You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ubuntu生产环境Docker拉取镜像报missing signature key故障排查

解决Ubuntu环境Docker拉取镜像报错"missing signature key"的方案

问题诊断

这个报错是Docker镜像仓库的签名验证失败导致的,和镜像拉取的核心配置、系统环境直接相关,下面是针对性的解决步骤:

解决步骤

1. 检查系统时间同步状态

签名验证对时间敏感,系统时间偏差过大直接导致签名失效:

  • 查看当前时间同步状态:
    timedatectl status
    
  • 如果显示NTP未同步,开启自动时间同步:
    sudo timedatectl set-ntp true
    

2. 重置Docker仓库配置

可能是自定义镜像源配置出错,恢复默认Docker Hub配置:

  • 备份现有配置(防止出错可恢复):
    sudo cp /etc/docker/daemon.json /etc/docker/daemon.json.bak
    
  • 创建/修改daemon.json文件,写入默认仓库配置:
    sudo tee /etc/docker/daemon.json <<EOF
    {
      "registry-mirrors": ["https://registry-1.docker.io"]
    }
    EOF
    
  • 重启Docker服务使配置生效:
    sudo systemctl restart docker
    

3. 重新配置Docker官方GPG密钥与源

如果系统里的Docker密钥过期或损坏,重新导入官方密钥并更新源:

  • 删除旧的Docker密钥:
    sudo apt-key del 9DC858229FC7DD38854AE2D88D81803C0EBFCD88
    
  • 导入新的官方GPG密钥:
    curl -fsSL https://download.docker.com/linux/ubuntu/gpg | sudo gpg --dearmor -o /usr/share/keyrings/docker-archive-keyring.gpg
    
  • 重新添加Docker官方源:
    echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/docker-archive-keyring.gpg] https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" | sudo tee /etc/apt/sources.list.d/docker.list > /dev/null
    
  • 更新包列表并重装Docker组件:
    sudo apt update && sudo apt install --reinstall docker-ce docker-ce-cli containerd.io docker-compose-plugin
    

4. 测试镜像拉取

执行以下命令验证问题是否解决:

docker pull mysql:8

额外提醒

你的docker-compose.yml里存在Windows风格的卷路径/C/Program Files/Apache Software Foundation/Tomcat 8.5/webapps/ROOT,在Ubuntu环境下要改成Linux格式的路径(比如/opt/tomcat/webapps/ROOT),避免容器启动时卷挂载失败。

内容的提问来源于stack exchange,提问作者JPG

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.08 09:28:10