You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无Root权限Podman容器DNS配置异常:Kerberos认证DNS解析失败

无root权限下Podman容器通过Ansible配置本地DNS解析Kerberos域名的解决方案

问题背景

在无root权限的客户端服务器上运行Podman容器,需要解析4个仅用于Kerberos认证、无公共DNS记录的域名。主机本地resolv.conf已指向本地dnsmasq服务:

servername 127.0.0.1

dnsmasq的配置文件dnsmasq.conf也已添加对应私有域名的DNS服务器规则:

user=dnsmasq
group=dnsmasq

listen-address=127.0.0.1
# Include all files in /etc/dnsmasq.d except RPM backup files
conf-dir=/etc/dnsmasq.d,.rpmnew,.rpmsave,.rpmorig

# Primary DNS Servers
server=/example1/dns1
server=/example2/dns2
server=/example3/dns3

# Secondary DNS Servers
server=/example1/dns1
server=/example2/dns2
server=/example3/dns3

但Podman容器启动时会自动使用公共DNS(8.8.8.8、8.8.4.4),导致私有域名无法解析。手动执行podman run --dns 127.0.0.1 -it localhost/example /bin/bash可以正常生效,现在需要通过Ansible Automation Platform实现自动化配置,但尝试使用127.0.0.11或127.1.1.11作为DNS地址时,容器仍无法解析目标域名。

可行解决方案

1. Ansible中直接指定容器DNS地址

使用Ansible的podman_container模块时,通过dns_servers参数直接指定127.0.0.1,和手动添加--dns参数效果完全一致。

示例Playbook:

- name: 启动Podman容器并配置本地DNS
  hosts: 目标主机组
  tasks:
    - name: 运行指定容器
      containers.podman.podman_container:
        name: example_container
        image: localhost/example
        command: /bin/bash
        interactive: true
        tty: true
        dns_servers:
          - 127.0.0.1

2. 配置Podman全局默认DNS(无root权限适用)

如果希望所有容器默认使用本地DNS,可以在当前用户目录下配置Podman的全局设置:

  1. 创建用户级Podman配置目录(如果不存在):mkdir -p ~/.config/containers
  2. 在该目录下创建containers.conf文件,添加以下内容:
    [containers]
    dns = ["127.0.0.1"]
    

通过Ansible自动化部署这个配置的Playbook示例:

- name: 配置Podman全局默认DNS
  hosts: 目标主机组
  tasks:
    - name: 创建Podman配置目录
      file:
        path: "{{ ansible_user_dir }}/.config/containers"
        state: directory
        mode: '0755'

    - name: 写入containers.conf配置
      copy:
        content: |
          [containers]
          dns = ["127.0.0.1"]
        dest: "{{ ansible_user_dir }}/.config/containers/containers.conf"
        mode: '0644'

3. 为什么127.0.0.11和127.1.1.11无效?

  • 127.0.0.11是Docker内置的DNS解析器地址,Podman在无root模式下并不将该地址指向主机的dnsmasq服务,而是使用自身的DNS解析逻辑,无法识别主机dnsmasq配置的私有域名规则。
  • 127.1.1.11并非标准的容器DNS地址,Podman不会将其关联到主机本地的DNS服务,自然无法解析私有域名。

内容的提问来源于stack exchange,提问作者Ramya

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.19 00:38:15