#5157·nerdctl

默认生成的 nerdctl-nat.conflist 未设置 capabilities.portMappings=true 以启用主机与容器端口映射

作者: mloskot创建于 2026年8月23日更新于 2026年8月24日
标签bugplatform/Windows/Non-WSL2area/network
  1. 安装 containerd
  2. 安装 nerdctl
  3. 运行 nerdctl run -p 5093:5093/tcp myapp:latest
  4. 观察,端口未映射/转发,且 myapp 服务无法从主机上访问,无论是 http://localhost:5093http://127.0.0.1:5093 还是 http://HOST_IP:5093
  5. 观察容器生成的 wincni.log 未报告任何映射。
  6. C:\Program Files\containerd\cni\conf\nerdctl-nat.conflist 文件中添加以下片段:
json
          "capabilities": {
             "portMappings": true,
             "dns": true
          }
  1. 运行 Restart-Service containerd
  2. 运行 nerdctl run -p 5093:5093/tcp myapp:latest
  3. 观察 myapp 可从主机上访问 http://127.0.0.1:5093http://HOST_IP:5093
  4. 观察 wincni.log 报告了映射:
json
{"level":"debug","msg":"Created raw policy from mapping: {HostPort:5093 ContainerPort:5093 Protocol:udp HostIp:0.0.0.0} --- {Type:EndpointPolicy Data:[123 34 84 121 112 101 34 58 34 80 111 114 116 77 97 112 112 105 110 103 34 44 34 83 101 116 116 105 110 103 115 34 58 123 34 80 114 111 116 111 99 111 108 34 58 49 55 44 34 73 110 116 101 114 110 97 108 80 111 114 116 34 58 53 48 57 51 44 34 69 120 116 101 114 110 97 108 80 111 114 116 34 58 53 48 57 51 44 34 86 73 80 34 58 34 48 46 48 46 48 46 48 34 125 125]}","time":"2026-08-23T15:23:41+01:00"}
...
{"level":"debug","msg":"hcn::HostComputeEndpoint::Create JSON:
…

内容来源: containerd/nerdctl