<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Containers on Bill Glover</title>
		<link>https://old.bill.dev/tags/containers/</link>
		<description>Recent content in Containers on Bill Glover</description>
		<generator>Hugo</generator>
		<language>en-gb</language>
		
			<managingEditor>hello@bill.dev (Bill)</managingEditor>
		
		
			<webMaster>hello@bill.dev (Bill)</webMaster>
		
		
		
			<lastBuildDate>Sun, 28 Sep 2025 22:27:35 +0100</lastBuildDate>
		
			<atom:link href="https://old.bill.dev/tags/containers/index.xml" rel="self" type="application/rss+xml" />
			<item>
				<title>Docker Desktop (Mac) Unix Socket</title>
				<link>https://old.bill.dev/2024/04/13/docker-desktop-mac-unix-socket/</link>
				<pubDate>Sat, 13 Apr 2024 18:37:00 +0000</pubDate><author>hello@bill.dev (Bill)</author>
				<guid>https://old.bill.dev/2024/04/13/docker-desktop-mac-unix-socket/</guid>
				<description>&lt;p&gt;Two of the tools in my container toolkit stopped working at some point recently. To demonstrate the issue, I first make sure that I have an image pulled locally.&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;bg@Bills-MBP ~ % docker image ls&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;REPOSITORY   TAG       IMAGE ID       CREATED       SIZE&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;golang       1.22      824aa3c1d42c   10 days ago   830MB&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;demo         latest    cf12555b1219   10 days ago   830MB&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The first tool, Dive, started producing errors like this.&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;bg@Bills-MBP tmp % dive demo&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Image Source: docker://demo&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Fetching image... (this can take a while for large images)&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Handler not available locally. Trying to pull &amp;#39;demo&amp;#39;...&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Using default tag: latest&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Error response from daemon: pull access denied for demo, repository does not exist or may require &amp;#39;docker login&amp;#39;: denied: requested access to the resource is denied&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;cannot fetch image&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;exit status 1&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The image was present locally and the docker daemon definitely running. I logged out, logged in again and tried different accounts. When I first hit this error I assumed that this was an issue with Dive. The workaround I used was to export the image to a &lt;code&gt;.tar&lt;/code&gt; file and then use dive to browse the disk image. But then I hit this error with Trivy.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Docker and LetsEncrypt</title>
				<link>https://old.bill.dev/notes/docker-and-letsencrypt/</link>
				<pubDate>Thu, 20 Oct 2022 20:14:45 +0100</pubDate><author>hello@bill.dev (Bill)</author>
				<guid>https://old.bill.dev/notes/docker-and-letsencrypt/</guid>
				<description>&lt;p&gt;If you are running a private container registry and using a certificate provided by &lt;a href=&#34;https://letsencrypt.org/&#34;&gt;LetsEncrypt&lt;/a&gt;, make sure you are using &lt;code&gt;fullchain.pem&lt;/code&gt; and not &lt;code&gt;cert.pem&lt;/code&gt;. If you miss this, the Docker CLI will report that your certificate is signed by an unknown authority.&lt;/p&gt;&#xA;&lt;p&gt;I have an instance of &lt;a href=&#34;https://goharbor.io/&#34;&gt;Harbor&lt;/a&gt; running as a private container registry. The certificate used by this instance is provided by LetsEncrypt and yet the Docker CLI refused to let me log in.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Copy Files to and from a Container</title>
				<link>https://old.bill.dev/notes/kubectl-cp/</link>
				<pubDate>Tue, 24 May 2022 09:56:32 +0000</pubDate><author>hello@bill.dev (Bill)</author>
				<guid>https://old.bill.dev/notes/kubectl-cp/</guid>
				<description>&lt;p&gt;&lt;strong&gt;Problem:&lt;/strong&gt; I needed to copy some database files into a container running on Kubernetes without modifying the image or restarting the parent Pod.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Solution:&lt;/strong&gt; The Kubernetes CLI includes a sub-command for copying files into and out of a running container: &lt;code&gt;kubectl cp /tmp/foo &amp;lt;some-pod&amp;gt;:/tmp/bar&lt;/code&gt;&lt;/p&gt;&#xA;&lt;h2 id=&#34;background&#34;&gt;Background&lt;/h2&gt;&#xA;&lt;p&gt;I&amp;rsquo;ve never found the need to copy files into a running container without issuing an updated image. This is somewhat of an anti-pattern as modifications to containerised filesystems that aren&amp;rsquo;t mounted externally are lost when the container process terminates.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Build Multi-Architecture Docker Images</title>
				<link>https://old.bill.dev/notes/build-multi-arch-docker-images/</link>
				<pubDate>Fri, 01 Apr 2022 19:22:32 +0000</pubDate><author>hello@bill.dev (Bill)</author>
				<guid>https://old.bill.dev/notes/build-multi-arch-docker-images/</guid>
				<description>&lt;p&gt;Back in 2018, I wrote about &lt;a href=&#34;https://old.bill.dev/2018/10/30/multi-architecture-docker-builds/&#34;&gt;Multi-Architecture Docker Builds&lt;/a&gt;. My main aim then was to run the occasional container image on a Raspberry Pi. Apple&amp;rsquo;s transition to M1 based machines has increased demand for multi-architecture container images. In this post, I document an improved approach to building multi-architecture images.&lt;/p&gt;&#xA;&lt;p&gt;I’ll use a Go application to show the build process. It prints the current runtime OS and CPU architecture to the terminal and then exits.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Use Harbor to Avoid Docker Hub Rate Limits</title>
				<link>https://old.bill.dev/2021/01/07/use-harbor-to-avoid-docker-hub-rate-limits/</link>
				<pubDate>Thu, 07 Jan 2021 11:00:00 +0000</pubDate><author>hello@bill.dev (Bill)</author>
				<guid>https://old.bill.dev/2021/01/07/use-harbor-to-avoid-docker-hub-rate-limits/</guid>
				<description>&lt;p&gt;In  November, Docker implemented new rate limits for anonymous and free use of Docker Hub. They added two new limits:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Anonymous: 100 container image requests / six hours&lt;/li&gt;&#xA;&lt;li&gt;Free Authenticated: 200 container image requests / six hours&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;If you find yourself operating above these limits, you have a few options. You can sign up for a Docker Pro or Team account, or you can reduce image request frequency below thresholds.&lt;/p&gt;</description>
			</item>
			<item>
				<title>My Toolbox: Octant</title>
				<link>https://old.bill.dev/2020/10/12/my-toolbox-octant/</link>
				<pubDate>Mon, 12 Oct 2020 10:00:00 +0000</pubDate><author>hello@bill.dev (Bill)</author>
				<guid>https://old.bill.dev/2020/10/12/my-toolbox-octant/</guid>
				<description>&lt;p&gt;&lt;img src=&#34;octant_overview.png&#34; alt=&#34;octant&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;We are constantly presented with new tools all the time; scripts, themes, or even code editors. We try them, we forget about them, and before you know it a &lt;code&gt;brew update&lt;/code&gt; take minutes rather than seconds to run. The few tools that do tend to stick around are those that solve a real need. Octant is one such tool. It&amp;rsquo;s not just the latest addition to my toolbox, it&amp;rsquo;s one that I&amp;rsquo;m turning to with increasing regularity.&lt;/p&gt;</description>
			</item>
			<item>
				<title>How I Manage Kubernetes Config</title>
				<link>https://old.bill.dev/2020/06/12/how-i-manage-kubernetes-config/</link>
				<pubDate>Fri, 12 Jun 2020 06:00:00 +0000</pubDate><author>hello@bill.dev (Bill)</author>
				<guid>https://old.bill.dev/2020/06/12/how-i-manage-kubernetes-config/</guid>
				<description>&lt;figure&gt;&lt;img &#xA;        sizes=&#34;(min-width: 35em) 1200px, 100vw&#34;&#xA;        srcset=&#39;&#xA;        &#xA;            /2020/06/12/how-i-manage-kubernetes-config/kubeconfig_hu_23d09877fb65fac4.png 500w&#xA;        &#xA;        &#xA;        &#xA;        &#39;&#xA;        &#xA;            src=&#34;https://old.bill.dev/2020/06/12/how-i-manage-kubernetes-config/kubeconfig.png&#34; &#xA;        &#xA;         alt=&#34;Image showing a roll of toilet paper covered in kubeconfig YAML.&#34;/&gt;&#xA;&lt;/figure&gt;&#xA;&lt;p&gt;If you work with Kubernetes, you&amp;rsquo;ll be aware of the config file that defines contexts. This config is what &lt;code&gt;kubectl&lt;/code&gt; uses to gain access to a cluster. I work with a large number of ephemeral clusters and have found that this config is difficult to manage. This post shows how I&amp;rsquo;ve switched to using individual config files for each cluster.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Dive Through the Layers</title>
				<link>https://old.bill.dev/2020/02/28/dive-through-the-layers/</link>
				<pubDate>Fri, 28 Feb 2020 06:16:35 +0000</pubDate><author>hello@bill.dev (Bill)</author>
				<guid>https://old.bill.dev/2020/02/28/dive-through-the-layers/</guid>
				<description>&lt;h1 id=&#34;dive-through-the-layers&#34;&gt;Dive Through the Layers&lt;/h1&gt;&#xA;&lt;p&gt;I&amp;rsquo;ve been working with a container image for a Django application and was surprised to find that an image for a simple application was 1.2 GB. This was particularly jarring as, coming from the world of Go, I&amp;rsquo;m used to images that come in at under 20 MB.&lt;/p&gt;&#xA;&lt;p&gt;It&amp;rsquo;s not the size of the container image that&amp;rsquo;s the problem. Layer caching and re-use means that you are rarely transferring the full image around and that storage on disk is usually less than the sum of all your images. The worry I have with an image that is 1.2 GB is that everything that makes up that image needs to be maintained, patched, watched for security vulnerabilities, etc. 1.2 GB is a lot of software.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Docker Compose: Conditional Services</title>
				<link>https://old.bill.dev/2020/02/21/docker-compose-conditional-services/</link>
				<pubDate>Fri, 21 Feb 2020 06:16:35 +0000</pubDate><author>hello@bill.dev (Bill)</author>
				<guid>https://old.bill.dev/2020/02/21/docker-compose-conditional-services/</guid>
				<description>&lt;p&gt;I recently added a &lt;code&gt;docker-compose&lt;/code&gt; definition of services to make it easier for people to contribute to the new &lt;a href=&#34;https://codebuddies.org&#34;&gt;CodeBuddies&lt;/a&gt; back-end. This addresses some of the pain new contributors were feeling with setting up a local development environment. The CodeBuddies backend is an API built using the Django REST Framework. PostgreSQL provides the data store. Everything is fronted by an Nginx reverse proxy. This is often referred to as a &lt;a href=&#34;https://en.wikipedia.org/wiki/Multitier_architecture#Three-tier_architecture&#34;&gt;three-tier architecture&lt;/a&gt;.&lt;/p&gt;</description>
			</item>
			<item>
				<title>The Sidecar Pattern</title>
				<link>https://old.bill.dev/2020/01/12/the-sidecar-pattern/</link>
				<pubDate>Sun, 12 Jan 2020 08:16:35 +0000</pubDate><author>hello@bill.dev (Bill)</author>
				<guid>https://old.bill.dev/2020/01/12/the-sidecar-pattern/</guid>
				<description>&lt;p&gt;The sidecar is a multi-container pattern used to provide additional functionality to a containerised-application without requiring changes to the application itself. The sidecar is the foundation of popular tools like the Istio service mesh. But how does it work?&lt;/p&gt;&#xA;&lt;p&gt;In this post, I will demonstrate how to use the Sidecar pattern to add TLS termination to an existing application using a custom-built proxy server. In reality, there should be no reason to build everything from scratch, I&amp;rsquo;ve done so here to validate my understanding of how things work. This post has been written so that you can read along without implementing the examples, but if you want to get your hands dirty and code along, I&amp;rsquo;ve made a few assumptions:&lt;/p&gt;</description>
			</item>
	</channel>
</rss>
