Azure应用代理后使用本地Artifactory作为Docker仓库登录失败求助
Environment
- Artifactory 6.0.1 PRO
- Docker version 18.03.1-ce, build 9ee9f40
- Multiple Docker repositories configured in Artifactory, with SAML-based SSO enabled
- Using PATH mode for Docker configuration, with direct Tomcat connection
DOCKER_OPTSset to:--insecure-registry artifactory.foo.internal
Issue
When attempting to login to the Docker registry via docker login artifactory.foo.internal (or specifying port 443), we get the following error regardless of the credentials used:
$ docker login artifactory.foo.internal Username: admin Password: Error response from daemon: Get https://artifactory.foo.internal/v2/: unknown: Unsupported docker repository request for 'v2'
We've tried using artifactory.foo.internal:443 as the registry URL, but the same error occurs.
Let's walk through targeted troubleshooting steps and fixes tailored to your setup:
1. Fix the Docker Login URL (Most Common PATH Mode Pitfall)
In PATH mode, you don't login to the root Artifactory URL—you need to target the specific repository path. For example, if your local Docker repo is mapped to artifactory.foo.internal/docker-local, use this command instead:
docker login artifactory.foo.internal/docker-local
Docker expects the login request to point directly to the repository's path, not the Artifactory root. This is the #1 mistake with PATH mode setups.
2. Verify Artifactory's Docker Repository Configuration
Double-check your repo settings to ensure PATH mode is properly enabled:
- Navigate to Artifactory Admin > Repositories > Docker Repositories
- For each Docker repo, confirm:
- The Repository Path is set correctly (e.g.,
docker-localfor a local repo) - The Docker Access Method is explicitly set to
Path(notPort)
- The Repository Path is set correctly (e.g.,
3. Validate Tomcat Routing Configuration
Since you're using direct Tomcat connectivity, ensure it's properly routing Docker requests:
- Open Tomcat's
conf/server.xmland verify the HTTPS Connector (port 443) has valid SSL certificates and no conflicting rules - Check Artifactory's
context.xml(usually intomcat/webapps/artifactory/META-INF/context.xml) for any routing blocks that might interfere with/v2/or Docker repo paths
4. Correct Artifactory's Base URL
A misconfigured base URL can break PATH mode routing:
- Go to Artifactory Admin > General > Base URL
- Set it to
https://artifactory.foo.internal(matching the URL you use for Docker operations) - Save the setting and restart both Artifactory and Tomcat
5. Exclude Docker Endpoints from SAML SSO
Even though Docker uses basic auth, SAML configurations can sometimes redirect API requests to the login page:
- Go to Artifactory Admin > Security > SSO
- Add these paths to Excluded Paths:
/v2/**,/docker/**(adjust based on your repo paths) - This ensures Docker's basic auth requests aren't intercepted by SAML
6. Fix the Insecure Registry Format
Your DOCKER_OPTS has an extra space before the flag, which might cause issues. Update it to:
DOCKER_OPTS="--insecure-registry artifactory.foo.internal"
Restart the Docker daemon after making this change.
7. Test Connectivity with Curl
Use curl to validate if the repo's /v2/ endpoint is reachable:
curl -u admin:<your-password> https://artifactory.foo.internal/docker-local/v2/
If this returns a 200 OK response, the issue is with your Docker client setup. If it errors out, check Artifactory's artifactory/logs/artifactory.log for detailed error messages about the "Unsupported docker repository request" issue.
Start with step 1 first—it's the quickest fix for most PATH mode login failures. If that doesn't resolve it, work through the other steps to narrow down the root cause.
内容的提问来源于stack exchange,提问作者awm

