容器互联
- 查看所有的docker网络
docker network ls
[root@z ~]# docker network ls
NETWORK ID NAME DRIVER SCOPE
7c0a6bbfb297 bridge bridge local
024e9d72cb99 host host local
8f57783bd653 none null local
网络模式
bridge:桥接docker(默认,使用bridge模式)
none:不配置网络
host :和宿主机共享网络
container :容器网络连通!(用的少!局限很大)定义一个网络 mynet
docker network create --driver bridge --subnet 192.168.0.0/16 --gateway 192.168.0.1 mynet
--driver bridge 模式:桥接 (不指定默认是bridge桥接模式)
--subnet 192.168.0.0/16 子网掩码
--gateway 192.168.0.1 网关地址
[root@z ~]# docker network create --driver bridge --subnet 192.168.0.0/16 --gateway 192.168.0.1 mynet
003a4c431d4731aaeb3cdb260ce7d9980758ac9321dfcc79d6583062a7d13a32
# 查看所有网络
[root@z ~]# docker network ls
NETWORK ID NAME DRIVER SCOPE
7c0a6bbfb297 bridge bridge local
024e9d72cb99 host host local
003a4c431d47 mynet bridge local
8f57783bd653 none null local
- 查看创建的网络详情
[root@z ~]# docker network inspect mynet
[
{
"Name": "mynet",
"Id": "003a4c431d4731aaeb3cdb260ce7d9980758ac9321dfcc79d6583062a7d13a32",
"Created": "2021-07-16T04:58:41.978269728-04:00",
"Scope": "local",
"Driver": "bridge",
"EnableIPv6": false,
"IPAM": {
"Driver": "default",
"Options": {},
"Config": [
{
"Subnet": "192.168.0.0/16",
"Gateway": "192.168.0.1"
}
]
},
"Internal": false,
"Attachable": false,
"Ingress": false,
"ConfigFrom": {
"Network": ""
},
"ConfigOnly": false,
"Containers": {},
"Options": {},
"Labels": {}
}
]
- 启动容器并指定网络
docker run -d --name tomcat01 --network 网络名 tomcat
[root@z ~]# docker run -d -P --name tomcat01 --network mynet tomcat
d58a59b091de1969403d96ff2e26449a881ac68c40f0abff2da3394d12d8f887
[root@z ~]# docker run -d -P --name tomcat02 --network mynet tomcat
2b4b3773f8acdbc98c2ba29e64122230cd4fc2b7ab8b08c3a9941fa3f0d8474c
- 查看自定义网络的详情
docker network inspect mynet
[root@z ~]# docker network inspect mynet
[
{
"Name": "mynet",
"Id": "003a4c431d4731aaeb3cdb260ce7d9980758ac9321dfcc79d6583062a7d13a32",
"Created": "2021-07-16T04:58:41.978269728-04:00",
"Scope": "local",
"Driver": "bridge",
"EnableIPv6": false,
"IPAM": {
"Driver": "default",
"Options": {},
"Config": [
{
"Subnet": "192.168.0.0/16",
"Gateway": "192.168.0.1"
}
]
},
"Internal": false,
"Attachable": false,
"Ingress": false,
"ConfigFrom": {
"Network": ""
},
"ConfigOnly": false,
"Containers": { 容器对应的网络配置
"2b4b3773f8acdbc98c2ba29e64122230cd4fc2b7ab8b08c3a9941fa3f0d8474c": {
"Name": "tomcat02",
"EndpointID": "b2f6378192743c496c8260f4c4ff5644ff341bc980720c417114f661c0ba6b5f",
"MacAddress": "02:42:c0:a8:00:03",
"IPv4Address": "192.168.0.3/16", tomcat02的地址192.168.0.3
"IPv6Address": ""
},
"d58a59b091de1969403d96ff2e26449a881ac68c40f0abff2da3394d12d8f887": {
"Name": "tomcat01",
"EndpointID": "93a9dddc9cf90c51eac83c201761868628f8d73d3ebb650d250e981a7ace25f2",
"MacAddress": "02:42:c0:a8:00:02",
"IPv4Address": "192.168.0.2/16", tomcat01的地址192.168.0.2
"IPv6Address": ""
}
},
"Options": {},
"Labels": {}
}
]
已经在网络信息里看到了容器网络信息
测试 通过服务名(容器名)进行通讯
- 查看容器tomcat01和容器tomcat02的ip
[root@z ~]# docker exec tomcat01 ip addr
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
13: eth0@if14: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default
link/ether 02:42:c0:a8:00:02 brd ff:ff:ff:ff:ff:ff link-netnsid 0
inet 192.168.0.2/16 brd 192.168.255.255 scope global eth0
valid_lft forever preferred_lft forever
[root@z ~]# docker exec tomcat02 ip addr
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
15: eth0@if16: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default
link/ether 02:42:c0:a8:00:03 brd ff:ff:ff:ff:ff:ff link-netnsid 0
inet 192.168.0.3/16 brd 192.168.255.255 scope global eth0
valid_lft forever preferred_lft forever
容器tomcat01的ip为 192.168.0.2
容器tomcat02的ip为 192.168.0.3
- 测试使用ip是否可以ping通
[root@z ~]# docker exec tomcat01 ping 192.168.0.3
PING 192.168.0.3 (192.168.0.3) 56(84) bytes of data.
64 bytes from 192.168.0.3: icmp_seq=1 ttl=64 time=0.122 ms
64 bytes from 192.168.0.3: icmp_seq=2 ttl=64 time=0.346 ms
64 bytes from 192.168.0.3: icmp_seq=3 ttl=64 time=1.06 ms
- 测试使用容器名是否可以ping通
[root@z ~]# docker exec tomcat01 ping tomcat02
PING tomcat02 (192.168.0.3) 56(84) bytes of data.
64 bytes from tomcat02.mynet (192.168.0.3): icmp_seq=1 ttl=64 time=0.082 ms
64 bytes from tomcat02.mynet (192.168.0.3): icmp_seq=2 ttl=64 time=0.057 ms
64 bytes from tomcat02.mynet (192.168.0.3): icmp_seq=3 ttl=64 time=0.052 ms
- 经测试 都可以ping通
总结:
自定义的网络docker都已经帮我们维护好了主机名和ip对应的关系(ip和主机名都能通)
好处︰
redis -不同的集群使用不同的网络,保证集群是安全和健康的
mysql -不同的集群使用不同的网络,保证集群是安全和健康的