Docker构建Python镜像时无法拉取私有GitLab仓库Python库
Let's break down your problem and walk through practical fixes:
The Problem
You're trying to build a Docker image based on continuumio/anaconda3 that integrates your company's private GitLab-hosted Python library CriteoPy. While your host machine can successfully download the library via curl, the Docker build fails at the pip install step with a hostname resolution error: No address associated with hostname for gitlab.criteois.com.
Your Dockerfile
FROM continuumio/anaconda3 RUN apt-get update RUN apt-get install -y curl RUN pip install --upgrade pip RUN pip install https://gitlab.criteois.com/ax-analytics/CriteoPy/repository/pep_8/archive.zip WORKDIR home CMD ["python3", "main.py"]
Error Output
Step 5/7 : RUN pip install https://gitlab.criteois.com/ax-analytics/CriteoPy/repository/pep_8/archive.zip ---> Running in 8f04623ef493 Collecting https://gitlab.criteois.com/ax-analytics/CriteoPy/repository/pep_8/archive.zip Retrying (Retry(total=4, connect=None, read=None, redirect=None, status=None)) after connection broken by 'NewConnectionError('<pip._vendor.urllib3.connection.VerifiedHTTPSConnection object at 0x7f8f926ae0f0>: Failed to establish a new connection: [Errno -5] No address associated with hostname',)': /ax-analytics/CriteoPy/repository/pep_8/archive.zip The command '/bin/sh -c pip install https://gitlab.criteois.com/ax-analytics/CriteoPy/repository/pep_8/archive.zip' returned a non-zero code: 1
Working Host Command
cbslax@cbslax-desktop:~/Documents/DockerCriteoPy$ curl https://gitlab.criteois.com/ax-analytics/CriteoPy/repository/pep_8/archive.zip --output CriteoPy-Pep-8.zip
Fixes to Try
1. Test DNS Resolution in the Container
First, confirm if the Docker container can resolve your private GitLab hostname. Modify your Dockerfile temporarily to add a ping test:
FROM continuumio/anaconda3 RUN apt-get update && apt-get install -y curl iputils-ping RUN ping -c 3 gitlab.criteois.com # Add this to test DNS resolution RUN pip install --upgrade pip RUN pip install https://gitlab.criteois.com/ax-analytics/CriteoPy/repository/pep_8/archive.zip WORKDIR /home CMD ["python3", "main.py"]
If the ping fails, your Docker daemon is using a DNS server that can't access your company's private domain.
2. Use Host DNS for Docker Build
Force the Docker build to use your host machine's DNS settings by passing the --dns flag during build:
docker build --dns $(cat /etc/resolv.conf | grep nameserver | awk '{print $2}' | head -n1) .
This pulls your primary DNS server from the host and uses it for the build container.
For a permanent fix, edit /etc/docker/daemon.json (create it if it doesn't exist) to use your company's DNS servers:
{ "dns": ["<your-company-dns-ip>", "8.8.8.8"] }
Then restart the Docker daemon:
sudo systemctl restart docker
3. Pre-Download the Library and Copy to Image
A reliable workaround is to download the library on your host first, then copy it into the Docker image (avoids container network issues entirely):
- Download the zip on your host (you already have this working):
curl https://gitlab.criteois.com/ax-analytics/CriteoPy/repository/pep_8/archive.zip -o CriteoPy.zip - Update your Dockerfile to copy and install the local file:
FROM continuumio/anaconda3 RUN apt-get update && apt-get install -y curl && pip install --upgrade pip COPY CriteoPy.zip /tmp/CriteoPy.zip # Copy local file to container RUN pip install /tmp/CriteoPy.zip # Install from local zip WORKDIR /home CMD ["python3", "main.py"]
4. Verify GitLab Authentication (If Needed)
Your host curl might be using cached credentials (from GitLab config or system keychain) that the Docker container doesn't have access to. If your repo requires authentication, use build arguments to pass credentials securely:
FROM continuumio/anaconda3 RUN apt-get update && apt-get install -y curl && pip install --upgrade pip ARG GITLAB_USER ARG GITLAB_TOKEN RUN pip install https://${GITLAB_USER}:${GITLAB_TOKEN}@gitlab.criteois.com/ax-analytics/CriteoPy/repository/pep_8/archive.zip WORKDIR /home CMD ["python3", "main.py"]
Build with your GitLab username and personal access token:
docker build --build-arg GITLAB_USER=your-username --build-arg GITLAB_TOKEN=your-personal-token .
内容的提问来源于stack exchange,提问作者Nicolas N

