Problem Background
Many people wonder why run Docker inside a container. I think there are mainly the following scenarios that may require running Docker in a container:
- Jenkins or other CI tools — these tools may themselves run in Docker containers, but when executing test jobs they still need to start containers. Theoretically speaking, this situation is fairly common.
- Some container orchestration tools are themselves Dockerized. For example: you write a software that builds Docker images by manipulating Docker’s API, and you run this software with Docker — at this point, the build operation is definitely triggered by the program inside the container calling the Docker API.
Two Ways to Run
dnd
This is a method of starting another docker process inside a container:
Using Docker-in-Docker for your CI or testing environment? Think twice.
The README also explains how it works:
1 | The main trick is to have the --privileged flag. Then, there are a few things to care about: |
Mounting docker.sock
This is the approach I use at work. The benefit of a unix socket is that as long as you mount it, you can interact with the program.
For example, using it directly on a machine with Docker (find all containers):
1 |
|
The biggest benefit of this mounting approach is sharing one docker environment; the biggest downside is also sharing one environment. Let me explain why:
- Calling the API manipulates the host’s containers — very suitable for Dockerizing certain orchestration tools
- The permissions are really too great; with the
--privilegedparameter in a container, we could even start a container used to shut down the host
Summary
In specific situations we inevitably need to call the Docker API from inside a container to operate. The hope here is to tell everyone
there are these two approaches, but concrete usage must be judged together with the usage scenario.