多项目Docker-Compose共享MySQL实例及跨机迁移需求咨询
Hey there! Let's walk through how to share the MySQL container from your first project with the second one—covering both your current same-machine setup and the future cross-machine migration plan.
The key here is getting both Docker Compose projects on the same network so App-2's Tomcat can reach the MySQL container from the first project. Here's a step-by-step approach:
Step 1: Configure the First Project's Network
Modify your first project's docker-compose.yml to use a named, shared network instead of the default auto-generated one. This makes it easy for the second project to connect:
version: '3.8' services: mysql: image: mysql:8.0 environment: MYSQL_ROOT_PASSWORD: your_secure_root_pass MYSQL_DATABASE: app_shared_db MYSQL_USER: app_service_user MYSQL_PASSWORD: your_secure_app_pass volumes: - mysql_data:/var/lib/mysql # Persist database data networks: - shared_db_network tomcat-app1: image: tomcat:9-jdk11 ports: - "8080:8080" volumes: - ./app1-war:/usr/local/tomcat/webapps networks: - shared_db_network # Define a named external network networks: shared_db_network: name: shared_db_network driver: bridge volumes: mysql_data:
Step 2: Connect the Second Project to the Shared Network
Update your second project's docker-compose.yml to join the same shared network, and configure App-2 to point to the MySQL service by name (Docker's DNS will resolve this):
version: '3.8' services: tomcat-app2: image: tomcat:9-jdk11 ports: - "8081:8080" volumes: - ./app2-war:/usr/local/tomcat/webapps environment: # Use the MySQL service name as the host (works within the shared network) DB_HOST: mysql DB_PORT: 3306 DB_NAME: app_shared_db DB_USER: app_service_user DB_PASSWORD: your_secure_app_pass networks: - shared_db_network # Declare the network as external (already created by the first project) networks: shared_db_network: external: true
Critical Notes for Same-Machine Setup
- Database User Permissions: Make sure your MySQL user (
app_service_userin the example) is allowed to connect from within the network. Run these commands inside the MySQL container to fix permissions if needed:docker exec -it <your-mysql-container-name> mysql -u root -p # Inside MySQL shell: CREATE USER 'app_service_user'@'%' IDENTIFIED BY 'your_secure_app_pass'; GRANT ALL PRIVILEGES ON app_shared_db.* TO 'app_service_user'@'%'; FLUSH PRIVILEGES; - Avoid Exposing MySQL Port: You don't need to map MySQL's 3306 port to the host here—services on the same Docker network can communicate directly using service names.
When you move App-2's Tomcat to another machine, you'll need to make the MySQL container accessible over the network. Here's how to adjust things safely:
Step 1: Update the First Project's MySQL Configuration
Modify the first project's docker-compose.yml to expose MySQL's port (with security restrictions) and ensure remote connections are allowed:
services: mysql: image: mysql:8.0 environment: # Keep existing env vars MYSQL_ROOT_PASSWORD: your_secure_root_pass MYSQL_DATABASE: app_shared_db MYSQL_USER: app_service_user MYSQL_PASSWORD: your_secure_app_pass volumes: - mysql_data:/var/lib/mysql ports: # Restrict access to only the second machine's IP (replace with actual IP) - "192.168.1.100:3306:3306" networks: - shared_db_network # Optional: Add a command to enforce bind-address (Docker MySQL usually allows 0.0.0.0 by default) command: --bind-address=0.0.0.0
Step 2: Configure the Second Project for Remote Access
Update the second project's docker-compose.yml to point to the first machine's IP instead of the MySQL service name:
services: tomcat-app2: image: tomcat:9-jdk11 ports: - "8080:8080" volumes: - ./app2-war:/usr/local/tomcat/webapps environment: # Replace with the first machine's public/private IP DB_HOST: 192.168.1.100 DB_PORT: 3306 DB_NAME: app_shared_db DB_USER: app_service_user DB_PASSWORD: your_secure_app_pass # No need for the shared network anymore—we're using remote IP
Security Best Practices for Cross-Machine Setup
- Firewall Rules: On the first machine, configure your firewall (like
ufwor iptables) to only allow incoming 3306 connections from the second machine's IP. - Avoid Root User: Never use the MySQL root user for application connections—stick to the dedicated
app_service_user. - Encrypt Connections: Enable MySQL SSL to encrypt data between App-2 and the database. You can add SSL-related environment variables to the MySQL service and configure your Tomcat app to use SSL for DB connections.
- Use Private Networks: If possible, use a private local network or VPN between the two machines instead of public IPs.
- Backup Regularly: Always back up your MySQL data, especially before migrations. Run this command to create a backup:
docker exec <mysql-container-name> mysqldump -u app_service_user -p app_shared_db > app_db_backup.sql - Manage Secrets Safely: Don't hardcode passwords in
docker-compose.yml—use a.envfile (add it to.gitignore) or Docker Secrets for sensitive values.
内容的提问来源于stack exchange,提问作者InKi

