[Service]
Type=notify
ExecStartPost=/sbin/iptables -I FORWARD -s 0.0.0.0/0 -j ACCEPT
ExecStart=/usr/bin/dockerd -H fd:// --containerd=/run/containerd/containerd.sock --insecure-registry
ExecReload=/bin/kill -s HUP $MAINPID
TimeoutSec=0
RestartSec=2
Restart=always
StartLimitBurst=3
StartLimitInterval=60s
TasksMax=infinity
Delegate=yes
KillMode=process
Environment="HTTP_PROXY=192.168.224.43:8118"
"HTTPS_PROXY=192.168.224.43:8118"
"NO_PROXY=localhost,127.0.0.1,docker-registry.net.cn,harbor.com"
{
"exec-opts": ["native.cgroupdriver=systemd"],
"log-driver": "json-file",
"log-opts": {
"max-size": "100m","max-file":"2"
},
"storage-driver": "overlay2",
"storage-opts": [
"overlay2.override_kernel_check=true"
],
"live-restore":true
#"metrics-addr" : "127.0.0.1:9323",
# "experimental" : true
}