You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Windows Server上VS2022构建Blazor.NET7容器报错125求助

问题:Windows Server上Blazor Web应用Docker容器化遇CTC1015错误(Exit Code 125)

错误现象

在Windows Server系统中,使用Visual Studio 2022为基于.NET 7的Blazor Web应用做Docker容器化时,运行调试触发CTC1015 Docker command failed with exit code 125错误,核心报错为:

docker: Error response from daemon: container ... encountered an error during hcsshim::System::CreateProcess: failure in a Windows system call: Access is denied. (0x5).

容器工具输出日志

1>------ Build started: Project: flow3webapp, Configuration: Debug Any CPU ------
1>Skipping analyzers to speed up the build. You can execute 'Build' or 'Rebuild' command to run analyzers.
1>FLOW3WebApp -> C:\code\FLOW\FLOWCSharp\FLOW3WebApp\bin\Debug\net7.0\FLOW3WebApp.dll
1>docker run -dt -v "C:\Users\*********\onecoremsvsmon\17.7.10830.2695:C:\remote_debugger:ro" -v "C:\Users\*********\AppData\Roaming\Microsoft\UserSecrets:C:\Users\ContainerUser\AppData\Roaming\Microsoft\UserSecrets:ro" -v "C:\Users\OITLASALLEGS0\AppData\Roaming\ASP.NET\Https:C:\Users\ContainerUser\AppData\Roaming\ASP.NET\Https:ro" -v "C:\Program Files\Microsoft Visual Studio\2022\Community\MSBuild\Sdks\Microsoft.Docker.Sdk\tools\TokenService.Proxy\win10-x64\net7.0:C:\TokenService.Proxy:ro" -v "C:\Program Files\Microsoft Visual Studio\2022\Community\MSBuild\Sdks\Microsoft.Docker.Sdk\tools\HotReloadProxy\win10-x64\net7.0:C:\HotReloadProxy:ro" -v "C:\Program Files\Microsoft Visual Studio\2022\Community\Common7\IDE\CommonExtensions\Microsoft\HotReload:C:\HotReloadAgent:ro" -v "C:\code\FLOW\FLOWCSharp\FLOW3WebApp:C:\app" -v "C:\code\FLOW\FLOWCSharp\FLOW3WebApp:c:\src" -v "C:\Users\**********.nuget\packages\:c:\.nuget\fallbackpackages" -e "ASPNETCORE_LOGGING__CONSOLE__DISABLECOLORS=true" -e "ASPNETCORE_ENVIRONMENT=Development" -e "DOTNET_USE_POLLING_FILE_WATCHER=1" -e "NUGET_PACKAGES=c:\.nuget\fallbackpackages" -e "NUGET_FALLBACK_PACKAGES=c:\.nuget\fallbackpackages" -P --name FLOW3WebApp_1 --entrypoint C:\remote_debugger\x64\msvsmon.exe flow3webapp:dev /noauth /anyuser /silent /nostatus /noclrwarn /nosecuritywarn /nofirewallwarn /nowowwarn /fallbackloadremotemanagedpdbs /timeout:2147483646 /LogDebuggeeOutputToStdOut
1>c61631fa1c93688583fb6b687da07e753fc5eae722e00f87793ffebf8c0dd109
1>docker: Error response from daemon: container c61631fa1c93688583fb6b687da07e753fc5eae722e00f87793ffebf8c0dd109 encountered an error during hcsshim::System::CreateProcess: failure in a Windows system call: Access is denied. (0x5).
1>docker rm -f c61631fa1c93688583fb6b687da07e753fc5eae722e00f87793ffebf8c0dd109
1>c61631fa1c93688583fb6b687da07e753fc5eae722e00f87793ffebf8c0dd109
1>C:\Users\***************\.nuget\packages\microsoft.visualstudio.azure.containers.tools.targets\1.19.4\build\Container.targets(213,5): error CTC1015: Docker command failed with exit code 125.
1>C:\Users\***********\.nuget\packages\microsoft.visualstudio.azure.containers.tools.targets\1.19.4\build\Container.targets(213,5): error CTC1015: docker: Error response from daemon: container c61631fa1c93688583fb6b687da07e753fc5eae722e00f87793ffebf8c0dd109 encountered an error during hcsshim::System::CreateProcess: failure in a Windows system call: Access is denied. (0x5).
1>C:\Users\**********\.nuget\packages\microsoft.visualstudio.azure.containers.tools.targets\1.19.4\build\Container.targets(213,5): error CTC1015: If the error persists, try restarting Docker Desktop.
1>Done building project "flow3webapp.csproj" -- FAILED.
========== Build: 0 succeeded, 1 failed, 0 up-to-date, 0 skipped ==========
========== Build started at 10:52 AM and took 15.110 seconds ==========

当前使用的Dockerfile

#See https://aka.ms/customizecontainer to learn how to customize your debug container and how Visual Studio uses this Dockerfile to build your images for faster debugging.

#Depending on the operating system of the host machines(s) that will build or run the containers, the image specified in the FROM statement may need to be changed.
#For more information, please see https://aka.ms/containercompat

FROM mcr.microsoft.com/dotnet/aspnet:7.0 AS base
WORKDIR /app
EXPOSE 80
EXPOSE 443

FROM mcr.microsoft.com/dotnet/sdk:7.0 AS build
WORKDIR /src
COPY ["FLOW3WebApp.csproj", "."]
RUN dotnet restore "./FLOW3WebApp.csproj"
COPY . .
WORKDIR "/src/."
RUN dotnet build "FLOW3WebApp.csproj" -c Release -o /app/build

FROM build AS publish
RUN dotnet publish "FLOW3WebApp.csproj" -c Release -o /app/publish /p:UseAppHost=false

FROM base AS final
WORKDIR /app
COPY --from=publish /app/publish .
ENTRYPOINT ["dotnet", "FLOW3WebApp.dll"]

已尝试的操作

  • 最初选择Linux镜像,因Docker配置为Windows,删除后重新生成Windows版本Dockerfile
  • 曾在Dockerfile中添加管理员配置,通过CLI可运行但会弹出管理员凭据窗口,而应用本身无需该权限
  • 尝试安装Docker Desktop提示与Windows Server不兼容,当前使用Program Files目录下的Docker,多次重启守护进程无效

解决方案

1. 适配Windows Server的Docker镜像版本

通用的.NET 7镜像可能与Windows Server版本不匹配,需替换为对应Server版本的镜像:

# 替换base和build阶段的镜像(以Windows Server 2022为例)
FROM mcr.microsoft.com/dotnet/aspnet:7.0-nanoserver-ltsc2022 AS base
FROM mcr.microsoft.com/dotnet/sdk:7.0-nanoserver-ltsc2022 AS build
  • 若使用Windows Server 2019,替换为7.0-nanoserver-ltsc2019
  • 确保镜像的OS版本与宿主Windows Server完全一致

2. 提升Visual Studio运行权限

以管理员身份启动Visual Studio,确保VS拥有足够权限操作Docker容器及挂载的本地目录,避免权限不足导致的进程创建失败。

3. 调整Visual Studio调试配置

修改项目的.csproj文件,添加以下配置,禁用VS自动添加的部分调试挂载项,减少权限冲突:

<PropertyGroup>
  <!-- 直接启动应用,跳过远程调试工具的启动流程 -->
  <DockerDebuggeeArguments>dotnet FLOW3WebApp.dll</DockerDebuggeeArguments>
  <DockerDebuggeeEntrypoint></DockerDebuggeeEntrypoint>
  <!-- 禁用用户密钥和HTTPS目录的挂载 -->
  <DockerMountUserSecrets>false</DockerMountUserSecrets>
  <DockerMountHttps>false</DockerMountHttps>
</PropertyGroup>

4. 切换Docker隔离模式为Process

在Windows Server上,Process隔离模式比Hyper-V隔离更轻量化且权限问题更少:

  • 临时方案:在启动容器时添加参数--isolation=process
  • 永久方案:修改Docker守护进程配置文件C:\ProgramData\Docker\config\daemon.json,添加:
    {
      "exec-opts": ["isolation=process"]
    }
    
    保存后重启Docker守护进程生效

内容的提问来源于stack exchange,提问作者Salvatore Allegra

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 20:35:57