You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无网Ubuntu环境下Docker镜像安装AzureCLI等软件失败求助

无网络Ubuntu环境构建Azure DevOps代理Docker镜像问题

我有一台无网络的Ubuntu机器,需制作预装AzureCLI、Docker、Node.js等软件的Docker镜像作为Azure DevOps构建代理。于是使用一台联网的AKS节点进行镜像构建,将AKS节点的sources.list内容复制到Ubuntu Dockerfile中:

# deb-src http://azure.archive.ubuntu.com/ubuntu/ bionic main restricted

## Major bug fix updates produced after the final release of the
## distribution.
deb http://azure.archive.ubuntu.com/ubuntu/ bionic-updates main restricted
# deb-src http://azure.archive.ubuntu.com/ubuntu/ bionic-updates main restricted

## N.B. software from this repository is ENTIRELY UNSUPPORTED by the Ubuntu
## team. Also, please note that software in universe WILL NOT receive any
## review or updates from the Ubuntu security team.
deb http://azure.archive.ubuntu.com/ubuntu/ bionic universe
# deb-src http://azure.archive.ubuntu.com/ubuntu/ bionic universe
deb http://azure.archive.ubuntu.com/ubuntu/ bionic-updates universe
# deb-src http://azure.archive.ubuntu.com/ubuntu/ bionic-updates universe

## N.B. software from this repository is ENTIRELY UNSUPPORTED by the Ubuntu
## team, and may not be under a free licence. Please satisfy yourself as to
## your rights to use the software. Also, please note that software in
## multiverse WILL NOT receive any review or updates from the Ubuntu
## security team.
deb http://azure.archive.ubuntu.com/ubuntu/ bionic multiverse
# deb-src http://azure.archive.ubuntu.com/ubuntu/ bionic multiverse
deb http://azure.archive.ubuntu.com/ubuntu/ bionic-updates multiverse
# deb-src http://azure.archive.ubuntu.com/ubuntu/ bionic-updates multiverse

## N.B. software from this repository may not have been tested as
## extensively as that contained in the main release, although it includes
## newer versions of some applications which may provide useful features.
## Also, please note that software in backports WILL NOT receive any review
## or updates from the Ubuntu security team.
deb http://azure.archive.ubuntu.com/ubuntu/ bionic-backports main restricted universe multiverse
# deb-src http://azure.archive.ubuntu.com/ubuntu/ bionic-backports main restricted universe multiverse

## Uncomment the following two lines to add software from Canonical's
## 'partner' repository.
## This software is not part of Ubuntu, but is offered by Canonical and the
## respective vendors as a service to Ubuntu users.
# deb http://archive.canonical.com/ubuntu bionic partner
# deb-src http://archive.canonical.com/ubuntu bionic partner

deb http://azure.archive.ubuntu.com/ubuntu/ bionic-security main restricted
# deb-src http://azure.archive.ubuntu.com/ubuntu/ bionic-security main restricted
deb http://azure.archive.ubuntu.com/ubuntu/ bionic-security universe
# deb-src http://azure.archive.ubuntu.com/ubuntu/ bionic-security universe
deb http://azure.archive.ubuntu.com/ubuntu/ bionic-security multiverse
# deb-src http://azure.archive.ubuntu.com/ubuntu/ bionic-security multiverse

通过COPY ./sources.list /etc/apt/将其加入构建流程后,可成功安装curl、wget等基础软件,但安装AzureCLI、Docker、Node.js时出现curl: (35) OpenSSL SSL_connect: SSL_ERROR_SYSCALL in connection to错误,相关Dockerfile片段如下:

#4-Install AzureCLI
RUN curl -LsS https://aka.ms/InstallAzureCLIDeb | bash \
  && rm -rf /var/lib/apt/lists/*

#7-install node
RUN curl -sL https://deb.nodesource.com/setup_11.x  | bash -
RUN apt-get -y install nodejs
RUN npm install


#9-install docker daemon inside docker
RUN curl -fsSL https://download.docker.com/linux/ubuntu/gpg |  gpg --dearmor -o /usr/share/keyrings/docker-archive-keyring.gpg
RUN echo \
   "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/docker-archive-keyring.gpg] https://download.docker.com/linux/ubuntu \
   $(lsb_release -cs) stable" | tee /etc/apt/sources.list.d/docker.list > /dev/null
RUN apt-get update
RUN apt-get install docker-ce docker-ce-cli containerd.io -y

现寻求无网络环境下成功安装上述软件的方法,或是否存在对应软件的Azure归档源。


解决方案

一、离线预下载所有依赖与安装资源

1. 联网节点预下载操作

  • AzureCLI:先下载安装脚本curl -LsS https://aka.ms/InstallAzureCLIDeb -o install_azurecli.sh,再执行apt-get --download-only install azure-cli下载所有deb依赖包,将脚本和deb包存入本地offline-packages目录。
  • Node.js:下载setup脚本curl -sL https://deb.nodesource.com/setup_11.x -o setup_nodejs.sh,执行apt-get --download-only install nodejs下载依赖deb包。
  • Docker:下载GPG密钥curl -fsSL https://download.docker.com/linux/ubuntu/gpg -o docker.gpg,执行apt-get --download-only install docker-ce docker-ce-cli containerd.io下载所有依赖deb包。

2. Dockerfile离线安装配置

# 复制预下载资源到镜像
COPY ./offline-packages/ /tmp/offline-packages/

# 安装AzureCLI
RUN dpkg -i /tmp/offline-packages/azure-cli*.deb \
    && bash /tmp/offline-packages/install_azurecli.sh \
    && rm -rf /var/lib/apt/lists/*

# 安装Node.js
RUN bash /tmp/offline-packages/setup_nodejs.sh \
    && dpkg -i /tmp/offline-packages/nodejs*.deb \
    && npm install

# 安装Docker
RUN gpg --dearmor /tmp/offline-packages/docker.gpg -o /usr/share/keyrings/docker-archive-keyring.gpg \
    && echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/docker-archive-keyring.gpg] http://mirror.azure.cn/docker-ce/linux/ubuntu $(lsb_release -cs) stable" | tee /etc/apt/sources.list.d/docker.list > /dev/null \
    && dpkg -i /tmp/offline-packages/docker-ce*.deb /tmp/offline-packages/containerd.io*.deb

二、替换为Azure托管的软件源

1. AzureCLI的Azure源

替换为微软官方Azure镜像源,避免外部SSL连接问题:

RUN echo "deb [arch=$(dpkg --print-architecture)] http://packages.microsoft.com/repos/azure-cli/ bionic main" | tee /etc/apt/sources.list.d/azure-cli.list
RUN curl -fsSL http://packages.microsoft.com/keys/microsoft.asc | gpg --dearmor -o /etc/apt/trusted.gpg.d/microsoft.gpg
RUN apt-get update && apt-get install -y azure-cli

2. Docker的Azure镜像源

使用Azure国内镜像源替代官方源:

RUN echo \
"deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/docker-archive-keyring.gpg] http://mirror.azure.cn/docker-ce/linux/ubuntu \
$(lsb_release -cs) stable" | tee /etc/apt/sources.list.d/docker.list > /dev/null
RUN apt-get update && apt-get install docker-ce docker-ce-cli containerd.io -y

3. Node.js的Azure镜像源

修改setup脚本中的源地址为Azure镜像源http://mirror.azure.cn/nodesource/deb/,或直接下载对应版本deb包离线安装。

三、构建流程优化

  • 合并多个RUN命令,减少镜像层数,避免重复执行apt-get update。
  • 复制sources.list后先执行apt-get update,再进行后续安装操作。
  • 最终无网络构建时,使用docker build --network none验证是否完全离线可用。

内容的提问来源于stack exchange,提问作者Vowneee

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.10 10:15:44