Docker容器内查看主机iptables异常问题求助
问题:Docker容器内无法查看主机iptables规则(Ubuntu 22.04主机+≤20.04容器场景)
需要在Docker容器内以只读权限查看主机iptables规则,已配置--cap-add=NET_ADMIN并设置network=host,但容器内iptables显示为空,容器内添加规则也不影响主机,容器与主机的iptables规则完全不同。
主机执行命令输出
root@host:~# iptables -xnvL OUTPUT # Warning: iptables-legacy tables present, use iptables-legacy to see them Chain OUTPUT (policy ACCEPT 1104394 packets, 407916631 bytes) pkts bytes target prot opt in out source destination 16498 3125381 all -- * * 8.8.8.8 0.0.0.0/0 107211 59743643 all -- * * 192.168.0.1 0.0.0.0/0
容器内执行命令输出
root@host:~# docker exec ct_monitor_1 iptables -xnvL OUTPUT Chain OUTPUT (policy ACCEPT 33081662 packets, 12617923760 bytes) pkts bytes target prot opt in out source destination 206142 41989385 all -- * * 1.1.1.1 0.0.0.0/0 3686279 1919571839 all -- * * 172.0.0.1 0.0.0.0/0
(规则为示例,仅用于展示容器与主机iptables不同)
场景限定
该问题仅出现在Ubuntu 22.04主机搭配≤20.04版本Ubuntu容器的场景中。
主机环境信息
root@host:~# lsb_release -a No LSB modules are available. Distributor ID: Ubuntu Description: Ubuntu 22.04.1 LTS Release: 22.04 Codename: jammy root@zitz:~# iptables -nvL OUTPUT # Warning: iptables-legacy tables present, use iptables-legacy to see them Chain OUTPUT (policy ACCEPT 437K packets, 229M bytes) pkts bytes target prot opt in out source destination 285K 142M all -- * * 8.8.8.8 0.0.0.0/0 120K 83M all -- * * 192.168.0.1 0.0.0.0/0
正常示例(使用ubuntu:jammy-20221003容器)
root@zitz:~# docker run --rm -it --network=host --cap-add=NET_ADMIN ubuntu:jammy-20221003 bash root@zitz:/# apt -qq -y update && apt install -qq -y iptables root@zitz:/# iptables -nvL OUTPUT # Warning: iptables-legacy tables present, use iptables-legacy to see them Chain OUTPUT (policy ACCEPT 436K packets, 229M bytes) pkts bytes target prot opt in out source destination 285K 142M all -- * * 8.8.8.8 0.0.0.0/0 120K 82M all -- * * 192.168.0.1 0.0.0.0/0
异常示例(使用≤20.04版本Ubuntu容器)
root@zitz:~# docker run --rm -it --network=host --cap-add=NET_ADMIN ubuntu:focal bash root@zitz:/# apt -qq update && apt install -y -qqq iptables . . . root@zitz:/# iptables -nvL OUTPUT Chain OUTPUT (policy ACCEPT 148K packets, 53M bytes) pkts bytes target prot opt in out source destination
原因分析
Ubuntu 22.04默认采用iptables-nft(基于nftables的iptables兼容层),但主机中同时存在iptables-legacy规则;而≤20.04版本的Ubuntu容器默认使用iptables-legacy,当容器以host网络模式运行时,容器内的iptables-legacy无法读取主机上的iptables-nft规则表,因此显示为空。
解决方法
方法1:切换容器内iptables后端为nft
在容器内执行以下命令:
# 安装iptables-nft包 apt install -y iptables-nft # 设置默认iptables后端为nft update-alternatives --set iptables /usr/sbin/iptables-nft # 验证是否能查看主机规则 iptables -xnvL OUTPUT
方法2:直接使用iptables-legacy查看主机legacy规则
如果主机确实存在iptables-legacy规则,可在容器内直接执行:
iptables-legacy -xnvL OUTPUT
内容的提问来源于stack exchange,提问作者Roberto Iglesias
相关产品推荐
相关产品推荐

