Tekton与Buildpack连接自签名证书本地Docker Registry遭遇x509证书信任问题解决方案咨询
The x509: certificate signed by unknown authority error occurs because neither the Docker client nor the system CA store in the Buildpacks task container trusts your self-signed registry certificate. Here's a step-by-step fix to resolve this:
Step 1: Prepare Your Registry Certificate
First, export the self-signed CA certificate from your Docker Registry. If you're running the registry with Docker, this file is typically stored in the registry's certs directory (e.g., /path/to/registry/certs/domain.crt). Save this file locally as registry.crt.
Step 2: Create Kubernetes Resources for Certificates
We'll create two Kubernetes resources to handle both system-level and Docker client certificate trust:
- A ConfigMap to store the certificate for system-wide CA trust.
- A Secret to store the certificate for Docker client configuration.
Run these commands in your terminal:
# Create ConfigMap for system CA trust kubectl create configmap registry-system-ca --from-file=host.k3d.internal.crt=registry.crt # Set up directory structure for Docker client certs mkdir -p certs.d/host.k3d.internal:5443 cp registry.crt certs.d/host.k3d.internal:5443/ca.crt # Create Secret for Docker client certificate configuration kubectl create secret generic registry-docker-certs --from-file=./certs.d
Step 3: Update Your Pipeline Configuration
Modify your pipeline.yaml to mount these resources into the Buildpacks task container, and add an init container to refresh the system CA cache:
apiVersion: tekton.dev/v1beta1 kind: Pipeline metadata: name: build-and-deploy-pipeline spec: workspaces: - name: git-source description: The git repo - name: dockerconfig-ws description: Docker configuration params: - name: gitUrl description: Git repository url tasks: - name: fetch-repository taskRef: name: git-clone workspaces: - name: output workspace: git-source params: - name: url value: "$(params.gitUrl)" - name: subdirectory value: "." - name: deleteExisting value: "true" - name: buildpacks taskRef: name: buildpacks runAfter: - fetch-repository workspaces: - name: source workspace: git-source - name: dockerconfig workspace: dockerconfig-ws params: - name: APP_IMAGE value: host.k3d.internal:5443/restservice - name: BUILDER_IMAGE value: paketobuildpacks/builder:tiny # Add pod template to mount certificates and update CA trust podTemplate: volumes: - name: registry-system-ca configMap: name: registry-system-ca - name: registry-docker-certs secret: name: registry-docker-certs initContainers: - name: update-ca-certificates image: paketobuildpacks/builder:tiny command: ["update-ca-certificates"] volumeMounts: - name: registry-system-ca mountPath: /usr/local/share/ca-certificates/host.k3d.internal.crt subPath: host.k3d.internal.crt readOnly: true containers: - name: buildpacks volumeMounts: - name: registry-system-ca mountPath: /usr/local/share/ca-certificates/host.k3d.internal.crt subPath: host.k3d.internal.crt readOnly: true - name: registry-docker-certs mountPath: /etc/docker/certs.d readOnly: true
Step 4: Re-Run Your Pipeline
Clean up any existing PipelineRuns and start a new one to apply the changes:
kubectl delete pipelinerun --all kubectl create -f pipelinerun.yaml
Why This Works
- The
registry-system-caConfigMap is mounted to the system CA directory, and the init container runsupdate-ca-certificatesto make the OS trust your registry's certificate (covering tools like curl/wget used during builds). - The
registry-docker-certsSecret is mounted to/etc/docker/certs.d, which tells the Docker client to use your CA certificate when pushing/pulling images to/fromhost.k3d.internal:5443.
内容的提问来源于stack exchange,提问作者Jordi

