You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kubernetes Pod出现ErrImagePull求助:本地镜像推送后仍无法拉取

Troubleshooting Kubernetes ErrImagePull with Local Docker Registry

Hey there, let's work through this ErrImagePull issue together—local registry setups can be tricky because of network and configuration gotchas. Here are the key steps to diagnose and fix the problem:

1. Verify Kubernetes Nodes Can Reach the Registry

The biggest mistake here is using localhost:5000 in your Pod's image reference. Remember: localhost on a Kubernetes worker node points to the node itself, not the machine where your registry is running.

  • First, find the actual IP address of the machine hosting your registry (run ip addr on that machine to get it, e.g., 192.168.1.100).
  • Test connectivity from every K8s node (master and workers) by running:
    curl http://<registry-ip>:5000/v2/_catalog
    
    You should get a response like {"repositories":["i-a"]} if the registry is reachable.

2. Fix the Image Reference in Your Pod/Deployment YAML

Update your Kubernetes manifest to use the registry's actual IP instead of localhost. For example:

apiVersion: v1
kind: Pod
metadata:
  name: my-app-pod
spec:
  containers:
  - name: my-app-container
    image: 192.168.1.100:5000/i-a:latest  # Replace with your registry's IP
    ports:
    - containerPort: 80

Apply the updated manifest with kubectl apply -f your-file.yaml.

3. Configure Docker/Containerd to Trust the Insecure Registry

By default, Docker rejects unencrypted (HTTP) private registries. You need to tell every K8s node's runtime to trust your registry:

For Docker:

  1. Edit or create /etc/docker/daemon.json on each node:
    {
      "insecure-registries": ["<registry-ip>:5000"]
    }
    
  2. Restart Docker to apply changes:
    sudo systemctl restart docker
    

For Containerd (if your cluster uses it):

Edit /etc/containerd/config.toml, find the [plugins."io.containerd.grpc.v1.cri".registry.configs] section, and add:

[plugins."io.containerd.grpc.v1.cri".registry.configs."<registry-ip>:5000".tls]
  insecure_skip_verify = true

Then restart containerd: sudo systemctl restart containerd.

4. Check Pod Events for Exact Error Details

Run this command to get granular info about why the image pull is failing:

kubectl describe pod <your-pod-name>

Look at the Events section—common issues here include:

  • connection refused: Network issue between node and registry
  • manifest unknown: The image/tag doesn't exist in the registry
  • unauthorized: Permission issue (though your local registry is open by default)

5. Confirm the Image Was Fully Pushed to the Registry

Your push output cuts off at cd7100a7241...—re-run the push command to ensure all layers are uploaded successfully:

sudo docker push localhost:5000/i-a

You should see all layers marked as Pushed or Already exists when it completes.

Start with steps 1 and 2—those are the most frequent fixes for this scenario. If you still run into issues, share the output of kubectl describe pod and we can dig deeper!

内容的提问来源于stack exchange,提问作者TungstenX

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 09:28:58