基于Tekton的Kaniko推送Nexus镜像报404错误求助
在企业内网环境中,使用Nexus作为Docker镜像仓库,基于Tekton编写流水线并采用Kaniko工具构建推送镜像,已配置好config.json认证文件,但运行流水线时遇到以下错误:
error checking push permissions -- make sure you entered the correct tag name, and that you are authenticated correctly, and try again: checking push permission for "nexus.example.com/project-name:image-tag": creating push check transport for nexus.example.com failed: GET https://nexus.example.com/v2/: unexpected status code 404 Not Found
当前配置
Volume和Kaniko的YAML配置
volumes: - name: nexus-secret secret: items: - key: .dockerconfigjson path: config.json secretName: nexus steps: - name: build-sources image: gcr.io/kaniko-project/executor:latest workingDir: /workspace/source/$(params.project-name) volumeMounts: - name: nexus-secret mountPath: /kaniko/.docker - name: kaniko-ssl mountPath: /kaniko/ssl/certs env: - name: DOCKER_CONFIG value: /kaniko/.docker command: - /kaniko/executor args: - --dockerfile=/workspace/source/$(params.project-name)/Dockerfile - --context=/workspace/source/$(params.project-name) - --destination=$(params.nexus-url)/$(params.project-name):$(params.image-tag) - --verbosity=debug
config.json文件内容
{ "auths": { "nexus.example.com": { "username": "my-username", "password": "my-password" } } }
已尝试的操作
- 确认
config.json配置正确且账号拥有Nexus推送权限 - 手动验证Nexus地址可正常访问
- 确认Kaniko配置正确且所需SSL证书已挂载
解决方案
1. 修正Nexus Docker仓库的访问路径
Nexus的Docker仓库默认不会将v2 API暴露在根域名下,必须加上仓库的具体子路径(比如你创建的Docker Hosted仓库名称为docker-hosted)。
调整Kaniko的--destination参数,补充仓库路径:
--destination=$(params.nexus-url)/repository/docker-hosted/$(params.project-name):$(params.image-tag)
同时手动访问https://nexus.example.com/repository/docker-hosted/v2/,确认返回状态码为200或401(未认证),而非404。
2. 规范config.json的认证格式
Docker标准的config.json中,认证信息需要将username:password进行Base64编码后放在auth字段,而非分开的username和password。
生成编码字符串:
echo -n "my-username:my-password" | base64
修改后的config.json:
{ "auths": { "nexus.example.com/repository/docker-hosted": { "auth": "替换为上面生成的Base64字符串" } } }
3. 验证Nexus仓库配置
- 确认Nexus中创建的是Docker Hosted类型仓库;若使用Group仓库,需确保其包含可接收推送的Hosted仓库
- 检查Nexus仓库的HTTP/HTTPS端口配置,确认v2 API已启用
4. 调试SSL证书与网络连通性
在Kaniko步骤中添加前置调试命令,验证Nexus仓库地址的连通性:
command: - sh - -c - | curl -v https://nexus.example.com/repository/docker-hosted/v2/ /kaniko/executor --dockerfile=/workspace/source/$(params.project-name)/Dockerfile --context=/workspace/source/$(params.project-name) --destination=$(params.nexus-url)/repository/docker-hosted/$(params.project-name):$(params.image-tag) --verbosity=debug
通过curl输出确认证书是否有效、地址是否可达。
5. 检查Tekton参数传递
确认$(params.nexus-url)是否包含正确的协议前缀(https://),以及所有参数是否准确传递到流水线中,避免因参数缺失导致地址错误。
内容的提问来源于stack exchange,提问作者Ömer Açık

