构建PDF OCR文本提取器Docker镜像遇Debian源签名错误
解决Debian Bullseye仓库签名错误导致Docker构建失败的问题
问题描述
构建基于OCR的PDF文本提取器Docker镜像时,遇到Debian Bullseye系列仓库签名验证失败,apt-get update进程终止,核心报错如下:
At least one invalid signature was encountered.
E: The repository 'http://deb.debian.org/debian bullseye InRelease' is not signed.
原Dockerfile
# Dockerfile FROM python:3.11.3 # Install Tesseract and poppler-utils RUN apt-get update && apt-get install -y --allow-unauthenticated \ tesseract-ocr \ poppler-utils \ && rm -rf /var/lib/apt/lists/* # Set the working directory in the container to /app WORKDIR /app # Copy the requirements.txt into the container at /app COPY requirements.txt /app/ # Install Python dependencies RUN pip install --no-cache-dir -r requirements.txt # Copy the content of the local src directory to the working directory COPY extract_text.py /app/ # Specify the command to run on container start CMD ["python", "./extract_text.py"]
构建命令及完整错误输出
juan@192 pdf_ocr_extractor % docker system prune -a -f docker builder prune -a -f docker build -t pdf_ocr_extractor . docker run -v /Users/juan/Desktop/dev/code/pdf_ocr_extractor:/data pdf_ocr_extractor python extract_text.py /data/doc.pdf Deleted build cache objects: kgkkmlafdg6akei7qbtf1bmu5 xskqcqk4opazcyvgt3fxb64yo 13bcwdvd9ut7vfs2satvgq08j vb7al8ahfvu8jt56qng0fl3rh zor7s3yozjzpgjpdu7qdpmpam hblvcrt146srhmr8auwq3le1k 30exdbkxsiz7spkzut7vivxc3 tbl3ja6j760iebspo2aj7upay popyaa0t3nv198bbynarrnzbx reo6ndn1n91u6y1ug5t7anec2 qkpqepkr00vpzqssgrrsmelwk Total reclaimed space: 1.143kB Total: 0B [+] Building 4.1s (7/11) docker:desktop-linux => [internal] load build definition from Dockerfile 0.0s => => transferring dockerfile: 708B 0.0s => [internal] load .dockerignore 0.0s => => transferring context: 2B 0.0s => [internal] load metadata for docker.io/library/python:3.11.3 3.4s => [auth] library/python:pull token for registry-1.docker.io 0.0s => [1/6] FROM docker.io/library/python:3.11.3@sha256:3a619e3c96fd4c5fc5e1998fd4dcb1f1403eb90c4c6409c70d7e80b9468df7df 0.1s => => resolve docker.io/library/python:3.11.3@sha256:3a619e3c96fd4c5fc5e1998fd4dcb1f1403eb90c4c6409c70d7e80b9468df7df 0.0s => => sha256:de5aeca5458519a772e9b344d3c1ac16a1be52eab179cf2a28a31382dd1018f1 2.01kB / 2.01kB 0.0s => => sha256:1918a277862c33ee6f35b696867ca414a014f2b63f1e257986a3f480c9da5edc 7.54kB / 7.54kB 0.0s => => sha256:3a619e3c96fd4c5fc5e1998fd4dcb1f1403eb90c4c6409c70d7e80b9468df7df 2.14kB / 2.14kB 0.0s => [internal] load build context 0.0s => => transferring context: 669B 0.0s => ERROR [2/6] RUN apt-get update && apt-get install -y --allow-unauthenticated tesseract-ocr poppler-utils && rm -rf /var/lib/apt/lists/ 0.5s ------ > [2/6] RUN apt-get update && apt-get install -y --allow-unauthenticated tesseract-ocr poppler-utils && rm -rf /var/lib/apt/lists/*: 0.368 Get:1 http://deb.debian.org/debian bullseye InRelease [116 kB] 0.386 Get:2 http://deb.debian.org/debian-security bullseye-security InRelease [48.4 kB] 0.387 Get:3 http://deb.debian.org/debian bullseye-updates InRelease [44.1 kB] 0.445 Err:1 http://deb.debian.org/debian bullseye InRelease 0.445 At least one invalid signature was encountered. 0.482 Err:2 http://deb.debian.org/debian-security bullseye-security InRelease 0.482 At least one invalid signature was encountered. 0.518 Err:3 http://deb.debian.org/debian bullseye-updates InRelease 0.518 At least one invalid signature was encountered. 0.525 Reading package lists... 0.534 W: GPG error: http://deb.debian.org/debian bullseye InRelease: At least one invalid signature was encountered. 0.534 E: The repository 'http://deb.debian.org/debian bullseye InRelease' is not signed. 0.534 W: GPG error: http://deb.debian.org/debian-security bullseye-security InRelease: At least one invalid signature was encountered. 0.534 E: The repository 'http://deb.debian.org/debian-security bullseye-security InRelease' is not signed. 0.534 W: GPG error: http://deb.debian.org/debian bullseye-updates InRelease: At least one invalid signature was encountered. 0.534 E: The repository 'http://deb.debian.org/debian bullseye-updates InRelease' is not signed. ------ Dockerfile:7 -------------------- 6 | # Install Tesseract and poppler-utils 7 | >>> RUN apt-get update && apt-get install -y --allow-unauthenticated \ 8 | >>> tesseract-ocr \ 9 | >>> poppler-utils \ 10 | >>> && rm -rf /var/lib/apt/lists/* 11 | -------------------- ERROR: failed to solve: process "/bin/sh -c apt-get update && apt-get install -y --allow-unauthenticated tesseract-ocr poppler-utils && rm -rf /var/lib/apt/lists/*" did not complete successfully: exit code: 100 Unable to find image 'pdf_ocr_extractor:latest' locally docker: Error response from daemon: pull access denied for pdf_ocr_extractor, repository does not exist or may require 'docker login': denied: requested access to the resource is denied. See 'docker run --help'. juan@192 pdf_ocr_extractor %
解决方案
1. 替换为国内Debian镜像源(推荐)
官方源可能存在签名过期或网络波动问题,替换为清华镜像源可直接绕过该问题。修改后的Dockerfile如下:
# Dockerfile FROM python:3.11.3 # 替换清华Debian Bullseye镜像源 RUN echo "deb https://mirrors.tuna.tsinghua.edu.cn/debian/ bullseye main contrib non-free" > /etc/apt/sources.list && \ echo "deb https://mirrors.tuna.tsinghua.edu.cn/debian-security/ bullseye-security main contrib non-free" >> /etc/apt/sources.list && \ echo "deb https://mirrors.tuna.tsinghua.edu.cn/debian/ bullseye-updates main contrib non-free" >> /etc/apt/sources.list # Install Tesseract and poppler-utils RUN apt-get update && apt-get install -y \ tesseract-ocr \ poppler-utils \ && rm -rf /var/lib/apt/lists/* # Set the working directory in the container to /app WORKDIR /app # Copy the requirements.txt into the container at /app COPY requirements.txt /app/ # Install Python dependencies RUN pip install --no-cache-dir -r requirements.txt # Copy the content of the local src directory to the working directory COPY extract_text.py /app/ # Specify the command to run on container start CMD ["python", "./extract_text.py"]
2. 跳过签名验证(不推荐)
若坚持使用官方源,可在apt-get update阶段也添加--allow-unauthenticated参数,强制跳过签名验证:
RUN apt-get update --allow-unauthenticated && apt-get install -y --allow-unauthenticated \ tesseract-ocr \ poppler-utils \ && rm -rf /var/lib/apt/lists/*
注意:此方法会降低镜像安全性,不建议在生产环境使用。
3. 升级基础Python镜像
Python 3.11.3对应的Debian镜像可能存在GPG密钥过期问题,尝试使用更新的Python 3.11版本或 slim 轻量化镜像:
FROM python:3.11.9-slim-bullseye
验证步骤
修改完成后,重新执行构建和运行命令:
# 构建镜像 docker build -t pdf_ocr_extractor . # 运行容器 docker run -v /Users/juan/Desktop/dev/code/pdf_ocr_extractor:/data pdf_ocr_extractor python extract_text.py /data/doc.pdf
内容的提问来源于stack exchange,提问作者user17281101
相关产品推荐
相关产品推荐

