You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ubuntu+Docker环境下Bind9 DNS服务器通信故障排查求助

问题排查:Docker部署Bind9 DNS服务器通信错误

我在Ubuntu上通过Docker搭建本地Bind9 DNS服务器,执行的启动命令如下:

docker run -d -p 1153:53/tcp -p 1153:53/udp -p 127.0.0.1:953:953/tcp --rm --name=dns-master --net=labnet --ip=192.168.0.2

但查询DNS服务器时提示通信错误,以下是我的相关配置文件:

Dockerfile

#Base Bind9 Image
FROM internetsystemsconsortium/bind9:9.18
RUN apt update \
  && apt install -y \
  bind9-doc \
  bind9-dnsutils \
  bind9-host \
  libedit2 \
  dnsutils \
  geoip-bin \
  mariadb-server \
  net-tools
# Copy configuration files
COPY configuration/named.conf.options /etc/bind/
COPY configuration/named.conf.local /etc/bind/
COPY configuration/db.vishnu /etc/bind/zones/
# Expose Ports
EXPOSE 53/tcp
EXPOSE 53/udp
EXPOSE 953/tcp
# Start the Name Service
CMD ["/usr/sbin/named", "-g", "-c", "/etc/bind/named.conf", "-u", "bind"]

zone文件 db.vishnu

$TTL    1d ; default expiration time (in seconds) of all RRs without their own TTL value
@       IN      SOA     ns1.vishnu. root.vishnu. (
                  3      ; Serial
                  1d     ; Refresh
                  1h     ; Retry
                  1w     ; Expire
                  1h )   ; Negative Cache TTL
; name servers - NS records
     IN      NS      ns1.vishnu.
; name servers - A records
ns1.vishnu.             IN      A      192.168.0.1
one.vishnu.             IN      A      192.168.1.1
two.vishnu.             IN      A      192.168.1.2

named.conf.local

zone "vishnu" {    
    type master;    
    file "/etc/bind/zones/db.vishnu";

排查修复步骤

  • 修复配置文件语法错误:named.conf.local末尾缺少闭合的};,这会直接导致Bind9服务启动失败,补充后重新构建镜像。
  • 调整DNS查询方式:容器53端口映射到了宿主机的1153端口,查询时必须指定端口,例如执行:
    dig @127.0.0.1 -p 1153 one.vishnu
    
  • 统一NS记录与容器IP:容器IP为192.168.0.2,但db.vishnu中ns1.vishnu的A记录指向192.168.0.1,两者不匹配,需将A记录修改为192.168.0.2,或调整容器启动时的--ip参数。
  • 检查服务启动日志:通过docker logs dns-master查看Bind9启动日志,确认配置加载状态、端口监听情况,这是定位启动类问题的核心依据。
  • 修正目录权限:确保/etc/bind/zones/目录存在且bind用户有读取权限,可在Dockerfile中添加以下命令:
    RUN mkdir -p /etc/bind/zones && chown -R bind:bind /etc/bind
    
  • 清理冗余依赖:Dockerfile中安装的mariadb-server等软件与Bind9服务无关,会增加镜像体积且可能引发冲突,建议从安装列表中移除。

内容的提问来源于stack exchange,提问作者Vishy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.21 15:22:09