You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker Buildx与Gitea Actions推送至不安全镜像仓库失败求助

问题:Gitea Action推送镜像到HTTP私有仓库失败

本地搭建了Gitea,使用Gitea Runner触发Action完成Docker镜像构建与推送,但推送时出现错误,提示http: server gave HTTP response to HTTPS client。私有仓库运行在<ip>:5000,已通过curl <ip>:5000/v2/_catalog验证,开发机手动推送正常,仓库无身份验证。

当前YAML配置

name: Docker Build and Push
run-name: ${{ gitea.actor }} made changes so running Gitea actions 🚀
on: [push]

jobs:
  build-and-push:
    runs-on: ubuntu-latest
    steps:
      - name: Checkout code
        uses: actions/checkout@v3

      - name: Force Buildx to Use HTTP
        run: |
          export BUILDKIT_INLINE_CACHE=1
          export DOCKER_BUILDKIT=0
          export REGISTRY_INSECURE=1
          export BUILDKIT_NO_CLIENT_TOKEN=true

      - name: Set up Docker Buildx
        uses: docker/setup-buildx-action@v3
        with:
          driver-opts: image=moby/buildkit:latest
          buildkitd-flags: "--allow-insecure-entitlement security.insecure --allow-insecure-entitlement network.host --config /data/registries.toml"
          install: true
          network: host

      - name: Build and push
        uses: docker/build-push-action@v6
        with:
          context: .
          file: ./Dockerfile
          push: true
          tags: 192.168.50.149:5000/chartsnap:latest
          allow:
            security.insecure

错误信息

#14 exporting to image
3537#14 exporting layers
3538#14 exporting layers 16.3s done
3539#14 exporting manifest sha256:8948fc8542b65700a3714d82b5091eb2e9337a4de14b46719799845b4a6eaf91 done
3540#14 exporting config sha256:a23c9fa7b2a6227d503ffcdb62ec509204ca77da5bc0847dea191ba345ecc043 done
3541#14 exporting attestation manifest sha256:403a0f1a5d60467531884c03625a47beab332973b86af9a6faa3909f4e98fb1b done
3542#14 exporting manifest list sha256:c5d5989d0102c3baa0076a35ae18383230c812f72e4e79f2408c9e3f827f89a8 done
3543#14 pushing layers done
3544#14 ERROR: failed to push <ip>:5000/chartsnap:latest: failed to do request: Head "https://<ip>:5000/v2/chartsnap/blobs/sha256:cf688aafa57c989d0a7d9d1b11eb344d09a44b6bdeaf726af74a625841ce26e3": http: server gave HTTP response to HTTPS client
3545------
3546 > exporting to image:

解决方案

1. 在Runner节点配置Docker不安全仓库

Gitea Runner运行的节点上,修改Docker配置将私有仓库标记为不安全:

  • 编辑/etc/docker/daemon.json(不存在则创建),添加内容:
    {
      "insecure-registries": ["<ip>:5000"]
    }
    
  • 重启Docker服务:sudo systemctl restart docker

2. 修复Buildx环境变量冲突

原配置中export DOCKER_BUILDKIT=0会禁用Buildkit,和后续docker/setup-buildx-action使用冲突,修改该步骤:

- name: Configure Insecure Registry
  run: |
    export BUILDKIT_INLINE_CACHE=1
    echo "{\"insecure-registries\": [\"<ip>:5000\"]}" > ~/.docker/config.json

3. 给build-push-action指定HTTP协议

在推送步骤中明确指定仓库使用HTTP:

- name: Build and push
  uses: docker/build-push-action@v6
  with:
    context: .
    file: ./Dockerfile
    push: true
    tags: <ip>:5000/chartsnap:latest
    allow:
      - security.insecure
    registry: http://<ip>:5000

4. 修正Buildkit的registries.toml配置

如果坚持使用buildkitd-flags指定配置文件,确保/data/registries.toml存在且配置正确:

[[registry]]
  index = "<ip>:5000"
  insecure = true

内容的提问来源于stack exchange,提问作者DeadlyViper

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 06:57:38