You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Gitlab CI流程中无法拉取Gitlab Registry镜像问题排查

GitLab CI跨项目拉取镜像失败:insufficient_scope授权错误

已通过Kaniko成功构建镜像并推送到GitLab容器仓库,但在另一项目的GitLab CI流程中拉取该镜像作为基础镜像时,触发以下错误:

WARNING: Failed to pull image with policy "": image pull failed: rpc error: code = Unknown desc = failed to pull and unpack image "registry.gitlab.com/:v1.0.0": failed to resolve reference "registry.gitlab.com/:v1.0.0": pull access denied, repository does not exist or may require authorization: server message: insufficient_scope: authorization failed

ERROR: Job failed: prepare environment: waiting for pod running: pulling image "registry.gitlab.com/:v1.0.0": image pull failed: rpc error: code = Unknown desc = failed to pull and unpack image "registry.gitlab.com/:v1.0.0": failed to resolve reference "registry.gitlab.com/:v1.0.0": pull access denied, repository does not exist or may require authorization: server message: insufficient_scope: authorization failed. Check https://docs.gitlab.com/runner/shells/index.html#shell-profile-loading for more information

用于构建并推送镜像的.gitlab-ci.yaml代码:

variables:
  GIT_STRATEGY: clone
  IMAGE_VERSION: v1.0.0

default:
  tags:
    - applications

stages:
  - build

build_gitlab_container:
  stage: build
  image:
    name: gcr.io/kaniko-project/executor:debug
    entrypoint: [""]
  script:
    - echo "{"auths":{"$CI_REGISTRY":{"username":"$CI_REGISTRY_USER","password":"$CI_REGISTRY_PASSWORD"}}}" > /kaniko/.docker/config.json
    - /kaniko/executor --context $CI_PROJECT_DIR --dockerfile $CI_PROJECT_DIR/Dockerfile --destination $CI_REGISTRY_IMAGE:$IMAGE_VERSION

已验证内容:

  • 镜像仓库URL正确
  • 授权信息无误
  • 本人是目标GitLab子组及项目的所有者

解决方法

1. 配置CI_JOB_TOKEN跨项目访问权限

GitLab默认的CI_JOB_TOKEN仅能访问当前项目资源,跨项目拉取镜像需在镜像所在项目中进行如下设置:

  • 进入项目「设置 → CI/CD → 令牌权限」
  • 启用「允许此项目的作业令牌访问此组中的项目」(若两个项目同属一个子组);或在「允许的项目」中添加需要拉取镜像的项目。

2. 使用个人访问令牌(PAT)

创建一个具备read_registry权限的个人访问令牌,将其添加为拉取镜像项目的CI/CD变量(例如命名为REGISTRY_PAT),然后在CI配置中指定拉取凭证:

your_job_name:
  image:
    name: registry.gitlab.com/your-group/your-image-repo:v1.0.0
    entrypoint: [""]
  variables:
    DOCKER_AUTH_CONFIG: '{"auths":{"registry.gitlab.com":{"username":"your-gitlab-username","password":"$REGISTRY_PAT"}}}'
  script:
    # 你的作业执行脚本

3. 确认镜像仓库访问权限

  • 检查镜像所在项目的可见性:若为私有项目,需确保拉取镜像的项目(或其所在组)被添加为镜像项目的成员,权限至少为Reporter(具备仓库读取权限)。
  • 确认镜像标签v1.0.0已成功推送到仓库,避免因标签拼写错误或推送未完成导致拉取失败。

内容的提问来源于stack exchange,提问作者dev12345

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.24 12:37:37