在轻量级云服务器上配置 Docker 运行环境
一、前期准备
1. 系统要求
- 操作系统:Ubuntu 20.04/22.04、Debian 10+、CentOS 7+ 等主流 Linux 发行版
- 内存建议:至少 512MB~1GB(推荐 ≥2GB)
- 磁盘空间:至少 10GB 可用空间
- 权限:需要
root或具有sudo权限的用户
2. 连接服务器
ssh root@your_server_ip
二、安装 Docker
方法一:使用官方脚本(最简方式,适合新手)
curl -fsSL https://get.docker.com | sh
⚠️ 此脚本会自动检测系统并安装最新稳定版 Docker。
方法二:手动安装(更可控,推荐生产环境)
Step 1:更新系统包
apt update && apt upgrade -y # Debian/Ubuntu
# 或
yum update -y # CentOS/RHEL
Step 2:安装依赖
# Debian/Ubuntu
apt install -y apt-transport-https ca-certificates curl gnupg lsb-release
# CentOS/RHEL
yum install -y yum-utils device-mapper-persistent-data lvm2
Step 3:添加 Docker 官方 GPG 密钥和仓库
# 设置 Docker 官方源
curl -fsSL https://download.docker.com/linux/ubuntu/gpg | sudo gpg --dearmor -o /usr/share/keyrings/docker-archive-keyring.gpg
echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/docker-archive-keyring.gpg]
https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" |
sudo tee /etc/apt/sources.list.d/docker.list > /dev/null
Step 4:安装 Docker Engine
apt update
apt install -y docker-ce docker-ce-cli containerd.io docker-compose-plugin
Step 5:启动并设置开机自启
systemctl start docker
systemctl enable docker
systemctl status docker # 验证是否运行正常
三、基础配置优化(针对轻量服务器)
1. 允许非 root 用户使用 Docker
sudo usermod -aG docker $USER
# 重新登录生效,或执行:newgrp docker
2. 配置镜像提速器(提速拉取)
创建/编辑 /etc/docker/daemon.json:
{
"registry-mirrors": [
"https://docker.m.daocloud.io",
"https://mirror.ccs.tencentyun.com"
],
"log-driver": "json-file",
"log-opts": {
"max-size": "10m",
"max-file": "3"
},
"storage-driver": "overlay2"
}
重启 Docker:
systemctl restart docker
3. 限制资源使用(防止 OOM)
# 在 daemon.json 中添加
{
"default-ulimits": {
"nofile": { "Name": "nofile", "Hard": 65536, "Soft": 65536 }
}
}
4. 清理机制(节省磁盘空间)
# 定期清理未使用的镜像、容器、卷
docker system prune -af
四、安全加固
1. 禁用 Docker Socket 暴露(默认已安全)
确保不通过 TCP 监听 Docker API:
# 检查是否有 -H tcp://0.0.0.0:2375 的配置
cat /lib/systemd/system/docker.service | grep -i host
2. 启用防火墙规则
# UFW (Ubuntu)
ufw allow 2376/tcp comment 'Docker TLS'
ufw enable
# firewalld (CentOS)
firewall-cmd --permanent --add-port=2376/tcp
firewall-cmd --reload
3. 使用非特权用户运行容器
# docker-compose.yml 示例
services:
app:
image: nginx
user: "1000:1000" # 指定非 root 用户
read_only: true # 只读文件系统
tmpfs:
- /tmp
五、常用操作命令速查
| 操作 | 命令 |
|---|---|
| 查看版本 | docker --version |
| 查看状态 | systemctl status docker |
| 启动/停止 | systemctl start/stop/restart docker |
| 拉取镜像 | docker pull nginx:latest |
| 运行容器 | docker run -d -p 80:80 --name web nginx |
| 查看容器 | docker ps -a |
| 查看日志 | docker logs -f <container_name> |
| 进入容器 | docker exec -it <container_name> bash |
| 删除容器 | docker rm -f <container_name> |
| 删除镜像 | docker rmi <image_id> |
| 构建镜像 | docker build -t myapp:v1 . |
六、验证安装成功
# 运行测试容器
docker run hello-world
# 预期输出:
# Hello from Docker!
# This message shows that your installation appears to be working correctly.
七、常见问题排查
| 问题 | 解决方案 |
|---|---|
permission denied |
将当前用户加入 docker 组:sudo usermod -aG docker $USER |
Cannot connect to the Docker daemon |
检查服务状态:systemctl status docker;尝试 sudo systemctl start docker |
| 拉取镜像超时 | 配置国内镜像提速器 |
| 磁盘空间不足 | docker system prune -af 清理无用资源 |
| 端口冲突 | 修改 -p 映射端口,如 -p 8080:80 |
八、轻量级最佳实践总结
✅ 使用 Alpine 基础镜像减小体积
✅ 设置日志轮转防止磁盘写满
✅ 定期清理无用镜像和容器
✅ 限制容器 CPU/内存资源
✅ 使用 docker-compose 管理多容器
❌ 避免在容器内运行不必要的服务
❌ 不要以 root 身份运行应用进程
💡 提示:对于极轻量场景(<512MB RAM),可考虑使用 Podman(无守护进程)或 Docker Rootless Mode 进一步降低开销。
云服务器