You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kubernetes中通过Traefik IngressRoute配置Nexus缓存Docker Hub遇阻求助

问题:Nexus Docker镜像缓存失效,仓库无数据

在Kubernetes环境通过Traefik IngressRoute搭建Nexus用于缓存Docker Hub镜像,执行docker pull ubuntu后镜像未被缓存,创建的Docker仓库无任何数据。

现有配置清单

nx-deploy.yml

apiVersion: apps/v1
kind: Deployment
metadata:
  name: nexus
spec:
  replicas: 1
  selector:
    matchLabels:
      app: nexus
  template:
    metadata:
      labels:
        app: nexus
    spec:
      containers:
      - name: nexus
        image: sonatype/nexus3
        ports:
        - containerPort: 8081
          protocol: TCP
        resources:
          requests:
            memory: "512Mi"
            cpu: "2000m"
          limits:
            memory: "2Gi"
            cpu: "4000m"
        volumeMounts:
        - name: nexus-data
          mountPath: /nexus-data
      volumes:
      - name: nexus-data
        persistentVolumeClaim:
          claimName: nexus-data

nx-service.yml

apiVersion: v1
kind: Service
metadata:
  name: nexus-service
  namespace: nexus
spec:
  type: ClusterIP
  ports:
  - name: web
    port: 80
    protocol: TCP
    targetPort: 8081
  selector:
    app: nexus

ingress.yml

apiVersion: traefik.containo.us/v1alpha1
kind: IngressRoute 
metadata:
  name: nexus
  namespace: nexus
spec:
  entryPoints:
    - web
  routes:
  - match: Host(`nexus.example.io`) && PathPrefix(`/`)
    kind: Rule 
    services:
    - name: nexus-service
      port: 80 

nx-pvc.yml

apiVersion: v1
kind: PersistentVolumeClaim
metadata:
  name: nexus-data
  namespace: nexus
spec:
  accessModes:
  - ReadWriteMany
  resources:
    requests:
      storage: 2Gi

已完成的配置

  • Nexus已开启匿名访问,未指定HTTP/HTTPS协议
  • Traefik监听80端口,Service将80端口转发至Nexus Pod的8081端口
  • 客户端机器修改daemon.json:
"insecure-registries": ["nexus.example.io"],
"registry-mirrors": ["http://nexus.example.io"]
  • 客户端/etc/hosts已添加Kubernetes节点IP与nexus.example.io的映射

排查与解决建议

1. 修正Nexus Docker仓库的路径配置

Nexus的Web管理端口(8081)和Docker仓库端口/路径是分离的,默认不会自动用8081处理Docker镜像拉取请求:

  • 登录Nexus后台,确认Docker代理仓库的Repository Path(比如设置为/docker-hub/)
  • 客户端daemon.json的镜像地址需对应修改:"registry-mirrors": ["http://nexus.example.io/docker-hub/"]

2. 验证IngressRoute的转发逻辑

当前IngressRoute的PathPrefix(/)可转发所有请求,但需确保客户端请求路径与Nexus仓库路径完全匹配:

  • 如果使用Nexus Docker仓库的端口模式(比如监听8082),需在Deployment中添加containerPort: 8082,Service新增对应端口映射,IngressRoute补充该端口的路由规则

3. 测试客户端与Nexus的连通性

  • 客户端执行curl http://nexus.example.io/v2/_catalog,若返回仓库列表则基础连通正常;若报错,排查Traefik转发规则或网络连通性
  • 直接执行docker pull nexus.example.io/ubuntu,强制从Nexus仓库拉取,测试是否触发缓存

4. 检查Nexus仓库的代理配置

  • 确认Docker代理仓库的Remote Storage设置为https://registry-1.docker.io,且Allow Anonymous Docker Pull已开启
  • 查看Nexus日志(kubectl logs -n nexus <nexus-pod-name>),排查是否有镜像拉取请求记录或报错信息

5. 确认Docker daemon配置生效

修改daemon.json后必须重启Docker服务:

systemctl restart docker

重启后执行docker info,检查Registry Mirrors和Insecure Registries是否正确显示配置内容


内容的提问来源于stack exchange,提问作者Meow

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.06 01:10:24