欢迎您访问程序员文章站本站旨在为大家提供分享程序员计算机编程知识!
您现在的位置是: 首页  >  网络运营

Centos 7中Docker私有仓库的搭建方法

程序员文章站 2023-11-02 09:38:52
系统配置: centos 7 内核 3.10.0-229.20.1.el7.x86_64 , docker version 1.8.2 运行 docker registr...

系统配置: centos 7 内核 3.10.0-229.20.1.el7.x86_64 docker version 1.8.2

运行 docker registry

执行下列命令:

复制代码 代码如下:

docker run /     -d /     --name private_registry  --restart=always /     -e settings_flavour=dev /     -e storage_path=/registry-storage /     -v /data/docker/private-registry/storage:/registry-storage /     -u root /     -p 5000:5000 /     registry:2

如果本地已有registry镜像,它会直接运行,否则它会到docker hub共有仓库下载之后再运行, -v /data/docker/private-registry/storage:/registry-storage 该命令将之后私有仓库的镜像存放到本地。

之后执行:

复制代码 代码如下:

docker tag docker.io/docker:1.8 192.168.100.9:5000/docker:1.8  docker push 192.168.100.9:5000/docker:1.8

这时会报很多错误:

复制代码 代码如下:

fata[0000] error response from daemon: v1 ping attempt failed with error: get : tls: oversized record received with length 20527/.  if this private registry supports only http or https with an unknown ca certificate,please add  `--insecure-registry 192.168.100.9:5000` to the daemon's arguments. in the case of https, if you have access to the registry's ca certificate, no need for the flag; simply place the ca certificate at /etc/docker/certs.d/192.168.100.9:5000/ca.crt

最简单的解决方法是修改 /etc/sysconfig/docker 文件添加 insecure_registry='--insecure-registry 192.168.100.9:5000' , ubuntu 14.04 的配置文件在 /etc/default/docker 在该文件里添加 docker_opts="--insecure-registry 192.168.100.9:5000" ,添加过之后重启 docker ,重新运行 docker registry 即可生效。这样做的缺点是你的私有仓库不安全,其次,其他要下载或者上传镜像的机器都要修改相应的配置文件。

安全的做法是去认证机构购买签名证书,在此我们使用自认证的方式。

自签名认证

首先执行:

复制代码 代码如下:

# mkdir -p certs && openssl req /   -newkey rsa:4096 -nodes -sha256 -keyout certs/domain.key /   -x509 -days 365 -out certs/domain.crt  country name (2 letter code) [au]:cn state or province name (full name) [some-state]:beijing locality name (eg, city) []:beijing organization name (eg, company) [internet widgits pty ltd]:sercxtyf organizational unit name (eg, section) []:it common name (e.g. server fqdn or your name) []:192.168.100.9:5000 email address []:xxx.yyy@ymail.com

生成认证证书和密钥。接下来将刚生成的 certs/domain.crt 复制到 /etc/docker/certs.d/192.168.100.9:5000/ca.crt ,之后重启 docker 并运行:

复制代码 代码如下:

docker run /     -d /     --name private_registry  --restart=always /     -e settings_flavour=dev /     -e storage_path=/registry-storage /     -v /data/docker/private-registry/storage:/registry-storage /     -u root /     -p 5000:5000 /     -v /root/certs:/certs /     -e registry_http_tls_certificate=/certs/domain.crt /     -e registry_http_tls_key=/certs/domain.key /     registry:2

这样之后应该可以成功了吧,于是执行:

# docker push 192.168.100.9:5000/docker:1.8

结果它还是报错了:

复制代码 代码如下:

the push refers to a repository 192.168.100.9:5000/docker:1.8 unable to ping registry endpoint v2 ping attempt failed with error: get : x509: cannot validate certificate for 192.168.100.9 because it doesn't contain any ip sans v1 ping attempt failed with error: get : x509: cannot validate certificate for 192.168.100.9 because it doesn't contain any ip sans

解决方法:修改 /etc/pki/tls/openssl.cnf 配置,在该文件中找到 [ v3_ca ] ,在它下面添加如下内容:

复制代码 代码如下:

[ v3_ca ] # extensions for a typical ca subjectaltname = ip:123.56.157.144

之后再次重启docker,并重新 run registry ,启动成功之后,执行:

复制代码 代码如下:

# docker push 192.168.100.9:5000/docker:1.8  the push refers to a repository [192.168.100.9:5000/docker] (len: 1) 793ab2f3d322: pushed  e1232be51d09: pushed  71ef33d4e0e5: pushed  e9d235d200dc: pushed  3fb9a265fbfc: pushed  9f50b4b1f00b: pushed  413668359dd0: pushed  da0daae25b21: pushed  f4fddc471ec2: pushed  1.8: digest: sha256:28a02a8a50b750a300904b53e802bdf76516d591b2d233ae21cf771b8c776d44 size: 17621

至此,上传终于成功。换台机器下载刚上传的镜像:

复制代码 代码如下:

# docker pull  192.168.100.9:5000/docker:1.8  trying to pull repository 192.168.100.9:5000/docker ... failed unable to ping registry endpoint v2 ping attempt failed with error: get : x509: certificate signed by unknown authority  v1 ping attempt failed with error: get : x509: certificate signed by unknown authority

仔细分析错误信息,发现是没有证书,将在 192.168.100.9 上生成的证书拷贝到相应的目录下 /etc/docker/certs.d/192.168.100.9:5000/ca.crt ,拷贝之后重启 docker ,再次执行:

复制代码 代码如下:

# docker pull  192.168.100.9:5000/docker:1.8  1.8: pulling from docker 9d58b928bc15: pull complete  dbe7e8a7807c: pull complete  ce14982b73d4: pull complete  b9f70905d763: pull complete  b9c93a2fb3cf: pull complete  1321a4d5d3ea: pull complete  5941048a7e27: pull complete  f57edf7c2e71: pull complete  5de2ade00f1b: pull complete  digest: sha256:28a02a8a50b750a300904b53e802bdf76516d591b2d233ae21cf771b8c776d44 status: downloaded newer image for 192.168.100.9:5000/docker:1.8

至此, docker registry 私有仓库安装成功。如果要部署到生产环境还需要进一步的配置,具体可以参考registry configuration reference

以上就是本文的全部内容,希望对大家的学习有所帮助,也希望大家多多支持。