使用官方jenkins图像,我已经安装了docker和docker-compose并将jenkins添加到docker组(容器中的GID 999) .
之后,我共享了主机的/var/run/docker.sock,因此启用jenkins创建“兄弟姐妹”容器 . 碰巧原始文件具有GID 134并且已安装此GID . 我收到以下错误:
demo_1 | docker:在尝试连接到unix上的Docker守护程序套接字时获得权限被拒绝:///var/run/docker.sock:发布http://%2Fvar%2Frun%2Fdocker.sock/v1.32/containers/create:拨打unix /var/run/docker.sock:connect:权限被拒绝 . demo_1 |请参阅'docker run --help' .
有关如何解决这个问题的任何想法?
我的最小(并没有优化)Dockerfile是:
FROM jenkins/jenkins:lts
USER root
RUN apt-get update && apt-get install -y apt-transport-https \
ca-certificates \
curl \
gnupg2 \
software-properties-common
RUN curl -fsSL https://download.docker.com/linux/$(. /etc/os-release; echo "$ID")/gpg | apt-key add -
RUN apt-key fingerprint 0EBFCD88
RUN add-apt-repository \
"deb [arch=amd64] https://download.docker.com/linux/$(. /etc/os-release; echo "$ID") \
$(lsb_release -cs) \
stable"
RUN apt-get update
RUN apt-get install -y docker-ce docker-compose
RUN usermod -aG docker jenkins
USER jenkins
RUN newgrp docker
我还创建了一个docker-compose来测试它:
version: '2'
services:
demo:
build: .
ports:
- 8080:8080
- 50000:50000
volumes:
- /var/run/docker.sock:/var/run/docker.sock
command: >
/bin/sh -c "
set -e
groups
docker -v
docker-compose -v
ls -ln /var/run/docker.sock
id jenkins
docker run hello-world
"
输出是:
demo_1 | jenkins staff docker
demo_1 | Docker version 17.09.0-ce, build afdb6d4
demo_1 | docker-compose version 1.8.0, build unknown
demo_1 | srw-rw---- 1 0 134 0 Sep 30 07:36 /var/run/docker.sock
demo_1 | uid=1000(jenkins) gid=1000(jenkins) groups=1000(jenkins),50(staff),999(docker)
demo_1 | docker: Got permission denied while trying to connect to the Docker daemon socket at unix:///var/run/docker.sock: Post http://%2Fvar%2Frun%2Fdocker.sock/v1.32/containers/create: dial unix /var/run/docker.sock: connect: permission denied.
demo_1 | See 'docker run --help'.
1 回答
我给这个问题做了一个肮脏的修复,所以我打开这个问题,看看是否出现了更好的问题 .
由于/var/run/docker.sock文件由root拥有,它具有相同的UID,因此我将jenkins添加到sudoers列表中而无需键入密码:
这解决了这个问题 . 我不喜欢它,但它有效 .