You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用Docker结合带证书的服务主体登录ACR并拉取镜像?

用带证书的Azure服务主体登录ACR并拉取镜像

1. 登录Azure容器注册表

先确认你已准备好:服务主体的证书文件(支持.pfx或.pem格式)、服务主体的应用ID(client ID)、ACR的登录服务器地址(格式为<registry-name>.azurecr.io)。

  • 如果你的证书是.pfx格式,先转换成Docker能识别的.pem格式:
openssl pkcs12 -in your-cert.pfx -out your-cert.pem -nodes

注:-nodes参数是让生成的私钥不加密,避免Docker登录时需要额外输入密码。

  • 执行Docker登录命令,用服务主体的client ID作为用户名,证书内容作为密码:
docker login <acr-login-server> --username <service-principal-client-id> --password-stdin < your-cert.pem

举个实际例子:

docker login mydemoacr.azurecr.io --username 12345678-1234-1234-1234-1234567890ab --password-stdin < my-sp-cert.pem

登录成功会返回Login Succeeded的提示。

2. 拉取ACR中的Docker镜像

认证通过后,直接用标准的docker pull命令拉取镜像,格式如下:

docker pull <acr-login-server>/<image-repo-name>:<tag>

示例:

docker pull mydemoacr.azurecr.io/web-app:v2

拉取完成后,用docker images命令就能看到本地已下载的镜像。

内容的提问来源于stack exchange,提问作者Алексей Иванов

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 15:42:07