<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Docker on BvBeJ的小站</title><link>https://www.bvbej.com/tags/docker/</link><description>Recent content in Docker on BvBeJ的小站</description><generator>Hugo</generator><language>zh-CN</language><lastBuildDate>Wed, 27 May 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://www.bvbej.com/tags/docker/feed.xml" rel="self" type="application/rss+xml"/><item><title>Docker Rootless 模式：落地路径与限制</title><link>https://www.bvbej.com/posts/docker-rootless-mode-practice/</link><pubDate>Wed, 27 May 2026 00:00:00 +0000</pubDate><guid>https://www.bvbej.com/posts/docker-rootless-mode-practice/</guid><description>最小权限运行可以提升安全性，但要评估网络和存储差异</description></item><item><title>Docker 镜像保留策略：存储成本与回滚能力平衡</title><link>https://www.bvbej.com/posts/docker-image-retention-policy/</link><pubDate>Sun, 24 May 2026 00:00:00 +0000</pubDate><guid>https://www.bvbej.com/posts/docker-image-retention-policy/</guid><description>保留太少影响回滚，保留太多拖垮仓库成本</description></item><item><title>Docker Compose 可观测性套件：本地联调模板</title><link>https://www.bvbej.com/posts/docker-compose-observability-stack/</link><pubDate>Thu, 21 May 2026 00:00:00 +0000</pubDate><guid>https://www.bvbej.com/posts/docker-compose-observability-stack/</guid><description>把日志、指标、追踪一次拉起，能显著提高问题定位效率</description></item><item><title>Docker Buildx 多架构构建：x86 与 ARM 一次产出</title><link>https://www.bvbej.com/posts/docker-multi-arch-buildx/</link><pubDate>Mon, 18 May 2026 00:00:00 +0000</pubDate><guid>https://www.bvbej.com/posts/docker-multi-arch-buildx/</guid><description>多架构交付的关键是可复现构建与缓存复用</description></item><item><title>Docker Registry Mirror：拉取加速与稳定性</title><link>https://www.bvbej.com/posts/docker-registry-mirror-acceleration/</link><pubDate>Fri, 15 May 2026 00:00:00 +0000</pubDate><guid>https://www.bvbej.com/posts/docker-registry-mirror-acceleration/</guid><description>镜像拉取链路优化是大规模 CI 的基础能力</description></item><item><title>容器运行时隔离权衡：runc、gVisor、Kata 的场景选择</title><link>https://www.bvbej.com/posts/container-runtime-isolation-tradeoff/</link><pubDate>Thu, 14 May 2026 00:00:00 +0000</pubDate><guid>https://www.bvbej.com/posts/container-runtime-isolation-tradeoff/</guid><description>隔离强度越高越安全吗？答案取决于威胁模型和性能预算。</description></item><item><title>Docker 运行时安全：Seccomp 与 AppArmor 基线</title><link>https://www.bvbej.com/posts/docker-runtime-security-profiles/</link><pubDate>Tue, 12 May 2026 00:00:00 +0000</pubDate><guid>https://www.bvbej.com/posts/docker-runtime-security-profiles/</guid><description>镜像安全只是第一层，运行时策略才是最后防线</description></item><item><title>Docker Layer 缓存治理：CI 时间控制实战</title><link>https://www.bvbej.com/posts/docker-layer-cache-governance/</link><pubDate>Sat, 09 May 2026 00:00:00 +0000</pubDate><guid>https://www.bvbej.com/posts/docker-layer-cache-governance/</guid><description>缓存不是越多越好，关键是可命中、可清理、可观测</description></item><item><title>Monorepo Docker 构建缓存：减少无效重建</title><link>https://www.bvbej.com/posts/docker-monorepo-build-cache/</link><pubDate>Tue, 05 May 2026 00:00:00 +0000</pubDate><guid>https://www.bvbej.com/posts/docker-monorepo-build-cache/</guid><description>仓库越大越要控制构建上下文，否则 CI 时间会持续恶化</description></item><item><title>Docker 供应链安全落地：从 SBOM 到 SLSA 的最小可行路径</title><link>https://www.bvbej.com/posts/docker-supply-chain-slsa-practice/</link><pubDate>Sun, 03 May 2026 00:00:00 +0000</pubDate><guid>https://www.bvbej.com/posts/docker-supply-chain-slsa-practice/</guid><description>安全不是扫描报告，而是可追溯、可验证、可阻断的发布链路。</description></item><item><title>Docker 供应链安全：SBOM 与镜像签名落地</title><link>https://www.bvbej.com/posts/docker-sbom-signing-pipeline/</link><pubDate>Sat, 02 May 2026 00:00:00 +0000</pubDate><guid>https://www.bvbej.com/posts/docker-sbom-signing-pipeline/</guid><description>镜像安全要从构建阶段开始，把可追溯和可验证做进流水线</description></item><item><title>Docker Compose：本地与线上环境一致性实践</title><link>https://www.bvbej.com/posts/docker-compose-devprod-parity/</link><pubDate>Tue, 28 Apr 2026 00:00:00 +0000</pubDate><guid>https://www.bvbej.com/posts/docker-compose-devprod-parity/</guid><description>本地能跑不代表线上稳定，关键是环境契约是否一致</description></item><item><title>Docker + BuildKit：CI 构建提速实战</title><link>https://www.bvbej.com/posts/docker-buildkit-ci-acceleration/</link><pubDate>Sat, 25 Apr 2026 00:00:00 +0000</pubDate><guid>https://www.bvbej.com/posts/docker-buildkit-ci-acceleration/</guid><description>同样的 Dockerfile，为什么有人 2 分钟构建完，有人要 15 分钟</description></item><item><title>Docker BuildKit 提速：缓存策略的正确打开方式</title><link>https://www.bvbej.com/posts/docker-buildkit-cache-strategy/</link><pubDate>Tue, 21 Apr 2026 00:00:00 +0000</pubDate><guid>https://www.bvbej.com/posts/docker-buildkit-cache-strategy/</guid><description>利用分层与缓存挂载，让镜像构建从分钟级降到秒级</description></item><item><title>Docker 镜像安全与瘦身：从能跑到适合上线</title><link>https://www.bvbej.com/posts/docker-image-security-hardening/</link><pubDate>Thu, 16 Apr 2026 00:00:00 +0000</pubDate><guid>https://www.bvbej.com/posts/docker-image-security-hardening/</guid><description>镜像优化不只是减小体积，真正上线时还要关心攻击面、权限模型和供应链风险</description></item><item><title>Docker 多阶段构建：让你的镜像小而美</title><link>https://www.bvbej.com/posts/docker-multi-stage-build/</link><pubDate>Wed, 15 Apr 2026 00:00:00 +0000</pubDate><guid>https://www.bvbej.com/posts/docker-multi-stage-build/</guid><description>用多阶段构建把 Go 镜像从 800MB 压到 8MB，还顺带优化构建速度</description></item></channel></rss>