You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Podman容器运行ENTRYPOINT脚本构建HAProxy时崩溃求助

问题描述

我想基于一份RHEL8相关指南,在AlmaLinux 8的Podman容器中构建HAProxy。

用下面的Dockerfile构建镜像并运行容器时,HAProxy构建阶段会崩溃:

FROM almalinux:8

COPY make_ha_proxy.sh /usr/local/bin
ENTRYPOINT ["make_ha_proxy.sh"]

但如果采用以下步骤操作,脚本能正常运行,且能从./return目录获取到生成的二进制文件:

podman run -tdi --rm --name test -v ./return:/tmp/binary_return almalinux:8
podman cp make_ha_proxy.sh test:/usr/local/bin
podman exec -it test bash /usr/local/bin/make_ha_proxy.sh

以下是make_ha_proxy.sh脚本内容:

#!/usr/bin/bash

HAPROXY_MINOR='2.8.2'
HAPROXY_MAJOR='2.8'
LUA_VERSION='5.4.6'
RETURN_DIR='/tmp/binary_return/'

# installing dependencies
dnf update -y
dnf install -y gcc openssl-devel readline-devel systemd-devel make pcre-devel file

# get and build lua
mkdir -p /opt/lua && cd /opt/lua || exit

curl https://www.lua.org/ftp/lua-${LUA_VERSION}.tar.gz > lua-${LUA_VERSION}.tar.gz
tar xvf lua-${LUA_VERSION}.tar.gz && cd lua-${LUA_VERSION} || exit
make INSTALL_TOP=/opt/lua-${LUA_VERSION} linux install

lua_rc=$?
if [ ${lua_rc} != 0 ] ; then
   echo "building lua failed !" ; exit 1
fi

# get and build ha_proxy
mkdir -p /opt/haproxy && cd /opt/haproxy || exit
curl http://www.haproxy.org/download/${HAPROXY_MAJOR}/src/haproxy-${HAPROXY_MINOR}.tar.gz > haproxy-${HAPROXY_MINOR}.tar.gz
curl http://www.haproxy.org/download/${HAPROXY_MAJOR}/src/haproxy-${HAPROXY_MINOR}.tar.gz.sha256 > haproxy-${HAPROXY_MINOR}.tar.gz.sha256

cd /opt/haproxy && tar xvf haproxy-${HAPROXY_MINOR}.tar.gz
cd /opt/haproxy/haproxy-${HAPROXY_MINOR} || exit
make USE_NS=1 \
    USE_TFO=1 \
    USE_OPENSSL=1 \
    USE_ZLIB=1 \
    USE_LUA=1 \
    USE_PCRE=1 \
    USE_SYSTEMD=1 \
    USE_LIBCRYPT=1 \
    USE_THREAD=1 \
    TARGET=linux-glibc \
    LUA_INC=/opt/lua-${LUA_VERSION}/include \
    LUA_LIB=/opt/lua-${LUA_VERSION}/lib

make PREFIX=/opt/haproxy-${HAPROXY_MINOR} install

# move the build binary to the return directory
if [ ! -d ${RETURN_DIR}  ] ; then
   mkdir -p -- "${RETURN_DIR}"
fi

# copying the created binary to the return directory
if [ $(file -b --mime-type /opt/haproxy/haproxy-${HAPROXY_MINOR}/haproxy | sed 's|/.*||') == application ] ; then
   cp /opt/haproxy/haproxy-${HAPROXY_MINOR}/haproxy "${RETURN_DIR}"/
else
   exit 1
fi

exit 0

求排查该问题的线索。


排查线索
  • 检查容器资源限制:Dockerfile运行容器时,默认内存、CPU限制可能比交互式exec场景更严格,HAProxy编译阶段资源消耗较高,容易因资源不足崩溃。可通过--memory、--cpus参数调高限制后测试:
    podman run --memory=2g --cpus=2 ...
    
  • 获取完整崩溃日志:运行容器时不使用-d参数,实时查看标准输出/错误;或用podman logs <容器名>查看历史日志,定位编译过程中具体哪一步出错(如依赖缺失、编译参数问题)。
  • 验证脚本执行权限:Dockerfile中COPY脚本后未添加可执行权限,ENTRYPOINT直接执行脚本会失败(交互式用bash调用不受影响)。可在Dockerfile中添加:
    RUN chmod +x /usr/local/bin/make_ha_proxy.sh
    
  • 确认挂载目录配置:Dockerfile运行容器时是否挂载了./return目录?若未挂载,脚本最后复制二进制文件的步骤会失败,虽你称是构建阶段崩溃,但也可能引发后续逻辑异常。另外可检查挂载目录的权限是否正常。
  • 对比两种运行环境差异:交互式exec与ENTRYPOINT直接运行的环境变量、系统状态可能不同。可在脚本开头添加env命令,分别输出两种方式下的环境变量进行对比;或在HAProxy编译前,打印当前工作目录、依赖库路径等信息,确认是否一致。
  • 添加包校验步骤:脚本仅下载了HAProxy的SHA256校验文件但未执行校验,Dockerfile运行时可能因网络问题导致包损坏,引发编译失败。可在脚本中添加校验逻辑:
    cd /opt/haproxy
    sha256sum -c haproxy-${HAPROXY_MINOR}.tar.gz.sha256
    if [ $? -ne 0 ]; then
        echo "HAProxy包校验失败"
        exit 1
    fi
    
  • 排查systemd依赖影响:编译HAProxy时启用了USE_SYSTEMD=1,但容器默认可能缺少完整的systemd环境。可尝试暂时移除该参数,观察是否仍崩溃,以此排除systemd相关问题。

内容的提问来源于stack exchange,提问作者vrms

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.11 23:09:58