linux中讓 Docker 使用 HTTPS的教程

來源:互聯網
上載者:User

Docker 啟動監聽連接埠後,使用的是 http,可以遠程來管理 Docker 主機。
這樣的情境存在弊端,API 層面是沒有提供使用者驗證、Token 之類身分識別驗證功能,任何人都可以通過地址加連接埠來控制 Docker 主機,為了避免這樣的情況發生,Docker 官方也支援 https 方式,不過需要我們自己來產生認證。

通過 OpenSSL 命令來產生 CA 憑證、伺服器私密金鑰、用戶端認證、簽名,openssl 命令比較複雜,我用指令碼直接產生:

# cat certgen.sh
set -ex

[ -e certs ] || mkdir certs
cd certs
echo "Creating ca keys..."
echo 01 > ca.srl
openssl genrsa -des3 -out ca-key.pem
openssl rsa -in ca-key.pem -out ca-key.pem
openssl req -subj "/CN=$(hostname -f)/" -new -x509 -days 365 -key ca-key.pem -out ca.pem

echo "Creating server keys..."
openssl genrsa -des3 -out server-key.pem
openssl rsa -in server-key.pem -out server-key.pem
openssl req -subj "/CN=$(hostname -f)/" -new -key server-key.pem -out server.csr
openssl x509 -req -days 365 -in server.csr -CA ca.pem -CAkey ca-key.pem -out server-cert.pem

echo "Creating client keys..."
openssl genrsa -des3 -out key.pem
openssl rsa -in key.pem -out key.pem
openssl req -subj '/CN=*/' -new -key key.pem -out client.csr
echo extendedKeyUsage = clientAuth > extfile.cnf
openssl x509 -req -days 365 -in client.csr -CA ca.pem -CAkey ca-key.pem -out cert.pem -extfile extfile.cnf

需要注意,在執行指令碼之前,確保你的主機名稱符合 FQDN 並能正常解析,不推薦修改指令碼內容 $(hostname -f) 為 IP 位址,無需修改指令碼,在指令碼執行過程中會反覆需要輸入密碼,統一輸入一個密碼就 ok:

sh certgen.sh
執行完後,會在目前的目錄下產生一個 certs 目錄,裡面有產生的所有的認證檔案。

為了避免混淆,現在拷貝 CA 和伺服器私密金鑰到其它目錄:

mkdir -p /etc/docker/certs
cd certs/
cp ca.pem server-cert.pem server-key.pem /etc/docker/certs/
伺服器私密金鑰有了,我們也知道在哪裡,現在只需要讓 Docker 知道:

vim /etc/default/docker
DOCKER_OPTS='-H unix:///var/run/docker.sock -H docker01.thstack.com:6732 --tlsverify --tlscacert=/etc/docker/certs/ca.pem --tlscert=/etc/docker/certs/server-cert.pem --tlskey=/etc/docker/certs/server-key.pem'
重啟 docker 服務:

service docker restart
添加 DOCKER_HOST 環境變數,地址為 Docker 主機的主機名稱,同樣如果設定 IP 位址會有問題:

# vim /etc/profile
export DOCKER_HOST=tcp://docker01.thstack.com:6732

# source /etc/profile
現在 Docker 已經開啟了 https 認證,在命令列裡敲 docker 命令會報錯,需要在每個 docker 命令加 –tlsverify 參數,docker 命令作為一個用戶端工具來操作 Docker 主機同樣依賴用戶端認證:

root@docker01:~/certs# docker info
2014/09/14 16:19:26 Get http://docker01.thstack.com:6732/v1.14/info: malformed HTTP response "x15x03x01x00x02x02"

root@docker01:~# docker --tlsverify images
2014/09/14 16:25:53 Couldn't read ca cert /root/.docker/ca.pem: open /root/.docker/ca.pem: no such file or directory   
從 docker –tlsverify images 結果輸出中瞭解到,加了 –tlsverify 參數後,就會預設去 ~/.docker 檔案中找用戶端認證,現在為 docker 用戶端命令添加認證:

mkdir ~/.docker
cd certs/
cp ca.pem cert.pem key.pem ~/.docker
再次嘗試執行命令:

root@docker01:~# docker ps
2014/09/14 16:28:42 Get http://docker01.thstack.com:6732/v1.14/containers/json: malformed HTTP response "x15x03x01x00x02x02"

root@docker01:~# docker --tlsverify images
REPOSITORY          TAG                 IMAGE ID            CREATED             VIRTUAL SIZE
ubuntu              14.04.1             826544226fdc        9 days ago          194.2 MB
ubuntu              14.04               826544226fdc        9 days ago          194.2 MB
ubuntu              trusty              826544226fdc        9 days ago          194.2 MB
ubuntu              latest              826544226fdc        9 days ago          194.2 MB
ubuntu              14.10               245ce11c1f25        9 days ago          202.5 MB
ubuntu              utopic              245ce11c1f25        9 days ago          202.5 MB
ubuntu              precise             c17f3f519388        9 days ago          106.7 MB
ubuntu              12.04.5             c17f3f519388        9 days ago          106.7 MB
ubuntu              12.04               c17f3f519388        9 days ago          106.7 MB
ubuntu              12.10               c5881f11ded9        12 weeks ago        172.2 MB
ubuntu              quantal             c5881f11ded9        12 weeks ago        172.2 MB
ubuntu              13.04               463ff6be4238        12 weeks ago        169.4 MB
ubuntu              raring              463ff6be4238        12 weeks ago        169.4 MB
ubuntu              13.10               195eb90b5349        12 weeks ago        184.7 MB
ubuntu              saucy               195eb90b5349        12 weeks ago        184.7 MB
ubuntu              lucid               3db9c44f4520        4 months ago        183 MB
ubuntu              10.04               3db9c44f4520        4 months ago        183 MB 
只要開啟 https 認證後,docker 命令就必須加 –tlsverify 參數。

上面所有的操作都是在 Docker 主機上操作,找另外一台機器來驗證 https 是否生效:

root@ubuntu:~# curl -v -s  https://docker01.thstack.com:6732/info
* About to connect() to docker01.thstack.com port 6732 (#0)
*   Trying 192.168.3.23... connected
* successfully set certificate verify locations:
*   CAfile: none
  CApath: /etc/ssl/certs
* SSLv3, TLS handshake, Client hello (1):
* SSLv3, TLS handshake, Server hello (2):
* SSLv3, TLS handshake, CERT (11):
* SSLv3, TLS alert, Server hello (2):
* SSL certificate problem, verify that the CA cert is OK. Details:
error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed
* Closing connection #0
上面提示,認證驗證失敗,在 Docker 主機上 scp 用戶端認證到這台機器上:

root@docker01:~# cd certs/
root@docker01:~/certs# scp ca.pem cert.pem key.pem root@ubuntu:/tmp
指明認證位置來驗證,可以看到驗證過程和結果:

root@ubuntu:~# curl -v -s -k --key /tmp/key.pem --cert /tmp/cert.pem https://docker01.thstack.com:6732/info

* About to connect() to docker01.thstack.com port 6732 (#0)
*   Trying 192.168.3.23... connected
* successfully set certificate verify locations:
*   CAfile: none
  CApath: /etc/ssl/certs
* SSLv3, TLS handshake, Client hello (1):
* SSLv3, TLS handshake, Server hello (2):
* SSLv3, TLS handshake, CERT (11):
* SSLv3, TLS handshake, Server key exchange (12):
* SSLv3, TLS handshake, Request CERT (13):
* SSLv3, TLS handshake, Server finished (14):
* SSLv3, TLS handshake, CERT (11):
* SSLv3, TLS handshake, Client key exchange (16):
* SSLv3, TLS handshake, CERT verify (15):
* SSLv3, TLS change cipher, Client hello (1):
* SSLv3, TLS handshake, Finished (20):
* SSLv3, TLS change cipher, Client hello (1):
* SSLv3, TLS handshake, Finished (20):
* SSL connection using ECDHE-RSA-AES256-SHA
* Server certificate:
*        subject: CN=docker01.thstack.com
*        start date: 2014-09-14 03:27:16 GMT
*        expire date: 2015-09-14 03:27:16 GMT
*        common name: docker01.thstack.com (matched)
*        issuer: CN=docker01.thstack.com
*        SSL certificate verify result: self signed certificate (18), continuing anyway.
> GET /info HTTP/1.1
> User-Agent: curl/7.22.0 (x86_64-pc-linux-gnu) libcurl/7.22.0 OpenSSL/1.0.1 zlib/1.2.3.4 libidn/1.23 librtmp/2.3
> Host: docker01.thstack.com:6732
> Accept: */*
>
< HTTP/1.1 200 OK
< Content-Type: application/json
< Job-Name: info
< Date: Sun, 14 Sep 2014 08:43:26 GMT
< Content-Length: 417
<
{"Containers":1,"Debug":0,"Driver":"aufs","DriverStatus":[["Root Dir","/var/lib/docker/aufs"],["Dirs","36"]],"ExecutionDriver":"native-0.2","IPv4Forwarding":1,"Images":34,"IndexServerAddress":"https://index.docker.io/v1/","InitPath":"/usr/bin/docker","InitSha1":"","KernelVersion":"3.13.0-24-generic","MemoryLimit":1,"NEventsListener":0,"NFd":11,"NGoroutines":11,"OperatingSystem":"Ubuntu 14.04.1 LTS","SwapLimit":0}
* Connection #0 to host docker01.thstack.com left intact
* Closing connection #0
* SSLv3, TLS alert, Client hello (1):
也可以在其它機器上安裝 lxc-docker,來用 docker 命令遠端管理 Docker 主機,同樣設定環境變數,添加認證。
如果在配置過程中出錯,查看 /var/log/upstart/docker.log 日誌,或重建認證

聯繫我們

該頁面正文內容均來源於網絡整理,並不代表阿里雲官方的觀點,該頁面所提到的產品和服務也與阿里云無關,如果該頁面內容對您造成了困擾,歡迎寫郵件給我們,收到郵件我們將在5個工作日內處理。

如果您發現本社區中有涉嫌抄襲的內容,歡迎發送郵件至: info-contact@alibabacloud.com 進行舉報並提供相關證據,工作人員會在 5 個工作天內聯絡您,一經查實,本站將立刻刪除涉嫌侵權內容。

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.