从GitLab拉取私有镜像时持续报错'requested access to the resource is denied'
GitLab私有容器镜像仓库外部拉取失败:requested access to the resource is denied
问题背景
在gitlab.com免费层级拥有带容器镜像仓库的私有GitLab仓库,已通过gitlab-ci成功构建并推送Docker镜像,但本地Docker/Podman无法从外部拉取,报错requested access to the resource is denied。Docker和Podman均出现相同问题,已尝试使用带read-registry权限的项目令牌、个人账号密码,在Linux和macOS多台机器测试过。
已执行操作
登录操作
user@machine:~$ podman login registry.gitlab.com Authenticating with existing credentials for registry.gitlab.com Existing credentials are valid. Already logged in to registry.gitlab.com
拉取操作(带debug日志)
user@machine:~$ podman pull --log-level=debug registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245 INFO[0000] podman filtering at log level debug DEBU[0000] Called pull.PersistentPreRunE(podman pull --log-level=debug registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245) DEBU[0000] Using conmon: "/usr/bin/conmon" INFO[0000] Using sqlite as database backend DEBU[0000] systemd-logind: Unknown object '/'. DEBU[0000] Using graph driver overlay DEBU[0000] Using graph root /home/user/.local/share/containers/storage DEBU[0000] Using run root /run/user/1000/containers DEBU[0000] Using static dir /home/user/.local/share/containers/storage/libpod DEBU[0000] Using tmp dir /run/user/1000/libpod/tmp DEBU[0000] Using volume path /home/user/.local/share/containers/storage/volumes DEBU[0000] Using transient store: false DEBU[0000] [graphdriver] trying provided driver "overlay" DEBU[0000] Cached value indicated that overlay is supported DEBU[0000] Cached value indicated that overlay is supported DEBU[0000] Cached value indicated that metacopy is not being used DEBU[0000] Cached value indicated that native-diff is usable DEBU[0000] backingFs=extfs, projectQuotaSupported=false, useNativeDiff=true, usingMetacopy=false DEBU[0000] Initializing event backend journald DEBU[0000] Configured OCI runtime crun-wasm initialization failed: no valid executable found for OCI runtime crun-wasm: invalid argument DEBU[0000] Configured OCI runtime krun initialization failed: no valid executable found for OCI runtime krun: invalid argument DEBU[0000] Configured OCI runtime runc initialization failed: no valid executable found for OCI runtime runc: invalid argument DEBU[0000] Configured OCI runtime runj initialization failed: no valid executable found for OCI runtime runj: invalid argument DEBU[0000] Configured OCI runtime kata initialization failed: no valid executable found for OCI runtime kata: invalid argument DEBU[0000] Configured OCI runtime runsc initialization failed: no valid executable found for OCI runtime runsc: invalid argument DEBU[0000] Configured OCI runtime youki initialization failed: no valid executable found for OCI runtime youki: invalid argument DEBU[0000] Configured OCI runtime ocijail initialization failed: no valid executable found for OCI runtime ocijail: invalid argument DEBU[0000] Using OCI runtime "/usr/bin/crun" INFO[0000] Setting parallel job count to 7 DEBU[0000] Pulling image registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245 (policy: always) DEBU[0000] Looking up image "registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245" in local containers storage DEBU[0000] Normalized platform linux/amd64 to {amd64 linux [] } DEBU[0000] Trying "registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245" ... DEBU[0000] reference "[overlay@/home/user/.local/share/containers/storage+/run/user/1000/containers]registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245" does not resolve to an image ID DEBU[0000] Trying "registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245" ... DEBU[0000] reference "[overlay@/home/user/.local/share/containers/storage+/run/user/1000/containers]registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245" does not resolve to an image ID DEBU[0000] Trying "registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245" ... DEBU[0000] Loading registries configuration "/etc/containers/registries.conf" DEBU[0000] Loading registries configuration "/etc/containers/registries.conf.d/shortnames.conf" DEBU[0000] Normalized platform linux/amd64 to {amd64 linux [] } DEBU[0000] Attempting to pull candidate registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245 for registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245 DEBU[0000] parsed reference into "[overlay@/home/user/.local/share/containers/storage+/run/user/1000/containers]registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245" Trying to pull registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245... DEBU[0000] Copying source image //registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245 to destination image [overlay@/home/user/.local/share/containers/storage+/run/user/1000/containers]registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245 DEBU[0000] Using registries.d directory /etc/containers/registries.d DEBU[0000] Trying to access "registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245" DEBU[0000] No credentials matching registry.gitlab.com/user.name/myapp/myapp-server found in /run/user/1000/containers/auth.json DEBU[0000] Found credentials for registry.gitlab.com/user.name/myapp/myapp-server in credential helper containers-auth.json in file /home/user/.config/containers/auth.json DEBU[0000] No signature storage configuration found for registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245, using built-in default file:///home/user/.local/share/containers/sigstore DEBU[0000] Looking for TLS certificates and private keys in /etc/docker/certs.d/registry.gitlab.com DEBU[0000] GET https://registry.gitlab.com/v2/ DEBU[0000] Ping https://registry.gitlab.com/v2/ status 401 DEBU[0000] GET https://gitlab.com/jwt/auth?account=user.name&scope=repository%3Auser.name%2Fmyapp%2Fmyapp-server%3Apull&service=container_registry DEBU[0000] Increasing token expiration to: 60 seconds DEBU[0000] GET https://registry.gitlab.com/v2/user.name/myapp/myapp-server/manifests/0.5.1245 DEBU[0001] Detected insufficient_scope error, will retry request with updated scope DEBU[0001] GET https://gitlab.com/jwt/auth?account=user.name&scope=repository%3Auser.name%2Fmyapp%2Fmyapp-server%3Apull&scope=repository%3Auser.name%2Fmyapp%2Fmyapp-server%3Apull&service=container_registry DEBU[0001] Increasing token expiration to: 60 seconds DEBU[0001] GET https://registry.gitlab.com/v2/user.name/myapp/myapp-server/manifests/0.5.1245 DEBU[0001] Content-Type from manifest GET is "application/json" DEBU[0001] Discarding non-primary errors: DEBU[0001] unauthorized: authentication required DEBU[0001] Accessing "registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245" failed: reading manifest 0.5.1245 in registry.gitlab.com/user.name/myapp/myapp-server: requested access to the resource is denied DEBU[0001] Error pulling candidate registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245: initializing source docker://registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245: reading manifest 0.5.1245 in registry.gitlab.com/user.name/myapp/myapp-server: requested access to the resource is denied Error: initializing source docker://registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245: reading manifest 0.5.1245 in registry.gitlab.com/user.name/myapp/myapp-server: requested access to the resource is denied DEBU[0001] Shutting down engines
容器镜像仓库条目截图

排查与解决方案
1. 确认镜像路径正确性
从截图看,镜像路径与拉取命令中的路径一致,这部分无问题。
2. 检查令牌/账号权限
- 项目令牌需确保勾选
read_registry权限,且关联角色(如Reporter)对项目有访问权限 - 个人账号需是项目成员,且拥有至少Reporter权限(私有仓库默认Guest权限无法拉取镜像)
3. 清理旧凭证重新登录
本地可能缓存无效凭证,执行以下操作:
# Podman清理并重新登录 podman logout registry.gitlab.com podman login registry.gitlab.com # Docker清理并重新登录 docker logout registry.gitlab.com docker login registry.gitlab.com
4. 检查GitLab仓库设置
进入项目设置 > 仓库 > 容器镜像仓库,确认:
- 仓库状态为启用
- 未设置IP或用户组访问限制
5. 手动验证凭证有效性
用curl测试令牌是否能获取镜像manifest:
# 替换<TOKEN>为你的项目令牌或个人访问令牌 curl --header "Authorization: Bearer <TOKEN>" https://registry.gitlab.com/v2/user.name/myapp/myapp-server/manifests/0.5.1245
返回403说明权限不足;返回200说明凭证有效,问题出在本地容器工具配置。
6. 检查容器工具配置
- 确认
registries.conf(Podman)或daemon.json(Docker)无registry.gitlab.com的特殊配置 - Podman用户可尝试删除
~/.config/containers/auth.json后重新登录
内容的提问来源于stack exchange,提问作者Sebastian
相关产品推荐
相关产品推荐

