实验 Docker镜像实战(SSH,systemctl,nginx,Tomcat,mysql)

一 构建SSH镜像

1.创建sshd目录
[root@localhost ~]# mkdir sshd
[root@localhost ~]# cd sshd/

2.编辑Dockerfile
[root@localhost sshd]# vim Dockerfile
FROM centos:7		//指定基础镜像
MAINTAINER The CentOS Project <cloud-centos>		//描述信息
RUN yum -y update		//更新容器yum源
RUN yum -y install openssh* net-tools lsof telnet passwd		//部署环境工具
RUN echo 'Abc123' | passwd --stdin root		//设置root登录密码
RUN sed -i 's/UsePAM yes/UsePAM no/g' /etc/ssh/sshd_config		//禁用ssh中的pam验证
RUN ssh-keygen -t rsa -f /etc/ssh/ssh_host_rsa_key		//创建非对称密钥对,并指定文件路径
RUN sed -i '/^session\s\+required\s\+pam_loginuid.so/s/^/#/' /etc/pam.d/sshd		//禁用pam的ssh的pam会话模块
RUN mkdir -p /root/.ssh && chown root.root /root && chmod 700 /root/.ssh		//创建ssh工作目录和设置权限
EXPOSE 22		//开放端口22
CMD ["/usr/sbin/sshd","-D"]		//容器加载时启动ssh服务时为不可中断的睡眠状态

Linux进程状态:R (TASK_RUNNING),可执行状态
Linux进程状态:S (TASK_INTERRUPTIBLE),可中断的睡眠状态
Linux进程状态:D (TASK_UNINTERRUPTIBLE),不可中断的睡眠状态
Linux进程状态:T (TASK_STOPPED or TASK_TRACED),暂停状态或跟踪状态
Linux进程状态:Z (TASK_DEAD - EXIT_ZOMBIE),退出状态,进程成为僵尸进程
Linux进程状态:X (TASK_DEAD - EXIT_DEAD),退出状态,进程即将被销毁

3.生成镜像
[root@localhost sshd]# docker build -t sshd:new .

4. 启动容器并查看随机生成的端口号
[root@localhost sshd]# docker run -d -P sshd:new 
c1f6db329d6c30b5e9118ab897aad63fb7cc32e0dc60ba07dd31c6eb01f8278a
[root@localhost sshd]# docker ps -a
CONTAINER ID        IMAGE                 COMMAND                  CREATED             STATUS                         PORTS                   NAMES
c1f6db329d6c        sshd:new              "/usr/sbin/sshd -D"      15 seconds ago      Up 15 seconds                  0.0.0.0:32768->22/tcp   keen_bhabha

5.远程登录
[root@localhost sshd]# ssh localhost -p 32768
Are you sure you want to continue connecting (yes/no)? yes
Warning: Permanently added '[localhost]:32768' (RSA) to the list of known hosts.
root@localhost's password: 
[root@c1f6db329d6c ~]# 

二 构建systemctl镜像

1.创建systemctl目录
[root@localhost ~]# mkdir systemctl
[root@localhost ~]# cd systemctl/

2. 编辑Dockerfile文件
[root@localhost systemctl]# vim Dockerfile
FROM sshd:new
ENV container docker		//设置环境变量,container和docker
RUN (cd /lib/systemd/system/sysinit.target.wants/; for i in *; do [ $i = = \systemd-tmpfiles-setup.service ] || rm -f $i; done); \
rm -f /lib/systemd/system/multi-user.target.wants/*; \
rm -f /etc/systemd/system/*.wants/*; \
rm -f /lib/systemd/system/local-fs.target.wants/*; \
rm -f /lib/systemd/system/sockets.target.wants/*udev*; \
rm -f /lib/systemd/system/sockets.target.wants/*initctl*; \
rm -f /lib/systemd/system/basic.target.wants/*; \
rm -f /lib/systemd/system/anaconda.target.wants/*;			//执行先到指定目录,进行for循环遍历目录下所有文件并删除指定的文件。之后进行一系列的删除
VOLUME ["/sys/fs/cgroup"]		//创建一个挂载卷
CMD ["/usr/sbin/init"]		//init指执行初始化

3. 生成镜像
[root@localhost systemctl]# docker build -t systemd:new .

4. 建立数据卷
[root@localhost systemctl]# docker run --privileged -it -v /sys/fs/cgroup/:/sys/fs/cgroup:ro systemd:new  &
//privileged container内的root拥有真正的root权限,否则,container内的root只是外部的一个普通用户权限
[1] 28851
[root@localhost systemctl]# docker ps -a
CONTAINER ID        IMAGE                 COMMAND                  CREATED             STATUS                   PORTS                   NAMES
12953c66ad51        systemd:new           "/sbin/init"             21 seconds ago      Up 20 seconds            22/tcp                  agitated_neumann
c1f6db329d6c        sshd:new              "/usr/sbin/sshd -D"      53 minutes ago      Up 53 minutes            0.0.0.0:32768->22/tcp   keen_bhabha
3b465ff113ad        httpd                 "/bin/bash -c ls /"      2 hours ago         Exited (0) 2 hours ago                           goofy_jennings
46bf59038bdb        centos:7              "/usr/bin/bash -c ls…"   2 hours ago         Exited (0) 2 hours ago                           nice_merkle
878bbfbbea77        paigeeworld/centos7   "/usr/bin/bash -c ls…"   2 hours ago         Exited (0) 2 hours ago                           gallant_torvalds
e1eb0990df20        centos:7              "/bin/bash"              4 hours ago         Up 2 hours                                       quirky_curie

5. 进入容器,验证systemd服务
[root@localhost systemctl]# docker exec -it 12953c66ad51 bash
[root@12953c66ad51 /]# systemctl status sshd
● sshd.service - OpenSSH server daemon
   Loaded: loaded (/usr/lib/systemd/system/sshd.service; disabled; vendor preset: enabled)
   Active: inactive (dead)
     Docs: man:sshd(8)
           man:sshd_config(5)
[root@12953c66ad51 /]# systemctl start sshd
[root@12953c66ad51 /]# systemctl status sshd

三 构建nginx镜像

1. 创建nginx目录
[root@localhost ~]# mkdir nginx
[root@localhost ~]# cd nginx/
[root@localhost nginx]# rz -E		##传包源
rz waiting to receive.
[root@localhost nginx]# ll
总用量 960
-rw-r--r-- 1 root root 981687 8月  18 2018 nginx-1.12.2.tar.gz

2. 编辑Dockerfile文件
[root@localhost nginx]# vim Dockerfile
#基于基础镜像
FROM systemd:new
#用户信息
MAINTAINER this is nginx image <cwj>
#添加环境包
RUN yum -y update
RUN yum -y install pcre-devel zlib-devel gcc gcc-c++ make
RUN useradd -M -s /sbin/nologin nginx
#下载nginx软件包
ADD nginx-1.12.2.tar.gz /usr/local/src
#指定工作目录
WORKDIR /usr/local/src/nginx-1.12.2
#编译安装
RUN ./configure \
--prefix=/usr/local/nginx \
--user=nginx \
--group=nginx \
--with-http_stub_status_module && make && make install
#设置环境变量
ENV PATH /usr/local/nginx/sbin:$PATH
#指定http和https端口
EXPOSE 80
EXPOSE 443
RUN echo "daemon off;" >> /usr/local/nginx/conf/nginx.conf		//关闭守护进程启动
#添加宿主机中run.sh到容器中
ADD run.sh /run.sh
RUN chmod 755 /run.sh
CMD ["/run.sh"]

3. 编辑运行脚本
[root@localhost nginx]# vim run.sh
#!/bin/bash
/usr/local/nginx/sbin/nginx

4. 创建新镜像
[root@localhost nginx]# docker build -t nginx:new .

5. 启动nginx容器
[root@localhost nginx]# docker run -d -P nginx:new 
ec1e74540305ae1cf361d5592b2718f329c79d98f351dca17ed772778e0bc9a4

[root@localhost nginx]# docker ps -a
CONTAINER ID        IMAGE               COMMAND               CREATED             STATUS              PORTS                                                                  NAMES
ec1e74540305        nginx:new           "/run.sh"             7 seconds ago       Up 7 seconds        0.0.0.0:32780->22/tcp, 0.0.0.0:32779->80/tcp, 0.0.0.0:32778->443/tcp   jolly_roentgen

6. 测试
http://20.0.0.101:32779/

四 构建Tomcat镜像

1. 创建tomcat目录
[root@localhost ~]# mkdir tomcat
[root@localhost ~]# cd tomcat/
[root@localhost Tomcat]# rz -E
rz waiting to receive.
[root@localhost Tomcat]# rz -E
rz waiting to receive.
[root@localhost Tomcat]# ls
apache-tomcat-8.5.23.tar.gz  jdk-8u144-linux-x64.tar.gz

2. 编辑Dockerfile文件
[root@localhost Tomcat]# vim Dockerfile
#基于基础镜像
FROM centos:7
#用户信息
MAINTAINER this is Tomcat image <cwj>
#安装JDK
ADD jdk-8u144-linux-x64.tar.gz /usr/local/
#指定工作路径
WORKDIR /usr/local/
RUN mv jdk1.8.0_144/ /usr/local/java
#设置环境变量
ENV JAVA_HOME /usr/local/java
ENV JRE_HOME /usr/local/java/jre
ENV CLASSPATH ./:/usr/local/java/lib:/usr/local/java/jre/lib
ENV PATH $PATH:/usr/local/java/bin
#安装Tomcat
ADD apache-tomcat-8.5.23.tar.gz /usr/local
#指定工作路径
WORKDIR /usr/local/
RUN mv apache-tomcat-8.5.23 /usr/local/tomcat8
#端口
EXPOSE 8080
#启动Tomcat
ENTRYPOINT ["/usr/local/tomcat8/bin/catalina.sh","run"]
'//此处除了使用CMD,还可以使用ENTRYPOINT'
'//CMD与ENTRYPOINT的区别'
1、ENRYPOINT指开启容器前镜像就已经执行了括号内的命令
2、CMD是开启容器时,要执行的指令,设置容器启动后默认执行的命令及其参数,但 CMD 能够被 docker run 后面跟的命令行参数替换
3、基于Dockerfile内有CMD或者ENTRYPOINT创建镜像时,docker run 后面就不要加指令(/bin/bash)了,会覆盖掉Dockerfile中的指令或者语法报错

3. 创建镜像
[root@localhost Tomcat]# docker build -t tomcat:centos .

4.启动tomcat容器
[root@localhost tomcat]# docker run -d --name tomcat1 -p 1216:8080 tomcat:centos 
b8a28160cdb57528b360a2c0f9b389e4ba71b812ad5c543fef4dc10cadf57ac5
[root@localhost tomcat]# docker ps -a
CONTAINER ID        IMAGE               COMMAND                  CREATED             STATUS                     PORTS                                                                  NAMES
b8a28160cdb5        tomcat:centos       "/usr/local/tomcat8/…"   6 seconds ago       Up 5 seconds               0.0.0.0:1216->8080/tcp  


5.测试
http://20.0.0.101:1216

五 构建mysql镜像

1. 创建mysqld目录
[root@localhost ~]# mkdir mysqld
[root@localhost ~]# cd mysqld/

2.编辑my.cnf配置文件
[root@localhost mysqld]# vim my.cnf
[client]
port = 3306
default-character-set=utf8
socket = /usr/local/mysql/mysql.sock

[mysql]
port = 3306
default-character-set=utf8
socket = /usr/local/mysql/mysql.sock

[mysqld]
user = mysql
basedir = /usr/local/mysql
datadir = /usr/local/mysql/data
port = 3306
character_set_server=utf8
pid-file = /usr/local/mysql/mysqld.pid
socket = /usr/local/mysql/mysql.sock
server-id = 1

sql_mode=NO_ENGINE_SUBSTITUTION,STRICT_TRANS_TABLES,NO_AUTO_CREATE_USER,NO_AUTO_VALUE_ON_ZERO,NO_ZERO_IN_DATE,NO_ZERO_DATE,ERROR_FOR_DIVISION_BY_ZERO,PIPES_AS_CONCAT,ANSI_QUOTES

3. 编辑Dockerfile文件
[root@localhost mysqld]# vim Dockerfile
FROM centos:7
RUN yum -y install \
ncurses \
ncurses-devel \
bison \
cmake \
make \
gcc \
gcc-c++
RUN useradd -s /sbin/nologin mysql
ADD mysql-boost-5.7.20.tar.gz /usr/local/src
WORKDIR /usr/local/src/mysql-5.7.20/
RUN cmake \
-DCMAKE_INSTALL_PREFIX=/usr/local/mysql \
-DMYSQL_UNIX_ADDR=/usr/local/mysql/mysql.sock \
-DSYSCONFDIR=/etc \
-DSYSTEMD_PID_DIR=/usr/local/mysql \
-DDEFAULT_CHARSET=utf8  \
-DDEFAULT_COLLATION=utf8_general_ci \
-DWITH_INNOBASE_STORAGE_ENGINE=1 \
-DWITH_ARCHIVE_STORAGE_ENGINE=1 \
-DWITH_BLACKHOLE_STORAGE_ENGINE=1 \
-DWITH_PERFSCHEMA_STORAGE_ENGINE=1 \
-DMYSQL_DATADIR=/usr/local/mysql/data \
-DWITH_BOOST=boost \
-DWITH_SYSTEMD=1 && make && make install
RUN chown -R mysql:mysql /usr/local/mysql
RUN rm -rf /etc/my.cnf
WORKDIR mysqld/
ADD my.cnf /etc
ENV PATH /usr/local/mysql/bin:/usr/local/mysql/lib:$PATH
WORKDIR /usr/local/mysql/
RUN bin/mysqld \
--initialize-insecure \
--user=mysql \
--basedir=/usr/local/mysql \
--datadir=/usr/local/mysql/data
RUN cp usr/lib/systemd/system/mysqld.service /usr/lib/systemd/system/
EXPOSE 3306
RUN echo -e "#!/bin/sh \nsystemctl enable mysqld" > /run.sh
RUN chmod 755 /run.sh
RUN sh /run.sh
CMD ["init"]

4. 创建容器
[root@localhost mysqld]# docker build -t mysql:centos .

5.启动mysql容器
[root@localhost mysqld]# docker run -d -P --privileged mysql:centos 
bee0381163d65366f0d962ebe0f659b3bdc62ec0a015d5c5752a59746118027e
[root@localhost mysqld]# docker ps -a
CONTAINER ID        IMAGE               COMMAND                  CREATED             STATUS              PORTS                                                                  NAMES
bee0381163d6        mysql:centos        "init"                   6 seconds ago       Up 5 seconds        0.0.0.0:32800->3306/tcp                                                unruffled_shtern
b8a28160cdb5        tomcat:centos       "/usr/local/tomcat8/…"   12 hours ago        Up 12 hours         0.0.0.0:1216->8080/tcp                                                 tomcat1
ec1e74540305        nginx:new           "/run.sh"                18 hours ago        Up 18 hours         0.0.0.0:32780->22/tcp, 0.0.0.0:32779->80/tcp, 0.0.0.0:32778->443/tcp   jolly_roentgen
6886cfb9960a        systemd:new         "/usr/sbin/init"         19 hours ago        Up 19 hours         22/tcp                                                                 vigilant_kowalevski
c1f6db329d6c        sshd:new            "/usr/sbin/sshd -D"      20 hours ago        Up 20 hours         0.0.0.0:32768->22/tcp                                                  keen_bhabha
e1eb0990df20        centos:7            "/bin/bash"              23 hours ago        Up 22 hours                                                                                quirky_curie

5. 进入mysql容器
[root@localhost mysqld]# docker exec -it bee0381163d6 /bin/bash

6. 登入mysql数据库,并授权访问
[root@bee0381163d6 mysql]# mysql -uroot -p
Enter password: 
Welcome to the MySQL monitor.  Commands end with ; or \g.
Your MySQL connection id is 3
Server version: 5.7.20 Source distribution

Copyright (c) 2000, 2017, Oracle and/or its affiliates. All rights reserved.

Oracle is a registered trademark of Oracle Corporation and/or its
affiliates. Other names may be trademarks of their respective
owners.

Type 'help;' or '\h' for help. Type '\c' to clear the current input statement.
mysql> grant all privileges on *.* to 'root'@'%' identified by 'Abc123';
Query OK, 0 rows affected, 1 warning (0.00 sec)

mysql> grant all privileges on *.* to 'root'@'localhost' identified by 'Abc123';
Query OK, 0 rows affected, 1 warning (0.00 sec)

mysql> flush privileges; 
Query OK, 0 rows affected (0.00 sec)


7. 远程登录mysql数据库
[root@ns1 ~]# mysql -h 20.0.0.101 -uroot -pAbc123 -P 32800
mysql: [Warning] Using a password on the command line interface can be insecure.
Welcome to the MySQL monitor.  Commands end with ; or \g.
Your MySQL connection id is 7
Server version: 5.7.20 Source distribution

Copyright (c) 2000, 2017, Oracle and/or its affiliates. All rights reserved.

Oracle is a registered trademark of Oracle Corporation and/or its
affiliates. Other names may be trademarks of their respective
owners.

Type 'help;' or '\h' for help. Type '\c' to clear the current input statement.

mysql> 

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值