I'm trying to do the bandwidth throttling to the Docker containers.
To limit the downlink bandwidth, I can first find the veth interface of the container and use tc: tc qdisc add dev vethpair1 root tbf rate 1mbit latency 50ms burst 10000
. If I want to limit the uplink bandwidth, I need to specify --cap-add=NET_ADMIN
when I spin up the container and use the same tc command on eth0
inside the container. Is there any non-intrusive way to do it, so that I can administrate any container without giving it privilege?
You could use the iptables limits module. For example, you could add a rule to the PREROUTING table using the options "-m limit --limit 10/s" to limit a particular port to receive only 10 connections per second. Save this answer.
It's possible to block outbound traffic from Docker containers using IPTables. In this configuration, traffic will be allowed from the internet to docker instances, but the instances themselves will only be able to communicate with each other (provided they are using the docker0 interface).
You must connect containers with the --link option in your docker run command. The Docker bridge supports port mappings and docker run --link allowing communications between containers on the docker0 network.
You could tell Docker to use LXC under the hoods : use the -e lxc
option.
Create your containers with a custom LXC directive to put them into a **traffic class** :
`docker run --lxc-conf="lxc.cgroup.net_cls.classid = 0x00100001" your/image /bin/stuff`
Check the official documentation about how to apply bandwidth limits to this class.
Note : the --storage-driver=devicemapper
and -e lxc
options are for the Docker daemon, not for the Docker client you're using when running docker run .......
.
ALso you can do this through this:
mkdir /var/run/netns
ln -sf /proc/`docker inspect -f '{{ .State.Pid }}' YOUR_CONTAINER`/ns/net /var/run/netns/SOME_NAME
ip netns exec SOME_NAME iptables -L -nv
If you love us? You can donate to us via Paypal or buy me a coffee so we can maintain and grow! Thank you!
Donate Us With