You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Openshift 4.x无法拉取仅支持HTTP的Sonatype Nexus镜像,求解决办法

问题原因

OpenShift默认强制使用HTTPS访问镜像仓库,但你的Sonatype Nexus镜像代理仅提供HTTP服务,导致拉取时出现http: server gave HTTP response to HTTPS client错误。Podman可通过sslverify=false跳过HTTPS校验,但OpenShift容器运行时需要单独配置允许HTTP仓库。

解决办法

1. 集群全局允许不安全仓库

适用于需要所有项目都能访问该HTTP仓库的场景:

  • 登录集群每个节点,编辑/etc/crio/crio.conf
  • 在[registries.insecure]段添加:
    registries = ["domain.ca:5000"]
    
  • 重启CRI-O服务:
    systemctl restart crio
    

2. 项目级配置(仅目标项目可用)

不想修改集群全局设置时用这个方法:

  • 创建ImageContentSourcePolicy配置文件:
    apiVersion: operator.openshift.io/v1alpha1
    kind: ImageContentSourcePolicy
    metadata:
      name: insecure-domain-ca
    spec:
      insecureRegistries:
      - domain.ca:5000
      repositoryDigestMirrors:
      - mirrors:
        - domain.ca:5000
        source: domain.ca:5000
    
  • 应用配置:
    oc apply -f insecure-domain-ca.yaml
    
    该配置会让OpenShift将domain.ca:5000标记为不安全仓库,允许HTTP访问。

3. GitLab Runner专属配置

如果是OpenShift上的GitLab Runner拉取镜像失败,需调整Runner配置:

  • 编辑Runner的config.toml,在[[runners]]下添加:
    [runners.docker]
      insecure_registries = ["domain.ca:5000"]
    
    若使用OpenShift executor,确保Runner的服务账号拥有镜像拉取权限,同时确认镜像拉取策略已允许不安全仓库。
验证

配置完成后,执行以下命令测试镜像拉取:

oc import-image gitlab-runner-helper:ubi-fips-x86_64-v15.8.2 --from=domain.ca:5000/gitlab/gitlab-runner-helper:ubi-fips-x86_64-v15.8.2 --confirm

成功导入则说明配置生效。

内容的提问来源于stack exchange,提问作者uniwinux

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.28 18:32:46