Azure App Service通过GitHub Action拉取Docker Hub私有镜像权限被拒
问题背景
使用以下GitHub Action YAML配置部署容器到Azure App Service时,流水线执行成功,但Azure日志流出现拉取镜像权限拒绝错误:
GitHub Action配置
name: Build and deploy container app to Azure Web App - dev-MasterBackend on: push: branches: - dev workflow_dispatch: jobs: build: runs-on: 'ubuntu-latest' steps: - uses: actions/checkout@v2 - name: Set up Docker Buildx uses: docker/setup-buildx-action@v1 - name: Log in to registry uses: docker/login-action@v1 with: registry: https://index.docker.io/v1/ username: ${{ secrets.AzureAppService_ContainerUsername_5c13827d32e9418391a1f094e5723b88 }} password: ${{ secrets.AzureAppService_ContainerPassword_a90eeb6bc307427f8a87ea0961dffdb9 }} - name: build the docker image run: docker-compose -f docker-compose.yml -f docker-compose.dev.yml build - name: docker push run: docker push curiousa/masterbackend:curio-master deploy: runs-on: ubuntu-latest needs: build environment: name: 'production' url: ${{ steps.deploy-to-webapp.outputs.webapp-url }} steps: - name: Deploy to Azure Web App id: deploy-to-webapp uses: azure/webapps-deploy@v2 with: app-name: 'dev-MasterBackend' slot-name: 'production' publish-profile: ${{ secrets.AzureAppService_PublishProfile_c97a2c2da444408dadd0ab1ca26f78e4 }} images: 'index.docker.io/${{ secrets.AzureAppService_ContainerUsername_5c13827d32e9418391a1f094e5723b88 }}/curiousa/masterbackend:curio-master'
Azure日志错误
2023-02-05T18:56:39.502Z ERROR - Pulling docker image index.docker.io/abhijeetcurio/curiousa/masterbackend:curio-master failed:
2023-02-05T18:56:41.356Z ERROR - DockerApiException: Docker API responded with status code=NotFound, response={"message":"pull access denied for abhijeetcurio/curiousa/masterbackend, repository does not exist or may require 'docker login': denied: requested access to the resource is denied"}
错误分析
- 镜像路径错误:日志中显示的镜像路径
index.docker.io/abhijeetcurio/curiousa/masterbackend存在层级错误,Docker Hub镜像的正确格式应为index.docker.io/<用户名>/<镜像名>:<标签>,这里错误地拼接了两次用户名(abhijeetcurio和curiousa),导致镜像不存在。 - Azure拉取私有镜像缺少凭据:即使GitHub Action推送镜像成功,Azure App Service拉取私有Docker Hub镜像时,需要单独配置注册表登录凭据,仅通过publish-profile无法提供容器注册表的访问权限。
解决步骤
1. 修正镜像路径配置
- 检查
docker-compose.yml或docker-compose.dev.yml中的image字段,确保构建后的镜像tag为curiousa/masterbackend:curio-master(假设curiousa是你的Docker Hub用户名)。 - 修改GitHub Action部署步骤中的
images参数,去掉多余的用户名拼接:
或直接使用短格式:images: 'index.docker.io/curiousa/masterbackend:curio-master'images: 'curiousa/masterbackend:curio-master'
2. 配置Azure App Service容器注册表凭据
在Azure门户中操作:
- 进入目标App Service -> 配置 -> 应用程序设置
- 添加以下三个应用设置:
DOCKER_REGISTRY_SERVER_URL:https://index.docker.io/v1/DOCKER_REGISTRY_SERVER_USERNAME: 你的Docker Hub用户名(对应GitHub Secrets中的AzureAppService_ContainerUsername_xxx值)DOCKER_REGISTRY_SERVER_PASSWORD: 你的Docker Hub密码(对应GitHub Secrets中的AzureAppService_ContainerPassword_xxx值)
- 保存设置,重启App Service。
3. 验证镜像推送状态
登录Docker Hub,确认curiousa/masterbackend:curio-master镜像已成功推送,且镜像权限设置正确(如果是私有镜像,确保所用用户名拥有拉取权限)。
4. 重新触发部署
手动触发GitHub Action流水线,或推送代码到dev分支,验证Azure App Service是否能正常拉取并启动容器。
内容的提问来源于stack exchange,提问作者Abhijeet Srivastava

