VSCode DevContainer构建Dockerfile失败:OAuth令牌获取超时
Docker CLI构建正常但VSCode Dev Container构建失败(OAuth Token获取超时)
用docker build命令可正常构建镜像、docker run能启动容器,但通过VSCode DevContainer插件执行「重新在容器中打开文件夹」时构建失败,报错信息如下:
=> ERROR resolve image config for docker.io/docker/dockerfile:1.4 ERROR: failed to solve: rpc error: code = Unknown desc = failed to solve with frontend dockerfile.v0: failed to solve with frontend gateway.v0: failed to authorize: rpc error: code = Unknown desc = failed to fetch oauth token: Post "https://auth.docker.io/token": dial tcp 16.214.118.28:443: i/o timeout
已尝试docker logout和docker login操作,问题未解决。当前使用的Dockerfile内容:
FROM python:3.10-slim-buster ENV http_proxy "http://web-proxy.myorg.net:8080" ENV https_proxy "http://web-proxy.myorg.net:8080" ENV no_proxy "127.0.0.1,localhost" ENV PYTHONPATH "${PYTHONPATH}:/workspaces/automation/test/" COPY test/poetry.lock test/pyproject.toml test/requirements.txt /tmp/ RUN python -m pip install poetry \ && poetry config virtualenvs.create false \ && cd /tmp \ && poetry install \ && rm -f /tmp/poetry.lock /tmp/pyproject.toml \ && pip install -r /tmp/requirements.txt RUN apt update \ && apt install iputils-ping -y \ && apt install git -y \ && apt install curl -y WORKDIR /automation/
解决方法
1. 为Dev Container单独配置代理
VSCode Dev Container构建不会自动继承Docker CLI的代理设置,需在项目.devcontainer目录下配置:
- 创建/修改
devcontainer.json,添加代理参数:
{ "build": { "args": { "HTTP_PROXY": "http://web-proxy.myorg.net:8080", "HTTPS_PROXY": "http://web-proxy.myorg.net:8080", "NO_PROXY": "127.0.0.1,localhost" } }, "remoteEnv": { "HTTP_PROXY": "http://web-proxy.myorg.net:8080", "HTTPS_PROXY": "http://web-proxy.myorg.net:8080", "NO_PROXY": "127.0.0.1,localhost" } }
- 修改Dockerfile,在
FROM指令前添加代理变量声明(确保构建前端流程能获取代理):
ARG HTTP_PROXY ARG HTTPS_PROXY ARG NO_PROXY ENV http_proxy=${HTTP_PROXY} ENV https_proxy=${HTTPS_PROXY} ENV no_proxy=${NO_PROXY} FROM python:3.10-slim-buster # 原有Dockerfile内容...
2. 配置Docker守护进程代理
Dev Container构建依赖Docker daemon,需确保守护进程已配置代理:
- 编辑Docker daemon配置文件(Linux路径为
/etc/docker/daemon.json,Windows/macOS在Docker Desktop设置中找到对应选项):
{ "proxies": { "default": { "httpProxy": "http://web-proxy.myorg.net:8080", "httpsProxy": "http://web-proxy.myorg.net:8080", "noProxy": "127.0.0.1,localhost,docker.io" } } }
- 重启Docker守护进程:
- Linux:执行
sudo systemctl restart docker - Windows/macOS:在Docker Desktop中重启应用
- Linux:执行
3. 临时禁用Docker BuildKit
错误涉及BuildKit前端流程,可尝试禁用该功能:
- 在
devcontainer.json中添加禁用参数:
{ "build": { "dockerfile": "Dockerfile", "options": ["--no-cache", "--progress=plain", "--build-arg BUILDKIT_INLINE_CACHE=0"] }, "runArgs": ["--env", "DOCKER_BUILDKIT=0"] }
或直接在Docker Desktop设置中关闭BuildKit选项。
4. 检查公司代理/防火墙规则
确认公司代理允许访问auth.docker.io(对应IP 16.214.118.28)的443端口,若有白名单限制,需将该域名加入允许列表。
内容的提问来源于stack exchange,提问作者Samselvaprabu
相关产品推荐
相关产品推荐

