You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GitLab CI执行docker build时出现签名无法验证错误求助

解决Debian仓库GPG密钥验证失败问题

问题根源

你使用的python:3.9-slim基础镜像基于Debian Bookworm,但镜像内置的GPG密钥已过期或缺失,导致apt-get update时无法验证仓库签名,触发报错。

修复方法

修改ci_cd/python/Dockerfile,在执行apt-get update前先安装缺失的GPG密钥:

FROM python:3.9-slim
RUN mkdir -p /home/gitlab && addgroup gitlab && useradd -d /home/gitlab -g gitlab gitlab && chown gitlab:gitlab /home/gitlab
# 安装缺失的Debian仓库GPG密钥
RUN apt-get update --allow-insecure-repositories && \
    apt-get install -y --allow-unauthenticated gnupg2 && \
    apt-key adv --keyserver keyserver.ubuntu.com --recv-keys 0E98404D386FA1D9 6ED0E7B82643E131 F8D2585B8783D481 54404762BBB6E853 BDE6D2B9216EC7A8 && \
    apt-get update && \
    apt-get install -y curl
USER gitlab
WORKDIR /home/gitlab
RUN curl -sSL https://install.python-poetry.org | python3 -
ENV PATH=/home/gitlab/.local/bin:$PATH
RUN poetry config virtualenvs.in-project true

临时应急方案(不推荐生产环境)

如果只是测试需求,可以跳过GPG验证,直接执行:

RUN apt-get update --allow-unauthenticated && apt-get install -y --allow-unauthenticated curl

优化建议

  1. 使用指定发行版的Python镜像,比如python:3.9-slim-bookworm,这类镜像通常包含最新的仓库密钥,避免类似问题。
  2. 更新GitLab CI中的Docker镜像版本,比如将docker:19.03.0和docker:19.03.0-dind替换为docker:24.0.6,提升兼容性和安全性。

内容的提问来源于stack exchange,提问作者yoyoyoyo123

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.01 00:57:16