Kubernetes中通过Traefik IngressRoute配置Nexus缓存Docker Hub遇阻求助
问题:Nexus Docker镜像缓存失效,仓库无数据
在Kubernetes环境通过Traefik IngressRoute搭建Nexus用于缓存Docker Hub镜像,执行docker pull ubuntu后镜像未被缓存,创建的Docker仓库无任何数据。
现有配置清单
nx-deploy.yml
apiVersion: apps/v1 kind: Deployment metadata: name: nexus spec: replicas: 1 selector: matchLabels: app: nexus template: metadata: labels: app: nexus spec: containers: - name: nexus image: sonatype/nexus3 ports: - containerPort: 8081 protocol: TCP resources: requests: memory: "512Mi" cpu: "2000m" limits: memory: "2Gi" cpu: "4000m" volumeMounts: - name: nexus-data mountPath: /nexus-data volumes: - name: nexus-data persistentVolumeClaim: claimName: nexus-data
nx-service.yml
apiVersion: v1 kind: Service metadata: name: nexus-service namespace: nexus spec: type: ClusterIP ports: - name: web port: 80 protocol: TCP targetPort: 8081 selector: app: nexus
ingress.yml
apiVersion: traefik.containo.us/v1alpha1 kind: IngressRoute metadata: name: nexus namespace: nexus spec: entryPoints: - web routes: - match: Host(`nexus.example.io`) && PathPrefix(`/`) kind: Rule services: - name: nexus-service port: 80
nx-pvc.yml
apiVersion: v1 kind: PersistentVolumeClaim metadata: name: nexus-data namespace: nexus spec: accessModes: - ReadWriteMany resources: requests: storage: 2Gi
已完成的配置
- Nexus已开启匿名访问,未指定HTTP/HTTPS协议
- Traefik监听80端口,Service将80端口转发至Nexus Pod的8081端口
- 客户端机器修改
daemon.json:
"insecure-registries": ["nexus.example.io"], "registry-mirrors": ["http://nexus.example.io"]
- 客户端
/etc/hosts已添加Kubernetes节点IP与nexus.example.io的映射
排查与解决建议
1. 修正Nexus Docker仓库的路径配置
Nexus的Web管理端口(8081)和Docker仓库端口/路径是分离的,默认不会自动用8081处理Docker镜像拉取请求:
- 登录Nexus后台,确认Docker代理仓库的Repository Path(比如设置为
/docker-hub/) - 客户端
daemon.json的镜像地址需对应修改:"registry-mirrors": ["http://nexus.example.io/docker-hub/"]
2. 验证IngressRoute的转发逻辑
当前IngressRoute的PathPrefix(/)可转发所有请求,但需确保客户端请求路径与Nexus仓库路径完全匹配:
- 如果使用Nexus Docker仓库的端口模式(比如监听8082),需在Deployment中添加
containerPort: 8082,Service新增对应端口映射,IngressRoute补充该端口的路由规则
3. 测试客户端与Nexus的连通性
- 客户端执行
curl http://nexus.example.io/v2/_catalog,若返回仓库列表则基础连通正常;若报错,排查Traefik转发规则或网络连通性 - 直接执行
docker pull nexus.example.io/ubuntu,强制从Nexus仓库拉取,测试是否触发缓存
4. 检查Nexus仓库的代理配置
- 确认Docker代理仓库的Remote Storage设置为
https://registry-1.docker.io,且Allow Anonymous Docker Pull已开启 - 查看Nexus日志(
kubectl logs -n nexus <nexus-pod-name>),排查是否有镜像拉取请求记录或报错信息
5. 确认Docker daemon配置生效
修改daemon.json后必须重启Docker服务:
systemctl restart docker
重启后执行docker info,检查Registry Mirrors和Insecure Registries是否正确显示配置内容
内容的提问来源于stack exchange,提问作者Meow
相关产品推荐
相关产品推荐

