Closed10

さくらVPS+UbuntuにDocker入れる

ranran

ubuntu 24.04

$ lsb_release -a
No LSB modules are available.
Distributor ID: Ubuntu
Description:    Ubuntu 24.04 LTS
Release:        24.04
Codename:       noble
ranran

docker engineインストール

公式みてやる。docker engineはコンテナ動かすためのやつ
https://docs.docker.com/engine/install/ubuntu/

aptリポジトリげっちゅ

ubuntu
# Add Docker's official GPG key:
sudo apt-get update
sudo apt-get install ca-certificates curl
sudo install -m 0755 -d /etc/apt/keyrings
sudo curl -fsSL https://download.docker.com/linux/ubuntu/gpg -o /etc/apt/keyrings/docker.asc
sudo chmod a+r /etc/apt/keyrings/docker.asc

# Add the repository to Apt sources:
echo \
  "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.asc] https://download.docker.com/linux/ubuntu \
  $(. /etc/os-release && echo "$VERSION_CODENAME") stable" | \
  sudo tee /etc/apt/sources.list.d/docker.list > /dev/null
sudo apt-get update

インストール

ubuntu
sudo apt-get install docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin

動作確認

ubuntu
sudo docker run hello-world

Unable to find image 'hello-world:latest' locally
latest: Pulling from library/hello-world
c1ec31eb5944: Pull complete 
Digest: sha256:1408fec50309afee38f3535383f5b09419e6dc0925bc69891e79d84cc4cdcec6
Status: Downloaded newer image for hello-world:latest

Hello from Docker! # これがでたらよき
This message shows that your installation appears to be working correctly.

To generate this message, Docker took the following steps:
 1. The Docker client contacted the Docker daemon.
 2. The Docker daemon pulled the "hello-world" image from the Docker Hub.
    (amd64)
 3. The Docker daemon created a new container from that image which runs the
    executable that produces the output you are currently reading.
 4. The Docker daemon streamed that output to the Docker client, which sent it
    to your terminal.

To try something more ambitious, you can run an Ubuntu container with:
 $ docker run -it ubuntu bash

Share images, automate workflows, and more with a free Docker ID:
 https://hub.docker.com/

For more examples and ideas, visit:
 https://docs.docker.com/get-started

バージョン確認

ubuntu
$ docker -v
Docker version 27.0.3, build 7d4bcd8
ranran

Dockerデーモンを非ルートユーザーとして実行する(ルートレスモード)

https://docs.docker.com/engine/security/rootless/

ルートレス モードでは、Docker デーモンとコンテナを非ルート ユーザーとして実行して、デーモンとコンテナ ランタイムの潜在的な脆弱性を軽減できます。

ルートレス モードでは、Docker デーモンとコンテナがユーザー名前空間内で実行されます。これは userns-remapモードと非常に似ていますが、userns-remapモードではデーモン自体がルート権限で実行されるのに対し、ルートレス モードではデーモンとコンテナの両方がルート権限なしで実行されるという点が異なります。

dockerデーモンとは
https://zenn.dev/link/comments/de7001ec3d32cd

ルートレスモードだと何がうれしいのか
https://medium.com/nttlabs/rootless-docker-12decb900fb9

というわけでやってみる

ranran

前提条件の確認

必要なパッケージがインストールされているか

You must install newuidmap and newgidmap on the host. These commands are provided by the uidmap package on most distros.

ubuntu
$ dpkg -l dbus-user-session uidmap systemd-container
ubuntu
dpkg-query: no packages found matching uidmap
Desired=Unknown/Install/Remove/Purge/Hold
| Status=Not/Inst/Conf-files/Unpacked/halF-conf/Half-inst/trig-aWait/Trig-pend
|/ Err?=(none)/Reinst-required (Status,Err: uppercase=bad)
||/ Name              Version          Architecture Description
+++-=================-================-============-=================================================================
ii  dbus-user-session 1.14.10-4ubuntu4 amd64        simple interprocess messaging system (systemd --user integration)
un  systemd-container <none>           <none>       (no description available)

uidmapがないらしい

というわけでインストール

ubuntu
$ sudo apt-get install -y uidmap

/etc/subuidまた、/etc/subgidユーザーには少なくとも 65,536 個の従属 UID/GID が含まれている必要があります

/etc/subuid and /etc/subgid should contain at least 65,536 subordinate UIDs/GIDs for the user. In the following example, the user testuser has 65,536 subordinate UIDs/GIDs (231072-296607).

ubuntu
$ grep ^$(whoami): /etc/subuid
ubuntu:100000:65536 # これが65,536以上あればいい
$ grep ^$(whoami): /etc/subgid
ubuntu:100000:65536 # これが65,536以上あればいい
ranran

インストール

dockerデーモンが実行していたら無効にする

ubuntu
$ sudo systemctl disable --now docker.service docker.socket
$ sudo rm /var/run/docker.sock

dockerd-rootless-setuptool.shが存在するか確認

ubuntu
$ find /usr/bin/ -name 'dockerd-rootless-setuptool.sh'
/usr/bin/dockerd-rootless-setuptool.sh # ある

なかったら

ubuntu
$  sudo apt-get install -y docker-ce-rootless-extras

dockerd-rootless-setuptool.shを実行

ubuntu
$ dockerd-rootless-setuptool.sh install
ubuntu
[INFO] Creating /home/ubuntu/.config/systemd/user/docker.service
[INFO] starting systemd service docker.service
+ systemctl --user start docker.service
+ systemctl --user --no-pager --full status docker.service
● docker.service - Docker Application Container Engine (Rootless)
     Loaded: loaded (/home/ubuntu/.config/systemd/user/docker.service; disabled; preset: enabled)
     Active: active (running) since Fri 2024-07-19 16:59:30 JST; 3s ago
       Docs: https://docs.docker.com/go/rootless/
   Main PID: 1658 (rootlesskit)
      Tasks: 34
     Memory: 122.5M (peak: 122.8M)
        CPU: 432ms
     CGroup: /user.slice/user-1000.slice/user@1000.service/app.slice/docker.service
             ├─1658 rootlesskit --state-dir=/run/user/1000/dockerd-rootless --net=slirp4netns --mtu=65520 --slirp4netns-sandbox=auto --slirp4netns-seccomp=auto --disable-host-loopback --port-driver=builtin --copy-up=/etc --copy-up=/run --propagation=rslave /usr/bin/dockerd-rootless.sh
             ├─1668 /proc/self/exe --state-dir=/run/user/1000/dockerd-rootless --net=slirp4netns --mtu=65520 --slirp4netns-sandbox=auto --slirp4netns-seccomp=auto --disable-host-loopback --port-driver=builtin --copy-up=/etc --copy-up=/run --propagation=rslave /usr/bin/dockerd-rootless.sh
             ├─1688 slirp4netns --mtu 65520 -r 3 --disable-host-loopback --enable-sandbox --enable-seccomp 1668 tap0
             ├─1695 dockerd
             └─1712 containerd --config /run/user/1000/docker/containerd/containerd.toml

Jul 19 16:59:29 ik1-406-35195 dockerd-rootless.sh[1695]: time="2024-07-19T16:59:29.993511678+09:00" level=warning msg="WARNING: No io.max (rbps) support"
Jul 19 16:59:29 ik1-406-35195 dockerd-rootless.sh[1695]: time="2024-07-19T16:59:29.993521052+09:00" level=warning msg="WARNING: No io.max (wbps) support"
Jul 19 16:59:29 ik1-406-35195 dockerd-rootless.sh[1695]: time="2024-07-19T16:59:29.993525986+09:00" level=warning msg="WARNING: No io.max (riops) support"
Jul 19 16:59:29 ik1-406-35195 dockerd-rootless.sh[1695]: time="2024-07-19T16:59:29.993530539+09:00" level=warning msg="WARNING: No io.max (wiops) support"
Jul 19 16:59:29 ik1-406-35195 dockerd-rootless.sh[1695]: time="2024-07-19T16:59:29.993535077+09:00" level=warning msg="WARNING: bridge-nf-call-iptables is disabled"
Jul 19 16:59:29 ik1-406-35195 dockerd-rootless.sh[1695]: time="2024-07-19T16:59:29.993539392+09:00" level=warning msg="WARNING: bridge-nf-call-ip6tables is disabled"
Jul 19 16:59:29 ik1-406-35195 dockerd-rootless.sh[1695]: time="2024-07-19T16:59:29.993557067+09:00" level=info msg="Docker daemon" commit=662f78c containerd-snapshotter=false storage-driver=overlay2 version=27.0.3
Jul 19 16:59:29 ik1-406-35195 dockerd-rootless.sh[1695]: time="2024-07-19T16:59:29.993673769+09:00" level=info msg="Daemon has completed initialization"
Jul 19 16:59:30 ik1-406-35195 dockerd-rootless.sh[1695]: time="2024-07-19T16:59:30.037660842+09:00" level=info msg="API listen on /run/user/1000/docker.sock"
Jul 19 16:59:30 ik1-406-35195 systemd[703]: Started docker.service - Docker Application Container Engine (Rootless).
+ DOCKER_HOST=unix:///run/user/1000/docker.sock /usr/bin/docker version
Client: Docker Engine - Community
 Version:           27.0.3
 API version:       1.46
 Go version:        go1.21.11
 Git commit:        7d4bcd8
 Built:             Sat Jun 29 00:02:23 2024
 OS/Arch:           linux/amd64
 Context:           default

Server: Docker Engine - Community
 Engine:
  Version:          27.0.3
  API version:      1.46 (minimum version 1.24)
  Go version:       go1.21.11
  Git commit:       662f78c
  Built:            Sat Jun 29 00:02:23 2024
  OS/Arch:          linux/amd64
  Experimental:     false
 containerd:
  Version:          1.7.19
  GitCommit:        2bf793ef6dc9a18e00cb12efb64355c2c9d5eb41
 runc:
  Version:          1.7.19
  GitCommit:        v1.1.13-0-g58aa920
 docker-init:
  Version:          0.19.0
  GitCommit:        de40ad0
 rootlesskit:
  Version:          2.0.2
  ApiVersion:       1.1.1
  NetworkDriver:    slirp4netns
  PortDriver:       builtin
  StateDir:         /run/user/1000/dockerd-rootless
 slirp4netns:
  Version:          1.2.1
  GitCommit:        09e31e92fa3d2a1d3ca261adaeb012c8d75a8194
+ systemctl --user enable docker.service
Created symlink /home/ubuntu/.config/systemd/user/default.target.wants/docker.service → /home/ubuntu/.config/systemd/user/docker.service.
[INFO] Installed docker.service successfully.
[INFO] To control docker.service, run: `systemctl --user (start|stop|restart) docker.service`
[INFO] To run docker.service on system startup, run: `sudo loginctl enable-linger ubuntu`

[INFO] Creating CLI context "rootless"
Successfully created context "rootless"
[INFO] Using CLI context "rootless"
Current context is now "rootless"

[INFO] Make sure the following environment variable(s) are set (or add them to ~/.bashrc):
export PATH=/usr/bin:$PATH

[INFO] Some applications may require the following environment variable too:
export DOCKER_HOST=unix:///run/user/1000/docker.sock
ranran

dockerデーモンをユーザー権限で実行

ubuntu
$ systemctl --user start docker

システムの起動時にデーモンを自動起動

ubuntu
$ systemctl --user enable docker
$ sudo loginctl enable-linger $(whoami)
ranran

rootlessモードで実行できているか確認

ubuntu
$ docker info
ubuntu
Client: Docker Engine - Community
 Version:    27.0.3
 Context:    rootless
 Debug Mode: false
 Plugins:
  buildx: Docker Buildx (Docker Inc.)
    Version:  v0.15.1
    Path:     /usr/libexec/docker/cli-plugins/docker-buildx
  compose: Docker Compose (Docker Inc.)
    Version:  v2.28.1
    Path:     /usr/libexec/docker/cli-plugins/docker-compose

いいね!

ranran

docker info実行時の警告

$ docker info
WARNING: No cpuset support
WARNING: No io.weight support
WARNING: No io.weight (per device) support
WARNING: No io.max (rbps) support
WARNING: No io.max (wbps) support
WARNING: No io.max (riops) support
WARNING: No io.max (wiops) support
WARNING: bridge-nf-call-iptables is disabled
WARNING: bridge-nf-call-ip6tables is disabled
  • WARNING: No cpuset support
  • WARNING: No io.weight support
  • WARNING: No io.weight (per device) support
  • WARNING: No io.max (rbps) support
  • WARNING: No io.max (wbps) support
  • WARNING: No io.max (riops) support
  • WARNING: No io.max (wiops) support

Cgroup is supported only when running with cgroup v2 and systemd. See Limiting resources.
https://docs.docker.com/engine/security/rootless/#known-limitations

システムリソース制限できませんよ 的なことっぽい
systemdでやるdocker runするときにオプションを指定することでできそう

  • WARNING: bridge-nf-call-iptables is disable
  • WARNING: bridge-nf-call-ip6tables is disabled

/proc/sys/net/bridge/bridge-nf-call-iptables(またはbridge-nf-call-ip6tables)がなければ無視していい

このスクラップは4ヶ月前にクローズされました