You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker构建执行apt-get时遇GPG公钥缺失错误的求助

解决Docker构建时GPG公钥缺失问题(NO_PUBKEY 4EB27DB2A3B88B8B)

你的问题出在基础镜像自带的谷歌Chrome软件源未正确配置签名密钥,且你之前在宿主机执行的apt-key命令不会影响Docker容器内的环境——必须把密钥导入步骤写到Dockerfile里。另外Ubuntu 22.04已弃用apt-key命令,推荐使用密钥环文件的方式配置。

正确解决方案

方法1:导入密钥并配置源使用密钥环(推荐)

修改Dockerfile,在apt-get update前添加密钥导入和源配置步骤:

FROM dorowu/ubuntu-desktop-lxde-vnc

WORKDIR /data

# 导入谷歌Chrome的GPG密钥到密钥环文件
RUN apt-get update && apt-get install -y --no-install-recommends \
    curl gnupg2 \
    && curl -fsSL https://dl.google.com/linux/linux_signing_key.pub | gpg --dearmor -o /usr/share/keyrings/google-chrome-keyring.gpg \
    # 修改源列表,让它引用密钥环
    && echo "deb [arch=amd64 signed-by=/usr/share/keyrings/google-chrome-keyring.gpg] http://dl.google.com/linux/chrome/deb stable main" > /etc/apt/sources.list.d/google-chrome.list \
    # 安装ffmpeg
    && apt-get update && apt-get install -y \
    ffmpeg \
    # 清理缓存减小镜像体积
    && apt-get clean && rm -rf /var/lib/apt/lists/*

方法2:临时跳过源签名检查(不推荐,仅用于测试)

若只是临时解决,可在apt-get命令中添加跳过签名检查的参数,但这会降低安全性:

FROM dorowu/ubuntu-desktop-lxde-vnc

WORKDIR /data

RUN apt-get update --allow-unauthenticated && apt-get install -y --allow-unauthenticated \
    ffmpeg 

为什么之前的操作无效

你在宿主机执行sudo apt-key adv...仅会给宿主机添加密钥,而Docker构建过程在独立的容器环境中进行,宿主机的密钥配置不会被容器继承,必须把密钥导入逻辑写入Dockerfile,让构建过程在容器内完成密钥配置。

内容的提问来源于stack exchange,提问作者Itzik.B

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.26 04:53:14