使用containrrr/watchtower遇401错误及config.json凭证未找到求助
排查Watchtower无法读取私有镜像仓库凭证的问题
本地Docker配置文件确认
99.9%确认Linux虚拟机上已自动生成正确的/root/.docker/config.json,内容如下:
{ "auths": { "https://index.docker.io/v1/": { "auth": "xxxxxx" } } }
错误日志信息
所有私有容器均出现以下错误,尝试用docker exec -it进入容器查看/config目录,但容器内无shell:
time="2023-03-20T21:13:07Z" level=debug msg="Trying to load authentication credentials." container=/svccrscproxy image="pkellner/svccuppercaseproxy:latest" time="2023-03-20T21:13:07Z" level=debug msg="No credentials for pkellner found" config_file=/config.json
Watchtower启动配置
services: watchtower: image: index.docker.io/containrrr/watchtower:latest restart: always volumes: - /var/run/docker.sock:/var/run/docker.sock - /etc/timezone:/etc/timezone:ro - /root/.docker/config.json:/config.json environment: - WATCHTOWER_CLEANUP=true - WATCHTOWER_LABEL_ENABLE=false - WATCHTOWER_INCLUDE_RESTARTING=true - WATCHTOWER_DEBUG=true - WATCHTOWER_TRACE=true - WATCHTOWER_POLL_INTERVAL=30 labels: - "com.centurylinklabs.watchtower.enable=true"
排查方向
- 检查挂载文件权限:执行
ls -l /root/.docker/config.json查看本地文件权限,确保容器内运行用户有读取权限,可尝试将权限改为644(chmod 644 /root/.docker/config.json)。 - 匹配仓库地址格式:当前
config.json中认证地址是https://index.docker.io/v1/,但Docker Hub私有仓库的V2地址应为https://index.docker.io/v2/,尝试修改auths中的地址为https://index.docker.io/v2/或直接https://index.docker.io/。 - 调整挂载路径:Watchtower默认会读取容器内
/root/.docker/config.json,可将挂载配置改为/root/.docker/config.json:/root/.docker/config.json,让程序按默认路径加载凭证。 - 验证auth值有效性:执行
echo "xxxxxx" | base64 -d解码auth字段值,确认格式为用户名:密码,无编码错误。 - 更换稳定版本:
latest版本可能存在兼容问题,尝试指定稳定版本如containrrr/watchtower:1.5.3重新部署测试。
内容的提问来源于stack exchange,提问作者Peter Kellner
相关产品推荐
相关产品推荐

