You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Podman报`tcp: tls: first record does not look like a TLS handshake`错误求助

解决Podman 1.6.4在RHEL7.9构建镜像时的TLS握手错误

针对你遇到的tcp: tls: first record does not look like a TLS handshake错误,结合Podman 1.6.x的旧版本特性,可按以下步骤排查解决:

1. 配置Podman全局代理(覆盖构建与容器运行场景)

Podman 1.6.x核心配置文件为containers.conf,需在其中明确代理参数:

  • 编辑全局配置(影响所有用户):vi /etc/containers/containers.conf
  • 找到[containers]段,添加或修改代理配置:
    [containers]
    http_proxy = "http://你的代理IP:端口"
    https_proxy = "http://你的代理IP:端口"
    no_proxy = "localhost,127.0.0.1,本地内部域名"
    
  • 若仅需当前用户生效,编辑~/.config/containers/containers.conf即可。

2. 单独配置Buildah代理(Podman构建依赖该工具)

老版本Podman的构建功能依赖Buildah,需单独配置其代理:

  • 编辑全局Buildah配置:vi /etc/containers/buildah.conf
  • 在[buildah]段添加代理参数:
    [buildah]
    http_proxy = "http://你的代理IP:端口"
    https_proxy = "http://你的代理IP:端口"
    

3. 构建时直接传递代理参数(临时验证方案)

若全局配置不生效,可在构建命令中通过--build-arg直接传递代理变量,确保构建阶段获取代理信息:

podman build --build-arg http_proxy=http://你的代理IP:port --build-arg https_proxy=http://你的代理IP:port -t 镜像名称 .

4. 排查TLS握手错误核心原因

  • 代理协议匹配:确保https_proxy设置为代理的HTTP地址(而非HTTPS),因为代理转发HTTPS请求使用CONNECT方法,无需代理本身为HTTPS协议。
  • 代理CONNECT权限:检查代理服务器是否允许CONNECT到443端口(镜像仓库的HTTPS端口),若被禁止需联系管理员开放。
  • 仓库TLS信任:拉取私有镜像仓库时,需将仓库CA证书导入系统信任链:
    cp 仓库CA证书.pem /etc/pki/ca-trust/source/anchors/
    update-ca-trust extract
    
  • 临时关闭仓库TLS验证(测试场景用):若为测试需求,可在/etc/containers/registries.conf对应仓库配置中添加insecure = true:
    [[registry]]
    prefix = "docker.io"
    location = "registry-1.docker.io"
    insecure = true
    

5. 重启Podman服务使配置生效

systemctl restart podman.socket podman.service

内容的提问来源于stack exchange,提问作者louis

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.09 00:15:34