无法修改Docker镜像仓库URL,拉取镜像仍指向Docker Hub
我是Docker新手,正在学习为Spring Boot应用构建Docker镜像。目前我的Dockerfile非常基础:
# AS <NAME> to name this stage as maven FROM eclipse-temurin:11-jdk-alpine as jdk FROM maven:3.8.4 as maven
我的Docker环境信息:
Client: Context: default Debug Mode: false Server: Containers: 0 Running: 0 Paused: 0 Stopped: 0 Images: 0 Server Version: 20.10.17-ce Storage Driver: btrfs Build Version: Btrfs v4.15 Library Version: 102 Logging Driver: json-file Cgroup Driver: cgroupfs Cgroup Version: 1 Plugins: Volume: local Network: bridge host ipvlan macvlan null overlay Log: awslogs fluentd gcplogs gelf journald json-file local logentries splunk syslog Swarm: inactive Runtimes: io.containerd.runc.v2 io.containerd.runtime.v1.linux oci runc Default Runtime: runc Init Binary: docker-init containerd version: 10c12954828e7c7c9b6e0ea9b0c02b01407d3ae1 runc version: v1.1.4-0-ga916309fff0f init version: Security Options: apparmor seccomp Profile: default Kernel Version: 5.14.21-150400.24.28-default Operating System: openSUSE Leap 15.4 OSType: linux Architecture: x86_64 CPUs: 1 Total Memory: 9.714GiB Name: localhost.localdomain ID: CHSH:Q5ZQ:5MPU:X5MR:FG7M:IFV7:RG5Z:MKNO:KWG6:ZM4L:QX6E:QMNE Docker Root Dir: /var/lib/docker Debug Mode: false Registry: https://index.docker.io/v1/ Labels: Experimental: false Insecure Registries: 127.0.0.0/8 Registry Mirrors: https://MY_DOCKER_URL/ Live Restore Enabled: false
我的/etc/docker/daemon.json配置:
{ "log-level": "warn", "log-driver": "json-file", "log-opts": { "max-size": "10m", "max-file": "5" }, "registry-mirrors": ["https://MY_DOCKER_URL/"] }
其中registry-mirrors是我自行添加的。
我的/usr/lib/systemd/system/docker.service内容:
[Unit] Description=Docker Application Container Engine Documentation=http://docs.docker.com After=network.target lvm2-monitor.service SuSEfirewall2.service [Service] EnvironmentFile=/etc/sysconfig/docker Environment="HTTP_PROXY=MY_COMPANYS_PROXY" Environment="HTTPS_PROXY=MY_COMPANYS_PROXY" Environment="NO_PROXY=localhost,127.0.0.1" # While Docker has support for socket activation (-H fd://), this is not # enabled by default because enabling socket activation means that on boot your # containers won't start until someone tries to administer the Docker daemon. Type=notify ExecStart=/usr/bin/dockerd --add-runtime oci=/usr/sbin/docker-runc $DOCKER_NETWORK_OPTIONS $DOCKER_OPTS ExecReload=/bin/kill -s HUP $MAINPID # Having non-zero Limit*s causes performance problems due to accounting overhead # in the kernel. We recommend using cgroups to do container-local accounting. LimitNOFILE=1048576 LimitNPROC=infinity LimitCORE=infinity # Uncomment TasksMax if your systemd version supports it. # Only systemd 226 and above support this property. TasksMax=infinity # Set delegate yes so that systemd does not reset the cgroups of docker containers # Only systemd 218 and above support this property. Delegate=yes # Kill only the docker process, not all processes in the cgroup. KillMode=process # Restart the docker process if it exits prematurely. Restart=on-failure StartLimitBurst=3 StartLimitInterval=60s [Install] WantedBy=multi-user.target
我已执行以下命令登录公司镜像仓库:
sudo docker login -u MY_USERNAME -p MY_PASSWORD MY_CORPORATE_REGISTRY
但执行docker pull或构建镜像时,仍尝试从Docker Hub拉取,出现如下错误:
Sending build context to Docker daemon 547.3kB Step 1/3 : FROM eclipse-temurin:11-jdk-alpine as jdk Get "https://registry-1.docker.io/v2/": net/http: TLS handshake timeout
1. 确保镜像源配置生效
修改daemon.json后必须重启Docker服务,否则配置不会生效:
sudo systemctl daemon-reload sudo systemctl restart docker
重启后执行docker info,检查输出中的Registry Mirrors是否显示你配置的地址,确认没有拼写错误。
2. 调整代理的NO_PROXY列表
你的Docker服务配置了公司代理,如果镜像源地址不在NO_PROXY范围内,可能导致请求被代理拦截。需要将你的镜像源地址MY_DOCKER_URL添加到docker.service的NO_PROXY中:
Environment="NO_PROXY=localhost,127.0.0.1,MY_DOCKER_URL"
修改后重启Docker服务:
sudo systemctl daemon-reload sudo systemctl restart docker
3. 直接指定公司仓库拉取镜像
如果镜像源无法正常代理Docker Hub请求,直接在Dockerfile中指定公司仓库的镜像地址(前提是公司仓库同步了所需镜像):
FROM MY_CORPORATE_REGISTRY/eclipse-temurin:11-jdk-alpine as jdk FROM MY_CORPORATE_REGISTRY/maven:3.8.4 as maven
这样Docker会直接从公司仓库拉取镜像,无需访问Docker Hub。
4. 测试公司仓库的可用性
执行以下命令测试能否正常连接公司镜像仓库:
curl -v https://MY_CORPORATE_REGISTRY/v2/
如果返回200或401(需要认证),说明仓库可访问;如果无法连接,联系公司运维确认仓库地址、权限和网络连通性。
5. 确认登录状态
执行docker login后,检查是否登录成功:
docker info | grep "Username"
或者查看~/.docker/config.json文件,确认其中包含公司仓库的认证信息。
内容的提问来源于stack exchange,提问作者hell_storm2004

