A discussion about when to upgrade Docker and how to do it safely is ongoing. tophee initially asked about upgrading Docker, citing a bug that affected their instance. Stephen suggested a conservative approach and provided instructions on how to uninstall and reinstall Docker.
itsbhanusharma shared their experience with Docker version 18.04.0-ce, which has been running smoothly. However, Stephen cautioned that running doesn’t necessarily mean running well, and performance issues can arise between versions.
codinghorror recommended using the latest Docker version unless there are specific reasons not to. However, mpalmer explained that their environment and processes might not be suitable for everyone, and specific reasons for not upgrading might exist.
The discussion also touched on the topic of IPv6 routing issues with Docker and a bug that causes Docker to blow away IPv6 routing. tophee expressed doubts about upgrading due to a bug in Docker that has not been entirely fixed.
Regarding the “how” part, peternlewis asked about the safety of uninstalling old Docker versions and installing Docker CE. codinghorror reassured that the process is safe since the container file is not touched. peternlewis successfully upgraded to Docker CE version 18.06.0-ce, but noted that the storage driver did not transition to overlay2 as expected.
Lastly, dandv reported an issue with the apt-cache policy docker-ce command, which returned an empty version table.
I had made a mental not that I’ll eventuall need to allow my instance to upgrade docker again, after downgrading because of that bug, but I’m not sure when I should do that nor how I do it without breaking stuff… Or do I need to do anything?
Pretty much a guaranteed way to jinx your installs!
Seriously though, over the past few years we’ve had a number of run-ins with docker versions. Even if instances appear to be building and running ok there have been plenty of performance issues between versions.
I’d totally agree to that, There have been multiple edge cases and other complaints due to people being on a specific version of docker which contains some bug. About the performance part, I haven’t really invested myself into creating stats for known good and the delta between those and the latest so I can’t say much but I never had it trigger any alerts for me.
I’m however curious to know what strategy you use to observe the performance metrics for docker in relation to discourse?
Usually the difference is observable from whatever server management you use, we’ve got everything in either AWS or DO and most of it is hooked up into New Relic. If there’s a performance difference there’s also usually an observable step up or down in CPU usage.
We’ve not gone so far as to look at transaction times, but as these machines only run Discourse it’s very easy to see if a docker version has an impact on load.
I provide insights into our environment, processes, and decision-making for informational purposes only, unless clearly stated otherwise. What we at CDCK do, given our scale, priorities, and the skills and experience of our team, is not necessarily a good idea for everyone else, whose circumstances are likely very different. That’s the “unless you have specific reasons not to” in Jeff’s post.
I’d interpret that as “specific reasons that your installation of Discourse is different from ‘Most’ installations of Discourse”. Or “you should already know if this applies to you” or “your sysadmin said you need to hold back the upgrade” or …
Well, something like that happened back then. But I guess the reasons for being more than conservative with docker upgrades that existed some months ago don’t exist anymore. Otherwise we’d have heard them by now.
For example. All our internal stuff is wedded deeply to ipv6. It turns out the rest of the world barely uses ipv6, apparently, because Docker had a release where it blew away all ipv6 routing (which caused a massive internal hosting outage for us), and we were basically the only people to report it as a problem. It still isn’t fixed as far as we know.
There’s a concrete, very specific example of how “the world” and “discourse internal” can deviate.
The IPv6 one got fixed, it just missed the next stable release which was frustrating, since we needed to roll custom packages with the bugfix. It’s all the other ones that are still open. The “logging long lines” bug hasn’t even been substantively looked at, as far as I can tell, however we deployed a workaround that shouldn’t cause it to trip when running Discourse. I wouldn’t call wanting to write your logs to Docker “badly behaved”, though, since that’s what Docker’s supposed to be for (“ill-advised”, yes, but not badly behaved).
WARNING: Docker version 17.05.0-ce deprecated, recommend upgrade to 17.06.2 or newer.
However the Get Docker CE for Ubuntu instructions start with “Uninstall old versions docker or docker-engine” before installing docker-ce.
Needless to say, anything that starts with “uninstall stuff” makes me more than a little nervous as to how much of my site it plans on deleting, and how safe it is to go ahead and uninstall docker-engine, and then install docker-ce, and expect my site to be there and working when I finish. How safe is this process? If I have a site working with docker-engine, and I follow the Get Docker CE for Ubuntu instructions, uninstall docker-engine, install docker-ce via the “Install using the repository” instructions, am I likely to actually have a working site at the end of it?
OK, followed the instructions and it all went smoothly. The most time consuming part by far was taking a snapshot beforehand as a safety precaution (on top of normal backups and such).
docker info now reports:
Server Version: 18.06.0-ce
Storage Driver: aufs
I include the aufs since the update Get Docker page says:
For Ubuntu 16.04 and higher, the Linux kernel includes support for OverlayFS, and Docker CE uses the overlay2 storage driver by default. If you need to use aufs instead, you need to configure it manually. See aufs
But it seems that the update did not transition to using overlay instead of aufs.
Do I need to do something to make that happen as well, or just ignore it and continue with aufs?