Docker容器iptables权限拒绝及端口无法访问问题求助
Docker容器后端服务端口无法访问求助
容器部署配置(docker-compose.yml)
test: image: captainteemo/aips:1.0 container_name: test hostname: test volumes: - /home/{{.Node.Hostname}}/share/hosts:/etc/hosts - /home/{{.Node.Hostname}}/share/java-1.8.0-openjdk-1.8.0.312.b07-1.el7_9.x86_64:/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.312.b07-1.el7_9.x86_64 environment: - LC_ALL=C.UTF-8 - LANG=C.UTF-8 - JAVA_HOME=/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.312.b07-1.el7_9.x86_64 privileged: true cap_add: - NET_ADMIN tty: true command: /sbin/init ports: - 8128:8128 deploy: placement: constraints: - node.hostname == user1
问题详情
容器绑定8128端口供后端服务访问,但用uvicorn启动服务后无法正常访问,执行netstat看不到8128端口处于监听状态。安装iptables包后,执行以下命令尝试开放端口:
iptables -I INPUT 1-ptcp --dport 8128-j ACCEPT
出现错误提示:
iptables v1.6.1: can't initialize iptables table `filter': Permission denied (you must be root) Perhaps iptables or your kernel needs to be upgraded.
搜索相关解决方案均无效,特此求助。
补充信息
- 服务启动命令:
uvicorn main:app --reload --host=0.0.0.0 --port=8128
- 执行
netstat的结果:
Active Internet connections (only servers) Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name tcp 0 0 127.0.0.11:33727 0.0.0.0:* LISTEN -
- 不同节点启动服务的差异:
- 在user1节点启动时,输出以下信息后进程卡住:
INFO: Will watch for changes in these directories: ['/home/zioz/server_place/test_web'] INFO: Uvicorn running on 0.0.0.0:8128 (Press CTRL+C to quit) INFO: Started reloader process [531] using StatReload- 在其他(leader)节点启动时,输出完整日志且服务运行正常:
INFO: Will watch for changes in these directories: ['/home/zioz/server_place/test_web'] INFO: Uvicorn running on 0.0.0.0:8128 (Press CTRL+C to quit) INFO: Started reloader process [531] using StatReload INFO: Started server process [429] INFO: Waiting for application startup. INFO: Application startup complete.
内容的提问来源于stack exchange,提问作者SecY
相关产品推荐
相关产品推荐

