You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker macvlan配置:如何确定适配环境的subnet、gateway及parent参数

How to Determine Macvlan Parameters & Enable Cross-Host Container Access

Let’s walk through this step by step—macvlan networks can seem intimidating when you’re starting out, but once you know how to parse your host’s network output, it’s easy to get right.

1. Find the parent Parameter

The parent is the physical network interface on your host that connects to the local network you want your containers to join. Here’s how to track it down:

  • Run ip addr on Host A. Skip the loopback interface (lo) and look for the interface with a valid inet (IPv4) address attached to your local network.
    Example output snippet:
    2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000
        inet 192.168.1.10/24 brd 192.168.1.255 scope global dynamic eth0
    
  • The interface name here (eth0) is what you’ll use for the parent parameter.

2. Get subnet and gateway Values

These are pulled straight from your host’s active network configuration:

Subnet

  • From the ip addr output, take your host’s IP prefix. If your host has 192.168.1.10/24, the subnet is 192.168.1.0/24 (replace the host-specific portion with 0 while keeping the CIDR suffix).

Gateway

  • Run ip route on Host A and look for the default route line:
    default via 192.168.1.1 dev eth0 proto dhcp src 192.168.1.10 metric 100
    
  • The IP immediately after via (192.168.1.1) is your network gateway.

3. Create the Macvlan Network

Plug your gathered values into the Docker network create command:

docker network create -d macvlan \
  --subnet=192.168.1.0/24 \
  --gateway=192.168.1.1 \
  -o parent=eth0 \
  my-macvlan-net

When you launch a container on this network, it will receive an IP in the same subnet as your host, behaving like any other physical device on the local network.

4. Enable Host B to Access Host A’s Container

Macvlan containers are directly attached to the physical network, so Host B (on the same local subnet) can reach the container directly via its IP—but first, we need to fix a common quirk: by default, Host A can’t communicate with its own macvlan containers due to layer 2 isolation. Here’s how to resolve that and ensure full connectivity:

On Host A: Create a Macvlan Bridge Interface

This interface acts as a bridge between Host A and its macvlan containers:

  1. Create a macvlan subinterface tied to your parent interface:
    ip link add mac0 link eth0 type macvlan mode bridge
    
  2. Assign an unused IP from your subnet to this interface (make sure it doesn’t conflict with other devices):
    ip addr add 192.168.1.11/24 dev mac0
    
  3. Bring the interface online:
    ip link set mac0 up
    
  4. Add a route to direct macvlan subnet traffic through this interface:
    ip route add 192.168.1.0/24 dev mac0
    

On Host B: Access the Container

Simply ping or connect to the container’s IP address (you can retrieve this with docker inspect <container-name> | grep "IPAddress" on Host A). Since the container is on the same physical network as Host B, it will work just like connecting to any other device on the network.


内容的提问来源于stack exchange,提问作者ealeon

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 10:03:37