Mac OSX系统 Docker启用Docker远程API功能
在MacOSX系统的Docker机上启用Docker远程API功能
Docker守护进程提供了一套远程RESTAPI,具体可以参考文档:
https://docs.docker.com/engine/reference/api/docker_remote_api/
这套API是提供给客户端与Docker引擎通信时使用,这套API也可以由其他工具调用,比如curl或Chrome浏览器的PostmanREST客户端工具。
如果是在MacOSXMavericks系统上使用Docker机创建Docker守护进程,那么要启用Docker远程API功能需要一定的技巧。下面一一道来。
可以使用curl工具连接到安全的Docker端口,命令如下:
$curlhttps://$HOST:2376/images/json --cert~/.docker/cert.pem --key~/.docker/key.pem --cacert~/.docker/ca.pem
此命令存在一定的问题。主要有:
1)命令可能不工作,因为每一个Docker机的证书存储在.docker/machine/machines/目录。
2)即使命令根据路径做了修改,比如:
curlhttps://192.168.99.100:2376/images/json--cert$DOCKER_CERT_PATH/cert.pem--key$DOCKER_CERT_PATH/key.pem--cacert$DOCKER_CERT_PATH/ca.pem
执行命令仍然会得到错误信息:
curl:(58)SSL:Can'tloadthecertificate"/Users/arungupta/.docker/machine/machines/couchbase/cert.pem"anditsprivatekey:OSStatus-25299
解决方法是需要更新curl工具。总的来说,最新版的curl工具使用了Apple的安全传输层API(SecureTransportAPI),取代了原先的OpenSSLAPI。这意味着证书必须是p12格式。
下面可以这样修复命令:
1)进入Docker机存放证书的目录,比如.docker/machine/machines/couchbase目录
2)生成*.p12格式的证书
opensslpkcs12-export -inkeykey.pem -incert.pem -CAfileca.pem -chain -nameclient-side -outcert.p12 -passwordpass:mypass
现在可以调用RESTAPI了:
curlhttps://192.168.99.100:2376/images/json--cert$DOCKER_CERT_PATH/cert.p12--passmypass--key$DOCKER_CERT_PATH/key.pem--cacert$DOCKER_CERT_PATH/ca.pem
注意,–cert参数现在指向了生成的p12证书,证书的密码使用–pass参数进行指定。
然后会得到如下结果:
[{"Id":"sha256:d38beda529d3274636d6cb1c9000afe4f00fbdcfa544140d6cc0f5d7f5b8434a","ParentId":"", "RepoTags":["arungupta/couchbase:latest"],"RepoDigests":null,"Created":1450330075,"Size":374824677, "VirtualSize":374824677,"Labels":{}}]
现在可以尝试启动CouchBase服务器:
~>dockerrun-d-p8091-8093:8091-8093-p11210:11210arungupta/couchbase 42d1414883affd0fbb272cb1378c2f6b5118acf3ed5cb60cbecdc42f95602e3e
再调用另一个RESTAPI来查看容器的细节内容:
~>curlhttps://192.168.99.100:2376/containers/json--cert$DOCKER_CERT_PATH/cert2.p12--passmypass--key$DOCKER_CERT_PATH/key.pem--cacert$DOCKER_CERT_PATH/ca.pem [{"Id":"42d1414883affd0fbb272cb1378c2f6b5118acf3ed5cb60cbecdc42f95602e3e","Names":["/admiring_pike"],"Image":"arungupta/couchbase","ImageID":"sha256:d38beda529d3274636d6cb1c9000afe4f00fbdcfa544140d6cc0f5d7f5b8434a","Command":"/entrypoint.sh/opt/couchbase/configure-cluster.sh","Created":1454850194,"Ports":[{"IP":"0.0.0.0","PrivatePort":8092,"PublicPort":8092,"Type":"tcp"},{"PrivatePort":11207,"Type":"tcp"},{"IP":"0.0.0.0","PrivatePort":11210,"PublicPort":11210,"Type":"tcp"},{"PrivatePort":18092,"Type":"tcp"},{"PrivatePort":18091,"Type":"tcp"},{"IP":"0.0.0.0","PrivatePort":8093,"PublicPort":8093,"Type":"tcp"},{"IP":"0.0.0.0","PrivatePort":8091,"PublicPort":8091,"Type":"tcp"},{"PrivatePort":11211,"Type":"tcp"}],"Labels":{},"Status":"Up2seconds","HostConfig":{"NetworkMode":"default"},"NetworkSettings":{"Networks":{"bridge":{"IPAMConfig":null,"Links":null,"Aliases":null,"NetworkID":"","EndpointID":"6feaf4c1c70feaf0ba240ce55fb58ce83ebb84c8098bef9171998e84f607fa0b","Gateway":"172.17.0.1","IPAddress":"172.17.0.2","IPPrefixLen":16,"IPv6Gateway":"","GlobalIPv6Address":"","GlobalIPv6PrefixLen":0,"MacAddress":"02:42:ac:11:00:02"}}}}]
感谢阅读,希望能帮助到大家,谢谢大家对本站的 支持!