如何列出Rancher启动容器在内部网络暴露的端口?
Great question! You absolutely don’t need the Rancher CLI to get this info—native Docker commands work perfectly here, since Rancher builds on top of Docker and stores all container metadata in Docker itself. Let’s walk through how to do this:
1. Check exposed ports for a single Rancher container
The docker container ls command doesn’t show these ports because Rancher doesn’t map them to the host by default (no -p flag used). But the container’s internally exposed ports (from its Dockerfile or startup config) are still stored in Docker’s metadata.
Use docker inspect to pull this data directly:
- To get a raw list of exposed ports:
docker inspect --format '{{.Config.ExposedPorts}}' <container-id-or-name> - For a cleaner, human-readable list:
docker inspect --format '{{range $p, $conf := .Config.ExposedPorts}}- {{$p}}{{end}}' <container-id-or-name>
This will show every port the container exposes within Rancher’s internal networks.
2. Batch-check ports for all Rancher-managed containers
Rancher adds unique labels to containers it manages, so we can filter for those first. Run this loop to list all Rancher containers and their exposed ports:
for container in $(docker ps -q --filter "label=io.rancher.container.created.by"); do echo "### Container: $(docker inspect --format '{{.Name}}' $container | sed 's/^\///')" docker inspect --format '{{range $p, $conf := .Config.ExposedPorts}}- {{$p}}{{end}}' $container echo "" done
This will iterate over every container created by Rancher, print its name, then list each exposed port.
3. Why docker container ls doesn’t show these ports
Just to clarify: The Ports column in docker container ls only shows ports that are mapped to the host (via -p or -P). Since Rancher keeps containers in internal networks by default, there are no host mappings—hence the empty column. But the container’s own exposed ports are still tracked by Docker.
4. Fallback if label filtering doesn’t work
If some Rancher containers don’t have the expected labels, you can identify them by their attached network. Rancher typically creates custom networks (often named with a cattle- prefix or your project name). List all networks with:
docker network ls
Then inspect the Rancher network to see which containers are attached:
docker network inspect <rancher-network-name>
Grab the container IDs from the Containers section, then use the docker inspect commands from step 1 to check their ports.
内容的提问来源于stack exchange,提问作者WeSee

