通过Docker从测试服务器登录GitLab容器注册表遇ACME权限问题
Docker登录自托管GitLab容器注册表失败:ACME Access Only 解决方法
问题概述
测试服务器通过VPN连接自托管GitLab(16.9版本),尝试HTTP方式登录GitLab容器注册表时触发错误:
Error response from daemon: Get "http://dsgitlab-registry.directservices.local:5050/v2/": denied: <!DOCTYPE html><html><head> <title>ACME Access Only</title> </head> <body>ACME Access Only</body> </html>
但curl http://dsgitlab-registry.directservices.local:5050可正常访问,且已配置Docker的insecure-registries和GitLab的registry_external_url。
排查与解决步骤
1. 验证GitLab注册表端点的本地可用性
在GitLab服务器上直接访问注册表的v2端点,确认是否被本地代理拦截:
curl http://localhost:5050/v2/
- 正常预期:返回
{"errors":[{"code":"UNAUTHORIZED","message":"authentication required","detail":null}]}(未授权的标准响应) - 若仍返回ACME页面,说明GitLab自带Nginx或第三方反向代理配置有误,需检查代理规则,确保
/v2/路径未被ACME挑战规则误拦截。
2. 完善GitLab注册表配置
确保GitLab的/etc/gitlab/gitlab.rb中启用容器注册表并完成配置重载:
- 添加或确认以下配置项:
registry_external_url 'http://dsgitlab-registry.directservices.local:5050' registry['enable'] = true registry_nginx['enable'] = true - 执行配置重载与服务重启:
gitlab-ctl reconfigure gitlab-ctl restart registry
3. 确保Docker客户端配置生效
验证测试服务器的Docker daemon配置已正确加载:
- 确认
/etc/docker/daemon.json配置无误:{ "insecure-registries" : [ "dsgitlab-registry.directservices.local:5050" ] } - 重启Docker服务:
systemctl restart docker - 尝试用GitLab服务器IP代替域名登录,排除DNS解析问题:
docker login --username xxx --password xxx http://<GitLab服务器IP>:5050
4. 排查VPN/防火墙拦截规则
因测试服务器通过VPN连接,需检查:
- VPN设备是否对
/v2/路径的请求做了拦截或重定向 - 防火墙规则是否允许测试服务器访问GitLab服务器5050端口的所有HTTP请求(而非仅根路径)
- 中间是否存在透明代理篡改了
/v2/端点的响应
内容的提问来源于stack exchange,提问作者Manuel Gnerlich
相关产品推荐
相关产品推荐

