无网Ubuntu环境下Docker镜像安装AzureCLI等软件失败求助
无网络Ubuntu环境构建Azure DevOps代理Docker镜像问题
我有一台无网络的Ubuntu机器,需制作预装AzureCLI、Docker、Node.js等软件的Docker镜像作为Azure DevOps构建代理。于是使用一台联网的AKS节点进行镜像构建,将AKS节点的sources.list内容复制到Ubuntu Dockerfile中:
# deb-src http://azure.archive.ubuntu.com/ubuntu/ bionic main restricted ## Major bug fix updates produced after the final release of the ## distribution. deb http://azure.archive.ubuntu.com/ubuntu/ bionic-updates main restricted # deb-src http://azure.archive.ubuntu.com/ubuntu/ bionic-updates main restricted ## N.B. software from this repository is ENTIRELY UNSUPPORTED by the Ubuntu ## team. Also, please note that software in universe WILL NOT receive any ## review or updates from the Ubuntu security team. deb http://azure.archive.ubuntu.com/ubuntu/ bionic universe # deb-src http://azure.archive.ubuntu.com/ubuntu/ bionic universe deb http://azure.archive.ubuntu.com/ubuntu/ bionic-updates universe # deb-src http://azure.archive.ubuntu.com/ubuntu/ bionic-updates universe ## N.B. software from this repository is ENTIRELY UNSUPPORTED by the Ubuntu ## team, and may not be under a free licence. Please satisfy yourself as to ## your rights to use the software. Also, please note that software in ## multiverse WILL NOT receive any review or updates from the Ubuntu ## security team. deb http://azure.archive.ubuntu.com/ubuntu/ bionic multiverse # deb-src http://azure.archive.ubuntu.com/ubuntu/ bionic multiverse deb http://azure.archive.ubuntu.com/ubuntu/ bionic-updates multiverse # deb-src http://azure.archive.ubuntu.com/ubuntu/ bionic-updates multiverse ## N.B. software from this repository may not have been tested as ## extensively as that contained in the main release, although it includes ## newer versions of some applications which may provide useful features. ## Also, please note that software in backports WILL NOT receive any review ## or updates from the Ubuntu security team. deb http://azure.archive.ubuntu.com/ubuntu/ bionic-backports main restricted universe multiverse # deb-src http://azure.archive.ubuntu.com/ubuntu/ bionic-backports main restricted universe multiverse ## Uncomment the following two lines to add software from Canonical's ## 'partner' repository. ## This software is not part of Ubuntu, but is offered by Canonical and the ## respective vendors as a service to Ubuntu users. # deb http://archive.canonical.com/ubuntu bionic partner # deb-src http://archive.canonical.com/ubuntu bionic partner deb http://azure.archive.ubuntu.com/ubuntu/ bionic-security main restricted # deb-src http://azure.archive.ubuntu.com/ubuntu/ bionic-security main restricted deb http://azure.archive.ubuntu.com/ubuntu/ bionic-security universe # deb-src http://azure.archive.ubuntu.com/ubuntu/ bionic-security universe deb http://azure.archive.ubuntu.com/ubuntu/ bionic-security multiverse # deb-src http://azure.archive.ubuntu.com/ubuntu/ bionic-security multiverse
通过COPY ./sources.list /etc/apt/将其加入构建流程后,可成功安装curl、wget等基础软件,但安装AzureCLI、Docker、Node.js时出现curl: (35) OpenSSL SSL_connect: SSL_ERROR_SYSCALL in connection to错误,相关Dockerfile片段如下:
#4-Install AzureCLI RUN curl -LsS https://aka.ms/InstallAzureCLIDeb | bash \ && rm -rf /var/lib/apt/lists/* #7-install node RUN curl -sL https://deb.nodesource.com/setup_11.x | bash - RUN apt-get -y install nodejs RUN npm install #9-install docker daemon inside docker RUN curl -fsSL https://download.docker.com/linux/ubuntu/gpg | gpg --dearmor -o /usr/share/keyrings/docker-archive-keyring.gpg RUN echo \ "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/docker-archive-keyring.gpg] https://download.docker.com/linux/ubuntu \ $(lsb_release -cs) stable" | tee /etc/apt/sources.list.d/docker.list > /dev/null RUN apt-get update RUN apt-get install docker-ce docker-ce-cli containerd.io -y
现寻求无网络环境下成功安装上述软件的方法,或是否存在对应软件的Azure归档源。
解决方案
一、离线预下载所有依赖与安装资源
1. 联网节点预下载操作
- AzureCLI:先下载安装脚本
curl -LsS https://aka.ms/InstallAzureCLIDeb -o install_azurecli.sh,再执行apt-get --download-only install azure-cli下载所有deb依赖包,将脚本和deb包存入本地offline-packages目录。 - Node.js:下载setup脚本
curl -sL https://deb.nodesource.com/setup_11.x -o setup_nodejs.sh,执行apt-get --download-only install nodejs下载依赖deb包。 - Docker:下载GPG密钥
curl -fsSL https://download.docker.com/linux/ubuntu/gpg -o docker.gpg,执行apt-get --download-only install docker-ce docker-ce-cli containerd.io下载所有依赖deb包。
2. Dockerfile离线安装配置
# 复制预下载资源到镜像 COPY ./offline-packages/ /tmp/offline-packages/ # 安装AzureCLI RUN dpkg -i /tmp/offline-packages/azure-cli*.deb \ && bash /tmp/offline-packages/install_azurecli.sh \ && rm -rf /var/lib/apt/lists/* # 安装Node.js RUN bash /tmp/offline-packages/setup_nodejs.sh \ && dpkg -i /tmp/offline-packages/nodejs*.deb \ && npm install # 安装Docker RUN gpg --dearmor /tmp/offline-packages/docker.gpg -o /usr/share/keyrings/docker-archive-keyring.gpg \ && echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/docker-archive-keyring.gpg] http://mirror.azure.cn/docker-ce/linux/ubuntu $(lsb_release -cs) stable" | tee /etc/apt/sources.list.d/docker.list > /dev/null \ && dpkg -i /tmp/offline-packages/docker-ce*.deb /tmp/offline-packages/containerd.io*.deb
二、替换为Azure托管的软件源
1. AzureCLI的Azure源
替换为微软官方Azure镜像源,避免外部SSL连接问题:
RUN echo "deb [arch=$(dpkg --print-architecture)] http://packages.microsoft.com/repos/azure-cli/ bionic main" | tee /etc/apt/sources.list.d/azure-cli.list RUN curl -fsSL http://packages.microsoft.com/keys/microsoft.asc | gpg --dearmor -o /etc/apt/trusted.gpg.d/microsoft.gpg RUN apt-get update && apt-get install -y azure-cli
2. Docker的Azure镜像源
使用Azure国内镜像源替代官方源:
RUN echo \ "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/docker-archive-keyring.gpg] http://mirror.azure.cn/docker-ce/linux/ubuntu \ $(lsb_release -cs) stable" | tee /etc/apt/sources.list.d/docker.list > /dev/null RUN apt-get update && apt-get install docker-ce docker-ce-cli containerd.io -y
3. Node.js的Azure镜像源
修改setup脚本中的源地址为Azure镜像源http://mirror.azure.cn/nodesource/deb/,或直接下载对应版本deb包离线安装。
三、构建流程优化
- 合并多个
RUN命令,减少镜像层数,避免重复执行apt-get update。 - 复制
sources.list后先执行apt-get update,再进行后续安装操作。 - 最终无网络构建时,使用
docker build --network none验证是否完全离线可用。
内容的提问来源于stack exchange,提问作者Vowneee
相关产品推荐
相关产品推荐

