You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在通用Kubernetes中用Radius/Bicep从私有Docker仓库带认证拉取镜像?

在通用Kubernetes集群中配置Radius拉取私有Docker镜像的方法

问题背景

已有可正常拉取私有Docker镜像的Kubernetes部署(使用imagePullSecrets关联docker-registry-secret密钥),但在通用Kubernetes集群(非Azure)中使用Radius Bicep配置时,出现Failed to pull image ... no basic auth credentials错误,需要找到Radius中对应K8s imagePullSecrets的配置方式,且目标命名空间default-my-api及默认命名空间已存在docker-registry-secret密钥。

解决方案

方法1:复用已有的Kubernetes镜像拉取密钥

Radius支持在容器资源的podTemplate字段中指定已存在的K8s镜像拉取密钥,这是和K8s imagePullSecrets等价的配置方式。示例Bicep代码:

param appName string = 'my-api'
param image string = 'private-registry.example.com/my-image:v1'

resource app 'Applications.Core/applications@2023-10-01-preview' = {
  name: appName
  location: 'global'
}

resource container 'Applications.Containers/containers@2023-10-01-preview' = {
  name: 'my-container'
  location: 'global'
  parent: app
  properties: {
    osType: 'Linux'
    containers: [
      {
        name: 'my-container'
        image: image
        resources: {
          requests: {
            cpu: '100m'
            memory: '128Mi'
          }
        }
      }
    ]
    podTemplate: {
      imagePullSecrets: [
        {
          name: 'docker-registry-secret' // 引用已存在的密钥名称
        }
      ]
    }
  }
}

注意:确保docker-registry-secret存在于Radius容器所在的default-my-api命名空间中,且密钥类型为kubernetes.io/dockerconfigjson或kubernetes.io/dockercfg。

方法2:直接在Bicep中配置私有仓库凭证

如果不想依赖已有的K8s密钥,可直接在Radius Bicep资源中定义私有仓库的认证凭证,通过registryCredentials字段配置:

param appName string = 'my-api'
param image string = 'private-registry.example.com/my-image:v1'
param registryUsername string
param registryPassword string

resource app 'Applications.Core/applications@2023-10-01-preview' = {
  name: appName
  location: 'global'
}

resource container 'Applications.Containers/containers@2023-10-01-preview' = {
  name: 'my-container'
  location: 'global'
  parent: app
  properties: {
    osType: 'Linux'
    containers: [
      {
        name: 'my-container'
        image: image
        resources: {
          requests: {
            cpu: '100m'
            memory: '128Mi'
          }
        }
      }
    ]
    registryCredentials: [
      {
        server: 'private-registry.example.com'
        username: registryUsername
        password: registryPassword
      }
    ]
  }
}

建议:敏感的用户名和密码不要硬编码,可通过Radius的秘密管理功能存储,部署时通过参数传递。

错误排查要点

  • 确认default-my-api命名空间中的docker-registry-secret类型正确,可通过kubectl get secret docker-registry-secret -n default-my-api -o yaml检查
  • 确保Radius容器资源的命名空间与密钥所在命名空间一致,跨命名空间引用密钥需要额外的权限配置
  • 使用registryCredentials时,检查私有仓库的服务器地址、用户名、密码是否准确,无拼写错误

内容的提问来源于stack exchange,提问作者hawky

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.26 07:45:20