Compare commits

..
72 Commits
Author SHA1 Message Date
yeasy fab4e41587 Update OS examples to Debian 13, Ubuntu 26.04, Fedora 43 2026-04-28 09:24:17 +00:00
yeasy 229aec2f1e Update Kubernetes node status conditions terminology 2026-04-28 09:24:17 +00:00
yeasy 8ebf284f9e Update nginx references from 1.25 to 1.30 2026-04-28 09:24:03 +00:00
yeasy a89f7285c7 Fix typos and update Docker Hub limits and versions 2026-04-28 09:15:40 +00:00
yeasy 15c7fe1dc2 Update Docker Hub rate limits and version refs 2026-04-28 08:20:21 +00:00
yeasy 4d1e323faf Fix seccomp typo, postgres path and DCA exam details 2026-04-28 04:21:10 +00:00
yeasy 16203c5018 Complete Dockerfile instruction reference list 2026-04-27 23:17:39 +00:00
yeasy 3d3befa16a Add ipvlan driver and update EKS pricing 2026-04-27 22:45:17 +00:00
yeasy 09fd556c18 Refresh image CLI docs 2026-04-27 09:15:19 -07:00
yeasy 37e376d578 Fix mongosh, DCA price, compose healthcheck and cleanup 2026-04-27 14:17:57 +00:00
yeasy 04fd53ea3c Update Docker image tags and etcd commands 2026-04-27 11:18:08 +00:00
yeasy b1cd2f0878 Fix Docker Hub rate limits and etcdctl API version 2026-04-27 05:13:02 +00:00
yeasy e416a1be7e Fix Docker Hub rate limits, DCT timeline, image tags, etcd and Alertmanager 2026-04-27 01:15:52 +00:00
yeasy e406ed9185 Update Gateway API docs and image security practices 2026-04-26 00:18:39 +00:00
yeasy c36c420c7e Add nftables support and Time namespace documentation 2026-04-26 00:18:39 +00:00
yeasy 72513eb673 更新 Namespace/Gateway API/nftables/DCT 退役时间线
- ch12: 添加 TIME namespace (Linux 5.6+),内核 namespace 类型从 7 更新为 8
- ch12: 补充 Docker Engine v29.x 实���性 nftables 支持
- ch13: Ingress-NGINX 退役通知,添加 Gateway API 推荐方案和示例
- ch13: 添加 Pod Security Standards 章节(替代已移除的 PSP)
- ch18: 补充 DCT 退役时间线(2028-03-31 完全移除)和迁移建议
2026-04-26 00:12:59 +00:00
yeasy 8ea52620cc Update Prometheus to v3.11.2, fix etcdctl version 2026-04-25 22:39:33 +00:00
yeasy 22dd236122 Fix network IPs, compose healthcheck, update GH Actions versions 2026-04-25 21:11:50 +00:00
yeasy 98f4f7b1e5 Add official doc links to install guides 2026-04-25 21:11:50 +00:00
yeasy 87bb4b2ceb Add version notes and image tag best practices 2026-04-25 21:11:50 +00:00
yeasy dad26ccb28 Update docker0 default subnet to 172.17.0.0/16 2026-04-25 21:03:39 +00:00
yeasy 84a801f3ac Document depends_on condition and healthcheck 2026-04-25 21:03:39 +00:00
yeasy 420a5776ce Accurate cgroup v2 description, update Actions versions 2026-04-25 20:42:35 +00:00
yeasy b2839f735c Fix broken code block in laravel multistage Dockerfile 2026-04-25 20:42:18 +00:00
yeasy 98e299a38e Add version notes and official doc links 2026-04-25 15:58:42 +00:00
Baohua Yang aa204fb454 chore: lint cleanup and version corrections
- Accept benign linter changes (version notes, explicit tags, formatting)
- Fix incorrect version downgrades introduced by linter:
  - golang:1.22→1.26 (restored)
  - rust:1.82→1.95 (restored)
- 23 files updated
2026-04-25 15:58:27 +00:00
yeasy 1e9cdeea3f Update Grafana to v13, add version notes 2026-04-25 15:50:13 +00:00
yeasy 515ba9f64a Add blank lines before lists per CommonMark 2026-04-25 15:13:27 +00:00
yeasy 9abc1cbb69 Update Kubernetes to v1.36, build-push-action to v7 2026-04-25 15:10:51 +00:00
yeasy 839a63f5af Update versions and fix formatting issues 2026-04-25 15:10:43 +00:00
yeasy 20a3479f8a Add Docker Scout, remove deprecated type_name 2026-04-25 15:02:24 +00:00
yeasy 52329fee5a Update etcd to v3.5.29 2026-04-25 15:00:47 +00:00
yeasy 8093b198ce Update node-exporter to v1.11.1, fcct to butane 2026-04-25 14:58:40 +00:00
yeasy 77a537df54 Add blank lines before lists per CommonMark 2026-04-25 14:57:09 +00:00
yeasy e414d9475b Update containerd config path for 2.x 2026-04-25 14:22:55 +00:00
yeasy 037591e5af Update content and fix issues 2026-04-25 02:14:58 +00:00
yeasy 94f74fc86e Clarify image build semantics 2026-04-24 10:51:49 -07:00
yeasy 4b44d64cd8 Fix straight quotes to curly quotes in mirror doc 2026-04-24 13:24:52 +00:00
yeasy 49a85c802e Fix Ubuntu codenames and containerd LTS description 2026-04-24 03:16:05 +00:00
yeasy 2a7f7d9a3d Fix apt cache cleanup path in Dockerfile example 2026-04-23 13:16:21 -07:00
yeasy 544ede8498 Pin Prometheus and Grafana image versions 2026-04-22 12:24:31 -07:00
yeasy 54a9a6e55b Add runC CVEs and AuthZ plugin guidance 2026-04-22 12:24:31 -07:00
yeasy 27617ea619 Add section numbers to ecosystem headings 2026-04-22 12:24:30 -07:00
yeasy 69fc2234d0 Update nginx version and K8s dashboard date 2026-04-22 12:24:30 -07:00
yeasy ac92e6c536 Fix Debian dates and FAQ template syntax 2026-04-22 08:43:48 -07:00
yeasy 1fc64ab875 Refresh install guidance
# Conflicts:
#	03_install/3.1_ubuntu.md
#	03_install/3.2_debian.md
#	03_install/3.3_fedora.md
#	03_install/3.9_mirror.md
2026-04-22 08:24:38 -07:00
yeasy c9c72618c3 Refresh k8s docker versions and references 2026-04-21 20:57:33 -07:00
yeasy 4b93651989 Refine Docker concepts 2026-04-21 14:39:41 -07:00
yeasy b3d1508310 Add new content and update versions 2026-04-19 22:35:33 -07:00
yeasy 1d780f70c5 Drop legacy plugins 2026-04-19 20:14:36 -07:00
yeasy ff48ac79ee Clarify intro chapter 2026-04-18 20:25:29 -07:00
yeasy 077e55f494 Update software versions and fix security refs 2026-04-18 19:04:14 -07:00
yeasy 1bed644e5e Fix mermaid syntax and update K8s taint labels 2026-04-18 15:17:56 -07:00
yeasy da5867c921 Update Kind v0.31.0 and Flannel v0.28.2 2026-04-18 13:31:43 -07:00
yeasy 407d508590 Restructure README with badges and cover 2026-04-17 21:51:38 -07:00
yeasy 6fcb74bccc Add Ubuntu 20.04 EOL exact date 2026-04-17 21:19:32 -07:00
yeasy d81405a807 Update versions and fix stale data 2026-04-17 21:17:12 -07:00
github-actions[bot]andGitHub 983e7c18c3 Merge pull request #564 from yeasy/dependabot/github_actions/dependencies-8fe05ed821
chore(deps): bump the dependencies group with 2 updates
2026-04-15 18:46:57 +00:00
dependabot[bot]andGitHub 9e194b9a74 chore(deps): bump the dependencies group with 2 updates
Bumps the dependencies group with 2 updates: [softprops/action-gh-release](https://github.com/softprops/action-gh-release) and [dependabot/fetch-metadata](https://github.com/dependabot/fetch-metadata).


Updates `softprops/action-gh-release` from 2 to 3
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](https://github.com/softprops/action-gh-release/compare/v2...v3)

Updates `dependabot/fetch-metadata` from 2 to 3
- [Release notes](https://github.com/dependabot/fetch-metadata/releases)
- [Commits](https://github.com/dependabot/fetch-metadata/compare/v2...v3)

---
updated-dependencies:
- dependency-name: softprops/action-gh-release
  dependency-version: '3'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: dependencies
- dependency-name: dependabot/fetch-metadata
  dependency-version: '3'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-04-15 18:46:44 +00:00
yeasy 6b2ebd12ac Fix Chinese curly quotes in prose text 2026-04-14 20:29:35 -07:00
yeasy f86e3567e8 Fix figure caption punctuation and table formatting 2026-04-13 18:37:00 -07:00
yeasy 2dacddb999 Fix figure caption format 2026-04-09 09:02:44 -07:00
yeasy 422123dd70 Add section numbering and archive notice 2026-04-08 22:40:15 -07:00
yeasy adee45f7bc Fix bash comment style to single hash 2026-04-08 22:39:51 -07:00
yeasy 04b81a8c05 Fix mdpress port 4000 to 9000 2026-04-05 13:39:46 -07:00
yeasy e85ca7a11e Fix typo in offline install image alt text 2026-04-05 12:59:09 -07:00
yeasy 66905627b8 Remove time annotation in install docs 2026-04-05 12:58:42 -07:00
yeasy aec453b9bb Remove duplicate release-pdf workflow 2026-04-05 08:55:52 -07:00
yeasy 565b40ab0b Add release-pdf CI workflow for automated PDF builds 2026-04-05 08:29:11 -07:00
yeasy 50fe8ebbbb Replace defunct AtomHub mirror with docker.1ms.run 2026-04-05 08:16:08 -07:00
yeasy c84927c196 ci: add auto-release.yml, remove release-pdf.yml, limit CI trigger to master 2026-04-05 07:57:56 -07:00
Baohua Yang 2b0c00c5e5 Add recommended reading paths table to README 2026-04-04 22:31:23 -07:00
11 changed files with 23 additions and 23 deletions
+1 -1
View File
@@ -172,7 +172,7 @@ registry.example.com/myproject/myapp:v1.2.3
## 简写(使用 Docker Hub
nginx:1.25
nginx:1.30
ubuntu:24.04
## 省略标签(默认使用 latest)
+3 -3
View File
@@ -1,6 +1,6 @@
## 2.3 仓库
> **版本说明**本节示例基于 Docker v29.x 和常见镜像版本编写示例中的版本号 `nginx:1.25``mysql:8.0``mysql:5.7` 为演示用途实际使用时请访问 [Docker Hub 官方页面](https://hub.docker.com) 或相应镜像的发布页确认最新可用版本和标签。
> **版本说明**本节示例基于 Docker v29.x 和常见镜像版本编写示例中的版本号 `nginx:1.30``mysql:8.0``mysql:5.7` 为演示用途实际使用时请访问 [Docker Hub 官方页面](https://hub.docker.com) 或相应镜像的发布页确认最新可用版本和标签。
Docker Registry 是镜像分发和管理的核心组件本节将介绍 Registry 的基本概念公共和私有服务的选择以及镜像的安全管理
@@ -73,7 +73,7 @@ registry.example.com/mycompany/myapp:v1.2.3
## Docker Hub 官方镜像(省略 registry 和用户名)
nginx:1.25
nginx:1.30
ubuntu:24.04
## Docker Hub 用户镜像
@@ -217,7 +217,7 @@ $ docker login registry.example.com # 登录其他 Registry
## 拉取镜像
$ docker pull nginx:1.25
$ docker pull nginx:1.30
## 标记镜像(准备推送)
+1 -1
View File
@@ -34,7 +34,7 @@ Starting ──成功──> Healthy ──失败N次──> Unhealthy
#### Web 服务检查
```docker
# 注:nginx 镜像推荐使用具体的版本标签(如 nginx:1.25-alpine
# 注:nginx 镜像推荐使用具体的版本标签(如 nginx:1.30-alpine
FROM nginx
RUN apt-get update && apt-get install -y curl && rm -rf /var/lib/apt/lists/*
+1 -1
View File
@@ -176,5 +176,5 @@ $ docker build --target builder -t username/imagename:tag .
上面例子中我们使用 `COPY --from=0 /go/src/github.com/go/helloworld/app .` 从上一阶段的镜像中复制文件我们也可以复制任意镜像中的文件
```docker
COPY --from=nginx:1.25-alpine /etc/nginx/nginx.conf /nginx.conf
COPY --from=nginx:1.30-alpine /etc/nginx/nginx.conf /nginx.conf
```
@@ -128,8 +128,8 @@ RUN set -x ; cd ${LARAVEL_PATH} \
### 7.18.5 最后一个阶段构建 NGINX 镜像
```docker
# nginx 镜像推荐使用具体的版本标签 nginx:1.25-alpine
FROM nginx:1.25-alpine as nginx
# nginx 镜像推荐使用具体的版本标签 nginx:1.30-alpine
FROM nginx:1.30-alpine as nginx
ARG LARAVEL_PATH=/app/laravel
@@ -179,7 +179,7 @@ $ docker run -dit --rm --network=laravel -p 8080:80 my/nginx
完整的 `Dockerfile` 文件如下
```docker
# 生产环境推荐使用具体的版本标签 node:20-alpinecomposer:2.xphp:8.3-fpm-alpinenginx:1.25-alpine
# 生产环境推荐使用具体的版本标签 node:20-alpinecomposer:2.xphp:8.3-fpm-alpinenginx:1.30-alpine
FROM node:20-alpine as frontend
COPY package.json /app/
@@ -229,7 +229,7 @@ RUN set -x ; cd ${LARAVEL_PATH} \
&& chmod -R 777 storage \
&& php artisan package:discover
FROM nginx:1.25-alpine as nginx
FROM nginx:1.30-alpine as nginx
ARG LARAVEL_PATH=/app/laravel
+1 -1
View File
@@ -35,7 +35,7 @@
##### 节点状态
节点的状态主要是用来描述处于 `Running` 的节点当前可用的有 `NodeReachable` `NodeReady`以后可能会增加其他状态`NodeReachable` 表示集群可达`NodeReady` 表示 kubelet 返回 Status Ok 并且 HTTP 状态检查健康
节点的状态通过一组条件Conditions来描述主要条件包括 `Ready`kubelet 健康且可以接收 Pod`MemoryPressure`内存不足`DiskPressure`磁盘不足 `PIDPressure`进程数过多其中 `Ready` 条件最为关键值为 `True` 表示节点健康可调度`False` 表示节点异常`Unknown` 表示节点控制器超过一定时间未收到心跳
#### 节点管理
+1 -1
View File
@@ -8,7 +8,7 @@
一个普通的 Linux 内核提供了 300 多个系统调用而一个正常运行的容器化应用例如 Nginx 服务通常只会用到几十个调用这就给攻击者留下了大量的闲置入口点来进行内核层的缓冲区溢出攻击
Docker 默认启用了 Seccomp 并利用预置的 [默认配置文件](https://github.com/moby/moby/blob/master/profiles/seccomp/default.json) 将可以利用的系统调用缩减到了不足一半(默认禁用了 44 个危险的统调用,比如修改时区或重启系统)。
Docker 默认启用了 Seccomp 并利用预置的 [默认配置文件](https://github.com/moby/moby/blob/master/profiles/seccomp/default.json) 将可以利用的系统调用缩减到了不足一半(默认禁用了 44 个危险的统调用,比如修改时区或重启系统)。
如果你对应用的系统调用特征了如指掌你可以为容器定制专属规则
+7 -7
View File
@@ -25,7 +25,7 @@ Debian 是一个常用的基础镜像。
```bash
$ docker run -it debian bash
root@668e178d8d69:/# cat /etc/issue
Debian GNU/Linux 12
Debian GNU/Linux 13
```
`Debian` 镜像很适合作为基础镜像构建自定义镜像
@@ -43,18 +43,18 @@ Debian GNU/Linux 12
Ubuntu 是目前最流行的 Linux 发行版之一
下面以 `ubuntu:24.04` 为例演示如何使用该镜像安装一些常用软件
下面以 `ubuntu:26.04` 为例演示如何使用该镜像安装一些常用软件
首先使用 `-ti` 参数启动容器登录 `bash`查看 `ubuntu` 的发行版本号
```bash
$ docker run -ti ubuntu:24.04 /bin/bash
$ docker run -ti ubuntu:26.04 /bin/bash
root@7d93de07bf76:/# cat /etc/os-release
PRETTY_NAME="Ubuntu 24.04 LTS"
PRETTY_NAME="Ubuntu 26.04 LTS"
NAME="Ubuntu"
VERSION_ID="24.04"
VERSION="24.04 LTS (Noble Numbat)"
VERSION_CODENAME=noble
VERSION_ID="26.04"
VERSION="26.04 LTS (Resolute Raccoon)"
VERSION_CODENAME=resolute
ID=ubuntu
ID_LIKE=debian
HOME_URL="https://www.ubuntu.com/"
+1 -1
View File
@@ -50,7 +50,7 @@ latest: Pulling from library/fedora
Digest: sha256:64a02df6aac27d1200c2572fe4b9949f1970d05f74d367ce4af994ba5dc3669e
Status: Downloaded newer image for fedora:latest
[root@196ca341419b /]# cat /etc/redhat-release
Fedora release 39 (Thirty Nine)
Fedora release 43 (Forty Three)
```
### 20.4.3 相关资源
+1 -1
View File
@@ -190,7 +190,7 @@ ENV PG_MAJOR 9.3
ENV PG_VERSION 9.3.4
RUN curl -SL http://example.com/postgres-$PG_VERSION.tar.xz | tar -xJC /usr/src/postgress && …
RUN curl -SL http://example.com/postgres-$PG_VERSION.tar.xz | tar -xJC /usr/src/postgres && …
ENV PATH /usr/local/postgres-$PG_MAJOR/bin:$PATH
```
+2 -2
View File
@@ -434,8 +434,8 @@ Kubernetes 进阶 (Week 24-36)
- 题目数55
- 时间限制90 分钟
- 及格分数73% 41 道题
- 费用$165 USD
- 有效期3
- 费用$199 USD
- 有效期2
考试内容比例
```text