Docker容器停止重启后端口转发失效,需重装才能恢复?
Docker端口转发在容器重启后失效(Ubuntu 18.04 + Docker 20.10.17)
问题现象
在Ubuntu 18.04上使用官方文档安装的Docker 20.10.17时,出现以下问题:
- 容器停止并重启后,端口转发功能完全失效,必须重装Docker才能恢复正常
- 首次创建并运行PostgreSQL 13容器时,可正常通过psql连接;但用Ctrl+C停止容器后,再次运行相同命令启动容器,就无法连接,报错"server closed the connection unexpectedly"
- 该问题并非PostgreSQL容器独有,所有容器的端口转发均受影响,比如运行
docker run -p 9999:80 httpd后,执行curl localhost:9999返回curl: (56) Recv failure: Connection reset by peer
已完成的排查操作
1. 容器创建命令
创建PostgreSQL容器的命令:
docker run -it \ -e POSTGRES_USER="root" \ -e POSTGRES_PASSWORD="root" \ -e POSTGRES_DB="ny_taxi" \ -v /my/absolute/path/to/my/local/folder/ny_taxi_postgres_data:/var/lib/postgresql/data:rw \ -p 5432:5432 \ postgres:13
2. 连接错误信息
执行psql连接命令后的报错:
➜ ~ psql -h localhost -p 5432 -U root -W Password for user root: psql: connection to server at "localhost" (127.0.0.1), port 5432 failed: server closed the connection unexpectedly This probably means the server terminated abnormally before or while processing the request.
- 尝试替换
localhost为0.0.0.0、使用本地pgadmin4连接均失败 - 尝试用错误的用户名/密码连接,容器日志无任何变化,怀疑是Docker端口转发层面的问题
3. 本地服务与端口占用检查
- 本地未运行PostgreSQL服务:
➜ ~ systemctl status postgresql Unit postgresql.service could not be found. ➜ ~ service postgresql status Unit postgresql.service could not be found.
- 端口5432仅被docker-proxy进程占用:
➜ sudo lsof -i -P -n | grep LISTEN ... docker-pr 5125 root 4u IPv4 3785093 0t0 TCP *:5432 (LISTEN) docker-pr 5132 root 4u IPv6 3778439 0t0 TCP *:5432 (LISTEN) ➜ sudo netstat -tulpen | grep 5432 tcp 0 0 0.0.0.0:5432 0.0.0.0:* LISTEN 0 4897282 15384/docker-proxy tcp6 0 0 :::5432 :::* LISTEN 0 4897287 15391/docker-proxy
4. 容器状态与日志
- 容器处于正常运行状态:
➜ docker container ls CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES 033699b59c10 postgres:13 "docker-entrypoint.s…" 3 hours ago Up 3 hours 0.0.0.0:5432->5432/tcp, :::5432->5432/tcp lucid_mcclintock
- 容器日志显示PostgreSQL已准备好接受连接:
➜ docker container logs lucid_mcclintock PostgreSQL Database directory appears to contain a database; Skipping initialization 2022-08-16 20:51:39.219 UTC [1] LOG: starting PostgreSQL 13.8 (Debian 13.8-1.pgdg110+1) on x86_64-pc-linux-gnu, compiled by gcc (Debian 10.2.1-6) 10.2.1 20210110, 64-bit 2022-08-16 20:51:39.219 UTC [1] LOG: listening on IPv4 address "0.0.0.0", port 5432 2022-08-16 20:51:39.219 UTC [1] LOG: listening on IPv6 address "::", port 5432 2022-08-16 20:51:39.231 UTC [1] LOG: listening on Unix socket "/var/run/postgresql/.s.PGSQL.5432" 2022-08-16 20:51:39.249 UTC [26] LOG: database system was shut down at 2022-08-16 20:51:34 UTC 2022-08-16 20:51:39.261 UTC [1] LOG: database system is ready to accept connections
5. Docker与网络配置检查
- Docker组配置正常,当前用户已加入docker组:
➜ cat /etc/group | grep docker docker:x:999:myusername
- Docker版本信息:
➜ docker version Client: Docker Engine - Community Version: 20.10.17 API version: 1.41 Go version: go1.17.11 Git commit: 100c701 Built: Mon Jun 6 23:02:56 2022 OS/Arch: linux/amd64 Context: default Experimental: true
- IPTables规则:
➜ sudo iptables --list Chain INPUT (policy ACCEPT) target prot opt source destination Chain FORWARD (policy DROP) target prot opt source destination DOCKER-USER all -- anywhere anywhere DOCKER-ISOLATION-STAGE-1 all -- anywhere anywhere ACCEPT all -- anywhere anywhere ctstate RELATED,ESTABLISHED DOCKER all -- anywhere anywhere ACCEPT all -- anywhere anywhere ACCEPT all -- anywhere anywhere Chain OUTPUT (policy ACCEPT) target prot opt source destination Chain DOCKER (1 references) target prot opt source destination ACCEPT tcp -- anywhere 172.17.0.2 tcp dpt:postgresql Chain DOCKER-ISOLATION-STAGE-1 (1 references) target prot opt source destination DOCKER-ISOLATION-STAGE-2 all -- anywhere anywhere RETURN all -- anywhere anywhere Chain DOCKER-ISOLATION-STAGE-2 (1 references) target prot opt source destination DROP all -- anywhere anywhere RETURN all -- anywhere anywhere Chain DOCKER-USER (1 references) target prot opt source destination RETURN all -- anywhere anywhere
- Docker桥接网络中仅存在该PostgreSQL容器,容器IP为172.17.0.2
求助内容
- 请提供问题排查方向或可能的原因分析
- 告知还需要补充哪些诊断信息
内容的提问来源于stack exchange,提问作者lampShadesDrifter
相关产品推荐
相关产品推荐

