Gitlab CI流程中无法拉取Gitlab Registry镜像问题排查
GitLab CI跨项目拉取镜像失败:insufficient_scope授权错误
已通过Kaniko成功构建镜像并推送到GitLab容器仓库,但在另一项目的GitLab CI流程中拉取该镜像作为基础镜像时,触发以下错误:
WARNING: Failed to pull image with policy "": image pull failed: rpc error: code = Unknown desc = failed to pull and unpack image "registry.gitlab.com/:v1.0.0": failed to resolve reference "registry.gitlab.com/:v1.0.0": pull access denied, repository does not exist or may require authorization: server message: insufficient_scope: authorization failed ERROR: Job failed: prepare environment: waiting for pod running: pulling image "registry.gitlab.com/:v1.0.0": image pull failed: rpc error: code = Unknown desc = failed to pull and unpack image "registry.gitlab.com/:v1.0.0": failed to resolve reference "registry.gitlab.com/:v1.0.0": pull access denied, repository does not exist or may require authorization: server message: insufficient_scope: authorization failed. Check https://docs.gitlab.com/runner/shells/index.html#shell-profile-loading for more information
用于构建并推送镜像的.gitlab-ci.yaml代码:
variables: GIT_STRATEGY: clone IMAGE_VERSION: v1.0.0 default: tags: - applications stages: - build build_gitlab_container: stage: build image: name: gcr.io/kaniko-project/executor:debug entrypoint: [""] script: - echo "{"auths":{"$CI_REGISTRY":{"username":"$CI_REGISTRY_USER","password":"$CI_REGISTRY_PASSWORD"}}}" > /kaniko/.docker/config.json - /kaniko/executor --context $CI_PROJECT_DIR --dockerfile $CI_PROJECT_DIR/Dockerfile --destination $CI_REGISTRY_IMAGE:$IMAGE_VERSION
已验证内容:
- 镜像仓库URL正确
- 授权信息无误
- 本人是目标GitLab子组及项目的所有者
解决方法
1. 配置CI_JOB_TOKEN跨项目访问权限
GitLab默认的CI_JOB_TOKEN仅能访问当前项目资源,跨项目拉取镜像需在镜像所在项目中进行如下设置:
- 进入项目「设置 → CI/CD → 令牌权限」
- 启用「允许此项目的作业令牌访问此组中的项目」(若两个项目同属一个子组);或在「允许的项目」中添加需要拉取镜像的项目。
2. 使用个人访问令牌(PAT)
创建一个具备read_registry权限的个人访问令牌,将其添加为拉取镜像项目的CI/CD变量(例如命名为REGISTRY_PAT),然后在CI配置中指定拉取凭证:
your_job_name: image: name: registry.gitlab.com/your-group/your-image-repo:v1.0.0 entrypoint: [""] variables: DOCKER_AUTH_CONFIG: '{"auths":{"registry.gitlab.com":{"username":"your-gitlab-username","password":"$REGISTRY_PAT"}}}' script: # 你的作业执行脚本
3. 确认镜像仓库访问权限
- 检查镜像所在项目的可见性:若为私有项目,需确保拉取镜像的项目(或其所在组)被添加为镜像项目的成员,权限至少为
Reporter(具备仓库读取权限)。 - 确认镜像标签
v1.0.0已成功推送到仓库,避免因标签拼写错误或推送未完成导致拉取失败。
内容的提问来源于stack exchange,提问作者dev12345
相关产品推荐
相关产品推荐

