Docker 데몬 설정은 /etc/docker/daemon.json 하나에 모은다. 항목마다 다른 문서를 보고 그대로 옮겨 적다 보면 최상위 키가 중복되거나 쉼표가 남아 JSON 이 깨지고, 그러면 데몬이 아예 뜨지 않는다. 자주 함께 쓰는 항목(ulimit · 주소 풀 · data-root · cgroup 드라이버)을 한 파일에 합치는 방법과, daemon.json 을 쓰지 않고 systemd 드롭인으로 같은 값을 주는 방법을 정리한다.
JSON 은 같은 이름의 최상위 키를 두 번 쓸 수 없다. 두 설정을 합칠 때는 각 파일의 최상위 키를 한 객체 안에 나란히 둔다. 마지막 항목 뒤에 쉼표를 남기면 파싱 오류가 난다.
{
"default-ulimits": {
"nofile": { "Name": "nofile", "Hard": 65535, "Soft": 65535 },
"nproc": { "Name": "nproc", "Hard": 65535, "Soft": 65535 }
},
"default-address-pools": [
{ "base": "192.168.0.0/16", "size": 24 }
],
"data-root": "/data/docker",
"exec-opts": ["native.cgroupdriver=systemd"]
}
적용 전에 문법을 확인하고, 데몬을 재시작한 뒤 docker info 로 반영 여부를 본다.
python3 -m json.tool /etc/docker/daemon.json
systemctl restart docker
docker info | grep -E 'Docker Root Dir|Cgroup Driver'
패키지가 설치한 docker.service 를 직접 고치면 업그레이드 때 덮어써진다. 드롭인 파일을 만들어 ExecStart 를 비운 뒤 다시 정의한다. 첫 줄의 빈 ExecStart= 가 원래 값을 지우는 역할을 하며, 이 줄이 없으면 docker.service: Service has more than one ExecStart= setting 오류가 난다.
# /etc/systemd/system/docker.service.d/override.conf
[Service]
ExecStart=
ExecStart=/usr/bin/dockerd -H fd:// --containerd=/run/containerd/containerd.sock --data-root=/data/docker --exec-opt native.cgroupdriver=systemd
systemctl daemon-reload
systemctl restart docker
같은 항목을 daemon.json 과 dockerd 플래그 양쪽에 주면 데몬이 "unable to configure the Docker daemon with file /etc/docker/daemon.json: the following directives are specified both as a flag and in the configuration file" 로 기동을 거부한다. 한쪽에만 둔다[1].
data-root 를 바꾸는 것만으로 기존 이미지가 옮겨지지는 않는다. 데몬을 멈추고 디렉터리를 복사한 뒤 바꿔야 한다.
default-ulimits 항목의 의미와 컨테이너별 재정의.default-address-pools 와 bip 의 차이.dockerd — Daemon configuration file. https://docs.docker.com/reference/cli/dockerd/ ↩︎