Amazon ECS에서 Docker 데몬의 상세(verbose) 출력 구성하기

Amazon ECS에서 Docker 데몬의 상세(verbose) 출력 구성하기

Docker 컨테이너나 이미지에 문제가 있다면 Docker 데몬에서 디버그 모드를 켤 수 있어요. 디버깅을 사용하면 데몬에서 더 상세한 출력을 얻을 수 있고, Amazon ECR 같은 컨테이너 레지스트리에서 보내는 오류 메시지를 가져오는 데 사용할 수 있습니다.

출처: 문서

본문

Docker 컨테이너나 이미지에 문제가 있을 때 Docker 데몬의 디버그 모드를 켤 수 있습니다. 디버깅을 켜면 데몬에서 더 상세한 출력을 얻을 수 있고, Amazon ECR 같은 컨테이너 레지스트리가 보내는 오류 메시지를 가져오는 데 사용할 수 있어요.

중요: 이 절차는 Amazon ECS-optimized Amazon Linux AMI용으로 작성되었습니다. 다른 운영 체제에서는 Docker 문서의 "Enable debugging"과 "Control and configure Docker with systemd"를 참고하세요.

Amazon ECS-optimized Amazon Linux AMI에서 Docker 데몬 디버그 모드 사용하기

  1. 컨테이너 인스턴스에 연결합니다.

  2. vi 같은 텍스트 편집기로 Docker 옵션 파일을 엽니다. Amazon ECS-optimized Amazon Linux AMI에서 Docker 옵션 파일은 /etc/sysconfig/docker에 있습니다.

  3. Docker options 문장을 찾아 문자열 안에 -D 옵션을 추가합니다.

    참고: Docker options 문장이 #로 시작하면 해당 문자를 제거해 주석을 해제하고 옵션을 활성화하세요. Amazon ECS-optimized Amazon Linux AMI에서 Docker options 문장은 OPTIONS라고 불립니다.

    예:

    # Additional startup options for the Docker daemon, for example:
    # OPTIONS="--ip-forward=true --iptables=true"
    # By default we limit the number of open files per container
    OPTIONS="-D --default-ulimit nofile=1024:4096"
    
  4. 파일을 저장하고 텍스트 편집기를 종료합니다.

  5. Docker 데몬을 재시작합니다.

    sudo service docker restart
    

    출력은 다음과 같습니다.

    Stopping docker:                                          [  OK  ]
    Starting docker:	.                                  [  OK  ]
    
  6. Amazon ECS 에이전트를 재시작합니다.

    sudo service ecs restart
    
  7. 이제 Docker 로그에서 더 상세한 출력을 볼 수 있습니다.

    time="2015-12-30T21:48:21.907640838Z" level=debug msg="Unexpected response from server: \"{\\\"errors\\\":[{\\\"code\\\":\\\"DENIED\\\",\\\"message\\\":\\\"User: arn:aws:sts::1111:assumed-role/ecrReadOnly/i-abcdefg is not authorized to perform: ecr:InitiateLayerUpload on resource: arn:aws:ecr:us-east-1:1111:repository/nginx_test\\\"}]}\n\" http.Header{\"Connection\":[]string{\"keep-alive\"}, \"Content-Type\":[]string{\"application/json; charset=utf-8\"}, \"Date\":[]string{\"Wed, 30 Dec 2015 21:48:21 GMT\"}, \"Docker-Distribution-Api-Version\":[]string{\"registry/2.0\"}, \"Content-Length\":[]string{\"235\"}}"
    

이처럼 디버그 출력을 통해 인증 실패나 레지스트리 응답 같은 상세 오류 메시지를 확인할 수 있어요.

더 알아보기 (Learn more)

  • Docker 데몬 디버깅에 대한 자세한 내용은 Docker 공식 문서를 참고해 주세요.