Azure ACI无法从公共Docker Registry拉取镜像(疑似BUG)
问题现象
此前功能运行正常,当前Azure ACI无法从公共Docker Hub拉取镜像,具体表现:
- 在两个订阅(含全新订阅)分别通过Azure控制台、Terraform部署ACI,均触发相同错误
- 部署公共IP类型的ACI实例也遇到同样问题
- 本地执行
docker image pull nginx拉取镜像无异常 - 错误信息:
performing ContainerGroupsCreateOrUpdate: unexpected status 409 (409 Conflict) with error: RegistryErrorResponse: An error response is received from the docker registry 'index.docker.io'. Please retry later.
此前可正常运行的Terraform配置示例:
resource "azurerm_container_group" "forwarder" { name = "${var.app_name}-forwarder-${var.environment}" resource_group_name = var.rg-name location = var.region ip_address_type = "Private" os_type = "Linux" subnet_ids = [var.private-subnet.id] restart_policy = "Always" container { name = "${var.app_name}-forwarder-${var.environment}" image = "nginx" //Changing image doesn't make a difference cpu = 0.5 memory = 1 readiness_probe { ... } liveness_probe { ... } ports { port = local.forwarder_local_port protocol = "TCP" } } exposed_port { port = local.forwarder_local_port protocol = "TCP" } diagnostics { log_analytics { ... } } }
排查与解决方案
检查Azure区域服务健康
登录Azure门户,进入「服务健康」页面,查看西欧(eu west)区域的Container Instances服务是否存在已知故障或维护事件。使用完整镜像路径
将Terraform配置中的镜像名称改为完整路径,比如docker.io/library/nginx:latest,避免ACI在解析简写镜像时出现异常。配置Docker Hub访问凭据
Docker Hub对匿名请求有速率限制,Azure ACI的集群出口IP可能触发限流。创建Docker Hub个人访问令牌,在ACI配置中添加镜像拉取凭据:
resource "azurerm_container_group" "forwarder" { // ... 其他配置不变 container { // ... 其他配置不变 image = "nginx" image_registry_credential { username = "你的Docker Hub用户名" password = "你的Docker Hub个人访问令牌" } } }
测试其他邻近区域
临时将部署区域切换至北欧(eu north)或荷兰(eu netherlands),验证是否为西欧区域的特定问题。排查出站网络限制
虽然NSG已开放,若虚拟网络配置了Azure防火墙或应用程序网关,需确保允许出站访问index.docker.io的443端口,检查是否有网络规则拦截了ACI的镜像拉取请求。
内容的提问来源于stack exchange,提问作者Jeppe Christensen

