You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker Swarm集群GitLab/Travis自动化部署技术咨询

Getting GitLab/Travis to Deploy to Your Docker Swarm Cluster

Hey there! Sounds like you've already checked off the big initial steps for Swarm: got your manager node initialized with docker swarm init, spun up the Registry as a service, and can push images from a non-Swarm server. Since you're hitting a snag with the CI/CD deployment part, let's break down the most common hurdles and fixes to get you up and running.

1. Ensure All Swarm Nodes Can Access Your Private Registry

Even if your CI server can push images, your Swarm workers (and manager) need to pull them to run the services. Here's what to check:

  • Use an overlay network: When you deployed the Registry service, make sure it's attached to an overlay network (not the default bridge) so all Swarm nodes can reach it. You can create one with docker network create --driver overlay swarm-net and attach the Registry to it when deploying.
  • Insecure Registry setup (if no HTTPS): If you're not using a trusted SSL cert for your Registry, every Swarm node needs to allow insecure registries. Edit /etc/docker/daemon.json on each node to add:
    {
      "insecure-registries": ["<registry-ip-or-host>:<port>"]
    }
    
    Then restart Docker with systemctl restart docker (on Linux) or the equivalent for your OS.

2. Give Your CI Server Access to Swarm & Registry

Your CI runner needs two key things: permission to push images to the Registry, and permission to send deployment commands to the Swarm manager.

  • Registry auth: You probably already do this, but double-check your CI script runs docker login <registry-url> with valid credentials before docker push. Store those credentials as secret variables in GitLab/Travis so they're not hardcoded.
  • Swarm access: The easiest way (for testing) is to expose the Swarm manager's Docker API over TLS. Generate client certificates on the manager, then pass these env vars to your CI runner:
    • DOCKER_TLS_VERIFY=1
    • DOCKER_CERT_PATH=/path/to/your/certs
    • DOCKER_HOST=tcp://<swarm-manager-ip>:2376
      For production, avoid exposing the API directly if possible—consider using a Swarm service account or a tool like Portainer for more controlled access.

3. Tweak Your Compose File for Swarm

Regular docker-compose.yml files aren't fully compatible with Swarm—you need to add a deploy section to each service. Here's a quick example:

version: "3.8"
services:
  my-app:
    image: <registry-url>/my-app:${CI_COMMIT_SHA} # Use a unique tag (like Git SHA) instead of latest
    deploy:
      replicas: 2 # Number of instances to run
      restart_policy:
        condition: on-failure # Restart if the service crashes
      resources:
        limits:
          cpus: "0.5" # Limit CPU usage per instance
          memory: 512M # Limit memory per instance
    networks:
      - swarm-net # Attach to the overlay network we created earlier

networks:
  swarm-net:
    external: true

Note: Use a unique image tag (like the Git commit SHA) instead of latest—this avoids caching issues and lets you track exactly which version is deployed.

4. Deploy with docker stack deploy (Not docker-compose up)

When deploying to Swarm, forget docker-compose up—use docker stack deploy instead. Your CI script should run something like:

docker stack deploy --compose-file docker-compose.yml my-app-stack

This will create a stack (a group of services) in your Swarm cluster. You can check the status with docker stack ps my-app-stack if something goes wrong.

5. GitLab CI Specific Tips

If you're using GitLab CI:

  • Use the docker:latest image with the docker:dind (Docker-in-Docker) service to get a working Docker environment in your runner.
  • Store your Swarm TLS certs as file variables in GitLab, so they're copied to the runner during the job.
  • Example .gitlab-ci.yml snippet for deployment:
stages:
  - build
  - deploy

build:
  stage: build
  image: docker:latest
  services:
    - docker:dind
  script:
    - docker login <registry-url> -u $REGISTRY_USER -p $REGISTRY_PASS
    - docker build -t <registry-url>/my-app:$CI_COMMIT_SHA .
    - docker push <registry-url>/my-app:$CI_COMMIT_SHA

deploy:
  stage: deploy
  image: docker:latest
  services:
    - docker:dind
  variables:
    DOCKER_TLS_VERIFY: "1"
    DOCKER_CERT_PATH: "./certs"
    DOCKER_HOST: "tcp://<swarm-manager-ip>:2376"
  before_script:
    - mkdir -p certs
    - echo "$SWARM_CA_CERT" > certs/ca.pem
    - echo "$SWARM_CLIENT_CERT" > certs/cert.pem
    - echo "$SWARM_CLIENT_KEY" > certs/key.pem
  script:
    - docker stack deploy --compose-file docker-compose.yml my-app-stack

Store REGISTRY_USER, REGISTRY_PASS, SWARM_CA_CERT, SWARM_CLIENT_CERT, and SWARM_CLIENT_KEY as masked, protected variables in GitLab.

6. Travis CI Specific Tips

For Travis CI:

  • Enable Docker support in your .travis.yml with services: [docker].
  • Encrypt your credentials using travis encrypt so they're not exposed in your repo.
  • Example deployment step:
services:
  - docker

before_install:
  - docker login <registry-url> -u $REGISTRY_USER -p $REGISTRY_PASS

script:
  - docker build -t <registry-url>/my-app:$TRAVIS_COMMIT .
  - docker push <registry-url>/my-app:$TRAVIS_COMMIT

deploy:
  provider: script
  script: |
    export DOCKER_TLS_VERIFY=1
    export DOCKER_CERT_PATH=./certs
    export DOCKER_HOST=tcp://<swarm-manager-ip>:2376
    mkdir -p certs
    echo "$SWARM_CA_CERT" > certs/ca.pem
    echo "$SWARM_CLIENT_CERT" > certs/cert.pem
    echo "$SWARM_CLIENT_KEY" > certs/key.pem
    docker stack deploy --compose-file docker-compose.yml my-app-stack
  on:
    branch: main

7. Debugging Common Issues

  • Swarm can't pull images: Check the service logs with docker service logs my-app-stack_my-app to see if there's an auth error or image not found. Make sure the image tag matches exactly what you pushed.
  • CI can't connect to Swarm: Test the connection from your CI server manually with docker -H tcp://<manager-ip>:2376 --tlsverify --tlscacert=ca.pem --tlscert=cert.pem --tlskey=key.pem info—if this fails, your TLS certs are wrong or the manager's firewall is blocking port 2376.
  • Deployments are stuck: Use docker stack ps my-app-stack to see the state of each task. If it says "Pending" or "Failed", hover over the task (or check the logs) to see why—often it's a network issue or resource limit.

If you hit a specific error message or have a more niche problem, drop it here and I'll help you dig into it!

内容的提问来源于stack exchange,提问作者Federico Bevione

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 07:47:02