You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Docker Swarm模式下运行DIND服务?所需--cap-add参数

Great question! Running Docker-in-Docker (DIND) in Docker Swarm without relying on the --privileged flag is totally feasible—you just need to add the right capability flags to mimic what --privileged provides. Let's break this down:

Required --cap-add Flags for DIND in Swarm

These core capabilities cover most of the system-level access Docker needs to run inside a Swarm service:

  • NET_ADMIN: Enables management of network interfaces (critical for Docker to create bridges, overlay networks, and handle routing).
  • NET_RAW: Allows raw socket access, which Docker uses for network operations like ICMP traffic and direct packet handling.
  • SYS_ADMIN: Essential for mounting filesystems (like the Docker graph driver's storage) and performing other system-level administrative tasks.
  • SYS_MODULE: Useful if you need to load kernel modules (e.g., for certain storage drivers); while less critical for modern setups, it adds compatibility.
  • IPC_LOCK: Helps manage shared memory and inter-process communication resources that Docker relies on internally.
Key Additional Configuration

Beyond capabilities, you'll want to add a tmpfs mount to /var/lib/docker—this avoids filesystem conflicts and improves performance for the nested Docker daemon:

--mount type=tmpfs,destination=/var/lib/docker
Complete Swarm Service Example

Here's a ready-to-use command to create a DIND service in Swarm with all the necessary flags:

docker service create \
  --name dind-swarm-node \
  --cap-add NET_ADMIN \
  --cap-add NET_RAW \
  --cap-add SYS_ADMIN \
  --cap-add SYS_MODULE \
  --cap-add IPC_LOCK \
  --mount type=tmpfs,destination=/var/lib/docker \
  docker:dind
Extra Tips for Smooth Operation
  • If you're using the default overlay2 storage driver, you might need to add --security-opt apparmor:unconfined to bypass AppArmor restrictions on some hosts.
  • Keep in mind this setup isn't a perfect 1:1 replacement for --privileged, but it's more than sufficient for most DIND use cases in Swarm (like CI/CD runners or isolated container testing).
  • Always test with your specific workload to ensure all operations work as expected—some niche use cases might require additional tweaks.

内容的提问来源于stack exchange,提问作者Vad1mo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 07:56:28