无Docker daemon环境下如何用az acr build仅构建镜像暂不推送
解决方案
方案1:使用ACR临时扫描仓库(无需下载镜像到本地)
适合使用ACR内置漏洞扫描能力的场景,全程不需要本地Docker daemon:
- 提前在你的Azure容器注册表中创建专用的临时扫描仓库,该仓库仅存放待验证镜像,不用于业务部署
- 执行构建命令将镜像推送至临时扫描仓库:
az acr build --image scan-temp/hello-world:v1 \ --registry myContainerRegistry008 \ --file Dockerfile . - 等待ACR内置的漏洞扫描完成,确认镜像无需要修复的风险问题
- 扫描通过后,直接在ACR内部复制镜像到正式业务仓库,无需重新构建:
az acr import \ --name myContainerRegistry008 \ --source myContainerRegistry008.azurecr.io/scan-temp/hello-world:v1 \ --image sample/hello-world:v1 - 可定期清理临时扫描仓库中的过期镜像,节约存储成本
方案2:导出镜像tar包到本地扫描
适合使用本地自定义扫描工具的场景,镜像不会先推送到ACR:
- 执行带产物导出参数的ACR构建命令,将构建完成的镜像以tar格式保存到本地,不会自动推送到ACR:
az acr build \ --registry myContainerRegistry008 \ --file Dockerfile \ --output type=tar,dest=./hello-world-v1.tar . - 使用支持直接扫描镜像tar包的工具完成漏洞验证,这类工具运行无需依赖Docker daemon,示例:
trivy image --input ./hello-world-v1.tar - 扫描通过后,将本地tar包直接导入ACR的正式仓库:
az acr import \ --name myContainerRegistry008 \ --source ./hello-world-v1.tar \ --image sample/hello-world:v1
内容的提问来源于stack exchange,提问作者avinash mitta
相关产品推荐
相关产品推荐

