You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何限制Docker拉取/推送至特定Registry及免仓库名拉取私有镜像

Great questions! Let's break them down one by one.

1. Restricting Docker to Pull/Push Only to Specific Registries

To limit Docker to interacting only with your designated registries, you'll need to modify the Docker daemon configuration. Here's how to do it step by step:

  • Edit the Docker daemon config file: The default location is /etc/docker/daemon.json (create it if it doesn't exist). Add the allowed-registries field to specify your trusted registries:
    {
      "allowed-registries": ["docker-myorganisation.com", "registry.yourcompany.com"]
    }
    
    If your registry uses HTTP instead of HTTPS, you'll also need to add it to insecure-registries to avoid SSL errors:
    {
      "allowed-registries": ["docker-myorganisation.com"],
      "insecure-registries": ["docker-myorganisation.com"]
    }
    
  • Restart the Docker daemon: Apply the changes by restarting the service. On most Linux systems:
    sudo systemctl restart docker
    
  • Authenticate for push operations: To push images to your private registry, you'll first need to log in with valid credentials:
    docker login docker-myorganisation.com
    
  • Verify the restriction: Test by pulling an image from an unallowed registry (e.g., docker pull ubuntu from Docker Hub) – you should receive an error indicating the registry isn't whitelisted.

This configuration enforces that all pull/push operations are limited to the registries you've explicitly allowed.

2. Pulling from Private Registry Without Specifying the Registry Name

Absolutely! You can set up Docker to automatically pull images from your private registry when using short image names (like alpine instead of docker-myorganisation.com/alpine). Here are two practical methods:

Method 1: Prioritize Private Registry as a Mirror

Configure Docker to check your private registry first, falling back to Docker Hub only if the image isn't found there:

  1. Edit /etc/docker/daemon.json and add these settings:

    {
      "registry-mirrors": ["https://docker-myorganisation.com"],
      "add-registry": ["docker-myorganisation.com"]
    }
    
    • registry-mirrors tells Docker to use your private registry as the primary source for image pulls.
    • add-registry ensures Docker recognizes your registry as a valid, trusted source.
  2. Restart the Docker daemon to apply changes:

    sudo systemctl restart docker
    

Method 2: Force Private Registry Use (Block Docker Hub)

If you want to completely bypass Docker Hub and only pull from your private registry, add the block-registry directive to block Docker Hub (docker.io):

{
  "registry-mirrors": ["https://docker-myorganisation.com"],
  "add-registry": ["docker-myorganisation.com"],
  "block-registry": ["docker.io"]
}

Now any docker pull command for a short image name will only search your private registry.

Key Notes:

  • Ensure your private registry contains images with the same names/tags as you'd use from Docker Hub (e.g., docker-myorganisation.com/alpine:latest must exist to pull alpine).
  • For HTTP registries, remember to include the registry in insecure-registries as shown in the first question.

内容的提问来源于stack exchange,提问作者Rahul Sahotay

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 06:45:18