You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker拉取/登录始终使用HTTP而非HTTPS的问题排查

问题:Docker访问私有镜像仓库时强制使用HTTP而非HTTPS

环境与配置

我在VMware上的Ubuntu Live 22.04中安装了Docker 20.10.22,daemon.json配置如下:

{
  "registry-mirrors" : [
    "https://my-domain.com"
  ],
  "insecure-registries": [
  ]
}

其中https://my-domain.com是部署在另一台机器上的私有镜像仓库。

报错现象

执行docker pull或docker login操作时,Docker始终使用HTTP而非HTTPS,报错如下:

root@root:~# docker pull my-domain.com/example/hello-world
Error response from daemon: Get "http://my-domain.com/v2/": dial tcp [::1]:80: connect: connection refused

root@root:~# docker login my-domain.com
Username: ******
Password: ******
Error response from daemon: Get "http://my-domain.com/v2/": dial tcp [::1]:80: connect: connection refused

Docker Info信息

Client:
 Context:    default
 Debug Mode: false
 Plugins:
  app: Docker App (Docker Inc., v0.9.1-beta3)
  buildx: Docker Buildx (Docker Inc., v0.9.1-docker)
  compose: Docker Compose (Docker Inc., v2.14.1)
  scan: Docker Scan (Docker Inc., v0.23.0)

Server:
 Containers: 1
  Running: 1
  Paused: 0
  Stopped: 0
 Images: 2
 Server Version: 20.10.22
 Storage Driver: overlay2
  Backing Filesystem: extfs
  Supports d_type: true
  Native Overlay Diff: true
  userxattr: false
 Logging Driver: json-file
 Cgroup Driver: systemd
 Cgroup Version: 2
 Plugins:
  Volume: local
  Network: bridge host ipvlan macvlan null overlay
  Log: awslogs fluentd gcplogs gelf journald json-file local logentries splunk syslog
 Swarm: inactive
 Runtimes: io.containerd.runc.v2 io.containerd.runtime.v1.linux runc
 Default Runtime: runc
 Init Binary: docker-init
 containerd version: 9ba4b250366a5ddde94bb7c9d1def331423aa323
 runc version: v1.1.4-0-g5fd4c4d
 init version: de40ad0
 Security Options:
  apparmor
  seccomp
   Profile: default
  cgroupns
 Kernel Version: 5.15.0-57-generic
 Operating System: Ubuntu 22.04.1 LTS
 OSType: linux
 Architecture: x86_64
 CPUs: 1
 Total Memory: 1.896GiB
 Name: suyj
 ID: HB2H:FWFC:GOZT:K7HR:EFLZ:Z6TM:MJCC:MS3W:EO44:NZ4G:W3WZ:TWGJ
 Docker Root Dir: /var/lib/docker
 Debug Mode: false
 Registry: https://index.docker.io/v1/
 Labels:
 Experimental: false
 Insecure Registries:
  127.0.0.0/8
 Registry Mirrors:
  https://my-domain.com/
 Live Restore Enabled: false

问题原因与解决方法

核心原因

  1. 域名解析错误:报错显示连接[::1]:80,说明my-domain.com被解析到了本地IPv6回环地址,而非私有仓库所在机器的真实IP。Docker找不到目标HTTPS服务, fallback尝试访问本地HTTP端口(80)导致连接拒绝。
  2. 镜像仓库配置混淆:registry-mirrors是用于加速公共仓库(如Docker Hub)的代理配置,不是用来指定私有镜像仓库的。将私有仓库设为mirror会导致所有镜像拉取请求被转发到该地址,同时解析错误加剧了问题。

解决步骤

  1. 修正域名解析
    编辑/etc/hosts文件,添加私有仓库的IP与域名映射:

    echo "192.168.x.x my-domain.com" >> /etc/hosts
    

    替换192.168.x.x为私有仓库机器的真实IP。

  2. 调整Docker daemon配置
    修改/etc/docker/daemon.json,移除私有仓库的mirror配置(若无需用它代理公共仓库):

    {
      "insecure-registries": []
    }
    

    重启Docker服务生效:

    systemctl restart docker
    
  3. 验证HTTPS连通性
    在Ubuntu机器上用curl测试私有仓库的HTTPS服务:

    curl -v https://my-domain.com/v2/
    

    若存在证书信任问题(如自签名证书),可选择:

    • 给私有仓库配置受系统信任的SSL证书(推荐生产环境);
    • 将私有仓库加入insecure-registries(仅测试环境使用):
      {
        "insecure-registries": ["my-domain.com"]
      }
      
      配置后重启Docker服务。

内容的提问来源于stack exchange,提问作者Su_yj

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.05 13:50:17