Docker构建时apt安装dnsutils成功,进入容器shell后工具缺失求助
问题:Docker镜像中nslookup命令不存在的原因及解决办法
你编写的Dockerfile如下:
#dockerfile FROM debian ENV DEBIAN_FRONTEND=noninteractive RUN apt update && apt install -y dnsutils && rm -rf /var/lib/apt/lists/* FROM php:7.0-apache WORKDIR /var/www/html COPY index.php index.php EXPOSE 80
执行构建命令sudo docker build -t lookup-demo .后显示成功,输出如下:
# docker build output sudo docker build -t lookup-demo . Sending build context to Docker daemon 3.584kB Step 1/7 : FROM debian latest: Pulling from library/debian d836772a1c1f: Pull complete Digest: sha256:2ce44bbc00a79113c296d9d25524e15d423b23303fdbbe20190d2f96e0aeb251 Status: Downloaded newer image for debian:latest ---> 123c2f3835fd Step 2/7 : ENV DEBIAN_FRONTEND=noninteractive ---> Running in c030e13e5c4d Removing intermediate container c030e13e5c4d ---> 64f8a1b2f607 Step 3/7 : RUN apt update && apt install -y dnsutils && rm -rf /var/lib/apt/lists/* ---> Running in 7b35c913afa7 WARNING: apt does not have a stable CLI interface. Use with caution in scripts. Get:1 http://deb.debian.org/debian bullseye InRelease [116 kB] Get:2 http://deb.debian.org/debian-security bullseye-security InRelease [44.1 kB] --SNIPPED-- Fetched 8550 kB in 6s (1486 kB/s) Reading package lists... Building dependency tree... Reading state information... All packages are up to date. WARNING: apt does not have a stable CLI interface. Use with caution in scripts. Reading package lists... Building dependency tree... Reading state information... The following additional packages will be installed: bind9-dnsutils bind9-host bind9-libs libbsd0 libedit2 libfstrm0 libicu67 libjson-c5 liblmdb0 libmaxminddb0 libmd0 libprotobuf-c1 libuv1 libxml2 Suggested packages: mmdb-bin The following NEW packages will be installed: bind9-dnsutils bind9-host bind9-libs dnsutils libbsd0 libedit2 libfstrm0 libicu67 libjson-c5 liblmdb0 libmaxminddb0 libmd0 libprotobuf-c1 libuv1 libxml2 0 upgraded, 15 newly installed, 0 to remove and 0 not upgraded. Need to get 12.2 MB of archives. After this operation, 42.3 MB of additional disk space will be used. Get:1 http://deb.debian.org/debian bullseye/main amd64 libfstrm0 amd64 0.6.0-1+b1 [21.5 kB] --SNIPPED-- ... Setting up bind9-dnsutils (1:9.16.27-1~deb11u1) ... Setting up dnsutils (1:9.16.27-1~deb11u1) ... Processing triggers for libc-bin (2.31-13+deb11u3) ... Removing intermediate container 7b35c913afa7 ---> e06841ed6429 Step 4/7 : FROM php:7.0-apache ---> aa67a9c9814f Step 5/7 : WORKDIR /var/www/html ---> Running in f23042e65327 Removing intermediate container f23042e65327 ---> 2d99a8d80b10 Step 6/7 : COPY index.php index.php ---> d7a6b1478f79 Step 7/7 : EXPOSE 80 ---> Running in 2b873b46e964 Removing intermediate container 2b873b46e964 ---> 5c8964ef0a4e Successfully built 5c8964ef0a4e Successfully tagged lookup-demo:latest
但运行容器并进入shell后,执行nslookup提示命令不存在:
# output from the shell sudo docker exec -it 1cd5f6b568cf bash root@1cd5f6b568cf:/var/www/html# nslookup bash: nslookup: command not found
原因
你使用了Docker多阶段构建,每个FROM指令都会启动一个全新的构建阶段,前一个阶段(debian镜像)中安装的dnsutils不会自动继承到后一个阶段(php:7.0-apache镜像)。最终生成的镜像只包含最后一个阶段的内容,所以nslookup命令不存在。
解决办法
方法1:直接在目标镜像阶段安装依赖
修改Dockerfile,将安装dnsutils的命令放到php:7.0-apache阶段中,这是最简单的方案:
#dockerfile FROM php:7.0-apache WORKDIR /var/www/html ENV DEBIAN_FRONTEND=noninteractive RUN apt update && apt install -y dnsutils && rm -rf /var/lib/apt/lists/* COPY index.php index.php EXPOSE 80
方法2:多阶段构建复制依赖(不推荐,复杂)
如果一定要保留多阶段结构,需要显式将debian阶段中dnsutils及其依赖文件复制到php阶段,但这种方式需要手动定位所有依赖路径,操作繁琐,不如直接在目标阶段安装高效。
重新构建镜像后,运行容器即可正常使用nslookup命令。
内容的提问来源于stack exchange,提问作者Pwn Bot
相关产品推荐
相关产品推荐

