You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

OpenShift Pipelines 1.11任务使用本地镜像失败求助

解决OpenShift Pipelines 1.11+中使用同命名空间本地镜像的问题

问题原因分析

OpenShift Pipelines 1.11+版本(对应Tekton Pipelines 0.40+)对镜像拉取逻辑做了调整,未指定标签的镜像默认会尝试拉取latest标签,若本地镜像没有该标签,或者镜像引用方式不符合新版本要求,就会触发manifest unknown错误。

解决方案

1. 明确指定镜像标签

避免依赖默认的latest标签,在镜像引用中添加具体的标签值,修改Task的参数默认值:

params:
  - default: 'image-registry.openshift-image-registry.svc:5000/mynamespace/mytaskimage:v1'  # 替换为你的实际镜像标签
    description: image used to execute this task
    name: task-image
    type: string

2. 使用OpenShift内部镜像短名称

同命名空间内可简化镜像引用格式,减少完整域名带来的潜在问题:

  • 同命名空间直接使用:mytaskimage:v1
  • 跨命名空间使用:other-namespace/mytaskimage:v1
    修改后的Task步骤镜像引用示例:
steps:
  - command:
      - ./runscript.sh
    image: $(params.task-image)  # 参数值可设置为短名称格式
    name: run-script
    resources: {}

3. 授予Tekton服务账户镜像拉取权限

Tekton默认使用pipeline服务账户执行任务,需为该账户授予目标命名空间的镜像拉取权限:

oc policy add-role-to-user system:image-puller system:serviceaccount:mynamespace:pipeline -n mynamespace

4. 验证本地镜像存在性

确认镜像已正确推送至OpenShift内部镜像仓库:

  • 查看ImageStream(通过BuildConfig构建的镜像):
    oc get imagestreams -n mynamespace
    
  • 直接查看镜像仓库中的标签:
    skopeo list-tags docker://image-registry.openshift-image-registry.svc:5000/mynamespace/mytaskimage
    

确保输出结果中存在你要使用的镜像标签。

5. 升级Task API版本(可选)

将Task的API版本从tekton.dev/v1beta1升级为tekton.dev/v1(OpenShift Pipelines 1.11+已支持稳定版API),规避版本兼容问题:

apiVersion: tekton.dev/v1
kind: Task
metadata:
  name: my-task
  namespace: mynamespace
# 其余配置内容保持不变

内容的提问来源于stack exchange,提问作者Gas

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 16:00:08