You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure App Service通过GitHub Action拉取Docker Hub私有镜像权限被拒

Azure App Service容器部署权限拒绝问题解决方案

问题背景

使用以下GitHub Action YAML配置部署容器到Azure App Service时,流水线执行成功,但Azure日志流出现拉取镜像权限拒绝错误:

GitHub Action配置

name: Build and deploy container app to Azure Web App - dev-MasterBackend

on:
  push:
    branches:
      - dev
  workflow_dispatch:

jobs:
  build:
    runs-on: 'ubuntu-latest'

    steps:
      - uses: actions/checkout@v2

      - name: Set up Docker Buildx
        uses: docker/setup-buildx-action@v1

      - name: Log in to registry
        uses: docker/login-action@v1
        with:
          registry: https://index.docker.io/v1/
          username: ${{ secrets.AzureAppService_ContainerUsername_5c13827d32e9418391a1f094e5723b88 }}
          password: ${{ secrets.AzureAppService_ContainerPassword_a90eeb6bc307427f8a87ea0961dffdb9 }}

      - name: build the docker image
        run: docker-compose -f docker-compose.yml -f docker-compose.dev.yml build

      - name: docker push 
        run: docker push curiousa/masterbackend:curio-master

  deploy:
    runs-on: ubuntu-latest
    needs: build
    environment:
      name: 'production'
      url: ${{ steps.deploy-to-webapp.outputs.webapp-url }}

    steps:   
      - name: Deploy to Azure Web App
        id: deploy-to-webapp
        uses: azure/webapps-deploy@v2
        with:
          app-name: 'dev-MasterBackend'
          slot-name: 'production'
          publish-profile: ${{ secrets.AzureAppService_PublishProfile_c97a2c2da444408dadd0ab1ca26f78e4 }}
          images: 'index.docker.io/${{ secrets.AzureAppService_ContainerUsername_5c13827d32e9418391a1f094e5723b88 }}/curiousa/masterbackend:curio-master'

Azure日志错误

2023-02-05T18:56:39.502Z ERROR - Pulling docker image index.docker.io/abhijeetcurio/curiousa/masterbackend:curio-master failed:
2023-02-05T18:56:41.356Z ERROR - DockerApiException: Docker API responded with status code=NotFound, response={"message":"pull access denied for abhijeetcurio/curiousa/masterbackend, repository does not exist or may require 'docker login': denied: requested access to the resource is denied"}

错误分析

  1. 镜像路径错误:日志中显示的镜像路径index.docker.io/abhijeetcurio/curiousa/masterbackend存在层级错误,Docker Hub镜像的正确格式应为index.docker.io/<用户名>/<镜像名>:<标签>,这里错误地拼接了两次用户名(abhijeetcurio和curiousa),导致镜像不存在。
  2. Azure拉取私有镜像缺少凭据:即使GitHub Action推送镜像成功,Azure App Service拉取私有Docker Hub镜像时,需要单独配置注册表登录凭据,仅通过publish-profile无法提供容器注册表的访问权限。

解决步骤

1. 修正镜像路径配置

  • 检查docker-compose.yml或docker-compose.dev.yml中的image字段,确保构建后的镜像tag为curiousa/masterbackend:curio-master(假设curiousa是你的Docker Hub用户名)。
  • 修改GitHub Action部署步骤中的images参数,去掉多余的用户名拼接:
    images: 'index.docker.io/curiousa/masterbackend:curio-master'
    
    或直接使用短格式:
    images: 'curiousa/masterbackend:curio-master'
    

2. 配置Azure App Service容器注册表凭据

在Azure门户中操作:

  • 进入目标App Service -> 配置 -> 应用程序设置
  • 添加以下三个应用设置:
    • DOCKER_REGISTRY_SERVER_URL: https://index.docker.io/v1/
    • DOCKER_REGISTRY_SERVER_USERNAME: 你的Docker Hub用户名(对应GitHub Secrets中的AzureAppService_ContainerUsername_xxx值)
    • DOCKER_REGISTRY_SERVER_PASSWORD: 你的Docker Hub密码(对应GitHub Secrets中的AzureAppService_ContainerPassword_xxx值)
  • 保存设置,重启App Service。

3. 验证镜像推送状态

登录Docker Hub,确认curiousa/masterbackend:curio-master镜像已成功推送,且镜像权限设置正确(如果是私有镜像,确保所用用户名拥有拉取权限)。

4. 重新触发部署

手动触发GitHub Action流水线,或推送代码到dev分支,验证Azure App Service是否能正常拉取并启动容器。

内容的提问来源于stack exchange,提问作者Abhijeet Srivastava

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.01 17:40:25