Ubuntu+Docker环境下Bind9 DNS服务器通信故障排查求助
问题排查:Docker部署Bind9 DNS服务器通信错误
我在Ubuntu上通过Docker搭建本地Bind9 DNS服务器,执行的启动命令如下:
docker run -d -p 1153:53/tcp -p 1153:53/udp -p 127.0.0.1:953:953/tcp --rm --name=dns-master --net=labnet --ip=192.168.0.2
但查询DNS服务器时提示通信错误,以下是我的相关配置文件:
Dockerfile
#Base Bind9 Image FROM internetsystemsconsortium/bind9:9.18 RUN apt update \ && apt install -y \ bind9-doc \ bind9-dnsutils \ bind9-host \ libedit2 \ dnsutils \ geoip-bin \ mariadb-server \ net-tools # Copy configuration files COPY configuration/named.conf.options /etc/bind/ COPY configuration/named.conf.local /etc/bind/ COPY configuration/db.vishnu /etc/bind/zones/ # Expose Ports EXPOSE 53/tcp EXPOSE 53/udp EXPOSE 953/tcp # Start the Name Service CMD ["/usr/sbin/named", "-g", "-c", "/etc/bind/named.conf", "-u", "bind"]
zone文件 db.vishnu
$TTL 1d ; default expiration time (in seconds) of all RRs without their own TTL value @ IN SOA ns1.vishnu. root.vishnu. ( 3 ; Serial 1d ; Refresh 1h ; Retry 1w ; Expire 1h ) ; Negative Cache TTL ; name servers - NS records IN NS ns1.vishnu. ; name servers - A records ns1.vishnu. IN A 192.168.0.1 one.vishnu. IN A 192.168.1.1 two.vishnu. IN A 192.168.1.2
named.conf.local
zone "vishnu" { type master; file "/etc/bind/zones/db.vishnu";
排查修复步骤
- 修复配置文件语法错误:
named.conf.local末尾缺少闭合的};,这会直接导致Bind9服务启动失败,补充后重新构建镜像。 - 调整DNS查询方式:容器53端口映射到了宿主机的1153端口,查询时必须指定端口,例如执行:
dig @127.0.0.1 -p 1153 one.vishnu - 统一NS记录与容器IP:容器IP为
192.168.0.2,但db.vishnu中ns1.vishnu的A记录指向192.168.0.1,两者不匹配,需将A记录修改为192.168.0.2,或调整容器启动时的--ip参数。 - 检查服务启动日志:通过
docker logs dns-master查看Bind9启动日志,确认配置加载状态、端口监听情况,这是定位启动类问题的核心依据。 - 修正目录权限:确保
/etc/bind/zones/目录存在且bind用户有读取权限,可在Dockerfile中添加以下命令:RUN mkdir -p /etc/bind/zones && chown -R bind:bind /etc/bind - 清理冗余依赖:Dockerfile中安装的
mariadb-server等软件与Bind9服务无关,会增加镜像体积且可能引发冲突,建议从安装列表中移除。
内容的提问来源于stack exchange,提问作者Vishy
相关产品推荐
相关产品推荐

