Earthly配置自定义自签名CA证书无效问题求助
Looks like your current config is missing a couple key pieces—you're mounting the certificate file, but not telling Earthly/Buildkit to actually use it for SSL validation. Let's break down the fixes step by step:
1. Update Your Earthly Config File
Your ~/.earthly/config.yml needs to both mount the certificate into the Buildkit container and set environment variables that tell tools like git and curl to use it. Replace your current config with this:
global: buildkit_additional_args: # Mount your corporate CA cert into the standard system cert location (read-only) - "-v" - "/Users/maca/.config/corporate/cert/cacerts:/etc/ssl/certs/ca-certificates.crt:ro" # Tell tools to use the mounted cert file - "-e" - "SSL_CERT_FILE=/etc/ssl/certs/ca-certificates.crt" - "-e" - "CURL_CA_BUNDLE=/etc/ssl/certs/ca-certificates.crt"
This ensures any process running inside Buildkit (like the alpine/git container used for cloning) will pick up your corporate CA cert instead of relying on default system certs.
2. Configure Git to Trust Your CA Cert
Earthly might use your local Git client for some operations, so let's make sure Git recognizes your certificate globally:
git config --global http.sslCAInfo /Users/maca/.config/corporate/cert/cacerts
This directly addresses the "SSL certificate problem" error you're seeing during the GIT CLONE step.
3. Ensure Docker Daemon Trusts the Certificate
Since Earthly pulls Docker images (like alpine/git) via Docker, you need to add your CA cert to Docker's trusted list:
- Create a directory for Docker's registry-specific certs (if it doesn't exist):
mkdir -p ~/.docker/certs.d/docker.io - Copy your CA cert into this directory (rename it to
ca.crtfor Docker to recognize it automatically):cp /Users/maca/.config/corporate/cert/cacerts ~/.docker/certs.d/docker.io/ca.crt - Restart your Docker daemon to apply the changes.
If you need to trust the cert for all registries, you can edit Docker's daemon config (/etc/docker/daemon.json on Linux, or via Docker Desktop settings on macOS/Windows) to include:
{ "tlscacert": "/Users/maca/.config/corporate/cert/cacerts" }
4. Restart Earthly Daemon
Finally, restart the Earthly daemon to load your updated config:
earthly daemon stop earthly daemon start
Test the Fix
Run a simple Earthly build to verify everything works as expected:
earthly github.com/earthly/hello-world:main+hello
This should successfully clone the repo and pull the required Docker images without SSL errors.
内容的提问来源于stack exchange,提问作者Martin Macak

