You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

配置ctr使用Nexus Docker拉取代理失败如何解决?

解决ctr拉取镜像时不使用Nexus代理的问题

问题原因

你之前在/etc/containerd/config.toml中配置的是CRI插件专属的镜像仓库镜像,仅对通过CRI接口调用containerd的组件(如kubelet)生效。而ctr是containerd的原生命令行工具,不会读取CRI插件的配置,因此会直接请求docker.io的官方地址,导致DNS解析超时。

解决方案

方法一:临时拉取(直接指定代理地址)

拉取镜像时,将原镜像名替换为Nexus代理仓库的地址前缀,Nexus会自动将请求转发到docker.io:

ctr images pull 10.13.75.3:8181/plndr/kube-vip:latest

如果需要保留原镜像标签(方便后续使用),拉取完成后可以重新打标签:

ctr images tag 10.13.75.3:8181/plndr/kube-vip:latest docker.io/plndr/kube-vip:latest

方法二:全局配置(对ctr永久生效)

修改/etc/containerd/config.toml,添加containerd全局的registry镜像配置(注意是顶级的[registry]区块,而非CRI插件下的配置):

[registry]
  [registry.mirrors]
    [registry.mirrors."docker.io"]
      endpoint = ["http://10.13.75.3:8181"]

配置完成后重启containerd服务:

systemctl restart containerd

之后即可直接使用原镜像名拉取:

ctr images pull docker.io/plndr/kube-vip:latest

补充:若Nexus需要认证

如果你的Nexus代理仓库开启了认证,需要在config.toml中添加auth配置:

[registry.configs]
  [registry.configs."10.13.75.3:8181".auth]
    username = "你的Nexus用户名"
    password = "你的Nexus密码"

添加后同样需要重启containerd生效。

内容的提问来源于stack exchange,提问作者PrestonDocks

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.15 16:32:50