diff --git a/source/clear-linux/tutorials/docker/docker.rst b/source/clear-linux/tutorials/docker/docker.rst index 2312f240..32b1b4d0 100644 --- a/source/clear-linux/tutorials/docker/docker.rst +++ b/source/clear-linux/tutorials/docker/docker.rst @@ -3,16 +3,18 @@ Docker* on |CL| ###################################################### -|CLOSIA| supports many containerization platforms, including Docker*. |CL| has many `unique features`_ including a minimal default installation +|CLOSIA| supports many containerization platforms, including Docker*. +|CL| has many `unique features`_ including a minimal default installation which makes it compelling to use as a host for container management, orchestration, and workloads. This tutorial will go over: #. Installing the required bundle for Docker +#. Integration with Kata Containers (optional) #. Additional Docker* configuration on |CL| #. Pulling and Running an image from Docker* Hub -#. Integration with Kata Containers + @@ -27,18 +29,23 @@ Prerequisites * You have a basic understanding of Linux and Docker. -* You have successfully installed :ref:`Clear Linux on bare metal` - -* Your |CL| installation has transparent network access to the Internet. If you are behind a HTTP proxy server, in a corporate setting for example, please refer to the `Docker* proxy instructions`_ . - +* You have successfully installed + :ref:`Clear Linux on bare metal` +* Your |CL| installation has transparent network access to the Internet. + If you are behind a HTTP proxy server, in a corporate setting for example, + please refer to the `Docker* proxy instructions`_ . + | + | + | Installing the required bundle =============================== -Software in Clear Linux is offered in the form of `bundles`_ to provide a complete function. +Software in Clear Linux is offered in the form +of `bundles`_ to provide a complete function. The *containers-basic* provides all the required software packages to run Docker images as containers. #. First, install the *containers-basic* bundle by running this :command:`swupd` command: @@ -62,7 +69,8 @@ The *containers-basic* provides all the required software packages to run Docker sudo systemctl enable docker -#. Finally, verify :command:`docker` has been installed by running this command and checking the version output for both *client* and *server*: +#. Finally, verify :command:`docker` has been installed by running this + command and checking the version output for both *client* and *server*: .. code-block:: bash @@ -71,13 +79,53 @@ The *containers-basic* provides all the required software packages to run Docker Congratulations! At this point, you have a working installation of Docker* on |CL| and are ready to start using container images on your system. + | + | + | + + +Integration with Kata Containers (optional) +================================ +`Kata Containers`_, formerly known as Intel Clear Containers, is an open source project aiming to increase security of containers by using lightweight virtual machine technology. +The Docker* package from |CL| will automatically use the runtime required for Kata Containers if it is available on your Clear Linux system. + +#. You can take advantage of Kata Containers in |CL| by simply installing the *containers-virt* bundle by running the command below: + + .. code-block:: bash + + sudo swupd bundle-add containers-virt + +#. Restart the Docker* daemon through systemd manager by running this command: + + .. code-block:: bash + + sudo systemctl restart docker + +#. After restarting, the Docker* daemon will seamlessly use katacontainers to launch containers. The default runtime for Docker containers is *runc*. You can see the runtime has changed to :command:`cc-runtime` by running this command: + + .. code-block:: bash + + sudo docker info | grep Runtime + +#. You should see the following output indicating the *cc-runtime* is the Default Runtime: + + .. code-block:: bash + + Runtimes: cc-runtime runc + Default Runtime: cc-runtime + +Congratulations! At this point, you have successfully replaced the default container runtime with Kata. + +| +| +| + .. note:: The proceeding sections of this tutorial are standard to Docker* setup and configuration. If you are familiar with Docker basics, you do not need to continue reading. The following sections are provided here for sake of completeness. - Additional Docker configuration =============================== @@ -91,7 +139,7 @@ Additional Docker* daemon configuration done can be via a configuration file typ touch /etc/docker/daemon.json -Refer to the `Docker daemon configuration documentation`_ for the full list of available configuration options and examples. + Refer to the `Docker* daemon configuration documentation`_ for the full list of available configuration options and examples. #. Once you've made any required changes, be sure to restart the Docker* daemon through systemd manager by running this command: @@ -100,6 +148,10 @@ Refer to the `Docker daemon configuration documentation`_ for the full list of a sudo systemctl restart docker + | + | + | + Pulling and Running an image from Docker* Hub ========================== @@ -111,6 +163,7 @@ Pulling and Running an image from Docker* Hub sudo docker pull nginx + #. Create and launch a new container using the :command:`docker run` command. Launch a nginx container by running this command: .. code-block:: bash @@ -119,7 +172,7 @@ Pulling and Running an image from Docker* Hub .. note:: - Below is an explaination of switches used in the command above. For detailed :command:`docker run` switches and syntax, refer to the `Docker Documentation`_ . + Below is an explaination of switches used in the command above. For detailed :command:`docker run` switches and syntax, refer to the `Docker* Documentation`_ . The :option:`--name` switch lets you provide a friendly name to target the container for future operations @@ -135,52 +188,27 @@ Pulling and Running an image from Docker* Hub curl 127.0.0.1:8080 -# Finally, stop and delete the nginx container by running the :command:`docker stop` and :command:`docker rm` commands. +#. Finally, stop and delete the nginx container by running the :command:`docker stop` and :command:`docker rm` commands. .. code-block:: bash sudo docker stop test-nginx sudo docker rm test-nginx + Congratulations! At this point, you have successfully pulled a nginx container image from `DockerHub`_ and ran an example container. + + | + | + | -Integration with Kata Containers -================================ -`Kata Containers`_, formerly known as Intel Clear Containers, is an open source project aiming to increase security of containers by using lightweight virtual machine technology. -You can take advantage of Kata Containers in |CL| by simply installing the *containers-virt* bundle by running the command below: - .. code-block:: bash - - sudo swupd bundle-add containers-virt - -Restart the Docker* daemon through systemd manager by running this command: - - .. code-block:: bash - - sudo systemctl restart docker - -After restarting, the Docker daemon will seamlessly use katacontainers to launch containers. The default runtime for Docker containers is *runc*. -You can see the runtime has changed to :command:`cc-runtime` by running this command: - - .. code-block:: bash - - sudo docker info | grep Runtime - -You should see the following output indicating the *cc-runtime* is the Default Runtime: - - .. code-block:: bash - - Runtimes: cc-runtime runc - Default Runtime: cc-runtime - -Congratulations! At this point, you have successfully replaced the default container runtime with Kata. -You can repeat the steps from :ref:`Pulling and Running an image from Docker* Hub` without changing anything special. Also see: ========= -* `Docker Home`_ -* `Docker Documentation`_ +* `Docker* Home`_ +* `Docker* Documentation`_ * `DockerHub`_ * `Kata Containers`_ @@ -190,11 +218,11 @@ Also see: .. _`unique features`: https://clearlinux.org/features .. _`DockerHub image`: https://hub.docker.com/_/clearlinux/ .. _`building a custom Clear Linux docker image`: https://clearlinux.org/documentation/clear-linux/guides/network/custom-clear-container -.. _`Docker proxy instructions`: https://docs.docker.com/config/daemon/systemd/#httphttps-proxy +.. _`Docker* proxy instructions`: https://docs.docker.com/config/daemon/systemd/#httphttps-proxy .. _`bundles`: https://clearlinux.org/documentation/clear-linux/concepts/bundles-about#related-concepts .. _`stateless system`: https://clearlinux.org/features/stateless .. _`Docker daemon configuration documentation`: https://docs.docker.com/engine/reference/commandline/dockerd/#daemon-configuration-file .. _`Kata Containers`: https://katacontainers.io/ -.. _`Docker Home`: https://www.docker.com/ -.. _`Docker Documentation`: https://docs.docker.com/ +.. _`Docker* Home`: https://www.docker.com/ +.. _`Docker* Documentation`: https://docs.docker.com/ .. _`DockerHub`: https://hub.docker.com/ \ No newline at end of file