Docker构建报错:无法解析主机名,CentOS镜像适配方案求助
问题描述
此前由他人配置的Docker镜像一直运行正常,清理卷空间后重新构建时出现报错。构建过程中执行Dockerfile中的RUN dnf --disablerepo '*' --enablerepo=extras swap centos-linux-repos centos-stream-repos -y && \ dnf distro-sync -y指令时,触发Curl错误(6):无法解析主机名mirrorlist.centos.org。已知CentOS已停止维护,现需修改Dockerfile解决该问题。
构建报错日志
=> [internal] load build definition from Dockerfile.python 0.0s => => transferring dockerfile: 1.70kB 0.0s => [internal] load metadata for docker.io/library/centos:latest 2.0s => [auth] library/centos:pull token for registry-1.docker.io 0.0s => [internal] load .dockerignore 0.0s => => transferring context: 2B 0.0s => CANCELED [internal] load build context 1.1s => => transferring context: 55.43MB 1.0s => CACHED [ 1/16] FROM docker.io/library/centos:latest@sha256:a2 0.0s => ERROR [ 2/16] RUN dnf --disablerepo '*' --enablerepo=extras swap centos-linux-repos centos-stream-repos -y && dnf distro-sync -y 1.1s ------ > [ 2/16] RUN dnf --disablerepo '*' --enablerepo=extras swap centos-linux-repos centos-stream-repos -y && dnf distro-sync -y: 0.949 CentOS Linux 8 - Extras 0.0 B/s | 0 B 00:00 0.949 Errors during downloading metadata for repository 'extras': 0.949 - Curl error (6): Couldn't resolve host name for http://mirrorlist.centos.org/?release=8&arch=x86_64&repo=extras&infra=container [Could not resolve host: mirrorlist.centos.org] 0.953 Error: Failed to download metadata for repo 'extras': Cannot prepare internal mirrorlist: Curl error (6): Couldn't resolve host name for http://mirrorlist.centos.org/?release=8&arch=x86_64&repo=extras&infra=container [Could not resolve host: mirrorlist.centos.org] ------ 2 warnings found (use docker --debug to expand): - SecretsUsedInArgOrEnv: Do not use ARG or ENV instructions for sensitive data (ENV "DESTINATION_KEY") (line 64) - SecretsUsedInArgOrEnv: Do not use ARG or ENV instructions for sensitive data (ENV "SOURCE_KEY") (line 62) Dockerfile.python:3 -------------------- 2 | 3 | >>> RUN dnf --disablerepo '*' --enablerepo=extras swap centos-linux-repos centos-stream-repos -y && \ 4 | >>> dnf distro-sync -y 5 | -------------------- ERROR: failed to solve: process "/bin/sh -c dnf --disablerepo '*' --enablerepo=extras swap centos-linux-repos centos-stream-repos -y && dnf distro-sync -y" did not complete successfully: exit code: 1
原Dockerfile内容
FROM centos:latest RUN dnf --disablerepo '*' --enablerepo=extras swap centos-linux-repos centos-stream-repos -y && \ dnf distro-sync -y RUN yum -y install epel-release && \ yum -y update && \ yum groupinstall "Development Tools" -y && \ yum install openssl-devel libffi-devel bzip2-devel -y RUN yum install wget -y && \ wget https://www.python.org/ftp/python/3.9.7/Python-3.9.7.tgz && \ tar xvf Python-3.9.7.tgz && \ cd Python-3.9*/ && \ ./configure --enable-optimizations && \ make altinstall RUN ln -s /usr/local/bin/python3.9 /usr/local/bin/python && \ ln -s /usr/local/bin/pip3.9 /usr/local/bin/pip3 ARG USER=centos ARG V_ENV=boto3venv ARG VOLUME=/home/${USER}/app-src USER root # RUN yum install -y epel-release # RUN yum install -y \ # python3-pip # Upgrade pip # RUN pip3 install --upgrade pip # create user RUN useradd -ms /bin/bash ${USER} USER ${USER} WORKDIR /home/${USER} # add credentials RUN mkdir -p /home/${USER}/.aws COPY aws/credentials /home/${USER}/.aws RUN pip3 install virtualenv --user # create virtual environment RUN /home/${USER}/.local/bin/virtualenv ${V_ENV} ENV PYTHONPATH=${VOLUME} # set PATH to python3, pip3 ENV PATH=/home/${USER}/${V_ENV}/bin:$PATH # install python packages using pip in the virtual environment RUN mkdir -p ${VOLUME} COPY requirements.txt ${VOLUME} COPY src/ ${VOLUME} RUN pip3 install -r ${VOLUME}/requirements.txt #RUN pip3 install --upgrade -r ${VOLUME}/requirements.txt # Run list files python ENV SOURCE_BUCKET= ENV SOURCE_KEY= ENV DESTINATION_BUCKET= ENV DESTINATION_KEY= WORKDIR ${VOLUME} ENTRYPOINT [ "python" ] CMD ["--version"]
修改方案
CentOS 8已停止官方维护,原镜像的源地址已失效,需替换为维护中的发行版镜像并调整源配置:
1. 替换基础镜像
将FROM centos:latest替换为Rocky Linux 8或AlmaLinux 8(均为CentOS兼容的替代发行版),以Rocky Linux 8为例:
FROM rockylinux:8
2. 删除失效的CentOS源切换指令
原Dockerfile中切换CentOS Stream源的指令已无意义,直接删除以下内容:
RUN dnf --disablerepo '*' --enablerepo=extras swap centos-linux-repos centos-stream-repos -y && \ dnf distro-sync -y
3. 调整包管理命令
Rocky Linux使用dnf作为默认包管理器,将原yum命令替换为dnf(两者兼容,dnf是yum的升级版本),修改后的安装步骤:
RUN dnf -y install epel-release && \ dnf -y update && \ dnf groupinstall "Development Tools" -y && \ dnf install openssl-devel libffi-devel bzip2-devel wget -y
(将单独的yum install wget合并到前面的指令中,减少镜像构建层)
4. 可选:直接使用系统预编译的Python 3.9
Rocky Linux 8的软件源中包含Python 3.9,可跳过手动编译步骤,直接安装:
RUN dnf -y install python39 python39-pip RUN ln -s /usr/bin/python3.9 /usr/local/bin/python && \ ln -s /usr/bin/pip3.9 /usr/local/bin/pip3
这会大幅缩短构建时间,避免编译过程的资源消耗。
5. 修复敏感信息警告
原Dockerfile中使用ENV存储SOURCE_KEY和DESTINATION_KEY属于敏感信息泄露风险,需改为构建时传入参数:
- 替换
ENV为ARG,构建时通过--build-arg传入:
ARG SOURCE_BUCKET= ARG SOURCE_KEY= ARG DESTINATION_BUCKET= ARG DESTINATION_KEY=
构建命令示例:
docker build --build-arg SOURCE_KEY=your_key --build-arg DESTINATION_KEY=your_dest_key -t your-image .
修改后的完整Dockerfile
FROM rockylinux:8 RUN dnf -y install epel-release && \ dnf -y update && \ dnf groupinstall "Development Tools" -y && \ dnf install openssl-devel libffi-devel bzip2-devel wget -y # 可选:使用系统预编译Python3.9,替换手动编译步骤 # RUN dnf -y install python39 python39-pip # RUN ln -s /usr/bin/python3.9 /usr/local/bin/python && \ # ln -s /usr/bin/pip3.9 /usr/local/bin/pip3 # 保留原手动编译步骤(如需特定编译参数) RUN wget https://www.python.org/ftp/python/3.9.7/Python-3.9.7.tgz && \ tar xvf Python-3.9.7.tgz && \ cd Python-3.9*/ && \ ./configure --enable-optimizations && \ make altinstall RUN ln -s /usr/local/bin/python3.9 /usr/local/bin/python && \ ln -s /usr/local/bin/pip3.9 /usr/local/bin/pip3 ARG USER=centos ARG V_ENV=boto3venv ARG VOLUME=/home/${USER}/app-src USER root RUN useradd -ms /bin/bash ${USER} USER ${USER} WORKDIR /home/${USER} # add credentials RUN mkdir -p /home/${USER}/.aws COPY aws/credentials /home/${USER}/.aws RUN pip3 install virtualenv --user # create virtual environment RUN /home/${USER}/.local/bin/virtualenv ${V_ENV} ENV PYTHONPATH=${VOLUME} # set PATH to python3, pip3 ENV PATH=/home/${USER}/${V_ENV}/bin:$PATH # install python packages using pip in the virtual environment RUN mkdir -p ${VOLUME} COPY requirements.txt ${VOLUME} COPY src/ ${VOLUME} RUN pip3 install -r ${VOLUME}/requirements.txt # 使用ARG存储敏感信息,构建时传入 ARG SOURCE_BUCKET= ARG SOURCE_KEY= ARG DESTINATION_BUCKET= ARG DESTINATION_KEY= WORKDIR ${VOLUME} ENTRYPOINT [ "python" ] CMD ["--version"]
内容的提问来源于stack exchange,提问作者user1769197

