You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何从GitHub拉取Docker镜像并在EC2实例中构建镜像?

How to Pull a Docker Image from GitHub (GHCR)

Hey there! Let's break down exactly how to pull a Docker image hosted on GitHub. First, a quick heads-up: GitHub stores container images in their GitHub Container Registry (GHCR)—so that's the registry we'll be interacting with here. Here's your step-by-step guide tailored for your EC2 instance:

  • Step 1: Confirm Docker is installed on your EC2 instance
    First, check if Docker is up and running with this command:

    docker --version
    

    If it's not installed, use your EC2's package manager to set it up:

    • For Amazon Linux: sudo yum install docker -y
    • For Ubuntu: sudo apt install docker.io -y
      Don't forget to start and enable the Docker service so it runs on boot:
    sudo systemctl start docker
    sudo systemctl enable docker
    
  • Step 2: Find your image's GHCR path
    GitHub container images follow this standard format:

    ghcr.io/<your-github-username>/<image-repo-name>:<tag>
    

    For example, if your GitHub username is krish0033 and your image repo is my-web-app tagged latest, the full path would be ghcr.io/krish0033/my-web-app:latest. You can grab this path by visiting your GitHub repo's Packages tab (look in the repo sidebar under "Packages") or checking the repo's README if the image is documented there.

  • Step 3: Log into GHCR (only for private images)
    If the image is private, you'll need to authenticate with a GitHub Personal Access Token (PAT). First, create a PAT in your GitHub account settings with the read:packages permission (this is the only permission needed for pulling private images). Then run this command on your EC2 instance to log in securely:

    echo "<your-github-pat>" | docker login ghcr.io -u <your-github-username> --password-stdin
    

    Using --password-stdin keeps your PAT out of your shell history, which is way safer than typing it directly.

  • Step 4: Pull the image
    Now run the pull command with your image's full GHCR path:

    docker pull ghcr.io/<your-github-username>/<image-repo-name>:<tag>
    

    If you're pulling the latest tag, you can skip the :latest part—Docker will default to it automatically:

    docker pull ghcr.io/<your-github-username>/<image-repo-name>
    
  • Step 5: Verify the pull worked
    Check your local Docker images to confirm the image is now on your EC2 instance:

    docker images
    

    You should see your GitHub-hosted image listed in the output.

Quick Tips

  • Public images: No login required! Just run the docker pull command directly.
  • PAT security: On EC2, avoid hardcoding your PAT in scripts. Store it in AWS Secrets Manager and retrieve it programmatically, or use a temporary environment variable that doesn't get saved.

内容的提问来源于stack exchange,提问作者krish0033

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 07:01:36