You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Tekton与Buildpack连接自签名证书本地Docker Registry遭遇x509证书信任问题解决方案咨询

Solution: Trusting Self-Signed Docker Registry CA in Tekton Buildpacks Task

The x509: certificate signed by unknown authority error occurs because neither the Docker client nor the system CA store in the Buildpacks task container trusts your self-signed registry certificate. Here's a step-by-step fix to resolve this:

Step 1: Prepare Your Registry Certificate

First, export the self-signed CA certificate from your Docker Registry. If you're running the registry with Docker, this file is typically stored in the registry's certs directory (e.g., /path/to/registry/certs/domain.crt). Save this file locally as registry.crt.

Step 2: Create Kubernetes Resources for Certificates

We'll create two Kubernetes resources to handle both system-level and Docker client certificate trust:

  1. A ConfigMap to store the certificate for system-wide CA trust.
  2. A Secret to store the certificate for Docker client configuration.

Run these commands in your terminal:

# Create ConfigMap for system CA trust
kubectl create configmap registry-system-ca --from-file=host.k3d.internal.crt=registry.crt

# Set up directory structure for Docker client certs
mkdir -p certs.d/host.k3d.internal:5443
cp registry.crt certs.d/host.k3d.internal:5443/ca.crt

# Create Secret for Docker client certificate configuration
kubectl create secret generic registry-docker-certs --from-file=./certs.d

Step 3: Update Your Pipeline Configuration

Modify your pipeline.yaml to mount these resources into the Buildpacks task container, and add an init container to refresh the system CA cache:

apiVersion: tekton.dev/v1beta1
kind: Pipeline
metadata:
  name: build-and-deploy-pipeline
spec:
  workspaces:
    - name: git-source
      description: The git repo
    - name: dockerconfig-ws
      description: Docker configuration
  params:
    - name: gitUrl
      description: Git repository url
  tasks:
    - name: fetch-repository
      taskRef:
        name: git-clone
      workspaces:
        - name: output
          workspace: git-source
      params:
        - name: url
          value: "$(params.gitUrl)"
        - name: subdirectory
          value: "."
        - name: deleteExisting
          value: "true"
    - name: buildpacks
      taskRef:
        name: buildpacks
      runAfter:
        - fetch-repository
      workspaces:
        - name: source
          workspace: git-source
        - name: dockerconfig
          workspace: dockerconfig-ws
      params:
        - name: APP_IMAGE
          value: host.k3d.internal:5443/restservice
        - name: BUILDER_IMAGE
          value: paketobuildpacks/builder:tiny
      # Add pod template to mount certificates and update CA trust
      podTemplate:
        volumes:
          - name: registry-system-ca
            configMap:
              name: registry-system-ca
          - name: registry-docker-certs
            secret:
              name: registry-docker-certs
        initContainers:
          - name: update-ca-certificates
            image: paketobuildpacks/builder:tiny
            command: ["update-ca-certificates"]
            volumeMounts:
              - name: registry-system-ca
                mountPath: /usr/local/share/ca-certificates/host.k3d.internal.crt
                subPath: host.k3d.internal.crt
                readOnly: true
        containers:
          - name: buildpacks
            volumeMounts:
              - name: registry-system-ca
                mountPath: /usr/local/share/ca-certificates/host.k3d.internal.crt
                subPath: host.k3d.internal.crt
                readOnly: true
              - name: registry-docker-certs
                mountPath: /etc/docker/certs.d
                readOnly: true

Step 4: Re-Run Your Pipeline

Clean up any existing PipelineRuns and start a new one to apply the changes:

kubectl delete pipelinerun --all
kubectl create -f pipelinerun.yaml

Why This Works

  • The registry-system-ca ConfigMap is mounted to the system CA directory, and the init container runs update-ca-certificates to make the OS trust your registry's certificate (covering tools like curl/wget used during builds).
  • The registry-docker-certs Secret is mounted to /etc/docker/certs.d, which tells the Docker client to use your CA certificate when pushing/pulling images to/from host.k3d.internal:5443.

内容的提问来源于stack exchange,提问作者Jordi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.28 20:07:50