You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

构建自定义Cloud Shell容器时遭遇GPG签名错误求助

问题描述

我参考官方文档构建自定义Cloud Shell容器,Dockerfile内容如下:

FROM gcr.io/cloudshell-images/cloudshell:latest

RUN sudo apt -q update
RUN sudo apt -q install zsh virtualenvwrapper zsh-syntax-highlighting ttf-ancient-fonts fonts-powerline -y

执行cloudshell env build-local命令时,在apt -q update阶段出现密钥相关错误,部分错误日志如下:

=> ERROR [2/3] RUN sudo apt -q update                                                                                                                                                           12.1s
------
 > [2/3] RUN sudo apt -q update:
0.706 
0.706 WARNING: apt does not have a stable CLI interface. Use with caution in scripts.
0.707 
0.995 Get:1 http://deb.debian.org/debian bullseye InRelease [116 kB]
2.453 Get:23 http://deb.debian.org/debian bullseye-updates/main amd64 Packages T-2023-12-29-1403.39-F-2023-12-11-2008.48.pdiff [1914 B]
2.622 Err:6 https://cli.github.com/packages bullseye InRelease
2.622   The following signatures were invalid: EXPKEYSIG 23F3D4EA75716059 GitHub CLI <opensource+cli@github.com>
3.091 Err:8 https://packages.sury.org/php bullseye InRelease
3.091   The following signatures were invalid: EXPKEYSIG B188E2B695BD4743 DEB.SURY.ORG Automatic Signing Key <deb@sury.org>
3.556 Err:10 https://repo.mysql.com/apt/debian bullseye InRelease
3.556   The following signatures couldn't be verified because the public key is not available: NO_PUBKEY B7B3B788A8D3785C
5.662 E: Repository 'https://packages.cloud.google.com/apt gcsfuse-bullseye InRelease' changed its 'Origin' value from 'namespaces/gcs-fuse-prod/repositories/gcsfuse-bullseye' to 'gcsfuse-bullseye'
5.662 E: Repository 'https://packages.cloud.google.com/apt gcsfuse-bullseye InRelease' changed its 'Label' value from 'namespaces/gcs-fuse-prod/repositories/gcsfuse-bullseye' to 'gcsfuse-bullseye'
------
Dockerfile:3
--------------------
   1 |     FROM gcr.io/cloudshell-images/cloudshell:latest
   2 |     
   3 | >>> RUN sudo apt -q update
   4 |     RUN sudo apt -q install zsh virtualenvwrapper zsh-syntax-highlighting ttf-ancient-fonts fonts-powerline -y
   5 |     
--------------------
ERROR: failed to solve: process "/bin/sh -c sudo apt -q update" did not complete successfully: exit code: 100

已搜索到2022年有类似GitHub CLI密钥过期及Ubuntu相关问题,但未找到针对Cloud Shell镜像的解决方案。查看Artifact Registry,该镜像最近11天有更新(创建于2023年)。求解决思路。

解决思路与方案

1. 手动修复过期/缺失的GPG密钥

在Dockerfile中添加修复密钥的步骤,针对错误中提到的三个问题源:

FROM gcr.io/cloudshell-images/cloudshell:latest

# 修复GitHub CLI过期密钥
RUN sudo apt-key adv --keyserver keyserver.ubuntu.com --recv-keys 23F3D4EA75716059
# 修复DEB.SURY.ORG过期密钥
RUN sudo apt-key adv --keyserver keyserver.ubuntu.com --recv-keys B188E2B695BD4743
# 添加MySQL缺失的公钥
RUN sudo apt-key adv --keyserver keyserver.ubuntu.com --recv-keys B7B3B788A8D3785C

# 忽略仓库Origin/Label变更警告
RUN sudo apt -q update --allow-releaseinfo-change
RUN sudo apt -q install zsh virtualenvwrapper zsh-syntax-highlighting ttf-ancient-fonts fonts-powerline -y

2. 移除不需要的第三方仓库

如果你不需要GitHub CLI、PHP(sury源)或MySQL相关包,可以直接删除这些仓库配置,减少错误来源:

FROM gcr.io/cloudshell-images/cloudshell:latest

# 删除不需要的第三方仓库配置文件
RUN sudo rm -f /etc/apt/sources.list.d/*.list \
    && sudo rm -f /etc/apt/sources.list.d/*.sources

RUN sudo apt -q update
RUN sudo apt -q install zsh virtualenvwrapper zsh-syntax-highlighting ttf-ancient-fonts fonts-powerline -y

3. 强制拉取最新基础镜像

即使镜像显示最近更新,本地可能缓存了旧版本,先手动拉取最新镜像再构建:

docker pull gcr.io/cloudshell-images/cloudshell:latest

之后重新执行cloudshell env build-local

4. 临时忽略签名错误(不推荐,仅应急)

如果以上方法都无效,可临时在apt update中添加忽略参数,但会降低安全性:

RUN sudo apt -q update --allow-unauthenticated

内容的提问来源于stack exchange,提问作者Taoism

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 14:40:11