我一直在嘗試使用 Docker Machine 和 Docker Compose 部署容器。我正在運行一個Windows 10和適用於 Windows 的 Docker v1.12.5。
當我開始配置時,我運行以下命令:
docker-machine env my-machine
& "C:\Program Files\Docker\Docker\Resources\bin\docker-machine.exe" env my-machine | Invoke-Expression
這將我的機器設定為活動狀態
之後我想部署我的配置,其中有一個Nginx 代理和一個節點js應用。在此代理上我配置了 2 個網站。
server {
listen 443 ssl;
server_name mysite.com;
access_log /var/log/nginx/mysite.log;
error_log /var/log/nginx/mysite.log;
location / {
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header Host $http_host;
proxy_set_header X-NginX-Proxy true;
proxy_pass http://myapp:8080/;
proxy_redirect off;
}
location ^~ /.well-known/acme-challenge {
root /usr/share/nginx/html;
default_type "text/plain";
}
ssl_certificate /etc/letsencrypt/live/msite.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/mysite.com/privkey.pem;
ssl_session_cache shared:le_nginx_SSL:1m;
ssl_session_timeout 1440m;
ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
ssl_prefer_server_ciphers on;
ssl_stapling on;
ssl_stapling_verify on;
ssl_dhparam /etc/ssl/certs/dhparam.pem;
ssl_ciphers "ECDHE-ECDSA-AES128-GCM-SHA256 ECDHE-ECDSA-AES256-GCM-SHA384 ECDHE-ECDSA-AES128-SHA ECDHE-ECDSA-AES256-SHA ECDHE-ECDSA-AES128-SHA256 ECDHE-ECDSA-AES256-SHA384 ECDHE-RSA-AES128-GCM-SHA256 ECDHE-RSA-AES256-GCM-SHA384 ECDHE-RSA-AES128-SHA ECDHE-RSA-AES128-SHA256 ECDHE-RSA-AES256-SHA384 DHE-RSA-AES128-GCM-SHA256 DHE-RSA-AES256-GCM-SHA384 DHE-RSA-AES128-SHA DHE-RSA-AES256-SHA DHE-RSA-AES128-SHA256 DHE-RSA-AES256-SHA256 EDH-RSA-DES-CBC3-SHA";
}
server {
listen 8000;
server_name mysite;
return 301 https://$host$request_uri;
}
nginx現在應該獲得一個證書,為此我發現我可以使用它letsencrypt-nginx-proxy-companion
來為我的網站生成和管理證書。
我對這個伴侶的配置如下:
letsencrypt-nginx-proxy-companion:
image: jrcs/letsencrypt-nginx-proxy-companion
volumes_from:
- nginx
volumes:
- /var/run/docker.sock:/tmp/docker.sock:ro
- nginx_certs:/etc/nginx/certs:rw
environment:
- NGINX_DOCKER_GEN_CONTAINER=nginx-gen
每次我運行時docker-compose up -d
都會收到以下錯誤訊息:
對於 LetsEncrypt-nginx-proxy-companion 無法為服務 LetsEncrypt-nginx-proxy-companion 建立容器:建立 \var\run\docker.sock:「\var\run\docker.sock」包含本地磁碟區名稱的無效字元,僅僅允許“[a-zA-Z0-9][a-zA-Z0-9_.-]”
希望有人可以幫我修復這個錯誤。