You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Kubernetes中配置Docker从指定IP的不安全Registry拉取镜像?

Alright, let's walk through exactly how to set up your Kubernetes nodes to pull images from that insecure HTTP registry you mentioned—since this isn't about a private registry (that's a whole other workflow), we just need to tell the container runtime to skip HTTPS checks for that specific IP/port.

The setup depends on which container runtime your Kubernetes nodes are using (Docker Engine or Containerd, the most common options these days), so I'll break down both scenarios:

1. For Nodes Using Docker Engine (dockerd)

If your cluster still uses Docker as the container runtime, here's what to do on each node:

  • Locate or create Docker's daemon config file at /etc/docker/daemon.json. If it doesn't exist, just create a new file.
  • Add the insecure-registries field with your target IP and port:
    {
      "insecure-registries": ["192.168.1.100:5000"]
    }
    
    Replace 192.168.1.100:5000 with your actual registry IP and port.
  • Restart Docker to apply the changes:
    sudo systemctl restart docker
    
  • Finally, restart kubelet since it relies on Docker to run containers:
    sudo systemctl restart kubelet
    

2. For Nodes Using Containerd (Modern Kubernetes Default)

Most new Kubernetes clusters (like those deployed with kubeadm, EKS, or GKE) use Containerd instead of Docker. Here's how to configure it:

  • First, if you don't have a custom Containerd config yet, generate the default config file:
    containerd config default > /etc/containerd/config.toml
    
  • Open /etc/containerd/config.toml in a text editor and find the [plugins."io.containerd.grpc.v1.cri".registry] section. Add the following config for your insecure registry:
    [plugins."io.containerd.grpc.v1.cri".registry]
      # Add mirror for your insecure registry
      [plugins."io.containerd.grpc.v1.cri".registry.mirrors]
        [plugins."io.containerd.grpc.v1.cri".registry.mirrors."192.168.1.100:5000"]
          endpoint = ["http://192.168.1.100:5000"]
      # Skip TLS verification for the registry
      [plugins."io.containerd.grpc.v1.cri".registry.configs]
        [plugins."io.containerd.grpc.v1.cri".registry.configs."192.168.1.100:5000".tls]
          insecure_skip_verify = true
    
    Again, replace the IP/port with your actual registry details.
  • Restart Containerd to apply the config:
    sudo systemctl restart containerd
    
  • Restart kubelet to ensure it picks up the new runtime config:
    sudo systemctl restart kubelet
    

Important Notes

  • These configurations are node-specific—you need to apply this change to every node in your cluster that needs to pull images from the insecure registry.
  • For managed Kubernetes clusters (like EKS, GKE, AKS), you can't manually edit each node's config directly. Instead, use custom node images or node group initialization scripts to apply these settings during node provisioning.
  • To test if it works, log into a node and try pulling an image manually:
    • For Docker: docker pull 192.168.1.100:5000/your-image:tag
    • For Containerd: ctr images pull 192.168.1.100:5000/your-image:tag
      If this succeeds without HTTPS-related errors, your config is working.

内容的提问来源于stack exchange,提问作者BlueMagma

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 11:23:32