如何在Kubernetes中配置Docker从指定IP的不安全Registry拉取镜像?
Alright, let's walk through exactly how to set up your Kubernetes nodes to pull images from that insecure HTTP registry you mentioned—since this isn't about a private registry (that's a whole other workflow), we just need to tell the container runtime to skip HTTPS checks for that specific IP/port.
The setup depends on which container runtime your Kubernetes nodes are using (Docker Engine or Containerd, the most common options these days), so I'll break down both scenarios:
1. For Nodes Using Docker Engine (dockerd)
If your cluster still uses Docker as the container runtime, here's what to do on each node:
- Locate or create Docker's daemon config file at
/etc/docker/daemon.json. If it doesn't exist, just create a new file. - Add the
insecure-registriesfield with your target IP and port:
Replace{ "insecure-registries": ["192.168.1.100:5000"] }192.168.1.100:5000with your actual registry IP and port. - Restart Docker to apply the changes:
sudo systemctl restart docker - Finally, restart kubelet since it relies on Docker to run containers:
sudo systemctl restart kubelet
2. For Nodes Using Containerd (Modern Kubernetes Default)
Most new Kubernetes clusters (like those deployed with kubeadm, EKS, or GKE) use Containerd instead of Docker. Here's how to configure it:
- First, if you don't have a custom Containerd config yet, generate the default config file:
containerd config default > /etc/containerd/config.toml - Open
/etc/containerd/config.tomlin a text editor and find the[plugins."io.containerd.grpc.v1.cri".registry]section. Add the following config for your insecure registry:
Again, replace the IP/port with your actual registry details.[plugins."io.containerd.grpc.v1.cri".registry] # Add mirror for your insecure registry [plugins."io.containerd.grpc.v1.cri".registry.mirrors] [plugins."io.containerd.grpc.v1.cri".registry.mirrors."192.168.1.100:5000"] endpoint = ["http://192.168.1.100:5000"] # Skip TLS verification for the registry [plugins."io.containerd.grpc.v1.cri".registry.configs] [plugins."io.containerd.grpc.v1.cri".registry.configs."192.168.1.100:5000".tls] insecure_skip_verify = true - Restart Containerd to apply the config:
sudo systemctl restart containerd - Restart kubelet to ensure it picks up the new runtime config:
sudo systemctl restart kubelet
Important Notes
- These configurations are node-specific—you need to apply this change to every node in your cluster that needs to pull images from the insecure registry.
- For managed Kubernetes clusters (like EKS, GKE, AKS), you can't manually edit each node's config directly. Instead, use custom node images or node group initialization scripts to apply these settings during node provisioning.
- To test if it works, log into a node and try pulling an image manually:
- For Docker:
docker pull 192.168.1.100:5000/your-image:tag - For Containerd:
ctr images pull 192.168.1.100:5000/your-image:tag
If this succeeds without HTTPS-related errors, your config is working.
- For Docker:
内容的提问来源于stack exchange,提问作者BlueMagma

