You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

通过Docker从测试服务器登录GitLab容器注册表遇ACME权限问题

Docker登录自托管GitLab容器注册表失败:ACME Access Only 解决方法

问题概述

测试服务器通过VPN连接自托管GitLab(16.9版本),尝试HTTP方式登录GitLab容器注册表时触发错误:

Error response from daemon: Get "http://dsgitlab-registry.directservices.local:5050/v2/": denied: 
<!DOCTYPE html><html><head>
<title>ACME Access Only</title>
</head>
<body>ACME Access Only</body>
</html>

但curl http://dsgitlab-registry.directservices.local:5050可正常访问,且已配置Docker的insecure-registries和GitLab的registry_external_url。

排查与解决步骤

1. 验证GitLab注册表端点的本地可用性

在GitLab服务器上直接访问注册表的v2端点,确认是否被本地代理拦截:

curl http://localhost:5050/v2/
  • 正常预期:返回{"errors":[{"code":"UNAUTHORIZED","message":"authentication required","detail":null}]}(未授权的标准响应)
  • 若仍返回ACME页面,说明GitLab自带Nginx或第三方反向代理配置有误,需检查代理规则,确保/v2/路径未被ACME挑战规则误拦截。

2. 完善GitLab注册表配置

确保GitLab的/etc/gitlab/gitlab.rb中启用容器注册表并完成配置重载:

  1. 添加或确认以下配置项:
    registry_external_url 'http://dsgitlab-registry.directservices.local:5050'
    registry['enable'] = true
    registry_nginx['enable'] = true
    
  2. 执行配置重载与服务重启:
    gitlab-ctl reconfigure
    gitlab-ctl restart registry
    

3. 确保Docker客户端配置生效

验证测试服务器的Docker daemon配置已正确加载:

  1. 确认/etc/docker/daemon.json配置无误:
    {
      "insecure-registries" : [ "dsgitlab-registry.directservices.local:5050" ]
    }
    
  2. 重启Docker服务:
    systemctl restart docker
    
  3. 尝试用GitLab服务器IP代替域名登录,排除DNS解析问题:
    docker login --username xxx --password xxx http://<GitLab服务器IP>:5050
    

4. 排查VPN/防火墙拦截规则

因测试服务器通过VPN连接,需检查:

  • VPN设备是否对/v2/路径的请求做了拦截或重定向
  • 防火墙规则是否允许测试服务器访问GitLab服务器5050端口的所有HTTP请求(而非仅根路径)
  • 中间是否存在透明代理篡改了/v2/端点的响应

内容的提问来源于stack exchange,提问作者Manuel Gnerlich

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.21 07:12:14