Helm无法从私有Nexus3仓库拉取镜像:HTTP响应错误
问题描述
执行Helm安装命令后拉取私有镜像失败,报错:
http: server gave HTTP response to HTTPS client
操作背景:
- 创建了
myrelease命名空间 - 执行命令:
helm install myrelease -n myrelease .触发错误 - 已配置Docker接受不安全仓库:所有节点编辑
/etc/docker/daemon.json:
{ "features": { "buildkit": false }, "insecure-registries" : [ "http://xx.xx.xx.xx:8082" ] }
docker login myrepo登录成功- 已配置Helm Chart镜像拉取密钥:
- 创建
templates/secret.yaml:
apiVersion: v1 kind: Secret metadata: name: {{ .Values.imageCredentials.name }} type: kubernetes.io/dockerconfigjson data: .dockerconfigjson: {{ template "imagePullSecret" . }}- 修改
templates/_helper.tpl末尾添加:
//added to the end of the file: {{- define "imagePullSecret" }} {{- with .Values.imageCredentials }} {{- printf "{\"auths\":{\"%s\":{\"username\":\"%s\",\"password\":\"%s\",\"email\":\"%s\",\"auth\":\"%s\"}}}" .registry .username .password .email (printf "%s:%s" .username .password | b64enc) | b64enc }} {{- end }} {{- end }}values.yaml配置:
image: repository: xx.xx.xx.xx:8082/helloworldwar pullPolicy: IfNotPresent tag: "11" imageCredentials: name: nexuscreds registry: xx.xx.xx.xx:8082/helloworld username: xxxx password: xxxx email: xxxx@gmail.com imagePullSecrets: - name: nexuscreds - 创建
docker info显示不安全仓库已配置:
Insecure Registries: xx.xx.xx.xx:8082 127.0.0.0/8
解决方案
1. 修正Docker不安全仓库配置格式
/etc/docker/daemon.json里的insecure-registries不需要带http://前缀,改为:
{ "features": { "buildkit": false }, "insecure-registries" : [ "xx.xx.xx.xx:8082" ] }
修改后所有节点重启Docker服务:
systemctl restart docker
2. 修正Helm配置中的仓库地址
values.yaml里的imageCredentials.registry应该是纯仓库地址,不能包含镜像路径(/helloworld),改为:
imageCredentials: name: nexuscreds registry: xx.xx.xx.xx:8082 username: xxxx password: xxxx email: xxxx@gmail.com
Secret中auths的key需要和镜像仓库的根地址完全匹配,否则Kubernetes拉取镜像时无法匹配到对应的凭证。
3. 验证Secret正确性
重新安装Helm release后,检查生成的Secret:
kubectl get secret nexuscreds -n myrelease -o jsonpath='{.data.\.dockerconfigjson}' | base64 -d
输出应包含"xx.xx.xx.xx:8082"作为auths的key,确保和镜像仓库地址一致。
4. 确认所有Kubernetes节点的Docker配置生效
在每个Worker节点执行docker info,确认Insecure Registries中正确显示xx.xx.xx.xx:8082,且Docker服务已重启。
内容的提问来源于stack exchange,提问作者michael
相关产品推荐
相关产品推荐

