构建自定义Cloud Shell容器时遭遇GPG签名错误求助
问题描述
我参考官方文档构建自定义Cloud Shell容器,Dockerfile内容如下:
FROM gcr.io/cloudshell-images/cloudshell:latest RUN sudo apt -q update RUN sudo apt -q install zsh virtualenvwrapper zsh-syntax-highlighting ttf-ancient-fonts fonts-powerline -y
执行cloudshell env build-local命令时,在apt -q update阶段出现密钥相关错误,部分错误日志如下:
=> ERROR [2/3] RUN sudo apt -q update 12.1s ------ > [2/3] RUN sudo apt -q update: 0.706 0.706 WARNING: apt does not have a stable CLI interface. Use with caution in scripts. 0.707 0.995 Get:1 http://deb.debian.org/debian bullseye InRelease [116 kB] 2.453 Get:23 http://deb.debian.org/debian bullseye-updates/main amd64 Packages T-2023-12-29-1403.39-F-2023-12-11-2008.48.pdiff [1914 B] 2.622 Err:6 https://cli.github.com/packages bullseye InRelease 2.622 The following signatures were invalid: EXPKEYSIG 23F3D4EA75716059 GitHub CLI <opensource+cli@github.com> 3.091 Err:8 https://packages.sury.org/php bullseye InRelease 3.091 The following signatures were invalid: EXPKEYSIG B188E2B695BD4743 DEB.SURY.ORG Automatic Signing Key <deb@sury.org> 3.556 Err:10 https://repo.mysql.com/apt/debian bullseye InRelease 3.556 The following signatures couldn't be verified because the public key is not available: NO_PUBKEY B7B3B788A8D3785C 5.662 E: Repository 'https://packages.cloud.google.com/apt gcsfuse-bullseye InRelease' changed its 'Origin' value from 'namespaces/gcs-fuse-prod/repositories/gcsfuse-bullseye' to 'gcsfuse-bullseye' 5.662 E: Repository 'https://packages.cloud.google.com/apt gcsfuse-bullseye InRelease' changed its 'Label' value from 'namespaces/gcs-fuse-prod/repositories/gcsfuse-bullseye' to 'gcsfuse-bullseye' ------ Dockerfile:3 -------------------- 1 | FROM gcr.io/cloudshell-images/cloudshell:latest 2 | 3 | >>> RUN sudo apt -q update 4 | RUN sudo apt -q install zsh virtualenvwrapper zsh-syntax-highlighting ttf-ancient-fonts fonts-powerline -y 5 | -------------------- ERROR: failed to solve: process "/bin/sh -c sudo apt -q update" did not complete successfully: exit code: 100
已搜索到2022年有类似GitHub CLI密钥过期及Ubuntu相关问题,但未找到针对Cloud Shell镜像的解决方案。查看Artifact Registry,该镜像最近11天有更新(创建于2023年)。求解决思路。
解决思路与方案
1. 手动修复过期/缺失的GPG密钥
在Dockerfile中添加修复密钥的步骤,针对错误中提到的三个问题源:
FROM gcr.io/cloudshell-images/cloudshell:latest # 修复GitHub CLI过期密钥 RUN sudo apt-key adv --keyserver keyserver.ubuntu.com --recv-keys 23F3D4EA75716059 # 修复DEB.SURY.ORG过期密钥 RUN sudo apt-key adv --keyserver keyserver.ubuntu.com --recv-keys B188E2B695BD4743 # 添加MySQL缺失的公钥 RUN sudo apt-key adv --keyserver keyserver.ubuntu.com --recv-keys B7B3B788A8D3785C # 忽略仓库Origin/Label变更警告 RUN sudo apt -q update --allow-releaseinfo-change RUN sudo apt -q install zsh virtualenvwrapper zsh-syntax-highlighting ttf-ancient-fonts fonts-powerline -y
2. 移除不需要的第三方仓库
如果你不需要GitHub CLI、PHP(sury源)或MySQL相关包,可以直接删除这些仓库配置,减少错误来源:
FROM gcr.io/cloudshell-images/cloudshell:latest # 删除不需要的第三方仓库配置文件 RUN sudo rm -f /etc/apt/sources.list.d/*.list \ && sudo rm -f /etc/apt/sources.list.d/*.sources RUN sudo apt -q update RUN sudo apt -q install zsh virtualenvwrapper zsh-syntax-highlighting ttf-ancient-fonts fonts-powerline -y
3. 强制拉取最新基础镜像
即使镜像显示最近更新,本地可能缓存了旧版本,先手动拉取最新镜像再构建:
docker pull gcr.io/cloudshell-images/cloudshell:latest
之后重新执行cloudshell env build-local
4. 临时忽略签名错误(不推荐,仅应急)
如果以上方法都无效,可临时在apt update中添加忽略参数,但会降低安全性:
RUN sudo apt -q update --allow-unauthenticated
内容的提问来源于stack exchange,提问作者Taoism
相关产品推荐
相关产品推荐

