You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

从GitLab拉取私有镜像时持续报错'requested access to the resource is denied'

GitLab私有容器镜像仓库外部拉取失败:requested access to the resource is denied

问题背景

在gitlab.com免费层级拥有带容器镜像仓库的私有GitLab仓库,已通过gitlab-ci成功构建并推送Docker镜像,但本地Docker/Podman无法从外部拉取,报错requested access to the resource is denied。Docker和Podman均出现相同问题,已尝试使用带read-registry权限的项目令牌、个人账号密码,在Linux和macOS多台机器测试过。

已执行操作

登录操作

user@machine:~$ podman login registry.gitlab.com
Authenticating with existing credentials for registry.gitlab.com
Existing credentials are valid. Already logged in to registry.gitlab.com

拉取操作(带debug日志)

user@machine:~$ podman pull --log-level=debug registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245
INFO[0000] podman filtering at log level debug          
DEBU[0000] Called pull.PersistentPreRunE(podman pull --log-level=debug registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245) 
DEBU[0000] Using conmon: "/usr/bin/conmon"              
INFO[0000] Using sqlite as database backend             
DEBU[0000] systemd-logind: Unknown object '/'.          
DEBU[0000] Using graph driver overlay                   
DEBU[0000] Using graph root /home/user/.local/share/containers/storage 
DEBU[0000] Using run root /run/user/1000/containers     
DEBU[0000] Using static dir /home/user/.local/share/containers/storage/libpod 
DEBU[0000] Using tmp dir /run/user/1000/libpod/tmp      
DEBU[0000] Using volume path /home/user/.local/share/containers/storage/volumes 
DEBU[0000] Using transient store: false                 
DEBU[0000] [graphdriver] trying provided driver "overlay" 
DEBU[0000] Cached value indicated that overlay is supported 
DEBU[0000] Cached value indicated that overlay is supported 
DEBU[0000] Cached value indicated that metacopy is not being used 
DEBU[0000] Cached value indicated that native-diff is usable 
DEBU[0000] backingFs=extfs, projectQuotaSupported=false, useNativeDiff=true, usingMetacopy=false 
DEBU[0000] Initializing event backend journald          
DEBU[0000] Configured OCI runtime crun-wasm initialization failed: no valid executable found for OCI runtime crun-wasm: invalid argument 
DEBU[0000] Configured OCI runtime krun initialization failed: no valid executable found for OCI runtime krun: invalid argument 
DEBU[0000] Configured OCI runtime runc initialization failed: no valid executable found for OCI runtime runc: invalid argument 
DEBU[0000] Configured OCI runtime runj initialization failed: no valid executable found for OCI runtime runj: invalid argument 
DEBU[0000] Configured OCI runtime kata initialization failed: no valid executable found for OCI runtime kata: invalid argument 
DEBU[0000] Configured OCI runtime runsc initialization failed: no valid executable found for OCI runtime runsc: invalid argument 
DEBU[0000] Configured OCI runtime youki initialization failed: no valid executable found for OCI runtime youki: invalid argument 
DEBU[0000] Configured OCI runtime ocijail initialization failed: no valid executable found for OCI runtime ocijail: invalid argument 
DEBU[0000] Using OCI runtime "/usr/bin/crun"            
INFO[0000] Setting parallel job count to 7              
DEBU[0000] Pulling image registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245 (policy: always) 
DEBU[0000] Looking up image "registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245" in local containers storage 
DEBU[0000] Normalized platform linux/amd64 to {amd64 linux  [] } 
DEBU[0000] Trying "registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245" ... 
DEBU[0000] reference "[overlay@/home/user/.local/share/containers/storage+/run/user/1000/containers]registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245" does not resolve to an image ID 
DEBU[0000] Trying "registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245" ... 
DEBU[0000] reference "[overlay@/home/user/.local/share/containers/storage+/run/user/1000/containers]registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245" does not resolve to an image ID 
DEBU[0000] Trying "registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245" ... 
DEBU[0000] Loading registries configuration "/etc/containers/registries.conf" 
DEBU[0000] Loading registries configuration "/etc/containers/registries.conf.d/shortnames.conf" 
DEBU[0000] Normalized platform linux/amd64 to {amd64 linux  [] } 
DEBU[0000] Attempting to pull candidate registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245 for registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245 
DEBU[0000] parsed reference into "[overlay@/home/user/.local/share/containers/storage+/run/user/1000/containers]registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245" 
Trying to pull registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245...
DEBU[0000] Copying source image //registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245 to destination image [overlay@/home/user/.local/share/containers/storage+/run/user/1000/containers]registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245 
DEBU[0000] Using registries.d directory /etc/containers/registries.d 
DEBU[0000] Trying to access "registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245" 
DEBU[0000] No credentials matching registry.gitlab.com/user.name/myapp/myapp-server found in /run/user/1000/containers/auth.json 
DEBU[0000] Found credentials for registry.gitlab.com/user.name/myapp/myapp-server in credential helper containers-auth.json in file /home/user/.config/containers/auth.json 
DEBU[0000]  No signature storage configuration found for registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245, using built-in default file:///home/user/.local/share/containers/sigstore 
DEBU[0000] Looking for TLS certificates and private keys in /etc/docker/certs.d/registry.gitlab.com 
DEBU[0000] GET https://registry.gitlab.com/v2/          
DEBU[0000] Ping https://registry.gitlab.com/v2/ status 401 
DEBU[0000] GET https://gitlab.com/jwt/auth?account=user.name&scope=repository%3Auser.name%2Fmyapp%2Fmyapp-server%3Apull&service=container_registry 
DEBU[0000] Increasing token expiration to: 60 seconds   
DEBU[0000] GET https://registry.gitlab.com/v2/user.name/myapp/myapp-server/manifests/0.5.1245 
DEBU[0001] Detected insufficient_scope error, will retry request with updated scope 
DEBU[0001] GET https://gitlab.com/jwt/auth?account=user.name&scope=repository%3Auser.name%2Fmyapp%2Fmyapp-server%3Apull&scope=repository%3Auser.name%2Fmyapp%2Fmyapp-server%3Apull&service=container_registry 
DEBU[0001] Increasing token expiration to: 60 seconds   
DEBU[0001] GET https://registry.gitlab.com/v2/user.name/myapp/myapp-server/manifests/0.5.1245 
DEBU[0001] Content-Type from manifest GET is "application/json" 
DEBU[0001] Discarding non-primary errors:               
DEBU[0001]   unauthorized: authentication required      
DEBU[0001] Accessing "registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245" failed: reading manifest 0.5.1245 in registry.gitlab.com/user.name/myapp/myapp-server: requested access to the resource is denied 
DEBU[0001] Error pulling candidate registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245: initializing source docker://registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245: reading manifest 0.5.1245 in registry.gitlab.com/user.name/myapp/myapp-server: requested access to the resource is denied 
Error: initializing source docker://registry.gitlab.com/user.name/myapp/myapp-server:0.5.1245: reading manifest 0.5.1245 in registry.gitlab.com/user.name/myapp/myapp-server: requested access to the resource is denied
DEBU[0001] Shutting down engines 

容器镜像仓库条目截图

容器镜像仓库截图

排查与解决方案

1. 确认镜像路径正确性

从截图看,镜像路径与拉取命令中的路径一致,这部分无问题。

2. 检查令牌/账号权限

  • 项目令牌需确保勾选read_registry权限,且关联角色(如Reporter)对项目有访问权限
  • 个人账号需是项目成员,且拥有至少Reporter权限(私有仓库默认Guest权限无法拉取镜像)

3. 清理旧凭证重新登录

本地可能缓存无效凭证,执行以下操作:

# Podman清理并重新登录
podman logout registry.gitlab.com
podman login registry.gitlab.com

# Docker清理并重新登录
docker logout registry.gitlab.com
docker login registry.gitlab.com

4. 检查GitLab仓库设置

进入项目设置 > 仓库 > 容器镜像仓库,确认:

  • 仓库状态为启用
  • 未设置IP或用户组访问限制

5. 手动验证凭证有效性

用curl测试令牌是否能获取镜像manifest:

# 替换<TOKEN>为你的项目令牌或个人访问令牌
curl --header "Authorization: Bearer <TOKEN>" https://registry.gitlab.com/v2/user.name/myapp/myapp-server/manifests/0.5.1245

返回403说明权限不足;返回200说明凭证有效,问题出在本地容器工具配置。

6. 检查容器工具配置

  • 确认registries.conf(Podman)或daemon.json(Docker)无registry.gitlab.com的特殊配置
  • Podman用户可尝试删除~/.config/containers/auth.json后重新登录

内容的提问来源于stack exchange,提问作者Sebastian

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 16:52:03