You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker容器无法访问外部网络及本地数据库问题求助

问题

Docker部署的Appsmith服务昨日运行正常,今日登录后卡在白屏。具体现象:

  • 容器内执行curl命令无法连接cs.appsmith.com及google.com,提示连接超时或网络不可达;主机系统执行相同命令可正常连接
  • 关闭Plesk防火墙后,容器可正常访问外部网络,但仍无法连接本地数据库完成查询
  • 长时间未修改防火墙及服务器配置,需找到开启防火墙时让Docker正常访问外部网络及本地数据库的解决方法

容器内curl测试输出

root@0436f43ca4d0:/opt/appsmith# curl -iv -m 10 https://cs.appsmith.com

Trying 3.136.102.67:443...
TCP_NODELAY set
After 4994ms connect time, move on!
connect to 3.136.102.67 port 443 failed: Connection timed out
Trying 3.17.92.160:443...
TCP_NODELAY set
After 2496ms connect time, move on!
connect to 3.17.92.160 port 443 failed: Connection timed out
Failed to connect to cs.appsmith.com port 443: Connection timed out
Closing connection 0
curl: (28) Failed to connect to cs.appsmith.com port 443: Connection timed out

主机curl测试输出

root@server:~# curl -iv -m 10 https://cs.appsmith.com

Trying 3.17.92.160:443...
TCP_NODELAY set
Connected to cs.appsmith.com (3.17.92.160) port 443 (#0)
ALPN, offering h2
ALPN, offering http/1.1
successfully set certificate verify locations:
CAfile: /etc/ssl/certs/ca-certificates.crt
CApath: /etc/ssl/certs
TLSv1.3 (OUT), TLS handshake, Client hello (1):
TLSv1.3 (IN), TLS handshake, Server hello (2):
TLSv1.2 (IN), TLS handshake, Certificate (11):
TLSv1.2 (IN), TLS handshake, Server key exchange (12):
TLSv1.2 (IN), TLS handshake, Server finished (14):
TLSv1.2 (OUT), TLS handshake, Client key exchange (16):
TLSv1.2 (OUT), TLS change cipher, Change cipher spec (1):
TLSv1.2 (OUT), TLS handshake, Finished (20):
TLSv1.2 (IN), TLS handshake, Finished (20):
SSL connection using TLSv1.2 / ECDHE-RSA-AES128-GCM-SHA256
ALPN, server did not agree to a protocol
Server certificate:
subject: CN=*.appsmith.com
start date: Nov 4 00:00:00 2024 GMT
expire date: Dec 3 23:59:59 2025 GMT
subjectAltName: host "cs.appsmith.com" matched cert's "*.appsmith.com"
issuer: C=US; O=Amazon; CN=Amazon RSA 2048 M03
SSL certificate verify ok.
GET / HTTP/1.1
Host: cs.appsmith.com
User-Agent: curl/7.68.0
Accept: /

Mark bundle as not supporting multiuse
< HTTP/1.1 401 Unauthorized
HTTP/1.1 401 Unauthorized
< Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
< Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *; worker-src 'self' blob:; connect-src * 'self' blob: raw.githubusercontent.com .intercom.io wss://.intercom.io *.algolianet.com *.algolia.net api.segment.io *.sentry.io *.hotjar.com maps.googleapis.com fonts.googleapis.com www.gstatic.com fonts.gstatic.com appcdn.appsmith.com; img-src * data: blob:; media-src * data: blob:; style-src * 'self' 'unsafe-inline'; font-src * 'self' data:; frame-ancestors *; frame-src * data: blob:
Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *; worker-src 'self' blob:; connect-src * 'self' blob: raw.githubusercontent.com .intercom.io wss://.intercom.io *.algolianet.com *.algolia.net api.segment.io *.sentry.io *.hotjar.com maps.googleapis.com fonts.googleapis.com www.gstatic.com fonts.gstatic.com appcdn.appsmith.com; img-src * data: blob:; media-src * data: blob:; style-src * 'self' 'unsafe-inline'; font-src * 'self' data:; frame-ancestors *; frame-src * data: blob:
< Date: Thu, 20 Feb 2025 16:32:07 GMT
Date: Thu, 20 Feb 2025 16:32:07 GMT
< Expires: 0
Expires: 0
< Pragma: no-cache
Pragma: no-cache
< Referrer-Policy: no-referrer
Referrer-Policy: no-referrer
< Strict-Transport-Security: max-age=31536000; includeSubDomains
Strict-Transport-Security: max-age=31536000; includeSubDomains
< X-Content-Type-Options: nosniff
X-Content-Type-Options: nosniff
< X-Frame-Options: DENY
X-Frame-Options: DENY
< X-XSS-Protection: 0
X-XSS-Protection: 0
< Content-Length: 0
Content-Length: 0
< Connection: keep-alive
Connection: keep-alive
<

Connection #0 to host cs.appsmith.com left intact
解决方案

一、解决Docker容器访问外部网络问题(Plesk防火墙开启时)

Plesk防火墙默认可能拦截了Docker的网络转发流量,按以下步骤添加规则:

  1. 允许Docker网桥接口出站流量
    • 进入Plesk后台 > 工具与设置 > 防火墙 > 管理规则
    • 添加新规则:方向设为出站,源地址填Docker网桥子网(默认172.17.0.0/16,可通过主机执行ip addr show docker0确认),目标地址0.0.0.0/0,协议选tcp和udp,端口范围1-65535,规则名称设为Allow Docker outbound
  2. 允许主机IP转发
    • 编辑/etc/sysctl.conf,确保net.ipv4.ip_forward=1,执行sysctl -p生效
    • 在Plesk防火墙添加转发规则:方向转发,源地址172.17.0.0/16,目标地址0.0.0.0/0,协议tcp/udp,端口1-65535
  3. 重启服务
    systemctl restart docker
    plesk firewall restart
    

二、解决容器访问本地数据库问题

容器无法访问本地数据库通常是因为数据库绑定回环地址或防火墙拦截,按以下步骤处理:

  1. 修改数据库绑定地址
    • 编辑数据库配置文件(MySQL:/etc/mysql/mysql.conf.d/mysqld.cnf;PostgreSQL:/etc/postgresql/<版本>/main/postgresql.conf)
    • 将bind-address(MySQL)或listen_addresses(PostgreSQL)改为0.0.0.0或Docker子网地址(如172.17.0.0/16)
    • 重启数据库服务:systemctl restart mysql(或postgresql)
  2. 授权容器访问数据库
    • 登录数据库,执行授权命令(以MySQL为例):
      GRANT ALL PRIVILEGES ON <数据库名>.* TO '<用户名>'@'<容器IP或Docker子网>' IDENTIFIED BY '<密码>';
      FLUSH PRIVILEGES;
      
  3. 添加Plesk防火墙规则
    • 进入Plesk防火墙,添加入站规则:源地址172.17.0.0/16,目标地址主机内网IP,协议tcp,端口填数据库端口(如MySQL 3306、PostgreSQL 5432),规则名称设为Allow Docker access local DB
  4. 容器内连接数据库时,使用主机内网IP(而非localhost),因为容器的localhost指向自身内部

内容的提问来源于stack exchange,提问作者PaulMcF87

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 08:43:12