如何将docker容器连接到同一个macvlan网络上的多个ips?

如何将docker容器连接到同一个macvlan网络上的多个ips?

当我尝试在同一个 macvlan 网络中向我的 docker 容器添加第二个 ip 地址时,使用 create,, docker network connectstart 模式它似乎会覆盖第一个 ip 地址。

重现步骤:

1)创建docker macvlan网络:

docker network create -d macvlan \
    --subnet=192.168.100.1/24 \
    -o parent=eth0 pub_net

2)从镜像创建一个docker容器,并将子网中的ip地址添加到容器中:

docker create \
    --network pub_net \
    --ip=192.168.100.2 \
    -h mycontainer \
    --name mycontainer \
    -ti \
    alpine \
    /bin/sh

3)向容器添加第二个具有别名的 IP 地址

docker network connect \
    --ip 192.168.100.3 \
    --alias mycontainer-int2 \
    pub_net \
    mycontainer

(并且为了确保万无一失,该命令的结果是 0 - 成功)

$ echo $?
0

4)运行并打开看看

$ docker start mycontainer
mycontainer
$ docker attach mycontainer
/ # ip a
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN qlen 1
    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
    inet 127.0.0.1/8 scope host lo
   valid_lft forever preferred_lft forever
inet6 ::1/128 scope host 
   valid_lft forever preferred_lft forever
10: eth0@if2: <NO-CARRIER,BROADCAST,MULTICAST,UP,M-DOWN> mtu 1500 qdisc noqueue state LOWERLAYERDOWN 
    link/ether 02:42:c0:a8:c8:03 brd ff:ff:ff:ff:ff:ff
    inet 192.168.100.3/24 scope global eth0
   valid_lft forever preferred_lft forever
/ # 

并且...为了确保万无一失:

$ docker network inspect pub_net
[
    {
        "Name": "pub_net",
        "Id": "578df6fd9929b0c44356e32a04043b358c2a052e11377ee7430743cd48566203",
        "Scope": "local",
        "Driver": "macvlan",
        "EnableIPv6": false,
        "IPAM": {
            "Driver": "default",
            "Options": {},
            "Config": [
                {
                    "Subnet": "192.168.100.1/24"
                }
            ]
        },
        "Internal": false,
        "Containers": {
            "7f2fd160b8f7340d75861c1c0f743820ee713b13738a1f09252b0b17da58f111": {
                "Name": "mycontainer",
                "EndpointID": "44af06571b1c6334001cbb13c15702640d93930e30f415052e684a96b0d0a893",
                "MacAddress": "02:42:c0:a8:c8:03",
                "IPv4Address": "192.168.100.3/24",
                "IPv6Address": ""
            }
        },
        "Options": {
            "parent": "eth0"
        },
        "Labels": {}
    }
]

如何将同一个 docker macvlan 网络中的附加 IP(在同一个或附加的虚拟接口上)正确地添加到同一个 docker 容器中?

答案1

作为对我的问题的临时回答。可以通过进行两项更改来实现此目的:

1)在创建命令中添加--cap-add=NET_ADMIN,例如

docker create \
    --cap-add=NET_ADMIN
    --network pub_net \
    --ip=192.168.100.2 \
    -h mycontainer \
    --name mycontainer \
    -ti \
    alpine \
    /bin/sh

2)跳过第 3 步并添加 ip 地址之内Docker容器:

$ docker start mycontainer
mycontainer
$ docker attach mycontainer
/ # ip a a 192.168.100.3/24 dev eth0
/ # ip a
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN qlen 1
    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
    inet 127.0.0.1/8 scope host lo
   valid_lft forever preferred_lft forever
inet6 ::1/128 scope host 
   valid_lft forever preferred_lft forever
10: eth0@if2: <NO-CARRIER,BROADCAST,MULTICAST,UP,M-DOWN> mtu 1500 qdisc noqueue state LOWERLAYERDOWN 
    link/ether 02:42:c0:a8:c8:03 brd ff:ff:ff:ff:ff:ff
    inet 192.168.100.2/24 scope global eth0
   valid_lft forever preferred_lft forever
    inet 192.168.100.3/24 scope global secondary eth0
   valid_lft forever preferred_lft forever
    / # 

这是可行的,因为我现在可以通过任一 IP ping 并访问同一个容器。

但需要注意的是,必须手动管理 IP。只有创建命令中的原始 IP 才会显示在docker network inspect

相关内容