docker - 无法使用 traefik 获取正确的容器 IP
问题描述
使用 Traefik 和 Docker-compose 时,我想获取容器 IP 以执行基于 IP 的过滤,而是获取 docker 网络网关 IP。
这是来自 curl-client 容器的 curl 请求的结果:
docker-compose exec curl-client curl https://whoami.domain.name
Hostname: 608f3dcaf7d9
IP: 127.0.0.1
IP: 172.18.0.2
GET / HTTP/1.1
Host: whoami.domain.name
User-Agent: curl/7.58.0
Accept: */*
Accept-Encoding: gzip
X-Forwarded-For: 172.18.0.1
X-Forwarded-Host: whoami.domain.name
X-Forwarded-Port: 443
X-Forwarded-Proto: https
X-Forwarded-Server: 88756553599b
X-Real-Ip: 172.18.0.1
这里,172.18.0.1 是 traefik_net 网络的网关。相反,我希望在 X-Forwarded-For 字段中看到 172.18.0.9,因为它是 curl-client 容器的 IP:
docker-compose exec curl-client cat /etc/hosts
172.18.0.9 34f7b6e5472f
我也尝试使用 'traefik.frontend.whiteList.useXForwardedFor=true' 选项但没有成功。
traefik.toml
logLevel = "ERROR"
defaultEntryPoints = ["http", "https"]
[entryPoints]
[entryPoints.dashboard]
address = ":8080"
[entryPoints.http]
address = ":80"
[entryPoints.http.redirect]
entryPoint = "https"
[entryPoints.https]
address = ":443"
[entryPoints.https.tls]
[api]
entrypoint="dashboard"
[acme]
email = "something@aaa.com"
storage = "acme.json"
entryPoint = "https"
[acme.dnsChallenge]
provider = "ovh"
delayBeforeCheck = 0
[[acme.domains]]
main = "*.domain.name"
[docker]
domain = "domain.name"
watch = true
network = "traefik_net"
码头工人-compose.yml
version: '3'
services:
traefik_proxy:
image: traefik:alpine
container_name: traefik
networks:
- traefik_net
ports:
- 80:80
- 443:443
volumes:
- /var/run/docker.sock:/var/run/docker.sock
- ./traefik.toml:/traefik.toml
- ./acme.json:/acme.json
restart: unless-stopped
environment:
- OVH_ENDPOINT=ovh-eu
- OVH_APPLICATION_KEY=secretsecret
- OVH_APPLICATION_SECRET=secretsecret
- OVH_CONSUMER_KEY=secretsecret
labels:
- 'traefik.frontend.rule=Host:traefik.domain.name'
- 'traefik.port=8080'
- 'traefik.backend=traefik'
whoami:
image: containous/whoami
container_name: whoami
networks:
- traefik_net
labels:
- 'traefik.frontend.rule=Host:whoami.domain.name'
curl-client:
image: ubuntu
networks:
- traefik_net
command: sleep infinity
networks:
traefik_net:
external: true
编辑:使用以下 dnsmasq.conf 解析域名:
domain-needed
expand-hosts
bogus-priv
interface=eno1
domain=domain.name
cache-size=1024
listen-address=127.0.0.1
bind-interfaces
dhcp-range=10.0.10.10,10.0.10.100,24h
dhcp-option=3,10.0.10.1
dhcp-authoritative
server=208.67.222.222
server=208.67.220.220
address=/domain.name/10.0.10.3
解决方案
经过一番调查,似乎 Traefik 不是这里的问题,无法访问容器 IP 是由于 Docker 管理其内部网络的方式(见以下评论:https ://github.com/containous/traefik/issues/ 4352和https://github.com/docker/for-mac/issues/180)。
通过在nework_host模式下运行我的openvpn容器,我能够实现将内部连接列入白名单的目标,这样客户端就可以直接由系统分配一个IP。
推荐阅读
- python - 如果 a 数据框为空,如何打印零
- java - 如何将字符串值与 ArrayList 进行比较?
- c# - netcoreapp3.1 中的 C# 项目参考 F# 类库
- bash - 在这个 bash 脚本中详细发生了什么?
- azure - 如何仅授予对 Azure 订阅中某些资源的读取权限?
- swift - Swift:如何快速返回字典
- python - Python pygame sprites 碰撞检测。如何定义哪个精灵与组碰撞并通过减少一个点来影响它的属性
- reactjs - 为什么在函数返回之前这里没有调用 React 的 useEffect 钩子?
- ruby-on-rails - 带日期的条件活动模型序列化器
- c++ - 在多文件项目中重新定义“int main()”。C++