You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GitLab Runner拉取自定义Docker镜像失败:权限被拒求助

问题描述

我是GitLab Runner和Docker的新手,正尝试通过CI/CD流水线实现项目自动化。参照旧文章搭建时对Dockerfile和setup.sh做了修改,但在GitLab流水线中遇到如下错误:

Running with gitlab-runner 15.4.0 (43b2dc3d)
on Generic debian wheezy package build runner r1Z1sTLv
Preparing the "docker" executor
Using Docker executor with image generic-package-build-runner:v1 ...
Pulling docker image registry.gitlab.com/gitlab-org/gitlab-runner/gitlab-runner-helper:arm64-43b2dc3d ...
Using docker image sha256:b7934566c48e2f47719fe08bbfb89d92b8ad4181ffdc6592f2a25cefab0c284e for registry.gitlab.com/gitlab-org/gitlab-runner/gitlab-runner-helper:arm64-43b2dc3d with digest registry.gitlab.com/gitlab-org/gitlab-runner/gitlab-runner-helper@sha256:358a57cd8617424239fcfdffd9a47ebca6e72d0dc940c223af2cec95c77f9bbd ...
Pulling docker image generic-package-build-runner:v1 ...
WARNING: Failed to pull image with policy "always": Error response from daemon: pull access denied for generic-package-build-runner, repository does not exist or may require 'docker login': denied: requested access to the resource is denied (manager.go:235:3s)
ERROR: Job failed: failed to pull image "generic-package-build-runner:v1" with specified policies [always]: Error response from daemon: pull access denied for generic-package-build-runner, repository does not exist or may require 'docker login': denied: requested access to the resource is denied (manager.go:235:3s)

我使用以下命令构建Docker镜像:

docker build -t generic-package-build-runner:v1 .

注册GitLab Runner的命令:

gitlab-runner register \
--non-interactive \
--url "SOMEURL" \
--registration-token "SOMETOKEN" \
--description "Generic debian wheezy package build runner" \
--executor "docker" \
--docker-image "generic-package-build-runner:v1"

(SOMEURL和SOMETOKEN已替换为实际内容)

我的Dockerfile:

FROM dockette/wheezy
ADD  setup.sh /opt/  
RUN  /bin/bash /opt/setup.sh

setup.sh:

deb http://archive.debian.org/debian wheezy main contrib non-free
deb http://archive.debian.org/debian-archive/debian-security/ wheezy/updates main contrib non-free
deb [arch=armhf] http://repos.rcn-ee.com/debian/ wheezy main
yes | apt-get update 
yes | apt-get --force-yes install git dh-make build-essential autoconf autotools-dev

gitlab-ci.yml:

# Is performed before the scripts in the stage step
before_script:  
  - source /etc/profile
  - echo "Hello, $GITLAB_USER_LOGIN!"
  - echo "Hello, $GITLAB_USER_PASSWORD"
#  - sudo rm /var/cache/apt/archives/lock
#  - sudo rm /var/lib/dpkg/lock
#  - sudo su
#  - sudo -S su < $password_secret

# Defines stages which are to be executed
stages:  
  - build

# Stage "build"
run-build:  
  stage: build
  script:
#    - apt-get install -y libncurses5-dev libglib2.0-dev libgeoip-dev libtokyocabinet-dev zlib1g-dev libncursesw5-dev libbz2-dev
    - autoreconf -fvi
    - cp COPYING debian/copyright
    - dpkg-buildpackage -us -uc
    - mkdir build
    - mv ../goaccess*.deb build/

  # This stage is only executed for new tags
  only:
    - tags

  # The files which are to be made available in GitLab
  artifacts:
    paths:
      - build/*

已在GitLab注册Runner:
GitLab已注册Runner截图

Docker桌面截图:
Docker桌面截图1
Docker桌面截图2

请求解决GitLab Runner无法拉取自定义Docker镜像的权限问题。


解决方案

1. 确认镜像在Runner节点本地存在

你构建的generic-package-build-runner:v1是本地镜像,GitLab Runner的Docker executor默认会优先从Docker Hub拉取镜像,而非直接使用本地镜像。

  • 登录运行GitLab Runner的机器,执行docker images查看该镜像是否存在。如果不存在,重新运行docker build -t generic-package-build-runner:v1 .构建镜像。
  • 如果Runner和你构建镜像的机器不是同一台,要么把镜像复制到Runner节点,要么将镜像推送到可访问的镜像仓库。

2. 修改Runner配置,优先使用本地镜像

在Runner的配置文件(通常路径为/etc/gitlab-runner/config.toml)中,找到对应Runner的配置段,添加pull_policy = "if-not-present",这样Runner会先检查本地是否有镜像,不存在时再去拉取:

[[runners]]
  name = "Generic debian wheezy package build runner"
  url = "SOMEURL"
  token = "r1Z1sTLv..."
  executor = "docker"
  [runners.docker]
    tls_verify = false
    image = "generic-package-build-runner:v1"
    pull_policy = "if-not-present"  # 添加此行
    privileged = false
    disable_entrypoint_overwrite = false
    oom_kill_disable = false
    disable_cache = false
    volumes = ["/cache"]
    shm_size = 0

修改后重启GitLab Runner:sudo gitlab-runner restart

3. 推送镜像到GitLab Container Registry(推荐)

如果需要多台Runner共享镜像,或Runner是远程机器,推荐将镜像推送到项目的GitLab Container Registry:

  1. 登录GitLab Container Registry:
docker login registry.gitlab.com

(使用GitLab账号密码或个人访问令牌)

  1. 给镜像打标签,格式为registry.gitlab.com/<你的用户名>/<你的项目名>:v1:
docker tag generic-package-build-runner:v1 registry.gitlab.com/<你的用户名>/<你的项目名>:v1
  1. 推送镜像:
docker push registry.gitlab.com/<你的用户名>/<你的项目名>:v1
  1. 修改Runner配置中的镜像地址为推送后的地址,可重新注册Runner或直接编辑config.toml:
gitlab-runner register \
--non-interactive \
--url "SOMEURL" \
--registration-token "SOMETOKEN" \
--description "Generic debian wheezy package build runner" \
--executor "docker" \
--docker-image "registry.gitlab.com/<你的用户名>/<你的项目名>:v1"

4. 检查Runner的Docker权限

确保GitLab Runner用户有权限访问Docker守护进程:

  • 将gitlab-runner用户添加到docker组:sudo usermod -aG docker gitlab-runner
  • 重启GitLab Runner:sudo gitlab-runner restart

内容的提问来源于stack exchange,提问作者Thor

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.10 01:20:38