You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无SSH访问的K8s节点如何从无TLS的本地Harbor拉取镜像?

解决未配置TLS的私有Harbor仓库镜像拉取x509错误方案

以下是无需SSH访问节点、无需重建集群的可行方案,根据你的容器运行时类型选择:

方案1:针对Docker运行时的DaemonSet配置更新

通过特权模式DaemonSet直接修改节点的/etc/docker/daemon.json并重启Docker服务,将私有仓库加入不安全列表:

apiVersion: apps/v1
kind: DaemonSet
metadata:
  name: docker-config-updater
  namespace: kube-system
spec:
  selector:
    matchLabels:
      name: docker-config-updater
  template:
    metadata:
      labels:
        name: docker-config-updater
    spec:
      hostPID: true
      hostNetwork: true
      containers:
      - name: updater
        # 确保该镜像已存在于节点或私有Harbor仓库(无网络环境需提前导入)
        image: alpine:3.18
        command: ["/bin/sh", "-c"]
        args:
        - |
          # 替换为你的私有Harbor地址(如192.168.1.100:80)
          REGISTRY="your-harbor-address:port"
          DOCKER_CONFIG="/host/etc/docker/daemon.json"

          # 初始化或更新daemon.json的insecure-registries配置
          if [ ! -f "$DOCKER_CONFIG" ]; then
            echo "{\"insecure-registries\": [\"$REGISTRY\"]}" > "$DOCKER_CONFIG"
          else
            # 使用jq确保配置唯一(若容器无jq,可替换为sed逻辑)
            jq --arg reg "$REGISTRY" '.insecure-registries |= (. + [$reg] | unique)' "$DOCKER_CONFIG" > "$DOCKER_CONFIG.tmp" && mv "$DOCKER_CONFIG.tmp" "$DOCKER_CONFIG"
          fi

          # 重启Docker服务(通过nsenter进入宿主机PID 1执行命令)
          nsenter --target 1 --mount --uts --ipc --net --pid systemctl restart docker
        securityContext:
          privileged: true
        volumeMounts:
        - name: docker-config
          mountPath: /host/etc/docker
        - name: host-root
          mountPath: /host
          mountPropagation: HostToContainer
      volumes:
      - name: docker-config
        hostPath:
          path: /etc/docker
      - name: host-root
        hostPath:
          path: /

注意事项

  • 若容器镜像无jq工具,可替换为sed命令(需确保原有daemon.json格式正确):
    sed -i '/"insecure-registries"/s/\]/, "'"$REGISTRY"'"]/' "$DOCKER_CONFIG"
    
  • 执行后查看DaemonSet Pod日志确认配置生效:kubectl logs -n kube-system <pod-name>

方案2:针对containerd运行时的DaemonSet配置更新

若集群使用containerd作为容器运行时,修改/etc/containerd/config.toml添加私有仓库的TLS跳过验证规则:

apiVersion: apps/v1
kind: DaemonSet
metadata:
  name: containerd-config-updater
  namespace: kube-system
spec:
  selector:
    matchLabels:
      name: containerd-config-updater
  template:
    metadata:
      labels:
        name: containerd-config-updater
    spec:
      hostPID: true
      hostNetwork: true
      containers:
      - name: updater
        image: alpine:3.18
        command: ["/bin/sh", "-c"]
        args:
        - |
          REGISTRY="your-harbor-address:port"
          CONTAINERD_CONFIG="/host/etc/containerd/config.toml"

          # 检查是否已配置目标仓库的insecure规则
          if ! grep -q "insecure_skip_verify = true" "$CONTAINERD_CONFIG" || ! grep -q "\"$REGISTRY\"" "$CONTAINERD_CONFIG"; then
            cat >> "$CONTAINERD_CONFIG" << EOF
            [plugins."io.containerd.grpc.v1.cri".registry.configs."$REGISTRY".tls]
              insecure_skip_verify = true
            EOF
          fi

          # 重启containerd服务
          nsenter --target 1 --mount --uts --ipc --net --pid systemctl restart containerd
        securityContext:
          privileged: true
        volumeMounts:
        - name: containerd-config
          mountPath: /host/etc/containerd
        - name: host-root
          mountPath: /host
          mountPropagation: HostToContainer
      volumes:
      - name: containerd-config
        hostPath:
          path: /etc/containerd
      - name: host-root
        hostPath:
          path: /

方案3:修改kubelet启动参数添加不安全仓库

部分集群可通过kubelet启动参数直接配置不安全镜像仓库,适用于Docker/containerd运行时:

apiVersion: apps/v1
kind: DaemonSet
metadata:
  name: kubelet-config-updater
  namespace: kube-system
spec:
  selector:
    matchLabels:
      name: kubelet-config-updater
  template:
    metadata:
      labels:
        name: kubelet-config-updater
    spec:
      hostPID: true
      hostNetwork: true
      containers:
      - name: updater
        image: alpine:3.18
        command: ["/bin/sh", "-c"]
        args:
        - |
          REGISTRY="your-harbor-address:port"
          KUBELET_CONF="/host/etc/systemd/system/kubelet.service.d/10-kubeadm.conf"

          # 检查是否已添加目标仓库参数
          if ! grep -q "--image-insecure-registries=$REGISTRY" "$KUBELET_CONF"; then
            sed -i '/KUBELET_ARGS=/s/"$/ --image-insecure-registries='$REGISTRY'"/' "$KUBELET_CONF"
            # 重载systemd并重启kubelet
            nsenter --target 1 --mount --uts --ipc --net --pid systemctl daemon-reload
            nsenter --target 1 --mount --uts --ipc --net --pid systemctl restart kubelet
          fi
        securityContext:
          privileged: true
        volumeMounts:
        - name: kubelet-config
          mountPath: /host/etc/systemd/system/kubelet.service.d
        - name: host-root
          mountPath: /host
          mountPropagation: HostToContainer
      volumes:
      - name: kubelet-config
        hostPath:
          path: /etc/systemd/system/kubelet.service.d
      - name: host-root
        hostPath:
          path: /

验证步骤

  1. 应用DaemonSet:kubectl apply -f <yaml-file>
  2. 等待所有节点的Pod运行完成:kubectl rollout status daemonset <daemonset-name> -n kube-system
  3. 部署测试Pod,检查是否仍出现ImagePullBackOff错误

内容的提问来源于stack exchange,提问作者Ed Black

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.15 14:17:09