You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Helm无法从私有Nexus3仓库拉取镜像:HTTP响应错误

问题描述

执行Helm安装命令后拉取私有镜像失败,报错:

http: server gave HTTP response to HTTPS client

操作背景:

  • 创建了myrelease命名空间
  • 执行命令:helm install myrelease -n myrelease .触发错误
  • 已配置Docker接受不安全仓库:所有节点编辑/etc/docker/daemon.json:
{
    "features": {
       "buildkit": false
    },
    "insecure-registries" : [ "http://xx.xx.xx.xx:8082" ]
}
  • docker login myrepo登录成功
  • 已配置Helm Chart镜像拉取密钥:
    1. 创建templates/secret.yaml:
    apiVersion: v1
    kind: Secret
    metadata:
      name: {{ .Values.imageCredentials.name }}
    type: kubernetes.io/dockerconfigjson
    data:
      .dockerconfigjson: {{ template "imagePullSecret" . }}
    
    1. 修改templates/_helper.tpl末尾添加:
    //added to the end of the file:
    {{- define "imagePullSecret" }}
    {{- with .Values.imageCredentials }}
    {{- printf "{\"auths\":{\"%s\":{\"username\":\"%s\",\"password\":\"%s\",\"email\":\"%s\",\"auth\":\"%s\"}}}" .registry .username .password .email (printf "%s:%s" .username .password | b64enc) | b64enc }}
    {{- end }}
    {{- end }}
    
    1. values.yaml配置:
    image:
      repository: xx.xx.xx.xx:8082/helloworldwar
      pullPolicy: IfNotPresent
      tag: "11"
    imageCredentials:
      name: nexuscreds
      registry: xx.xx.xx.xx:8082/helloworld
      username: xxxx
      password: xxxx
      email: xxxx@gmail.com
    imagePullSecrets:
      - name: nexuscreds
    
  • docker info显示不安全仓库已配置:
Insecure Registries:
  xx.xx.xx.xx:8082
  127.0.0.0/8
解决方案

1. 修正Docker不安全仓库配置格式

/etc/docker/daemon.json里的insecure-registries不需要带http://前缀,改为:

{
    "features": {
       "buildkit": false
    },
    "insecure-registries" : [ "xx.xx.xx.xx:8082" ]
}

修改后所有节点重启Docker服务:

systemctl restart docker

2. 修正Helm配置中的仓库地址

values.yaml里的imageCredentials.registry应该是纯仓库地址,不能包含镜像路径(/helloworld),改为:

imageCredentials:
  name: nexuscreds
  registry: xx.xx.xx.xx:8082
  username: xxxx
  password: xxxx
  email: xxxx@gmail.com

Secret中auths的key需要和镜像仓库的根地址完全匹配,否则Kubernetes拉取镜像时无法匹配到对应的凭证。

3. 验证Secret正确性

重新安装Helm release后,检查生成的Secret:

kubectl get secret nexuscreds -n myrelease -o jsonpath='{.data.\.dockerconfigjson}' | base64 -d

输出应包含"xx.xx.xx.xx:8082"作为auths的key,确保和镜像仓库地址一致。

4. 确认所有Kubernetes节点的Docker配置生效

在每个Worker节点执行docker info,确认Insecure Registries中正确显示xx.xx.xx.xx:8082,且Docker服务已重启。

内容的提问来源于stack exchange,提问作者michael

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.16 05:23:20