GitLab共享Runner构建Docker镜像失败:无法链接容器
GitLab共享Runner执行Docker构建任务失败原因分析
问题现象
Docker构建任务使用GitLab官方共享Runner时持续失败,报错信息如下:
ERROR: Job failed (system failure): prepare environment: Error response from daemon: Cannot link to a non running container: /runner-3fjcetbw-project-36861-concurrent-0-8c1f412098c40e0b-docker-0 AS /runner-3fjcetbw-project-36861-concurrent-0-8c1f412098c40e0b-predefined-0/docker (exec.go:73:0s). Check docs.gitlab.com/runner/shells/index.html#shell-profile-loading for more information
但使用调整配置后的私有Runner可正常运行。
相关配置
.gitlab-ci.yml内容
stages: - test - build variables: INLINE_GLOBAL_VARIABLE: "I'm an inline variable set at the global level of the CI/CD configuration file" test job: stage: test script: - echo "I am a unit test!" build job: stage: build script: - echo "I am a build image!" environment echoes: stage: build script: - echo "Who am I running as..." - whoami - echo "Where am I..." - pwd - ls -al - echo "Here's what is available in our environment..." - env environment variables: stage: build variables: INLINE_LOCAL_VARIABLE: "I'm an inline variable set at the job level of the CI/CD configuration file" script: - echo "Do a test here" - echo "Here are some default, global, & local variables..." - echo $CI_COMMIT_SHORT_SHA - echo $group_level_variable - echo $project_level_variable - echo $INLINE_GLOBAL_VARIABLE - echo $INLINE_LOCAL_VARIABLE build image: stage: build image: docker:18 services: - docker:18-dind variables: IMAGE: $CI_REGISTRY_IMAGE/$CI_COMMIT_REF_SLUG:$CI_COMMIT_SHA script: - echo $IMAGE - docker login -u $CI_REGISTRY_USER -p $CI_REGISTRY_PASSWORD $CI_REGISTRY - docker build -t $IMAGE . - docker push $IMAGE
私有Runner有效配置(config.toml)
concurrent = 1 check_interval = 0 shutdown_timeout = 0 [session_server] session_timeout = 1800 [[runners]] name = "AMD-PC" url = "https://spt.gitlabtraining.cloud/" id = 4316 token = "xxxxxxxxxxxxxxxxx" token_obtained_at = 2023-03-04T04:09:18Z token_expires_at = 0001-01-01T00:00:00Z executor = "docker" [runners.cache] MaxUploadedArchiveSize = 0 [runners.docker] tls_verify = false image = "docker" privileged = true disable_entrypoint_overwrite = false oom_kill_disable = false disable_cache = false volumes = ["/cache", "/certs/client"] shm_size = 0
私有Runner调整前无效配置
privileged = false volumes = ["/cache"]
失败原因
GitLab共享Runner无法运行该Docker构建任务的核心原因是共享Runner未启用privileged模式,且缺少Docker-in-Docker(DinD)运行所需的证书卷配置:
privileged = true的必要性:DinD模式需要Docker容器拥有特权权限,才能在容器内部创建并运行嵌套的Docker守护进程。共享Runner默认不会开启特权模式,这会导致docker:18-dind服务容器无法正常启动,进而出现“无法链接到非运行容器”的报错。- 证书卷
/certs/client的必要性:DinD模式下,客户端容器(docker:18)需要通过证书与守护进程容器(docker:18-dind)建立TLS连接。共享Runner的默认配置中没有挂载该证书卷,会导致客户端无法与Docker守护进程通信,间接引发容器链接失败。
调整后的私有Runner同时满足了这两个条件:开启特权模式并挂载了证书卷,因此任务可以正常执行。
内容的提问来源于stack exchange,提问作者Dilep Dev
相关产品推荐
相关产品推荐

