You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kubernetes 1.28从私有HTTP镜像仓库拉取镜像遇ErrImagePull问题

Kubernetes 1.28使用HTTP私有镜像仓库拉取镜像失败的解决方法

问题核心

你遇到的ErrImagePull错误,本质是kubelet通过CRI接口调用containerd时,containerd的CRI插件未加载/etc/containerd/certs.d下的HTTP配置;而nerdctl直接调用containerd原生API,因此能正常拉取镜像。

解决步骤

1. 启用containerd CRI插件的certs.d配置加载

编辑containerd主配置文件/etc/containerd/config.toml,确保添加或保留以下配置段:

[plugins."io.containerd.grpc.v1.cri".registry]
  config_path = "/etc/containerd/certs.d"

保存后重启containerd和kubelet使配置生效:

systemctl restart containerd
systemctl restart kubelet

2. 修正hosts.toml配置的语法错误

你的配置中plain-http应为plain_http(下划线而非横杠),同时简化冗余配置,修改后的/etc/containerd/certs.d/172.16.20.182/hosts.toml如下:

server = "http://172.16.20.182"
[host."http://172.16.20.182"]
  capabilities = ["pull", "resolve"]
  plain_http = true
  skip_verify = true
  header = {authorization = "Basic YWRtaW46c2luSDW=="}

3. 验证CRI接口的镜像拉取能力

使用crictl(kubelet配套的CRI工具)测试拉取镜像,确认配置生效:

crictl pull 172.16.20.182/k8sdemo/k8s-demo:1.0

如果拉取成功,重新部署你的Deployment:

kubectl apply -f k8s-demo.yaml

4. 确认kubelet使用正确的containerd端点

检查kubelet是否指向默认的containerd套接字:

ps aux | grep kubelet | grep containerd

输出应包含unix:///run/containerd/containerd.sock,若使用自定义端点,需确保对应containerd实例已加载certs.d配置。

5. 修复配置文件权限

确保certs.d目录及文件权限正确,containerd可正常读取:

chown -R root:root /etc/containerd/certs.d/172.16.20.182
chmod 644 /etc/containerd/certs.d/172.16.20.182/hosts.toml

内容的提问来源于stack exchange,提问作者YongGuang Huang

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 07:38:12