# Running Docker in MicroK8s Kubernetes container

**URL:** <https://discuss.kubernetes.io/t/running-docker-in-microk8s-kubernetes-container/23362>\
**Category:** microk8s\
**Created:** [March 8, 2023, 7:21am UTC](https://discuss.kubernetes.io/t/running-docker-in-microk8s-kubernetes-container/23362 "2023-03-08T07:21:06Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![onknows](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/onknows/32/11998_2.png) [@onknows](https://discuss.kubernetes.io/u/onknows)\
**Post date:** [March 8, 2023, 7:21am UTC](https://discuss.kubernetes.io/t/running-docker-in-microk8s-kubernetes-container/23362/1 "2023-03-08T07:21:06Z")

</div>

I have MicroK8s cluster node with Gitlab Runner container. I can delegate Gitlab pipeline steps to this container. This works fine but I also want to build and run Docker images in this container. When I try for example command like below:

```auto
docker run --rm -v $(pwd)/test/:/test --ipc=host --user pwuser registry.gitlab.com/c2platform/docker/robot:latest bash -c "robot --outputdir /tmp/output /test"`

```

This fails with message

> Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?

 ![image](https://us1.discourse-cdn.com/flex016/uploads/kubernetes/original/2X/e/e09f9f33cf3b2864fdee14af9ce73791fbc5ea8e.png)

So the log shows that the Gitlab Runner pod is using Kubernetes executor.

Is it possible to use Docker inside a Kubernetes pod?

With Docker in Docker I noticed that sometimes a mount is used

```bash
docker run --name whater -it --rm -v /var/run/docker.sock:/var/run/docker.sock ubuntu:latest bash

```

Inside the container I can then run

```bash
apt update && apt install docker.io
docker ps
docker run --name whatever2 -it --rm ubuntu:latest bash # works

```

So in order to enable this, I could install `docker.io` on MicroK8s worker nodes? Does this make sense?

---

<div class="post-metadata">

**Author:** ![protosam](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/protosam/32/7732_2.png) [@protosam](https://discuss.kubernetes.io/u/protosam)\
**Post date:** [March 9, 2023, 7:07am UTC](https://discuss.kubernetes.io/t/running-docker-in-microk8s-kubernetes-container/23362/2 "2023-03-09T07:07:42Z")

</div>

A Gitlab runner that supports doing the work as in-cluster jobs is going to be better. This document seems to be talking about something like that: [Kubernetes executor | GitLab](https://docs.gitlab.com/runner/executors/kubernetes.html)

As a comparison, [drone.io](http://drone.io) has a Kubernetes provider that does this and I wish the forked OSS project Woodpecker-CI had it.

If having this legacy runner architecture work is absolutely required, you can build a pod that uses the [docker:dind](https://hub.docker.com/_/docker). You can expose the socket between containers in the pod. The same thing can be done with podman as well, it can expose a docker compatible socker iirc.

---

<div class="post-metadata">

**Author:** ![onknows](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/onknows/32/11998_2.png) [@onknows](https://discuss.kubernetes.io/u/onknows)\
**Post date:** [March 13, 2023, 5:15am UTC](https://discuss.kubernetes.io/t/running-docker-in-microk8s-kubernetes-container/23362/3 "2023-03-13T05:15:42Z")

</div>

I managed to create two working examples:

1. Example [gitlab-docker-build](https://gitlab.com/c2platform/examples/kubernetes/gitlab-docker-build) creates builds and releases images.
2. Example [gitlab-robot](https://gitlab.com/c2platform/examples/kubernetes/gitlab-robot) runs Robot Framework tests using a Robot container. So this is also a “dind” approach.

In addition to documentation linked by @protosam I can recommend [Docker-in-Docker with TLS enabled in Kubernetes](https://docs.gitlab.com/ee/ci/docker/using_docker_build.html#docker-in-docker-with-tls-enabled-in-kubernetes)
