如何从容器内部运行podman? [英] How to run podman from inside a container?
问题描述
我想运行 podman 作为运行CI/CD管道的容器.但是,我不断从podman容器中收到此错误:
I want to run podman as a container to run CI/CD pipelines. However, I keep getting this error from the podman container:
$ podman info
ERRO[0000] 'overlay' is not supported over overlayfs
Error: could not get runtime: 'overlay' is not supported over overlayfs: backing file system is unsupported for this graph driver
我正在使用 Jenkins Kubernetes插件编写作为容器中的容器运行的CI/CD管道Kubernetes集群.我已经成功编写了使用Docker-in-Docker容器运行docker build
和docker push
命令的管道.
I am using the Jenkins Kubernetes plugin to write CI/CD pipelines that run as containers within a Kubernetes cluster. I've been successful at writing pipelines that use a Docker-in-Docker container to run docker build
and docker push
commands.
但是,在容器中运行Docker客户端和Docker Daemon会使CI/CD环境非常膨胀,难以配置,并且不适合使用.因此,我认为我可以使用 podman 从Dockerfile构建Docker映像,而无需使用繁琐的Docker守护进程.
However, running a Docker client and a Docker Daemon inside a container makes the CI/CD environment very bloated, hard to configure, and just not ideal to work with. So I figured I could use podman to build Docker images from Dockerfiles without using a fat Docker daemon.
问题在于 podman 太新了,以至于我以前从未见过有人尝试过此操作,也没有足够的Podman专家来正确执行此操作.
The problem is that podman is so new that I have not seen anyone attempt this before, nor I am enough of a podman expert to properly execute this.
因此,请使用针对Ubuntu的Podman安装说明创建了以下Dockerfile:
So, using the podman installation instructions for Ubuntu I created the following Dockerfile:
FROM ubuntu:16.04
RUN apt-get update -qq \
&& apt-get install -qq -y software-properties-common uidmap \
&& add-apt-repository -y ppa:projectatomic/ppa \
&& apt-get update -qq \
&& apt-get -qq -y install podman
# To keep it running
CMD tail -f /dev/null
因此,我构建了图像并按如下所示运行它:
So I built the image and ran it as follows:
# Build
docker build -t podman:ubuntu-16.04 .
# Run
docker run --name podman -d podman:ubuntu-16.04
然后在正在运行的容器上运行此命令时,出现错误:
Then when running this command on the running container, I get an error:
$ docker exec -ti podman bash -c "podman info"
ERRO[0000] 'overlay' is not supported over overlayfs
Error: could not get runtime: 'overlay' is not supported over overlayfs: backing file system is unsupported for this graph driver
我在装有Ubuntu 16.04的计算机上安装了podman,并运行了相同的podman info
命令,得到了预期的结果:
I install podman on an Ubuntu 16.04 machine I had and ran the same podman info
command I got the expected results:
host:
BuildahVersion: 1.8-dev
Conmon:
package: 'conmon: /usr/libexec/crio/conmon'
path: /usr/libexec/crio/conmon
version: 'conmon version , commit: '
Distribution:
distribution: ubuntu
version: "16.04"
MemFree: 2275770368
MemTotal: 4142137344
OCIRuntime:
package: 'cri-o-runc: /usr/lib/cri-o-runc/sbin/runc'
path: /usr/lib/cri-o-runc/sbin/runc
version: 'runc version spec: 1.0.1-dev'
SwapFree: 2146758656
SwapTotal: 2146758656
arch: amd64
cpus: 2
hostname: jumpbox-4b3620b3
kernel: 4.4.0-141-generic
os: linux
rootless: false
uptime: 222h 46m 33.48s (Approximately 9.25 days)
insecure registries:
registries: []
registries:
registries:
- docker.io
store:
ConfigFile: /etc/containers/storage.conf
ContainerStore:
number: 0
GraphDriverName: overlay
GraphOptions: null
GraphRoot: /var/lib/containers/storage
GraphStatus:
Backing Filesystem: extfs
Native Overlay Diff: "true"
Supports d_type: "true"
Using metacopy: "false"
ImageStore:
number: 15
RunRoot: /var/run/containers/storage
VolumePath: /var/lib/containers/storage/volumes
有人知道我该如何解决该错误并使Podman从容器中工作?
Does anyone know how I can fix this error and get podman working from a container?
推荐答案
您的Dockerfile也应该安装iptables:
Your Dockerfile should install iptables as well:
FROM ubuntu:16.04
RUN apt-get update -qq \
&& apt-get install -qq -y software-properties-common uidmap \
&& add-apt-repository -y ppa:projectatomic/ppa \
&& apt-get update -qq \
&& apt-get -qq -y install podman \
&& apt-get install -y iptables
# To keep it running
CMD tail -f /dev/null
然后使用以下命令运行命令:
Then run the command with:
docker run -ti --rm podman:test bash -c "podman --storage-driver=vfs info"
这应该给您您期望的答复.
This should give you the response you expect.
这篇关于如何从容器内部运行podman?的文章就介绍到这了,希望我们推荐的答案对大家有所帮助,也希望大家多多支持IT屋!