You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无法推送镜像至OCR容器仓库:租户命名空间training未找到

问题描述

尝试将镜像推送至training compartment下的OCI容器仓库(OCIR)时,Docker返回错误:unknown: Tenant with namespace training not found。

已完成的操作:

  • 确认training compartment处于活跃状态:
oci iam compartment list --all --output table --compartment-id-in-subtree true --query "data [?\"lifecycle-state\" =='ACTIVE'].{Name:name}" | grep training
| training                  |
  • 在training compartment下创建了名为ocr1的容器仓库:
export DISPLAY_NAME=ocr1
oci artifacts container repository create \
  --compartment-id $C \
  --is-public false \
  --display-name $DISPLAY_NAME
  • Docker登录OCIR成功:
cat token | docker login fra.ocir.io --username=${NS}/api.user --password-stdin
Login Succeeded
  • 打标签并推送失败:
docker pull alpine:latest
docker tag alpine:latest fra.ocir.io/training/ocr1/alpine:latest
docker push fra.ocir.io/training/ocr1/alpine:latest
The push refers to repository [fra.ocir.io/training/ocr1/alpine]
7cd52847ad77: Retrying in 1 second
unknown: Tenant with namespace training not found
  • 仅能推送至根compartment(非预期结果):
docker tag alpine:latest fra.ocir.io/$NS/ocr1/alpine:latest
docker push fra.ocir.io/$NS/ocr1/alpine:latest
The push refers to repository [fra.ocir.io/<NS>/ocr1/alpine]
7cd52847ad77: Layer already exists
latest: digest: sha256:e2e16842c9b54d985bf1ef9242a313f36b856181f188de21313820e177002501 size: 528

疑问:为何无法推送至指定的training compartment?


问题原因与解决方法

核心原因

OCIR的镜像标签格式中,第一个位置必须是租户命名空间(Tenant Namespace),而非compartment名称。你错误地将training(compartment名称)放在了租户命名空间的位置,导致系统误认为training是租户命名空间,从而触发报错。

正确的镜像标签格式

OCIR镜像标签的标准格式为:

region.ocir.io/tenant-namespace/compartment-path/repository-name/image:tag

各部分说明:

  • tenant-namespace:你的OCI租户命名空间(即登录命令中使用的${NS}变量)
  • compartment-path:目标compartment的完整路径(若为根compartment的直接子级,路径就是training;若为嵌套子compartment,格式为parent-compartment/sub-compartment)
  • repository-name:已创建的容器仓库名称(此处为ocr1)

针对该场景的正确操作

  1. 使用符合规范的标签格式打镜像:
docker tag alpine:latest fra.ocir.io/${NS}/training/ocr1/alpine:latest
  1. 推送镜像:
docker push fra.ocir.io/${NS}/training/ocr1/alpine:latest

补充说明

  • 之前能推送到根compartment,是因为标签中直接使用了租户命名空间${NS}并省略了compartment路径,系统默认将镜像推送到根compartment下的对应仓库。
  • 仓库创建时通过--compartment-id $C指定了training compartment,因此推送时必须在标签中包含该compartment的路径,才能匹配到对应的仓库位置。

内容的提问来源于stack exchange,提问作者Bjarte Brandt

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.31 15:50:30