拉取/安装Bitnami PostgreSQL Helm Chart时无法获取凭证
拉取Bitnami PostgreSQL OCI Helm Chart时提示无法获取凭证
错误现象
执行拉取命令时持续报错:
helm pull --debug oci://registry-1.docker.io/bitnamicharts/postgresql
错误输出:
Error: GET "https://registry-1.docker.io/v2/bitnamicharts/postgresql/tags/list": unable to retrieve credentials helm.go:86: 2025-01-03 12:00:09.845663145 -0500 EST m=+1.353337835 [debug] GET "https://registry-1.docker.io/v2/bitnamicharts/postgresql/tags/list": unable to retrieve credentials
已做操作
- 用个人访问令牌(PAT)成功登录Docker:
# docker login registry-1.docker.io Username: pgardella Password: Login Succeeded - 完成Helm仓库登录:
# helm registry login registry-1.docker.io Username: pgardella Password: Login Succeeded - 可正常安装非OCI格式Chart,但测试Bitnami Tomcat的OCI Chart时出现相同错误。
- 尝试替换
~/.docker/config.json和~/.config/helm/registry/config.json为空白文件,问题依旧。
注:操作是
helm pull/helm install,并非helm push,目标仓库为公开仓库。
环境信息
- Helm版本:
version.BuildInfo{Version:"v3.16.3", GitCommit:"cfd07493f46efc9debd9cc1b02a0961186df7fdf", GitTreeState:"clean", GoVersion:"go1.22.7"} - Kubectl版本:
Client Version: v1.32.0 Kustomize Version: v5.5.0 Server Version: v1.31.4+k3s1 - 云平台/环境:
k3s - 服务器信息:amd64架构的
Ubuntu 24.04.1 LTS
配置文件内容
~/.config/helm/registry/config.json:{ "auths": { "https://index.docker.io/v1/": {}, "https://registry-1.docker.io/v1/": {} }, "credsStore": "pass" }~/.docker/config.json:{ "auths": { "https://index.docker.io/v1/": {}, "https://index.docker.io/v1/access-token": {}, "https://index.docker.io/v1/refresh-token": {}, "registry-1.docker.io": {} }, "credsStore": "pass", "currentContext": "default" }
解决方法
1. 禁用凭证存储,明文保存凭证
当前配置使用credsStore: pass,Helm可能无法正确读取凭证。按以下步骤操作:
- 备份
~/.docker/config.json和~/.config/helm/registry/config.json - 删除两个文件中的
"credsStore": "pass"行 - 重新执行Docker和Helm登录:
docker login registry-1.docker.io helm registry login registry-1.docker.io
登录后配置文件会生成明文auth字段,不再依赖外部存储。
2. 直接指定版本拉取
错误触发于请求标签列表,若已知目标版本,可直接指定版本跳过标签查询:
helm pull oci://registry-1.docker.io/bitnamicharts/postgresql --version 16.2.0
(替换为实际需要的版本号)
3. 重置Helm凭证配置
删除Helm的registry配置文件后重新登录,确保凭证同步:
rm ~/.config/helm/registry/config.json helm registry login registry-1.docker.io
4. 检查密钥环状态(若坚持用pass)
确保pass已正确初始化,当前用户可访问密钥环:
pass init <你的GPG密钥ID>
若未初始化过,需先创建GPG密钥再执行初始化。
内容的提问来源于stack exchange,提问作者Patrick Gardella
相关产品推荐
相关产品推荐

