You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

K8s集群containerd运行时拉取不安全HTTP镜像仓库报错如何解决

报错根因

containerd作为容器运行时默认强制所有镜像仓库走HTTPS协议,你部署的私有仓库为HTTP非安全模式,没有被containerd加入信任列表,因此访问被拦截。

修复步骤

你需要在所有Kubernetes工作节点上完成以下配置:

1. 生成/修改containerd配置文件

默认配置文件路径为/etc/containerd/config.toml,如果不存在先执行以下命令生成默认配置:

mkdir -p /etc/containerd
containerd config default > /etc/containerd/config.toml

编辑配置文件,定位到[plugins."io.containerd.grpc.v1.cri".registry]配置块,替换为以下内容,注意替换为你自己的私有仓库地址1.1.1.2:4657:

[plugins."io.containerd.grpc.v1.cri".registry]
  config_path = ""
  [plugins."io.containerd.grpc.v1.cri".registry.mirrors]
    # 配置私有仓库镜像源端点为HTTP地址
    [plugins."io.containerd.grpc.v1.cri".registry.mirrors."1.1.1.2:4657"]
      endpoint = ["http://1.1.1.2:4657"]
  # 跳过私有仓库的TLS证书校验
  [plugins."io.containerd.grpc.v1.cri".registry.configs."1.1.1.2:4657".tls]
    insecure_skip_verify = true

2. 重启containerd服务生效

systemctl daemon-reload
systemctl restart containerd

3. 验证配置有效性

使用crictl工具在节点上测试镜像拉取:

crictl pull 1.1.1.2:4657/82d4bb7b89/dockerimages/abc:v2.3.0

拉取成功则说明配置生效,之后通过kubectl create -f创建Pod即可正常拉取镜像。

附加说明

如果你的私有仓库配置了身份认证,需要额外在上述registry配置块中添加auth配置,或者为Pod关联对应仓库的ImagePullSecret。


内容的提问来源于stack exchange,提问作者Dilip

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.04 23:42:03