䜿çšããŸãã
泚: ãã¹ã ã¢ãŒãã§ã¯ãã³ã³ããã«ããŒã«ã« PID ãžã®ãã« ã¢ã¯ã»ã¹ãäžããããããã
å®å šã§ã¯ãªããšèããããŠããŸãã
--uts=host
ã³ã³ããã® UTS ã¢ãŒããèšå®ãã
host: ã³ã³ããå ã®ãã¹ãã® UTS åå空éã䜿çšããŸãã
泚: ãã¹ã ã¢ãŒãã§ã¯ãã³ã³ããã«ãã¹ãã®ãã¹ãåãå€æŽããã¢ã¯ã»ã¹æš©ãäžããããŸãã
ãããã£ãŠãå®å šã§ã¯ãªããšèããããŸãã
-ç¹æš©=true|false
ãã®ã³ã³ããã«æ¡åŒµæš©éãäžããŸãã ããã©ã«ã㯠false.
ããã©ã«ãã§ã¯ãDocker ã³ã³ããã¯ãéç¹æš©ã (=false) ã§ãããããšãã°ã
Dockerã³ã³ããå ã®DockerããŒã¢ã³ã ããã¯ãããã©ã«ãã§ã¯ã³ã³ãããŒã¯
ããããããã€ã¹ãžã®ã¢ã¯ã»ã¹ãèš±å¯ãããŸãã ãç¹æš©ãã³ã³ããã«ã¯ããã¹ãŠã®ããã€ã¹ãžã®ã¢ã¯ã»ã¹ãäžããããŸãã
ãªãã¬ãŒã¿ãŒãå®è¡ãããšã ããã«ãŒ ã©ã³ -ç¹æš©, Docker ã«ããããã¹ãŠã®ã¢ã¯ã»ã¹ãå¯èœã«ãªããŸãã
ãã¹ãäžã®ããã€ã¹ã«å ããŠãã³ã³ãããŒãèš±å¯ããããã« AppArmor ã§ããã€ãã®æ§æãèšå®ããŸãã
ãã¹ããžã®ã¢ã¯ã»ã¹ã¯ãã³ã³ããã®å€éšã§å®è¡ãããŠããããã»ã¹ãšã»ãŒåãã§ãã
ãã¹ãã
-èªã¿åãå°çš=true|false
ã³ã³ããã®ã«ãŒã ãã¡ã€ã«ã·ã¹ãã ãèªã¿åãå°çšãšããŠããŠã³ãããŸãã
ããã©ã«ãã§ã¯ãã³ã³ããã®ã«ãŒã ãã¡ã€ã«ã·ã¹ãã ã¯æžã蟌ã¿å¯èœã«ãªããããã»ã¹ãæžã蟌ã¿ã§ããããã«ãªããŸãã
ã©ãã«ã§ããã¡ã€ã«ãä¿åã§ããŸãã ãæå®ããããšã§ã -èªã¿åãå°çš ã³ã³ããã«ã«ãŒããååšããããšã瀺ããã©ã°ãç«ãŠã
ãã¡ã€ã«ã·ã¹ãã ã¯èªã¿åãå°çšãšããŠããŠã³ããããŠãããæžã蟌ã¿ã¯çŠæ¢ãããŠããŸãã
- åèµ·å="ããã"
ã³ã³ãããŒã®çµäºæã«é©çšããåèµ·åããªã·ãŒ (ããããon-failure[:max-retry]ãåžžã«ã
åæ¢ããªãéã)ã
--rm=true|false
ã³ã³ãããŒã®çµäºæã«èªåçã«åé€ããŸã (-d ãšã¯äºææ§ããããŸãã)ã ããã©ã«ãã¯
false.
--ã»ãã¥ãªãã£ãªãã= []
ã»ãã¥ãªãã£ãªãã·ã§ã³
"label:user:USER" : ã³ã³ããã®ã©ãã«ãŠãŒã¶ãŒãèšå®ããŸã
"label:role:ROLE" : ã³ã³ããã®ã©ãã«ããŒã«ãèšå®ããŸã
"label:type:TYPE" : ã³ã³ããã®ã©ãã«ã¿ã€ããèšå®ããŸã
"label:level:LEVEL" : ã³ã³ããã®ã©ãã« ã¬ãã«ãèšå®ããŸã
"label:disable" : ã³ã³ãããŒã®ã©ãã«å¶éããªãã«ããŸã
--åæ¢ä¿¡å·=ã·ã°ã¿ãŒã
ã³ã³ãããåæ¢ããä¿¡å·ãéããŸãã ããã©ã«ã㯠SIGTERM ã§ãã
--shm ãµã€ãº=""
ã®ãµã€ãº / dev / shmã ãã©ãŒããã㯠.
æ° ããã倧ãããªããã°ãªããŸãã 0ã ãŠãããã¯ãªãã·ã§ã³ã§ããã b (ãã€ã)ã k (ãããã€ã)ã
m(ã¡ã¬ãã€ã)ããŸã㯠g (ã®ã¬ãã€ã)ã
åäœãçç¥ããå Žåãã·ã¹ãã ã¯ãã€ãã䜿çšããŸãã ãµã€ãºãå®å šã«çç¥ãããšãã·ã¹ãã ã¯
䜿çšãããŸã 64m.
--sig-proxy=true|false
åä¿¡ä¿¡å·ãããã»ã¹ã«ãããã·ããŸã (é TTY ã¢ãŒãã®ã¿)ã SIGCHLDãSIGSTOPãããã³
SIGKILL ã¯ãããã·ãããŸããã ããã©ã«ã㯠true.
--ã¡ã¢ãªã¹ã¯ãããã¹=""
ã³ã³ãããŒã®ã¡ã¢ãª ã¹ã¯ããåäœã調æŽããŸãã 0 ãã 100 ãŸã§ã®æŽæ°ãåãå ¥ããŸãã
-t, --tty=true|false
ç䌌TTYãå²ãåœãŠãŸãã ããã©ã«ã㯠false.
true ã«èšå®ãããšãDocker ã¯ç䌌 tty ãå²ãåœãŠãä»»æã®æšæºå ¥åã«æ¥ç¶ã§ããŸãã
容åšã ããã¯ãããšãã°ã䜿ãæšãŠã®å¯Ÿè©±åã·ã§ã«ãå®è¡ããããã«äœ¿çšã§ããŸãã ã®
ããã©ã«ãã¯falseã§ãã
ã -t ãªãã·ã§ã³ã¯ãDockerã¯ã©ã€ã¢ã³ãã®æšæºå ¥åã®ãªãã€ã¬ã¯ããšäºææ§ããããŸããã
--tmpfs=[] tmpfs ããŠã³ããäœæãã
äžæãã¡ã€ã«ã·ã¹ãã ãããŠã³ãããŸã (tmpfs) ã³ã³ããã«ããŠã³ãããŸããäŸ:
$ docker run -d --tmpfs / tmpã«:rw,size=787448k,mode=1777 my_image
ãã®ã³ãã³ãã¯ã tmpfs at / tmpã« ã³ã³ããã®äžã ãµããŒããããŠããããŠã³ã ãªãã·ã§ã³ã¯æ¬¡ã®ãšããã§ãã
Linuxã®ããã©ã«ããšåã mount ãã©ã°ã ãªãã·ã§ã³ãæå®ããªãå Žåãã·ã¹ãã ã¯
次ã®ãªãã·ã§ã³ã䜿çšããŸãã rwãnoexecãnosuidãnodevãsize=65536k.
-u, - ãŠãŒã¶ãŒ=""
䜿çšãããŠãŒã¶ãŒåãŸãã¯UIDãèšå®ãããªãã·ã§ã³ã§ãæå®ããã°ã«ãŒãåãŸãã¯GIDãèšå®ããŸã
次ã®äŸã¯ãã¹ãŠæå¹ã§ãã
--user [user | userïŒgroup | uid | uidïŒgid | userïŒgid | uidïŒgroup]
ãã®åŒæ°ããªããšãã³ãã³ãã¯ã³ã³ããå ã®rootãšããŠå®è¡ãããŸãã
--ulimit= []
Ulimitãªãã·ã§ã³
-v|- é³é[=[[ãã¹ããã£ã¬ã¯ããª:]ã³ã³ãããã£ã¬ã¯ããª[:ãªãã·ã§ã³]]]
ãã€ã³ãããŠã³ããäœæããŸãã ãæå®ããã ãå Žåã¯ã -v /ãã¹ããã£ã¬ã¯ããª:/ã³ã³ãããã£ã¬ã¯ããªãããã«ãŒ
ãã€ã³ãããŠã³ã /ãã¹ããã£ã¬ã¯ã㪠ãã¹ãå 㧠/ã³ã³ãããã£ã¬ã¯ã㪠ããã«ãŒå ã§
容åšã ãHOST-DIRããçç¥ããå ŽåãDocker ã¯èªåçã«æ°ãããã£ã¬ã¯ããªãäœæããŸãã
ãã¹ãäžã®ããªã¥ãŒã ã ã® OPTIONS ã¯ã«ã³ãåºåãã®ãªã¹ãã§ããã次ã®ãšããã§ãã
· [rw|ro]
· [z|Z]
ã»[[r]å ±æ|[r]ã¹ã¬ãŒã|[r]ãã©ã€ããŒã]
ã ã³ã³ãã-DIR 次ã®ãããªçµ¶å¯Ÿãã¹ã§ããå¿ èŠããããŸã /src/docsãéžæããŸãã ãã¹ããã£ã¬ã¯ã㪠ããããšãã§ããŸã
絶察ãã¹ãŸã㯠å 䟡å€ã ã å å€ã¯è±æ°åã§å§ãŸãå¿ èŠããããŸãã
ç¶ã a-z0-9, _ ïŒã¢ã³ããŒã¹ã³ã¢ïŒã . ïŒæéïŒãŸã㯠- ïŒãã€ãã³ïŒã 絶察ãã¹ã¯æ¬¡ã§å§ãŸããŸã
a / ïŒã¹ã©ãã·ã¥ïŒã
ãäŸçµŠããå Žåã ãã¹ããã£ã¬ã¯ã㪠ããã¯çµ¶å¯Ÿãã¹ã§ããDocker ã¯æå®ãããã¹ã«ãã€ã³ãããŠã³ãããŸãã
ç¹å®ã ãäŸçµŠããå Žåã å, Dockerã¯ããã«ãã£ãŠååä»ãããªã¥ãŒã ãäœæããŸã åã äŸãã°ã
ã©ã¡ãããæå®ã§ããŸã / foo or foo ã®ããã« ãã¹ããã£ã¬ã¯ã㪠䟡å€ã ãäŸçµŠããå Žåã / foo å€ã
Docker ã¯ãã€ã³ãããŠã³ããäœæããŸãã ãäŸçµŠããå Žåã foo ä»æ§ã«å¿ããŠãDocker ãååä»ãã®
ããªã¥ãŒã ã
è€æ°æå®ã§ããŸã -v ã³ã³ããã« XNUMX ã€ä»¥äžã®ããŠã³ããããŠã³ããããªãã·ã§ã³ã 䜿çšããã«ã¯
ãããã®åãããŠã³ããä»ã®ã³ã³ãããŒã«ããŠã³ãããã«ã¯ã --ããªã¥ãŒã -å ãªãã·ã§ã³ãã
ããªããè¿œå ããããšãã§ããŸã :ã or :rw ããªã¥ãŒã ã«ãµãã£ãã¯ã¹ãä»ããŠèªã¿åãå°çšãŸãã¯èªã¿åã/æžã蟌ã¿ã¢ãŒãã§ããŠã³ãããŸãã
ããããã ããã©ã«ãã§ã¯ãããªã¥ãŒã ã¯èªã¿åã/æžã蟌ã¿å¯èœã«ããŠã³ããããŸãã äŸãåç §ããŠãã ããã
SELinux ãªã©ã®ã©ãã«ä»ãã·ã¹ãã ã§ã¯ãããªã¥ãŒã ã³ã³ãã³ãã«é©åãªã©ãã«ãé 眮ããå¿ èŠããããŸã
ã³ã³ããã«åãä»ããããŸããã ã©ãã«ããªããšãã»ãã¥ãªã㣠ã·ã¹ãã ã«ãã£ãŠããã»ã¹ã劚ããããå¯èœæ§ããããŸãã
ã³ã³ãã³ãã䜿çšããããšã§ã³ã³ããå ã§å®è¡ãããŸãã ããã©ã«ãã§ã¯ãDocker ã¯å€æŽãããŸãã
OSã«ãã£ãŠèšå®ãããã©ãã«ã
ã³ã³ããã³ã³ããã¹ãã§ã©ãã«ãå€æŽããã«ã¯ãXNUMX ã€ã®ãµãã£ãã¯ã¹ã®ãããããè¿œå ã§ããŸãã :z or :Z ããž
ããªã¥ãŒã ããŠã³ãã ãããã®ãµãã£ãã¯ã¹ã¯ãå ±æãã¡ã€ã«äžã®ãã¡ã€ã« ãªããžã§ã¯ãã®ã©ãã«ãåèšå®ããããã« Docker ã«æ瀺ããŸãã
ããªã¥ãŒã ã ã® z ãªãã·ã§ã³ã¯ãXNUMX ã€ã®ã³ã³ãããŒãããªã¥ãŒã ã®ã³ã³ãã³ããå ±æããããšã Docker ã«äŒããŸãã ãšããŠ
ãã®çµæãDocker ã¯ã³ã³ãã³ãã«å ±æã³ã³ãã³ã ã©ãã«ãä»ããŸãã å ±æããªã¥ãŒã ã©ãã«ã䜿çšãããšã
ãã¹ãŠã®ã³ã³ãããã³ã³ãã³ããèªã¿åã/æžã蟌ã¿ããŸãã ã® Z ãªãã·ã§ã³ã¯ãDocker ã«ã³ã³ãã³ãã«ã©ãã«ãä»ããããã«æ瀺ããŸãã
ãã©ã€ããŒãéå ±æã©ãã«ã çŸåšã®ã³ã³ããã®ã¿ããã©ã€ããŒã ããªã¥ãŒã ã䜿çšã§ããŸãã
ããã©ã«ãã§ã¯ããã€ã³ãããŠã³ããããããªã¥ãŒã 㯠ãã©ã€ããŒãã ã€ãŸããã³ã³ããå ã§è¡ãããããŠã³ãã¯ãã¹ãŠ
ãã¹ãã§ã¯è¡šç€ºãããªããªãããã®éãåæ§ã§ãã ãæå®ããããšã§ãã®åäœãå€æŽã§ããŸãã
ããªã¥ãŒã ããŠã³ãã®äŒæããããã£ã ããªã¥ãŒã ãäœã shared ãã®ããªã¥ãŒã ã®äžã§è¡ãããããŠã³ã
ã³ã³ããå ã¯ãã¹ãäžã§è¡šç€ºããããã®éãåæ§ã§ãã ããªã¥ãŒã ãäœã ã¹ã¬ãŒã å¯èœ
äžæ¹åã®ããŠã³ãäŒæã®ã¿ã§ããããã®ããªã¥ãŒã ã®äžã®ãã¹ãäžã§ããŠã³ããè¡ãããŸãã
ã³ã³ããå ã§ã¯è¡šç€ºãããŸããããã®éã¯è¡šç€ºãããŸããã
ããªã¥ãŒã ã®ããŠã³ãäŒæããããã£ãå¶åŸ¡ããã«ã¯ã次ã䜿çšã§ããŸãã :[r]å ±æ, :[r]ã¹ã¬ãŒã or
:[r]ãã©ã€ããŒã äŒæãã©ã°ã äŒæããããã£ã¯ãã€ã³ãããŠã³ãã«å¯ŸããŠã®ã¿æå®ã§ããŸã
å éšããªã¥ãŒã ãååä»ãããªã¥ãŒã ã§ã¯ãªãããªã¥ãŒã ã§ãã ããŠã³ãã®äŒæãæ©èœããããã«ã¯
ãœãŒã¹ ããŠã³ã ãã€ã³ã (ãœãŒã¹ ãã£ã¬ã¯ããªãããŠã³ããããŠããããŠã³ã ãã€ã³ã) ã«ã¯é©åãªæš©éãå¿ èŠã§ã
äŒæç¹æ§ã å ±æããªã¥ãŒã ã®å ŽåããœãŒã¹ ããŠã³ã ãã€ã³ããå ±æããå¿ èŠããããŸãã ãããŠãã®ããã«
ã¹ã¬ãŒã ããªã¥ãŒã ã®å ŽåããœãŒã¹ ããŠã³ãã¯å ±æãŸãã¯ã¹ã¬ãŒãã®ããããã§ããå¿ èŠããããŸãã
ã df ãœãŒã¹ããŠã³ããç¹å®ããŠãã䜿çšããŸã èŠã€ãããŸãã -o
ã¿ãŒã²ãããäŒæ ãœãŒã¹ã®äŒæç¹æ§ãææ¡ãã
ããŠã³ãã ãã èŠã€ãããŸãã ãŠãŒãã£ãªãã£ãå©çšã§ããªãå Žåã¯ããœãŒã¹ã®ããŠã³ã ãšã³ããªã確èªã§ããŸãã
ã®ããŠã³ããã€ã³ã / proc / self / mountinfoã èŠã ä»»æ ãã£ãŒã«ã äŒæããããã©ããã確èªããŠãã ãã
ããããã£ãæå®ãããŠããŸãã å ±æ:X ããŠã³ãã shared, ãã¹ã¿ãŒ:X ããŠã³ãã ã¹ã¬ãŒã
ããã«äœããªãå Žåã¯ãããŠã³ããååšããããšãæå³ããŸã ãã©ã€ããŒã.
ããŠã³ã ãã€ã³ãã®äŒæããããã£ãå€æŽããã«ã¯ã次ã䜿çšããŸãã mount æ瀺ã ããšãã°ã
ããŠã³ããœãŒã¹ãã£ã¬ã¯ããªããã€ã³ãããã / foo ã§ãã mount - ç·Žã / foo / foo & mount
--ãã©ã€ããŒãã«ãã --ã¡ã€ã¯å ±æ / fooã ããã«ããã/foo ã shared ããŠã³ããã€ã³ãã
ãããã¯ããœãŒã¹ ããŠã³ãã®äŒæããããã£ãçŽæ¥å€æŽããããšãã§ããŸãã èšã / is
ãœãŒã¹ããŠã³ã / fooã次ã«äœ¿çš mount --ã¡ã€ã¯å ±æ / å€æãã / shared ããŠã³ãã
Note: systemd ã䜿çšã㊠Docker ããŒã¢ã³ã®éå§ãšåæ¢ã管çããå Žåã
systemd ãŠããã ãã¡ã€ã«ã«ã¯ãDocker ã®ããŠã³ãäŒæãå¶åŸ¡ãããªãã·ã§ã³ããããŸã
ããŒã¢ã³èªäœããšåŒã°ãã ããŠã³ããã©ã°ã ãã®èšå®ã®å€ã«ãããDocker ãæ©èœããªããªãå¯èœæ§ããããŸãã
ããŠã³ã ãã€ã³ãã§è¡ãããããŠã³ãäŒæã®å€æŽãåç §ããŠãã ããã ããšãã°ããã®å€ã®å Žåã
is ã¹ã¬ãŒãã䜿çšã§ããªãå ŽåããããŸãã shared or å ±æ ããªã¥ãŒã äžã®äŒæã
--ããªã¥ãŒã ãã©ã€ããŒ=""
ã³ã³ããã®ããªã¥ãŒã ãã©ã€ããŒã ãã®ãã©ã€ããŒã¯ã次ã®ããããã§æå®ãããããªã¥ãŒã ãäœæããŸãã
Dockerfile ã® VOLUME æ瀺ãŸã㯠ããã«ãŒ ã©ã³ -v ãã©ã°ã
èŠã docker-ããªã¥ãŒã -äœæ(1) å®å šãªè©³çŽ°ã«ã€ããŠã¯ã
--ããªã¥ãŒã -å = []
æå®ããã³ã³ããããããªã¥ãŒã ãããŠã³ãããŸã
ãã§ã«ããŠã³ããããŠããããªã¥ãŒã ããœãŒã¹ ã³ã³ããããå¥ã®ã³ã³ããã«ããŠã³ãããŸã
容åšã ãœãŒã¹ã®ã³ã³ãã㌠ID ãæå®ããå¿ èŠããããŸãã å ±æããã«ã¯
ããªã¥ãŒã ã®å Žåã¯ã --ããªã¥ãŒã -å å®è¡æã®ãªãã·ã§ã³
ã¿ãŒã²ããã®ã³ã³ããã ãœãŒã¹ã³ã³ãããç°ãªãå Žåã§ãããªã¥ãŒã ãå ±æã§ããŸãã
å®è¡ãããŠããŸããã
ããã©ã«ãã§ã¯ãDocker ã¯ããªã¥ãŒã ãåãã¢ãŒã (èªã¿åã/æžã蟌ã¿ã¢ãŒããŸãã¯
èªã¿åãå°çš) ã¯ããœãŒã¹ ã³ã³ãããŒã«ããŠã³ããããŠããããã§ãã ãªãã·ã§ã³ã§ãããªãã¯ã
ãããå€æŽããã«ã¯ãcontainer-id ã®æ«å°Ÿã«æ¬¡ã®ãããããè¿œå ããŸãã :ã or
:rw ããŒã¯ãŒãã
ãœãŒã¹ã³ã³ããããã®ããªã¥ãŒã ã®äœçœ®ãéè€ããŠããå Žå
ããŒã¿ãã¿ãŒã²ãã ã³ã³ããäžã«ååšããå Žåãããªã¥ãŒã ã¯é衚瀺ã«ãªããŸã
ã¿ãŒã²ããäžã®ãã®ããŒã¿ã
-w, --workdir=""
ã³ã³ããå ã®äœæ¥ãã£ã¬ã¯ããª
ã³ã³ããå ã§ãã€ããªãå®è¡ããããã®ããã©ã«ãã®äœæ¥ãã£ã¬ã¯ããªã¯ã«ãŒãã§ãã
ãã£ã¬ã¯ã㪠(/)ã éçºè ã¯ãDockerfile WORKDIR ã䜿çšããŠå¥ã®ããã©ã«ããèšå®ã§ããŸãã
åœä»€ã ãªãã¬ãŒã¿ã¯ã次ã®ã³ãã³ãã䜿çšããŠäœæ¥ãã£ã¬ã¯ããªããªãŒããŒã©ã€ãã§ããŸãã -w ãªãã·ã§ã³ãéžæããŸãã
åºå£ Status:
ããã®çµäºã³ãŒã ããã«ãŒ ã©ã³ ã³ã³ãããå®è¡ã«å€±æããçç±ã«é¢ããæ å ±ãæäŸãããã
ãªãæããã®ãã ã〠ããã«ãŒ ã©ã³ ãŒã以å€ã®ã³ãŒãã§çµäºããå Žåãçµäºã³ãŒãã¯æ¬¡ã®ãšããã§ãã
chroot æšæºã以äžãåç §ããŠãã ããã
125 if ã ãšã©ãŒ is ã ããã«ãŒ ããŒã¢ã³ èªäœ
$ docker run --foo ããžãŒããã¯ã¹; ãšã³ãŒ$?
# ãã©ã°ãæå®ãããŠããŸãããå®çŸ©ãããŠããŸãã: --foo
ãdocker run --helpããåç §ããŠãã ããã
125
126 if ã å«ãŸããŠãã command be åŒã³åºããã
$ docker run ããžãŒããã¯ã¹ ã®/ etc; ãšã³ãŒ$?
# å®è¡: "ã®/ etc"ïŒ èš±å¯ãæåŠãããŸãã
docker: ããŒã¢ã³ããã®ãšã©ãŒå¿ç: å«ãŸããŠããã³ãã³ããåŒã³åºãããšãã§ããŸããã§ãã
126
127 if ã å«ãŸããŠãã command be çºèŠ
$ docker runbusybox foo; ãšã³ãŒ$?
# exec: "foo": $PATH ã«å®è¡å¯èœãã¡ã€ã«ãèŠã€ãããŸãã
docker: ããŒã¢ã³ããã®ãšã©ãŒå¿ç: å«ãŸããŠããã³ãã³ããèŠã€ãããªãããååšããŸãã
127
åºå£ ã³ãŒã of å«ãŸããŠãã command ãããªããš
$ docker run ããžãŒããã¯ã¹ /bin/sh -c 'åºå£ 3'
ïŒ3
äŸ
Running: ã³ã³ãã in èªã¿åãå°çšã® ã¢ãŒã
ã³ã³ãã㌠ã€ã¡ãŒãžã®éçºäžãã³ã³ãããŒã¯å€ãã®å Žåãã€ã¡ãŒãž ã³ã³ãã³ãã«æžã蟌ãå¿ èŠããããŸãã
ããã±ãŒãžãã€ã³ã¹ããŒã«ãã / usrã äŸãã°ã éçšç°å¢ã§ã¯ãã¢ããªã±ãŒã·ã§ã³ã次ã®ããšãè¡ãå¿ èŠã¯ã»ãšãã©ãããŸããã
ç»åã«æžã蟌ã¿ãŸãã ã³ã³ãã ã¢ããªã±ãŒã·ã§ã³ã¯ããã¡ã€ã«ã«æžã蟌ãå¿ èŠãããå Žåãããªã¥ãŒã ã«æžã蟌ã¿ãŸãã
ã·ã¹ãã ã¯ãŸã£ããã ã¢ããªã±ãŒã·ã§ã³ãèªã¿åãå°çšã¢ãŒãã§å®è¡ããããšã§ãã¢ããªã±ãŒã·ã§ã³ã®å®å šæ§ãé«ããããšãã§ããŸã
--read-only ã¹ã€ããã䜿çšããŸãã ããã«ãããã³ã³ãã㌠ã€ã¡ãŒãžãå€æŽãããªãããã«ä¿è·ãããŸãã èªã
äžæããŒã¿ãæžã蟌ãå¿ èŠãããã®ã¯ã³ã³ããã ãã§ãã ããã«å¯ŸåŠããæåã®æ¹æ³ã¯ã
tmpfs ãã£ã¬ã¯ããªãããŠã³ãããŸã / run ããã³/tmpã
# docker run --read-only --tmpfs / run --tmpfs / tmpã« -i -t ãã§ããŒã©åžœ /bin/bash
å ¬éãã ãã° ã¡ãã»ãŒãž ãã ã ã³ã³ãã ããž ã ãã¹ãã® ãã°
ã³ã³ããã«èšé²ãããã¡ãã»ãŒãžããã¹ãã®ã³ã³ããã«è¡šç€ºãããå Žåã¯ã
syslog/journal ã®å Žåã¯ã次ã®ããã« /dev/log ãã£ã¬ã¯ããªããã€ã³ãããŠã³ãããå¿ èŠããããŸãã
# docker run -v /dev/log:/dev/log -i -t fedora /bin/bash
ã³ã³ããå ãããã°ã«ã¡ãã»ãŒãžãéä¿¡ããããšã§ããããã¹ãã§ããŸãã
(bash)# ãã¬ãŒãã³ã³ããããããã«ã¡ã¯ã
次ã«ãçµäºããŠãžã£ãŒãã«ã確èªããŸãã
ïŒ åºå£
#journalctl -b | grep ããã«ã¡ã¯
ããã«ããããã¬ãŒã«éä¿¡ãããã¡ãã»ãŒãžããªã¹ããããŸãã
ã¢ã¿ãã ããž XNUMX〠or ä»ã«ã¯ïŒ ãã æšæºå ¥åã æšæºåºåã æšæº
-a ãæå®ããªãå ŽåãDocker ã¯å¿ èŠãªãã® (stdinãstdoutãstderr) ããã¹ãŠã¢ã¿ããããŸãã
代ããã«æ¬¡ã®ããã«æ¥ç¶ããŸãã
# docker run -a stdin -a stdout -i -t fedora /bin/bash
åæ IPC ã®éã« ã³ã³ãã
ããã§å ¥æã§ãã shm_server.c ã®äœ¿çš: âšhttps://www.cs.cf.ac.uk/Dave/C/node27.htmlâ©
ãã¹ã --ipc=ãã¹ã ã¢ãŒãïŒ
ãã¹ãã«ã¯ 7 ã€ã® PID ãæ¥ç¶ãããå ±æã¡ã¢ãª ã»ã°ã¡ã³ãã衚瀺ãããŸããããã¯ããŸã㟠httpd ããã®ãã®ã§ãã
$ sudo ipcs -m
------ å ±æã¡ã¢ãªã»ã°ã¡ã³ã --------
ã㌠shmid ææè ããã€ããåºå®ããã¹ããŒã¿ã¹ãååŸããŸã
0x01128e25 0 ã«ãŒã 600 1000 7
ããã§éåžžã®ã³ã³ãããå®è¡ããŸãããã³ã³ããããã®å ±æã¡ã¢ãªã»ã°ã¡ã³ããæ£ããèªèãããŸããã
ã¶ã»ãã¹ãïŒ
$ docker run -it shm ipcs -m
------ å ±æã¡ã¢ãªã»ã°ã¡ã³ã --------
ã㌠shmid ææè ããã€ããåºå®ããã¹ããŒã¿ã¹ãååŸããŸã
æ°ãããã®ã§ã³ã³ãããå®è¡ããŸã --ipc=ãã¹ã ãªãã·ã§ã³ãéžæãããšãå ±æã¡ã¢ãªã»ã°ã¡ã³ãã衚瀺ãããããã«ãªããŸã
ãã¹ã httpd ãã:
$ docker run -it --ipc=host shm ipcs -m
------ å ±æã¡ã¢ãªã»ã°ã¡ã³ã --------
ã㌠shmid ææè ããã€ããåºå®ããã¹ããŒã¿ã¹ãååŸããŸã
0x01128e25 0 ã«ãŒã 600 1000 7
ãã¹ã --ipc=ã³ã³ãã:ã³ã³ããID ã¢ãŒãïŒ
ããã°ã©ã ã§ã³ã³ãããèµ·åããå ±æã¡ã¢ãª ã»ã°ã¡ã³ããäœæããŸãã
$ docker run -it shm bash
$ sudo shm/shm_server
$ sudo ipcs -m
------ å ±æã¡ã¢ãªã»ã°ã¡ã³ã --------
ã㌠shmid ææè ããã€ããåºå®ããã¹ããŒã¿ã¹ãååŸããŸã
0x0000162e 0 ã«ãŒã 666 27 1
2 çªç®ã®ã³ã³ãããæ£ããäœæãããšã1 çªç®ã®ã³ã³ããããã®å ±æã¡ã¢ãª ã»ã°ã¡ã³ãã衚瀺ãããŸããã
$ docker run shm ipcs -m
------ å ±æã¡ã¢ãªã»ã°ã¡ã³ã --------
ã㌠shmid ææè ããã€ããåºå®ããã¹ããŒã¿ã¹ãååŸããŸã
æ°ãã --ipc=container:CONTAINERID ãªãã·ã§ã³ã䜿çšã㊠3 çªç®ã®ã³ã³ãããäœæãããšã
æåããã®å ±æã¡ã¢ãªã»ã°ã¡ã³ã:
$ docker run -it --ipc=container:ed735b2264ac shm ipcs -m
$ sudo ipcs -m
------ å ±æã¡ã¢ãªã»ã°ã¡ã³ã --------
ã㌠shmid ææè ããã€ããåºå®ããã¹ããŒã¿ã¹ãååŸããŸã
0x0000162e 0 ã«ãŒã 666 27 1
é£çµ ã³ã³ãã
Note: ãã®ã»ã¯ã·ã§ã³ã§ã¯ãããã©ã«ã (ããªããž) ã§ã®ã³ã³ããéã®ãªã³ã¯ã«ã€ããŠèª¬æããŸãã
ãããã¯ãŒã¯ããã¬ã¬ã·ãŒ ãªã³ã¯ããšãåŒã°ããŸãã 䜿çšãã - ãªã³ã¯ ãŠãŒã¶ãŒå®çŸ©ã®ãããã¯ãŒã¯ã§äœ¿çšãã
DNS ããŒã¹ã®æ€åºããšã³ããªã¯è¿œå ãããŸããã /etc/hostsãèšå®ãããŸãã
æ€åºçšã®ç°å¢å€æ°ã
ãªã³ã¯æ©èœã䜿çšãããšãè€æ°ã®ã³ã³ãããçžäºã«éä¿¡ã§ããããã«ãªããŸãã ããšãã°ã
Dockerfile ãããŒã 80 ãå ¬éããŠããã³ã³ãããŒã¯ã次ã®ããã«å®è¡ããŠååãä»ããããšãã§ããŸãã
# docker run --name=link-test -d -i -t fedora/httpd
XNUMX çªç®ã®ã³ã³ãã㌠(ãã®å Žåã¯ãªã³ã«ãŒãšåŒã°ããŸã) 㯠httpd ã³ã³ãããŒãšéä¿¡ã§ããŸãã
link-test ãšããååã§ã --link= :
# docker run -t -i --link=link-test:lt --name=linker fedora /bin/bash
ããã§ãã³ã³ãã ãªã³ã«ãŒã¯ããšã€ãªã¢ã¹ lt ã䜿çšããŠã³ã³ãã link-test ã«ãªã³ã¯ãããŸããã ãå®è¡ãã
env ãªã³ã«ã³ã³ããå ã®ã³ãã³ãã§ç°å¢å€æ°ã衚瀺ããã
LT (ãšã€ãªã¢ã¹) ã³ã³ããã¹ã (LT_)
# ç°å¢
ãã¹ãå=668231cb0978
TERM=xterm
LT_PORT_80_TCP=tcp://172.17.0.3:80
LT_PORT_80_TCP_PORT=80
LT_PORT_80_TCP_PROTO=tcp
LT_PORT=tcp://172.17.0.3:80
PATH =/ usr / local / sbin:/ usr / local / bin:/ usr / sbin:/ usr / bin:/ sbin:/ binã«
PWD=/
LT_NAME=/ãªã³ã«ãŒ/lt
SHLVL=1
ããŒã =/
LT_PORT_80_TCP_ADDR=172.17.0.3
_=/ usr / bin / env
XNUMX ã€ã®ã³ã³ããããªã³ã¯ããå ŽåãDocker ã¯ã³ã³ããã®å ¬éããŒãã䜿çšããŠ
芪ãã¢ã¯ã»ã¹ã§ããå®å šãªãã³ãã«ã
ã³ã³ãããããã©ã«ãã®ããªããž ãããã¯ãŒã¯ã«æ¥ç¶ãããŠããå Žåã ãªã³ã¯ ä»ãšã®
ã³ã³ããã次ã«ã³ã³ããã® /etc/hosts ãã¡ã€ã«ã¯ãªã³ã¯ãããã³ã³ããã®å 容ã§æŽæ°ãããŸã
ååã
Note Docker ã¯ã³ã³ããã®ã©ã€ãã¢ããããŒããè¡ãå¯èœæ§ãããããã /etc/hosts ãã¡ã€ã«ããããããããŸãã
ã³ã³ããå ã®ããã»ã¹ã空ã®ããŸãã¯
äžå®å š /etc/hosts ãã¡ã€ã«ã ã»ãšãã©ã®å Žåãèªã¿åããå床詊è¡ãããšåé¡ã解決ãããã¯ãã§ãã
åé¡ã
ãããã³ã° ããŒã for å€éš 䜿çšæ³
ã¢ããªã±ãŒã·ã§ã³ã®å ¬éããŒãã¯ã -p åœæã ã«ãšã£ãŠ
ããšãã°ã次ã®ããã«ããŠãhttpd ããŒã 80 ããã¹ã ããŒã 8080 ã«ãããã³ã°ã§ããŸãã
# docker run -p 8080:80 -d -i -t fedora/httpd
äœæ & åãä»ã a äžã€ é³é ã³ã³ãã
å€ãã®ã¢ããªã±ãŒã·ã§ã³ã§ã¯ãè€æ°ã®ã³ã³ããéã§æ°žç¶ããŒã¿ãå ±æããå¿ èŠããããŸãã ããã«ãŒ
ä»ã®ã³ã³ãããããŠã³ãã§ããããŒã¿ ããªã¥ãŒã ã³ã³ãããäœæã§ããŸãã ã®ããã«
ããšãã°ããã£ã¬ã¯ã㪠/var/volume1 ããã³ /tmp/volume2 ãå«ãååä»ãã³ã³ãããäœæããŸãã
ã€ã¡ãŒãžã«ã¯ãããã®ãã£ã¬ã¯ããªãå«ãŸããŠããå¿ èŠããããããããã€ãã® RUN mkdir åœä»€ãå®è¡ããŸãã
Fedora-data ã€ã¡ãŒãžã«å¿ èŠãªå ŽåããããŸãã
# docker run --name=data -v /var/volume1 -v /tmp/volume2 -i -t fedora-data true
# docker run --volumes-from=data --name=fedora-container1 -i -t fedora bash
è€æ°ã® --volumes-from ãã©ã¡ãŒã¿ãŒã¯ãè€æ°ã®ããŒã¿ ããªã¥ãŒã ãè€æ°ã®ããŒã¿ ããªã¥ãŒã ã«ãŸãšããŸãã
ã³ã³ããã ãŸããDATA ã³ã³ããããååŸããããªã¥ãŒã ãããŠã³ãããããšãã§ããŸãã
fedora-container1 äžéã³ã³ãããä»ããŠããã«å¥ã®ã³ã³ããã䜿çšãããšã
å®éã®ããŒã¿ ãœãŒã¹ããã®ããŒã¿ã®ãŠãŒã¶ãŒããæœè±¡åããŸãã
# docker run --volumes-from=fedora-container1 --name=fedora-container2 -i -t fedora bash
åãä»ã å€éš ããªã¥ãŒã
ãã¹ã ãã£ã¬ã¯ããªãã³ã³ãã ããªã¥ãŒã ãšããŠããŠã³ãããã«ã¯ããã¹ã ãã£ã¬ã¯ããªãžã®çµ¶å¯Ÿãã¹ãæå®ããŸãã
ãã£ã¬ã¯ããªãšãã³ãã³ã§åºåãããã³ã³ãã ãã£ã¬ã¯ããªã®çµ¶å¯Ÿãã¹:
# docker run -v /var/db:/data1 -i -t fedora bash
SELinux ã䜿çšããå Žåããã¹ãã¯ã³ã³ãããŒã® SELinux ããªã·ãŒãèªèããªãããšã«æ³šæããŠãã ããã
ãããã£ãŠãäžèšã®äŸã§ã¯ãSELinux ããªã·ãŒãé©çšããããšã /var/db ãã£ã¬ã¯ããªã¯
ã³ã³ããã«ã¯æžã蟌ã¿ã§ããŸããã ãèš±å¯ãæåŠãããŸããããšããã¡ãã»ãŒãžã衚瀺ãããavc:
ãã¹ãã® syslog å ã®ã¡ãã»ãŒãžã
ãããåé¿ããã«ã¯ããã®ããã¥ã¢ã« ããŒãžã®äœææç¹ã§ã¯ã次ã®ã³ãã³ããå®è¡ããå¿ èŠããããŸãã
é©å㪠SELinux ããªã·ãŒ ã¿ã€ã ã©ãã«ããã¹ãã«ä»å ããããã«å®è¡ããŸãã
ãã£ã¬ã¯ããªïŒ
# chcon -Rt svirt_sandbox_file_t /var/db
ããã§ãã³ã³ããå ã® /data1 ããªã¥ãŒã ãžã®æžã蟌ã¿ãèš±å¯ãããå€æŽãåæ ãããŸãã
/var/db ã®ãã¹ãã«ãåæ ãããŸãã
䜿ãæ¹ ä»£æ¿æ¡ ã»ãã¥ãªã㣠ã©ããªã³ã°
ãæå®ããããšã§ãåã³ã³ããã®ããã©ã«ãã®ã©ãã«ä»ãã¹ããŒã ããªãŒããŒã©ã€ãã§ããŸãã
--ã»ãã¥ãªãã£ãªãã ãã©ã°ã ããšãã°ãMLS ã®èŠä»¶ã§ãã MCS/MLS ã¬ãã«ãæå®ã§ããŸãã
ã·ã¹ãã ã 次ã®ã³ãã³ãã§ã¬ãã«ãæå®ãããšãåããã®ãå ±æã§ããŸãã
ã³ã³ããéã®ã³ã³ãã³ãã
# docker run --security-opt label:level:s0:c100,c200 -i -t fedora bash
MLS ã®äŸã¯æ¬¡ã®ãšããã§ãã
# docker run --security-opt label:level:TopSecret -i -t rhel7 bash
ãã®ã³ã³ããã®ã»ãã¥ãªãã£ã©ãã«ãç¡å¹ã«ããã«ã¯ã --å¯å®¹
ãã©ã°ãèšå®ããã«ã¯ã次ã®ã³ãã³ãã䜿çšããŸãã
# docker run --security-opt label:disable -i -t fedora bash
ã³ã³ããå ã®ããã»ã¹ã«å¯ŸããŠããå³æ Œãªã»ãã¥ãªã㣠ããªã·ãŒãå¿ èŠãªå Žåã¯ã次ã®ããã«æå®ã§ããŸãã
ã³ã³ããã®ä»£æ¿ã¿ã€ãã ã®ã¿ãèš±å¯ãããŠããã³ã³ãããå®è¡ã§ããŸãã
次ã®ã³ãã³ããå®è¡ããŠãApache ããŒãããªãã¹ã³ããŸãã
# docker run --security-opt label:type:svirt_apache_t -i -t centos bash
泚ïŒ
ãå®çŸ©ããããªã·ãŒãäœæããå¿ èŠããããŸãã svirt_apache_t ã¿ã€ãã
èšå® ããã€ã¹ éé
èšå®ãããå Žå / dev / sdaã« ããã€ã¹ã®ééãŸã§ 200ã次ã®ããã«ããã€ã¹ã®ééãæå®ã§ããŸãã
--blkio-weight-device ãã©ã°ã 次ã®ã³ãã³ãã䜿çšããŸãã
# docker run -it --blkio-weight-device "/dev/sda:200" ubuntu
æå® åé¢ ãã¯ãããžãŒ for ã³ã³ãã ïŒ - åé¢ïŒ
ãã®ãªãã·ã§ã³ã¯ãMicrosoft äžã§ Docker ã³ã³ãããå®è¡ããŠããå Žåã«äŸ¿å©ã§ãã
ãŠã£ã³ããŠãºã ã® - åé¢ ãªãã·ã§ã³ã¯ã³ã³ããã®åé¢ãã¯ãããžãŒãèšå®ããŸãã Linux ã§ã¯ã
ãµããŒããããŠããã®ã¯ ããã©ã«ã Linux åå空éã䜿çšãããªãã·ã§ã³ã ããã XNUMX ã€ã®ã³ãã³ã
Linux ã§ã¯åçã§ãã
$ docker run -d ããžãŒããã¯ã¹ããã
$ docker run -d --isolation ããã©ã«ãã®busyboxããã
Microsoft Windows ã§ã¯ã次ã®ããããã®å€ãååŸã§ããŸãã
· ããã©ã«ã: Docker ããŒã¢ã³ã«ãã£ãŠæå®ãããå€ã䜿çšããŸãã --exec-opt ã ãã ããŒã¢ã³ ãããŸãã
åé¢ãã¯ãããžãæå®ããªããšãMicrosoft Windows ã䜿çšããŸã ããã»ã¹ ããã©ã«ããšããŠ
ã®å€ã§ãã
· ããã»ã¹: åå空éã®åé¢ã®ã¿ã
· ãã€ããŒã: Hyper-V ãã€ããŒãã€ã¶ãŒã®ããŒãã£ã·ã§ã³ããŒã¹ã®åé¢ã
å®éã«ã¯ãMicrosoft Windows äžã§ ããŒã¢ã³ ãªãã·ã§ã³ã»ããããã®XNUMXã€
ã³ãã³ãã¯åçã§ãã
$ docker run -d --isolation ããã©ã«ãã®busyboxããã
$ docker run -d --isolation process ããžãŒããã¯ã¹ã®ããã
ãèšå®ããŠããå Žåã¯ã --exec-opt åé¢=hyperv Docker ã®ãªãã·ã§ã³ ããŒã¢ã³ããããã®ãããã
ã³ãã³ãã§ã次ã®çµæãåŸãããŸã ãã€ããŒã åé¢ïŒ
$ docker run -d --isolation ããã©ã«ãã®busyboxããã
$ docker run -d --isolation hyperv ããžãŒããã¯ã¹ããã
æŽå²
2014幎XNUMXæãå ã ã¯William HenryïŒredhat dot comã®whenryïŒã«ãã£ãŠç·šéãããŸããã
docker.comã®ãœãŒã¹è³æãšå éšäœæ¥ã 2014幎XNUMXæãSvenDowideitã«ãã£ãŠæŽæ°ãããŸãã
âš[ã¡ãŒã«ä¿è·]â© 2014 幎 XNUMX æãSven Dowideit ã«ããæŽæ° âš[ã¡ãŒã«ä¿è·]â©
2015 幎 XNUMX æããµãªãŒã»ãªããªãŒã«ããæŽæ° âš[ã¡ãŒã«ä¿è·]â©
onworks.net ãµãŒãã¹ã䜿çšããŠãªã³ã©ã€ã³ã§ docker-run ã䜿çšãã