Docker容器无法接收主机HTTP请求的排查求助
Docker容器无法接收主机HTTP请求的排查求助
我在Ubuntu 18.04服务器上用Docker部署API(容器基础镜像为Ubuntu 22.04),之前用完全相同的配置在另一台服务器部署时毫无问题。现在容器构建成功、日志也显示正常,但就是接收不到来自主机的HTTP请求(容器名demowebsiteapi,内部IP为172.17.0.2)。
以下是我做的测试情况:
curl 172.17.0.2:8001/test # => 请求超时 curl 127.0.0.1:8001/test # 返回404错误的HTML页面 # 进入容器内部测试 docker exec -it demowebsiteapi /bin/bash /home/demowebsite# wget -qO- localhost:8001/test > {"response":"ok"}
奇怪的是,主机上访问所有本地端口都会返回这个相同的404 HTML页面,我找不到这个响应对应的服务器配置文件:/etc/apache2/目录里只有一个javascript-common.conf文件,用sudo find / -type d -name '.htaccess'也没找到任何相关内容。
想请教大家:是什么导致容器接收不到HTTP请求?有没有什么系统交互或配置影响了容器的可访问性?有没有进一步排查或调试的建议?
Docker配置详情
Dockerfile示例
FROM ubuntu:22.04 ENV USER demowebsite ... COPY /docker-confs/nginx.conf /etc/nginx/conf.d/demowebsite.conf EXPOSE 8001 CMD export LC_ALL=C.UTF-8 && export LANG=C.UTF-8 && \ source venv/bin/activate && \ supervisord -c api/docker-confs/supervisord.conf
容器构建与启动脚本
docker build --rm -t demowebsiteapi . -f Dockerfile --build-arg USERID="$DEMO_UID"; docker rm demowebsiteapi docker run -d --name demowebsiteapi \ -v $DATA_FOLDER:/data/ -p 127.0.0.1:8001:8001 \ --restart unless-stopped --ipc=host demowebsiteapi
容器网络配置(docker inspect demowebsiteapi截取)
"NetworkSettings": { ... "Ports": { "8001/tcp": [ { "HostIp": "127.0.0.1", "HostPort": "8001" } ] }, "Networks": { "bridge": { ... "Gateway": "172.17.0.1", "IPAddress": "172.17.0.2", "IPPrefixLen": 16, "IPv6Gateway": "", "GlobalIPv6Address": "", "GlobalIPv6PrefixLen": 0, "MacAddress": "02:42:ac:11:00:02", "DriverOpts": null } } }
容器内重复进程问题
我发现容器里有重复的进程在运行:
$ ps aux | grep demowebsite userme 10534 0.0 0.0 28140 21484 ? S 13:53 0:00 /home/demowebsite/venv/bin/python3 /home/demowebsite/venv/bin/gunicorn --bind unix:/tmp/website.sock app.main:app --worker-connections 1001 --workers 4 userme 10563 0.5 0.2 3890376 381392 ? Sl 13:53 0:03 /home/demowebsite/venv/bin/python3 /home/demowebsite/venv/bin/gunicorn --bind unix:/tmp/website.sock app.main:app --worker-connections 1001 --workers 4 userme 10567 0.5 0.2 3890220 381952 ? Sl 13:53 0:03 /home/demowebsite/venv/bin/python3 /home/demowebsite/venv/bin/gunicorn --bind unix:/tmp/website.sock app.main:app --worker-connections 1001 --workers 4 userme 10538 0.0 0.0 104748 24676 ? Sl 13:53 0:00 /home/demowebsite/venv/bin/python3 /home/demowebsite/venv/bin/dramatiq app.main -p 1 -t 1 userme 10566 0.6 0.2 4186140 379588 ? Sl 13:53 0:04 /home/demowebsite/venv/bin/python3 /home/demowebsite/venv/bin/dramatiq app.main -p 1 -t 1 userme 10800 0.0 0.0 31188 18580 ? S 13:54 0:00 /home/demowebsite/venv/bin/python3 /home/demowebsite/venv/bin/dramatiq app.main -p 1 -t 1
主机网络设置
$ sudo ufw status Status: inactive $ sudo ufw app list Available applications: CUPS OpenSSH $ netstat -tuln Active Internet connections (only servers) Proto Recv-Q Send-Q Local Address Foreign Address State tcp 0 0 127.0.0.1:8001 0.0.0.0:* LISTEN tcp 0 0 0.0.0.0:8080 0.0.0.0:* LISTEN ... $ ping 172.17.0.2 PING 172.17.0.2 (172.17.0.2) 56(84) bytes of data. 64 bytes from 172.17.0.2: icmp_seq=1 ttl=64 time=0.083 ms 64 bytes from 172.17.0.2: icmp_seq=2 ttl=64 time=0.042 ms
补充排查信息
docker ps输出
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES 430796e48525 demowebsiteapi "/bin/bash -c 'expor…" 12 hours ago Up 27 minutes 0.0.0.0:8001->8001/tcp demowebsiteapi
iptables配置异常
我发现iptables的配置有点奇怪,尝试重置后,重启服务器又会恢复成原来的配置:
sudo iptables -L -v Chain INPUT (policy ACCEPT 4173 packets, 508K bytes) pkts bytes target prot opt in out source destination Chain FORWARD (policy DROP 0 packets, 0 bytes) pkts bytes target prot opt in out source destination 0 0 DOCKER-USER all -- any any anywhere anywhere 0 0 DOCKER-ISOLATION-STAGE-1 all -- any any anywhere anywhere 0 0 ACCEPT all -- any docker0 anywhere anywhere ctstate RELATED,ESTABLISHED 0 0 DOCKER all -- any docker0 anywhere anywhere 0 0 ACCEPT all -- docker0 !docker0 anywhere anywhere 0 0 ACCEPT all -- docker0 docker0 anywhere anywhere Chain OUTPUT (policy ACCEPT 753 packets, 111K bytes) pkts bytes target prot opt in out source destination Chain DOCKER (1 references) pkts bytes target prot opt in out source destination 0 0 ACCEPT tcp -- !docker0 docker0 anywhere 172.17.0.2 tcp dpt:8001 Chain DOCKER-ISOLATION-STAGE-1 (1 references) pkts bytes target prot opt in out source destination 0 0 DOCKER-ISOLATION-STAGE-2 all -- docker0 !docker0 anywhere anywhere 0 0 RETURN all -- any any anywhere anywhere Chain DOCKER-ISOLATION-STAGE-2 (1 references) pkts bytes target prot opt in out source destination 0 0 DROP all -- any docker0 anywhere anywhere 0 0 RETURN all -- any any anywhere anywhere Chain DOCKER-USER (1 references) pkts bytes target prot opt in out source destination 0 0 RETURN all -- any any anywhere anywhere
我已经被这个问题卡了一周了,任何建议或思路对我来说都非常宝贵,万分感谢!
备注:内容来源于stack exchange,提问作者Seglinglin
相关产品推荐
相关产品推荐

