You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

跨主机连接两个Docker容器的可行方案咨询(已试Swarm/Weave未果)

Hey there! Sorry to hear you've hit snags with Docker Swarm and Weave when trying to connect your web container on Host A to the DB container on Host B. Let's break down some reliable, actionable solutions that should get things working:

1. Quick Fix: Direct Host IP + Port Mapping

If you need a fast, no-frills solution, this is the way to go—great for testing or small setups:

  • On Host B, start your DB container with a port mapped to Host B's internal or public IP (stick to internal if possible for security). For example, with PostgreSQL:
    docker run -d -p <HostB_INTERNAL_IP>:5432:5432 --name my-db -e POSTGRES_PASSWORD=yoursecurepassword postgres
    
  • On Host A, configure your web app to connect to <HostB_INTERNAL_IP>:5432 instead of a container name.
  • Critical Checks: Make sure Host A and Host B can reach each other over the network (test with ping <HostB_INTERNAL_IP>) and that your firewall/security group allows incoming traffic on the DB port (5432 in this example).
  • Pro Tip: Avoid exposing the DB port to the public internet if you can—use your internal network or a VPN for remote setups.
2. Fix Your Docker Swarm Overlay Network (Since You Tried This Already)

Chances are your earlier Swarm attempt failed due to missing port openings or incorrect network configuration. Here's the step-by-step correct setup:

  1. Initialize Swarm on Host A:
    docker swarm init --advertise-addr <HostA_INTERNAL_IP>
    
    Copy the docker swarm join command that's output—you'll need it for Host B.
  2. Join Host B to the Swarm:
    Run the copied join command on Host B (it'll look like this, with your unique token):
    docker swarm join --token SWMTKN-1-xxxxxx <HostA_INTERNAL_IP>:2377
    
  3. Create an Attachable Overlay Network:
    This lets standalone containers (not just Swarm services) connect to the network:
    docker network create --driver overlay --attachable cross-host-net
    
  4. Launch Containers on the Network:
    • On Host A: docker run -d --name my-web --network cross-host-net your-web-image
    • On Host B: docker run -d --name my-db --network cross-host-net your-db-image
  5. Test the Connection:
    Inside your web container, you can now connect to the DB using the container name my-db (Swarm's overlay network handles service discovery automatically).
  • Why You Might Have Failed Before: Ensure these ports are open on both hosts:
    • 2377 (Swarm management)
    • 7946 (node-to-node communication)
    • 4789 (overlay network data traffic)
3. Zero VPN Tools (Tailscale, WireGuard)

Perfect if you're working across cloud providers or remote machines without a dedicated internal network:

  • Install Tailscale (or WireGuard) on both Host A and Host B. Once logged in, both hosts will be part of a secure virtual network with unique internal IPs.
  • You can either:
    • Use the port mapping method above, but replace Host B's IP with its Tailscale virtual IP.
    • Or, for a cleaner setup, create a bridge network on each host and use Tailscale to forward the DB container's port to Host A (though port mapping is simpler for most cases).
  • The best part? No complex network config—Tailscale handles encryption and routing out of the box.
4. Service Discovery with Consul + Docker Connect

For larger, distributed systems where you need service discovery and encrypted connections:

  • Deploy a Consul agent on both Host A and Host B to form a small Consul cluster.
  • Configure Docker Connect to register your web and DB containers as services in Consul.
  • Your web container can then access the DB using its Consul service name, and Connect will automatically establish a secure, encrypted connection between the two containers across hosts.
  • This is overkill for simple setups, but ideal if you're scaling to more containers or hosts.

Quick Troubleshooting Tips

Before diving into any solution, confirm:

  • Host A can ping Host B and vice versa.
  • You can telnet to the DB port from Host A: telnet <HostB_IP> <DB_PORT>—if this fails, your firewall is blocking traffic.
  • Check container logs with docker logs my-web or docker logs my-db to see specific connection errors (e.g., "connection refused" vs "timeout").

内容的提问来源于stack exchange,提问作者Rakesh Sivagouni

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 06:23:35