You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Dockerfile构建时,AWS CodeArtifact源加载失败问题排查

问题

我们使用AWS CodeArtifact存储软件包,在通过Dockerfile构建Docker镜像时,restore阶段出现无法加载源的失败问题。我们有一个计划部署到AWS Fargate的.NET Web API项目,该项目在Visual Studio 2022中使用Docker可正常运行,但在PowerShell中添加CodeArtifact包后无法构建镜像。我们通过Buildkit传递主机上的NuGet.Config来注入凭证,相关文件及输出如下:

Dockerfile

#See https://aka.ms/containerfastmode to understand how Visual Studio uses this Dockerfile to build your images for faster debugging.

FROM mcr.microsoft.com/dotnet/aspnet:6.0 AS base
WORKDIR /app
EXPOSE 80
ENV ASPNETCORE_URLS=http://+:49151

FROM mcr.microsoft.com/dotnet/sdk:6.0 AS build
WORKDIR /src 
COPY . .

WORKDIR /src
COPY ["Src/Presentation/Project.API/Project.API.csproj", "Src/Presentation/Project.API/"]
RUN --mount=type=cache,id=nuget,target=/root/.nuget/packages \
    --mount=type=secret,id=nugetconfig \
    dotnet restore "Src/Presentation/Project.API/Project.API.csproj" \
    --configfile /run/secrets/nugetconfig

COPY . .
WORKDIR "/src/Src/Presentation/Project.API"
RUN --mount=type=cache,id=nuget,target=/root/.nuget/packages \
    dotnet build "Project.API.csproj" -c Release -o /app/build \
    --no-restore

FROM build AS publish
RUN --mount=type=cache,id=nuget,target=/root/.nuget/packages \
    dotnet publish "Project.API.csproj" -c Release -o /app/publish \
    --no-restore

FROM base AS final
WORKDIR /app
COPY --from=publish /app/publish .
ENTRYPOINT ["dotnet", "Project.API.dll"]

PowerShell构建脚本

docker buildx build --secret id=nugetconfig,src=$HOME\AppData\Roaming\NuGet\NuGet.Config -f "Src\Presentation\Project.API\Dockerfile" -t my-dotnet-image .

错误输出

#14 [build 6/9] RUN --mount=type=cache,id=nuget,target=/root/.nuget/packages    --mount=type=secret,id=nugetconfig  dotnet restore "Src/Presentation/Project.API/Project.API.csproj"    
--configfile /run/secrets/nugetconfig
#14 1.175   Determining projects to restore...
#14 2.504 /src/Src/Presentation/Project.API/Project.API.csproj : error NU1301: Unable to load the service index for source 
https://domain-123456789012.d.codeartifact.us-east-2.amazonaws.com/nuget/repository/v3/index.json.

我们已使用aws codeartifact login命令完成服务认证,当前环境为Windows系统搭配Linux容器,请问遗漏了什么配置?待Dockerfile正常工作后,我们计划使用CDK部署镜像及相关基础设施。

解决方案
  • 检查CodeArtifact凭证有效期:aws codeartifact login生成的凭证默认有效期12小时,过期会导致访问失败。重新执行登录命令生成最新的NuGet.Config:

    aws codeartifact login --tool nuget --repository <你的仓库名> --domain <你的域名> --domain-owner <AWS账号ID>
    
  • 转换NuGet.Config的换行格式:Windows下的NuGet.Config是CRLF换行,Linux容器期望LF格式,可在Dockerfile中添加转换步骤:

    RUN --mount=type=cache,id=nuget,target=/root/.nuget/packages \
        --mount=type=secret,id=nugetconfig \
        cat /run/secrets/nugetconfig | tr -d '\r' > /tmp/NuGet.Config && \
        dotnet restore "Src/Presentation/Project.API/Project.API.csproj" --configfile /tmp/NuGet.Config
    
  • 注入AWS凭证环境变量:部分场景下CodeArtifact需要AWS_ACCESS_KEY_ID、AWS_SECRET_ACCESS_KEY、AWS_SESSION_TOKEN环境变量支持,可通过Buildkit传递:

    1. 修改PowerShell构建命令:
      docker buildx build `
        --secret id=nugetconfig,src=$HOME\AppData\Roaming\NuGet\NuGet.Config `
        --build-arg AWS_ACCESS_KEY_ID=$env:AWS_ACCESS_KEY_ID `
        --build-arg AWS_SECRET_ACCESS_KEY=$env:AWS_SECRET_ACCESS_KEY `
        --build-arg AWS_SESSION_TOKEN=$env:AWS_SESSION_TOKEN `
        -f "Src\Presentation\Project.API\Dockerfile" -t my-dotnet-image .
      
    2. 在Dockerfile的build阶段添加环境变量声明:
      FROM mcr.microsoft.com/dotnet/sdk:6.0 AS build
      ARG AWS_ACCESS_KEY_ID
      ARG AWS_SECRET_ACCESS_KEY
      ARG AWS_SESSION_TOKEN
      ENV AWS_ACCESS_KEY_ID=$AWS_ACCESS_KEY_ID
      ENV AWS_SECRET_ACCESS_KEY=$AWS_SECRET_ACCESS_KEY
      ENV AWS_SESSION_TOKEN=$AWS_SESSION_TOKEN
      
  • 验证NuGet.Config源配置:打开主机上的NuGet.Config,确认CodeArtifact源的配置是否包含正确的认证信息:

    <packageSources>
      <add key="codeartifact" value="https://domain-123456789012.d.codeartifact.us-east-2.amazonaws.com/nuget/repository/v3/index.json" />
    </packageSources>
    <packageSourceCredentials>
      <codeartifact>
        <add key="Username" value="aws" />
        <add key="ClearTextPassword" value="<你的临时token>" />
      </codeartifact>
    </packageSourceCredentials>
    
  • 排查容器网络连通性:在Dockerfile中添加临时命令测试容器到CodeArtifact端点的连通性:

    RUN curl -v https://domain-123456789012.d.codeartifact.us-east-2.amazonaws.com/nuget/repository/v3/index.json
    

    若无法访问,检查Windows主机防火墙、代理设置,或确认容器网络模式是否正常。

内容的提问来源于stack exchange,提问作者Elián Rodríguez

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.24 14:06:19