Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
[deSymfony] Docker on every environment
Search
Sponsored
·
SiteGround - Reliable hosting with speed, security, and support you can count on.
→
Jose Armesto
September 16, 2016
Programming
680
2
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
[deSymfony] Docker on every environment
Jose Armesto
September 16, 2016
More Decks by Jose Armesto
See All by Jose Armesto
Lessons learnt trying to deploy Docker in production
fiunchinho
0
200
Unit Testing Sucks (... and it's our fault)
fiunchinho
5
1.5k
Hexagonal Architecture
fiunchinho
9
1.2k
Other Decks in Programming
See All in Programming
S3 を使うアプリケーションをローカル完結で動かすことに全力を注いでみた / Running S3 Apps Offline
contour_gara
0
560
PostgreSQL 18で考えるUUID主キー
kazuhiro1982
0
490
引き算の組織 ― アウトカムとAIに全振りするために辞めたこと ― / Organization by Subtraction
hirokiyamamoto14
PRO
0
270
ソフトウェアエンジニアにとっての生成AI - 特性を知って使い倒す / generative ai for software enginner
kishida
7
2k
AIと壁打ちしながら進めるコスト管理
fufuhu
1
1.1k
Claude Code全社展開のためにやったことn選~プラグイン302個・コミッター271人を支えるために~
kenchan
5
1.6k
170k Jobs a Day on GKE: Scaling Mercari's CI Platform - and What's Next for AI-Native Development
junyaokabe
0
120
Japan Community Day at Kubecon + CloudNativeCon Japan 2026: Learning Container Privilege Control by Building My Own Low-Level Container Runtime
ternbusty
1
170
「つくるAI」だけではバグは見つからない ~テストに必要な「見つけるAI」を分離させる戦略~
mfunaki
0
120
Detecting Compromised CI with eBPF and Cilium Tetragon
lizrice
0
220
仕様駆動開発へのトライを機に チームに適合する手法を模索し続けている話
freee
PRO
0
590
人間の目はかわらない、だからJPEGは30年もつ
yuzneri
12
19k
Featured
See All Featured
Effective software design: The role of men in debugging patriarchy in IT @ Voxxed Days AMS
baasie
0
480
How GitHub (no longer) Works
holman
316
150k
Measuring & Analyzing Core Web Vitals
bluesmoon
9
970
The #1 spot is gone: here's how to win anyway
tamaranovitovic
3
1.1k
The Illustrated Children's Guide to Kubernetes
chrisshort
51
53k
How to Ace a Technical Interview
jacobian
281
24k
Designing for Timeless Needs
cassininazir
1
450
Mozcon NYC 2025: Stop Losing SEO Traffic
samtorres
1
490
Why You Should Never Use an ORM
jnunemaker
PRO
61
10k
Future Trends and Review - Lecture 12 - Web Technologies (1019888BNR)
signer
PRO
0
3.7k
Practical Orchestrator
shlominoach
191
12k
Measuring Dark Social's Impact On Conversion and Attribution
stephenakadiri
2
260
Transcript
None
None
None
Containers. How do we transport containers from development to production?
You take the red pill, you stay in Wonderland, and
I show you how deep the rabbit hole goes.
Docker provides a beautiful API that hides the real complexity.
Why do we call them containers?
ISO standards for containers were published between 1968 and 1970.
Software containers try to be the standard for Applications distribution
Applications runtime
Development Workflow Dev Prod CI / CD
CI / CD Development Workflow Dev Prod
None
Distribution: Container Images
Packaging applications for distribution is not a new problem.
❏ Disk images .iso ❏ VMware .vdmk ❏ Vagrant .box
❏ Amazon Machine Images AMI Systems Packaging
❏ zip/tgz ❏ Java jar/war ❏ Debian deb ❏ RedHat
rpm Application Packaging
Container images combine both system and application packaging. Old best
practices still apply.
Container images can be easily built using manifests.
Building the same manifest twice could produce different images.
The difference between how you think something works and how
it actually works risks hard-to-debug production issues. Gareth Rushgrove @garethr
None
❏ Which OS is it based on? ❏ Which packages
are installed? ❏ What application is running inside? Giving a running container
❏ Which OS is it based on? ❏ Which packages
are installed? ❏ What application is running inside? Giving a running container
Operating System Which Alpine? FROM alpine CMD [“echo”, “Knock”, ”Knock”,
“Neo”]
Operating System Is this better? FROM alpine:3.4 CMD [“echo”, “Knock”,
”Knock”, “Neo”]
Operating System Tags can be overwritten! 3.4 won’t be the
same in two weeks, probably FROM alpine:3.4 CMD [“echo”, “Knock”, ”Knock”, “Neo”]
❏ Which OS is it based on? ❏ Which packages
are installed? ❏ What application is running inside? Giving a running container
Packages Which pip? FROM alpine:3.4 RUN apk add -‐-‐update py-‐pip
CMD [“echo”, “Knock”, ”Knock”, “Neo”]
Versions Specify the version FROM alpine:3.4 RUN apk add -‐-‐update
py-‐pip=8.1.2-‐r0 CMD [“echo”, “Knock”, ”Knock”, “Neo”]
❏ Which OS is it based on? ❏ Which packages
are installed? ❏ What application is running inside? Giving a running container
Application Which version of our application? FROM alpine:3.4 RUN apk
add -‐-‐update py-‐pip=8.1.2-‐r0 COPY app.py /app.py CMD [“python”, “/app.py”]
Metadata Use Docker Labels for application metadata FROM alpine:3.4 ARG
vcs_ref="Unknown" ARG build_date="Unknown" RUN apk add -‐-‐update py-‐pip=8.1.2-‐r0 LABEL org.label-‐schema.vcs-‐ref=$vcs_ref \ org.label-‐schema.build-‐date=$build_date COPY app.py /app.py CMD [“python”, “/app.py”]
Metadata Use Docker Labels for application metadata FROM alpine:3.4 ARG
vcs_ref="Unknown" ARG build_date="Unknown" RUN apk add -‐-‐update py-‐pip=8.1.2-‐r0 LABEL org.label-‐schema.vcs-‐ref=$vcs_ref \ org.label-‐schema.build-‐date=$build_date COPY app.py /app.py CMD [“python”, “/app.py”]
Standard for Docker labels
Use labels to extract info
Metadata Use Docker Labels for application metadata FROM alpine:3.4 ARG
vcs_ref="Unknown" ARG build_date="Unknown" RUN apk add -‐-‐update py-‐pip=8.1.2-‐r0 LABEL org.label-‐schema.vcs-‐ref=$vcs_ref \ org.label-‐schema.build-‐date=$build_date COPY app.py /app.py CMD [“python”, “/app.py”]
Metadata Calculate the values for the labels $ docker build
\ -‐-‐build-‐arg vcs_ref=`git rev-‐parse HEAD` \ -‐-‐build-‐arg date=`date -‐u + "%Y-‐%m-‐%dT%H:%MZ"` \ -‐t your_image_name .
Open Source Docker Registries
Docker Hub
Official Docker Registry
Harbor (VMware)
Port.us (Suse)
Paid Docker Registries
Docker DataCenter
AWS ECR
JFrog Artifactory
Development Workflow Dev CI / CD Prod
Building our images
Building the same manifest twice could produce different images.
Build once. Promote images to different environments.
Jenkins Workflow 1. Detect merge to repository
Jenkins Workflow 1. Detect merge to repository 2. If tests
pass, build image and push it to pre production registry
Jenkins Workflow 1. Detect merge to repository 2. If tests
pass, build image and push it to pre production registry 3. Deploy to pre environment
Jenkins Workflow 1. Detect merge to repository 2. If tests
pass, build image and push it to pre production registry 3. Deploy to pre environment 4. If tests pass, push image to pro registry
Jenkins Workflow 1. Detect merge to repository 2. If tests
pass, build image and push it to pre production registry 3. Deploy to pre environment 4. If tests pass, push image to pro registry 5. Deploy to production
Keep In Mind ❏ Be clear on which versions of
docker/docker-compose you allow ❏ Use Jenkins build number or timestamp as image tag ❏ Seek a Generic Build process ❏ Clean old images/containers
Clean old images/containers
CI / CD Development Workflow Dev Prod
Container Runtime
Container vs VM comparison
It’s better to think about containers as regular unix processes
Run only one process
❏ Easier debugging ❏ Simplified setup of networks, ports... ❏
Logs have only one format ❏ Resources sharing: CPU vs memory Running one process
Processes inside containers are started and stopped the same way
a unix system would do it.
❏ How they start? ❏ How they stop? Containers and
processes share a similar lifecycle
Unix Processes: the chosen PID1 (the One, got it? :D)
When you run the container, the init (PID1) process is
started, which is responsible for starting other processes, creating a tree-like hierarchy.
$ ps -‐e -‐o user,pid,ppid,args -‐-‐forest UID PID
PPID CMD root 1 0 init root 205 1 /sbin/udevd -‐-‐daemon root 1113 205 \_ /sbin/udevd -‐-‐daemon root 1114 205 \_ /sbin/udevd -‐-‐daemon root 1199 1 crond -‐f -‐d 8 root 1216 1 VBoxService root 1241 1 /usr/local/sbin/acpid root 1249 1 /sbin/udhcpc -‐b -‐i eth1...
Every process has a parent process, except for the init
process.
When a process ends, its entry in the process table
remains, keeping the process in a defunct or zombie status.
Only after the parent read the child’s exit status to
know what happened, the zombie is removed. This is called reaping.
The init process also adopts orphans. An orphan is a
process that is still executing but whose parent has died.
None
If your process is running as PID1, it’s probably expecting
a init process to properly adopting and reaping processes.
Running our process as a subcommand of bash would solve
this problem. But bash doesn’t handle unix signals.
Unix Signals
A signal is an asynchronous notification sent to a process
in order to notify it of an event that occurred.
SIGINT Interrupt from keyboard SIGKILL Kill process immediately SIGTERM Request
nice process termination
Signals sent by the Docker engine to the containers are
handled by the init process.
Unless a process has registered a custom signal handler for
SIGTERM, the kernel will fall back sending a SIGKILL signal.
For PID1, though, the kernel won’t even fall back to
SIGKILL. If your process hasn’t registered a handler, SIGTERM will have no effect on the process.
None
By default, docker stop sends a SIGTERM and waits 10
seconds for the container to stop. After that, it sends a SIGKILL.
nginx expects a SIGQUIT to do a graceful shutdown. Apache
expects a SIGWINCH.
Options for your container entrypoint ❏ shell form
Options for your container entrypoint ❏ shell form ❏ exec
form
Options for your container entrypoint ❏ shell form ❏ exec
form ❏ Using a proper init process
shell form ❏ ENTRYPOINT command param1 param2 ❏ The process
will be started as a subcommand of /bin/sh -c ❏ Remember, bash does not pass signals
exec form ❏ ENTRYPOINT ["executable", "param1"] ❏ The process will
be PID1 init process inside the container ❏ Your process should adopt and take care of reaping
Using a proper init process ❏ A init process that
pass signals, adopt orphans and takes care of reaping. ❏ There are several init processes for containers ❏ tini ❏ dumb-init
Demo
Wrapping Up
We need formal pipelines to promote images from development to
production. Build once and promote.
Without a proper init system ❏ Zombie processes could become
a problem in the system. ❏ Signals are not passed to your process as you may expect, not being able to gracefully stop a process.
We need to understand the container lifecycle to deploy those
images.
Your Kubernetes cluster on raspberry pi is not production ready.
None
@fiunchinho Schibsted Spain Jose Armesto