--- title: 容器管理模块与系统设置要点 type: fact permalink: main/projects/d5a7f581-c442-4554-87b9-ee723b8b0258/容器管理模块与系统设置要点 stable_id: 669e2c30-1109-4f5f-962c-93460d1b1328 scope: project project_id: d5a7f581-c442-4554-87b9-ee723b8b0258 memory_type: fact status: active revision: 1 restored_from_commit: 6a6a895eafcca6052e81a14fca103a42635dd1c2 created_at: '2026-09-23T15:10:19.849500+00:00' updated_at: '2026-09-23T15:10:19.849562+00:00' tags: - containers - module - settings --- 容器模块:Docker SDK 连当前宿主 Docker Engine(自动检测 DOCKER_HOST/socket/named pipe/本地 TCP,可手动覆盖);容器/镜像/卷管理,高危写操作仅 Web 登录态(require_web_session)。镜像导入/导出任务 ContainerJob 完整生命周期:启动时重置中断任务为 failed、按 container_job_retention_hours(默认 168h)清理、导入 tar 用完即删、文件落 METRIX_RUNTIME_DIR/container_jobs/。删镜像前用 daemon 侧 ancestor 过滤检查所有容器占用(不限可见容器)。创建容器环境变量名含 password/secret/token/key 显式 400(error.containerEnvKeyNotAllowed)。Docker 引擎信息区默认收起(n-collapse,localStorage 记忆)。系统设置要点:session_token_expire_hours(默认 12,0=永不过期);各种并发/保留/配额类设置 0=不限制;前端 localStorage key 统一用 appKey() 前缀。