nerdctl管理容器,网络,存储,命名空间
·
nerdctl 管理容器
ls
作用:查看容器清单
[root@ubuntu ~ 09:59:32]# nerdctl container ls
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
run
作用:创建并运行容器。
[root@ubuntu ~ 09:59:43]# nerdctl run -it busybox
/ # INFO[0003] read detach keys
[root@ubuntu ~ 10:00:05]# nerdctl container ls
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
3b436f8e0b56 docker.io/library/busybox:latest "sh" 10 seconds ago Up busybox-3b436
rm
作用:删除容器
##容器运行时需要停止再删除
[root@ubuntu ~ 10:00:11]# nerdctl container rm 3b
FATA[0000] 1 errors:
container 3b436f8e0b5600eff7db8b27b61f16ae4bef6aec5c5ced1375ae364f22be4aa9 is in running status. unpause/stop container first or force removal
[root@ubuntu ~ 10:00:44]# nerdctl container stop 3b
3b
[root@ubuntu ~ 10:01:00]# nerdctl container rm 3b
3b
[root@ubuntu ~ 10:01:08]# nerdctl container ls
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
prune
作用:删除所有未运行的容器
[root@ubuntu ~ 10:01:33]# nerdctl container ls -a
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
c6f460c76150 docker.io/library/busybox:latest "sh" 12 seconds ago Exited (0) 11 seconds ago busybox-c6f46
[root@ubuntu ~ 10:01:40]# nerdctl container prune
WARNING! This will remove all stopped containers.
Are you sure you want to continue? [y/N] y
Deleted Containers:
c6f460c761501f3f46736cca1946b9fdc3b4e4fc50e188caa26116bd61526d71
[root@ubuntu ~ 10:02:04]# nerdctl container ls -a
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
rename
作用:重命名容器
[root@ubuntu ~ 10:03:10]# nerdctl container run --name busybox-1 busybox
[root@ubuntu ~ 10:03:32]# nerdctl container ls -a
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
f8b81d124153 docker.io/library/busybox:latest "sh" 6 seconds ago Exited (0) 6 seconds ago busybox-1
[root@ubuntu ~ 10:04:00]# nerdctl container rename busybox-1 busybox-2
[root@ubuntu ~ 10:04:27]# nerdctl container ls -a
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
f8b81d124153 docker.io/library/busybox:latest "sh" About a minute ago Exited (0) About a minute ago busybox-2
stop 和 start
作用:停止和启动容器
[root@ubuntu ~ 10:06:02]# nerdctl ps -a
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
550b0b5a2b10 docker.io/library/nginx:latest "/docker-entrypoint.…" 4 seconds ago Up nginx-1
f8b81d124153 docker.io/library/busybox:latest "sh" 2 minutes ago Exited (0) About a minute ago busybox-2
[root@ubuntu ~ 10:06:06]# nerdctl stop nginx-1
nginx-1
[root@ubuntu ~ 10:06:17]# nerdctl ps -a
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
550b0b5a2b10 docker.io/library/nginx:latest "/docker-entrypoint.…" 20 seconds ago Exited (0) 4 seconds ago nginx-1
f8b81d124153 docker.io/library/busybox:latest "sh" 2 minutes ago Exited (0) About a minute ago busybox-2
[root@ubuntu ~ 10:06:22]# nerdctl start nginx-1
nginx-1
[root@ubuntu ~ 10:06:29]# nerdctl ps -a
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
550b0b5a2b10 docker.io/library/nginx:latest "/docker-entrypoint.…" 34 seconds ago Up nginx-1
f8b81d124153 docker.io/library/busybox:latest "sh" 3 minutes ago Exited (0) About a minute ago busybox-2
restart
作用:重启容器
pause 和 unpause
作用:挂起和取消挂起容器
[root@ubuntu ~ 10:06:53]# nerdctl pause nginx-1
nginx-1
[root@ubuntu ~ 10:07:01]# nerdctl ps -a
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
550b0b5a2b10 docker.io/library/nginx:latest "/docker-entrypoint.…" About a minute ago Paused nginx-1
f8b81d124153 docker.io/library/busybox:latest "sh" 3 minutes ago Exited (0) 2 minutes ago busybox-2
[root@ubuntu ~ 10:07:20]# nerdctl unpause nginx-1
nginx-1
[root@ubuntu ~ 10:07:46]# nerdctl ps -a
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
550b0b5a2b10 docker.io/library/nginx:latest "/docker-entrypoint.…" About a minute ago Up nginx-1
f8b81d124153 docker.io/library/busybox:latest "sh" 4 minutes ago Exited (0) 2 minutes ago busybox-2
kill
作用:给容器发信号,默认发KILL信号
[root@ubuntu ~ 10:09:16]# nerdctl ps -a
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
550b0b5a2b10 docker.io/library/nginx:latest "/docker-entrypoint.…" 3 minutes ago Up nginx-1
f8b81d124153 docker.io/library/busybox:latest "sh" 5 minutes ago Exited (0) 4 minutes ago busybox-2
[root@ubuntu ~ 10:09:26]# nerdctl container kill 550b0b5a2b10
550b0b5a2b101602cba217b84af2aaf94829d9836e8ddeb6a6bef72023c5b65f
[root@ubuntu ~ 10:09:43]# nerdctl ps -a
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
550b0b5a2b10 docker.io/library/nginx:latest "/docker-entrypoint.…" 3 minutes ago Exited (137) 5 seconds ago nginx-1
f8b81d124153 docker.io/library/busybox:latest "sh" 6 minutes ago Exited (0) 4 minutes ago busybox-2
exec
作用:在运行的容器内部执行命令
[root@ubuntu ~ 10:10:10]# nerdctl container exec -it nginx-1 bash
root@550b0b5a2b10:/# exit
exit
cp
作用:将宿主机文件复制给容器
[root@ubuntu ~ 10:11:49]# nerdctl container cp /etc/hostname nginx-1:
[root@ubuntu ~ 10:12:26]# nerdctl container exec nginx-1 ls hostname
hostname
inspect
作用:查看容器详细信息
[root@ubuntu ~ 10:12:35]# nerdctl inspect nginx-1
[
{
"Id": "550b0b5a2b101602cba217b84af2aaf94829d9836e8ddeb6a6bef72023c5b65f",
"Created": "2026-06-22T02:06:02.330111415Z",
"Path": "/docker-entrypoint.sh",
"Args": [
"nginx",
"-g",
"daemon off;"
],
"State": {
"Status": "running",
"Running": true,
"Paused": false,
"Restarting": false,
"Pid": 3111,
"ExitCode": 0,
"Error": "",
"FinishedAt": "0001-01-01T00:00:00Z"
},
"Image": "docker.io/library/nginx:latest",
"ResolvConfPath": "/var/lib/nerdctl/1935db59/containers/default/550b0b5a2b101602cba217b84af2aaf94829d9836e8ddeb6a6bef72023c5b65f/resolv.conf",
"HostnamePath": "/var/lib/nerdctl/1935db59/containers/default/550b0b5a2b101602cba217b84af2aaf94829d9836e8ddeb6a6bef72023c5b65f/hostname",
"LogPath": "/var/lib/nerdctl/1935db59/containers/default/550b0b5a2b101602cba217b84af2aaf94829d9836e8ddeb6a6bef72023c5b65f/550b0b5a2b101602cba217b84af2aaf94829d9836e8ddeb6a6bef72023c5b65f-json.log",
"Name": "nginx-1",
"RestartCount": 0,
"Driver": "overlayfs",
"Platform": "linux",
"AppArmorProfile": "nerdctl-default",
"Mounts": null,
"Config": {
"Hostname": "550b0b5a2b10",
"AttachStdin": false,
"Labels": {
"containerd.io/restart.explicitly-stopped": "false",
"io.containerd.image.config.stop-signal": "SIGQUIT",
"nerdctl/extraHosts": "null",
"nerdctl/hostname": "550b0b5a2b10",
"nerdctl/log-uri": "binary:///usr/bin/nerdctl?_NERDCTL_INTERNAL_LOGGING=%2Fvar%2Flib%2Fnerdctl%2F1935db59",
"nerdctl/name": "nginx-1",
"nerdctl/namespace": "default",
"nerdctl/networks": "[\"bridge\"]",
"nerdctl/platform": "linux/amd64",
"nerdctl/state-dir": "/var/lib/nerdctl/1935db59/containers/default/550b0b5a2b101602cba217b84af2aaf94829d9836e8ddeb6a6bef72023c5b65f"
}
},
"NetworkSettings": {
"Ports": {},
"GlobalIPv6Address": "",
"GlobalIPv6PrefixLen": 0,
"IPAddress": "10.4.0.8",
"IPPrefixLen": 24,
"MacAddress": "ea:bc:b1:94:cc:02",
"Networks": {
"unknown-eth0": {
"IPAddress": "10.4.0.8",
"IPPrefixLen": 24,
"GlobalIPv6Address": "",
"GlobalIPv6PrefixLen": 0,
"MacAddress": "ea:bc:b1:94:cc:02"
}
}
}
}
]
logs
作用:显示容器console终端内容
[root@ubuntu ~ 10:13:26]# nerdctl container logs nginx-1
/docker-entrypoint.sh: /docker-entrypoint.d/ is not empty, will attempt to perform configuration
/docker-entrypoint.sh: Looking for shell scripts in /docker-entrypoint.d/
/docker-entrypoint.sh: Launching /docker-entrypoint.d/10-listen-on-ipv6-by-default.sh
10-listen-on-ipv6-by-default.sh: info: IPv6 listen already enabled
/docker-entrypoint.sh: Sourcing /docker-entrypoint.d/15-local-resolvers.envsh
/docker-entrypoint.sh: Launching /docker-entrypoint.d/20-envsubst-on-templates.sh
/docker-entrypoint.sh: Launching /docker-entrypoint.d/30-tune-worker-processes.sh
/docker-entrypoint.sh: Configuration complete; ready for start up
2026/06/22 02:10:10 [notice] 1#1: using the "epoll" event method
2026/06/22 02:10:10 [notice] 1#1: nginx/1.29.8
2026/06/22 02:10:10 [notice] 1#1: built by gcc 14.2.0 (Debian 14.2.0-19)
2026/06/22 02:10:10 [notice] 1#1: OS: Linux 6.8.0-31-generic
2026/06/22 02:10:10 [notice] 1#1: getrlimit(RLIMIT_NOFILE): 1048576:1048576
2026/06/22 02:10:10 [notice] 1#1: start worker processes
2026/06/22 02:10:10 [notice] 1#1: start worker process 22
2026/06/22 02:10:10 [notice] 1#1: start worker process 23
port
作用:显示宿主机和容器之间端口映射关系
[root@ubuntu ~ 10:13:32]# nerdctl container run --name nginx -d -p 8080:80 nginx
16a336f3b8bb61210acafa7f7ff75c769202e08d71273f8e249378063e4393e9
[root@ubuntu ~ 10:14:33]# nerdctl container port nginx
80/tcp -> 0.0.0.0:8080
commit
作用:将容器提交为镜像
[root@ubuntu ~ 10:14:49]# nerdctl commit nginx nginx.tar
sha256:9057b9625475362175b7aa3ac95e52c7f78ba960277e69d1d7ed23a27d548961
[root@ubuntu ~ 10:15:46]# nerdctl images
REPOSITORY TAG IMAGE ID CREATED PLATFORM SIZE BLOB SIZE
busybox latest 92b1d1cae5f2 4 days ago linux/amd64 4.4 MiB 2.2 MiB
mysql latest 3b1edfde8351 4 days ago linux/amd64 938.3 MiB 254.0 MiB
nginx.tar latest 93e23fc6cbc4 28 seconds ago linux/amd64 166.2 MiB 61.0 MiB
nginx latest 86d1d130d9ed 9 minutes ago linux/amd64 166.1 MiB 61.0 MiB
registry.k8s.io/pause 3.8 900118502363 4 days ago linux/amd64 700.0 KiB 304.0 KiB
nerdctl 管理网络
Containerd 中的网络与Docker类似,所有网络接口默认都是虚拟接口。
当使用nerdctl创建容器时,nerdctl命令会创建一个名称为bridge的Linux网桥(其上有一个nerdctl0内部接口),利用了Linux虚拟网络技术,在本地主机和容器内分别创建一个虚拟接口,并让它们彼此连通(这样的一对接口叫做vethpair)。Containerd 默认指定了nerdctl0接口的IP地址和子网掩码,让主机和容器之间可以通过网桥相互通信
[root@ubuntu ~ 11:14:15]# nerdctl network ls
NETWORK ID NAME FILE
17f29b073143 bridge /etc/cni/net.d/nerdctl-bridge.conflist
host
none
[root@ubuntu ~ 11:14:21]# apt install -y bridge-utils
[root@ubuntu ~ 11:17:07]# brctl show
bridge name bridge id STP enabled interfaces
nerdctl0 8000.bae34e2761ec no veth1a718aa5
veth8e62f284
[root@ubuntu ~ 11:17:13]# nerdctl network inspect bridge
[
{
"Name": "bridge",
"Id": "17f29b073143d8cd97b5bbe492bdeffec1c5fee55cc1fe2112c8b9335f8b6121",
"IPAM": {
"Config": [
{
"Subnet": "10.4.0.0/24",
"Gateway": "10.4.0.1"
}
]
},
"Labels": {
"nerdctl/default-network": "true"
}
}
]
[root@ubuntu ~ 11:18:04]# ip addr
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host noprefixroute
valid_lft forever preferred_lft forever
2: ens32: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP group default qlen 1000
link/ether 00:0c:29:f9:6d:46 brd ff:ff:ff:ff:ff:ff
altname enp2s0
inet 10.1.8.10/24 brd 10.1.8.255 scope global ens32
valid_lft forever preferred_lft forever
inet6 fe80::20c:29ff:fef9:6d46/64 scope link
valid_lft forever preferred_lft forever
3: nerdctl0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
link/ether ba:e3:4e:27:61:ec brd ff:ff:ff:ff:ff:ff
inet 10.4.0.1/24 brd 10.4.0.255 scope global nerdctl0
valid_lft forever preferred_lft forever
inet6 fe80::b8e3:4eff:fe27:61ec/64 scope link
valid_lft forever preferred_lft forever
12: veth1a718aa5@if2: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master nerdctl0 state UP group default qlen 1000
link/ether 42:36:8e:80:ce:6e brd ff:ff:ff:ff:ff:ff link-netnsid 0
inet6 fe80::4036:8eff:fe80:ce6e/64 scope link
valid_lft forever preferred_lft forever
13: veth8e62f284@if2: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master nerdctl0 state UP group default qlen 1000
link/ether 52:ec:fe:6d:ef:43 brd ff:ff:ff:ff:ff:ff link-netnsid 1
inet6 fe80::50ec:feff:fe6d:ef43/64 scope link
valid_lft forever preferred_lft forever
示例host网络
[root@ubuntu ~ 10:20:39]# nerdctl run -d --name web --network host nginx
f7edbc0dfb7803229a20b34b1a50f08358d0ece6c327f766cb6ded10baab820d
[root@ubuntu ~ 10:32:35]# nerdctl ps -a
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
16a336f3b8bb docker.io/library/nginx:latest "/docker-entrypoint.…" 18 minutes ago Up 0.0.0.0:8080->80/tcp nginx
550b0b5a2b10 docker.io/library/nginx:latest "/docker-entrypoint.…" 26 minutes ago Up nginx-1
f7edbc0dfb78 docker.io/library/nginx:latest "/docker-entrypoint.…" 8 seconds ago Up web
f8b81d124153 docker.io/library/busybox:latest "sh" 29 minutes ago Exited (0) 27 minutes ago busybox-2
[root@ubuntu ~ 10:32:43]# nerdctl logs web
/docker-entrypoint.sh: /docker-entrypoint.d/ is not empty, will attempt to perform configuration
/docker-entrypoint.sh: Looking for shell scripts in /docker-entrypoint.d/
/docker-entrypoint.sh: Launching /docker-entrypoint.d/10-listen-on-ipv6-by-default.sh
10-listen-on-ipv6-by-default.sh: info: Getting the checksum of /etc/nginx/conf.d/default.conf
10-listen-on-ipv6-by-default.sh: info: Enabled listen on IPv6 in /etc/nginx/conf.d/default.conf
/docker-entrypoint.sh: Sourcing /docker-entrypoint.d/15-local-resolvers.envsh
/docker-entrypoint.sh: Launching /docker-entrypoint.d/20-envsubst-on-templates.sh
/docker-entrypoint.sh: Launching /docker-entrypoint.d/30-tune-worker-processes.sh
/docker-entrypoint.sh: Configuration complete; ready for start up
2026/06/22 02:32:35 [notice] 1#1: using the "epoll" event method
2026/06/22 02:32:35 [notice] 1#1: nginx/1.29.8
2026/06/22 02:32:35 [notice] 1#1: built by gcc 14.2.0 (Debian 14.2.0-19)
2026/06/22 02:32:35 [notice] 1#1: OS: Linux 6.8.0-31-generic
2026/06/22 02:32:35 [notice] 1#1: getrlimit(RLIMIT_NOFILE): 1048576:1048576
2026/06/22 02:32:35 [notice] 1#1: start worker processes
2026/06/22 02:32:35 [notice] 1#1: start worker process 29
2026/06/22 02:32:35 [notice] 1#1: start worker process 30
[root@ubuntu ~ 10:32:56]# ss -lntp
State Recv-Q Send-Q Local Address:Port Peer Address:Port Process
LISTEN 0 128 127.0.0.1:6010 0.0.0.0:* users:(("sshd",pid=1331,fd=7))
LISTEN 0 511 0.0.0.0:80 0.0.0.0:* users:(("nginx",pid=3833,fd=6),("nginx",pid=3832,fd=6),("nginx",pid=3794,fd=6))
LISTEN 0 4096 127.0.0.54:53 0.0.0.0:* users:(("systemd-resolve",pid=638,fd=17))
LISTEN 0 4096 127.0.0.53%lo:53 0.0.0.0:* users:(("systemd-resolve",pid=638,fd=15))
LISTEN 0 4096 *:22 *:* users:(("sshd",pid=1295,fd=3),("systemd",pid=1,fd=93))
LISTEN 0 511 [::]:80 [::]:* users:(("nginx",pid=3833,fd=7),("nginx",pid=3832,fd=7),("nginx",pid=3794,fd=7))
LISTEN 0 128 [::1]:6010 [::]:* users:(("sshd",pid=1331,fd=6))
[root@ubuntu ~ 10:33:15]# systemctl status nginx
○ nginx.service - A high performance web server and a reverse proxy server
Loaded: loaded (/usr/lib/systemd/system/nginx.service; enabled; preset: enabled)
Active: inactive (dead)
Condition: start condition unmet at Mon 2026-06-22 09:30:18 CST; 1h 3min ago
└─ ConditionFileIsExecutable=/usr/sbin/nginx was not met
Docs: man:nginx(8)
Jun 22 09:30:18 ubuntu systemd[1]: nginx.service - A high performance web server and a reverse proxy server was skipped b>
[root@ubuntu ~ 10:33:33]# ls /usr/lib/systemd/system/n
networkd-dispatcher.service network-pre.target nftables.service nss-lookup.target
network-online.target network.target nginx.service nss-user-lookup.target
[root@ubuntu ~ 10:33:33]# ls /usr/lib/systemd/system/nginx.service
/usr/lib/systemd/system/nginx.service
[root@ubuntu ~ 10:34:02]# curl localhost
<!DOCTYPE html>
<html>
<head>
<title>Welcome to nginx!</title>
<style>
html { color-scheme: light dark; }
body { width: 35em; margin: 0 auto;
font-family: Tahoma, Verdana, Arial, sans-serif; }
</style>
</head>
<body>
<h1>Welcome to nginx!</h1>
<p>If you see this page, nginx is successfully installed and working.
Further configuration is required for the web server, reverse proxy,
API gateway, load balancer, content cache, or other features.</p>
<p>For online documentation and support please refer to
<a href="https://nginx.org/">nginx.org</a>.<br/>
To engage with the community please visit
<a href="https://community.nginx.org/">community.nginx.org</a>.<br/>
For enterprise grade support, professional services, additional
security features and capabilities please refer to
<a href="https://f5.com/nginx">f5.com/nginx</a>.</p>
<p><em>Thank you for using nginx.</em></p>
</body>
</html>
[root@ubuntu ~ 10:34:11]# echo hello from container web > index.html
[root@ubuntu ~ 10:34:59]# nerdctl cp index.html web:/usr/share/nginx/html
[root@ubuntu ~ 10:35:04]# curl localhost
hello from container web
nerdctl 管理存储
nerdctl 命令创建容器的时候,可以使用 -v 选项将本地目录挂载给容器实现数据持久化。
示例:
通过文件
[root@ubuntu ~ 11:04:02]# echo hello from volume > index.html
[root@ubuntu ~ 11:05:25]# nerdctl run -d -v ./index.html:/usr/share/nginx/html/index.html nginx
WARN[0000] expected an absolute path, got a relative path "./index.html" (allowed for nerdctl, but disallowed for Docker, so unrecommended)
914f1e1bc975b464b4abd54d78a96a971a603fc072642cd69fb7e09228278a35
[root@ubuntu ~ 11:06:01]# nerdctl container exec 914f1e1bc cat /usr/share/nginx/html/index.html
hello from volume
nerdctl 命令创建容器的时候,也可以使用 -v 选项指定volume
示例:
通过卷来实现
[root@ubuntu ~ 11:08:17]# nerdctl run -d -v web:/usr/share/nginx/html/ nginx
6b61aa46c22182c31c91b1b581027b74d824c81f9e12dd9112432cab41b704d8
[root@ubuntu ~ 11:08:27]# nerdctl volume ls
VOLUME NAME DIRECTORY
web /var/lib/nerdctl/1935db59/volumes/default/web/_data
[root@ubuntu ~ 11:08:39]# echo hello volume > /var/lib/nerdctl/1935db59/volumes/default/web/_data/index.html
[root@ubuntu ~ 11:09:04]# nerdctl container exec 6b61aa46c2 cat /usr/share/nginx/html/index.html
hello volume
nerdctl 管理命名空间
[root@ubuntu ~ 11:09:48]# nerdctl namespace ls
NAME CONTAINERS IMAGES VOLUMES LABELS
default 3 4
##查看namespae帮助
[root@ubuntu ~ 11:11:48]# nerdctl namespace --help
Unrelated to Linux namespaces and Kubernetes namespaces
Usage: nerdctl namespace [flags]
Aliases: namespace, ns
Commands:
create Create a new namespace
inspect Display detailed information on one or more namespaces.
ls List containerd namespaces
remove Remove one or more namespaces
update Update labels for a namespace
Flags:
-h, --help help for namespace
See also 'nerdctl --help' for the global flags such as '--namespace', '--snapshotter', and '--cgroup-manager'.
更多推荐

所有评论(0)