如何为Drone.io实例添加daemon.json,使流水线镜像适配私有仓库与客户端证书
Got it, let's walk through how to set up a daemon.json for your Drone.io instance to get Docker working with private registries and client certificates. Here's a step-by-step breakdown tailored to your use case:
1. Locate or create the Docker daemon config file
Docker's core config file lives at /etc/docker/daemon.json on most Linux hosts. If it doesn't exist yet, create it with:
sudo touch /etc/docker/daemon.json
2. Populate daemon.json with registry and certificate settings
Open the file in your favorite editor (e.g., sudo nano /etc/docker/daemon.json) and add the config below. This example covers both private registry access and TLS client certificate authentication:
{ "insecure-registries": ["your-private-registry.example.com:5000"], "auths": { "your-private-registry.example.com:5000": {} }, "tls": true, "tlscacert": "/etc/docker/certs.d/your-private-registry.example.com:5000/ca.crt", "tlscert": "/etc/docker/certs.d/your-private-registry.example.com:5000/client.cert", "tlskey": "/etc/docker/certs.d/your-private-registry.example.com:5000/client.key", "tlsverify": true }
Quick notes on the config:
insecure-registries: Only use this if your registry uses HTTP (not HTTPS) or you're testing with a self-signed cert without verification. Omit this if you're using proper TLS withtlsverify.- Certificate setup: First create the certs directory for your registry, then copy your files over:
sudo mkdir -p /etc/docker/certs.d/your-private-registry.example.com:5000 sudo cp /path/to/your/ca.crt /etc/docker/certs.d/your-private-registry.example.com:5000/ sudo cp /path/to/your/client.cert /etc/docker/certs.d/your-private-registry.example.com:5000/ sudo cp /path/to/your/client.key /etc/docker/certs.d/your-private-registry.example.com:5000/ tlsverify: Set totrueto enforce strict TLS validation using your CA certificate.
3. Restart Docker to apply the config
After saving the file, restart the Docker daemon to load the new settings:
sudo systemctl restart docker
You can verify the config is active by running:
docker info
Look for sections like Insecure Registries or TLS Configuration to confirm your settings are loaded correctly.
4. Restart Drone services
Since Drone runs as Docker containers, it needs to pick up the updated Docker daemon config. Restart your Drone server and any runners:
# Restart the main Drone server container sudo docker restart drone-server # If using separate Docker runners, restart those too sudo docker restart drone-runner-docker
5. Test your pipeline
Create a quick test pipeline to ensure Drone can pull from your private registry. Example:
kind: pipeline type: docker name: test-private-registry steps: - name: pull-private-image image: your-private-registry.example.com:5000/your-test-image:latest commands: - echo "Successfully pulled private image!"
If the pipeline runs without "pull access denied" or TLS errors, your setup works.
Critical note for remote runners
If you have Drone runners on separate hosts, repeat steps 1-4 on each runner machine. Each runner relies on its local Docker daemon, so the daemon.json and certificates must be present on every runner host.
内容的提问来源于stack exchange,提问作者Techradar

