为何同版本Docker镜像在不同主机容器中ls命令可用性不同?
同一Nginx Docker镜像在不同主机执行
ls /etc出现差异的原因分析 问题现象
在两台不同主机上使用nginx:1.25.1镜像执行以下命令:
docker run -it --name nginx --entrypoint ls nginx:1.25.1 /etc
得到完全不同的结果:
机器A执行成功,输出/etc目录内容
docker run -it --name nginx --entrypoint ls nginx:1.25.1 /etc adduser.conf fonts ld.so.cache passwd shadow alternatives fstab ld.so.conf passwd- shadow- apt gai.conf ld.so.conf.d profile shells bash.bashrc group libaudit.conf profile.d skel bindresvport.blacklist group- localtime rc0.d ssl ca-certificates gshadow login.defs rc1.d subgid ca-certificates.conf gshadow- logrotate.d rc2.d subuid cron.d gss mke2fs.conf rc3.d systemd cron.daily host.conf motd rc4.d terminfo debconf.conf hostname mtab rc5.d timezone debian_version hosts nginx rc6.d update-motd.d default init.d nsswitch.conf rcS.d xattr.conf deluser.conf inputrc opt resolv.conf dpkg issue os-release rmt e2scrub.conf issue.net pam.conf security environment kernel pam.d selinux
机器B执行失败,提示ls不存在
docker run -it --name nginx --entrypoint ls nginx:1.25.1 /etc docker: Error response from daemon: OCI runtime create failed: container_linux.go:349: starting container process caused "exec: \"ls\": executable file not found in $PATH": unknown. ERRO[0000] error waiting for container: context canceled
两台主机信息
机器A
uname -a Linux ubuntu2204.localdomain 5.15.0-69-generic #76-Ubuntu SMP Fri Mar 17 17:19:29 UTC 2023 x86_64 x86_64 x86_64 GNU/Linux docker info Client: Context: default Debug Mode: false Plugins: buildx: Docker Buildx (Docker Inc., v0.10.4) compose: Docker Compose (Docker Inc., v2.17.2) Server: Containers: 2 Running: 1 Paused: 0 Stopped: 1 Images: 2 Server Version: 20.10.24 Storage Driver: overlay2 Backing Filesystem: extfs Supports d_type: true Native Overlay Diff: true userxattr: false Logging Driver: json-file Cgroup Driver: systemd Cgroup Version: 2 Plugins: Volume: local Network: bridge host ipvlan macvlan null overlay Log: awslogs fluentd gcplogs gelf journald json-file local logentries splunk syslog Swarm: inactive Runtimes: io.containerd.runtime.v1.linux runc io.containerd.runc.v2 Default Runtime: runc Init Binary: docker-init containerd version: 2806fc1057397dbaeefbea0e4e17bddfbd388f38 runc version: init version: de40ad0 Security Options: apparmor seccomp Profile: default cgroupns Kernel Version: 5.15.0-69-generic Operating System: Ubuntu Core 22 OSType: linux Architecture: x86_64 CPUs: 4 Total Memory: 7.763GiB Name: ubuntu2204.localdomain ID: C75T:TAOG:RQZP:LIYO:3MRE:W5ER:5I2D:IMUC:PTQP:LWZL:62KP:U5XQ Docker Root Dir: /var/snap/docker/common/var-lib-docker Debug Mode: false Registry: https://index.docker.io/v1/ Labels: Experimental: false Insecure Registries: 127.0.0.0/8 Registry Mirrors: https://xxx Live Restore Enabled: false
机器B
uname -a Linux master 3.10.0-1160.an7.x86_64 #1 SMP Thu Oct 14 16:04:36 CST 2021 x86_64 x86_64 x86_64 GNU/Linux docker info Client: Debug Mode: false Server: Containers: 145 Running: 76 Paused: 0 Stopped: 69 Images: 252 Server Version: 19.03.13 Storage Driver: overlay2 Backing Filesystem: xfs Supports d_type: true Native Overlay Diff: true Logging Driver: json-file Cgroup Driver: systemd Plugins: Volume: local Network: bridge host ipvlan macvlan null overlay Log: awslogs fluentd gcplogs gelf journald json-file local logentries splunk syslog Swarm: inactive Runtimes: runc Default Runtime: runc Init Binary: docker-init containerd version: ea765aba0d05254012b0b9e595e995c09186427f runc version: dc9208a3303feef5b3839f4323d9beb36df0a9dd init version: fec3683 Security Options: seccomp Profile: default Kernel Version: 3.10.0-1160.an7.x86_64 Operating System: Anolis OS 7.9 OSType: linux Architecture: x86_64 CPUs: 6 Total Memory: 11.58GiB Name: master ID: TMQB:QWTV:CQMU:FN32:TUU4:XQBZ:I4F3:DMX2:U4BV:MRU3:5JU6:YJHR Docker Root Dir: /var/lib/docker Debug Mode: false HTTP Proxy: http://172.31.1.1:8070 HTTPS Proxy: http://172.31.1.1:8070 No Proxy: 127.0.0.0/8,10.0.0.0/8,172.0.0.0/8,192.168.0.0/16,169.254.0.0/16,100.0.0.0/8,168.0.0.0/8,localhost,svc,local Registry: https://index.docker.io/v1/ Labels: Experimental: false Insecure Registries: 127.0.0.0/8 Registry Mirrors: https://xxx Live Restore Enabled: false
原因分析
1. Docker版本兼容性问题
nginx:1.25.1基于Debian 12(Bookworm)镜像,该系统使用glibc 2.36。机器B的Docker版本为19.03.13,属于较旧的稳定版,其配套的runc/containerd组件对新glibc版本的镜像支持存在缺陷,无法正确初始化容器内的$PATH环境变量,导致系统找不到位于/bin/ls的可执行文件。而机器A的Docker 20.10.24已经修复了这类兼容性问题。
2. 内核版本的间接影响
机器B使用3.10.x内核(Anolis 7.9),机器A使用5.15.x内核(Ubuntu 22.04)。旧内核与旧Docker版本的组合,在处理overlay2存储驱动下的新镜像文件系统时,可能存在路径解析的潜在问题,进一步加剧了PATH异常的情况。
3. 验证方式
在机器B上执行带完整路径的ls命令,确认是否能正常运行:
docker run -it --name nginx --entrypoint /bin/ls nginx:1.25.1 /etc
若执行成功,即可确认是$PATH未正确加载导致的问题。
解决建议
- 升级机器B的Docker版本至20.10及以上版本,确保对新Debian镜像的兼容性。
- 若无法升级Docker,可选择基于旧版Debian(如Debian 11)的Nginx镜像,例如
nginx:1.25.1-bullseye或降级到nginx:1.21.6这类适配旧Docker版本的镜像。
内容的提问来源于stack exchange,提问作者Hamusuta0320
相关产品推荐
相关产品推荐

