Docker容器无法访问外部网络及本地数据库问题求助
问题
Docker部署的Appsmith服务昨日运行正常,今日登录后卡在白屏。具体现象:
- 容器内执行
curl命令无法连接cs.appsmith.com及google.com,提示连接超时或网络不可达;主机系统执行相同命令可正常连接 - 关闭Plesk防火墙后,容器可正常访问外部网络,但仍无法连接本地数据库完成查询
- 长时间未修改防火墙及服务器配置,需找到开启防火墙时让Docker正常访问外部网络及本地数据库的解决方法
容器内curl测试输出
root@0436f43ca4d0:/opt/appsmith# curl -iv -m 10 https://cs.appsmith.com Trying 3.136.102.67:443... TCP_NODELAY set After 4994ms connect time, move on! connect to 3.136.102.67 port 443 failed: Connection timed out Trying 3.17.92.160:443... TCP_NODELAY set After 2496ms connect time, move on! connect to 3.17.92.160 port 443 failed: Connection timed out Failed to connect to cs.appsmith.com port 443: Connection timed out Closing connection 0 curl: (28) Failed to connect to cs.appsmith.com port 443: Connection timed out
主机curl测试输出
root@server:~# curl -iv -m 10 https://cs.appsmith.com Trying 3.17.92.160:443... TCP_NODELAY set Connected to cs.appsmith.com (3.17.92.160) port 443 (#0) ALPN, offering h2 ALPN, offering http/1.1 successfully set certificate verify locations: CAfile: /etc/ssl/certs/ca-certificates.crt CApath: /etc/ssl/certs TLSv1.3 (OUT), TLS handshake, Client hello (1): TLSv1.3 (IN), TLS handshake, Server hello (2): TLSv1.2 (IN), TLS handshake, Certificate (11): TLSv1.2 (IN), TLS handshake, Server key exchange (12): TLSv1.2 (IN), TLS handshake, Server finished (14): TLSv1.2 (OUT), TLS handshake, Client key exchange (16): TLSv1.2 (OUT), TLS change cipher, Change cipher spec (1): TLSv1.2 (OUT), TLS handshake, Finished (20): TLSv1.2 (IN), TLS handshake, Finished (20): SSL connection using TLSv1.2 / ECDHE-RSA-AES128-GCM-SHA256 ALPN, server did not agree to a protocol Server certificate: subject: CN=*.appsmith.com start date: Nov 4 00:00:00 2024 GMT expire date: Dec 3 23:59:59 2025 GMT subjectAltName: host "cs.appsmith.com" matched cert's "*.appsmith.com" issuer: C=US; O=Amazon; CN=Amazon RSA 2048 M03 SSL certificate verify ok. GET / HTTP/1.1 Host: cs.appsmith.com User-Agent: curl/7.68.0 Accept: / Mark bundle as not supporting multiuse < HTTP/1.1 401 Unauthorized HTTP/1.1 401 Unauthorized < Cache-Control: no-cache, no-store, max-age=0, must-revalidate Cache-Control: no-cache, no-store, max-age=0, must-revalidate < Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *; worker-src 'self' blob:; connect-src * 'self' blob: raw.githubusercontent.com .intercom.io wss://.intercom.io *.algolianet.com *.algolia.net api.segment.io *.sentry.io *.hotjar.com maps.googleapis.com fonts.googleapis.com www.gstatic.com fonts.gstatic.com appcdn.appsmith.com; img-src * data: blob:; media-src * data: blob:; style-src * 'self' 'unsafe-inline'; font-src * 'self' data:; frame-ancestors *; frame-src * data: blob: Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *; worker-src 'self' blob:; connect-src * 'self' blob: raw.githubusercontent.com .intercom.io wss://.intercom.io *.algolianet.com *.algolia.net api.segment.io *.sentry.io *.hotjar.com maps.googleapis.com fonts.googleapis.com www.gstatic.com fonts.gstatic.com appcdn.appsmith.com; img-src * data: blob:; media-src * data: blob:; style-src * 'self' 'unsafe-inline'; font-src * 'self' data:; frame-ancestors *; frame-src * data: blob: < Date: Thu, 20 Feb 2025 16:32:07 GMT Date: Thu, 20 Feb 2025 16:32:07 GMT < Expires: 0 Expires: 0 < Pragma: no-cache Pragma: no-cache < Referrer-Policy: no-referrer Referrer-Policy: no-referrer < Strict-Transport-Security: max-age=31536000; includeSubDomains Strict-Transport-Security: max-age=31536000; includeSubDomains < X-Content-Type-Options: nosniff X-Content-Type-Options: nosniff < X-Frame-Options: DENY X-Frame-Options: DENY < X-XSS-Protection: 0 X-XSS-Protection: 0 < Content-Length: 0 Content-Length: 0 < Connection: keep-alive Connection: keep-alive < Connection #0 to host cs.appsmith.com left intact
解决方案
一、解决Docker容器访问外部网络问题(Plesk防火墙开启时)
Plesk防火墙默认可能拦截了Docker的网络转发流量,按以下步骤添加规则:
- 允许Docker网桥接口出站流量
- 进入Plesk后台 > 工具与设置 > 防火墙 > 管理规则
- 添加新规则:方向设为出站,源地址填Docker网桥子网(默认
172.17.0.0/16,可通过主机执行ip addr show docker0确认),目标地址0.0.0.0/0,协议选tcp和udp,端口范围1-65535,规则名称设为Allow Docker outbound
- 允许主机IP转发
- 编辑
/etc/sysctl.conf,确保net.ipv4.ip_forward=1,执行sysctl -p生效 - 在Plesk防火墙添加转发规则:方向转发,源地址
172.17.0.0/16,目标地址0.0.0.0/0,协议tcp/udp,端口1-65535
- 编辑
- 重启服务
systemctl restart docker plesk firewall restart
二、解决容器访问本地数据库问题
容器无法访问本地数据库通常是因为数据库绑定回环地址或防火墙拦截,按以下步骤处理:
- 修改数据库绑定地址
- 编辑数据库配置文件(MySQL:
/etc/mysql/mysql.conf.d/mysqld.cnf;PostgreSQL:/etc/postgresql/<版本>/main/postgresql.conf) - 将
bind-address(MySQL)或listen_addresses(PostgreSQL)改为0.0.0.0或Docker子网地址(如172.17.0.0/16) - 重启数据库服务:
systemctl restart mysql(或postgresql)
- 编辑数据库配置文件(MySQL:
- 授权容器访问数据库
- 登录数据库,执行授权命令(以MySQL为例):
GRANT ALL PRIVILEGES ON <数据库名>.* TO '<用户名>'@'<容器IP或Docker子网>' IDENTIFIED BY '<密码>'; FLUSH PRIVILEGES;
- 登录数据库,执行授权命令(以MySQL为例):
- 添加Plesk防火墙规则
- 进入Plesk防火墙,添加入站规则:源地址
172.17.0.0/16,目标地址主机内网IP,协议tcp,端口填数据库端口(如MySQL 3306、PostgreSQL 5432),规则名称设为Allow Docker access local DB
- 进入Plesk防火墙,添加入站规则:源地址
- 容器内连接数据库时,使用主机内网IP(而非
localhost),因为容器的localhost指向自身内部
内容的提问来源于stack exchange,提问作者PaulMcF87
相关产品推荐
相关产品推荐

