如何解决因UID范围不足导致Docker镜像无法提取的问题?
Node.js镜像构建后拉取失败的问题与解决
错误表现
Azure App Service拉取镜像时错误:
2023-03-31T09:44:59.401Z ERROR - failed to register layer: Error processing tar file(exit status 1): Container ID 2119470584 cannot be mapped to a host IDErr: 0, Message: failed to register layer: Error processing tar file(exit status 1): Container ID 2119470584 cannot be mapped to a host ID
本地机器拉取镜像时错误:
failed to register layer: ApplyLayer exit status 1 stdout: stderr: failed to Lchown "/app/node_modules/external-editor/node_modules/tmp/LICENSE" for UID 2119470584, GID 2042662593 (try increasing the number of subordinate IDs in /etc/subuid and /etc/subgid): lchown /app/node_modules/external-editor/node_modules/tmp/LICENSE: invalid argument
过往临时处理
数月前首次遇到该问题时,曾在Dockerfile最后一步添加以下命令,当时问题暂时解决:
RUN chown -R $(id -u):$(id -g) /app
但不排除当时问题是npm包仓库临时异常导致,并非该命令直接生效。
排查过程
后续定位到问题根源可能出在官方node:18基础镜像上。我们的场景是在Github Actions中为NX Monorepo里的NestJS和NextJS应用构建镜像:
- 基于node:18基础镜像
- 复制源码(含package.json等文件)到镜像内
- 执行
npm ci安装依赖 - 发布镜像到Azure容器注册表
本地构建时发现npm ci输出大量警告:
npm WARN tar TAR_ENTRY_ERROR EINVAL: invalid argument, fchown npm WARN tar TAR_ENTRY_ERROR EINVAL: invalid argument, fchown npm WARN tar TAR_ENTRY_ERROR EINVAL: invalid argument, fchown npm WARN tar TAR_ENTRY_ERROR EINVAL: invalid argument, fchown npm WARN tar TAR_ENTRY_ERROR EINVAL: invalid argument, fchown [...]
命令虽能执行完成,但CI构建日志里的npm ci环节提示npm版本可更新:
added 2896 packages, and audited 3126 packages in 53s 351 packages are looking for funding run `npm fund` for details 1 high severity vulnerability To address all issues, run: npm audit fix Run `npm audit` for details. npm notice npm notice New minor version of npm available! 9.5.0 -> 9.6.3 npm notice Changelog: <https://github.com/npm/cli/releases/tag/v9.6.3> npm notice Run `npm install -g npm@9.6.3` to update!
最终解决
在Dockerfile中npm ci命令前添加npm版本升级命令:
RUN npm install -g npm@9.6.3
重新触发CI构建后,镜像可正常从Azure容器注册表拉取并提取。
内容的提问来源于stack exchange,提问作者dfsg76
相关产品推荐
相关产品推荐

