Kubernetes Pod出现ErrImagePull求助:本地镜像推送后仍无法拉取
Hey there, let's work through this ErrImagePull issue together—local registry setups can be tricky because of network and configuration gotchas. Here are the key steps to diagnose and fix the problem:
1. Verify Kubernetes Nodes Can Reach the Registry
The biggest mistake here is using localhost:5000 in your Pod's image reference. Remember: localhost on a Kubernetes worker node points to the node itself, not the machine where your registry is running.
- First, find the actual IP address of the machine hosting your registry (run
ip addron that machine to get it, e.g.,192.168.1.100). - Test connectivity from every K8s node (master and workers) by running:
You should get a response likecurl http://<registry-ip>:5000/v2/_catalog{"repositories":["i-a"]}if the registry is reachable.
2. Fix the Image Reference in Your Pod/Deployment YAML
Update your Kubernetes manifest to use the registry's actual IP instead of localhost. For example:
apiVersion: v1 kind: Pod metadata: name: my-app-pod spec: containers: - name: my-app-container image: 192.168.1.100:5000/i-a:latest # Replace with your registry's IP ports: - containerPort: 80
Apply the updated manifest with kubectl apply -f your-file.yaml.
3. Configure Docker/Containerd to Trust the Insecure Registry
By default, Docker rejects unencrypted (HTTP) private registries. You need to tell every K8s node's runtime to trust your registry:
For Docker:
- Edit or create
/etc/docker/daemon.jsonon each node:{ "insecure-registries": ["<registry-ip>:5000"] } - Restart Docker to apply changes:
sudo systemctl restart docker
For Containerd (if your cluster uses it):
Edit /etc/containerd/config.toml, find the [plugins."io.containerd.grpc.v1.cri".registry.configs] section, and add:
[plugins."io.containerd.grpc.v1.cri".registry.configs."<registry-ip>:5000".tls] insecure_skip_verify = true
Then restart containerd: sudo systemctl restart containerd.
4. Check Pod Events for Exact Error Details
Run this command to get granular info about why the image pull is failing:
kubectl describe pod <your-pod-name>
Look at the Events section—common issues here include:
connection refused: Network issue between node and registrymanifest unknown: The image/tag doesn't exist in the registryunauthorized: Permission issue (though your local registry is open by default)
5. Confirm the Image Was Fully Pushed to the Registry
Your push output cuts off at cd7100a7241...—re-run the push command to ensure all layers are uploaded successfully:
sudo docker push localhost:5000/i-a
You should see all layers marked as Pushed or Already exists when it completes.
Start with steps 1 and 2—those are the most frequent fixes for this scenario. If you still run into issues, share the output of kubectl describe pod and we can dig deeper!
内容的提问来源于stack exchange,提问作者TungstenX

