无Root权限Podman容器DNS配置异常:Kerberos认证DNS解析失败
无root权限下Podman容器通过Ansible配置本地DNS解析Kerberos域名的解决方案
问题背景
在无root权限的客户端服务器上运行Podman容器,需要解析4个仅用于Kerberos认证、无公共DNS记录的域名。主机本地resolv.conf已指向本地dnsmasq服务:
servername 127.0.0.1
dnsmasq的配置文件dnsmasq.conf也已添加对应私有域名的DNS服务器规则:
user=dnsmasq group=dnsmasq listen-address=127.0.0.1 # Include all files in /etc/dnsmasq.d except RPM backup files conf-dir=/etc/dnsmasq.d,.rpmnew,.rpmsave,.rpmorig # Primary DNS Servers server=/example1/dns1 server=/example2/dns2 server=/example3/dns3 # Secondary DNS Servers server=/example1/dns1 server=/example2/dns2 server=/example3/dns3
但Podman容器启动时会自动使用公共DNS(8.8.8.8、8.8.4.4),导致私有域名无法解析。手动执行podman run --dns 127.0.0.1 -it localhost/example /bin/bash可以正常生效,现在需要通过Ansible Automation Platform实现自动化配置,但尝试使用127.0.0.11或127.1.1.11作为DNS地址时,容器仍无法解析目标域名。
可行解决方案
1. Ansible中直接指定容器DNS地址
使用Ansible的podman_container模块时,通过dns_servers参数直接指定127.0.0.1,和手动添加--dns参数效果完全一致。
示例Playbook:
- name: 启动Podman容器并配置本地DNS hosts: 目标主机组 tasks: - name: 运行指定容器 containers.podman.podman_container: name: example_container image: localhost/example command: /bin/bash interactive: true tty: true dns_servers: - 127.0.0.1
2. 配置Podman全局默认DNS(无root权限适用)
如果希望所有容器默认使用本地DNS,可以在当前用户目录下配置Podman的全局设置:
- 创建用户级Podman配置目录(如果不存在):
mkdir -p ~/.config/containers - 在该目录下创建
containers.conf文件,添加以下内容:[containers] dns = ["127.0.0.1"]
通过Ansible自动化部署这个配置的Playbook示例:
- name: 配置Podman全局默认DNS hosts: 目标主机组 tasks: - name: 创建Podman配置目录 file: path: "{{ ansible_user_dir }}/.config/containers" state: directory mode: '0755' - name: 写入containers.conf配置 copy: content: | [containers] dns = ["127.0.0.1"] dest: "{{ ansible_user_dir }}/.config/containers/containers.conf" mode: '0644'
3. 为什么127.0.0.11和127.1.1.11无效?
127.0.0.11是Docker内置的DNS解析器地址,Podman在无root模式下并不将该地址指向主机的dnsmasq服务,而是使用自身的DNS解析逻辑,无法识别主机dnsmasq配置的私有域名规则。127.1.1.11并非标准的容器DNS地址,Podman不会将其关联到主机本地的DNS服务,自然无法解析私有域名。
内容的提问来源于stack exchange,提问作者Ramya
相关产品推荐
相关产品推荐

