月度归档:2020年01月

docker mark

#常见缺失软件

apk add procps
apk add docker-cli
apk add busybox-extras 

#rancher  通过yaml方式创建服务 不能ping通故障解决

1. 创建服务与设置好对应的主机DNS

rancher kubectl create -f appserver-extend.yaml

yaml示例代码:

---
apiVersion: v1
items:
- apiVersion: v1
  kind: Service
  metadata:
    annotations:
      field.cattle.io/creatorId: user-w9lgp
      field.cattle.io/ipAddresses: "null"
      field.cattle.io/targetDnsRecordIds: "null"
      field.cattle.io/targetWorkloadIds: '["deployment:application:appserver-extend-job"]'
    labels:
      cattle.io/creator: norman
    name: service-appserver-extend-extend-job
    namespace: application
    selfLink: /api/v1/namespaces/application/services/service-appserver-extend-extend-job
  spec:
    clusterIP: None
    ports:
    - name: default
      port: 42
      protocol: TCP
      targetPort: 42
    selector:
      workloadID_service-appserver-extend-extend-job: "true"
    sessionAffinity: None
    type: ClusterIP
  status:
    loadBalancer: {}
- apiVersion: apps/v1
  kind: Deployment
  metadata:
    annotations:
      deployment.kubernetes.io/revision: "1"
    generation: 1
    labels:
      cattle.io/creator: norman
      workload.user.cattle.io/workloadselector: deployment-application-appserver-extend-job
    name: appserver-extend-job
    namespace: application
    selfLink: /apis/apps/v1/namespaces/application/deployment/appserver-extend-job
  spec:
    progressDeadlineSeconds: 600
    replicas: 1
    revisionHistoryLimit: 10
    selector:
      matchLabels:
        workload.user.cattle.io/workloadselector: deployment-application-appserver-extend-job
    strategy:
      rollingUpdate:
        maxSurge: 1
        maxUnavailable: 0
      type: RollingUpdate
    template:
      metadata:
        creationTimestamp: null
        labels:
          workload.user.cattle.io/workloadselector: deployment-application-appserver-extend-job
      spec:
        containers:
        - env:
          - name: RUNPRO
            value: pro
          - name: aliyun_logs_catalina
            value: "stdout" 
          - name: aliyun_logs_access
            value: "/opt/logs/*.log"
          - name: aliyun_logs_catalina_tags
            value: "type=appserver-extend-xxx-catalina,topic=appserver-extend-xxx-extend-job-catalina"
          - name: aliyun_logs_access_tags
            value: "type=appserver-extend-xxx-access,topic=appserver-extend-xxx-extend-job-access"
          image: alpine
          imagePullPolicy: Always
          name: appserver-extend-job
          resources: {}
          securityContext:
            allowPrivilegeEscalation: false
            capabilities: {}
            privileged: false
            readOnlyRootFilesystem: false
            runAsNonRoot: false
          stdin: true
          terminationMessagePath: /dev/termination-log
          terminationMessagePolicy: File
          tty: true
        dnsPolicy: ClusterFirst
        imagePullSecrets:
        - name: registry-harbor
        restartPolicy: Always
        schedulerName: default-scheduler
        securityContext: {}
        terminationGracePeriodSeconds: 30
kind: List

故障现象:

同命名空间下 ping service-appserver-extend-extend-job 提示找不到主机。

排查过程:

rancher kubectl describe services service-appserver-extend-extend-job -n application
Name:              service-appserver-extend-extend-job
Namespace:         application
Labels:            cattle.io/creator=norman
Annotations:       field.cattle.io/creatorId: user-w9lgp
                   field.cattle.io/ipAddresses: null
                   field.cattle.io/targetDnsRecordIds: null
                   field.cattle.io/targetWorkloadIds: ["deployment:application:appserver-extend-job"]
Selector:          workloadID_service-appserver-extend-extend-job=true
Type:              ClusterIP
IP:                None
Port:              default  42/TCP
TargetPort:        42/TCP
Endpoints:         <none>      #故障点:  Endpoints 为空 
Session Affinity:  None
Events:            <none>

修复: 由于yaml文件中 先定义了service 后定义的 deployment  导致 service中找不到机器     知道原因后修复也很简单, 在yaml中先创建 deployment后, 再创建service然后就解决了。

#使用docker快速搭建各大漏洞学习平台,目前可以一键搭建12个平台

https://github.com/c0ny1/vulstudy

https://github.com/vulhub/vulhub

https://github.com/vulnspy

https://www.vsplate.com/labs.php

#at sun.awt.FontConfiguration.getVersion(FontConfiguration.java  docker  openjdk  openjdk:8-jdk-alpine 报错

原因为缺少字体

解决:添加 字体   ttf-dejavu

RUN apk add --no-cache ttf-dejavu 

//加上其它的
RUN apk add --no-cache bash tini ttf-dejavu libc6-compat linux-pam krb5 krb5-libs

#awvs  docker

docker run --name wvs13 -p 3443:3443 -itd registry.cn-shanghai.aliyuncs.com/t3st0r/acunetix_13:20200220
admin@admin.cn
Admin@admin.cn

#Could not initialize class org.xerial.snappy.Snappy

由于项目中使用了org.xerial.snappy.Snappy这个类,在正常的centos系统环境下,没有问题;在微服务容器(openjdk:8-jdk-alpine)测试的时候发现有一个功能不正常,爆出异常 Could not initialize class org.xerial.snappy.Snappy
解决方式:
由于openjdk:8-jdk-alpine容器使用的是Alpine Linux,
创建软连接
ln -s /lib /lib64

对应dockerfile为:

FROM openjdk:8-jdk-alpine
ARG RUNPRO
ENV TZ=Asia/Shanghai
RUN apk add -U tzdata
RUN ln -snf /usr/share/zoneinfo/$TZ /etc/localtime && echo $TZ > /etc/timezone
RUN ln -s /lib /lib64   #新增
RUN apk add --no-cache bash tini libc6-compat linux-pam krb5 krb5-libs #新增
VOLUME /tmp
VOLUME /opt/logs
WORKDIR /opt/
COPY server-xx*.jar server-xx.jar
ENTRYPOINT ["java","-jar","server-xx.jar","--spring.profiles.active=${RUNPRO}"]

最后还是准备直接用oracle jdk了, 感觉openjdk还是不太稳定。

参考:https://www.cnblogs.com/hellxz/p/11936994.html

解决php下通过shell_exec git clone 报fatal: unable to set up default path; use –file 问题

报错:

fatal: unable to set up default path; use --file
fatal: could not read Username for 'http://10.100.11.5': No such device or address

demo 代码:

$giturl='http://10.100.11.5/appserver/appserver-api/';
$output=shell_exec("git clone {$giturl} 2>&1");
var_dump($output)

对应的www-data用户做了sudo 免密码

做了git免密码  (git config –global credential.helper store)

此代码在CLI命令行下运行正常

在apache下的web界面下报如题所示错误, 中间尝过许多办法。都无解。

思考过程:

1. su – www-data用户下的cli能正常运行,说明权限应该是没问题的

2. 分别在cli下和web下打印env相关东西

system("env");

结果发现两种情况下的环境变量相差很大。

尝试把web中的环境变量补充HOME变量后,问题解决了。

putenv("HOME=/home/www-data");
putenv("USER=www-data");
$giturl='http://10.100.11.5/appserver/appserver-api/';
$output=shell_exec("git clone {$giturl} 2>&1");

另一个解决办法:

默认的apache2.4会把HOME环境变量给unset 掉  见:/etc/apache2/envvars 第4行

# envvars - default environment variables for apache2ctl

# this won't be correct after changing uid
unset HOME   #就是这里

# for supporting multiple apache2 instances

针对apache的解决办法也比较简单了 修改envvars文件,  增加HOME环境变量的导出就行

#unset HOME   注释这里

# for supporting multiple apache2 instances
if [ "${APACHE_CONFDIR##/etc/apache2-}" != "${APACHE_CONFDIR}" ] ; then
        SUFFIX="-${APACHE_CONFDIR##/etc/apache2-}"
else
        SUFFIX=
fi

#增加这里
export HOME=/home/www-data

apachectl stop && apachectl start   (restart好像不会刷新环境变量)

问题解决, 解决此小问题,花费了好几个小时,都搞得有些怀疑自己的技术了。  ^_^