Openshift 4.x无法拉取仅支持HTTP的Sonatype Nexus镜像,求解决办法
问题原因
OpenShift默认强制使用HTTPS访问镜像仓库,但你的Sonatype Nexus镜像代理仅提供HTTP服务,导致拉取时出现http: server gave HTTP response to HTTPS client错误。Podman可通过sslverify=false跳过HTTPS校验,但OpenShift容器运行时需要单独配置允许HTTP仓库。
解决办法
1. 集群全局允许不安全仓库
适用于需要所有项目都能访问该HTTP仓库的场景:
- 登录集群每个节点,编辑
/etc/crio/crio.conf - 在
[registries.insecure]段添加:registries = ["domain.ca:5000"] - 重启CRI-O服务:
systemctl restart crio
2. 项目级配置(仅目标项目可用)
不想修改集群全局设置时用这个方法:
- 创建
ImageContentSourcePolicy配置文件:apiVersion: operator.openshift.io/v1alpha1 kind: ImageContentSourcePolicy metadata: name: insecure-domain-ca spec: insecureRegistries: - domain.ca:5000 repositoryDigestMirrors: - mirrors: - domain.ca:5000 source: domain.ca:5000 - 应用配置:
该配置会让OpenShift将oc apply -f insecure-domain-ca.yamldomain.ca:5000标记为不安全仓库,允许HTTP访问。
3. GitLab Runner专属配置
如果是OpenShift上的GitLab Runner拉取镜像失败,需调整Runner配置:
- 编辑Runner的
config.toml,在[[runners]]下添加:
若使用OpenShift executor,确保Runner的服务账号拥有镜像拉取权限,同时确认镜像拉取策略已允许不安全仓库。[runners.docker] insecure_registries = ["domain.ca:5000"]
验证
配置完成后,执行以下命令测试镜像拉取:
oc import-image gitlab-runner-helper:ubi-fips-x86_64-v15.8.2 --from=domain.ca:5000/gitlab/gitlab-runner-helper:ubi-fips-x86_64-v15.8.2 --confirm
成功导入则说明配置生效。
内容的提问来源于stack exchange,提问作者uniwinux
相关产品推荐
相关产品推荐

