Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[docker-in-docker] - toggle ip6tables settings value as option #1068

Merged
Merged
Show file tree
Hide file tree
Changes from 41 commits
Commits
Show all changes
45 commits
Select commit Hold shift + click to select a range
2f64c44
[docker-in-docker] - toggle ip6tables settings value as option
gauravsaini04 Jul 29, 2024
322a350
Merge branch 'devcontainers:main' into docker_in_docker_#_1023
gauravsaini04 Jul 30, 2024
2fe16aa
Update src/docker-in-docker/devcontainer-feature.json
gauravsaini04 Jul 30, 2024
e585c05
Update src/docker-in-docker/devcontainer-feature.json
gauravsaini04 Jul 30, 2024
9cdc2be
Merge branch 'devcontainers:main' into docker_in_docker_#_1023
gauravsaini04 Aug 6, 2024
88cb142
Merge branch 'devcontainers:main' into docker_in_docker_#_1023
gauravsaini04 Aug 8, 2024
89ab50c
Merge branch 'devcontainers:main' into docker_in_docker_#_1023
gauravsaini04 Aug 13, 2024
037c05a
Merge branch 'devcontainers:main' into docker_in_docker_#_1023
gauravsaini04 Aug 14, 2024
cbcc284
Merge branch 'devcontainers:main' into docker_in_docker_#_1023
gauravsaini04 Aug 16, 2024
0a42b76
ip6tables - can be toggled
gauravsaini04 Aug 16, 2024
c3915be
changes as requested
gauravsaini04 Aug 16, 2024
054bdd5
change to add test file..
gauravsaini04 Aug 16, 2024
6d1d44f
Merge branch 'main' into docker_in_docker_#_1023
gauravsaini04 Aug 17, 2024
ca631a5
Merge branch 'main' into docker_in_docker_#_1023
gauravsaini04 Aug 19, 2024
f011055
Merge branch 'devcontainers:main' into docker_in_docker_#_1023
gauravsaini04 Aug 20, 2024
c6b43f6
Merge branch 'devcontainers:main' into docker_in_docker_#_1023
gauravsaini04 Aug 27, 2024
dbb3aaa
Merge branch 'devcontainers:main' into docker_in_docker_#_1023
gauravsaini04 Aug 28, 2024
b485b58
changes for docker_build_older test passing
gauravsaini04 Aug 28, 2024
1ef2903
misc change
gauravsaini04 Aug 28, 2024
30bc624
CHANGE
gauravsaini04 Aug 28, 2024
7d04ed7
chg
gauravsaini04 Aug 28, 2024
8d7277e
minor change to make tests pass
gauravsaini04 Aug 28, 2024
1300bf9
for sh compatibility
gauravsaini04 Aug 28, 2024
9cde8c3
change for version
gauravsaini04 Aug 28, 2024
313e82f
small change
gauravsaini04 Aug 28, 2024
8bec80d
few imp. changes
gauravsaini04 Aug 28, 2024
113a093
few changes
gauravsaini04 Aug 28, 2024
cced5b5
for test passing
gauravsaini04 Aug 28, 2024
eadcf01
minor commit
gauravsaini04 Aug 28, 2024
6e2914f
version added to a test scenario
gauravsaini04 Aug 28, 2024
b3fd0b5
changes
gauravsaini04 Aug 28, 2024
0e180ad
LOGIC was moved outside the init file for faster initialization times
gauravsaini04 Aug 29, 2024
8aa19ee
changes
gauravsaini04 Aug 29, 2024
6bcce46
logic updated !
gauravsaini04 Sep 3, 2024
fb7c3da
chg
gauravsaini04 Sep 3, 2024
ec74e20
default value to be null
gauravsaini04 Sep 3, 2024
abb1e23
Merge branch 'main' into docker_in_docker_#_1023
gauravsaini04 Sep 4, 2024
c0b2c36
changes as suggested in review comments..
gauravsaini04 Sep 4, 2024
c1c4eba
by mistake
gauravsaini04 Sep 4, 2024
d15c392
another small change
gauravsaini04 Sep 4, 2024
51fe00a
requested changes in comments (review pr)
gauravsaini04 Sep 5, 2024
c54789a
change as requested
gauravsaini04 Sep 7, 2024
d4a2545
Merge branch 'devcontainers:main' into docker_in_docker_#_1023
gauravsaini04 Sep 10, 2024
0a5d389
changes as suggested in review comments
gauravsaini04 Sep 10, 2024
e181e20
Update src/docker-in-docker/install.sh
gauravsaini04 Sep 11, 2024
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 6 additions & 1 deletion src/docker-in-docker/devcontainer-feature.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"id": "docker-in-docker",
"version": "2.11.0",
"version": "2.12.0",
"name": "Docker (Docker-in-Docker)",
"documentationURL": "https://github.com/devcontainers/features/tree/main/src/docker-in-docker",
"description": "Create child containers *inside* a container, independent from the host's docker instance. Installs Docker extension in the container along with needed CLIs.",
Expand Down Expand Up @@ -55,6 +55,11 @@
"type": "boolean",
"default": true,
"description": "Install Compose Switch (provided docker compose is available) which is a replacement to the Compose V1 docker-compose (python) executable. It translates the command line into Compose V2 docker compose then runs the latter."
},
"disableIp6tables": {
"type": "boolean",
"default": false,
"description": "Disable ip6tables (this option is only applicable for Docker versions 27 and greater)"
}
},
"entrypoint": "/usr/local/share/docker-init.sh",
Expand Down
29 changes: 27 additions & 2 deletions src/docker-in-docker/install.sh
Original file line number Diff line number Diff line change
Expand Up @@ -20,6 +20,7 @@ INSTALL_DOCKER_COMPOSE_SWITCH="${INSTALLDOCKERCOMPOSESWITCH:-"true"}"
MICROSOFT_GPG_KEYS_URI="https://packages.microsoft.com/keys/microsoft.asc"
DOCKER_MOBY_ARCHIVE_VERSION_CODENAMES="bookworm buster bullseye bionic focal jammy noble"
DOCKER_LICENSED_ARCHIVE_VERSION_CODENAMES="bookworm buster bullseye bionic focal hirsute impish jammy noble"
DISABLE_IP6_TABLES="${DISABLEIP6TABLES:-false}"

# Default: Exit on any failure.
set -e
Expand Down Expand Up @@ -468,6 +469,29 @@ if [ "${INSTALL_DOCKER_BUILDX}" = "true" ]; then
find "${docker_home}" -type d -print0 | xargs -n 1 -0 chmod g+s
fi

DOCKER_DEFAULT_IP6_TABLES=""
requested_version=""
# checking whether the version requested either is in semver format or just a number denoting the major version
# extracting the major version number out of the two scenarios
semver_regex="^(0|[1-9][0-9]*)\.(0|[1-9][0-9]*)\.(0|[1-9][0-9]*)(?:-([0-9A-Za-z-]+(?:\.[0-9A-Za-z-]+)*))?(?:\+([0-9A-Za-z-]+(?:\.[0-9A-Za-z-]+)*))?$"
gauravsaini04 marked this conversation as resolved.
Show resolved Hide resolved
gauravsaini04 marked this conversation as resolved.
Show resolved Hide resolved
samruddhikhandale marked this conversation as resolved.
Show resolved Hide resolved
samruddhikhandale marked this conversation as resolved.
Show resolved Hide resolved
if echo "$DOCKER_VERSION" | grep -Eq "$semver_regex"; then
gauravsaini04 marked this conversation as resolved.
Show resolved Hide resolved
requested_version=$(echo $DOCKER_VERSION | cut -d. -f1)
elif echo "$DOCKER_VERSION" | grep -Eq "^-?[0-9]+$"; then
requested_version=$DOCKER_VERSION
fi

if [[ -n "$requested_version" && "$requested_version" -ge 27 ]] || [ "$DOCKER_VERSION" = "latest" ]; then
if [ "$DISABLE_IP6_TABLES" == true ]; then
DOCKER_DEFAULT_IP6_TABLES="--ip6tables=false"
echo "(!) As requested, passing '${DOCKER_DEFAULT_IP6_TABLES}'"
fi
else
if [ "$DISABLE_IP6_TABLES" == false ]; then
gauravsaini04 marked this conversation as resolved.
Show resolved Hide resolved
echo "ERR: Passing --ip6tables=true is not supported for Docker v26 and below... Remove 'disableIp6tables:false' from Feature options..."
exit 1
gauravsaini04 marked this conversation as resolved.
Show resolved Hide resolved
fi
fi

tee /usr/local/share/docker-init.sh > /dev/null \
<< EOF
#!/bin/sh
Expand All @@ -480,11 +504,12 @@ set -e

AZURE_DNS_AUTO_DETECTION=${AZURE_DNS_AUTO_DETECTION}
DOCKER_DEFAULT_ADDRESS_POOL=${DOCKER_DEFAULT_ADDRESS_POOL}
DOCKER_DEFAULT_IP6_TABLES=${DOCKER_DEFAULT_IP6_TABLES}
EOF

tee -a /usr/local/share/docker-init.sh > /dev/null \
<< 'EOF'
dockerd_start="AZURE_DNS_AUTO_DETECTION=${AZURE_DNS_AUTO_DETECTION} DOCKER_DEFAULT_ADDRESS_POOL=${DOCKER_DEFAULT_ADDRESS_POOL} $(cat << 'INNEREOF'
dockerd_start="AZURE_DNS_AUTO_DETECTION=${AZURE_DNS_AUTO_DETECTION} DOCKER_DEFAULT_ADDRESS_POOL=${DOCKER_DEFAULT_ADDRESS_POOL} DOCKER_DEFAULT_IP6_TABLES=${DOCKER_DEFAULT_IP6_TABLES} $(cat << 'INNEREOF'
# explicitly remove dockerd and containerd PID file to ensure that it can start properly if it was stopped uncleanly
find /run /var/run -iname 'docker*.pid' -delete || :
find /run /var/run -iname 'container*.pid' -delete || :
Expand Down Expand Up @@ -562,7 +587,7 @@ dockerd_start="AZURE_DNS_AUTO_DETECTION=${AZURE_DNS_AUTO_DETECTION} DOCKER_DEFAU
fi

# Start docker/moby engine
( dockerd $CUSTOMDNS $DEFAULT_ADDRESS_POOL > /tmp/dockerd.log 2>&1 ) &
( dockerd $CUSTOMDNS $DEFAULT_ADDRESS_POOL $DOCKER_DEFAULT_IP6_TABLES > /tmp/dockerd.log 2>&1 ) &
INNEREOF
)"

Expand Down
24 changes: 24 additions & 0 deletions test/docker-in-docker/dockerIp6tablesDisabledTest.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
#!/bin/bash

set -e

# Optional: Import test library
source dev-container-features-test-lib

ip6tablesCheck() {
if command -v ip6tables > /dev/null 2>&1; then
if ip6tables -L > /dev/null 2>&1; then
echo "✔️ ip6tables is enabled."
else
echo "❌ ip6tables is disabled."
fi
else
echo "❕ip6tables command not found. ❕"
fi
}

check "ip6tables" ip6tablesCheck
check "ip6tables check" bash -c "docker network inspect bridge"
check "docker-build" docker build ./

reportResults
9 changes: 9 additions & 0 deletions test/docker-in-docker/scenarios.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,15 @@
}
}
},
"dockerIp6tablesDisabledTest": {
"image": "ubuntu:focal",
"features": {
"docker-in-docker": {
"version": "27.0.3",
"disableIp6tables": true
}
}
},
"dockerDefaultAddressPool": {
"image": "mcr.microsoft.com/vscode/devcontainers/javascript-node:0-18",
"remoteUser": "node",
Expand Down
Loading