From 181a7dd55dcbb4d0d44d54e49a34c010ed96062f Mon Sep 17 00:00:00 2001 From: niusmallnan Date: Wed, 2 Jan 2019 17:12:07 +0800 Subject: [PATCH 1/3] Support for multiple user Docker daemons in RancherOS --- .../configuration/docker/_index.md | 109 ++++++++++++++++++ 1 file changed, 109 insertions(+) diff --git a/content/os/v1.x/en/installation/configuration/docker/_index.md b/content/os/v1.x/en/installation/configuration/docker/_index.md index db7f03c56f1..6c343adbe22 100644 --- a/content/os/v1.x/en/installation/configuration/docker/_index.md +++ b/content/os/v1.x/en/installation/configuration/docker/_index.md @@ -154,3 +154,112 @@ DEBU[0204] Applied tar sha256:3fb66f713c9fa9debcdaa58bb9858bd04c17350d9614b7a250 Digest: sha256:0b94d1d1b5eb130dd0253374552445b39470653fb1a1ec2d81490948876e462c Status: Downloaded newer image for alpine:latest ``` + +### Using multiple user Docker daemons + +_Available as of v1.5_ + +#### Terminology + +| Term | Definition | +|-----------------------|--------------------------------------------------| +| Dind | Docker in docker, this is the key to our realization of this feature. | +| User docker, UD | The user-docker on RancherOS | +| Other user docker, OUD| The other user-docker daemons you create, these user-docker daemons are Dind mode | + +#### Prepare + +You must switch user-docker to 17.12.1 or earlier version. Otherwise, it may get these error when creating an user-defined network on system-docker. + +``` +$ ros engine switch docker-17.12.1-ce +``` + +Create an user-define network, need to use this network when creating an OUD: + +``` +$ system-docker network create --subnet=172.20.0.0/16 dind +``` + +#### Create OUD + +Just use `ros engine create`. For the OUD image, currently only support docker `17.12.1` and `18.03.1`. + +``` +$ ros engine create dind1 --network=dind --fixed-ip=172.20.0.2 +``` + +After the OUD service is created, users can query the OUD service as usual. + +``` +$ ros service list +... +... +disabled volume-efs +disabled volume-nfs +enabled dind1 +``` + +To make the dind1 service running, can use: + +``` +$ ros service up dind1 +``` + +After the OUD service is started, you can interact with it as if they were using the docker command. + +``` +$ docker-dind1 ps -a +``` + +#### SSH into OUD container + +You can specify an external ssh port with `--ssh-port`, and ssh keys with `--authorized-keys`. Both of them are optional. + +``` +$ ros engine create -h +... +... +OPTIONS: + --ssh-port value + --authorized-keys value +``` + +For `--authorized-keys`, user needs to put the key file in one of the following directories: +``` +/var/lib/rancher/ +/opt/ +/home/ +``` + +RancherOS will generate a random password for each OUD container, which you can see in the container logs. This password is useful if you do not set the keys. + +``` +$ system-docker logs dind1 + +====================================== +chpasswd: password for 'root' changed +password: xCrw6fEG +====================================== +``` + +You can ssh into any OUD container like this: + +``` +$ system-docker ps +CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES +2ca07a25799b rancher/os-dind:17.12.1 "docker-entrypoint..." 5 seconds ago Up 3 seconds 2375/tcp, 0.0.0.0:34791->22/tcp dind1 + +$ ssh -p 34791 root@ + +$ ssh root@ + +``` + +#### Remove OUD + +Just use `ros engine rm`: + +``` +$ ros engine rm dind1 +``` From c91654328e07d5f32120245bd1ffbd93e45dc607 Mon Sep 17 00:00:00 2001 From: Denise Date: Wed, 30 Jan 2019 14:30:51 -0800 Subject: [PATCH 2/3] Update _index.md --- .../v1.x/en/installation/configuration/docker/_index.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/content/os/v1.x/en/installation/configuration/docker/_index.md b/content/os/v1.x/en/installation/configuration/docker/_index.md index 6c343adbe22..a8b4adaff2f 100644 --- a/content/os/v1.x/en/installation/configuration/docker/_index.md +++ b/content/os/v1.x/en/installation/configuration/docker/_index.md @@ -155,17 +155,17 @@ Digest: sha256:0b94d1d1b5eb130dd0253374552445b39470653fb1a1ec2d81490948876e462c Status: Downloaded newer image for alpine:latest ``` -### Using multiple user Docker daemons +### Using Multiple User-Docker Daemons _Available as of v1.5_ #### Terminology -| Term | Definition | +| Terminology | Definition | |-----------------------|--------------------------------------------------| -| Dind | Docker in docker, this is the key to our realization of this feature. | +| Dind | Docker in docker | | User docker, UD | The user-docker on RancherOS | -| Other user docker, OUD| The other user-docker daemons you create, these user-docker daemons are Dind mode | +| Other user docker, OUD| The other user-docker daemons you create, these user-docker daemons are Dind mode. | #### Prepare From 30c8632c7785f1584d0e3a0ba73add534780e384 Mon Sep 17 00:00:00 2001 From: Denise Date: Tue, 5 Mar 2019 11:02:39 -0800 Subject: [PATCH 3/3] Update _index.md --- .../configuration/docker/_index.md | 65 ++++++++++--------- 1 file changed, 35 insertions(+), 30 deletions(-) diff --git a/content/os/v1.x/en/installation/configuration/docker/_index.md b/content/os/v1.x/en/installation/configuration/docker/_index.md index a8b4adaff2f..92b36b187b5 100644 --- a/content/os/v1.x/en/installation/configuration/docker/_index.md +++ b/content/os/v1.x/en/installation/configuration/docker/_index.md @@ -155,41 +155,45 @@ Digest: sha256:0b94d1d1b5eb130dd0253374552445b39470653fb1a1ec2d81490948876e462c Status: Downloaded newer image for alpine:latest ``` -### Using Multiple User-Docker Daemons +### Using Multiple User Docker Daemons -_Available as of v1.5_ +_Available as of v1.5.0_ + +When RancherOS is booted, you start with a User Docker service that is running in System Docker. With v1.5.0, RancherOS has the ability to create additional User Docker services that can run at the same time. #### Terminology +Throughout the rest of this documentation, we may simplify to use these terms when describing Docker. + | Terminology | Definition | |-----------------------|--------------------------------------------------| -| Dind | Docker in docker | -| User docker, UD | The user-docker on RancherOS | -| Other user docker, OUD| The other user-docker daemons you create, these user-docker daemons are Dind mode. | +| DinD | Docker in docker | +| User Docker | The user-docker on RancherOS | +| Other User Docker| The other user-docker daemons you create, these user-docker daemons are automatically assumed to be Docker in Docker. | -#### Prepare +#### Pre-Requisites -You must switch user-docker to 17.12.1 or earlier version. Otherwise, it may get these error when creating an user-defined network on system-docker. +User Docker must be set as Docker 17.12.1 or earlier. If it's a later Docker version, it will produce errors when creating a user defined network in System Docker. ``` $ ros engine switch docker-17.12.1-ce ``` -Create an user-define network, need to use this network when creating an OUD: +You will need to create a user-defined network, which will be used when creating the Other User Docker. ``` $ system-docker network create --subnet=172.20.0.0/16 dind ``` -#### Create OUD +#### Create the Other User Docker -Just use `ros engine create`. For the OUD image, currently only support docker `17.12.1` and `18.03.1`. +In order to create another User Docker, you will use `ros engine create`. Currently, RancherOS only supports Docker `17.12.1` and `18.03.1` for the Other User Docker image. ``` -$ ros engine create dind1 --network=dind --fixed-ip=172.20.0.2 +$ ros engine create otheruserdockername --network=dind --fixed-ip=172.20.0.2 ``` -After the OUD service is created, users can query the OUD service as usual. +After the Other User Docker service is created, users can query this service like other services. ``` $ ros service list @@ -197,27 +201,27 @@ $ ros service list ... disabled volume-efs disabled volume-nfs -enabled dind1 +enabled otheruserdockername ``` -To make the dind1 service running, can use: +You can use `ros service up` to start the Other User Docker service. ``` -$ ros service up dind1 +$ ros service up otheruserdockername ``` -After the OUD service is started, you can interact with it as if they were using the docker command. +After the Other User Docker service is running, you can interact with it just like you can use the built-in User Docker. You would need to append `-` to `docker`. ``` -$ docker-dind1 ps -a +$ docker-otheruserdockername ps -a ``` -#### SSH into OUD container +#### SSH into the Other User Docker container -You can specify an external ssh port with `--ssh-port`, and ssh keys with `--authorized-keys`. Both of them are optional. +When creating the Other User Docker, you can set an external SSH port so you can SSH into the Other User Docker container in System Docker. By using `--ssh-port` and adding ssh keys with `--authorized-keys`, you can set up this optional SSH port. ``` -$ ros engine create -h +$ ros engine create --help ... ... OPTIONS: @@ -225,17 +229,18 @@ OPTIONS: --authorized-keys value ``` -For `--authorized-keys`, user needs to put the key file in one of the following directories: +When using `--authorized-keys`, you will need to put the key file in one of the following directories: + ``` /var/lib/rancher/ /opt/ /home/ ``` -RancherOS will generate a random password for each OUD container, which you can see in the container logs. This password is useful if you do not set the keys. +RancherOS will generate a random password for each Other User Docker container, which can be viewed in the container logs. If you do not set any SSH keys, the password can be used. ``` -$ system-docker logs dind1 +$ system-docker logs otheruserdockername ====================================== chpasswd: password for 'root' changed @@ -243,23 +248,23 @@ password: xCrw6fEG ====================================== ``` -You can ssh into any OUD container like this: +In System Docker, you can SSH into any Other Uesr Docker Container using `ssh`. ``` $ system-docker ps CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES -2ca07a25799b rancher/os-dind:17.12.1 "docker-entrypoint..." 5 seconds ago Up 3 seconds 2375/tcp, 0.0.0.0:34791->22/tcp dind1 +2ca07a25799b rancher/os-dind:17.12.1 "docker-entrypoint..." 5 seconds ago Up 3 seconds 2375/tcp, 0.0.0.0:34791->22/tcp otheruserdockername -$ ssh -p 34791 root@ +$ ssh -p 34791 root@ -$ ssh root@ +$ ssh root@ ``` -#### Remove OUD +#### Removing any Other User Docker Service -Just use `ros engine rm`: +We recommend using `ros engine rm` to remove any Other User Docker service. ``` -$ ros engine rm dind1 +$ ros engine rm otheruserdockername ```