ARM架构下基于Ubuntu 23.10的Docker镜像构建失败,添加--privileged启动容器可正常运行
看起来你在ARM架构上用Ubuntu 23.10(代号mantic)做基础镜像构建Docker容器时,碰到了APT仓库签名验证的问题,而且只有用--privileged参数启动容器才能正常工作。我来帮你拆解一下这个问题的根源和可行的解决方案。
你遇到的错误信息
W: GPG error: http://ports.ubuntu.com/ubuntu-ports mantic InRelease: At least one invalid signature was encountered. E: The repository 'http://ports.ubuntu.com/ubuntu-ports mantic InRelease' is not signed. N: Updating from such a repository can't be done securely, and is therefore disabled by default. N: See apt-secure(8) manpage for repository creation and user configuration details. W: GPG error: http://ports.ubuntu.com/ubuntu-ports mantic-updates InRelease: At least one invalid signature was encountered. E: The repository 'http://ports.ubuntu.com/ubuntu-ports mantic-updates InRelease' is not signed. N: Updating from such a repository can't be done securely, and is therefore disabled by default. N: See apt-secure(8) manpage for repository creation and user configuration details. W: GPG error: http://ports.ubuntu.com/ubuntu-ports mantic-backports InRelease: At least one invalid signature was encountered. E: The repository 'http://ports.ubuntu.com/ubuntu-ports mantic-backports InRelease' is not signed. N: Updating from such a repository can't be done securely, and is therefore disabled by default. N: See apt-secure(8) manpage for repository creation and user configuration details. W: GPG error: http://ports.ubuntu.com/ubuntu-ports mantic-security InRelease: At least one invalid signature was encountered. E: The repository 'http://ports.ubuntu.com/ubuntu-ports mantic-security InRelease' is not signed. N: Updating from such a repository can't be done securely, and is therefore disabled by default. N: See apt-secure(8) manpage for repository creation and user configuration details. E: Problem executing scripts APT::Update::Post-Invoke 'rm -f /var/cache/apt/archives/*.deb /var/cache/apt/archives/partial/*.deb /var/cache/apt/*.bin || true' E: Sub-process returned an error code
你的Dockerfile内容
FROM ubuntu:23.10 ENV DEBIAN_FRONTEND=noninteractive RUN apt update \ && apt-get -y update \ && apt-get -y upgrade \ && rm -fr /root/.cache/pip/wheels/* \ && rm -fr /tmp/* \ && apt-get clean \ && apt-get autoclean \ && apt-get autoremove
问题根源分析
首先,Ubuntu 23.10是短期支持版本,生命周期只有9个月,到2024年7月就已经停止官方支持(End of Life, EOL)了。官方的ports.ubuntu.com仓库已经把EOL版本的软件源移到了归档服务器,原有的签名密钥也可能已经失效或者不再被信任。
至于为什么--privileged参数能让容器正常运行:特权模式会让容器获得主机的所有系统权限,这可能绕过了APT的某些安全验证机制,或者允许容器访问主机上的某些密钥资源,但这只是临时的 workaround,非常不推荐长期使用——特权模式会极大降低容器的安全性,让容器内的进程能直接操控主机系统。
可行的解决方案
1. 切换到受支持的Ubuntu LTS版本(最推荐)
放弃Ubuntu 23.10,改用长期支持版本比如Ubuntu 24.04 LTS(代号noble)或者22.04 LTS(jammy)。这些版本的软件源会持续维护,签名验证也不会出问题。修改Dockerfile的基础镜像即可:
FROM ubuntu:24.04
2. 修改软件源为归档服务器(必须用23.10时)
如果因为某些原因必须使用Ubuntu 23.10,你需要把软件源替换为官方的归档服务器old-releases.ubuntu.com。在Dockerfile中添加修改源的步骤:
FROM ubuntu:23.10 ENV DEBIAN_FRONTEND=noninteractive # 替换软件源为归档服务器 RUN sed -i 's/ports.ubuntu.com/old-releases.ubuntu.com/g' /etc/apt/sources.list RUN apt update \ && apt-get -y upgrade \ && rm -fr /root/.cache/pip/wheels/* \ && rm -fr /tmp/* \ && apt-get clean \ && apt-get autoclean \ && apt-get autoremove
3. 临时绕过签名验证(不推荐,仅测试用)
如果你只是临时测试,不想修改源或切换版本,可以在apt命令后添加--allow-unauthenticated参数跳过签名验证,但这会让你的容器面临安全风险:
RUN apt update --allow-unauthenticated \ && apt-get -y update --allow-unauthenticated \ && apt-get -y upgrade --allow-unauthenticated \ && rm -fr /root/.cache/pip/wheels/* \ && rm -fr /tmp/* \ && apt-get clean \ && apt-get autoclean \ && apt-get autoremove
备注:内容来源于stack exchange,提问作者Absurd Drama

