You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Kaniko构建镜像后Clair扫描失败:无法拉取fsLayers

解决Kaniko构建镜像后Clair扫描报错“Can't pull fsLayers”的问题

问题核心原因

Clair仅兼容Docker V2S2格式的镜像manifest,而Kaniko默认可能生成OCI格式镜像,或者私有仓库中的PostgreSQL基础镜像本身是OCI格式,导致扫描时无法识别文件系统层。

可行解决方案

  • 强制Kaniko生成Docker格式镜像
    修改GitLab CI的Kaniko命令,添加--format=docker参数,强制生成Docker兼容的镜像manifest:

    dbdr-publish:
        stage: publish
        extends: .rules
        image: registry.aws.site.mycompany.com:443/dx/containers/build-image:latest
        script:
          - >
            kaniko 
            --context $CI_PROJECT_DIR 
            --destination $CI_REGISTRY_IMAGE/dbdr:$DLA_TARGET 
            --dockerfile=$CI_PROJECT_DIR/Dockerfile-dbdr 
            --skip-unused-stages 
            --cache=false
            --cache-repo=""
            --format=docker
    
  • 检查并转换基础镜像格式
    用skopeo命令检查私有仓库中PostgreSQL基础镜像的manifest类型:

    skopeo inspect docker://docker.aws.site.mycompany.com:443/postgres:latest | jq '.ManifestType'
    

    如果输出为application/vnd.oci.image.manifest.v1+json,说明是OCI格式,可通过以下命令转换为Docker格式后重新推送:

    skopeo copy docker://docker.aws.site.mycompany.com:443/postgres:latest docker://docker.aws.site.mycompany.com:443/postgres:latest-docker --format docker
    

    之后Dockerfile中改用转换后的镜像作为基础镜像。

  • 验证构建后镜像的manifest格式
    镜像构建推送完成后,用skopeo确认目标镜像的manifest类型:

    skopeo inspect docker://$CI_REGISTRY_IMAGE/dbdr:$DLA_TARGET | jq '.ManifestType'
    

    预期输出应为application/vnd.docker.distribution.manifest.v2+json,确保格式符合Clair要求。

  • 清理仓库中旧镜像缓存
    如果仓库中存在同tag的旧OCI格式镜像,先删除该tag的镜像,再重新构建推送,避免Clair读取旧的manifest文件。

内容的提问来源于stack exchange,提问作者Rajath Rao - Software Engineer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 17:15:04