如何限制Docker拉取/推送至特定Registry及免仓库名拉取私有镜像
Great questions! Let's break them down one by one.
To limit Docker to interacting only with your designated registries, you'll need to modify the Docker daemon configuration. Here's how to do it step by step:
- Edit the Docker daemon config file: The default location is
/etc/docker/daemon.json(create it if it doesn't exist). Add theallowed-registriesfield to specify your trusted registries:
If your registry uses HTTP instead of HTTPS, you'll also need to add it to{ "allowed-registries": ["docker-myorganisation.com", "registry.yourcompany.com"] }insecure-registriesto avoid SSL errors:{ "allowed-registries": ["docker-myorganisation.com"], "insecure-registries": ["docker-myorganisation.com"] } - Restart the Docker daemon: Apply the changes by restarting the service. On most Linux systems:
sudo systemctl restart docker - Authenticate for push operations: To push images to your private registry, you'll first need to log in with valid credentials:
docker login docker-myorganisation.com - Verify the restriction: Test by pulling an image from an unallowed registry (e.g.,
docker pull ubuntufrom Docker Hub) – you should receive an error indicating the registry isn't whitelisted.
This configuration enforces that all pull/push operations are limited to the registries you've explicitly allowed.
Absolutely! You can set up Docker to automatically pull images from your private registry when using short image names (like alpine instead of docker-myorganisation.com/alpine). Here are two practical methods:
Method 1: Prioritize Private Registry as a Mirror
Configure Docker to check your private registry first, falling back to Docker Hub only if the image isn't found there:
Edit
/etc/docker/daemon.jsonand add these settings:{ "registry-mirrors": ["https://docker-myorganisation.com"], "add-registry": ["docker-myorganisation.com"] }registry-mirrorstells Docker to use your private registry as the primary source for image pulls.add-registryensures Docker recognizes your registry as a valid, trusted source.
Restart the Docker daemon to apply changes:
sudo systemctl restart docker
Method 2: Force Private Registry Use (Block Docker Hub)
If you want to completely bypass Docker Hub and only pull from your private registry, add the block-registry directive to block Docker Hub (docker.io):
{ "registry-mirrors": ["https://docker-myorganisation.com"], "add-registry": ["docker-myorganisation.com"], "block-registry": ["docker.io"] }
Now any docker pull command for a short image name will only search your private registry.
Key Notes:
- Ensure your private registry contains images with the same names/tags as you'd use from Docker Hub (e.g.,
docker-myorganisation.com/alpine:latestmust exist to pullalpine). - For HTTP registries, remember to include the registry in
insecure-registriesas shown in the first question.
内容的提问来源于stack exchange,提问作者Rahul Sahotay

