You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在Alpine容器执行go get download时如何解决x509证书未知权威错误?

解决CoreDNS Docker构建时的x509证书验证错误

我尝试用以下Dockerfile从头构建CoreDNS:

FROM golang:alpine
SHELL [ "/bin/sh", "-ec" ]

RUN apk update && apk add --no-cache git make ca-certificates openssl && update-ca-certificates
RUN  git clone https://github.com/coredns/coredns.git
WORKDIR /go/coredns
RUN go get download
RUN make

执行命令docker build --no-cache --progress=plain -t coredns .时,在RUN go get download步骤出现错误:

#8 [5/6] RUN go get download
#8 sha256:b2878fe66127be7ffe2e7f4e1f6b538679aebda0abffdd20b14bf928ef23957f
#8 3.603 go: cloud.google.com/go/compute@v1.14.0: Get \"https://proxy.golang.org/cloud.google.com/go/compute/@v/v1.14.0.mod\": x509: certificate signed by unknown authority
#8 ERROR: executor failed running [/bin/sh -ec go get download]: exit code: 1
------
 > [5/6] RUN go get download:
------
executor failed running [/bin/sh -ec go get download]: exit code: 1

以下是几个可行的解决方案:

  • 禁用Go模块代理
    报错源于Go无法验证proxy.golang.org的SSL证书,直接禁用代理让Go从源码仓库拉取依赖即可。修改Dockerfile,在go get download前添加环境变量:

    FROM golang:alpine
    SHELL [ "/bin/sh", "-ec" ]
    
    RUN apk update && apk add --no-cache git make ca-certificates openssl && update-ca-certificates
    RUN git clone https://github.com/coredns/coredns.git
    WORKDIR /go/coredns
    
    # 绕过Go模块代理,直接拉取源码
    ENV GOPROXY=direct
    RUN go get download
    RUN make
    
  • 添加自定义CA证书(企业代理场景)
    如果你的网络使用了企业HTTPS代理,需要将代理的CA证书导入容器的信任列表:

    1. 将代理的CA证书(比如proxy-ca.crt)放在Dockerfile同一目录下
    2. 修改Dockerfile:
    FROM golang:alpine
    SHELL [ "/bin/sh", "-ec" ]
    
    # 复制本地CA证书到容器
    COPY proxy-ca.crt /usr/local/share/ca-certificates/
    RUN apk update && apk add --no-cache git make ca-certificates openssl \
        && update-ca-certificates
    
    RUN git clone https://github.com/coredns/coredns.git
    WORKDIR /go/coredns
    RUN go get download
    RUN make
    
  • 切换到Debian基础的Go镜像
    Alpine的CA证书配置偶尔会有兼容性问题,换成Debian系的golang:latest镜像,其证书管理机制更稳定:

    FROM golang:latest
    SHELL [ "/bin/sh", "-ec" ]
    
    RUN apt-get update && apt-get install -y git make
    RUN git clone https://github.com/coredns/coredns.git
    WORKDIR /go/coredns
    RUN go get download
    RUN make
    

内容的提问来源于stack exchange,提问作者Chris Edwards

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.04 22:20:40