You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kubernetes集群未使用Docker Registry拉取缓存镜像问题排查

问题排查:Kubernetes集群未使用Docker Registry缓存拉取镜像

问题背景

我拥有一个部署在代理后的7节点Kubernetes Worker集群,在集群上部署及扩容应用时消耗大量互联网带宽,因此部署了Docker Registry作为拉取缓存服务器,但应用部署仍未从该Registry拉取镜像,求排查问题根源。

提供的配置信息

Docker daemon.json配置

...
"registry-mirrors": [
  "https://myregistry",
  "https://myregistry:443"
]

Docker版本信息

Client: Docker Engine - Community
 Version:           20.10.5
 API version:       1.40
 Go version:        go1.13.15
 Git commit:        55c4c88
 Built:             Tue Mar  2 20:33:55 2021
 OS/Arch:           linux/amd64
 Context:           default
 Experimental:      true

Server: Docker Engine - Community
 Engine:
  Version:          19.03.14
  API version:      1.40 (minimum version 1.12)
  Go version:       go1.13.15
  Git commit:       5eb3275d40
  Built:            Tue Dec  1 19:19:17 2020
  OS/Arch:          linux/amd64
  Experimental:     false
 containerd:
  Version:          1.4.3
  GitCommit:        269548fa27e0089a8b8278fc4fc781d7f65a939b
 runc:
  Version:          1.0.0-rc92
  GitCommit:        ff819c7e9184c13b7c2607fe6c30ae19403a7aff
 docker-init:
  Version:          0.18.0
  GitCommit:        fec3683

Kubernetes版本信息

Server Version: version.Info{Major:"1", Minor:"18", GitVersion:"v1.18.15", GitCommit:"73dd5c840662bb066a146d0871216333181f4b64", GitTreeState:"clean", BuildDate:"2021-01-13T13:14:05Z", GoVersion:"go1.13.15", Compiler:"gc", Platform:"linux/amd64"

Docker Registry配置

version: 0.1
log:
  fields:
    service: registry
storage:
  cache:
    blobdescriptor: inmemory
  filesystem:
    rootdirectory: /data
http:
  addr: :5000
  headers:
    X-Content-Type-Options: [nosniff]
health:
  storagedriver:
    enabled: true
    interval: 10s
    threshold: 3
proxy:
  remoteurl: https://index.docker.io/v1/

排查方向与解决方案

1. Docker Registry代理API版本不兼容

你的Registry配置中,proxy.remoteurl指向了https://index.docker.io/v1/,但Docker Hub早已废弃v1 API,现在统一使用v2 API。这会导致Registry无法正确代理镜像拉取请求,缓存功能完全失效。

解决步骤:
修改Registry配置文件中的proxy.remoteurl为v2地址:

proxy:
  remoteurl: https://registry-1.docker.io/v2/

重启Registry服务让配置生效。

2. Docker daemon与Registry的协议/端口不匹配

  • Registry配置中监听的是5000端口的HTTP服务,但daemon.json里配置的registry-mirrors用了HTTPS协议(https://myregistry和https://myregistry:443),两者协议/端口不匹配,Docker无法连接到缓存Registry,会直接 fallback 到公网拉取。
  • 同时,若使用HTTP协议访问Registry,需要在daemon.json中添加insecure-registries配置,否则Docker会拒绝访问未加密的私有仓库。

解决步骤:
修改daemon.json配置,统一指向Registry的实际地址,并添加不安全仓库配置:

{
  ...
  "registry-mirrors": [
    "http://myregistry:5000"
  ],
  "insecure-registries": [
    "myregistry:5000"
  ]
}

修改后重启Docker和kubelet服务:

systemctl restart docker
systemctl restart kubelet

验证配置是否生效:执行docker info,查看Registry Mirrors和Insecure Registries字段是否显示正确配置。

3. Kubernetes镜像拉取的配置优先级与运行时检查

  • 若Deployment/Pod的镜像指定了完整仓库地址(如docker.io/nginx:latest),K8s会直接按该地址下发拉取指令,此时依赖Docker daemon的镜像镜像配置自动转发请求到缓存Registry,确保daemon配置已生效。
  • 确认kubelet是否使用Docker作为容器运行时:执行kubectl get nodes -o wide查看CONTAINER-RUNTIME字段,若显示docker://xxx则正常;若使用containerd,需单独配置containerd的镜像镜像,而非Docker daemon的配置。

4. Registry的网络可达性验证

在任意Worker节点上测试能否访问Registry:

curl http://myregistry:5000/v2/_catalog

若返回{"repositories":[]}则说明网络连通正常;若无法访问,需检查:

  • Registry的部署位置是否在集群Worker节点可访问的网络内
  • 集群防火墙/安全组是否放行5000端口的访问
  • 节点的代理配置是否干扰了Registry的访问(比如代理未排除Registry的地址)

内容的提问来源于stack exchange,提问作者naiame

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.31 13:35:19