Skip to content
Guang Chen edited this page Apr 7, 2016 · 5 revisions

配置tls

生成证书 see https://docs.docker.com/engine/security/https/

CA只用创建一次,之后在不同的结点上分别创建csr然后到CA的server上去签署证书

修改/etc/default/docker

DOCKER_OPTS+=" -H unix:///var/run/docker.sock --tlsverify --tlscacert=/var/docker/ca.pem --tlscert=/var/docker/server-cert.pem --tlskey=/var/docker/server-key.pem -H tcp://<ip>:2376"

重启docker服务

sudo service docker restart