如何将Jfrog Debian远程仓库用作Ubuntu软件包仓库并解决证书验证问题
解决Jfrog仓库APT证书验证失败问题
先修正两个明显错误
sources.list中第一条源的仓库名拼写错误:oubuntu-virtual需改为ubuntu-virtual- 你使用的是Ubuntu 18.04(系统代号bionic),但
sources.list里写的是Debian的版本代号stretch,这会导致APT找不到对应版本的软件包,必须替换为bionic和bionic-updates
方法一:导入Jfrog仓库CA证书(推荐,安全合规)
- 从你的Jfrog Artifactory获取根CA证书文件(可在Artifactory设置页下载或联系管理员获取),保存为
myrepo-ca.crt放在Dockerfile同目录下。 - 修改Dockerfile,添加证书导入步骤:
FROM ubuntu:18.04 # 复制修正后的sources.list COPY ./sources.list /etc/apt/ # 导入Jfrog仓库CA证书并更新系统信任列表 COPY ./myrepo-ca.crt /usr/local/share/ca-certificates/ RUN update-ca-certificates # 原有配置步骤不变 ENV DEBIAN_FRONTEND=noninteractive RUN echo "APT::Get::Assume-Yes \"true\";" > /etc/apt/apt.conf.d/90assumeyes RUN apt-get update && apt-get install -y --no-install-recommends \ ca-certificates \ curl \ wget \ jq \ git \ iputils-ping \ libcurl4 \ libicu60 \ libunwind8 \ netcat \ telnet \ libssl1.0 \ python \ python3 \ nodejs \ python3-setuptools \ python3-pip \ vim \ openjdk-11-jdk-headless \ gnupg \ make \ yarn\ apt-transport-https \ lsb-release \ && rm -rf /var/lib/apt/lists/*
- 修正后的
sources.list内容:
deb https://myrepo/artifactory/ubuntu-virtual/ bionic main contrib non-free deb https://myrepo/artifactory/ubuntu-virtual/ bionic-updates main contrib non-free
方法二:临时跳过APT证书验证(仅应急使用,有安全风险)
如果暂时无法获取CA证书,可通过APT配置跳过证书验证,但此操作会降低系统安全性:
- 在Dockerfile中添加如下配置(放在
apt-get update之前):
RUN echo "Acquire::https::myrepo/artifactory/ubuntu-virtual/::Verify-Peer \"false\";" > /etc/apt/apt.conf.d/99-no-verify-peer
- 同样需要先修正
sources.list的拼写和版本代号错误。
内容的提问来源于stack exchange,提问作者Vowneee
相关产品推荐
相关产品推荐

