Docker拉取/登录始终使用HTTP而非HTTPS的问题排查
问题:Docker访问私有镜像仓库时强制使用HTTP而非HTTPS
环境与配置
我在VMware上的Ubuntu Live 22.04中安装了Docker 20.10.22,daemon.json配置如下:
{ "registry-mirrors" : [ "https://my-domain.com" ], "insecure-registries": [ ] }
其中https://my-domain.com是部署在另一台机器上的私有镜像仓库。
报错现象
执行docker pull或docker login操作时,Docker始终使用HTTP而非HTTPS,报错如下:
root@root:~# docker pull my-domain.com/example/hello-world Error response from daemon: Get "http://my-domain.com/v2/": dial tcp [::1]:80: connect: connection refused root@root:~# docker login my-domain.com Username: ****** Password: ****** Error response from daemon: Get "http://my-domain.com/v2/": dial tcp [::1]:80: connect: connection refused
Docker Info信息
Client: Context: default Debug Mode: false Plugins: app: Docker App (Docker Inc., v0.9.1-beta3) buildx: Docker Buildx (Docker Inc., v0.9.1-docker) compose: Docker Compose (Docker Inc., v2.14.1) scan: Docker Scan (Docker Inc., v0.23.0) Server: Containers: 1 Running: 1 Paused: 0 Stopped: 0 Images: 2 Server Version: 20.10.22 Storage Driver: overlay2 Backing Filesystem: extfs Supports d_type: true Native Overlay Diff: true userxattr: false Logging Driver: json-file Cgroup Driver: systemd Cgroup Version: 2 Plugins: Volume: local Network: bridge host ipvlan macvlan null overlay Log: awslogs fluentd gcplogs gelf journald json-file local logentries splunk syslog Swarm: inactive Runtimes: io.containerd.runc.v2 io.containerd.runtime.v1.linux runc Default Runtime: runc Init Binary: docker-init containerd version: 9ba4b250366a5ddde94bb7c9d1def331423aa323 runc version: v1.1.4-0-g5fd4c4d init version: de40ad0 Security Options: apparmor seccomp Profile: default cgroupns Kernel Version: 5.15.0-57-generic Operating System: Ubuntu 22.04.1 LTS OSType: linux Architecture: x86_64 CPUs: 1 Total Memory: 1.896GiB Name: suyj ID: HB2H:FWFC:GOZT:K7HR:EFLZ:Z6TM:MJCC:MS3W:EO44:NZ4G:W3WZ:TWGJ Docker Root Dir: /var/lib/docker Debug Mode: false Registry: https://index.docker.io/v1/ Labels: Experimental: false Insecure Registries: 127.0.0.0/8 Registry Mirrors: https://my-domain.com/ Live Restore Enabled: false
问题原因与解决方法
核心原因
- 域名解析错误:报错显示连接
[::1]:80,说明my-domain.com被解析到了本地IPv6回环地址,而非私有仓库所在机器的真实IP。Docker找不到目标HTTPS服务, fallback尝试访问本地HTTP端口(80)导致连接拒绝。 - 镜像仓库配置混淆:
registry-mirrors是用于加速公共仓库(如Docker Hub)的代理配置,不是用来指定私有镜像仓库的。将私有仓库设为mirror会导致所有镜像拉取请求被转发到该地址,同时解析错误加剧了问题。
解决步骤
修正域名解析
编辑/etc/hosts文件,添加私有仓库的IP与域名映射:echo "192.168.x.x my-domain.com" >> /etc/hosts替换
192.168.x.x为私有仓库机器的真实IP。调整Docker daemon配置
修改/etc/docker/daemon.json,移除私有仓库的mirror配置(若无需用它代理公共仓库):{ "insecure-registries": [] }重启Docker服务生效:
systemctl restart docker验证HTTPS连通性
在Ubuntu机器上用curl测试私有仓库的HTTPS服务:curl -v https://my-domain.com/v2/若存在证书信任问题(如自签名证书),可选择:
- 给私有仓库配置受系统信任的SSL证书(推荐生产环境);
- 将私有仓库加入
insecure-registries(仅测试环境使用):
配置后重启Docker服务。{ "insecure-registries": ["my-domain.com"] }
内容的提问来源于stack exchange,提问作者Su_yj
相关产品推荐
相关产品推荐

