You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Docker中更新apt-key列表?解决Dockerfile构建APT报错

Docker构建报错:APT源密钥过期与404问题

我的Dockerfile

FROM  mariadb:10.1.21

COPY mariadb.cnf /etc/mysql/conf.d

RUN apt-get update                                      \
    && apt-get install --assume-yes mariadb-backup-10.1 \
    && rm -rf /var/lib/apt/lists/*

构建报错信息

Get:8 https://repo.percona.com jessie/main amd64 Packages [22.1 kB]
Get:9 http://deb.debian.org jessie/main amd64 Packages [9098 kB]
W: GPG error: http://security.debian.org jessie/updates InRelease: The following signatures were invalid: KEYEXPIRED 1668892417 The following signatures couldn't be verified because the public key is not available: NO_PUBKEY AA8E81B4331F7F50
W: GPG error: http://deb.debian.org jessie-updates InRelease: The following signatures were invalid: KEYEXPIRED 1668891673
W: GPG error: http://deb.debian.org jessie Release: The following signatures were invalid: KEYEXPIRED 1668891673
W: Failed to fetch http://ftp.osuosl.org/pub/mariadb/repo/10.1/debian/dists/jessie/main/binary-amd64/Packages 404 Not Found [IP: 64.50.236.52 80]

E: Some index files failed to download. They have been ignored, or old ones used instead.

疑问

已知本地机器可通过更新密钥列表解决,但不清楚如何在Dockerfile中操作。容器内执行apt-key list发现大量过期密钥,请问是需要在Dockerfile中更新apt-key,还是仅升级顶部的MariaDB镜像版本?


解决方案

核心原因

MariaDB 10.1.21基于Debian Jessie,该系统版本早已停止官方维护,导致:

  • 官方APT源的GPG密钥过期
  • MariaDB 10.1的官方源已下线(出现404错误)

方案选择

优先方案:升级MariaDB镜像版本(强烈推荐)

这是根本解决方法,既能修复构建问题,又能获得安全更新和官方支持:

  • 替换Dockerfile开头的镜像为当前受支持的LTS版本(如10.6、10.11):
FROM mariadb:10.6
  • 新版本中mariadb-backup无需指定版本号,镜像会自动匹配对应版本:
RUN apt-get update \
    && apt-get install --assume-yes mariadb-backup \
    && rm -rf /var/lib/apt/lists/*

临时方案:修复过期密钥与源(不建议长期使用)

如果暂时无法升级,可手动替换为归档源并更新密钥,但这只是权宜之计,镜像仍存在安全风险:
修改后的Dockerfile示例:

FROM mariadb:10.1.21

COPY mariadb.cnf /etc/mysql/conf.d

# 替换Debian Jessie为归档源并更新密钥
RUN echo "deb http://archive.debian.org/debian jessie main" > /etc/apt/sources.list \
    && echo "deb http://archive.debian.org/debian jessie-updates main" >> /etc/apt/sources.list \
    && apt-key adv --keyserver keyserver.ubuntu.com --recv-keys AA8E81B4331F7F50 \
    && apt-key adv --keyserver keyserver.ubuntu.com --recv-keys 8B48AD6246925553 \
    # 替换MariaDB源为归档源
    && echo "deb http://archive.mariadb.org/mariadb-10.1/debian jessie main" > /etc/apt/sources.list.d/mariadb.list \
    && apt-get update \
    && apt-get install --assume-yes mariadb-backup-10.1 \
    && rm -rf /var/lib/apt/lists/*

总结

优先选择升级MariaDB镜像版本,这是最安全可靠的长期解决方案。临时修复仅适用于无法立即升级的紧急场景,不可长期依赖。

内容的提问来源于stack exchange,提问作者Tom

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.10 10:40:28