MicroK8s中使用ghrc.io镜像出现CreateContainerError问题求助
问题场景
在AWS EC2 t2.medium实例运行MicroK8s时,部署ghcr.io镜像出现CreateContainerError,错误详情:
Error: failed to create containerd container: error unpacking image: failed to extract layer sha256:b9b5285004b8a3: failed to get stream processor for application/vnd.in-toto+json: no processor for media-type: unknown
已通过jmtoken成功拉取镜像,且该镜像在本地Docker环境测试正常。
解决方案
1. 检查并升级containerd版本
旧版本containerd可能未支持application/vnd.in-toto+json媒体类型,先查看当前版本:
microk8s ctr version
若版本低于1.6.x,执行MicroK8s升级命令(可替换为对应稳定版本通道):
sudo snap refresh microk8s --channel=1.27/stable
2. 配置containerd支持该媒体类型
编辑MicroK8s的containerd模板配置文件:
sudo nano /var/snap/microk8s/current/args/containerd-template.toml
在[plugins."io.containerd.grpc.v1.cri".containerd]节点下添加内容处理器配置:
[plugins."io.containerd.grpc.v1.cri".containerd.content] [plugins."io.containerd.grpc.v1.cri".containerd.content.processors] [plugins."io.containerd.grpc.v1.cri".containerd.content.processors."application/vnd.in-toto+json"] type = "io.containerd.tocd.v1"
3. 重启MicroK8s服务
microk8s stop && microk8s start
4. 优化镜像拉取策略(可选)
在Deployment YAML中设置镜像拉取策略为IfNotPresent,避免重复解压已拉取的镜像:
spec: template: spec: containers: - name: your-container-name image: ghcr.io/your-image-path imagePullPolicy: IfNotPresent
原因说明
Docker内置了对in-toto元数据层的处理支持,但MicroK8s默认的containerd配置未注册对应处理器,导致解压包含该类型层的镜像时失败。手动添加处理器后即可兼容这类镜像。
内容的提问来源于stack exchange,提问作者MoonTaeTae

