WSL2下SAM CLI使用--use-container构建Lambda报Docker凭据错误
故障场景
- 操作目标:配置AWS SAM CLI用于Lambda函数本地测试,已部署helloworld Python示例函数
- 现象:未添加
--use-container参数时可正常完成构建与校验,添加该参数执行构建时触发报错 - 运行环境:Windows 11主机,Docker Desktop已安装并正常运行,操作在搭载WSL2后端的Ubuntu 20.04子系统内执行
执行构建命令及完整报错输出如下:
mylaptop:~/projects/lambda/lambda-python3.8$ sam build --use-container Starting Build inside a container Your template contains a resource with logical ID "ServerlessRestApi", which is a reserved logical ID in AWS SAM. It could result in unexpected behaviors and is not recommended. Building codeuri: /home/projects/lambda/lambda-python3.8/hello_world runtime: python3.8 metadata: {} architecture: x86_64 functions: HelloWorldFunction <3>init: (15570) ERROR: UtilConnectUnix:467: connect failed 111 Traceback (most recent call last): File "docker/credentials/store.py", line 80, in _execute File "subprocess.py", line 411, in check_output File "subprocess.py", line 512, in run subprocess.CalledProcessError: Command '['/usr/bin/docker-credential-desktop.exe', 'get']' returned non-zero exit status 255. During handling of the above exception, another exception occurred: Traceback (most recent call last): File "docker/auth.py", line 264, in _resolve_authconfig_credstore File "docker/credentials/store.py", line 35, in get File "docker/credentials/store.py", line 93, in _execute docker.credentials.errors.StoreError: Credentials store docker-credential-desktop.exe exited with "". During handling of the above exception, another exception occurred: Traceback (most recent call last): File "samcli/__main__.py", line 12, in <module> File "click/core.py", line 829, in __call__ File "click/core.py", line 782, in main File "click/core.py", line 1259, in invoke File "click/core.py", line 1066, in invoke File "click/core.py", line 610, in invoke File "click/decorators.py", line 73, in new_func File "click/core.py", line 610, in invoke File "samcli/lib/telemetry/metric.py", line 166, in wrapped File "samcli/lib/telemetry/metric.py", line 124, in wrapped File "samcli/lib/utils/version_checker.py", line 41, in wrapped File "samcli/cli/main.py", line 87, in wrapper File "samcli/commands/build/command.py", line 201, in cli File "samcli/commands/build/command.py", line 262, in do_cli File "samcli/commands/build/build_context.py", line 248, in run File "samcli/lib/build/app_builder.py", line 221, in build File "samcli/lib/build/build_strategy.py", line 79, in build File "samcli/lib/build/build_strategy.py", line 89, in _build_functions File "samcli/lib/build/build_strategy.py", line 171, in build_single_function_definition File "samcli/lib/build/app_builder.py", line 654, in _build_function File "samcli/lib/build/app_builder.py", line 819, in _build_function_on_container File "samcli/local/docker/manager.py", line 115, in run File "samcli/local/docker/manager.py", line 85, in create File "samcli/local/docker/manager.py", line 160, in pull_image File "docker/api/image.py", line 396, in pull File "docker/auth.py", line 48, in get_config_header File "docker/auth.py", line 324, in resolve_authconfig File "docker/auth.py", line 235, in resolve_authconfig File "docker/auth.py", line 281, in _resolve_authconfig_credstore docker.errors.DockerException: Credentials store error: StoreError('Credentials store docker-credential-desktop.exe exited with "".') [15567] Failed to execute script __main__

故障根因
WSL2子系统内的Docker配置错误指定了Windows侧的docker-credential-desktop.exe作为凭证存储程序,跨WSL/Windows的Unix socket连接被拒绝(对应报错connect failed 111),导致SAM拉取容器构建镜像时读取凭证失败,进程退出。
注:日志开头关于
ServerlessRestApi是预留逻辑ID的提示为SAM常规警告,不影响构建流程,可忽略。
修复步骤
- 编辑WSL内Docker配置文件,路径为
~/.docker/config.json,删除文件中所有指向docker-credential-desktop.exe的credsStore、credHelpers相关配置项。如果不需要拉取私有镜像仓库资源,配置文件保留空对象即可:
{}
- 执行
docker run hello-world验证WSL与Docker Desktop的连通性,确认可正常拉取、运行公共镜像,无凭证相关报错。 - 回到SAM项目目录,重新执行
sam build --use-container即可完成容器模式构建。
内容的提问来源于stack exchange,提问作者hyphen
相关产品推荐
相关产品推荐

