Azure容器实例(ACI)无法从ACR拉取镜像报InaccessibleImage错误
解决Azure容器实例(ACI)无法从ACR拉取镜像的InaccessibleImage错误
ERROR: (InaccessibleImage) The image '/todoapp/91' in container group 'day10app' is not accessible.
Code: InaccessibleImage
Message: The image '/todoapp/91' in container group 'day10app' is not accessible. Please check the image and registry credential.
排查与解决步骤
1. 确认镜像路径与存在性
ACR镜像的完整拉取路径必须包含ACR登录服务器地址,格式为[ACR名称].azurecr.io/[仓库名]:[标签],而非仅/todoapp/91。
- 登录ACR验证镜像是否存在:
如果使用镜像摘要拉取,格式应为az acr login --name <你的ACR名称> # 检查仓库是否存在 az acr repository show --name <你的ACR名称> --repository todoapp # 检查标签91是否存在 az acr repository show-tags --name <你的ACR名称> --repository todoapp[ACR名称].azurecr.io/todoapp@sha256:xxxx,需确认摘要值正确。
2. 验证ACR访问权限
方式一:通过角色分配(同一订阅推荐)
给ACI的托管标识或关联的服务主体分配AcrPull角色,授予拉取镜像权限:
az role assignment create --assignee <托管标识ID/服务主体ID> --role AcrPull --scope /subscriptions/<订阅ID>/resourceGroups/<资源组>/providers/Microsoft.ContainerRegistry/registries/<ACR名称>
方式二:使用注册表凭证
确认ACR的访问密钥已启用,获取正确的用户名和密码:
az acr credential show --name <你的ACR名称>
检查ACI容器组配置中,是否正确填写了registry.loginServer、registry.username和registry.password,确保凭证无拼写错误或过期。
3. 检查ACI容器组的镜像配置
查看容器组当前的镜像配置,确认地址是否完整:
az container show --resource-group <资源组名称> --name day10app --query 'containers[0].image'
若输出仅为/todoapp/91,需修正为包含ACR登录服务器的完整镜像路径,再重新部署容器组。
内容的提问来源于stack exchange,提问作者Neetu Pal
相关产品推荐
相关产品推荐

