mirror of
https://github.com/clearlinux/docker.git
synced 2026-08-19 20:26:54 +00:00
Compare commits
267 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 990021ac2b | |||
| 41d405fa53 | |||
| 8d06bfc12e | |||
| 98ea12ac38 | |||
| 7ba8788919 | |||
| 986a151b8a | |||
| abda245ddc | |||
| 4ad5af81c8 | |||
| 707ef9618b | |||
| d31ae5aed8 | |||
| b4857dffa8 | |||
| 2eac1c4bc5 | |||
| bdf4b74b52 | |||
| 346a350df4 | |||
| 181e54bff3 | |||
| 874698cb4a | |||
| a57298791c | |||
| 7303467c77 | |||
| 7b1f34d626 | |||
| cf331cdd6a | |||
| b1c114c3a7 | |||
| b13cdb01bd | |||
| f619243099 | |||
| a841152069 | |||
| 30313cacce | |||
| 8646bf4a40 | |||
| 421707f638 | |||
| a790d3309c | |||
| df217f5377 | |||
| c60d178ad0 | |||
| b132e7b36d | |||
| 1ca7964cdd | |||
| 3e2a9f667f | |||
| 7a0e599142 | |||
| 381050b1ee | |||
| f3db32c035 | |||
| d803523cdc | |||
| 443d923f08 | |||
| 586e72218c | |||
| 98041d26bb | |||
| 48907d57ed | |||
| 5c069940db | |||
| 65d4047cb6 | |||
| def86d0cf4 | |||
| c4c92e66cd | |||
| 7c52ab7f83 | |||
| 40b55a4174 | |||
| f53b922f40 | |||
| f08cd445b0 | |||
| d9d08c5ef5 | |||
| 331ae9c0f8 | |||
| 4195fc0494 | |||
| ffe3ae7bfb | |||
| 2294294e19 | |||
| cc96d31252 | |||
| 0c5d9626b8 | |||
| 438d26b405 | |||
| 42fe9327b9 | |||
| 6b352d1cfe | |||
| f0ec901819 | |||
| 04bfa8e91f | |||
| d0fe1147ea | |||
| ec0fb311ed | |||
| 4dcf4e9bd0 | |||
| 3336bdf5b5 | |||
| ba4ae2c46d | |||
| 092826152c | |||
| c7fdd51eb6 | |||
| 661a1e9026 | |||
| 3807f8b708 | |||
| 9e2cc4fcd9 | |||
| 698ded75b9 | |||
| 4902f047d3 | |||
| d0c4e44863 | |||
| cc42eeac21 | |||
| 52edbe6a23 | |||
| d4ec4d6e9b | |||
| 207d7807af | |||
| bf9482987f | |||
| 0ba7f934ee | |||
| 087acccf0c | |||
| cac97b6bd8 | |||
| e278082c21 | |||
| 690711b584 | |||
| 1c8ec01c55 | |||
| 2ed8b22099 | |||
| 1e0e86360f | |||
| 2629e2ec23 | |||
| 08a10f936b | |||
| d3023f25f5 | |||
| f1d7ed35bd | |||
| 62d97afaf8 | |||
| 686786f107 | |||
| c5b82f5e8d | |||
| c44c98edec | |||
| da327c8fa3 | |||
| 21849f1a21 | |||
| 5e8402568e | |||
| 7e9fbbba1c | |||
| 2c5405f699 | |||
| b3e80c6935 | |||
| 742d8bf922 | |||
| 8f6162f17b | |||
| d5f7b4df1b | |||
| 95ca361df6 | |||
| 4e2cf53f4f | |||
| d671768b52 | |||
| 69a1f53e70 | |||
| 8ae966de75 | |||
| ed5054389a | |||
| 7a7bb43db5 | |||
| 03ae463c8d | |||
| a6ce867e48 | |||
| aab9078ff9 | |||
| 4e20407d82 | |||
| 1c05ddd645 | |||
| f83c873d8b | |||
| 41d437117d | |||
| 7085ec875f | |||
| 2b468dc283 | |||
| 8df0b12d82 | |||
| 50d49d0db8 | |||
| 50fde602a1 | |||
| 8ca34e4b5e | |||
| 520163a00e | |||
| 0b97725340 | |||
| 4adab34dfa | |||
| be9dcbbef5 | |||
| c4327f7146 | |||
| c0c58b6b46 | |||
| 947405a909 | |||
| 93bf556f13 | |||
| e9f1f760f2 | |||
| cb92c47144 | |||
| d561fe6d2d | |||
| c40602b254 | |||
| 1a441d9aea | |||
| 821d3aab65 | |||
| 073382a9c6 | |||
| 77b09a6a19 | |||
| 65567e125d | |||
| 27b2d7ff72 | |||
| eb97163348 | |||
| 7b366b1f01 | |||
| 52e88d92f0 | |||
| 51b188c510 | |||
| 8091157038 | |||
| d871725cf2 | |||
| f9f6379a53 | |||
| 15243cdbde | |||
| f5979b9d0d | |||
| 9494643bf1 | |||
| a8d6d28be4 | |||
| fbf7815b25 | |||
| 784a008346 | |||
| 0bdadfe4e7 | |||
| dbee7dd69e | |||
| 3b9e8679db | |||
| cb47ddd968 | |||
| 4ccd91f0d8 | |||
| c99ee556d4 | |||
| 6cb16f1c31 | |||
| f411f8bfc5 | |||
| 37115ffb00 | |||
| 384b60b940 | |||
| 9ac293e1a8 | |||
| 6c953a3059 | |||
| 8f909221f5 | |||
| 96c03d6d92 | |||
| a092f979d4 | |||
| a1b7a35c90 | |||
| fa7c8d523e | |||
| 0b3fe55442 | |||
| db00e224c2 | |||
| b1bae92534 | |||
| a247af9c97 | |||
| d1757c005f | |||
| 8194556337 | |||
| 8a8b6d7964 | |||
| 4cf40c968f | |||
| cb40e3302e | |||
| 9a7bd6d95b | |||
| 9254a62cd6 | |||
| b83a171f9e | |||
| 5ff3a28cb4 | |||
| a7b60b21de | |||
| 53802d54d6 | |||
| 7ab1a90e59 | |||
| fb2ac5bedb | |||
| bae6a5a616 | |||
| 6158ccad97 | |||
| 052ad32a7b | |||
| cacb5c0dde | |||
| e827c8ff61 | |||
| fd32fc8062 | |||
| faf5ef6f80 | |||
| 07e9ac9ffe | |||
| d9939758e6 | |||
| 5dc6339e33 | |||
| 875d0b776d | |||
| e2fce7d612 | |||
| 135ced208c | |||
| 871299de0d | |||
| 11fee48c2d | |||
| 3b0ae3ec68 | |||
| 9e2e8188ae | |||
| 9bc75d008e | |||
| a43cebf088 | |||
| 83b446492c | |||
| 4fd9cc9980 | |||
| 63fe64c471 | |||
| 9722c66dad | |||
| b0a46d1cb9 | |||
| e570987c4f | |||
| c740c76017 | |||
| 744d39a466 | |||
| 23cc3e5c63 | |||
| e975687b9a | |||
| c37b4828dd | |||
| 23bdb3b3a6 | |||
| bb7baf1835 | |||
| 4dc5315e3b | |||
| 7842630480 | |||
| d87fdaa1e3 | |||
| ef364f7e1f | |||
| c9f216d2fa | |||
| b737837882 | |||
| 3cb59c5140 | |||
| 55d645246a | |||
| 90251a488d | |||
| f72a31ae31 | |||
| 8e851aaa27 | |||
| fa7946a510 | |||
| faeede0200 | |||
| 862d3eb284 | |||
| 8ac4261263 | |||
| 8349e282a9 | |||
| 2337f52999 | |||
| 1ecb170352 | |||
| d6c494671f | |||
| 5b85dc3584 | |||
| 752c3e9208 | |||
| 7992fb5911 | |||
| 38daa47ee2 | |||
| 5f9a673025 | |||
| 4a3b36f443 | |||
| 1151f9ef9e | |||
| 31e8993d57 | |||
| 259d714b93 | |||
| 8f99875d03 | |||
| cfd209fd6e | |||
| 8baafacf40 | |||
| a2c08792f0 | |||
| fa72eb3a58 | |||
| 39320f9393 | |||
| 94dc07c044 | |||
| daa89c420c | |||
| f7e4546af0 | |||
| a59e1949b5 | |||
| 0c611d9b15 | |||
| e2119f3050 | |||
| 92f46d233e | |||
| 5d07362a84 | |||
| c95f77866c | |||
| c624caa949 | |||
| 249524ec49 | |||
| 6854e2997e |
@@ -1,8 +1,37 @@
|
||||
# Changelog
|
||||
|
||||
## 1.0.1 (2014-06-19)
|
||||
|
||||
#### Notable features since 1.0.0
|
||||
* Enhance security for the LXC driver
|
||||
|
||||
#### Builder
|
||||
* Fix `ONBUILD` instruction passed to grandchildren
|
||||
|
||||
#### Runtime
|
||||
* Fix events subscription
|
||||
* Fix /etc/hostname file with host networking
|
||||
* Allow `-h` and `--net=none`
|
||||
* Fix issue with hotplug devices in `--privileged`
|
||||
|
||||
#### Client
|
||||
* Fix artifacts with events
|
||||
* Fix a panic with empty flags
|
||||
* Fix `docker cp` on Mac OS X
|
||||
|
||||
#### Miscellaneous
|
||||
* Fix compilation on Mac OS X
|
||||
* Fix several races
|
||||
|
||||
## 1.0.0 (2014-06-09)
|
||||
|
||||
#### Notable features since 0.12.0
|
||||
* Production support
|
||||
|
||||
## 0.12.0 (2014-06-05)
|
||||
|
||||
#### Notable features since 0.11.0
|
||||
* 40+ various improvements to stability, performance and usability
|
||||
* New `COPY` Dockerfile instruction to allow copying a local file from the context into the container without ever extracting if the file is a tar file
|
||||
* Inherit file permissions from the host on `ADD`
|
||||
* New `pause` and `unpause` commands to allow pausing and unpausing of containers using cgroup freezer
|
||||
|
||||
@@ -1,5 +1,4 @@
|
||||
Solomon Hykes <solomon@docker.com> (@shykes)
|
||||
Guillaume J. Charmes <guillaume@docker.com> (@creack)
|
||||
Victor Vieux <vieux@docker.com> (@vieux)
|
||||
Michael Crosby <michael@crosbymichael.com> (@crosbymichael)
|
||||
.mailmap: Tianon Gravi <admwiggin@gmail.com> (@tianon)
|
||||
|
||||
@@ -18,7 +18,13 @@ It benefits directly from the experience accumulated over several years
|
||||
of large-scale operation and support of hundreds of thousands of
|
||||
applications and databases.
|
||||
|
||||

|
||||

|
||||
|
||||
## Security Disclosure
|
||||
|
||||
Security is very important to us. If you have any issue regarding security,
|
||||
please disclose the information responsibly by sending an email to
|
||||
security@docker.com and not by creating a github issue.
|
||||
|
||||
## Better than VMs
|
||||
|
||||
@@ -142,11 +148,10 @@ Docker can be installed on your local machine as well as servers - both
|
||||
bare metal and virtualized. It is available as a binary on most modern
|
||||
Linux systems, or as a VM on Windows, Mac and other systems.
|
||||
|
||||
We also offer an interactive tutorial for quickly learning the basics of
|
||||
using Docker.
|
||||
We also offer an [interactive tutorial](http://www.docker.com/tryit/)
|
||||
for quickly learning the basics of using Docker.
|
||||
|
||||
For up-to-date install instructions and online tutorials, see the
|
||||
[Getting Started page](http://www.docker.io/gettingstarted/).
|
||||
For up-to-date install instructions, see the [Docs](http://docs.docker.com).
|
||||
|
||||
Usage examples
|
||||
==============
|
||||
|
||||
@@ -89,25 +89,6 @@ func (cli *DockerCli) CmdHelp(args ...string) error {
|
||||
return nil
|
||||
}
|
||||
|
||||
// FIXME: 'insert' is deprecated.
|
||||
func (cli *DockerCli) CmdInsert(args ...string) error {
|
||||
fmt.Fprintf(os.Stderr, "Warning: '%s' is deprecated and will be removed in a future version. Please use 'docker build' and 'ADD' instead.\n")
|
||||
cmd := cli.Subcmd("insert", "IMAGE URL PATH", "Insert a file from URL in the IMAGE at PATH")
|
||||
if err := cmd.Parse(args); err != nil {
|
||||
return nil
|
||||
}
|
||||
if cmd.NArg() != 3 {
|
||||
cmd.Usage()
|
||||
return nil
|
||||
}
|
||||
|
||||
v := url.Values{}
|
||||
v.Set("url", cmd.Arg(1))
|
||||
v.Set("path", cmd.Arg(2))
|
||||
|
||||
return cli.stream("POST", "/images/"+cmd.Arg(0)+"/insert?"+v.Encode(), nil, cli.out, nil)
|
||||
}
|
||||
|
||||
func (cli *DockerCli) CmdBuild(args ...string) error {
|
||||
cmd := cli.Subcmd("build", "[OPTIONS] PATH | URL | -", "Build a new image from the source code at PATH")
|
||||
tag := cmd.String([]string{"t", "-tag"}, "", "Repository name (and optionally a tag) to be applied to the resulting image in case of success")
|
||||
|
||||
+1
-1
@@ -105,7 +105,7 @@ func (cli *DockerCli) call(method, path string, data interface{}, passAuthInfo b
|
||||
if len(body) == 0 {
|
||||
return nil, resp.StatusCode, fmt.Errorf("Error: request returned %s for API route and version %s, check if the server supports the requested API version", http.StatusText(resp.StatusCode), req.URL)
|
||||
}
|
||||
return nil, resp.StatusCode, fmt.Errorf("Error: %s", bytes.TrimSpace(body))
|
||||
return nil, resp.StatusCode, fmt.Errorf("Error response from daemon: %s", bytes.TrimSpace(body))
|
||||
}
|
||||
return resp.Body, resp.StatusCode, nil
|
||||
}
|
||||
|
||||
@@ -398,7 +398,7 @@ func getContainersLogs(eng *engine.Engine, version version.Version, w http.Respo
|
||||
job.Stdout.Add(outStream)
|
||||
job.Stderr.Set(errStream)
|
||||
if err := job.Run(); err != nil {
|
||||
fmt.Fprintf(outStream, "Error: %s\n", err)
|
||||
fmt.Fprintf(outStream, "Error running logs job: %s\n", err)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
@@ -811,7 +811,7 @@ func postContainersAttach(eng *engine.Engine, version version.Version, w http.Re
|
||||
job.Stdout.Add(outStream)
|
||||
job.Stderr.Set(errStream)
|
||||
if err := job.Run(); err != nil {
|
||||
fmt.Fprintf(outStream, "Error: %s\n", err)
|
||||
fmt.Fprintf(outStream, "Error attaching: %s\n", err)
|
||||
|
||||
}
|
||||
return nil
|
||||
@@ -841,7 +841,7 @@ func wsContainersAttach(eng *engine.Engine, version version.Version, w http.Resp
|
||||
job.Stdout.Add(ws)
|
||||
job.Stderr.Set(ws)
|
||||
if err := job.Run(); err != nil {
|
||||
utils.Errorf("Error: %s", err)
|
||||
utils.Errorf("Error attaching websocket: %s", err)
|
||||
}
|
||||
})
|
||||
h.ServeHTTP(w, r)
|
||||
@@ -1022,7 +1022,7 @@ func makeHttpHandler(eng *engine.Engine, logging bool, localMethod string, local
|
||||
}
|
||||
|
||||
if err := handlerFunc(eng, version, w, r, mux.Vars(r)); err != nil {
|
||||
utils.Errorf("Error: %s", err)
|
||||
utils.Errorf("Error making handler: %s", err)
|
||||
httpError(w, err)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -114,6 +114,43 @@ func TestGetInfo(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestGetContainersByName(t *testing.T) {
|
||||
eng := engine.New()
|
||||
name := "container_name"
|
||||
var called bool
|
||||
eng.Register("container_inspect", func(job *engine.Job) engine.Status {
|
||||
called = true
|
||||
if job.Args[0] != name {
|
||||
t.Fatalf("name != '%s': %#v", name, job.Args[0])
|
||||
}
|
||||
if api.APIVERSION.LessThan("1.12") && !job.GetenvBool("dirty") {
|
||||
t.Fatal("dirty env variable not set")
|
||||
} else if api.APIVERSION.GreaterThanOrEqualTo("1.12") && job.GetenvBool("dirty") {
|
||||
t.Fatal("dirty env variable set when it shouldn't")
|
||||
}
|
||||
v := &engine.Env{}
|
||||
v.SetBool("dirty", true)
|
||||
if _, err := v.WriteTo(job.Stdout); err != nil {
|
||||
return job.Error(err)
|
||||
}
|
||||
return engine.StatusOK
|
||||
})
|
||||
r := serveRequest("GET", "/containers/"+name+"/json", nil, eng, t)
|
||||
if !called {
|
||||
t.Fatal("handler was not called")
|
||||
}
|
||||
if r.HeaderMap.Get("Content-Type") != "application/json" {
|
||||
t.Fatalf("%#v\n", r)
|
||||
}
|
||||
var stdoutJson interface{}
|
||||
if err := json.Unmarshal(r.Body.Bytes(), &stdoutJson); err != nil {
|
||||
t.Fatalf("%#v", err)
|
||||
}
|
||||
if stdoutJson.(map[string]interface{})["dirty"].(float64) != 1 {
|
||||
t.Fatalf("%#v", stdoutJson)
|
||||
}
|
||||
}
|
||||
|
||||
func serveRequest(method, target string, body io.Reader, eng *engine.Engine, t *testing.T) *httptest.ResponseRecorder {
|
||||
r := httptest.NewRecorder()
|
||||
req, err := http.NewRequest(method, target, body)
|
||||
|
||||
+2
-2
@@ -262,11 +262,11 @@ func createTarFile(path, extractDir string, hdr *tar.Header, reader io.Reader, L
|
||||
ts := []syscall.Timespec{timeToTimespec(hdr.AccessTime), timeToTimespec(hdr.ModTime)}
|
||||
// syscall.UtimesNano doesn't support a NOFOLLOW flag atm, and
|
||||
if hdr.Typeflag != tar.TypeSymlink {
|
||||
if err := system.UtimesNano(path, ts); err != nil {
|
||||
if err := system.UtimesNano(path, ts); err != nil && err != system.ErrNotSupportedPlatform {
|
||||
return err
|
||||
}
|
||||
} else {
|
||||
if err := system.LUtimesNano(path, ts); err != nil {
|
||||
if err := system.LUtimesNano(path, ts); err != nil && err != system.ErrNotSupportedPlatform {
|
||||
return err
|
||||
}
|
||||
}
|
||||
|
||||
@@ -164,6 +164,6 @@ func TestUntarUstarGnuConflict(t *testing.T) {
|
||||
}
|
||||
}
|
||||
if !found {
|
||||
t.Fatal("%s not found in the archive", "root/.cpanm/work/1395823785.24209/Plack-1.0030/blib/man3/Plack::Middleware::LighttpdScriptNameFix.3pm")
|
||||
t.Fatalf("%s not found in the archive", "root/.cpanm/work/1395823785.24209/Plack-1.0030/blib/man3/Plack::Middleware::LighttpdScriptNameFix.3pm")
|
||||
}
|
||||
}
|
||||
|
||||
@@ -59,7 +59,7 @@ func daemon(eng *engine.Engine) error {
|
||||
// builtins jobs independent of any subsystem
|
||||
func dockerVersion(job *engine.Job) engine.Status {
|
||||
v := &engine.Env{}
|
||||
v.Set("Version", dockerversion.VERSION)
|
||||
v.SetJson("Version", dockerversion.VERSION)
|
||||
v.SetJson("ApiVersion", api.APIVERSION)
|
||||
v.Set("GitCommit", dockerversion.GITCOMMIT)
|
||||
v.Set("GoVersion", runtime.Version())
|
||||
|
||||
@@ -100,7 +100,7 @@ echo
|
||||
echo 'Generally Necessary:'
|
||||
|
||||
echo -n '- '
|
||||
cgroupSubsystemDir="$(awk '/[, ](cpu|cpuacct|cpuset|devices|freezer|memory)([, ]|$)/ && $8 == "cgroup" { print $5 }' /proc/$$/mountinfo | head -n1)"
|
||||
cgroupSubsystemDir="$(awk '/[, ](cpu|cpuacct|cpuset|devices|freezer|memory)[, ]/ && $3 == "cgroup" { print $2 }' /proc/mounts | head -n1)"
|
||||
cgroupDir="$(dirname "$cgroupSubsystemDir")"
|
||||
if [ -d "$cgroupDir/cpu" -o -d "$cgroupDir/cpuacct" -o -d "$cgroupDir/cpuset" -o -d "$cgroupDir/devices" -o -d "$cgroupDir/freezer" -o -d "$cgroupDir/memory" ]; then
|
||||
echo "$(wrap_good 'cgroup hierarchy' 'properly mounted') [$cgroupDir]"
|
||||
@@ -116,7 +116,7 @@ fi
|
||||
flags=(
|
||||
NAMESPACES {NET,PID,IPC,UTS}_NS
|
||||
DEVPTS_MULTIPLE_INSTANCES
|
||||
CGROUPS CGROUP_CPUACCT CGROUP_DEVICE CGROUP_SCHED
|
||||
CGROUPS CGROUP_CPUACCT CGROUP_DEVICE CGROUP_FREEZER CGROUP_SCHED
|
||||
MACVLAN VETH BRIDGE
|
||||
NF_NAT_IPV4 IP_NF_TARGET_MASQUERADE
|
||||
NETFILTER_XT_MATCH_{ADDRTYPE,CONNTRACK}
|
||||
|
||||
@@ -309,14 +309,6 @@ _docker_info()
|
||||
return
|
||||
}
|
||||
|
||||
_docker_insert()
|
||||
{
|
||||
local counter=$(__docker_pos_first_nonflag)
|
||||
if [ $cword -eq $counter ]; then
|
||||
__docker_image_repos_and_tags_and_ids
|
||||
fi
|
||||
}
|
||||
|
||||
_docker_inspect()
|
||||
{
|
||||
case "$prev" in
|
||||
@@ -393,7 +385,7 @@ _docker_ps()
|
||||
{
|
||||
case "$prev" in
|
||||
--since|--before)
|
||||
__docker_containers_all
|
||||
__docker_containers_all
|
||||
;;
|
||||
-n)
|
||||
return
|
||||
@@ -438,9 +430,7 @@ _docker_push()
|
||||
{
|
||||
local counter=$(__docker_pos_first_nonflag)
|
||||
if [ $cword -eq $counter ]; then
|
||||
__docker_image_repos
|
||||
# TODO replace this with __docker_image_repos_and_tags
|
||||
# see https://github.com/dotcloud/docker/issues/3411
|
||||
__docker_image_repos_and_tags
|
||||
fi
|
||||
}
|
||||
|
||||
|
||||
@@ -120,10 +120,6 @@ complete -c docker -f -n '__fish_docker_no_subcommand' -a import -d 'Create a ne
|
||||
# info
|
||||
complete -c docker -f -n '__fish_docker_no_subcommand' -a info -d 'Display system-wide information'
|
||||
|
||||
# insert
|
||||
complete -c docker -f -n '__fish_docker_no_subcommand' -a insert -d 'Insert a file in an image'
|
||||
complete -c docker -A -f -n '__fish_seen_subcommand_from insert' -a '(__fish_print_docker_images)' -d "Image"
|
||||
|
||||
# inspect
|
||||
complete -c docker -f -n '__fish_docker_no_subcommand' -a inspect -d 'Return low-level information on a container'
|
||||
complete -c docker -A -f -n '__fish_seen_subcommand_from inspect' -s f -l format -d 'Format the output using the given go template.'
|
||||
|
||||
Executable → Regular
-5
@@ -139,11 +139,6 @@ __docker_subcommand () {
|
||||
(history)
|
||||
_arguments ':images:__docker_images'
|
||||
;;
|
||||
(insert)
|
||||
_arguments '1:containers:__docker_containers' \
|
||||
'2:URL:(http:// file://)' \
|
||||
'3:file:_files'
|
||||
;;
|
||||
(kill)
|
||||
_arguments '*:containers:__docker_runningcontainers'
|
||||
;;
|
||||
|
||||
@@ -38,7 +38,7 @@ A Dockerfile is similar to a Makefile.
|
||||
|
||||
**sudo docker build -t repository/tag .**
|
||||
-- specifies a repository and tag at which to save the new image if the build
|
||||
succeeds. The Docker daemon runs the steps one-by-one, commiting the result
|
||||
succeeds. The Docker daemon runs the steps one-by-one, committing the result
|
||||
to a new image if necessary before finally outputting the ID of the new
|
||||
image. The Docker daemon automatically cleans up the context it is given.
|
||||
|
||||
|
||||
@@ -26,9 +26,9 @@ An existing Fedora based container has had Apache installed while running
|
||||
in interactive mode with the bash shell. Apache is also running. To
|
||||
create a new image run docker ps to find the container's ID and then run:
|
||||
|
||||
# docker commit -me= "Added Apache to Fedora base image" \
|
||||
--a="A D Ministrator" 98bd7fc99854 fedora/fedora_httpd:20
|
||||
# docker commit -m= "Added Apache to Fedora base image" \
|
||||
-a="A D Ministrator" 98bd7fc99854 fedora/fedora_httpd:20
|
||||
|
||||
# HISTORY
|
||||
April 2014, Originally compiled by William Henry (whenry at redhat dot com)
|
||||
based on docker.io source material and in
|
||||
based on docker.io source material and in
|
||||
|
||||
@@ -20,7 +20,7 @@ seconds since epoch, or date string.
|
||||
## Listening for Docker events
|
||||
|
||||
After running docker events a container 786d698004576 is started and stopped
|
||||
(The container name has been shortened in the ouput below):
|
||||
(The container name has been shortened in the output below):
|
||||
|
||||
# docker events
|
||||
[2014-04-12 18:23:04 -0400 EDT] 786d69800457: (from whenry/testimage:latest) start
|
||||
@@ -43,4 +43,4 @@ Again the output container IDs have been shortened for the purposes of this docu
|
||||
|
||||
# HISTORY
|
||||
April 2014, Originally compiled by William Henry (whenry at redhat dot com)
|
||||
based on docker.io source material and internal work.
|
||||
based on docker.io source material and internal work.
|
||||
|
||||
@@ -5,17 +5,18 @@
|
||||
docker-pull - Pull an image or a repository from the registry
|
||||
|
||||
# SYNOPSIS
|
||||
**docker pull** NAME[:TAG]
|
||||
**docker pull** [REGISTRY_PATH/]NAME[:TAG]
|
||||
|
||||
# DESCRIPTION
|
||||
|
||||
This command pulls down an image or a repository from the registry. If
|
||||
there is more than one image for a repository (e.g. fedora) then all
|
||||
images for that repository name are pulled down including any tags.
|
||||
It is also possible to specify a non-default registry to pull from.
|
||||
|
||||
# EXAMPLE
|
||||
# EXAMPLES
|
||||
|
||||
# Pull a reposiotry with multiple images
|
||||
# Pull a repository with multiple images
|
||||
|
||||
$ sudo docker pull fedora
|
||||
Pulling repository fedora
|
||||
@@ -31,6 +32,19 @@ images for that repository name are pulled down including any tags.
|
||||
fedora heisenbug 105182bb5e8b 5 days ago 372.7 MB
|
||||
fedora latest 105182bb5e8b 5 days ago 372.7 MB
|
||||
|
||||
# Pull an image, manually specifying path to the registry and tag
|
||||
|
||||
$ sudo docker pull registry.hub.docker.com/fedora:20
|
||||
Pulling repository fedora
|
||||
3f2fed40e4b0: Download complete
|
||||
511136ea3c5a: Download complete
|
||||
fd241224e9cf: Download complete
|
||||
|
||||
$ sudo docker images
|
||||
REPOSITORY TAG IMAGE ID CREATED VIRTUAL SIZE
|
||||
fedora 20 3f2fed40e4b0 4 days ago 372.7 MB
|
||||
|
||||
|
||||
# HISTORY
|
||||
April 2014, Originally compiled by William Henry (whenry at redhat dot com)
|
||||
based on docker.io source material and internal work.
|
||||
|
||||
@@ -10,15 +10,15 @@ docker \- Docker image and container command line interface
|
||||
# DESCRIPTION
|
||||
**docker** has two distinct functions. It is used for starting the Docker
|
||||
daemon and to run the CLI (i.e., to command the daemon to manage images,
|
||||
containers etc.) So **docker** is both a server, as a deamon, and a client
|
||||
containers etc.) So **docker** is both a server, as a daemon, and a client
|
||||
to the daemon, through the CLI.
|
||||
|
||||
To run the Docker deamon you do not specify any of the commands listed below but
|
||||
To run the Docker daemon you do not specify any of the commands listed below but
|
||||
must specify the **-d** option. The other options listed below are for the
|
||||
daemon only.
|
||||
|
||||
The Docker CLI has over 30 commands. The commands are listed below and each has
|
||||
its own man page which explain usage and arguements.
|
||||
its own man page which explain usage and arguments.
|
||||
|
||||
To see the man page for a command run **man docker <command>**.
|
||||
|
||||
|
||||
@@ -13,7 +13,7 @@ for FILE in *.md; do
|
||||
base="$(basename "$FILE")"
|
||||
name="${base%.md}"
|
||||
num="${name##*.}"
|
||||
if [ -z "$num" -o "$base" = "$num" ]; then
|
||||
if [ -z "$num" -o "$name" = "$num" ]; then
|
||||
# skip files that aren't of the format xxxx.N.md (like README.md)
|
||||
continue
|
||||
fi
|
||||
|
||||
@@ -12,7 +12,7 @@
|
||||
<array>
|
||||
<dict>
|
||||
<key>match</key>
|
||||
<string>^\s*(ONBUILD\s+)?(FROM|MAINTAINER|RUN|EXPOSE|ENV|ADD|VOLUME|USER|WORKDIR)\s</string>
|
||||
<string>^\s*(ONBUILD\s+)?(FROM|MAINTAINER|RUN|EXPOSE|ENV|ADD|VOLUME|USER|WORKDIR|COPY)\s</string>
|
||||
<key>captures</key>
|
||||
<dict>
|
||||
<key>0</key>
|
||||
|
||||
@@ -11,7 +11,7 @@ let b:current_syntax = "dockerfile"
|
||||
|
||||
syntax case ignore
|
||||
|
||||
syntax match dockerfileKeyword /\v^\s*(ONBUILD\s+)?(ADD|CMD|ENTRYPOINT|ENV|EXPOSE|FROM|MAINTAINER|RUN|USER|VOLUME|WORKDIR)\s/
|
||||
syntax match dockerfileKeyword /\v^\s*(ONBUILD\s+)?(ADD|CMD|ENTRYPOINT|ENV|EXPOSE|FROM|MAINTAINER|RUN|USER|VOLUME|WORKDIR|COPY)\s/
|
||||
highlight link dockerfileKeyword Keyword
|
||||
|
||||
syntax region dockerfileString start=/\v"/ skip=/\v\\./ end=/\v"/
|
||||
|
||||
+101
-33
@@ -15,6 +15,8 @@ import (
|
||||
"syscall"
|
||||
"time"
|
||||
|
||||
"github.com/docker/libcontainer/devices"
|
||||
"github.com/docker/libcontainer/label"
|
||||
"github.com/dotcloud/docker/archive"
|
||||
"github.com/dotcloud/docker/daemon/execdriver"
|
||||
"github.com/dotcloud/docker/daemon/graphdriver"
|
||||
@@ -22,8 +24,6 @@ import (
|
||||
"github.com/dotcloud/docker/image"
|
||||
"github.com/dotcloud/docker/links"
|
||||
"github.com/dotcloud/docker/nat"
|
||||
"github.com/dotcloud/docker/pkg/label"
|
||||
"github.com/dotcloud/docker/pkg/libcontainer/devices"
|
||||
"github.com/dotcloud/docker/pkg/networkfs/etchosts"
|
||||
"github.com/dotcloud/docker/pkg/networkfs/resolvconf"
|
||||
"github.com/dotcloud/docker/pkg/symlink"
|
||||
@@ -85,7 +85,12 @@ type Container struct {
|
||||
}
|
||||
|
||||
func (container *Container) FromDisk() error {
|
||||
data, err := ioutil.ReadFile(container.jsonPath())
|
||||
pth, err := container.jsonPath()
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
data, err := ioutil.ReadFile(pth)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
@@ -101,15 +106,22 @@ func (container *Container) FromDisk() error {
|
||||
return container.readHostConfig()
|
||||
}
|
||||
|
||||
func (container *Container) ToDisk() (err error) {
|
||||
func (container *Container) ToDisk() error {
|
||||
data, err := json.Marshal(container)
|
||||
if err != nil {
|
||||
return
|
||||
return err
|
||||
}
|
||||
err = ioutil.WriteFile(container.jsonPath(), data, 0666)
|
||||
|
||||
pth, err := container.jsonPath()
|
||||
if err != nil {
|
||||
return
|
||||
return err
|
||||
}
|
||||
|
||||
err = ioutil.WriteFile(pth, data, 0666)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
return container.WriteHostConfig()
|
||||
}
|
||||
|
||||
@@ -118,33 +130,45 @@ func (container *Container) readHostConfig() error {
|
||||
// If the hostconfig file does not exist, do not read it.
|
||||
// (We still have to initialize container.hostConfig,
|
||||
// but that's OK, since we just did that above.)
|
||||
_, err := os.Stat(container.hostConfigPath())
|
||||
pth, err := container.hostConfigPath()
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
_, err = os.Stat(pth)
|
||||
if os.IsNotExist(err) {
|
||||
return nil
|
||||
}
|
||||
data, err := ioutil.ReadFile(container.hostConfigPath())
|
||||
|
||||
data, err := ioutil.ReadFile(pth)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
return json.Unmarshal(data, container.hostConfig)
|
||||
}
|
||||
|
||||
func (container *Container) WriteHostConfig() (err error) {
|
||||
func (container *Container) WriteHostConfig() error {
|
||||
data, err := json.Marshal(container.hostConfig)
|
||||
if err != nil {
|
||||
return
|
||||
return err
|
||||
}
|
||||
return ioutil.WriteFile(container.hostConfigPath(), data, 0666)
|
||||
|
||||
pth, err := container.hostConfigPath()
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
return ioutil.WriteFile(pth, data, 0666)
|
||||
}
|
||||
|
||||
func (container *Container) getResourcePath(path string) string {
|
||||
func (container *Container) getResourcePath(path string) (string, error) {
|
||||
cleanPath := filepath.Join("/", path)
|
||||
return filepath.Join(container.basefs, cleanPath)
|
||||
return symlink.FollowSymlinkInScope(filepath.Join(container.basefs, cleanPath), container.basefs)
|
||||
}
|
||||
|
||||
func (container *Container) getRootResourcePath(path string) string {
|
||||
func (container *Container) getRootResourcePath(path string) (string, error) {
|
||||
cleanPath := filepath.Join("/", path)
|
||||
return filepath.Join(container.root, cleanPath)
|
||||
return symlink.FollowSymlinkInScope(filepath.Join(container.root, cleanPath), container.root)
|
||||
}
|
||||
|
||||
func populateCommand(c *Container, env []string) error {
|
||||
@@ -324,7 +348,12 @@ func (container *Container) StderrLogPipe() io.ReadCloser {
|
||||
}
|
||||
|
||||
func (container *Container) buildHostnameFile() error {
|
||||
container.HostnamePath = container.getRootResourcePath("hostname")
|
||||
hostnamePath, err := container.getRootResourcePath("hostname")
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
container.HostnamePath = hostnamePath
|
||||
|
||||
if container.Config.Domainname != "" {
|
||||
return ioutil.WriteFile(container.HostnamePath, []byte(fmt.Sprintf("%s.%s\n", container.Config.Hostname, container.Config.Domainname)), 0644)
|
||||
}
|
||||
@@ -336,7 +365,11 @@ func (container *Container) buildHostnameAndHostsFiles(IP string) error {
|
||||
return err
|
||||
}
|
||||
|
||||
container.HostsPath = container.getRootResourcePath("hosts")
|
||||
hostsPath, err := container.getRootResourcePath("hosts")
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
container.HostsPath = hostsPath
|
||||
|
||||
extraContent := make(map[string]string)
|
||||
|
||||
@@ -681,19 +714,23 @@ func (container *Container) Unmount() error {
|
||||
return container.daemon.Unmount(container)
|
||||
}
|
||||
|
||||
func (container *Container) logPath(name string) string {
|
||||
func (container *Container) logPath(name string) (string, error) {
|
||||
return container.getRootResourcePath(fmt.Sprintf("%s-%s.log", container.ID, name))
|
||||
}
|
||||
|
||||
func (container *Container) ReadLog(name string) (io.Reader, error) {
|
||||
return os.Open(container.logPath(name))
|
||||
pth, err := container.logPath(name)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
return os.Open(pth)
|
||||
}
|
||||
|
||||
func (container *Container) hostConfigPath() string {
|
||||
func (container *Container) hostConfigPath() (string, error) {
|
||||
return container.getRootResourcePath("hostconfig.json")
|
||||
}
|
||||
|
||||
func (container *Container) jsonPath() string {
|
||||
func (container *Container) jsonPath() (string, error) {
|
||||
return container.getRootResourcePath("config.json")
|
||||
}
|
||||
|
||||
@@ -756,8 +793,7 @@ func (container *Container) Copy(resource string) (io.ReadCloser, error) {
|
||||
|
||||
var filter []string
|
||||
|
||||
resPath := container.getResourcePath(resource)
|
||||
basePath, err := symlink.FollowSymlinkInScope(resPath, container.basefs)
|
||||
basePath, err := container.getResourcePath(resource)
|
||||
if err != nil {
|
||||
container.Unmount()
|
||||
return nil, err
|
||||
@@ -808,11 +844,16 @@ func (container *Container) GetPtyMaster() (*os.File, error) {
|
||||
}
|
||||
|
||||
func (container *Container) HostConfig() *runconfig.HostConfig {
|
||||
return container.hostConfig
|
||||
container.Lock()
|
||||
res := container.hostConfig
|
||||
container.Unlock()
|
||||
return res
|
||||
}
|
||||
|
||||
func (container *Container) SetHostConfig(hostConfig *runconfig.HostConfig) {
|
||||
container.Lock()
|
||||
container.hostConfig = hostConfig
|
||||
container.Unlock()
|
||||
}
|
||||
|
||||
func (container *Container) DisableLink(name string) {
|
||||
@@ -861,7 +902,13 @@ func (container *Container) setupContainerDns() error {
|
||||
} else if len(daemon.config.DnsSearch) > 0 {
|
||||
dnsSearch = daemon.config.DnsSearch
|
||||
}
|
||||
container.ResolvConfPath = container.getRootResourcePath("resolv.conf")
|
||||
|
||||
resolvConfPath, err := container.getRootResourcePath("resolv.conf")
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
container.ResolvConfPath = resolvConfPath
|
||||
|
||||
return resolvconf.Build(container.ResolvConfPath, dns, dnsSearch)
|
||||
} else {
|
||||
container.ResolvConfPath = "/etc/resolv.conf"
|
||||
@@ -886,12 +933,20 @@ func (container *Container) initializeNetworking() error {
|
||||
content, err := ioutil.ReadFile("/etc/hosts")
|
||||
if os.IsNotExist(err) {
|
||||
return container.buildHostnameAndHostsFiles("")
|
||||
}
|
||||
if err != nil {
|
||||
} else if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
container.HostsPath = container.getRootResourcePath("hosts")
|
||||
if err := container.buildHostnameFile(); err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
hostsPath, err := container.getRootResourcePath("hosts")
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
container.HostsPath = hostsPath
|
||||
|
||||
return ioutil.WriteFile(container.HostsPath, content, 0644)
|
||||
} else if container.hostConfig.NetworkMode.IsContainer() {
|
||||
// we need to get the hosts files from the container to join
|
||||
@@ -1007,12 +1062,18 @@ func (container *Container) setupWorkingDirectory() error {
|
||||
if container.Config.WorkingDir != "" {
|
||||
container.Config.WorkingDir = path.Clean(container.Config.WorkingDir)
|
||||
|
||||
pthInfo, err := os.Stat(container.getResourcePath(container.Config.WorkingDir))
|
||||
pth, err := container.getResourcePath(container.Config.WorkingDir)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
pthInfo, err := os.Stat(pth)
|
||||
if err != nil {
|
||||
if !os.IsNotExist(err) {
|
||||
return err
|
||||
}
|
||||
if err := os.MkdirAll(container.getResourcePath(container.Config.WorkingDir), 0755); err != nil {
|
||||
|
||||
if err := os.MkdirAll(pth, 0755); err != nil {
|
||||
return err
|
||||
}
|
||||
}
|
||||
@@ -1025,12 +1086,19 @@ func (container *Container) setupWorkingDirectory() error {
|
||||
|
||||
func (container *Container) startLoggingToDisk() error {
|
||||
// Setup logging of stdout and stderr to disk
|
||||
if err := container.daemon.LogToDisk(container.stdout, container.logPath("json"), "stdout"); err != nil {
|
||||
pth, err := container.logPath("json")
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
if err := container.daemon.LogToDisk(container.stderr, container.logPath("json"), "stderr"); err != nil {
|
||||
|
||||
if err := container.daemon.LogToDisk(container.stdout, pth, "stdout"); err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
if err := container.daemon.LogToDisk(container.stderr, pth, "stderr"); err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
|
||||
+4
-2
@@ -12,6 +12,8 @@ import (
|
||||
"sync"
|
||||
"time"
|
||||
|
||||
"github.com/docker/libcontainer/label"
|
||||
"github.com/docker/libcontainer/selinux"
|
||||
"github.com/dotcloud/docker/archive"
|
||||
"github.com/dotcloud/docker/daemon/execdriver"
|
||||
"github.com/dotcloud/docker/daemon/execdriver/execdrivers"
|
||||
@@ -26,10 +28,8 @@ import (
|
||||
"github.com/dotcloud/docker/graph"
|
||||
"github.com/dotcloud/docker/image"
|
||||
"github.com/dotcloud/docker/pkg/graphdb"
|
||||
"github.com/dotcloud/docker/pkg/label"
|
||||
"github.com/dotcloud/docker/pkg/namesgenerator"
|
||||
"github.com/dotcloud/docker/pkg/networkfs/resolvconf"
|
||||
"github.com/dotcloud/docker/pkg/selinux"
|
||||
"github.com/dotcloud/docker/pkg/sysinfo"
|
||||
"github.com/dotcloud/docker/runconfig"
|
||||
"github.com/dotcloud/docker/utils"
|
||||
@@ -72,9 +72,11 @@ func (c *contStore) Delete(id string) {
|
||||
|
||||
func (c *contStore) List() []*Container {
|
||||
containers := new(History)
|
||||
c.Lock()
|
||||
for _, cont := range c.s {
|
||||
containers.Add(cont)
|
||||
}
|
||||
c.Unlock()
|
||||
containers.Sort()
|
||||
return *containers
|
||||
}
|
||||
|
||||
@@ -1,2 +1 @@
|
||||
Michael Crosby <michael@crosbymichael.com> (@crosbymichael)
|
||||
Guillaume J. Charmes <guillaume@docker.com> (@creack)
|
||||
|
||||
@@ -6,7 +6,7 @@ import (
|
||||
"os"
|
||||
"os/exec"
|
||||
|
||||
"github.com/dotcloud/docker/pkg/libcontainer/devices"
|
||||
"github.com/docker/libcontainer/devices"
|
||||
)
|
||||
|
||||
// Context is a generic key value pair that allows
|
||||
|
||||
@@ -0,0 +1 @@
|
||||
Dinesh Subhraveti <dineshs@altiscale.com> (@dineshs-altiscale)
|
||||
@@ -15,11 +15,10 @@ import (
|
||||
"syscall"
|
||||
"time"
|
||||
|
||||
"github.com/docker/libcontainer/cgroups"
|
||||
"github.com/docker/libcontainer/label"
|
||||
"github.com/docker/libcontainer/mount/nodes"
|
||||
"github.com/dotcloud/docker/daemon/execdriver"
|
||||
"github.com/dotcloud/docker/pkg/label"
|
||||
"github.com/dotcloud/docker/pkg/libcontainer/cgroups"
|
||||
"github.com/dotcloud/docker/pkg/libcontainer/mount/nodes"
|
||||
"github.com/dotcloud/docker/pkg/system"
|
||||
"github.com/dotcloud/docker/utils"
|
||||
)
|
||||
|
||||
@@ -37,16 +36,7 @@ func init() {
|
||||
if err := setupNetworking(args); err != nil {
|
||||
return err
|
||||
}
|
||||
if err := setupCapabilities(args); err != nil {
|
||||
return err
|
||||
}
|
||||
if err := setupWorkingDirectory(args); err != nil {
|
||||
return err
|
||||
}
|
||||
if err := system.CloseFdsFrom(3); err != nil {
|
||||
return err
|
||||
}
|
||||
if err := changeUser(args); err != nil {
|
||||
if err := finalizeNamespace(args); err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
|
||||
@@ -9,10 +9,8 @@ import (
|
||||
"strings"
|
||||
"syscall"
|
||||
|
||||
"github.com/docker/libcontainer/netlink"
|
||||
"github.com/dotcloud/docker/daemon/execdriver"
|
||||
"github.com/dotcloud/docker/pkg/netlink"
|
||||
"github.com/dotcloud/docker/pkg/user"
|
||||
"github.com/syndtr/gocapability/capability"
|
||||
)
|
||||
|
||||
// Clear environment pollution introduced by lxc-start
|
||||
@@ -107,65 +105,6 @@ func setupWorkingDirectory(args *execdriver.InitArgs) error {
|
||||
return nil
|
||||
}
|
||||
|
||||
// Takes care of dropping privileges to the desired user
|
||||
func changeUser(args *execdriver.InitArgs) error {
|
||||
uid, gid, suppGids, err := user.GetUserGroupSupplementary(
|
||||
args.User,
|
||||
syscall.Getuid(), syscall.Getgid(),
|
||||
)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
if err := syscall.Setgroups(suppGids); err != nil {
|
||||
return fmt.Errorf("Setgroups failed: %v", err)
|
||||
}
|
||||
if err := syscall.Setgid(gid); err != nil {
|
||||
return fmt.Errorf("Setgid failed: %v", err)
|
||||
}
|
||||
if err := syscall.Setuid(uid); err != nil {
|
||||
return fmt.Errorf("Setuid failed: %v", err)
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
func setupCapabilities(args *execdriver.InitArgs) error {
|
||||
if args.Privileged {
|
||||
return nil
|
||||
}
|
||||
|
||||
drop := []capability.Cap{
|
||||
capability.CAP_SETPCAP,
|
||||
capability.CAP_SYS_MODULE,
|
||||
capability.CAP_SYS_RAWIO,
|
||||
capability.CAP_SYS_PACCT,
|
||||
capability.CAP_SYS_ADMIN,
|
||||
capability.CAP_SYS_NICE,
|
||||
capability.CAP_SYS_RESOURCE,
|
||||
capability.CAP_SYS_TIME,
|
||||
capability.CAP_SYS_TTY_CONFIG,
|
||||
capability.CAP_AUDIT_WRITE,
|
||||
capability.CAP_AUDIT_CONTROL,
|
||||
capability.CAP_MAC_OVERRIDE,
|
||||
capability.CAP_MAC_ADMIN,
|
||||
capability.CAP_NET_ADMIN,
|
||||
capability.CAP_SYSLOG,
|
||||
}
|
||||
|
||||
c, err := capability.NewPid(os.Getpid())
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
c.Unset(capability.CAPS|capability.BOUNDS, drop...)
|
||||
|
||||
if err := c.Apply(capability.CAPS | capability.BOUNDS); err != nil {
|
||||
return err
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
func getEnv(args *execdriver.InitArgs, key string) string {
|
||||
for _, kv := range args.Env {
|
||||
parts := strings.SplitN(kv, "=", 2)
|
||||
|
||||
@@ -3,9 +3,60 @@
|
||||
package lxc
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"syscall"
|
||||
|
||||
"github.com/docker/libcontainer/namespaces"
|
||||
"github.com/docker/libcontainer/security/capabilities"
|
||||
"github.com/docker/libcontainer/utils"
|
||||
"github.com/dotcloud/docker/daemon/execdriver"
|
||||
"github.com/dotcloud/docker/daemon/execdriver/native/template"
|
||||
"github.com/dotcloud/docker/pkg/system"
|
||||
)
|
||||
|
||||
func setHostname(hostname string) error {
|
||||
return syscall.Sethostname([]byte(hostname))
|
||||
}
|
||||
|
||||
func finalizeNamespace(args *execdriver.InitArgs) error {
|
||||
if err := utils.CloseExecFrom(3); err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
// We use the native drivers default template so that things like caps are consistent
|
||||
// across both drivers
|
||||
container := template.New()
|
||||
|
||||
if !args.Privileged {
|
||||
// drop capabilities in bounding set before changing user
|
||||
if err := capabilities.DropBoundingSet(container); err != nil {
|
||||
return fmt.Errorf("drop bounding set %s", err)
|
||||
}
|
||||
|
||||
// preserve existing capabilities while we change users
|
||||
if err := system.SetKeepCaps(); err != nil {
|
||||
return fmt.Errorf("set keep caps %s", err)
|
||||
}
|
||||
}
|
||||
|
||||
if err := namespaces.SetupUser(args.User); err != nil {
|
||||
return fmt.Errorf("setup user %s", err)
|
||||
}
|
||||
|
||||
if !args.Privileged {
|
||||
if err := system.ClearKeepCaps(); err != nil {
|
||||
return fmt.Errorf("clear keep caps %s", err)
|
||||
}
|
||||
|
||||
// drop all other capabilities
|
||||
if err := capabilities.DropCapabilities(container); err != nil {
|
||||
return fmt.Errorf("drop capabilities %s", err)
|
||||
}
|
||||
}
|
||||
|
||||
if err := setupWorkingDirectory(args); err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
@@ -2,6 +2,12 @@
|
||||
|
||||
package lxc
|
||||
|
||||
import "github.com/dotcloud/docker/daemon/execdriver"
|
||||
|
||||
func setHostname(hostname string) error {
|
||||
panic("Not supported on darwin")
|
||||
}
|
||||
|
||||
func finalizeNamespace(args *execdriver.InitArgs) error {
|
||||
panic("Not supported on darwin")
|
||||
}
|
||||
|
||||
@@ -4,8 +4,8 @@ import (
|
||||
"strings"
|
||||
"text/template"
|
||||
|
||||
"github.com/docker/libcontainer/label"
|
||||
"github.com/dotcloud/docker/daemon/execdriver"
|
||||
"github.com/dotcloud/docker/pkg/label"
|
||||
)
|
||||
|
||||
const LxcTemplate = `
|
||||
|
||||
@@ -11,8 +11,8 @@ import (
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/docker/libcontainer/devices"
|
||||
"github.com/dotcloud/docker/daemon/execdriver"
|
||||
"github.com/dotcloud/docker/pkg/libcontainer/devices"
|
||||
)
|
||||
|
||||
func TestLXCConfig(t *testing.T) {
|
||||
|
||||
@@ -7,7 +7,7 @@ import (
|
||||
"strconv"
|
||||
"strings"
|
||||
|
||||
"github.com/dotcloud/docker/pkg/libcontainer"
|
||||
"github.com/docker/libcontainer"
|
||||
"github.com/dotcloud/docker/pkg/units"
|
||||
)
|
||||
|
||||
|
||||
@@ -3,8 +3,8 @@ package configuration
|
||||
import (
|
||||
"testing"
|
||||
|
||||
"github.com/docker/libcontainer"
|
||||
"github.com/dotcloud/docker/daemon/execdriver/native/template"
|
||||
"github.com/dotcloud/docker/pkg/libcontainer"
|
||||
)
|
||||
|
||||
// Checks whether the expected capability is specified in the capabilities.
|
||||
|
||||
@@ -6,12 +6,12 @@ import (
|
||||
"os/exec"
|
||||
"path/filepath"
|
||||
|
||||
"github.com/docker/libcontainer"
|
||||
"github.com/docker/libcontainer/apparmor"
|
||||
"github.com/docker/libcontainer/devices"
|
||||
"github.com/dotcloud/docker/daemon/execdriver"
|
||||
"github.com/dotcloud/docker/daemon/execdriver/native/configuration"
|
||||
"github.com/dotcloud/docker/daemon/execdriver/native/template"
|
||||
"github.com/dotcloud/docker/pkg/apparmor"
|
||||
"github.com/dotcloud/docker/pkg/libcontainer"
|
||||
"github.com/dotcloud/docker/pkg/libcontainer/devices"
|
||||
)
|
||||
|
||||
// createContainer populates and configures the container type with the
|
||||
|
||||
@@ -11,12 +11,12 @@ import (
|
||||
"sync"
|
||||
"syscall"
|
||||
|
||||
"github.com/docker/libcontainer"
|
||||
"github.com/docker/libcontainer/apparmor"
|
||||
"github.com/docker/libcontainer/cgroups/fs"
|
||||
"github.com/docker/libcontainer/cgroups/systemd"
|
||||
"github.com/docker/libcontainer/namespaces"
|
||||
"github.com/dotcloud/docker/daemon/execdriver"
|
||||
"github.com/dotcloud/docker/pkg/apparmor"
|
||||
"github.com/dotcloud/docker/pkg/libcontainer"
|
||||
"github.com/dotcloud/docker/pkg/libcontainer/cgroups/fs"
|
||||
"github.com/dotcloud/docker/pkg/libcontainer/cgroups/systemd"
|
||||
"github.com/dotcloud/docker/pkg/libcontainer/namespaces"
|
||||
"github.com/dotcloud/docker/pkg/system"
|
||||
)
|
||||
|
||||
|
||||
@@ -1,9 +1,9 @@
|
||||
package template
|
||||
|
||||
import (
|
||||
"github.com/dotcloud/docker/pkg/apparmor"
|
||||
"github.com/dotcloud/docker/pkg/libcontainer"
|
||||
"github.com/dotcloud/docker/pkg/libcontainer/cgroups"
|
||||
"github.com/docker/libcontainer"
|
||||
"github.com/docker/libcontainer/apparmor"
|
||||
"github.com/docker/libcontainer/cgroups"
|
||||
)
|
||||
|
||||
// New returns the docker default configuration for libcontainer
|
||||
@@ -21,6 +21,7 @@ func New() *libcontainer.Container {
|
||||
"SETPCAP",
|
||||
"NET_BIND_SERVICE",
|
||||
"SYS_CHROOT",
|
||||
"KILL",
|
||||
},
|
||||
Namespaces: map[string]bool{
|
||||
"NEWNS": true,
|
||||
|
||||
@@ -30,9 +30,9 @@ import (
|
||||
"sync"
|
||||
"syscall"
|
||||
|
||||
"github.com/docker/libcontainer/label"
|
||||
"github.com/dotcloud/docker/archive"
|
||||
"github.com/dotcloud/docker/daemon/graphdriver"
|
||||
"github.com/dotcloud/docker/pkg/label"
|
||||
mountpk "github.com/dotcloud/docker/pkg/mount"
|
||||
"github.com/dotcloud/docker/utils"
|
||||
)
|
||||
|
||||
@@ -39,7 +39,7 @@ func openNextAvailableLoopback(index int, sparseFile *os.File) (loopFile *os.Fil
|
||||
fi, err := os.Stat(target)
|
||||
if err != nil {
|
||||
if os.IsNotExist(err) {
|
||||
utils.Errorf("There are no more loopback device available.")
|
||||
utils.Errorf("There are no more loopback devices available.")
|
||||
}
|
||||
return nil, ErrAttachLoopbackDevice
|
||||
}
|
||||
|
||||
@@ -18,8 +18,8 @@ import (
|
||||
"syscall"
|
||||
"time"
|
||||
|
||||
"github.com/docker/libcontainer/label"
|
||||
"github.com/dotcloud/docker/daemon/graphdriver"
|
||||
"github.com/dotcloud/docker/pkg/label"
|
||||
"github.com/dotcloud/docker/pkg/units"
|
||||
"github.com/dotcloud/docker/utils"
|
||||
)
|
||||
@@ -55,7 +55,7 @@ type DevInfo struct {
|
||||
}
|
||||
|
||||
type MetaData struct {
|
||||
Devices map[string]*DevInfo `json:devices`
|
||||
Devices map[string]*DevInfo `json:"Devices"`
|
||||
devicesLock sync.Mutex `json:"-"` // Protects all read/writes to Devices map
|
||||
}
|
||||
|
||||
|
||||
@@ -1,12 +1,13 @@
|
||||
package graphtest
|
||||
|
||||
import (
|
||||
"github.com/dotcloud/docker/daemon/graphdriver"
|
||||
"io/ioutil"
|
||||
"os"
|
||||
"path"
|
||||
"syscall"
|
||||
"testing"
|
||||
|
||||
"github.com/dotcloud/docker/daemon/graphdriver"
|
||||
)
|
||||
|
||||
var (
|
||||
@@ -94,10 +95,10 @@ func verifyFile(t *testing.T, path string, mode os.FileMode, uid, gid uint32) {
|
||||
|
||||
if stat, ok := fi.Sys().(*syscall.Stat_t); ok {
|
||||
if stat.Uid != uid {
|
||||
t.Fatal("%s no owned by uid %d", path, uid)
|
||||
t.Fatalf("%s no owned by uid %d", path, uid)
|
||||
}
|
||||
if stat.Gid != gid {
|
||||
t.Fatal("%s not owned by gid %d", path, gid)
|
||||
t.Fatalf("%s not owned by gid %d", path, gid)
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
+3
-1
@@ -13,11 +13,13 @@ func (daemon *Daemon) ContainerInspect(job *engine.Job) engine.Status {
|
||||
}
|
||||
name := job.Args[0]
|
||||
if container := daemon.Get(name); container != nil {
|
||||
container.Lock()
|
||||
defer container.Unlock()
|
||||
if job.GetenvBool("dirty") {
|
||||
b, err := json.Marshal(&struct {
|
||||
*Container
|
||||
HostConfig *runconfig.HostConfig
|
||||
}{container, container.HostConfig()})
|
||||
}{container, container.hostConfig})
|
||||
if err != nil {
|
||||
return job.Error(err)
|
||||
}
|
||||
|
||||
@@ -8,13 +8,13 @@ import (
|
||||
"strings"
|
||||
"sync"
|
||||
|
||||
"github.com/docker/libcontainer/netlink"
|
||||
"github.com/dotcloud/docker/daemon/networkdriver"
|
||||
"github.com/dotcloud/docker/daemon/networkdriver/ipallocator"
|
||||
"github.com/dotcloud/docker/daemon/networkdriver/portallocator"
|
||||
"github.com/dotcloud/docker/daemon/networkdriver/portmapper"
|
||||
"github.com/dotcloud/docker/engine"
|
||||
"github.com/dotcloud/docker/pkg/iptables"
|
||||
"github.com/dotcloud/docker/pkg/netlink"
|
||||
"github.com/dotcloud/docker/pkg/networkfs/resolvconf"
|
||||
"github.com/dotcloud/docker/utils"
|
||||
)
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
package networkdriver
|
||||
|
||||
import (
|
||||
"github.com/dotcloud/docker/pkg/netlink"
|
||||
"github.com/docker/libcontainer/netlink"
|
||||
"net"
|
||||
"testing"
|
||||
)
|
||||
|
||||
@@ -6,7 +6,7 @@ import (
|
||||
"fmt"
|
||||
"net"
|
||||
|
||||
"github.com/dotcloud/docker/pkg/netlink"
|
||||
"github.com/docker/libcontainer/netlink"
|
||||
)
|
||||
|
||||
var (
|
||||
|
||||
+9
-4
@@ -98,12 +98,17 @@ func applyVolumesFrom(container *Container) error {
|
||||
continue
|
||||
}
|
||||
|
||||
stat, err := os.Stat(c.getResourcePath(volPath))
|
||||
pth, err := c.getResourcePath(volPath)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
if err := createIfNotExists(container.getResourcePath(volPath), stat.IsDir()); err != nil {
|
||||
stat, err := os.Stat(pth)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
if err := createIfNotExists(pth, stat.IsDir()); err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
@@ -280,8 +285,8 @@ func initializeVolume(container *Container, volPath string, binds map[string]Bin
|
||||
delete(container.VolumesRW, volPath)
|
||||
}
|
||||
|
||||
container.Volumes[newVolPath] = destination
|
||||
container.VolumesRW[newVolPath] = srcRW
|
||||
container.Volumes[volPath] = destination
|
||||
container.VolumesRW[volPath] = srcRW
|
||||
|
||||
if err := createIfNotExists(source, volIsDir); err != nil {
|
||||
return err
|
||||
|
||||
@@ -0,0 +1,3 @@
|
||||
docker.go contains Docker's main function.
|
||||
|
||||
This file provides first line CLI argument parsing and environment variable setting.
|
||||
+2
-4
@@ -13,10 +13,8 @@ RUN pip install mkdocs
|
||||
#RUN easy_install -U setuptools
|
||||
#RUN pip install MarkdownTools2
|
||||
|
||||
# this week I seem to need the latest dev release of awscli too
|
||||
# awscli 1.3.6 does --error-document correctly
|
||||
# https://github.com/aws/aws-cli/commit/edc2290e173dfaedc70b48cfa3624d58c533c6c3
|
||||
RUN pip install awscli
|
||||
# this version works, the current versions fail in different ways
|
||||
RUN pip install awscli==1.3.9
|
||||
|
||||
# get my sitemap.xml branch of mkdocs and use that for now
|
||||
RUN git clone https://github.com/SvenDowideit/mkdocs &&\
|
||||
|
||||
+5
-5
@@ -53,12 +53,12 @@ run `mkdocs serve`
|
||||
|
||||
## Style guide
|
||||
|
||||
The documentation is written with paragraphs wrapped at 80 colum lines to make
|
||||
The documentation is written with paragraphs wrapped at 80 column lines to make
|
||||
it easier for terminal use.
|
||||
|
||||
### Examples
|
||||
|
||||
When writing examples give the user hints by making them resemble what they see
|
||||
When writing examples, give the user hints by making them resemble what they see
|
||||
in their shell:
|
||||
|
||||
- Indent shell examples by 4 spaces so they get rendered as code.
|
||||
@@ -76,7 +76,7 @@ references them, or in a subdirectory if one already exists.
|
||||
|
||||
## Working using GitHub's file editor
|
||||
|
||||
Alternatively, for small changes and typos you might want to use GitHub's built
|
||||
Alternatively, for small changes and typos you might want to use GitHub's built-
|
||||
in file editor. It allows you to preview your changes right on-line (though
|
||||
there can be some differences between GitHub Markdown and [MkDocs
|
||||
Markdown](http://www.mkdocs.org/user-guide/writing-your-docs/)). Just be
|
||||
@@ -85,8 +85,8 @@ work!](../CONTRIBUTING.md#sign-your-work)
|
||||
|
||||
## Publishing Documentation
|
||||
|
||||
To publish a copy of the documentation you need a `docs/awsconfig` To make life
|
||||
easier for file containing AWS settings to deploy to. The release script will
|
||||
To publish a copy of the documentation you need a `docs/awsconfig`
|
||||
file containing AWS settings to deploy to. The release script will
|
||||
create an s3 if needed, and will then push the files to it.
|
||||
|
||||
[profile dowideit-docs] aws_access_key_id = IHOIUAHSIDH234rwf....
|
||||
|
||||
+13
-12
@@ -51,19 +51,19 @@ pages:
|
||||
|
||||
# User Guide:
|
||||
- ['userguide/index.md', 'User Guide', 'The Docker User Guide' ]
|
||||
- ['userguide/dockerio.md', 'User Guide', 'Getting Started with Docker.io' ]
|
||||
- ['userguide/dockerhub.md', 'User Guide', 'Getting Started with Docker Hub' ]
|
||||
- ['userguide/dockerizing.md', 'User Guide', 'Dockerizing Applications' ]
|
||||
- ['userguide/usingdocker.md', 'User Guide', 'Working with Containers' ]
|
||||
- ['userguide/dockerimages.md', 'User Guide', 'Working with Docker Images' ]
|
||||
- ['userguide/dockerlinks.md', 'User Guide', 'Linking containers together' ]
|
||||
- ['userguide/dockervolumes.md', 'User Guide', 'Managing data in containers' ]
|
||||
- ['userguide/dockerrepos.md', 'User Guide', 'Working with Docker.io' ]
|
||||
- ['userguide/dockerrepos.md', 'User Guide', 'Working with Docker Hub' ]
|
||||
|
||||
# Docker.io docs:
|
||||
- ['docker-io/index.md', 'Docker.io', 'Docker.io' ]
|
||||
- ['docker-io/accounts.md', 'Docker.io', 'Accounts']
|
||||
- ['docker-io/repos.md', 'Docker.io', 'Repositories']
|
||||
- ['docker-io/builds.md', 'Docker.io', 'Automated Builds']
|
||||
# Docker Hub docs:
|
||||
- ['docker-hub/index.md', 'Docker Hub', 'Docker Hub' ]
|
||||
- ['docker-hub/accounts.md', 'Docker Hub', 'Accounts']
|
||||
- ['docker-hub/repos.md', 'Docker Hub', 'Repositories']
|
||||
- ['docker-hub/builds.md', 'Docker Hub', 'Automated Builds']
|
||||
|
||||
# Examples:
|
||||
- ['examples/index.md', '**HIDDEN**']
|
||||
@@ -99,12 +99,13 @@ pages:
|
||||
- ['faq.md', 'Reference', 'FAQ']
|
||||
- ['reference/run.md', 'Reference', 'Run Reference']
|
||||
- ['reference/api/index.md', '**HIDDEN**']
|
||||
- ['reference/api/docker-io_api.md', 'Reference', 'Docker.io API']
|
||||
- ['reference/api/docker-io_api.md', 'Reference', 'Docker Hub API']
|
||||
- ['reference/api/registry_api.md', 'Reference', 'Docker Registry API']
|
||||
- ['reference/api/registry_index_spec.md', 'Reference', 'Registry & Index Spec']
|
||||
- ['reference/api/hub_registry_spec.md', 'Reference', 'Docker Hub and Registry Spec']
|
||||
- ['reference/api/docker_remote_api.md', 'Reference', 'Docker Remote API']
|
||||
- ['reference/api/docker_remote_api_v1.12.md', 'Reference', 'Docker Remote API v1.12']
|
||||
- ['reference/api/docker_remote_api_v1.11.md', 'Reference', 'Docker Remote API v1.11']
|
||||
- ['reference/api/docker_remote_api_v1.10.md', 'Reference', 'Docker Remote API v1.10']
|
||||
- ['reference/api/docker_remote_api_v1.10.md', '**HIDDEN**']
|
||||
- ['reference/api/docker_remote_api_v1.9.md', '**HIDDEN**']
|
||||
- ['reference/api/docker_remote_api_v1.8.md', '**HIDDEN**']
|
||||
- ['reference/api/docker_remote_api_v1.7.md', '**HIDDEN**']
|
||||
@@ -116,8 +117,8 @@ pages:
|
||||
- ['reference/api/docker_remote_api_v1.1.md', '**HIDDEN**']
|
||||
- ['reference/api/docker_remote_api_v1.0.md', '**HIDDEN**']
|
||||
- ['reference/api/remote_api_client_libraries.md', 'Reference', 'Docker Remote API Client Libraries']
|
||||
- ['reference/api/docker_io_oauth_api.md', 'Reference', 'Docker IO OAuth API']
|
||||
- ['reference/api/docker_io_accounts_api.md', 'Reference', 'Docker IO Accounts API']
|
||||
- ['reference/api/docker_io_oauth_api.md', 'Reference', 'Docker Hub OAuth API']
|
||||
- ['reference/api/docker_io_accounts_api.md', 'Reference', 'Docker Hub Accounts API']
|
||||
|
||||
- ['jsearch.md', '**HIDDEN**']
|
||||
|
||||
|
||||
+39
-4
@@ -30,10 +30,10 @@ echo "cfg file: $AWS_CONFIG_FILE ; profile: $AWS_DEFAULT_PROFILE"
|
||||
setup_s3() {
|
||||
echo "Create $BUCKET"
|
||||
# Try creating the bucket. Ignore errors (it might already exist).
|
||||
aws s3 mb s3://$BUCKET 2>/dev/null || true
|
||||
aws s3 mb --profile $BUCKET s3://$BUCKET 2>/dev/null || true
|
||||
# Check access to the bucket.
|
||||
echo "test $BUCKET exists"
|
||||
aws s3 ls s3://$BUCKET
|
||||
aws s3 --profile $BUCKET ls s3://$BUCKET
|
||||
# Make the bucket accessible through website endpoints.
|
||||
echo "make $BUCKET accessible as a website"
|
||||
#aws s3 website s3://$BUCKET --index-document index.html --error-document jsearch/index.html
|
||||
@@ -41,7 +41,7 @@ setup_s3() {
|
||||
echo
|
||||
echo $s3conf
|
||||
echo
|
||||
aws s3api put-bucket-website --bucket $BUCKET --website-configuration "$s3conf"
|
||||
aws s3api --profile $BUCKET put-bucket-website --bucket $BUCKET --website-configuration "$s3conf"
|
||||
}
|
||||
|
||||
build_current_documentation() {
|
||||
@@ -57,7 +57,42 @@ upload_current_documentation() {
|
||||
echo " to $dst"
|
||||
echo
|
||||
#s3cmd --recursive --follow-symlinks --preserve --acl-public sync "$src" "$dst"
|
||||
aws s3 sync --cache-control "max-age=3600" --acl public-read --exclude "*.rej" --exclude "*.rst" --exclude "*.orig" --exclude "*.py" "$src" "$dst"
|
||||
#aws s3 cp --profile $BUCKET --cache-control "max-age=3600" --acl public-read "site/search_content.json" "$dst"
|
||||
|
||||
# a really complicated way to send only the files we want
|
||||
# if there are too many in any one set, aws s3 sync seems to fall over with 2 files to go
|
||||
endings=( json html xml css js gif png JPG )
|
||||
for i in ${endings[@]}; do
|
||||
include=""
|
||||
for j in ${endings[@]}; do
|
||||
if [ "$i" != "$j" ];then
|
||||
include="$include --exclude *.$j"
|
||||
fi
|
||||
done
|
||||
echo "uploading *.$i"
|
||||
run="aws s3 sync --profile $BUCKET --cache-control \"max-age=3600\" --acl public-read \
|
||||
$include \
|
||||
--exclude *.txt \
|
||||
--exclude *.text* \
|
||||
--exclude *Dockerfile \
|
||||
--exclude *.DS_Store \
|
||||
--exclude *.psd \
|
||||
--exclude *.ai \
|
||||
--exclude *.svg \
|
||||
--exclude *.eot \
|
||||
--exclude *.otf \
|
||||
--exclude *.ttf \
|
||||
--exclude *.woff \
|
||||
--exclude *.rej \
|
||||
--exclude *.rst \
|
||||
--exclude *.orig \
|
||||
--exclude *.py \
|
||||
$src $dst"
|
||||
echo "======================="
|
||||
#echo "$run"
|
||||
#echo "======================="
|
||||
$run
|
||||
done
|
||||
}
|
||||
|
||||
setup_s3
|
||||
|
||||
@@ -18,6 +18,17 @@
|
||||
{ "Condition": { "KeyPrefixEquals": "use/working_with_links_names/" }, "Redirect": { "HostName": "$BUCKET", "ReplaceKeyPrefixWith": "userguide/dockerlinks/" } },
|
||||
{ "Condition": { "KeyPrefixEquals": "use/workingwithrepository/" }, "Redirect": { "HostName": "$BUCKET", "ReplaceKeyPrefixWith": "userguide/dockerrepos/" } },
|
||||
{ "Condition": { "KeyPrefixEquals": "use/port_redirection" }, "Redirect": { "HostName": "$BUCKET", "ReplaceKeyPrefixWith": "userguide/dockerlinks/" } },
|
||||
{ "Condition": { "KeyPrefixEquals": "use/networking/" }, "Redirect": { "HostName": "$BUCKET", "ReplaceKeyPrefixWith": "articles/networking/" } },
|
||||
{ "Condition": { "KeyPrefixEquals": "use/puppet/" }, "Redirect": { "HostName": "$BUCKET", "ReplaceKeyPrefixWith": "articles/puppet/" } },
|
||||
{ "Condition": { "KeyPrefixEquals": "use/ambassador_pattern_linking/" }, "Redirect": { "HostName": "$BUCKET", "ReplaceKeyPrefixWith": "articles/ambassador_pattern_linking/" } },
|
||||
{ "Condition": { "KeyPrefixEquals": "use/basics/" }, "Redirect": { "HostName": "$BUCKET", "ReplaceKeyPrefixWith": "articles/basics/" } },
|
||||
{ "Condition": { "KeyPrefixEquals": "use/chef/" }, "Redirect": { "HostName": "$BUCKET", "ReplaceKeyPrefixWith": "articles/chef/" } },
|
||||
{ "Condition": { "KeyPrefixEquals": "use/host_integration/" }, "Redirect": { "HostName": "$BUCKET", "ReplaceKeyPrefixWith": "articles/host_integration/" } },
|
||||
{ "Condition": { "KeyPrefixEquals": "docker-io/" }, "Redirect": { "HostName": "$BUCKET", "ReplaceKeyPrefixWith": "docker-hub/" } },
|
||||
{ "Condition": { "KeyPrefixEquals": "examples/cfengine_process_management/" }, "Redirect": { "HostName": "$BUCKET", "ReplaceKeyPrefixWith": "articles/cfengine_process_management/" } },
|
||||
{ "Condition": { "KeyPrefixEquals": "examples/https/" }, "Redirect": { "HostName": "$BUCKET", "ReplaceKeyPrefixWith": "articles/https/" } },
|
||||
{ "Condition": { "KeyPrefixEquals": "examples/using_supervisord/" }, "Redirect": { "HostName": "$BUCKET", "ReplaceKeyPrefixWith": "articles/using_supervisord/" } },
|
||||
{ "Condition": { "KeyPrefixEquals": "reference/api/registry_index_spec/" }, "Redirect": { "HostName": "$BUCKET", "ReplaceKeyPrefixWith": "reference/api/hub_registry_spec/" } },
|
||||
{ "Condition": { "KeyPrefixEquals": "use/" }, "Redirect": { "HostName": "$BUCKET", "ReplaceKeyPrefixWith": "examples/" } }
|
||||
]
|
||||
}
|
||||
|
||||
@@ -26,8 +26,8 @@ for installation instructions.
|
||||
$ sudo docker pull ubuntu
|
||||
|
||||
This will find the `ubuntu` image by name on
|
||||
[*Docker.io*](/userguide/dockerrepos/#find-public-images-on-dockerio)
|
||||
and download it from [Docker.io](https://index.docker.io) to a local
|
||||
[*Docker Hub*](/userguide/dockerrepos/#find-public-images-on-docker-hub)
|
||||
and download it from [Docker Hub](https://hub.docker.com) to a local
|
||||
image cache.
|
||||
|
||||
> **Note**:
|
||||
|
||||
@@ -110,7 +110,9 @@ Finally, several networking options can only be provided when calling
|
||||
The following sections tackle all of the above topics in an order that
|
||||
moves roughly from simplest to most complex.
|
||||
|
||||
## <a name="dns"></a>Configuring DNS
|
||||
## Configuring DNS
|
||||
|
||||
<a name="dns"></a>
|
||||
|
||||
How can Docker supply each container with a hostname and DNS
|
||||
configuration, without having to build a custom image with the hostname
|
||||
@@ -136,14 +138,14 @@ Four different options affect container domain name services.
|
||||
|
||||
* `-h HOSTNAME` or `--hostname=HOSTNAME` — sets the hostname by which
|
||||
the container knows itself. This is written into `/etc/hostname`,
|
||||
into `/etc/hosts` as the name of the container’s host-facing IP
|
||||
into `/etc/hosts` as the name of the container's host-facing IP
|
||||
address, and is the name that `/bin/bash` inside the container will
|
||||
display inside its prompt. But the hostname is not easy to see from
|
||||
outside the container. It will not appear in `docker ps` nor in the
|
||||
`/etc/hosts` file of any other container.
|
||||
|
||||
* `--link=CONTAINER_NAME:ALIAS` — using this option as you `run` a
|
||||
container gives the new container’s `/etc/hosts` an extra entry
|
||||
container gives the new container's `/etc/hosts` an extra entry
|
||||
named `ALIAS` that points to the IP address of the container named
|
||||
`CONTAINER_NAME`. This lets processes inside the new container
|
||||
connect to the hostname `ALIAS` without having to know its IP. The
|
||||
@@ -158,9 +160,9 @@ Four different options affect container domain name services.
|
||||
|
||||
* `--dns-search=DOMAIN...` — sets the domain names that are searched
|
||||
when a bare unqualified hostname is used inside of the container, by
|
||||
writing `search` lines into the container’s `/etc/resolv.conf`.
|
||||
writing `search` lines into the container's `/etc/resolv.conf`.
|
||||
When a container process attempts to access `host` and the search
|
||||
domain `exmaple.com` is set, for instance, the DNS logic will not
|
||||
domain `example.com` is set, for instance, the DNS logic will not
|
||||
only look up `host` but also `host.example.com`.
|
||||
|
||||
Note that Docker, in the absence of either of the last two options
|
||||
@@ -168,12 +170,14 @@ above, will make `/etc/resolv.conf` inside of each container look like
|
||||
the `/etc/resolv.conf` of the host machine where the `docker` daemon is
|
||||
running. The options then modify this default configuration.
|
||||
|
||||
## <a name="between-containers"></a>Communication between containers
|
||||
## Communication between containers
|
||||
|
||||
<a name="between-containers"></a>
|
||||
|
||||
Whether two containers can communicate is governed, at the operating
|
||||
system level, by three factors.
|
||||
|
||||
1. Does the network topology even connect the containers’ network
|
||||
1. Does the network topology even connect the containers' network
|
||||
interfaces? By default Docker will attach all containers to a
|
||||
single `docker0` bridge, providing a path for packets to travel
|
||||
between them. See the later sections of this document for other
|
||||
@@ -259,15 +263,17 @@ the `FORWARD` chain has a default policy of `ACCEPT` or `DROP`:
|
||||
|
||||
> **Note**:
|
||||
> Docker is careful that its host-wide `iptables` rules fully expose
|
||||
> containers to each other’s raw IP addresses, so connections from one
|
||||
> containers to each other's raw IP addresses, so connections from one
|
||||
> container to another should always appear to be originating from the
|
||||
> first container’s own IP address.
|
||||
> first container's own IP address.
|
||||
|
||||
## <a name="binding-ports"></a>Binding container ports to the host
|
||||
## Binding container ports to the host
|
||||
|
||||
<a name="binding-ports"></a>
|
||||
|
||||
By default Docker containers can make connections to the outside world,
|
||||
but the outside world cannot connect to containers. Each outgoing
|
||||
connection will appear to originate from one of the host machine’s own
|
||||
connection will appear to originate from one of the host machine's own
|
||||
IP addresses thanks to an `iptables` masquerading rule on the host
|
||||
machine that the Docker server creates when it starts:
|
||||
|
||||
@@ -289,7 +295,7 @@ page. There are two approaches.
|
||||
|
||||
First, you can supply `-P` or `--publish-all=true|false` to `docker run`
|
||||
which is a blanket operation that identifies every port with an `EXPOSE`
|
||||
line in the image’s `Dockerfile` and maps it to a host port somewhere in
|
||||
line in the image's `Dockerfile` and maps it to a host port somewhere in
|
||||
the range 49000–49900. This tends to be a bit inconvenient, since you
|
||||
then have to run other `docker` sub-commands to learn which external
|
||||
port a given service was mapped to.
|
||||
@@ -336,9 +342,11 @@ Again, this topic is covered without all of these low-level networking
|
||||
details in the [Docker User Guide](/userguide/dockerlinks/) document if you
|
||||
would like to use that as your port redirection reference instead.
|
||||
|
||||
## <a name="docker0"></a>Customizing docker0
|
||||
## Customizing docker0
|
||||
|
||||
By default, the Docker server creates and configures the host system’s
|
||||
<a name="docker0"></a>
|
||||
|
||||
By default, the Docker server creates and configures the host system's
|
||||
`docker0` interface as an *Ethernet bridge* inside the Linux kernel that
|
||||
can pass packets back and forth between other physical or virtual
|
||||
network interfaces so that they behave as a single Ethernet network.
|
||||
@@ -347,7 +355,7 @@ Docker configures `docker0` with an IP address and netmask so the host
|
||||
machine can both receive and send packets to containers connected to the
|
||||
bridge, and gives it an MTU — the *maximum transmission unit* or largest
|
||||
packet length that the interface will allow — of either 1,500 bytes or
|
||||
else a more specific value copied from the Docker host’s interface that
|
||||
else a more specific value copied from the Docker host's interface that
|
||||
supports its default route. Both are configurable at server startup:
|
||||
|
||||
* `--bip=CIDR` — supply a specific IP address and netmask for the
|
||||
@@ -380,8 +388,8 @@ install it.
|
||||
Finally, the `docker0` Ethernet bridge settings are used every time you
|
||||
create a new container. Docker selects a free IP address from the range
|
||||
available on the bridge each time you `docker run` a new container, and
|
||||
configures the container’s `eth0` interface with that IP address and the
|
||||
bridge’s netmask. The Docker host’s own IP address on the bridge is
|
||||
configures the container's `eth0` interface with that IP address and the
|
||||
bridge's netmask. The Docker host's own IP address on the bridge is
|
||||
used as the default gateway by which each container reaches the rest of
|
||||
the Internet.
|
||||
|
||||
@@ -408,7 +416,9 @@ packets out on to the Internet unless its `ip_forward` system setting is
|
||||
`1` — see the section above on [Communication between
|
||||
containers](#between-containers) for details.
|
||||
|
||||
## <a name="bridge-building"></a>Building your own bridge
|
||||
## Building your own bridge
|
||||
|
||||
<a name="bridge-building"></a>
|
||||
|
||||
If you want to take Docker out of the business of creating its own
|
||||
Ethernet bridge entirely, you can set up your own bridge before starting
|
||||
@@ -450,25 +460,27 @@ illustrate the technique.
|
||||
|
||||
The result should be that the Docker server starts successfully and is
|
||||
now prepared to bind containers to the new bridge. After pausing to
|
||||
verify the bridge’s configuration, try creating a container — you will
|
||||
verify the bridge's configuration, try creating a container — you will
|
||||
see that its IP address is in your new IP address range, which Docker
|
||||
will have auto-detected.
|
||||
|
||||
Just as we learned in the previous section, you can use the `brctl show`
|
||||
command to see Docker add and remove interfaces from the bridge as you
|
||||
start and stop containers, and can run `ip addr` and `ip route` inside a
|
||||
container to see that it has been given an address in the bridge’s IP
|
||||
address range and has been told to use the Docker host’s IP address on
|
||||
container to see that it has been given an address in the bridge's IP
|
||||
address range and has been told to use the Docker host's IP address on
|
||||
the bridge as its default gateway to the rest of the Internet.
|
||||
|
||||
## <a name="container-networking"></a>How Docker networks a container
|
||||
## How Docker networks a container
|
||||
|
||||
<a name="container-networking"></a>
|
||||
|
||||
While Docker is under active development and continues to tweak and
|
||||
improve its network configuration logic, the shell commands in this
|
||||
section are rough equivalents to the steps that Docker takes when
|
||||
configuring networking for each new container.
|
||||
|
||||
Let’s review a few basics.
|
||||
Let's review a few basics.
|
||||
|
||||
To communicate using the Internet Protocol (IP), a machine needs access
|
||||
to at least one network interface at which packets can be sent and
|
||||
@@ -477,11 +489,11 @@ reachable through that interface. Network interfaces do not have to be
|
||||
physical devices. In fact, the `lo` loopback interface available on
|
||||
every Linux machine (and inside each Docker container) is entirely
|
||||
virtual — the Linux kernel simply copies loopback packets directly from
|
||||
the sender’s memory into the receiver’s memory.
|
||||
the sender's memory into the receiver's memory.
|
||||
|
||||
Docker uses special virtual interfaces to let containers communicate
|
||||
with the host machine — pairs of virtual interfaces called “peers” that
|
||||
are linked inside of the host machine’s kernel so that packets can
|
||||
are linked inside of the host machine's kernel so that packets can
|
||||
travel between them. They are simple to create, as we will see in a
|
||||
moment.
|
||||
|
||||
@@ -495,12 +507,12 @@ The steps with which Docker configures a container are:
|
||||
|
||||
3. Toss the other interface over the wall into the new container (which
|
||||
will already have been provided with an `lo` interface) and rename
|
||||
it to the much prettier name `eth0` since, inside of the container’s
|
||||
it to the much prettier name `eth0` since, inside of the container's
|
||||
separate and unique network interface namespace, there are no
|
||||
physical interfaces with which this name could collide.
|
||||
|
||||
4. Give the container’s `eth0` a new IP address from within the
|
||||
bridge’s range of network addresses, and set its default route to
|
||||
4. Give the container's `eth0` a new IP address from within the
|
||||
bridge's range of network addresses, and set its default route to
|
||||
the IP address that the Docker host owns on the bridge.
|
||||
|
||||
With these steps complete, the container now possesses an `eth0`
|
||||
@@ -516,7 +528,7 @@ values.
|
||||
|
||||
* `--net=host` — Tells Docker to skip placing the container inside of
|
||||
a separate network stack. In essence, this choice tells Docker to
|
||||
**not containerize the container’s networking**! While container
|
||||
**not containerize the container's networking**! While container
|
||||
processes will still be confined to their own filesystem and process
|
||||
list and resource limits, a quick `ip addr` command will show you
|
||||
that, network-wise, they live “outside” in the main Docker host and
|
||||
@@ -524,10 +536,15 @@ values.
|
||||
**not** let the container reconfigure the host network stack — that
|
||||
would require `--privileged=true` — but it does let container
|
||||
processes open low-numbered ports like any other root process.
|
||||
It also allows the container to access local network services
|
||||
like D-bus. This can lead to processes in the container being
|
||||
able to do unexpected things like
|
||||
[restart your computer](https://github.com/dotcloud/docker/issues/6401).
|
||||
You should use this option with caution.
|
||||
|
||||
* `--net=container:NAME_or_ID` — Tells Docker to put this container’s
|
||||
* `--net=container:NAME_or_ID` — Tells Docker to put this container's
|
||||
processes inside of the network stack that has already been created
|
||||
inside of another container. The new container’s processes will be
|
||||
inside of another container. The new container's processes will be
|
||||
confined to their own filesystem and process list and resource
|
||||
limits, but will share the same IP address and port numbers as the
|
||||
first container, and processes on the two containers will be able to
|
||||
@@ -559,7 +576,7 @@ Docker do all of the configuration:
|
||||
$ sudo mkdir -p /var/run/netns
|
||||
$ sudo ln -s /proc/$pid/ns/net /var/run/netns/$pid
|
||||
|
||||
# Check the bridge’s IP address and netmask
|
||||
# Check the bridge's IP address and netmask
|
||||
|
||||
$ ip addr show docker0
|
||||
21: docker0: ...
|
||||
@@ -621,14 +638,16 @@ of the same kinds of configuration. Here are two:
|
||||
|
||||
* Brandon Rhodes has created a whole network topology of Docker
|
||||
containers for the next edition of Foundations of Python Network
|
||||
Programming that includes routing, NAT’d firewalls, and servers that
|
||||
Programming that includes routing, NAT'd firewalls, and servers that
|
||||
offer HTTP, SMTP, POP, IMAP, Telnet, SSH, and FTP:
|
||||
<https://github.com/brandon-rhodes/fopnp/tree/m/playground>
|
||||
|
||||
Both tools use networking commands very much like the ones you saw in
|
||||
the previous section, and will see in the following sections.
|
||||
|
||||
## <a name="point-to-point"></a>Building a point-to-point connection
|
||||
## Building a point-to-point connection
|
||||
|
||||
<a name="point-to-point"></a>
|
||||
|
||||
By default, Docker attaches all containers to the virtual subnet
|
||||
implemented by `docker0`. You can create containers that are each
|
||||
@@ -646,7 +665,7 @@ The solution is simple: when you create your pair of peer interfaces,
|
||||
simply throw *both* of them into containers, and configure them as
|
||||
classic point-to-point links. The two containers will then be able to
|
||||
communicate directly (provided you manage to tell each container the
|
||||
other’s IP address, of course). You might adjust the instructions of
|
||||
other's IP address, of course). You might adjust the instructions of
|
||||
the previous section to go something like this:
|
||||
|
||||
# Start up two containers in two terminal windows
|
||||
@@ -683,7 +702,7 @@ the previous section to go something like this:
|
||||
$ sudo ip netns exec 3004 ip route add 10.1.1.1/32 dev B
|
||||
|
||||
The two containers should now be able to ping each other and make
|
||||
connections sucessfully. Point-to-point links like this do not depend
|
||||
connections successfully. Point-to-point links like this do not depend
|
||||
on a subnet nor a netmask, but on the bare assertion made by `ip route`
|
||||
that some other single IP address is connected to a particular network
|
||||
interface.
|
||||
@@ -691,7 +710,7 @@ interface.
|
||||
Note that point-to-point links can be safely combined with other kinds
|
||||
of network connectivity — there is no need to start the containers with
|
||||
`--net=none` if you want point-to-point links to be an addition to the
|
||||
container’s normal networking instead of a replacement.
|
||||
container's normal networking instead of a replacement.
|
||||
|
||||
A final permutation of this pattern is to create the point-to-point link
|
||||
between the Docker host and one container, which would allow the host to
|
||||
|
||||
@@ -112,7 +112,7 @@ use traditional UNIX permission checks to limit access to the control
|
||||
socket.
|
||||
|
||||
You can also expose the REST API over HTTP if you explicitly decide so.
|
||||
However, if you do that, being aware of the abovementioned security
|
||||
However, if you do that, being aware of the above mentioned security
|
||||
implication, you should ensure that it will be reachable only from a
|
||||
trusted network or VPN; or protected with e.g. `stunnel`
|
||||
and client SSL certificates.
|
||||
|
||||
@@ -50,6 +50,13 @@ This command will take some time to complete when you first execute it.
|
||||
If the build is successful, congratulations! You have produced a clean
|
||||
build of docker, neatly encapsulated in a standard build environment.
|
||||
|
||||
> **Note**:
|
||||
> On Mac OS X, make targets such as `build`, `binary`, and `test`
|
||||
> must **not** be built under root. So, for example, instead of the above
|
||||
> command, issue:
|
||||
>
|
||||
> $ make build
|
||||
|
||||
## Build the Docker Binary
|
||||
|
||||
To create the Docker binary, run this command:
|
||||
|
||||
@@ -0,0 +1,49 @@
|
||||
page_title: Accounts on Docker Hub
|
||||
page_description: Docker Hub accounts
|
||||
page_keywords: Docker, docker, registry, accounts, plans, Dockerfile, Docker Hub, docs, documentation
|
||||
|
||||
# Accounts on Docker Hub
|
||||
|
||||
## Docker Hub Accounts
|
||||
|
||||
You can `search` for Docker images and `pull` them from [Docker
|
||||
Hub](https://hub.docker.com) without signing in or even having an
|
||||
account. However, in order to `push` images, leave comments or to *star*
|
||||
a repository, you are going to need a [Docker
|
||||
Hub](https://hub.docker.com) account.
|
||||
|
||||
### Registration for a Docker Hub Account
|
||||
|
||||
You can get a [Docker Hub](https://hub.docker.com) account by
|
||||
[signing up for one here](https://hub.docker.com/account/signup/). A valid
|
||||
email address is required to register, which you will need to verify for
|
||||
account activation.
|
||||
|
||||
### Email activation process
|
||||
|
||||
You need to have at least one verified email address to be able to use your
|
||||
[Docker Hub](https://hub.docker.com) account. If you can't find the validation email,
|
||||
you can request another by visiting the [Resend Email Confirmation](
|
||||
https://hub.docker.com/account/resend-email-confirmation/) page.
|
||||
|
||||
### Password reset process
|
||||
|
||||
If you can't access your account for some reason, you can reset your password
|
||||
from the [*Password Reset*](https://hub.docker.com/account/forgot-password/)
|
||||
page.
|
||||
|
||||
## Organizations & Groups
|
||||
|
||||
Also available on the Docker Hub are organizations and groups that allow
|
||||
you to collaborate across your organization or team. You can see what
|
||||
organizations [you belong to and add new organizations](Sam Alba
|
||||
<sam@docker.com>) from the Account
|
||||
tab.
|
||||
|
||||

|
||||
|
||||
From within your organizations you can create groups that allow you to
|
||||
further manage who can interact with your repositories.
|
||||
|
||||

|
||||
|
||||
@@ -1,13 +1,13 @@
|
||||
page_title: Automated Builds on Docker.io
|
||||
page_description: Docker.io Automated Builds
|
||||
page_keywords: Docker, docker, registry, accounts, plans, Dockerfile, Docker.io, docs, documentation, trusted, builds, trusted builds, automated, automated builds
|
||||
# Automated Builds on Docker.io
|
||||
page_title: Automated Builds on Docker Hub
|
||||
page_description: Docker Hub Automated Builds
|
||||
page_keywords: Docker, docker, registry, accounts, plans, Dockerfile, Docker Hub, docs, documentation, trusted, builds, trusted builds, automated builds
|
||||
# Automated Builds on Docker Hub
|
||||
|
||||
## Automated Builds
|
||||
|
||||
*Automated Builds* is a special feature allowing you to specify a source
|
||||
repository with a `Dockerfile` to be built by the
|
||||
[Docker.io](https://index.docker.io) build clusters. The system will
|
||||
[Docker Hub](https://hub.docker.com) build clusters. The system will
|
||||
clone your repository and build the `Dockerfile` using the repository as
|
||||
the context. The resulting image will then be uploaded to the registry
|
||||
and marked as an *Automated Build*.
|
||||
@@ -26,27 +26,28 @@ on both [GitHub](http://github.com) and
|
||||
|
||||
### Setting up Automated Builds with GitHub
|
||||
|
||||
In order to setup an Automated Build, you need to first link your [Docker.io](
|
||||
https://index.docker.io) account with a GitHub one. This will allow the registry
|
||||
to see your repositories.
|
||||
In order to setup an Automated Build, you need to first link your
|
||||
[Docker Hub](https://hub.docker.com) account with a GitHub one. This
|
||||
will allow the registry to see your repositories.
|
||||
|
||||
> *Note:* We currently request access for *read* and *write* since [Docker.io](
|
||||
> https://index.docker.io) needs to setup a GitHub service hook. Although nothing
|
||||
> else is done with your account, this is how GitHub manages permissions, sorry!
|
||||
> *Note:*
|
||||
> We currently request access for *read* and *write* since
|
||||
> [Docker Hub](https://hub.docker.com) needs to setup a GitHub service
|
||||
> hook. Although nothing else is done with your account, this is how
|
||||
> GitHub manages permissions, sorry!
|
||||
|
||||
Click on the [Automated Builds tab](https://index.docker.io/builds/) to
|
||||
get started and then select [+ Add
|
||||
New](https://index.docker.io/builds/add/).
|
||||
Click on the [Automated Builds
|
||||
tab](https://registry.hub.docker.com/builds/) to get started and then
|
||||
select [+ Add New](https://registry.hub.docker.com/builds/add/).
|
||||
|
||||
Select the [GitHub
|
||||
service](https://index.docker.io/associate/github/).
|
||||
Select the [GitHub service](https://registry.hub.docker.com/associate/github/).
|
||||
|
||||
Then follow the instructions to authorize and link your GitHub account
|
||||
to Docker.io.
|
||||
to Docker Hub.
|
||||
|
||||
#### Creating an Automated Build
|
||||
|
||||
You can [create an Automated Build](https://index.docker.io/builds/github/select/)
|
||||
You can [create an Automated Build](https://registry.hub.docker.com/builds/github/select/)
|
||||
from any of your public or private GitHub repositories with a `Dockerfile`.
|
||||
|
||||
#### GitHub organizations
|
||||
@@ -86,29 +87,29 @@ Automated Build:
|
||||
### Setting up Automated Builds with BitBucket
|
||||
|
||||
In order to setup an Automated Build, you need to first link your
|
||||
[Docker.io]( https://index.docker.io) account with a BitBucket one. This
|
||||
[Docker Hub](https://hub.docker.com) account with a BitBucket one. This
|
||||
will allow the registry to see your repositories.
|
||||
|
||||
Click on the [Automated Builds tab](https://index.docker.io/builds/) to
|
||||
Click on the [Automated Builds tab](https://registry.hub.docker.com/builds/) to
|
||||
get started and then select [+ Add
|
||||
New](https://index.docker.io/builds/add/).
|
||||
New](https://registry.hub.docker.com/builds/add/).
|
||||
|
||||
Select the [BitBucket
|
||||
service](https://index.docker.io/associate/bitbucket/).
|
||||
service](https://registry.hub.docker.com/associate/bitbucket/).
|
||||
|
||||
Then follow the instructions to authorize and link your BitBucket account
|
||||
to Docker.io.
|
||||
to Docker Hub.
|
||||
|
||||
#### Creating an Automated Build
|
||||
|
||||
You can [create an Automated
|
||||
Build](https://index.docker.io/builds/bitbucket/select/) from any of
|
||||
your public or private BitBucket repositories with a `Dockerfile`.
|
||||
You can [create an Automated Build](
|
||||
https://registry.hub.docker.com/builds/bitbucket/select/) from any of your
|
||||
public or private BitBucket repositories with a `Dockerfile`.
|
||||
|
||||
### The Dockerfile and Automated Builds
|
||||
|
||||
During the build process, we copy the contents of your `Dockerfile`. We also
|
||||
add it to the [Docker.io](https://index.docker.io) for the Docker community
|
||||
add it to the [Docker Hub](https://hub.docker.com) for the Docker community
|
||||
to see on the repository page.
|
||||
|
||||
### README.md
|
||||
@@ -163,7 +164,7 @@ payload:
|
||||
"description":"my docker repo that does cool things",
|
||||
"is_automated":false,
|
||||
"full_description":"This is my full description",
|
||||
"repo_url":"https://index.docker.io/u/username/reponame/",
|
||||
"repo_url":"https://registry.hub.docker.com/u/username/reponame/",
|
||||
"owner":"username",
|
||||
"is_official":false,
|
||||
"is_private":false,
|
||||
Binary file not shown.
|
After Width: | Height: | Size: 106 KiB |
@@ -1,13 +1,13 @@
|
||||
page_title: The Docker.io Registry Help
|
||||
page_title: The Docker Hub Registry Help
|
||||
page_description: The Docker Registry help documentation home
|
||||
page_keywords: Docker, docker, registry, accounts, plans, Dockerfile, Docker.io, docs, documentation
|
||||
page_keywords: Docker, docker, registry, accounts, plans, Dockerfile, Docker Hub, docs, documentation
|
||||
|
||||
# The Docker.io Registry Help
|
||||
# The Docker Hub Registry Help
|
||||
|
||||
## Introduction
|
||||
|
||||
For your questions about the [Docker.io](https://index.docker.io) registry you
|
||||
For your questions about the [Docker Hub](https://hub.docker.com) registry you
|
||||
can use [this documentation](docs.md).
|
||||
|
||||
If you can not find something you are looking for, please feel free to
|
||||
[contact us](https://index.docker.io/help/support/).
|
||||
[contact us](https://docker.com/resources/support/).
|
||||
Binary file not shown.
|
After Width: | Height: | Size: 91 KiB |
@@ -0,0 +1,23 @@
|
||||
page_title: The Docker Hub Help
|
||||
page_description: The Docker Help documentation home
|
||||
page_keywords: Docker, docker, registry, accounts, plans, Dockerfile, Docker Hub, docs, documentation, accounts, organizations, repositories, groups
|
||||
|
||||
# Docker Hub
|
||||
|
||||

|
||||
|
||||
## [Accounts](accounts/)
|
||||
|
||||
[Learn how to create](accounts/) a [Docker Hub](https://hub.docker.com)
|
||||
account and manage your organizations and groups.
|
||||
|
||||
## [Repositories](repos/)
|
||||
|
||||
Find out how to share your Docker images in [Docker Hub
|
||||
repositories](repos/) and how to store and manage private images.
|
||||
|
||||
## [Automated Builds](builds/)
|
||||
|
||||
Learn how to automate your build and deploy pipeline with [Automated
|
||||
Builds](builds/)
|
||||
|
||||
Binary file not shown.
|
After Width: | Height: | Size: 71 KiB |
@@ -0,0 +1,144 @@
|
||||
page_title: Repositories and Images on Docker Hub
|
||||
page_description: Repositories and Images on Docker Hub
|
||||
page_keywords: Docker, docker, registry, accounts, plans, Dockerfile, Docker Hub, docs, documentation
|
||||
|
||||
# Repositories and Images on Docker Hub
|
||||
|
||||

|
||||
|
||||
## Searching for repositories and images
|
||||
|
||||
You can `search` for all the publicly available repositories and images using
|
||||
Docker.
|
||||
|
||||
$ docker search ubuntu
|
||||
|
||||
This will show you a list of the currently available repositories on the
|
||||
Docker Hub which match the provided keyword.
|
||||
|
||||
If a repository is private it won't be listed on the repository search
|
||||
results. To see repository statuses, you can look at your [profile
|
||||
page](https://hub.docker.com) on [Docker Hub](https://hub.docker.com).
|
||||
|
||||
## Repositories
|
||||
|
||||
Your Docker Hub repositories have a number of useful features.
|
||||
|
||||
### Stars
|
||||
|
||||
Your repositories can be starred and you can star repositories in
|
||||
return. Stars are a way to show that you like a repository. They are
|
||||
also an easy way of bookmarking your favorites.
|
||||
|
||||
### Comments
|
||||
|
||||
You can interact with other members of the Docker community and maintainers by
|
||||
leaving comments on repositories. If you find any comments that are not
|
||||
appropriate, you can flag them for review.
|
||||
|
||||
### Collaborators and their role
|
||||
|
||||
A collaborator is someone you want to give access to a private
|
||||
repository. Once designated, they can `push` and `pull` to your
|
||||
repositories. They will not be allowed to perform any administrative
|
||||
tasks such as deleting the repository or changing its status from
|
||||
private to public.
|
||||
|
||||
> **Note:**
|
||||
> A collaborator cannot add other collaborators. Only the owner of
|
||||
> the repository has administrative access.
|
||||
|
||||
You can also collaborate on Docker Hub with organizations and groups.
|
||||
You can read more about that [here](accounts/).
|
||||
|
||||
## Official Repositories
|
||||
|
||||
The Docker Hub contains a number of [official
|
||||
repositories](http://registry.hub.docker.com/official). These are
|
||||
certified repositories from vendors and contributors to Docker. They
|
||||
contain Docker images from vendors like Canonical, Oracle, and Red Hat
|
||||
that you can use to build applications and services.
|
||||
|
||||
If you use Official Repositories you know you're using a supported,
|
||||
optimized and up-to-date image to power your applications.
|
||||
|
||||
> **Note:**
|
||||
> If you would like to contribute an official repository for your
|
||||
> organization, product or team you can see more information
|
||||
> [here](https://github.com/dotcloud/stackbrew).
|
||||
|
||||
## Private Docker Repositories
|
||||
|
||||
Private repositories allow you to have repositories that contain images
|
||||
that you want to keep private, either to your own account or within an
|
||||
organization or group.
|
||||
|
||||
To work with a private repository on [Docker
|
||||
Hub](https://hub.docker.com), you will need to add one via the [Add
|
||||
Repository](https://registry.hub.docker.com/account/repositories/add/)
|
||||
link. You get one private repository for free with your Docker Hub
|
||||
account. If you need more accounts you can upgrade your [Docker
|
||||
Hub](https://registry.hub.docker.com/plans/) plan.
|
||||
|
||||
Once the private repository is created, you can `push` and `pull` images
|
||||
to and from it using Docker.
|
||||
|
||||
> *Note:* You need to be signed in and have access to work with a
|
||||
> private repository.
|
||||
|
||||
Private repositories are just like public ones. However, it isn't
|
||||
possible to browse them or search their content on the public registry.
|
||||
They do not get cached the same way as a public repository either.
|
||||
|
||||
It is possible to give access to a private repository to those whom you
|
||||
designate (i.e., collaborators) from its Settings page. From there, you
|
||||
can also switch repository status (*public* to *private*, or
|
||||
vice-versa). You will need to have an available private repository slot
|
||||
open before you can do such a switch. If you don't have any available,
|
||||
you can always upgrade your [Docker
|
||||
Hub](https://registry.hub.docker.com/plans/) plan.
|
||||
|
||||
## Webhooks
|
||||
|
||||
You can configure webhooks for your repositories on the Repository
|
||||
Settings page. A webhook is called only after a successful `push` is
|
||||
made. The webhook calls are HTTP POST requests with a JSON payload
|
||||
similar to the example shown below.
|
||||
|
||||
> **Note:** For testing, you can try an HTTP request tool like
|
||||
> [requestb.in](http://requestb.in/).
|
||||
|
||||
*Example webhook JSON payload:*
|
||||
|
||||
{
|
||||
"push_data":{
|
||||
"pushed_at":1385141110,
|
||||
"images":[
|
||||
"imagehash1",
|
||||
"imagehash2",
|
||||
"imagehash3"
|
||||
],
|
||||
"pusher":"username"
|
||||
},
|
||||
"repository":{
|
||||
"status":"Active",
|
||||
"description":"my docker repo that does cool things",
|
||||
"is_automated":false,
|
||||
"full_description":"This is my full description",
|
||||
"repo_url":"https://registry.hub.docker.com/u/username/reponame/",
|
||||
"owner":"username",
|
||||
"is_official":false,
|
||||
"is_private":false,
|
||||
"name":"reponame",
|
||||
"namespace":"username",
|
||||
"star_count":1,
|
||||
"comment_count":1,
|
||||
"date_created":1370174400,
|
||||
"dockerfile":"my full dockerfile is listed here",
|
||||
"repo_name":"username/reponame"
|
||||
}
|
||||
}
|
||||
|
||||
Webhooks allow you to notify people, services and other applications of
|
||||
new updates to your images and repositories.
|
||||
|
||||
Binary file not shown.
|
After Width: | Height: | Size: 112 KiB |
@@ -1,32 +0,0 @@
|
||||
page_title: Accounts on Docker.io
|
||||
page_description: Docker.io accounts
|
||||
page_keywords: Docker, docker, registry, accounts, plans, Dockerfile, Docker.io, docs, documentation
|
||||
|
||||
# Accounts on Docker.io
|
||||
|
||||
## Docker.io Accounts
|
||||
|
||||
You can `search` for Docker images and `pull` them from [Docker.io](https://index.docker.io)
|
||||
without signing in or even having an account. However, in order to `push` images,
|
||||
leave comments or to *star* a repository, you are going to need a [Docker.io](
|
||||
https://www.docker.io) account.
|
||||
|
||||
### Registration for a Docker.io Account
|
||||
|
||||
You can get a [Docker.io](https://index.docker.io) account by
|
||||
[signing up for one here](https://www.docker.io/account/signup/). A valid
|
||||
email address is required to register, which you will need to verify for
|
||||
account activation.
|
||||
|
||||
### Email activation process
|
||||
|
||||
You need to have at least one verified email address to be able to use your
|
||||
[Docker.io](https://index.docker.io) account. If you can't find the validation email,
|
||||
you can request another by visiting the [Resend Email Confirmation](
|
||||
https://www.docker.io/account/resend-email-confirmation/) page.
|
||||
|
||||
### Password reset process
|
||||
|
||||
If you can't access your account for some reason, you can reset your password
|
||||
from the [*Password Reset*](https://www.docker.io/account/forgot-password/)
|
||||
page.
|
||||
@@ -1,8 +0,0 @@
|
||||
# Docker.io
|
||||
|
||||
## Contents:
|
||||
|
||||
- [Accounts](accounts/)
|
||||
- [Repositories](repos/)
|
||||
- [Automated Builds](builds/)
|
||||
|
||||
@@ -1,98 +0,0 @@
|
||||
page_title: Repositories and Images on Docker.io
|
||||
page_description: Repositories and Images on Docker.io
|
||||
page_keywords: Docker, docker, registry, accounts, plans, Dockerfile, Docker.io, docs, documentation
|
||||
|
||||
# Repositories and Images on Docker.io
|
||||
|
||||
## Searching for repositories and images
|
||||
|
||||
You can `search` for all the publicly available repositories and images using
|
||||
Docker. If a repository is not public (i.e., private), it won't be listed on
|
||||
the repository search results. To see repository statuses, you can look at your
|
||||
[profile page](https://index.docker.io/account/) on [Docker.io](
|
||||
https://index.docker.io).
|
||||
|
||||
## Repositories
|
||||
|
||||
### Stars
|
||||
|
||||
Stars are a way to show that you like a repository. They are also an easy way
|
||||
of bookmark your favorites.
|
||||
|
||||
### Comments
|
||||
|
||||
You can interact with other members of the Docker community and maintainers by
|
||||
leaving comments on repositories. If you find any comments that are not
|
||||
appropriate, you can flag them for the admins' review.
|
||||
|
||||
### Private Docker Repositories
|
||||
|
||||
To work with a private repository on [Docker.io](https://index.docker.io), you
|
||||
will need to add one via the [Add Repository](https://index.docker.io/account/repositories/add)
|
||||
link. Once the private repository is created, you can `push` and `pull` images
|
||||
to and from it using Docker.
|
||||
|
||||
> *Note:* You need to be signed in and have access to work with a private
|
||||
> repository.
|
||||
|
||||
Private repositories are just like public ones. However, it isn't possible to
|
||||
browse them or search their content on the public registry. They do not get cached
|
||||
the same way as a public repository either.
|
||||
|
||||
It is possible to give access to a private repository to those whom you
|
||||
designate (i.e., collaborators) from its settings page.
|
||||
|
||||
From there, you can also switch repository status (*public* to *private*, or
|
||||
viceversa). You will need to have an available private repository slot open
|
||||
before you can do such a switch. If you don't have any, you can always upgrade
|
||||
your [Docker.io](https://index.docker.io/plans/) plan.
|
||||
|
||||
### Collaborators and their role
|
||||
|
||||
A collaborator is someone you want to give access to a private repository. Once
|
||||
designated, they can `push` and `pull`. Although, they will not be allowed to
|
||||
perform any administrative tasks such as deleting the repository or changing its
|
||||
status from private to public.
|
||||
|
||||
> **Note:** A collaborator can not add other collaborators. Only the owner of
|
||||
> the repository has administrative access.
|
||||
|
||||
### Webhooks
|
||||
|
||||
You can configure webhooks on the repository settings page. A webhook is called
|
||||
only after a successful `push` is made. The webhook calls are HTTP POST requests
|
||||
with a JSON payload similar to the example shown below.
|
||||
|
||||
> **Note:** For testing, you can try an HTTP request tool like
|
||||
> [requestb.in](http://requestb.in/).
|
||||
|
||||
*Example webhook JSON payload:*
|
||||
|
||||
{
|
||||
"push_data":{
|
||||
"pushed_at":1385141110,
|
||||
"images":[
|
||||
"imagehash1",
|
||||
"imagehash2",
|
||||
"imagehash3"
|
||||
],
|
||||
"pusher":"username"
|
||||
},
|
||||
"repository":{
|
||||
"status":"Active",
|
||||
"description":"my docker repo that does cool things",
|
||||
"is_automated":false,
|
||||
"full_description":"This is my full description",
|
||||
"repo_url":"https://index.docker.io/u/username/reponame/",
|
||||
"owner":"username",
|
||||
"is_official":false,
|
||||
"is_private":false,
|
||||
"name":"reponame",
|
||||
"namespace":"username",
|
||||
"star_count":1,
|
||||
"comment_count":1,
|
||||
"date_created":1370174400,
|
||||
"dockerfile":"my full dockerfile is listed here",
|
||||
"repo_name":"username/reponame"
|
||||
}
|
||||
}
|
||||
@@ -1,15 +1,14 @@
|
||||
page_title: Dockerizing MongoDB
|
||||
page_description: Creating a Docker image with MongoDB pre-installed using a Dockerfile and sharing the image on Docker.io
|
||||
page_description: Creating a Docker image with MongoDB pre-installed using a Dockerfile and sharing the image on Docker Hub
|
||||
page_keywords: docker, dockerize, dockerizing, article, example, docker.io, platform, package, installation, networking, mongodb, containers, images, image, sharing, dockerfile, build, auto-building, virtualization, framework
|
||||
|
||||
# Dockerizing MongoDB
|
||||
|
||||
## Introduction
|
||||
|
||||
In this example, we are going to learn how to build a Docker image
|
||||
with MongoDB pre-installed.
|
||||
We'll also see how to `push` that image to the [Docker.io registry](
|
||||
https://index.docker.io) and share it with others!
|
||||
In this example, we are going to learn how to build a Docker image with
|
||||
MongoDB pre-installed. We'll also see how to `push` that image to the
|
||||
[Docker Hub registry](https://hub.docker.com) and share it with others!
|
||||
|
||||
Using Docker and containers for deploying [MongoDB](https://www.mongodb.org/)
|
||||
instances will bring several benefits, such as:
|
||||
@@ -41,7 +40,7 @@ Although optional, it is handy to have comments at the beginning of a
|
||||
> the *parent* of your *Dockerized MongoDB* image.
|
||||
|
||||
We will build our image using the latest version of Ubuntu from the
|
||||
[Docker.io Ubuntu](https://index.docker.io/_/ubuntu/) repository.
|
||||
[Docker Hub Ubuntu](https://registry.hub.docker.com/_/ubuntu/) repository.
|
||||
|
||||
# Format: FROM repository[:version]
|
||||
FROM ubuntu:latest
|
||||
@@ -109,10 +108,10 @@ experimenting, it is always a good practice to tag Docker images by passing the
|
||||
Once this command is issued, Docker will go through the `Dockerfile` and build
|
||||
the image. The final image will be tagged `my/repo`.
|
||||
|
||||
## Pushing the MongoDB image to Docker.io
|
||||
## Pushing the MongoDB image to Docker Hub
|
||||
|
||||
All Docker image repositories can be hosted and shared on
|
||||
[Docker.io](https://index.docker.io) with the `docker push` command. For this,
|
||||
[Docker Hub](https://hub.docker.com) with the `docker push` command. For this,
|
||||
you need to be logged-in.
|
||||
|
||||
# Log-in
|
||||
|
||||
@@ -65,9 +65,9 @@ requires to build (this example uses Docker 0.3.4):
|
||||
# DOCKER-VERSION 0.3.4
|
||||
|
||||
Next, define the parent image you want to use to build your own image on
|
||||
top of. Here, we'll use [CentOS](https://index.docker.io/_/centos/)
|
||||
(tag: `6.4`) available on the [Docker
|
||||
index](https://index.docker.io/):
|
||||
top of. Here, we'll use
|
||||
[CentOS](https://registry.hub.docker.com/_/centos/) (tag: `6.4`)
|
||||
available on the [Docker Hub](https://hub.docker.com/):
|
||||
|
||||
FROM centos:6.4
|
||||
|
||||
|
||||
@@ -11,7 +11,7 @@ page_keywords: docker, example, package installation, postgresql
|
||||
## Installing PostgreSQL on Docker
|
||||
|
||||
Assuming there is no Docker image that suits your needs on the [Docker
|
||||
Hub]( http://index.docker.io), you can create one yourself.
|
||||
Hub](http://hub.docker.com), you can create one yourself.
|
||||
|
||||
Start by creating a new `Dockerfile`:
|
||||
|
||||
|
||||
@@ -14,8 +14,8 @@ Create an empty file called `Dockerfile`:
|
||||
$ touch Dockerfile
|
||||
|
||||
Next, define the parent image you want to use to build your image on top
|
||||
of. We'll use [Ubuntu](https://index.docker.io/_/ubuntu/) (tag:
|
||||
`latest`), which is available on [Docker Hub](http://index.docker.io):
|
||||
of. We'll use [Ubuntu](https://registry.hub.docker.cm/_/ubuntu/) (tag:
|
||||
`latest`), which is available on [Docker Hub](https://hub.docker.com):
|
||||
|
||||
# Riak
|
||||
#
|
||||
|
||||
+3
-5
@@ -96,7 +96,7 @@ functionalities:
|
||||
all your future projects. And so on.
|
||||
|
||||
- *Sharing.*
|
||||
Docker has access to a [public registry](http://index.docker.io) where
|
||||
Docker has access to a [public registry](https://hub.docker.com) where
|
||||
thousands of people have uploaded useful containers: anything from Redis,
|
||||
CouchDB, Postgres to IRC bouncers to Rails app servers to Hadoop to
|
||||
base images for various Linux distros. The
|
||||
@@ -122,8 +122,7 @@ functionalities:
|
||||
### What is different between a Docker container and a VM?
|
||||
|
||||
There's a great StackOverflow answer [showing the differences](
|
||||
http://stackoverflow.com/questions/16047306/
|
||||
how-is-docker-io-different-from-a-normal-virtual-machine).
|
||||
http://stackoverflow.com/questions/16047306/how-is-docker-io-different-from-a-normal-virtual-machine).
|
||||
|
||||
### Do I lose my data when the container exits?
|
||||
|
||||
@@ -185,8 +184,7 @@ this [mailbox](mailto:security@docker.com).
|
||||
### Why do I need to sign my commits to Docker with the DCO?
|
||||
|
||||
Please read [our blog post](
|
||||
http://blog.docker.io/2014/01/
|
||||
docker-code-contributions-require-developer-certificate-of-origin/)
|
||||
http://blog.docker.io/2014/01/docker-code-contributions-require-developer-certificate-of-origin/)
|
||||
on the introduction of the DCO.
|
||||
|
||||
### Can I help by adding some questions and answers?
|
||||
|
||||
@@ -17,12 +17,12 @@ Docker consists of:
|
||||
* The Docker Engine - our lightweight and powerful open source container
|
||||
virtualization technology combined with a work flow for building
|
||||
and containerizing your applications.
|
||||
* [Docker.io](https://index.docker.io) - our SAAS service for
|
||||
* [Docker Hub](https://hub.docker.com) - our SaaS service for
|
||||
sharing and managing your application stacks.
|
||||
|
||||
## Why Docker?
|
||||
|
||||
- **Faster delivery of your applications**
|
||||
- **Faster delivery of your applications**
|
||||
* We want your environment to work better. Docker containers,
|
||||
and the work flow that comes with them, help your developers,
|
||||
sysadmins, QA folks, and release engineers work together to get your code
|
||||
@@ -39,7 +39,7 @@ Docker consists of:
|
||||
sub-second launch times, reducing the cycle
|
||||
time of development, testing, and deployment.
|
||||
|
||||
- **Deploy and scale more easily**
|
||||
- **Deploy and scale more easily**
|
||||
* Docker containers run (almost) everywhere. You can deploy
|
||||
containers on desktops, physical servers, virtual machines, into
|
||||
data centers, and up to public and private clouds.
|
||||
@@ -50,13 +50,13 @@ Docker consists of:
|
||||
down fast and easy. You can quickly launch more containers when
|
||||
needed and then shut them down easily when they're no longer needed.
|
||||
|
||||
- **Get higher density and run more workloads**
|
||||
- **Get higher density and run more workloads**
|
||||
* Docker containers don't need a hypervisor, so you can pack more of
|
||||
them onto your hosts. This means you get more value out of every
|
||||
server and can potentially reduce what you spend on equipment and
|
||||
licenses.
|
||||
|
||||
- **Faster deployment makes for easier management**
|
||||
- **Faster deployment makes for easier management**
|
||||
* As Docker speeds up your work flow, it gets easier to make lots
|
||||
of small changes instead of huge, big bang updates. Smaller
|
||||
changes mean reduced risk and more uptime.
|
||||
|
||||
@@ -0,0 +1 @@
|
||||
google.md: Johan Euphrosine <proppy@google.com> (@proppy)
|
||||
@@ -12,32 +12,24 @@ page_keywords: Docker, Docker documentation, installation, google, Google Comput
|
||||
2. Download and configure the [Google Cloud SDK][3] to use your
|
||||
project with the following commands:
|
||||
|
||||
```
|
||||
$ curl https://dl.google.com/dl/cloudsdk/release/install_google_cloud_sdk.bash | bash
|
||||
$ gcloud auth login
|
||||
Enter a cloud project id (or leave blank to not set): <google-cloud-project-id>
|
||||
...
|
||||
```
|
||||
$ curl https://dl.google.com/dl/cloudsdk/release/install_google_cloud_sdk.bash | bash
|
||||
$ gcloud auth login
|
||||
Enter a cloud project id (or leave blank to not set): <google-cloud-project-id>
|
||||
...
|
||||
|
||||
3. Start a new instance using the latest [Container-optimized image][4]:
|
||||
(select a zone close to you and the desired instance size)
|
||||
|
||||
```
|
||||
$ gcloud compute instances create docker-playground \
|
||||
--image projects/google-containers/global/images/container-vm-v20140522 \
|
||||
--zone us-central1-a \
|
||||
--machine-type f1-micro
|
||||
```
|
||||
$ gcloud compute instances create docker-playground \
|
||||
--image projects/google-containers/global/images/container-vm-v20140522 \
|
||||
--zone us-central1-a \
|
||||
--machine-type f1-micro
|
||||
|
||||
4. Connect to the instance using SSH:
|
||||
|
||||
```
|
||||
$ gcloud compute ssh --zone us-central1-a docker-playground
|
||||
```
|
||||
```
|
||||
docker-playground:~$ sudo docker run busybox echo 'docker on GCE \o/'
|
||||
docker on GCE \o/
|
||||
```
|
||||
$ gcloud compute ssh --zone us-central1-a docker-playground
|
||||
docker-playground:~$ sudo docker run busybox echo 'docker on GCE \o/'
|
||||
docker on GCE \o/
|
||||
|
||||
Read more about [deploying Containers on Google Cloud Platform][5].
|
||||
|
||||
|
||||
Binary file not shown.
|
After Width: | Height: | Size: 82 KiB |
@@ -4,105 +4,95 @@ page_keywords: Docker, Docker documentation, requirements, boot2docker, VirtualB
|
||||
|
||||
# Installing Docker on Mac OS X
|
||||
|
||||
> **Note**:
|
||||
> Docker is still under heavy development! We don't recommend using it in
|
||||
> production yet, but we're getting closer with each release. Please see
|
||||
> our blog post, [Getting to Docker 1.0](
|
||||
> http://blog.docker.io/2013/08/getting-to-docker-1-0/)
|
||||
|
||||
> **Note:**
|
||||
> Docker is supported on Mac OS X 10.6 "Snow Leopard" or newer.
|
||||
|
||||
The Docker Engine uses Linux-specific kernel features, so we run it on OS X
|
||||
using a lightweight virtual machine. You can use the OS X Docker client to
|
||||
control the virtualized engine to build, run and manage Docker containers.
|
||||
The Docker Engine uses Linux-specific kernel features, so to run it on OS X
|
||||
we need to use a lightweight virtual machine (vm). You use the OS X Docker client to
|
||||
control the virtualized Docker Engine to build, run, and manage Docker containers.
|
||||
|
||||
To make this process easier we designed a helper application called
|
||||
[boot2docker](https://github.com/boot2docker/boot2docker) to install the
|
||||
virtual machine and run the Docker daemon.
|
||||
To make this process easier, we've designed a helper application called
|
||||
[Boot2Docker](https://github.com/boot2docker/boot2docker) that installs the
|
||||
virtual machine and runs the Docker daemon.
|
||||
|
||||
## Demonstration
|
||||
|
||||
<iframe width="640" height="360" src="//www.youtube.com/embed/wQsrKX4588U?rel=0" frameborder="0" allowfullscreen></iframe>
|
||||
|
||||
## Installation
|
||||
|
||||
1. Download the latest release of the [Docker for OSX Installer](
|
||||
https://github.com/boot2docker/osx-installer/releases)
|
||||
|
||||
2. Run the installer, which will install VirtualBox and the Boot2Docker management
|
||||
tool.
|
||||

|
||||
3. Open a terminal and run:
|
||||
|
||||
```
|
||||
boot2docker init
|
||||
boot2docker start
|
||||
export DOCKER_HOST=tcp://localhost:2375
|
||||
```
|
||||
3. Run the `Boot2Docker` app in the `Applications` folder:
|
||||

|
||||
|
||||
`boot2docker init` will ask you to enter an ssh key passphrase - the simplest
|
||||
(but least secure) is to just hit [Enter]. This passphrase is used by the
|
||||
`boot2docker ssh` command.
|
||||
Or, to initiate Boot2Docker manually, open a terminal and run:
|
||||
|
||||
Once you have an initialized virtual machine, you can `boot2docker stop`
|
||||
and `boot2docker start` it.
|
||||
$ boot2docker init
|
||||
$ boot2docker start
|
||||
$ export DOCKER_HOST=tcp://$(boot2docker ip 2>/dev/null):2375
|
||||
|
||||
The `boot2docker init` command will ask you to enter an SSH key passphrase - the simplest
|
||||
(but least secure) is to just hit [Enter]. This passphrase is used by the
|
||||
`boot2docker ssh` command.
|
||||
|
||||
Once you have an initialized virtual machine, you can control it with `boot2docker stop`
|
||||
and `boot2docker start`.
|
||||
|
||||
## Upgrading
|
||||
|
||||
To upgrade:
|
||||
|
||||
1. Download the latest release of the [Docker for OSX Installer](
|
||||
https://github.com/boot2docker/osx-installer/releases)
|
||||
|
||||
2. Run the installer, which will update VirtualBox and the Boot2Docker management
|
||||
tool.
|
||||
|
||||
3. To upgrade your existing virtual machine, open a terminal and run:
|
||||
|
||||
```
|
||||
boot2docker stop
|
||||
boot2docker download
|
||||
boot2docker start
|
||||
```
|
||||
$ boot2docker stop
|
||||
$ boot2docker download
|
||||
$ boot2docker start
|
||||
|
||||
## Running Docker
|
||||
|
||||
From your terminal, you can try the “hello world” example. Run:
|
||||
From your terminal, you can test that Docker is running with a “hello world” example.
|
||||
Start the vm and then run:
|
||||
|
||||
$ docker run ubuntu echo hello world
|
||||
|
||||
This will download the `ubuntu` image and print `hello world`.
|
||||
This should download the `ubuntu` image and print `hello world`.
|
||||
|
||||
## Container port redirection
|
||||
|
||||
The latest version of `boot2docker` sets up two network adapters: one using NAT
|
||||
to allow the VM to download images and files from the Internet, and one host only
|
||||
network adapter to which the container's ports will be exposed on.
|
||||
The latest version of `boot2docker` sets up a host only network adaptor which provides
|
||||
access to the container's ports.
|
||||
|
||||
If you run a container with an exposed port:
|
||||
If you run a container with an exposed port,
|
||||
|
||||
```
|
||||
docker run --rm -i -t -p 80:80 apache
|
||||
```
|
||||
$ docker run --rm -i -t -p 80:80 nginx
|
||||
|
||||
Then you should be able to access that Apache server using the IP address reported
|
||||
to you using:
|
||||
then you should be able to access that Nginx server using the IP address reported by:
|
||||
|
||||
```
|
||||
boot2docker ssh ip addr show dev eth1
|
||||
```
|
||||
$ boot2docker ssh ip addr show dev eth1
|
||||
|
||||
Typically, it is 192.168.59.103, but at this point it can change.
|
||||
|
||||
If you want to share container ports with other computers on your LAN, you will
|
||||
need to set up [NAT adaptor based port forwarding](
|
||||
https://github.com/boot2docker/boot2docker/blob/master/doc/WORKAROUNDS.md)
|
||||
Typically, it is 192.168.59.103, but it could get changed by Virtualbox's DHCP
|
||||
implementation.
|
||||
|
||||
# Further details
|
||||
|
||||
The Boot2Docker management tool provides some commands:
|
||||
If you are curious, the username for the boot2docker default user is `docker` and the password is `tcuser`.
|
||||
|
||||
```
|
||||
$ ./boot2docker
|
||||
Usage: ./boot2docker [<options>]
|
||||
{help|init|up|ssh|save|down|poweroff|reset|restart|config|status|info|delete|download|version}
|
||||
[<args>]
|
||||
```
|
||||
The Boot2Docker management tool provides several commands:
|
||||
|
||||
$ ./boot2docker
|
||||
Usage: ./boot2docker [<options>]
|
||||
{help|init|up|ssh|save|down|poweroff|reset|restart|config|status|info|delete|download|version}
|
||||
|
||||
Continue with the [User Guide](/userguide/).
|
||||
|
||||
For further information or to report issues, please see the [Boot2Docker site](http://boot2docker.io).
|
||||
For further information or to report issues, please visit the [Boot2Docker site](http://boot2docker.io).
|
||||
|
||||
@@ -17,7 +17,7 @@ Please read [*Docker and UFW*](#docker-and-ufw), if you plan to use [UFW
|
||||
## Ubuntu Trusty 14.04 (LTS) (64-bit)
|
||||
|
||||
Ubuntu Trusty comes with a 3.13.0 Linux kernel, and a `docker.io` package which
|
||||
installs all its prerequisites from Ubuntu's repository.
|
||||
installs Docker 0.9.1 and all its prerequisites from Ubuntu's repository.
|
||||
|
||||
> **Note**:
|
||||
> Ubuntu (and Debian) contain a much older KDE3/GNOME2 package called ``docker``, so the
|
||||
@@ -32,13 +32,45 @@ To install the latest Ubuntu package (may not be the latest Docker release):
|
||||
$ sudo ln -sf /usr/bin/docker.io /usr/local/bin/docker
|
||||
$ sudo sed -i '$acomplete -F _docker docker' /etc/bash_completion.d/docker.io
|
||||
|
||||
If you'd like to try the latest version of Docker:
|
||||
|
||||
First, check that your APT system can deal with `https`
|
||||
URLs: the file `/usr/lib/apt/methods/https`
|
||||
should exist. If it doesn't, you need to install the package
|
||||
`apt-transport-https`.
|
||||
|
||||
[ -e /usr/lib/apt/methods/https ] || {
|
||||
apt-get update
|
||||
apt-get install apt-transport-https
|
||||
}
|
||||
|
||||
Then, add the Docker repository key to your local keychain.
|
||||
|
||||
$ sudo apt-key adv --keyserver hkp://keyserver.ubuntu.com:80 --recv-keys 36A1D7869245C8950F966E92D8576A8BA88D21E9
|
||||
|
||||
Add the Docker repository to your apt sources list, update and install
|
||||
the `lxc-docker` package.
|
||||
|
||||
*You may receive a warning that the package isn't trusted. Answer yes to
|
||||
continue installation.*
|
||||
|
||||
$ sudo sh -c "echo deb https://get.docker.io/ubuntu docker main\
|
||||
> /etc/apt/sources.list.d/docker.list"
|
||||
$ sudo apt-get update
|
||||
$ sudo apt-get install lxc-docker
|
||||
|
||||
> **Note**:
|
||||
>
|
||||
> There is also a simple `curl` script available to help with this process.
|
||||
>
|
||||
> $ curl -s https://get.docker.io/ubuntu/ | sudo sh
|
||||
|
||||
To verify that everything has worked as expected:
|
||||
|
||||
$ sudo docker run -i -t ubuntu /bin/bash
|
||||
|
||||
Which should download the `ubuntu` image, and then start `bash` in a container.
|
||||
|
||||
|
||||
## Ubuntu Precise 12.04 (LTS) (64-bit)
|
||||
|
||||
This installation path should work at all times.
|
||||
@@ -284,7 +316,7 @@ Docker daemon for the containers:
|
||||
$ sudo nano /etc/default/docker
|
||||
---
|
||||
# Add:
|
||||
$ docker_OPTS="--dns 8.8.8.8"
|
||||
$ DOCKER_OPTS="--dns 8.8.8.8"
|
||||
# 8.8.8.8 could be replaced with a local DNS server, such as 192.168.1.1
|
||||
# multiple DNS servers can be specified: --dns 8.8.8.8 --dns 192.168.1.1
|
||||
|
||||
|
||||
@@ -3,97 +3,85 @@ page_description: Docker installation on Microsoft Windows
|
||||
page_keywords: Docker, Docker documentation, Windows, requirements, virtualbox, boot2docker
|
||||
|
||||
# Windows
|
||||
> **Note:**
|
||||
> Docker has been tested on Windows 7.1 and 8; it may also run on older versions.
|
||||
|
||||
> **Note**:
|
||||
> Docker is still under heavy development! We don't recommend using it in
|
||||
> production yet, but we're getting closer with each release. Please see
|
||||
> our blog post, [Getting to Docker 1.0](
|
||||
> http://blog.docker.io/2013/08/getting-to-docker-1-0/)
|
||||
|
||||
Docker Engine runs on Windows using a lightweight virtual machine. There
|
||||
is no native Windows Docker client yet, so everything is done inside the virtual
|
||||
machine.
|
||||
The Docker Engine uses Linux-specific kernel features, so to run it on Windows
|
||||
we need to use a lightweight virtual machine (vm). You use the Windows Docker client to
|
||||
control the virtualized Docker Engine to build, run, and manage Docker containers.
|
||||
|
||||
To make this process easier we designed a helper application called
|
||||
[boot2docker](https://github.com/boot2docker/boot2docker) to install the
|
||||
virtual machine and run the Docker daemon.
|
||||
To make this process easier, we've designed a helper application called
|
||||
[Boot2Docker](https://github.com/boot2docker/boot2docker) that installs the
|
||||
virtual machine and runs the Docker daemon.
|
||||
|
||||
## Demonstration
|
||||
|
||||
<iframe width="640" height="480" src="//www.youtube.com/embed/oSHN8_uiZd4?rel=0" frameborder="0" allowfullscreen></iframe>
|
||||
|
||||
## Installation
|
||||
|
||||
1. Download the latest release of the [Docker for Windows Installer](https://github.com/boot2docker/windows-installer/releases)
|
||||
2. Run the installer, which will install VirtualBox, MSYS-git, the boot2docker Linux ISO and the
|
||||
Boot2Docker management tool.
|
||||
2. Run the installer, which will install VirtualBox, MSYS-git, the boot2docker Linux ISO,
|
||||
and the Boot2Docker management tool.
|
||||

|
||||
3. Run the `Boot2Docker Start` shell script from your Desktop or Program Files > Docker.
|
||||
The Start script will ask you to enter an ssh key passphrase - the simplest
|
||||
(but least secure) is to just hit [Enter].
|
||||
|
||||

|
||||
|
||||
The `Boot2Docker Start` script will connect you to a shell session in the virtual
|
||||
Machine. If needed, it will initialise a new VM and start it.
|
||||
The `Boot2Docker Start` script will connect you to a shell session in the virtual
|
||||
machine. If needed, it will initialize a new VM and start it.
|
||||
|
||||
## Upgrading
|
||||
|
||||
To upgrade:
|
||||
|
||||
1. Download the latest release of the [Docker for Windows Installer](
|
||||
https://github.com/boot2docker/windows-installer/releases)
|
||||
|
||||
2. Run the installer, which will update the Boot2Docker management tool.
|
||||
|
||||
3. To upgrade your existing virtual machine, open a terminal and run:
|
||||
|
||||
```
|
||||
|
||||
boot2docker stop
|
||||
boot2docker download
|
||||
boot2docker start
|
||||
```
|
||||
|
||||
|
||||
## Running Docker
|
||||
|
||||
Boot2Docker will log you in automatically so you can start using Docker
|
||||
right away.
|
||||
Boot2Docker will log you in automatically so you can start using Docker right away.
|
||||
|
||||
Let's try the “hello world” example. Run
|
||||
|
||||
$ docker run busybox echo hello world
|
||||
|
||||
This will download the small busybox image and print hello world.
|
||||
This will download the small busybox image and print "hello world".
|
||||
|
||||
|
||||
# Further Details
|
||||
|
||||
The Boot2Docker management tool provides some commands:
|
||||
The Boot2Docker management tool provides several commands:
|
||||
|
||||
```
|
||||
$ ./boot2docker
|
||||
Usage: ./boot2docker [<options>] {help|init|up|ssh|save|down|poweroff|reset|restart|config|status|info|delete|download|version} [<args>]
|
||||
```
|
||||
$ ./boot2docker
|
||||
Usage: ./boot2docker [<options>] {help|init|up|ssh|save|down|poweroff|reset|restart|config|status|info|delete|download|version} [<args>]
|
||||
|
||||
## Container port redirection
|
||||
|
||||
The latest version of `boot2docker` sets up two network adaptors: one using NAT
|
||||
to allow the VM to download images and files from the Internet, and one host only
|
||||
network adaptor to which the container's ports will be exposed on.
|
||||
## Container port redirection
|
||||
|
||||
If you are curious, the username for the boot2docker default user is `docker` and the password is `tcuser`.
|
||||
|
||||
The latest version of `boot2docker` sets up a host only network adaptor which provides access to the container's ports.
|
||||
|
||||
If you run a container with an exposed port:
|
||||
|
||||
```
|
||||
docker run --rm -i -t -p 80:80 apache
|
||||
```
|
||||
docker run --rm -i -t -p 80:80 nginx
|
||||
|
||||
Then you should be able to access that Apache server using the IP address reported
|
||||
Then you should be able to access that nginx server using the IP address reported
|
||||
to you using:
|
||||
|
||||
```
|
||||
boot2docker ssh ip addr show dev eth1
|
||||
```
|
||||
|
||||
Typically, it is 192.168.59.103, but at this point it can change.
|
||||
|
||||
If you want to share container ports with other computers on your LAN, you will
|
||||
need to set up [NAT adaptor based port forwarding](
|
||||
https://github.com/boot2docker/boot2docker/blob/master/doc/WORKAROUNDS.md)
|
||||
|
||||
boot2docker ip
|
||||
|
||||
Typically, it is 192.168.59.103, but it could get changed by Virtualbox's DHCP
|
||||
implementation.
|
||||
|
||||
For further information or to report issues, please see the [Boot2Docker site](http://boot2docker.io)
|
||||
|
||||
@@ -3,326 +3,284 @@ page_description: Docker explained in depth
|
||||
page_keywords: docker, introduction, documentation, about, technology, understanding
|
||||
|
||||
# Understanding Docker
|
||||
|
||||
**What is Docker?**
|
||||
|
||||
Docker is a platform for developing, shipping, and running applications.
|
||||
Docker is designed to deliver your applications faster. With Docker you
|
||||
can separate your applications from your infrastructure AND treat your
|
||||
infrastructure like a managed application. We want to help you ship code
|
||||
faster, test faster, deploy faster and shorten the cycle between writing
|
||||
code and running code.
|
||||
Docker is an open platform for developing, shipping, and running applications.
|
||||
Docker is designed to deliver your applications faster. With Docker you can
|
||||
separate your applications from your infrastructure AND treat your
|
||||
infrastructure like a managed application. Docker helps you ship code faster,
|
||||
test faster, deploy faster, and shorten the cycle between writing code and
|
||||
running code.
|
||||
|
||||
Docker does this by combining a lightweight container virtualization
|
||||
platform with workflow and tooling that helps you manage and deploy your
|
||||
applications.
|
||||
Docker does this by combining a lightweight container virtualization platform
|
||||
with workflows and tooling that help you manage and deploy your applications.
|
||||
|
||||
At its core Docker provides a way to run almost any application securely
|
||||
isolated into a container. The isolation and security allows you to run
|
||||
many containers simultaneously on your host. The lightweight nature of
|
||||
containers, which run without the extra overload of a hypervisor, means
|
||||
you can get more out of your hardware.
|
||||
At its core, Docker provides a way to run almost any application securely
|
||||
isolated in a container. The isolation and security allow you to run many
|
||||
containers simultaneously on your host. The lightweight nature of containers,
|
||||
which run without the extra load of a hypervisor, means you can get more out of
|
||||
your hardware.
|
||||
|
||||
Surrounding the container virtualization, we provide tooling and a
|
||||
platform to help you get your applications (and its supporting
|
||||
components) into Docker containers, to distribute and ship those
|
||||
containers to your teams to develop and test on them and then to deploy
|
||||
those applications to your production environment whether it be in a
|
||||
local data center or the Cloud.
|
||||
Surrounding the container virtualization are tooling and a platform which can
|
||||
help you in several ways:
|
||||
|
||||
* getting your applications (and supporting components) into Docker containers
|
||||
* distributing and shipping those containers to your teams for further development
|
||||
and testing
|
||||
* deploying those applications to your production environment,
|
||||
whether it be in a local data center or the Cloud.
|
||||
|
||||
## What can I use Docker for?
|
||||
|
||||
* Faster delivery of your applications
|
||||
*Faster delivery of your applications*
|
||||
|
||||
Docker is perfect for helping you with the development lifecycle. Docker
|
||||
can allow your developers to develop on local containers that contain
|
||||
your applications and services. It can integrate into a continuous
|
||||
integration and deployment workflow.
|
||||
allows your developers to develop on local containers that contain your
|
||||
applications and services. It can then integrate into a continuous integration and
|
||||
deployment workflow.
|
||||
|
||||
Your developers write code locally and share their development stack via
|
||||
Docker with their colleagues. When they are ready they can push their
|
||||
code and the stack they are developing on to a test environment and
|
||||
execute any required tests. From the testing environment you can then
|
||||
push your Docker images into production and deploy your code.
|
||||
For example, your developers write code locally and share their development stack via
|
||||
Docker with their colleagues. When they are ready, they push their code and the
|
||||
stack they are developing onto a test environment and execute any required
|
||||
tests. From the testing environment, you can then push the Docker images into
|
||||
production and deploy your code.
|
||||
|
||||
* Deploy and scale more easily
|
||||
*Deploying and scaling more easily*
|
||||
|
||||
Docker's container platform allows you to have highly portable
|
||||
workloads. Docker containers can run on a developer's local host, on
|
||||
physical or virtual machines in a data center or in the Cloud.
|
||||
Docker's container-based platform allows for highly portable workloads. Docker
|
||||
containers can run on a developer's local host, on physical or virtual machines
|
||||
in a data center, or in the Cloud.
|
||||
|
||||
Docker's portability and lightweight nature also makes managing
|
||||
workloads dynamically easy. You can use Docker to build and scale out
|
||||
applications and services. Docker's speed means that scaling can be near
|
||||
real time.
|
||||
Docker's portability and lightweight nature also make dynamically managing
|
||||
workloads easy. You can use Docker to quickly scale up or tear down applications
|
||||
and services. Docker's speed means that scaling can be near real time.
|
||||
|
||||
* Get higher density and run more workloads
|
||||
*Achieving higher density and running more workloads**
|
||||
|
||||
Docker is lightweight and fast. It provides a viable (and
|
||||
cost-effective!) alternative to hypervisor-based virtual machines. This
|
||||
is especially useful in high density environments, for example building
|
||||
your own Cloud or Platform-as-a-Service. But it is also useful
|
||||
for small and medium deployments where you want to get more out of the
|
||||
resources you have.
|
||||
Docker is lightweight and fast. It provides a viable, cost-effective alternative
|
||||
to hypervisor-based virtual machines. This is especially useful in high density
|
||||
environments: for example, building your own Cloud or Platform-as-a-Service. But
|
||||
it is also useful for small and medium deployments where you want to get more
|
||||
out of the resources you have.
|
||||
|
||||
## What are the major Docker components?
|
||||
|
||||
Docker has two major components:
|
||||
|
||||
|
||||
* Docker: the open source container virtualization platform.
|
||||
* [Docker.io](https://index.docker.io): our Software-as-a-Service
|
||||
* [Docker Hub](https://hub.docker.com): our Software-as-a-Service
|
||||
platform for sharing and managing Docker containers.
|
||||
|
||||
**Note:** Docker is licensed with the open source Apache 2.0 license.
|
||||
|
||||
## What is the architecture of Docker?
|
||||
**Note:** Docker is licensed under the open source Apache 2.0 license.
|
||||
|
||||
Docker has a client-server architecture. The Docker *client* talks to
|
||||
the Docker *daemon* which does the heavy lifting of building, running
|
||||
and distributing your Docker containers. Both the Docker client and the
|
||||
daemon *can* run on the same system, or you can connect a Docker client
|
||||
with a remote Docker daemon. The Docker client and service can
|
||||
communicate via sockets or through a RESTful API.
|
||||
## What is Docker's architecture?
|
||||
Docker uses a client-server architecture. The Docker *client* talks to the
|
||||
Docker *daemon*, which does the heavy lifting of building, running, and
|
||||
distributing your Docker containers. Both the Docker client and the daemon *can*
|
||||
run on the same system, or you can connect a Docker client to a remote Docker
|
||||
daemon. The Docker client and service communicate via sockets or through a
|
||||
RESTful API.
|
||||
|
||||

|
||||
|
||||
### The Docker daemon
|
||||
As shown in the diagram above, the Docker daemon runs on a host machine. The
|
||||
user does not directly interact with the daemon, but instead through the Docker
|
||||
client.
|
||||
|
||||
As shown on the diagram above, the Docker daemon runs on a host machine.
|
||||
The user does not directly interact with the daemon, but instead through
|
||||
the Docker client.
|
||||
|
||||
### The Docker client
|
||||
|
||||
### The Docker client
|
||||
The Docker client, in the form of the `docker` binary, is the primary user
|
||||
interface to Docker. It is tasked with accepting commands from the user
|
||||
and communicating back and forth with a Docker daemon.
|
||||
interface to Docker. It accepts commands from the user and communicates back and
|
||||
forth with a Docker daemon.
|
||||
|
||||
### Inside Docker
|
||||
### Inside Docker
|
||||
To understand Docker's internals, you need to know about three components:
|
||||
|
||||
Inside Docker there are three concepts we’ll need to understand:
|
||||
|
||||
* Docker images.
|
||||
* Docker registries.
|
||||
* Docker images.
|
||||
* Docker registries.
|
||||
* Docker containers.
|
||||
|
||||
#### Docker images
|
||||
|
||||
The Docker image is a read-only template, for example an Ubuntu operating system
|
||||
with Apache and your web application installed. Docker containers are
|
||||
created from images. You can download Docker images that other people
|
||||
have created or Docker provides a simple way to build new images or
|
||||
update existing images. You can consider Docker images to be the **build**
|
||||
portion of Docker.
|
||||
A Docker image is a read-only template. For example, an image could contain an Ubuntu
|
||||
operating system with Apache and your web application installed. Images are used to create
|
||||
Docker containers. Docker provides a simple way to build new images or update existing
|
||||
images, or you can download Docker images that other people have already created.
|
||||
Docker images are the **build** component of Docker.
|
||||
|
||||
#### Docker Registries
|
||||
Docker registries hold images. These are public or private stores from which you upload
|
||||
or download images. The public Docker registry is called
|
||||
[Docker Hub](http://index.docker.io). It provides a huge collection of existing
|
||||
images for your use. These can be images you create yourself or you
|
||||
can use images that others have previously created. Docker registries are the
|
||||
**distribution** component of Docker.
|
||||
|
||||
Docker registries hold images. These are public (or private!) stores
|
||||
that you can upload or download images to and from. The public Docker
|
||||
registry is called [Docker.io](http://index.docker.io). It provides a
|
||||
huge collection of existing images that you can use. These images can be
|
||||
images you create yourself or you can make use of images that others
|
||||
have previously created. You can consider Docker registries the
|
||||
**distribution** portion of Docker.
|
||||
####Docker containers
|
||||
Docker containers are similar to a directory. A Docker container holds everything that
|
||||
is needed for an application to run. Each container is created from a Docker
|
||||
image. Docker containers can be run, started, stopped, moved, and deleted. Each
|
||||
container is an isolated and secure application platform. Docker containers are the
|
||||
**run** component of Docker.
|
||||
|
||||
#### Docker containers
|
||||
|
||||
Docker containers are like a directory. A Docker container holds
|
||||
everything that is needed for an application to run. Each container is
|
||||
created from a Docker image. Docker containers can be run, started,
|
||||
stopped, moved and deleted. Each container is an isolated and secure
|
||||
application platform. You can consider Docker containers the **run**
|
||||
portion of Docker.
|
||||
|
||||
## So how does Docker work?
|
||||
|
||||
We've learned so far that:
|
||||
##So how does Docker work?
|
||||
So far, we've learned that:
|
||||
|
||||
1. You can build Docker images that hold your applications.
|
||||
2. You can create Docker containers from those Docker images to run your
|
||||
applications.
|
||||
3. You can share those Docker images via
|
||||
[Docker.io](https://index.docker.io) or your own registry.
|
||||
[Docker Hub](https://hub.docker.com) or your own registry.
|
||||
|
||||
Let's look at how these elements combine together to make Docker work.
|
||||
|
||||
### How does a Docker Image work?
|
||||
### How does a Docker Image work?
|
||||
We've already seen that Docker images are read-only templates from which Docker
|
||||
containers are launched. Each image consists of a series of layers. Docker
|
||||
makes use of [union file systems](http://en.wikipedia.org/wiki/UnionFS) to
|
||||
combine these layers into a single image. Union file systems allow files and
|
||||
directories of separate file systems, known as branches, to be transparently
|
||||
overlaid, forming a single coherent file system.
|
||||
|
||||
We've already seen that Docker images are read-only templates that
|
||||
Docker containers are launched from. Each image consists of a series of
|
||||
layers. Docker makes use of [union file
|
||||
systems](http://en.wikipedia.org/wiki/UnionFS) to combine these layers
|
||||
into a single image. Union file systems allow files and directories of
|
||||
separate file systems, known as branches, to be transparently overlaid,
|
||||
forming a single coherent file system.
|
||||
One of the reasons Docker is so lightweight is because of these layers. When you
|
||||
change a Docker image—for example, update an application to a new version— a new layer
|
||||
gets built. Thus, rather than replacing the whole image or entirely
|
||||
rebuilding, as you may do with a virtual machine, only that layer is added or
|
||||
updated. Now you don't need to distribute a whole new image, just the update,
|
||||
making distributing Docker images faster and simpler.
|
||||
|
||||
One of the reasons Docker is so lightweight is because of these layers.
|
||||
When you change a Docker image, for example update an application to a
|
||||
new version, this builds a new layer. Hence, rather than replacing the whole
|
||||
image or entirely rebuilding, as you may do with a virtual machine, only
|
||||
that layer is added or updated. Now you don't need to distribute a whole new image,
|
||||
just the update, making distributing Docker images fast and simple.
|
||||
Every image starts from a base image, for example `ubuntu`, a base Ubuntu image,
|
||||
or `fedora`, a base Fedora image. You can also use images of your own as the
|
||||
basis for a new image, for example if you have a base Apache image you could use
|
||||
this as the base of all your web application images.
|
||||
|
||||
Every image starts from a base image, for example `ubuntu`, a base Ubuntu
|
||||
image, or `fedora`, a base Fedora image. You can also use images of your
|
||||
own as the basis for a new image, for example if you have a base Apache
|
||||
image you could use this as the base of all your web application images.
|
||||
> **Note:** Docker usually gets these base images from
|
||||
> [Docker Hub](https://index.docker.io).
|
||||
>
|
||||
Docker images are then built from these base images using a simple, descriptive
|
||||
set of steps we call *instructions*. Each instruction creates a new layer in our
|
||||
image. Instructions include actions like:
|
||||
|
||||
> **Note:**
|
||||
> Docker usually gets these base images from [Docker.io](https://index.docker.io).
|
||||
|
||||
Docker images are then built from these base images using a simple
|
||||
descriptive set of steps we call *instructions*. Each instruction
|
||||
creates a new layer in our image. Instructions include steps like:
|
||||
|
||||
* Run a command.
|
||||
* Add a file or directory.
|
||||
* Run a command.
|
||||
* Add a file or directory.
|
||||
* Create an environment variable.
|
||||
* What process to run when launching a container from this image.
|
||||
|
||||
These instructions are stored in a file called a `Dockerfile`. Docker
|
||||
reads this `Dockerfile` when you request an image be built, executes the
|
||||
instructions and returns a final image.
|
||||
These instructions are stored in a file called a `Dockerfile`. Docker reads this
|
||||
`Dockerfile` when you request a build of an image, executes the instructions, and
|
||||
returns a final image.
|
||||
|
||||
### How does a Docker registry work?
|
||||
The Docker registry is the store for your Docker images. Once you build a Docker
|
||||
image you can *push* it to a public registry [Docker Hub](https://index.docker.io) or to
|
||||
your own registry running behind your firewall.
|
||||
|
||||
The Docker registry is the store for your Docker images. Once you build
|
||||
a Docker image you can *push* it to a public registry [Docker.io](
|
||||
https://index.docker.io) or to your own registry running behind your
|
||||
firewall.
|
||||
Using the Docker client, you can search for already published images and then
|
||||
pull them down to your Docker host to build containers from them.
|
||||
|
||||
Using the Docker client, you can search for already published images and
|
||||
then pull them down to your Docker host to build containers from them.
|
||||
|
||||
[Docker.io](https://index.docker.io) provides both public and
|
||||
private storage for images. Public storage is searchable and can be
|
||||
downloaded by anyone. Private storage is excluded from search
|
||||
results and only you and your users can pull them down and use them to
|
||||
build containers. You can [sign up for a plan
|
||||
[Docker Hub](https://index.docker.io) provides both public and private storage
|
||||
for images. Public storage is searchable and can be downloaded by anyone.
|
||||
Private storage is excluded from search results and only you and your users can
|
||||
pull images down and use them to build containers. You can [sign up for a storage plan
|
||||
here](https://index.docker.io/plans).
|
||||
|
||||
### How does a container work?
|
||||
|
||||
A container consists of an operating system, user added files and
|
||||
meta-data. As we've discovered each container is built from an image. That image tells
|
||||
Docker what the container holds, what process to run when the container
|
||||
is launched and a variety of other configuration data. The Docker image
|
||||
is read-only. When Docker runs a container from an image it adds a
|
||||
read-write layer on top of the image (using a union file system as we
|
||||
saw earlier) in which your application is then run.
|
||||
A container consists of an operating system, user-added files, and meta-data. As
|
||||
we've seen, each container is built from an image. That image tells Docker
|
||||
what the container holds, what process to run when the container is launched, and
|
||||
a variety of other configuration data. The Docker image is read-only. When
|
||||
Docker runs a container from an image, it adds a read-write layer on top of the
|
||||
image (using a union file system as we saw earlier) in which your application can
|
||||
then run.
|
||||
|
||||
### What happens when you run a container?
|
||||
|
||||
The Docker client using the `docker` binary, or via the API, tells the
|
||||
Docker daemon to run a container. Let's take a look at what happens
|
||||
next.
|
||||
Either by using the `docker` binary or via the API, the Docker client tells the Docker
|
||||
daemon to run a container.
|
||||
|
||||
$ docker run -i -t ubuntu /bin/bash
|
||||
|
||||
Let's break down this command. The Docker client is launched using the
|
||||
`docker` binary with the `run` option telling it to launch a new
|
||||
container. The bare minimum the Docker client needs to tell the
|
||||
Docker daemon to run the container is:
|
||||
Let's break down this command. The Docker client is launched using the `docker`
|
||||
binary with the `run` option telling it to launch a new container. The bare
|
||||
minimum the Docker client needs to tell the Docker daemon to run the container
|
||||
is:
|
||||
|
||||
* What Docker image to build the container from, here `ubuntu`, a base
|
||||
Ubuntu image;
|
||||
* What Docker image to build the container from, here `ubuntu`, a base Ubuntu
|
||||
image;
|
||||
* The command you want to run inside the container when it is launched,
|
||||
here `bin/bash` to shell the Bash shell inside the new container.
|
||||
here `/bin/bash`, to start the Bash shell inside the new container.
|
||||
|
||||
So what happens under the covers when we run this command?
|
||||
So what happens under the hood when we run this command?
|
||||
|
||||
Docker begins with:
|
||||
In order, Docker does the following:
|
||||
|
||||
- **Pulling the `ubuntu` image:**
|
||||
Docker checks for the presence of the `ubuntu` image and if it doesn't
|
||||
exist locally on the host, then Docker downloads it from
|
||||
[Docker.io](https://index.docker.io). If the image already exists then
|
||||
Docker uses it for the new container.
|
||||
- **Creates a new container:**
|
||||
Once Docker has the image it creates a container from it:
|
||||
* **Allocates a filesystem and mounts a read-write _layer_:**
|
||||
The container is created in the file system and a read-write layer is
|
||||
added to the image.
|
||||
* **Allocates a network / bridge interface:**
|
||||
Creates a network interface that allows the Docker container to talk to
|
||||
the local host.
|
||||
* **Sets up an IP address:**
|
||||
Finds and attaches an available IP address from a pool.
|
||||
- **Executes a process that you specify:**
|
||||
Runs your application, and;
|
||||
- **Captures and provides application output:**
|
||||
Connects and logs standard input, outputs and errors for you to see how
|
||||
your application is running.
|
||||
- **Pulls the `ubuntu` image:** Docker checks for the presence of the `ubuntu`
|
||||
image and, if it doesn't exist locally on the host, then Docker downloads it from
|
||||
[Docker Hub](https://index.docker.io). If the image already exists, then Docker
|
||||
uses it for the new container.
|
||||
- **Creates a new container:** Once Docker has the image, it uses it to create a
|
||||
container.
|
||||
- **Allocates a filesystem and mounts a read-write _layer_:** The container is created in
|
||||
the file system and a read-write layer is added to the image.
|
||||
- **Allocates a network / bridge interface:** Creates a network interface that allows the
|
||||
Docker container to talk to the local host.
|
||||
- **Sets up an IP address:** Finds and attaches an available IP address from a pool.
|
||||
- **Executes a process that you specify:** Runs your application, and;
|
||||
- **Captures and provides application output:** Connects and logs standard input, outputs
|
||||
and errors for you to see how your application is running.
|
||||
|
||||
Now you have a running container! From here you can manage your running
|
||||
container, interact with your application and then when finished stop
|
||||
and remove your container.
|
||||
You now have a running container! From here you can manage your container, interact with
|
||||
your application and then, when finished, stop and remove your container.
|
||||
|
||||
## The underlying technology
|
||||
|
||||
Docker is written in Go and makes use of several Linux kernel features to
|
||||
deliver the features we've seen.
|
||||
deliver the functionality we've seen.
|
||||
|
||||
### Namespaces
|
||||
Docker takes advantage of a technology called `namespaces` to provide the
|
||||
isolated workspace we call the *container*. When you run a container, Docker
|
||||
creates a set of *namespaces* for that container.
|
||||
|
||||
Docker takes advantage of a technology called `namespaces` to provide an
|
||||
isolated workspace we call a *container*. When you run a container,
|
||||
Docker creates a set of *namespaces* for that container.
|
||||
|
||||
This provides a layer of isolation: each aspect of a container runs in
|
||||
its own namespace and does not have access outside it.
|
||||
This provides a layer of isolation: each aspect of a container runs in its own
|
||||
namespace and does not have access outside it.
|
||||
|
||||
Some of the namespaces that Docker uses are:
|
||||
|
||||
- **The `pid` namespace:**
|
||||
Used for process isolation (PID: Process ID).
|
||||
- **The `net` namespace:**
|
||||
Used for managing network interfaces (NET: Networking).
|
||||
- **The `ipc` namespace:**
|
||||
Used for managing access to IPC resources (IPC: InterProcess
|
||||
Communication).
|
||||
- **The `mnt` namespace:**
|
||||
Used for managing mount-points (MNT: Mount).
|
||||
- **The `uts` namespace:**
|
||||
Used for isolating kernel and version identifiers. (UTS: Unix Timesharing
|
||||
System).
|
||||
- **The `pid` namespace:** Used for process isolation (PID: Process ID).
|
||||
- **The `net` namespace:** Used for managing network interfaces (NET:
|
||||
Networking).
|
||||
- **The `ipc` namespace:** Used for managing access to IPC
|
||||
resources (IPC: InterProcess Communication).
|
||||
- **The `mnt` namespace:** Used for managing mount-points (MNT: Mount).
|
||||
- **The `uts` namespace:** Used for isolating kernel and version identifiers. (UTS: Unix
|
||||
Timesharing System).
|
||||
|
||||
### Control groups
|
||||
|
||||
Docker also makes use of another technology called `cgroups` or control
|
||||
groups. A key need to run applications in isolation is to have them only
|
||||
use the resources you want. This ensures containers are good
|
||||
multi-tenant citizens on a host. Control groups allow Docker to
|
||||
share available hardware resources to containers and if required, set up to
|
||||
limits and constraints, for example limiting the memory available to a
|
||||
specific container.
|
||||
Docker also makes use of another technology called `cgroups` or control groups.
|
||||
A key to running applications in isolation is to have them only use the
|
||||
resources you want. This ensures containers are good multi-tenant citizens on a
|
||||
host. Control groups allow Docker to share available hardware resources to
|
||||
containers and, if required, set up limits and constraints. For example,
|
||||
limiting the memory available to a specific container.
|
||||
|
||||
### Union file systems
|
||||
Union file systems, or UnionFS, are file systems that operate by creating layers,
|
||||
making them very lightweight and fast. Docker uses union file systems to provide
|
||||
the building blocks for containers. Docker can make use of several union file system variants
|
||||
including: AUFS, btrfs, vfs, and DeviceMapper.
|
||||
|
||||
Union file systems or UnionFS are file systems that operate by creating
|
||||
layers, making them very lightweight and fast. Docker uses union file
|
||||
systems to provide the building blocks for containers. We learned about
|
||||
union file systems earlier in this document. Docker can make use of
|
||||
several union file system variants including: AUFS, btrfs, vfs, and
|
||||
DeviceMapper.
|
||||
|
||||
### Container format
|
||||
|
||||
Docker combines these components into a wrapper we call a container
|
||||
format. The default container format is called `libcontainer`. Docker
|
||||
also supports traditional Linux containers using
|
||||
[LXC](https://linuxcontainers.org/). In future Docker may support other
|
||||
container formats, for example integration with BSD Jails or Solaris
|
||||
Zones.
|
||||
### Container format
|
||||
Docker combines these components into a wrapper we call a container format. The
|
||||
default container format is called `libcontainer`. Docker also supports
|
||||
traditional Linux containers using [LXC](https://linuxcontainers.org/). In the
|
||||
future, Docker may support other container formats, for example, by integrating with
|
||||
BSD Jails or Solaris Zones.
|
||||
|
||||
## Next steps
|
||||
|
||||
### Installing Docker
|
||||
|
||||
Visit the [installation](/installation/#installation) section.
|
||||
Visit the [installation section](/installation/#installation).
|
||||
|
||||
### The Docker User Guide
|
||||
|
||||
[Learn how to use Docker](/userguide/).
|
||||
[Learn Docker in depth](/userguide/).
|
||||
|
||||
|
||||
|
||||
@@ -42,7 +42,7 @@ interfaces:
|
||||
|
||||
- [3 Authorization](registry_api/#authorization)
|
||||
|
||||
- [Docker.io API](index_api/)
|
||||
- [Docker Hub API](index_api/)
|
||||
- [1. Brief introduction](index_api/#brief-introduction)
|
||||
- [2. Endpoints](index_api/#endpoints)
|
||||
- [2.1 Repository](index_api/#repository)
|
||||
@@ -52,6 +52,7 @@ interfaces:
|
||||
- [Docker Remote API](docker_remote_api/)
|
||||
- [1. Brief introduction](docker_remote_api/#brief-introduction)
|
||||
- [2. Versions](docker_remote_api/#versions)
|
||||
- [v1.12](docker_remote_api/#v1-12)
|
||||
- [v1.11](docker_remote_api/#v1-11)
|
||||
- [v1.10](docker_remote_api/#v1-10)
|
||||
- [v1.9](docker_remote_api/#v1-9)
|
||||
@@ -83,4 +84,4 @@ interfaces:
|
||||
- [1.3 List email addresses for a user](docker_io_accounts_api/#list-email-addresses-for-a-user)
|
||||
- [1.4 Add email address for a user](docker_io_accounts_api/#add-email-address-for-a-user)
|
||||
- [1.5 Update an email address for a user](docker_io_accounts_api/#update-an-email-address-for-a-user)
|
||||
- [1.6 Delete email address for a user](docker_io_accounts_api/#delete-email-address-for-a-user)
|
||||
- [1.6 Delete email address for a user](docker_io_accounts_api/#delete-email-address-for-a-user)
|
||||
|
||||
@@ -1,12 +1,12 @@
|
||||
page_title: Docker.io API
|
||||
page_description: API Documentation for the Docker.io API
|
||||
page_keywords: API, Docker, index, REST, documentation, Docker.io, registry
|
||||
page_title: Docker Hub API
|
||||
page_description: API Documentation for the Docker Hub API
|
||||
page_keywords: API, Docker, index, REST, documentation, Docker Hub, registry
|
||||
|
||||
# Docker.io API
|
||||
# Docker Hub API
|
||||
|
||||
## Introduction
|
||||
|
||||
- This is the REST API for [Docker.io](http://index.docker.io).
|
||||
- This is the REST API for [Docker Hub](https://hub.docker.com).
|
||||
- Authorization is done with basic auth over SSL
|
||||
- Not all commands require authentication, only those noted as such.
|
||||
|
||||
|
||||
@@ -117,7 +117,7 @@ an Authorization Code.
|
||||
## 3.2 Get an Access Token
|
||||
|
||||
Once the user has authorized your application, a request will be made to
|
||||
your application'sspecified `redirect_uri` which
|
||||
your application's specified `redirect_uri` which
|
||||
includes a `code` parameter that you must then use
|
||||
to get an Access Token.
|
||||
|
||||
|
||||
@@ -4,29 +4,27 @@ page_keywords: API, Docker, rcli, REST, documentation
|
||||
|
||||
# Docker Remote API
|
||||
|
||||
- The Remote API is replacing rcli
|
||||
- By default the Docker daemon listens on unix:///var/run/docker.sock
|
||||
and the client must have root access to interact with the daemon
|
||||
- If a group named *docker* exists on your system, docker will apply
|
||||
ownership of the socket to the group
|
||||
- The Remote API is replacing `rcli`.
|
||||
- By default the Docker daemon listens on `unix:///var/run/docker.sock`
|
||||
and the client must have `root` access to interact with the daemon.
|
||||
- If a group named `docker` exists on your system, docker will apply
|
||||
ownership of the socket to the group.
|
||||
- The API tends to be REST, but for some complex commands, like attach
|
||||
or pull, the HTTP connection is hijacked to transport stdout stdin
|
||||
and stderr
|
||||
or pull, the HTTP connection is hijacked to transport STDOUT, STDIN,
|
||||
and STDERR.
|
||||
- Since API version 1.2, the auth configuration is now handled client
|
||||
side, so the client has to send the authConfig as POST in /images/(name)/push
|
||||
side, so the client has to send the `authConfig` as a `POST` in `/images/(name)/push`.
|
||||
- authConfig, set as the `X-Registry-Auth` header, is currently a Base64
|
||||
encoded (json) string with credentials:
|
||||
encoded (JSON) string with credentials:
|
||||
`{'username': string, 'password': string, 'email': string, 'serveraddress' : string}`
|
||||
|
||||
|
||||
|
||||
The current version of the API is v1.12
|
||||
|
||||
Calling /images/<name>/insert is the same as calling
|
||||
/v1.12/images/<name>/insert
|
||||
Calling `/images/<name>/insert` is the same as calling
|
||||
`/v1.12/images/<name>/insert`.
|
||||
|
||||
You can still call an old version of the api using
|
||||
/v1.12/images/<name>/insert
|
||||
You can still call an old version of the API using
|
||||
`/v1.12/images/<name>/insert`.
|
||||
|
||||
## v1.12
|
||||
|
||||
@@ -51,7 +49,7 @@ All the JSON keys are now in CamelCase
|
||||
Trusted builds are now Automated Builds - `is_trusted` is now `is_automated`.
|
||||
|
||||
**Removed Insert Endpoint**
|
||||
The insert endpoint has been removed.
|
||||
The `insert` endpoint has been removed.
|
||||
|
||||
## v1.11
|
||||
|
||||
@@ -96,7 +94,7 @@ You can now use the force parameter to force delete of an
|
||||
`DELETE /containers/(id)`
|
||||
|
||||
**New!**
|
||||
You can now use the force paramter to force delete a
|
||||
You can now use the force parameter to force delete a
|
||||
container, even if it is currently running
|
||||
|
||||
## v1.9
|
||||
|
||||
@@ -734,7 +734,7 @@ Remove the image `name` from the filesystem
|
||||
|
||||
`GET /images/search`
|
||||
|
||||
Search for an image on [Docker.io](https://index.docker.io)
|
||||
Search for an image on [Docker Hub](https://hub.docker.com)
|
||||
|
||||
**Example request**:
|
||||
|
||||
|
||||
@@ -745,7 +745,7 @@ Remove the image `name` from the filesystem
|
||||
|
||||
`GET /images/search`
|
||||
|
||||
Search for an image on [Docker.io](https://index.docker.io)
|
||||
Search for an image on [Docker Hub](https://hub.docker.com)
|
||||
|
||||
**Example request**:
|
||||
|
||||
|
||||
@@ -932,7 +932,7 @@ Tag the image `name` into a repository
|
||||
|
||||
`GET /images/search`
|
||||
|
||||
Search for an image on [Docker.io](https://index.docker.io).
|
||||
Search for an image on [Docker Hub](https://hub.docker.com).
|
||||
|
||||
> **Note**:
|
||||
> The response keys have changed from API v1.6 to reflect the JSON
|
||||
|
||||
@@ -6,12 +6,12 @@ page_keywords: API, Docker, rcli, REST, documentation
|
||||
|
||||
## 1. Brief introduction
|
||||
|
||||
- The Remote API has replaced rcli
|
||||
- The Remote API has replaced `rcli`.
|
||||
- The daemon listens on `unix:///var/run/docker.sock` but you can bind
|
||||
Docker to another host/port or a Unix socket.
|
||||
- The API tends to be REST, but for some complex commands, like `attach`
|
||||
or `pull`, the HTTP connection is hijacked to transport `stdout, stdin`
|
||||
and `stderr`
|
||||
or `pull`, the HTTP connection is hijacked to transport `STDOUT`, `STDIN`
|
||||
and `STDERR`.
|
||||
|
||||
# 2. Endpoints
|
||||
|
||||
@@ -948,7 +948,7 @@ Remove the image `name` from the filesystem
|
||||
|
||||
`GET /images/search`
|
||||
|
||||
Search for an image on [Docker.io](https://index.docker.io).
|
||||
Search for an image on [Docker Hub](https://hub.docker.com).
|
||||
|
||||
> **Note**:
|
||||
> The response keys have changed from API v1.6 to reflect the JSON
|
||||
|
||||
@@ -6,13 +6,13 @@ page_keywords: API, Docker, rcli, REST, documentation
|
||||
|
||||
## 1. Brief introduction
|
||||
|
||||
- The Remote API has replaced rcli
|
||||
- The Remote API has replaced `rcli`.
|
||||
- The daemon listens on `unix:///var/run/docker.sock` but you can
|
||||
[*Bind Docker to another host/port or a Unix socket*](
|
||||
/use/basics/#bind-docker).
|
||||
- The API tends to be REST, but for some complex commands, like `attach`
|
||||
or `pull`, the HTTP connection is hijacked to transport `stdout, stdin`
|
||||
and `stderr`
|
||||
or `pull`, the HTTP connection is hijacked to transport `STDOUT`,
|
||||
`STDIN` and `STDERR`.
|
||||
|
||||
# 2. Endpoints
|
||||
|
||||
@@ -406,6 +406,7 @@ Start the container `id`
|
||||
|
||||
{
|
||||
"Binds":["/tmp:/tmp"],
|
||||
"Links":["redis3:redis"],
|
||||
"LxcConf":{"lxc.utsname":"docker"},
|
||||
"PortBindings":{ "22/tcp": [{ "HostPort": "11022" }] },
|
||||
"PublishAllPorts":false,
|
||||
@@ -983,7 +984,7 @@ Remove the image `name` from the filesystem
|
||||
|
||||
`GET /images/search`
|
||||
|
||||
Search for an image on [Docker.io](https://index.docker.io).
|
||||
Search for an image on [Docker Hub](https://hub.docker.com).
|
||||
|
||||
> **Note**:
|
||||
> The response keys have changed from API v1.6 to reflect the JSON
|
||||
@@ -1164,6 +1165,7 @@ Show the docker version information
|
||||
Content-Type: application/json
|
||||
|
||||
{
|
||||
"ApiVersion":"1.12",
|
||||
"Version":"0.2.2",
|
||||
"GitCommit":"5a2a5cc+CHANGES",
|
||||
"GoVersion":"go1.0.3"
|
||||
|
||||
@@ -772,7 +772,7 @@ Remove the image `name` from the filesystem
|
||||
|
||||
`GET /images/search`
|
||||
|
||||
Search for an image on [Docker.io](https://index.docker.io)
|
||||
Search for an image on [Docker Hub](https://hub.docker.com)
|
||||
|
||||
**Example request**:
|
||||
|
||||
|
||||
@@ -821,7 +821,7 @@ Remove the image `name` from the filesystem
|
||||
|
||||
`GET /images/search`
|
||||
|
||||
Search for an image on [Docker.io](https://index.docker.io)
|
||||
Search for an image on [Docker Hub](https://hub.docker.com)
|
||||
|
||||
**Example request**:
|
||||
|
||||
|
||||
@@ -866,7 +866,7 @@ Remove the image `name` from the filesystem
|
||||
|
||||
`GET /images/search`
|
||||
|
||||
Search for an image on [Docker.io](https://index.docker.io)
|
||||
Search for an image on [Docker Hub](https://hub.docker.com)
|
||||
|
||||
**Example request**:
|
||||
|
||||
|
||||
@@ -871,7 +871,7 @@ Remove the image `name` from the filesystem
|
||||
|
||||
`GET /images/search`
|
||||
|
||||
Search for an image on [Docker.io](https://index.docker.io)
|
||||
Search for an image on [Docker Hub](https://hub.docker.com)
|
||||
|
||||
**Example request**:
|
||||
|
||||
|
||||
@@ -975,7 +975,7 @@ Remove the image `name` from the filesystem
|
||||
|
||||
`GET /images/search`
|
||||
|
||||
Search for an image on [Docker.io](https://index.docker.io)
|
||||
Search for an image on [Docker Hub](https://hub.docker.com)
|
||||
|
||||
**Example request**:
|
||||
|
||||
|
||||
@@ -901,7 +901,7 @@ Remove the image `name` from the filesystem
|
||||
|
||||
`GET /images/search`
|
||||
|
||||
Search for an image on [Docker.io](https://index.docker.io).
|
||||
Search for an image on [Docker Hub](https://hub.docker.com).
|
||||
|
||||
> **Note**:
|
||||
> The response keys have changed from API v1.6 to reflect the JSON
|
||||
|
||||
@@ -943,7 +943,7 @@ Remove the image `name` from the filesystem
|
||||
|
||||
`GET /images/search`
|
||||
|
||||
Search for an image on [Docker.io](https://index.docker.io).
|
||||
Search for an image on [Docker Hub](https://hub.docker.com).
|
||||
|
||||
> **Note**:
|
||||
> The response keys have changed from API v1.6 to reflect the JSON
|
||||
|
||||
@@ -946,7 +946,7 @@ Tag the image `name` into a repository
|
||||
|
||||
`GET /images/search`
|
||||
|
||||
Search for an image on [Docker.io](https://index.docker.io).
|
||||
Search for an image on [Docker Hub](https://hub.docker.com).
|
||||
|
||||
> **Note**:
|
||||
> The response keys have changed from API v1.6 to reflect the JSON
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user