Ubuntu 18.04 VPS上Docker容器无法访问互联网求助
Docker容器内网络连接故障求助
问题现象
在Ubuntu 18.04 VPS上运行Docker容器时,容器内无法正常访问外部网络,具体表现为执行apk update命令失败。
复现步骤
- 启动Alpine容器:
docker run -it alpine
容器可正常启动。
- 在容器内执行更新命令:
apk update
返回错误信息:
fetch https://dl-cdn.alpinelinux.org/alpine/v3.19/main/x86_64/APKINDEX.tar.gz WARNING: updating and opening https://dl-cdn.alpinelinux.org/alpine/v3.19/main: temporary error (try again later) fetch https://dl-cdn.alpinelinux.org/alpine/v3.19/community/x86_64/APKINDEX.tar.gz WARNING: updating and opening https://dl-cdn.alpinelinux.org/alpine/v3.19/community: temporary error (try again later) 4 unavailable, 0 stale; 15 distinct packages available
已完成的排查操作
- 宿主机网络正常:可ping通
dl-cdn.alpinelinux.org,也能通过curl获取该地址的APKINDEX文件。 - 容器内DNS配置(
/etc/resolv.conf):
# This file is managed by man:systemd-resolved(8). Do not edit. # # This is a dynamic resolv.conf file for connecting local clients directly to # all known uplink DNS servers. This file lists all configured search domains. # # Third party programs must not access this file directly, but only through the # symlink at /etc/resolv.conf. To manage man:resolv.conf(5) in a different way, # replace this symlink by a static file or a different symlink. # # See man:systemd-resolved.service(8) for details about the supported modes of # operation for /etc/resolv.conf. nameserver 172.26.0.2 search us-east-2.compute.internal
- 宿主机iptables规则:
Chain INPUT (policy ACCEPT) target prot opt source destination Chain FORWARD (policy DROP) target prot opt source destination DOCKER-USER all -- anywhere anywhere DOCKER-ISOLATION-STAGE-1 all -- anywhere anywhere ACCEPT all -- anywhere anywhere ctstate RELATED,ESTABLISHED DOCKER all -- anywhere anywhere ACCEPT all -- anywhere anywhere ACCEPT all -- anywhere anywhere Chain OUTPUT (policy ACCEPT) target prot opt source destination Chain DOCKER (1 references) target prot opt source destination Chain DOCKER-ISOLATION-STAGE-1 (1 references) target prot opt source destination DOCKER-ISOLATION-STAGE-2 all -- anywhere anywhere RETURN all -- anywhere anywhere Chain DOCKER-ISOLATION-STAGE-2 (1 references) target prot opt source destination DROP all -- anywhere anywhere RETURN all -- anywhere anywhere Chain DOCKER-USER (1 references) target prot opt source destination RETURN all -- anywhere anywhere
- Docker桥接网络配置(
docker network inspect bridge):
[ { "Name": "bridge", "Id": "92d96247979cc2db1b6b25f471a8c9f7761104ef5e1a69d14eb982032b6b5d65", "Created": "2024-02-15T17:47:46.223814476Z", "Scope": "local", "Driver": "bridge", "EnableIPv6": false, "IPAM": { "Driver": "default", "Options": null, "Config": [ { "Subnet": "172.17.0.0/16", "Gateway": "172.17.0.1" } ] }, "Internal": false, "Attachable": false, "Ingress": false, "ConfigFrom": { "Network": "" }, "ConfigOnly": false, "Containers": { "c52c39b0836d766002f39909a3745cd84e442650d3ab2d439bdc9d3bce834f36": { "Name": "suspicious_cannon", "EndpointID": "3bc35e264a77081eb701885ed8d7f1ed917136b163a07ddcebd3abd865120385", "MacAddress": "02:42:ac:11:00:02", "IPv4Address": "172.17.0.2/16", "IPv6Address": "" } }, "Options": { "com.docker.network.bridge.default_bridge": "true", "com.docker.network.bridge.enable_icc": "true", "com.docker.network.bridge.enable_ip_masquerade": "true", "com.docker.network.bridge.host_binding_ipv4": "0.0.0.0", "com.docker.network.bridge.name": "docker0", "com.docker.network.driver.mtu": "1500" }, "Labels": {} } ]
- 未处于代理环境(无法完全确认),未发现额外防火墙规则(无法完全确认)。
求助需求
已排查多日仍未解决问题,恳请协助定位并修复容器内的网络连接故障。
内容的提问来源于stack exchange,提问作者SJL
相关产品推荐
相关产品推荐

