You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ubuntu 18.04 VPS上Docker容器无法访问互联网求助

Docker容器内网络连接故障求助

问题现象

在Ubuntu 18.04 VPS上运行Docker容器时,容器内无法正常访问外部网络,具体表现为执行apk update命令失败。

复现步骤

  • 启动Alpine容器:
docker run -it alpine

容器可正常启动。

  • 在容器内执行更新命令:
apk update

返回错误信息:

fetch https://dl-cdn.alpinelinux.org/alpine/v3.19/main/x86_64/APKINDEX.tar.gz
WARNING: updating and opening https://dl-cdn.alpinelinux.org/alpine/v3.19/main: temporary error (try again later)
fetch https://dl-cdn.alpinelinux.org/alpine/v3.19/community/x86_64/APKINDEX.tar.gz
WARNING: updating and opening https://dl-cdn.alpinelinux.org/alpine/v3.19/community: temporary error (try again later)
4 unavailable, 0 stale; 15 distinct packages available

已完成的排查操作

  1. 宿主机网络正常:可ping通dl-cdn.alpinelinux.org,也能通过curl获取该地址的APKINDEX文件。
  2. 容器内DNS配置(/etc/resolv.conf):
# This file is managed by man:systemd-resolved(8). Do not edit.
#
# This is a dynamic resolv.conf file for connecting local clients directly to
# all known uplink DNS servers. This file lists all configured search domains.
#
# Third party programs must not access this file directly, but only through the
# symlink at /etc/resolv.conf. To manage man:resolv.conf(5) in a different way,
# replace this symlink by a static file or a different symlink.
#
# See man:systemd-resolved.service(8) for details about the supported modes of
# operation for /etc/resolv.conf.

nameserver 172.26.0.2
search us-east-2.compute.internal
  1. 宿主机iptables规则:
Chain INPUT (policy ACCEPT)
target     prot opt source               destination          

Chain FORWARD (policy DROP)
target     prot opt source               destination         
DOCKER-USER  all  --  anywhere             anywhere            
DOCKER-ISOLATION-STAGE-1  all  --  anywhere             anywhere            
ACCEPT     all  --  anywhere             anywhere             ctstate RELATED,ESTABLISHED
DOCKER     all  --  anywhere             anywhere            
ACCEPT     all  --  anywhere             anywhere            
ACCEPT     all  --  anywhere             anywhere            

Chain OUTPUT (policy ACCEPT)
target     prot opt source               destination          

Chain DOCKER (1 references)
target     prot opt source               destination          

Chain DOCKER-ISOLATION-STAGE-1 (1 references)
target     prot opt source               destination         
DOCKER-ISOLATION-STAGE-2  all  --  anywhere             anywhere            
RETURN     all  --  anywhere             anywhere            

Chain DOCKER-ISOLATION-STAGE-2 (1 references)
target     prot opt source               destination         
DROP       all  --  anywhere             anywhere            
RETURN     all  --  anywhere             anywhere            

Chain DOCKER-USER (1 references)
target     prot opt source               destination         
RETURN     all  --  anywhere             anywhere 
  1. Docker桥接网络配置(docker network inspect bridge):
[
    {
        "Name": "bridge",
        "Id": "92d96247979cc2db1b6b25f471a8c9f7761104ef5e1a69d14eb982032b6b5d65",
        "Created": "2024-02-15T17:47:46.223814476Z",
        "Scope": "local",
        "Driver": "bridge",
        "EnableIPv6": false,
        "IPAM": {
            "Driver": "default",
            "Options": null,
            "Config": [
                {
                    "Subnet": "172.17.0.0/16",
                    "Gateway": "172.17.0.1"
                }
            ]
        },
        "Internal": false,
        "Attachable": false,
        "Ingress": false,
        "ConfigFrom": {
            "Network": ""
        },
        "ConfigOnly": false,
        "Containers": {
            "c52c39b0836d766002f39909a3745cd84e442650d3ab2d439bdc9d3bce834f36": {
                "Name": "suspicious_cannon",
                "EndpointID": "3bc35e264a77081eb701885ed8d7f1ed917136b163a07ddcebd3abd865120385",
                "MacAddress": "02:42:ac:11:00:02",
                "IPv4Address": "172.17.0.2/16",
                "IPv6Address": ""
            }
        },
        "Options": {
            "com.docker.network.bridge.default_bridge": "true",
            "com.docker.network.bridge.enable_icc": "true",
            "com.docker.network.bridge.enable_ip_masquerade": "true",
            "com.docker.network.bridge.host_binding_ipv4": "0.0.0.0",
            "com.docker.network.bridge.name": "docker0",
            "com.docker.network.driver.mtu": "1500"
        },
        "Labels": {}
    }
]
  1. 未处于代理环境(无法完全确认),未发现额外防火墙规则(无法完全确认)。

求助需求

已排查多日仍未解决问题,恳请协助定位并修复容器内的网络连接故障。


内容的提问来源于stack exchange,提问作者SJL

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 19:10:35