You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

containerd无法从HTTP私有Registry拉取镜像问题求助

问题诊断与解决方案

1. 确认containerd配置生效

containerd v2.0.0的配置结构有调整,需确保私有仓库的HTTP兼容配置正确写入[plugins."io.containerd.grpc.v1.cri".registry.configs]区块:

[plugins."io.containerd.grpc.v1.cri".registry]
  config_path = ""

[plugins."io.containerd.grpc.v1.cri".registry.configs]
  [plugins."io.containerd.grpc.v1.cri".registry.configs."你的仓库地址:端口".tls]
    insecure = true          # 允许HTTP访问
    insecure_skip_verify = true  # 跳过证书验证(自签HTTPS场景也需开启)

替换你的仓库地址:端口为实际私有仓库地址(如192.168.3.10:5000),修改后重启服务并验证配置:

systemctl restart containerd
containerd config dump | grep -A5 -B5 "你的仓库地址:端口"

2. 修正手动拉取命令

用ctr拉取时必须指定完整镜像路径(仓库地址+镜像名+标签),否则会默认从Docker Hub拉取:

ctr -n k8s.io image pull --plain-http=true 你的仓库地址:端口/镜像名:标签

若仍提示镜像不存在,先确认仓库内确实有该镜像:

curl http://你的仓库地址:端口/v2/_catalog
curl http://你的仓库地址:端口/v2/镜像名/tags/list

3. 校验K8S镜像拉取Secret

确保Secret配置正确且Pod已引用:

  • 创建Secret命令(基于Docker认证信息):
kubectl create secret docker-registry regcred \
  --docker-server=你的仓库地址:端口 \
  --docker-username=仓库用户名 \
  --docker-password=仓库密码 \
  --docker-email=任意邮箱
  • Pod YAML中需明确指定拉取密钥:
apiVersion: v1
kind: Pod
metadata:
  name: test-pod
spec:
  containers:
  - name: test-container
    image: 你的仓库地址:端口/镜像名:标签
  imagePullSecrets:
  - name: regcred

4. 排查节点网络连通性

确认K8S节点能正常访问私有仓库:

nc -zv 你的仓库地址 端口
# 或
telnet 你的仓库地址 端口

若不通,检查节点防火墙规则、仓库服务状态或局域网路由配置。

5. 通过containerd日志定位细节

查看containerd实时日志,获取更具体的错误原因:

journalctl -u containerd -f

重点关注镜像拉取阶段的日志条目,区分是认证失败、网络阻塞还是镜像不存在问题。


内容的提问来源于stack exchange,提问作者kursk.ye

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 08:02:11