You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker登录成功后推送私有仓库仍报access forbidden求助

Docker私有镜像仓库推送access forbidden问题排查

问题场景

本地已存在alpine镜像:

$ sudo docker images
REPOSITORY                                          TAG       IMAGE ID       CREATED      SIZE
alpine                                              3.21.2    b0c9d60fc5e3   8 days ago   7.83MB
$ 

执行docker login提示成功:

$ sudo docker login myRegistry.myDomain.com --username myUser
Password:
WARNING! Your password will be stored unencrypted in /root/.docker/config.json.
Configure a credential helper to remove this warning. See
https://docs.docker.com/engine/reference/commandline/login/#credential-stores

Login Succeeded
$

为镜像打标签:

$ sudo docker tag alpine:3.21.2 myRegistry.myDomain.com/seb_repo/alpine:3.21.2
$

推送镜像时触发权限错误:

$ sudo docker push myRegistry.myDomain.com/seb_repo/alpine:3.21.2
The push refers to repository [myRegistry.myDomain.com/seb_repo/alpine]
a0904247e36a: Preparing
denied: access forbidden
$ 

排查方向

  • 核对仓库路径权限:确认seb_repo/alpine仓库路径是否已创建,当前登录用户myUser是否拥有该仓库的写入权限。多数私有仓库要求提前创建仓库目录,或为用户分配对应仓库的推送权限。
  • 重新验证登录凭证:虽然显示登录成功,但可能存在凭证过期、后台权限变更的情况。执行sudo docker logout myRegistry.myDomain.com后重新登录,再尝试推送。
  • 检查镜像标签格式:确认标签中的仓库地址myRegistry.myDomain.com无拼写错误,部分私有仓库对路径大小写敏感,需保证仓库名称、路径的大小写与后台配置一致。
  • 排查私有仓库配置:若为自行搭建的私有仓库(如Harbor、Docker Registry),需确认仓库是否开启推送权限、是否存在镜像上传限制(如存储空间不足、大小限制),以及仓库服务是否正常运行。
  • 验证网络连通性:确保本地机器可正常访问私有仓库地址,未被防火墙、代理拦截请求。可通过curl -u myUser:<password> https://myRegistry.myDomain.com/v2/测试仓库API的连通性,查看是否能正常返回信息。
  • 确认用户权限范围:检查myUser是否为seb_repo仓库的所有者,或被加入拥有推送权限的用户组。部分私有仓库按仓库粒度分配权限,即使登录成功,无对应仓库权限仍会被拒绝。

内容的提问来源于stack exchange,提问作者SebMa

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 21:42:02