While full hardware virtualization such as KVM, Xen or Hyper-V is great at running fully isolated instances of multiple operating systems on a physical host, it comes with various overheads in terms of performance, resource, and provisioning time. Depending on your use cases, full machine virtualization may actually not be necessary.
An alternative lightweight virtualization approach is so-called Linux Containers (LXC), which provides operating system level virtualization. Without the overhead of running virtual machines, LXC allows you to run multiple instances of full Linux operating system within lightweight container sandbox. Containers can be very useful when you set up a reproducible development/test environment or deploy applications within secure sandboxes.
Docker is an open-source tool which was developed to facilitate the deployment of Linux containers. Docker is fast becoming a de-facto standard for container technologies, being embraced in major Linux distros such as Ubuntu and Red Hat.
In this tutorial, I am going to demonstrate how to manage Linux containers with Docker on Ubuntu 14.10. Note that instructions may be slightly different for earlier versions of Ubuntu. If you want to try out Docker on Fedora or CentOS, refer to this tutorial.
At this time, the Docker package available on Ubuntu only supports 64-bit systems. To run it on 32-bit machine, you will need to build 32-bit version of Docker from source.
Installing Docker is easy with apt-get command.
To allow non-root user to run Docker, add yourself to docker group. The command below will allow the current user to run Docker without root permission.
Log out and then re-login to activate group membership change.
Next, edit the Docker configuration file to update the location of the Docker binary.
Note that on Ubuntu 14.04 and earlier, the Docker configuration file is loated at /etc/default/docker.io, and its binary is /usr/bin/docker.io (due to naming conflict with a system tray app called docker).
Restart Docker service.
(or sudo service docker.io restart)
Manage Docker Containers
If you want to start a new Docker container of Ubuntu operating system, first pull Ubuntu Docker image first. The command below will download Docker image over a network, and cache it locally. The first time you run this command, it will take a couple of minutes to finish.
You can start a Ubuntu Docker in an interactive mode as follows.
In the above command, the last argument "/bin/bash" is the command that will be executed inside a container once it is launched, in this case, a simple bash shell. So it will launch a Ubuntu container immediately (which is the beauty of containers!), and give you a shell prompt inside the container. At this point, you should be able to access a full Ubuntu operating system inside a sandboxed environment.
To exit a Docker container, type "exit" at the prompt inside the container.
You can launch containers in different flavors. For example, to start a Fedora container:
If a Fedora Docker image is not available locally, the command will automatically download the image first, and then launch a Docker. So it will take a couple of minutes to start a new Docker. Subsequent launch of additional Dockers of the same image will be finished instantly.
If you want to launch a container with a particular distro release, you can also do that. For example, to start a Ubuntu 13.04 Docker:
To see a list of currently running Docker containers, use the following command.
If you want to see a list of all (active or terminated) Docker containers, run this command instead.
Docker uses Linux bridge to interconnect containers with each other, and to connect them to external networks. After installing Docker, you should see docker0 Linux bridge created automatically by default. Every container you create will be connected to docker0 bridge interface.
Custom Linux Bridge
If you want, you can use a custom Linux bridge to interconnect containers. For that, you can create a custom bridge and configure it as follows. You can assign a separate subnet to the bridge, and have Dockers assigned IP addresses from the subnet. I am going to use 10.0.0.0/24 as a Docker subnet.
$ sudo brctl addbr br0
$ sudo ifconfig br0 10.0.0.1 netmask 255.255.255.0
To make the custom bridge used by Docker, add "-b=br0" to DOCKER_OPTS variable in /etc/default/docker.io, and restart Docker service.
(or sudo service docker.io restart)
At this point, any new container will be connected to br0, and its IP address will automatically be assigned from 10.0.0.0/24.
There are several other ways to customize the default network settings of Docker, mostly by tweaking DOCKER_OPTS variable in /etc/default/docker.io.
- "-dns 18.104.22.168 -dns 22.214.171.124": specify the DNS servers used by a container.
- "-icc=false": make containers isolated from each other.
If you want to interconnect Docker containers across different hosts, I strongly recommend using weave, a powerful Docker networking tool.
1. You encounter the following error when running docker command.
dial unix /var/run/docker.sock: no such file or directory
The error may be because Docker daemon is not running. Check the status of Docker daemon, and make sure to start it first.
$ sudo service docker start
Subscribe to Xmodulo
Do you want to receive Linux FAQs, detailed tutorials and tips published at Xmodulo? Enter your email address below, and we will deliver our Linux posts straight to your email box, for free. Delivery powered by Google Feedburner.
Did you find this tutorial helpful? Then please be generous and support Xmodulo!
Latest posts by Dan Nanni (see all)
- How to install Suricata intrusion detection system on Linux - September 3, 2015
- How to switch from NetworkManager to systemd-networkd on Linux - August 31, 2015
- How to set up a system status page of your infrastructure - August 25, 2015