Docker运行IIS Windows容器启动失败 报PowerShell解析错误
Windows容器IIS站点启动报错修复
问题场景
尝试使用Docker Desktop在Windows容器中运行遗留.NET应用,使用的Dockerfile内容如下:
FROM mcr.microsoft.com/windows/servercore:ltsc2019 SHELL ["powershell", "-Command", "$ErrorActionPreference = 'Stop';"] RUN dism.exe /online /enable-feature /all /featurename:iis-webserver /NoRestart #Configure IIS RUN Import-Module WebAdministration;New-Item –Path IIS:\AppPools\CustomApppool RUN C:\windows\system32\inetsrv\appcmd.exe set apppool /apppool.name:CustomApppool /processModel.identityType:SpecificUser /processModel.username:us\user1 /processModel.password:P@@Ss RUN Install-WindowsFeature Web-Windows-Auth; RUN Install-WindowsFeature Web-IP-Security; RUN Install-WindowsFeature NET-WCF-HTTP-Activation45; RUN Install-WindowsFeature Web-Dyn-Compression; RUN Install-WindowsFeature Web-Scripting-Tools; RUN Install-WindowsFeature Web-AppInit; RUN Install-WindowsFeature Web-Http-Redirect; RUN Install-WindowsFeature Web-WebSockets; # Update permissions on website folder RUN icacls 'c:\inetpub\wwwroot' /Grant 'IUSR:(OI)(CI)(RX)' RUN icacls 'c:\inetpub\wwwroot' /Grant 'IIS AppPool\DefaultAppPool:(OI)(CI)(RX)' RUN icacls 'c:\inetpub\wwwroot' /Grant 'IIS AppPool\CustomApppool:(OI)(CI)(RX)' #Copy website files from App host folder to container wwwroot folder COPY Admin/ "c:/inetpub/wwwroot/Admin" COPY Sade/ "c:/inetpub/wwwroot/Sade" COPY Rater/ "c:/inetpub/wwwroot/Rater" #Copy Service Monitor file COPY ServiceMonitor.exe C:/ RUN New-WebApplication -Name Admin -Site 'Default Web Site' -PhysicalPath C:\inetpub\wwwroot\Admin -ApplicationPool CustomApppool; RUN New-WebApplication -Name Sade -Site 'Default Web Site' -PhysicalPath C:\inetpub\wwwroot\Sade -ApplicationPool CustomApppool; RUN New-WebApplication -Name Rater -Site 'Default Web Site' -PhysicalPath C:\inetpub\wwwroot\Rater -ApplicationPool CustomApppool; #Authentication Settings # Enable Directory browsing RUN C:\Windows\system32\inetsrv\appcmd.exe set config 'Default Web Site' /section:system.webServer/directoryBrowse /enabled:'True' # Enable anonymous authentication RUN Set-WebConfigurationProperty -Filter '/system.webServer/security/authentication/anonymousAuthentication' -Location 'Default Web Site' -Name enabled -Value True; # Enable basic authentication #RUN Set-WebConfigurationProperty -Filter '/system.webServer/security/authentication/basicAuthentication' -Location 'Default Web Site' -Name enabled -Value True; # Enable Windows authentication RUN Set-WebConfigurationProperty -Filter '/system.webServer/security/authentication/windowsAuthentication' -Location 'Default Web Site' -Name Enabled -Value False; RUN Restart-Service W3SVC EXPOSE 80 ENTRYPOINT ['C:\ServiceMonitor.exe','w3svc']
执行docker build -t demo/site命令可成功构建镜像,但执行docker run -p 8000:80 demo/site:latest命令启动容器时,抛出如下错误:
At line:1 char:35 + $ErrorActionPreference = 'Stop'; ['C:\ServiceMonitor.exe','w3svc'] + ~ Missing type name after '['. At line:1 char:58 + $ErrorActionPreference = 'Stop'; ['C:\ServiceMonitor.exe','w3svc'] + ~ Missing argument in parameter list. + CategoryInfo : ParserError: (:) [], ParentContainsErrorRecordException + FullyQualifiedErrorId : MissingTypename
故障根因
报错由ENTRYPOINT指令的写法错误导致:
- Dockerfile中
ENTRYPOINT、CMD、RUN的exec执行格式要求必须使用双引号包裹参数,本质是标准JSON数组结构,单引号不符合语法规范。 - 当前配置中
ENTRYPOINT使用了单引号,Docker无法将其识别为合法的exec格式指令,会自动将整行内容传入之前通过SHELL指定的PowerShell环境执行。PowerShell中[是类型转换语法的起始标识,直接传入['C:\ServiceMonitor.exe','w3svc']会被判定为语法错误,最终抛出类型名缺失的报错。
修复步骤
- 修正Dockerfile中ENTRYPOINT的写法
将最后一行的ENTRYPOINT替换为符合规范的格式,注意路径中的反斜杠需要转义:
ENTRYPOINT ["C:\\ServiceMonitor.exe", "w3svc"]
- 补全构建命令的上下文参数
原构建命令缺少构建上下文路径,建议使用完整命令构建,避免文件读取异常:
docker build -t demo/site .
- 重新构建并启动容器
依次执行以下命令重新生成镜像、启动容器:
# 重新构建镜像 docker build -t demo/site . # 后台启动容器,映射本地8000端口到容器80端口 docker run -d -p 8000:80 demo/site:latest
等待2-3秒待IIS服务完成初始化后,即可通过http://localhost:8000访问部署的网站。
内容的提问来源于stack exchange,提问作者aven
相关产品推荐
相关产品推荐

