You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ArgoCD Image Updater连接Docker Registry遇未知权威证书签名错误

解决ArgoCD Image Updater访问DockerHub时的x509证书错误

问题场景

搭建ArgoCD Image Updater镜像更新流程时,出现证书验证失败错误,日志输出:

time="2023-12-16T10:10:27Z" level=error msg="Could not get tags from registry: Get \"https://registry-1.docker.io/v2/\": x509: certificate signed by unknown authority" alias=img application=argo-image-updater2-app image_name=ghalamif/imageupdater image_tag=v0.1.0 registry=
time="2023-12-16T10:10:27Z" level=info msg="Processing results: applications=1 images_considered=1 images_skipped=0 images_updated=0 errors=1"

DockerHub仓库为公开状态,对应的Application配置如下:

apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
  name: argo-image-updater2-app
  namespace: argocd
  finalizers: 
    - resources-finalizer.argocd.argoproj.io
  annotations:
    argocd-image-updater.argoproj.io/image-list: img=ghalamif/imageupdater:~v0.1
    argocd-image-updater.argoproj.io/write-back-method: git 
    argocd-image-updater.argoproj.io/git-branch: main
spec:
  project: default
  source:
    repoURL: https://github.com/ghalamif/prfaps.git
    targetRevision: HEAD
    path: argo-image-updater/image-updater
    helm: 
      valueFiles:
        - values.yaml
  destination: 
    server: https://kubernetes.default.svc
    namespace: argo-image-updater2-app

  syncPolicy:
    syncOptions:
      - CreateNamespace=true

    automated:
      selfHeal: true
      prune: true

解决方法

1. 挂载主机根证书到Image Updater容器

错误核心是容器内缺少DockerHub证书的签发根证书(DockerHub使用Let's Encrypt证书),可以通过挂载主机系统的根证书目录解决:

  • 编辑Image Updater的Deployment:
    kubectl edit deployment argocd-image-updater -n argocd
    
  • 在容器的volumeMounts中添加挂载配置:
    spec:
      template:
        spec:
          containers:
          - name: argocd-image-updater
            volumeMounts:
            - name: ca-certs
              mountPath: /etc/ssl/certs
              readOnly: true
          volumes:
          - name: ca-certs
            hostPath:
              path: /etc/ssl/certs
              type: Directory
    
  • 保存后Deployment会自动重启容器,使用主机的完整根证书池。

2. 临时跳过证书验证(仅测试环境可用)

如果是测试场景,可以临时禁用TLS证书验证:

  • 编辑Image Updater的ConfigMap:
    kubectl edit configmap argocd-image-updater-config -n argocd
    
  • 添加DockerHub的不安全验证配置:
    data:
      registries.conf: |
        registries:
        - name: docker.io
          api_url: https://registry-1.docker.io
          tls:
            insecure_skip_verify: true
    
  • 重启Deployment使配置生效:
    kubectl rollout restart deployment argocd-image-updater -n argocd
    

3. 修复集群节点的根证书

如果集群节点本身缺少必要的根证书,需要在每个节点上安装更新:

  • Ubuntu/Debian系统:
    sudo apt update && sudo apt install -y ca-certificates
    sudo update-ca-certificates
    
  • RHEL/CentOS系统:
    sudo yum install -y ca-certificates
    sudo update-ca-trust extract
    

内容的提问来源于stack exchange,提问作者Farzan Ghalami

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.04 03:00:18