You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

为何同版本Docker镜像在不同主机容器中ls命令可用性不同?

同一Nginx Docker镜像在不同主机执行ls /etc出现差异的原因分析

问题现象

在两台不同主机上使用nginx:1.25.1镜像执行以下命令:

docker run -it --name nginx --entrypoint ls nginx:1.25.1 /etc

得到完全不同的结果:

机器A执行成功,输出/etc目录内容

docker run -it --name nginx --entrypoint ls nginx:1.25.1 /etc
adduser.conf            fonts      ld.so.cache    passwd       shadow
alternatives            fstab      ld.so.conf     passwd-      shadow-
apt                     gai.conf   ld.so.conf.d   profile      shells
bash.bashrc             group      libaudit.conf  profile.d    skel
bindresvport.blacklist  group-     localtime      rc0.d        ssl
ca-certificates         gshadow    login.defs     rc1.d        subgid
ca-certificates.conf    gshadow-   logrotate.d    rc2.d        subuid
cron.d                  gss        mke2fs.conf    rc3.d        systemd
cron.daily              host.conf  motd           rc4.d        terminfo
debconf.conf            hostname   mtab           rc5.d        timezone
debian_version          hosts      nginx          rc6.d        update-motd.d
default                 init.d     nsswitch.conf  rcS.d        xattr.conf
deluser.conf            inputrc    opt            resolv.conf
dpkg                    issue      os-release     rmt
e2scrub.conf            issue.net  pam.conf       security
environment             kernel     pam.d          selinux

机器B执行失败,提示ls不存在

docker run -it --name nginx --entrypoint ls  nginx:1.25.1 /etc     
docker: Error response from daemon: OCI runtime create failed: container_linux.go:349: starting container process caused "exec: \"ls\": executable file not found in $PATH": unknown.
ERRO[0000] error waiting for container: context canceled

两台主机信息

机器A

uname -a
Linux ubuntu2204.localdomain 5.15.0-69-generic #76-Ubuntu SMP Fri Mar 17 17:19:29 UTC 2023 x86_64 x86_64 x86_64 GNU/Linux
docker info
Client:
 Context:    default
 Debug Mode: false
 Plugins:
  buildx: Docker Buildx (Docker Inc., v0.10.4)
  compose: Docker Compose (Docker Inc., v2.17.2)

Server:
 Containers: 2
  Running: 1
  Paused: 0
  Stopped: 1
 Images: 2
 Server Version: 20.10.24
 Storage Driver: overlay2
  Backing Filesystem: extfs
  Supports d_type: true
  Native Overlay Diff: true
  userxattr: false
 Logging Driver: json-file
 Cgroup Driver: systemd
 Cgroup Version: 2
 Plugins:
  Volume: local
  Network: bridge host ipvlan macvlan null overlay
  Log: awslogs fluentd gcplogs gelf journald json-file local logentries splunk syslog
 Swarm: inactive
 Runtimes: io.containerd.runtime.v1.linux runc io.containerd.runc.v2
 Default Runtime: runc
 Init Binary: docker-init
 containerd version: 2806fc1057397dbaeefbea0e4e17bddfbd388f38
 runc version:
 init version: de40ad0
 Security Options:
  apparmor
  seccomp
   Profile: default
  cgroupns
 Kernel Version: 5.15.0-69-generic
 Operating System: Ubuntu Core 22
 OSType: linux
 Architecture: x86_64
 CPUs: 4
 Total Memory: 7.763GiB
 Name: ubuntu2204.localdomain
 ID: C75T:TAOG:RQZP:LIYO:3MRE:W5ER:5I2D:IMUC:PTQP:LWZL:62KP:U5XQ
 Docker Root Dir: /var/snap/docker/common/var-lib-docker
 Debug Mode: false
 Registry: https://index.docker.io/v1/
 Labels:
 Experimental: false
 Insecure Registries:
  127.0.0.0/8
 Registry Mirrors:
  https://xxx
 Live Restore Enabled: false

机器B

uname -a
Linux master 3.10.0-1160.an7.x86_64 #1 SMP Thu Oct 14 16:04:36 CST 2021 x86_64 x86_64 x86_64 GNU/Linux

docker info
Client:
 Debug Mode: false

Server:
 Containers: 145
  Running: 76
  Paused: 0
  Stopped: 69
 Images: 252
 Server Version: 19.03.13
 Storage Driver: overlay2
  Backing Filesystem: xfs
  Supports d_type: true
  Native Overlay Diff: true
 Logging Driver: json-file
 Cgroup Driver: systemd
 Plugins:
  Volume: local
  Network: bridge host ipvlan macvlan null overlay
  Log: awslogs fluentd gcplogs gelf journald json-file local logentries splunk syslog
 Swarm: inactive
 Runtimes: runc
 Default Runtime: runc
 Init Binary: docker-init
 containerd version: ea765aba0d05254012b0b9e595e995c09186427f
 runc version: dc9208a3303feef5b3839f4323d9beb36df0a9dd
 init version: fec3683
 Security Options:
  seccomp
   Profile: default
 Kernel Version: 3.10.0-1160.an7.x86_64
 Operating System: Anolis OS 7.9
 OSType: linux
 Architecture: x86_64
 CPUs: 6
 Total Memory: 11.58GiB
 Name: master
 ID: TMQB:QWTV:CQMU:FN32:TUU4:XQBZ:I4F3:DMX2:U4BV:MRU3:5JU6:YJHR
 Docker Root Dir: /var/lib/docker
 Debug Mode: false
 HTTP Proxy: http://172.31.1.1:8070
 HTTPS Proxy: http://172.31.1.1:8070
 No Proxy: 127.0.0.0/8,10.0.0.0/8,172.0.0.0/8,192.168.0.0/16,169.254.0.0/16,100.0.0.0/8,168.0.0.0/8,localhost,svc,local
 Registry: https://index.docker.io/v1/
 Labels:
 Experimental: false
 Insecure Registries:
  127.0.0.0/8
 Registry Mirrors:
  https://xxx
 Live Restore Enabled: false

原因分析

1. Docker版本兼容性问题

nginx:1.25.1基于Debian 12(Bookworm)镜像,该系统使用glibc 2.36。机器B的Docker版本为19.03.13,属于较旧的稳定版,其配套的runc/containerd组件对新glibc版本的镜像支持存在缺陷,无法正确初始化容器内的$PATH环境变量,导致系统找不到位于/bin/ls的可执行文件。而机器A的Docker 20.10.24已经修复了这类兼容性问题。

2. 内核版本的间接影响

机器B使用3.10.x内核(Anolis 7.9),机器A使用5.15.x内核(Ubuntu 22.04)。旧内核与旧Docker版本的组合,在处理overlay2存储驱动下的新镜像文件系统时,可能存在路径解析的潜在问题,进一步加剧了PATH异常的情况。

3. 验证方式

在机器B上执行带完整路径的ls命令,确认是否能正常运行:

docker run -it --name nginx --entrypoint /bin/ls nginx:1.25.1 /etc

若执行成功,即可确认是$PATH未正确加载导致的问题。

解决建议

  • 升级机器B的Docker版本至20.10及以上版本,确保对新Debian镜像的兼容性。
  • 若无法升级Docker,可选择基于旧版Debian(如Debian 11)的Nginx镜像,例如nginx:1.25.1-bullseye或降级到nginx:1.21.6这类适配旧Docker版本的镜像。

内容的提问来源于stack exchange,提问作者Hamusuta0320

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.04 15:09:55