从Docker Cloud部署Docker容器:新手部署实践及疑难求助
Hey there! Let's walk through how to get your Docker Cloud-hosted images deployed onto your AWS EC2 Amazon Linux instance, plus some tailored best practices that'll help you avoid headaches with that t2.micro's limited memory.
Before you can pull images from Docker Cloud, you need to log in to your account on the EC2 server. Run this command in your SSH session:
docker login
When prompted, enter your Docker Cloud username and password. That's it—your EC2 Docker client can now access your private images.
Next, grab the images you pushed earlier. Make sure to use the full image reference (including your Docker Cloud username and a specific tag—never rely on latest alone, it's a recipe for version confusion):
docker pull your-docker-cloud-username/your-image-name:v1.0.0
Replace your-docker-cloud-username, your-image-name, and v1.0.0 with your actual details.
Option A: Use docker run (for simple setups)
If you're running a single container, use the docker run command with your pulled image. For example:
docker run -d --name your-container-name -p 80:80 your-docker-cloud-username/your-image-name:v1.0.0
-druns the container in detached mode (background)--namegives it a friendly name for easy management-pmaps your EC2 instance's port 80 to the container's port 80 (adjust ports as needed)
Option B: Use docker-compose (for multi-container apps)
Since you already use docker-compose.yml locally, this is probably your go-to. Here's what to do:
- Copy your local
docker-compose.ymlfile to the EC2 instance (usescpor a terminal SCP tool):scp /path/to/your/docker-compose.yml ec2-user@your-ec2-public-ip:/home/ec2-user/ - SSH into EC2, navigate to the directory with the file, and update the
imagefield in each service to point to your Docker Cloud image (e.g.,image: your-docker-cloud-username/your-image-name:v1.0.0) - Start the containers with:
docker-compose up -d
That t2.micro only has 1GB of RAM—here's how to keep it from choking:
- Enable swap space: This gives Docker a safety net when memory runs low. Run these commands:
sudo fallocate -l 2G /swapfile sudo chmod 600 /swapfile sudo mkswap /swapfile sudo swapon /swapfile # Make swap permanent on reboot echo '/swapfile none swap sw 0 0' | sudo tee -a /etc/fstab - Clean up unused resources regularly: Free up space and memory by pruning old images, containers, and volumes:
(Thedocker system prune -a -f --volumes-fflag skips confirmation—use it only if you're sure you don't need those resources) - Limit container memory: Prevent a single container from hogging all RAM. In
docker-compose.yml, add this to each service:
Or withservices: your-service: image: ... mem_limit: 512m # Restrict to 512MB of RAMdocker run:--memory 512m
- Tag images properly: Use semantic versions (v1.0.0), Git commit hashes, or build IDs instead of
latest. This lets you roll back to a known good version if something breaks. - Optimize image size: Use a
.dockerignorefile in your local build context to exclude unnecessary files (likenode_modules,.git, or log files). Smaller images push/pull faster and use less storage on EC2. - Manage logs effectively: On EC2, configure Docker to limit log file sizes so they don't fill up your disk. Add this to your
docker-compose.ymlservices:logging: driver: "json-file" options: max-size: "10m" max-file: "3" - Run containers as non-root users: In your Dockerfile, create a regular user and switch to it before running your app. This reduces the risk of privilege escalation if a container is compromised:
RUN useradd -m appuser USER appuser - Automate updates carefully: Tools like Watchtower can automatically pull new images and restart containers, but test updates in a staging environment first before enabling this in production.
- Backup persistent data: If your app uses volumes to store data, regularly back up those volumes to AWS S3. You can use
docker run --rm -v your-volume:/data -v $(pwd):/backup busybox tar czf /backup/volume-backup.tar.gz /datato create a backup archive.
内容的提问来源于stack exchange,提问作者duhaime

