Podman容器运行ENTRYPOINT脚本构建HAProxy时崩溃求助
问题描述
我想基于一份RHEL8相关指南,在AlmaLinux 8的Podman容器中构建HAProxy。
用下面的Dockerfile构建镜像并运行容器时,HAProxy构建阶段会崩溃:
FROM almalinux:8 COPY make_ha_proxy.sh /usr/local/bin ENTRYPOINT ["make_ha_proxy.sh"]
但如果采用以下步骤操作,脚本能正常运行,且能从./return目录获取到生成的二进制文件:
podman run -tdi --rm --name test -v ./return:/tmp/binary_return almalinux:8 podman cp make_ha_proxy.sh test:/usr/local/bin podman exec -it test bash /usr/local/bin/make_ha_proxy.sh
以下是make_ha_proxy.sh脚本内容:
#!/usr/bin/bash HAPROXY_MINOR='2.8.2' HAPROXY_MAJOR='2.8' LUA_VERSION='5.4.6' RETURN_DIR='/tmp/binary_return/' # installing dependencies dnf update -y dnf install -y gcc openssl-devel readline-devel systemd-devel make pcre-devel file # get and build lua mkdir -p /opt/lua && cd /opt/lua || exit curl https://www.lua.org/ftp/lua-${LUA_VERSION}.tar.gz > lua-${LUA_VERSION}.tar.gz tar xvf lua-${LUA_VERSION}.tar.gz && cd lua-${LUA_VERSION} || exit make INSTALL_TOP=/opt/lua-${LUA_VERSION} linux install lua_rc=$? if [ ${lua_rc} != 0 ] ; then echo "building lua failed !" ; exit 1 fi # get and build ha_proxy mkdir -p /opt/haproxy && cd /opt/haproxy || exit curl http://www.haproxy.org/download/${HAPROXY_MAJOR}/src/haproxy-${HAPROXY_MINOR}.tar.gz > haproxy-${HAPROXY_MINOR}.tar.gz curl http://www.haproxy.org/download/${HAPROXY_MAJOR}/src/haproxy-${HAPROXY_MINOR}.tar.gz.sha256 > haproxy-${HAPROXY_MINOR}.tar.gz.sha256 cd /opt/haproxy && tar xvf haproxy-${HAPROXY_MINOR}.tar.gz cd /opt/haproxy/haproxy-${HAPROXY_MINOR} || exit make USE_NS=1 \ USE_TFO=1 \ USE_OPENSSL=1 \ USE_ZLIB=1 \ USE_LUA=1 \ USE_PCRE=1 \ USE_SYSTEMD=1 \ USE_LIBCRYPT=1 \ USE_THREAD=1 \ TARGET=linux-glibc \ LUA_INC=/opt/lua-${LUA_VERSION}/include \ LUA_LIB=/opt/lua-${LUA_VERSION}/lib make PREFIX=/opt/haproxy-${HAPROXY_MINOR} install # move the build binary to the return directory if [ ! -d ${RETURN_DIR} ] ; then mkdir -p -- "${RETURN_DIR}" fi # copying the created binary to the return directory if [ $(file -b --mime-type /opt/haproxy/haproxy-${HAPROXY_MINOR}/haproxy | sed 's|/.*||') == application ] ; then cp /opt/haproxy/haproxy-${HAPROXY_MINOR}/haproxy "${RETURN_DIR}"/ else exit 1 fi exit 0
求排查该问题的线索。
排查线索
- 检查容器资源限制:Dockerfile运行容器时,默认内存、CPU限制可能比交互式exec场景更严格,HAProxy编译阶段资源消耗较高,容易因资源不足崩溃。可通过
--memory、--cpus参数调高限制后测试:podman run --memory=2g --cpus=2 ... - 获取完整崩溃日志:运行容器时不使用
-d参数,实时查看标准输出/错误;或用podman logs <容器名>查看历史日志,定位编译过程中具体哪一步出错(如依赖缺失、编译参数问题)。 - 验证脚本执行权限:Dockerfile中COPY脚本后未添加可执行权限,ENTRYPOINT直接执行脚本会失败(交互式用
bash调用不受影响)。可在Dockerfile中添加:RUN chmod +x /usr/local/bin/make_ha_proxy.sh - 确认挂载目录配置:Dockerfile运行容器时是否挂载了
./return目录?若未挂载,脚本最后复制二进制文件的步骤会失败,虽你称是构建阶段崩溃,但也可能引发后续逻辑异常。另外可检查挂载目录的权限是否正常。 - 对比两种运行环境差异:交互式exec与ENTRYPOINT直接运行的环境变量、系统状态可能不同。可在脚本开头添加
env命令,分别输出两种方式下的环境变量进行对比;或在HAProxy编译前,打印当前工作目录、依赖库路径等信息,确认是否一致。 - 添加包校验步骤:脚本仅下载了HAProxy的SHA256校验文件但未执行校验,Dockerfile运行时可能因网络问题导致包损坏,引发编译失败。可在脚本中添加校验逻辑:
cd /opt/haproxy sha256sum -c haproxy-${HAPROXY_MINOR}.tar.gz.sha256 if [ $? -ne 0 ]; then echo "HAProxy包校验失败" exit 1 fi - 排查systemd依赖影响:编译HAProxy时启用了
USE_SYSTEMD=1,但容器默认可能缺少完整的systemd环境。可尝试暂时移除该参数,观察是否仍崩溃,以此排除systemd相关问题。
内容的提问来源于stack exchange,提问作者vrms
相关产品推荐
相关产品推荐

