2016-08-01 45 views
45

私人注册表是基于泊坞窗1.10.3效果不错,但我不能拉/泊坞窗更新至1.12.0后推的图像。不能推/拉更新泊坞窗后的图像,以1.12

我已经修改了的/ etc/SYSCONFIG /泊坞窗为:

OPTIONS='--selinux-enabled=true --insecure-registry=myip:5000' 

OPTIONS='--selinux-enabled=true --insecure-registry myip:5000' 

但是当我exec的推/拉,我得到这个错误:

$ docker pull myip:5000/cadvisor 
Using default tag: latest 
Error response from daemon: Get https://myip:5000/v1/_ping: http: server gave HTTP response to HTTPS client 

当我搬运工变回1.10.3,它仍然运行良好如下:

$ docker pull myip:5000/cadvisor 
Using default tag: latest 
Trying to pull repository myip:5000/cadvisor ... 
latest: Pulling from myip:5000/cadvisor 
09d0220f4043: Pull complete 
a3ed95caeb02: Pull complete 
151807d34af9: Pull complete 
14cd28dce332: Pull complete  
Digest: 
sha256:33b6475cd5b7646b3748097af1224de3eee3ba7cf5105524d95c0cf135f59b47 
Status: Downloaded newer image for myip/cadvisor:latest 

一些相关信息,列举如下:

docker version 
Client: 
Version: 1.12.0 
API version: 1.24 
Go version: go1.6.3 
Git commit: 8eab29e 
Built: 

OS/Arch: linux/amd64 

Server: 
Version: 1.12.0 
API version: 1.24 
Go version: go1.6.3 
Git commit: 8eab29e 
Built: 

OS/Arch: linux/amd64 

docker info 
Containers: 4 
Running: 1 
Paused: 0 
Stopped: 3 
Images: 241 
Server Version: 1.12.0 
Storage Driver: devicemapper 
Pool Name: docker-253:0-6809-pool 
Pool Blocksize: 65.54 kB 
Base Device Size: 107.4 GB 
Backing Filesystem: xfs 
Data file: /dev/loop0 
Metadata file: /dev/loop1 
Data Space Used: 5.459 GB 
Data Space Total: 107.4 GB 
Data Space Available: 34.74 GB 
Metadata Space Used: 9.912 MB 
Metadata Space Total: 2.147 GB 
Metadata Space Available: 2.138 GB 
Thin Pool Minimum Free Space: 10.74 GB 
Udev Sync Supported: true 
Deferred Removal Enabled: false 
Deferred Deletion Enabled: false 
Deferred Deleted Device Count: 0 
Data loop file: /var/lib/docker/devicemapper/devicemapper/data 
WARNING: Usage of loopback devices is strongly discouraged for production use. Use '--storage-opt dm.thinpooldev' to specify a custom block storage device. 
Metadata loop file: /var/lib/docker/devicemapper/devicemapper/metadata 
Library Version: 1.02.107-RHEL7 (2016-06-09) 
Logging Driver: json-file 
Cgroup Driver: cgroupfs 
Plugins: 
Volume: local 
Network: host overlay null bridge 
Swarm: inactive 
Runtimes: runc 
Default Runtime: runc 
Security Options: seccomp 
Kernel Version: 3.10.0-229.el7.x86_64 
Operating System: CentOS Linux 7 (Core) 
OSType: linux 
Architecture: x86_64 
CPUs: 24 
Total Memory: 62.39 GiB 
Name: server_3 
ID: TITS:BL4B:M5FE:CIRO:5SW6:TVIV:HW36:J7OS:WLHF:46T6:2RBA:WCNV 
Docker Root Dir: /var/lib/docker 
Debug Mode (client): false 
Debug Mode (server): true 
File Descriptors: 21 
Goroutines: 32 
System Time: 2016-08-02T10:33:06.414048675+08:00 
EventsListeners: 0 
Registry: https://index.docker.io/v1/ 
WARNING: bridge-nf-call-iptables is disabled 
WARNING: bridge-nf-call-ip6tables is disabled 
Insecure Registries: 
127.0.0.0/8 

docker exec <registry-container> registry -version 
registry github.com/docker/distribution v2.2.1 

我重新启动在调试模式下的泊坞窗守护程序后,重现我的问题时,守护进程会记录如下:

DEBU[0794] Calling POST /v1.24/images/create?fromImage=10.10.10.40%3A5000%2Fcadvisor&tag=latest 
DEBU[0794] hostDir: /etc/docker/certs.d/10.10.10.40:5000 
DEBU[0794] hostDir: /etc/docker/certs.d/10.10.10.40:5000 
DEBU[0794] Trying to pull 10.10.10.40:5000/cadvisor from https://10.10.10.40:5000 v2 
WARN[0794] Error getting v2 registry: Get https://10.10.10.40:5000/v2/: http: server gave HTTP response to HTTPS client 
ERRO[0794] Attempting next endpoint for pull after error: Get https://10.10.10.40:5000/v2/: http: server gave HTTP response to HTTPS client 
DEBU[0794] Trying to pull 10.10.10.40:5000/cadvisor from https://10.10.10.40:5000 v1 
DEBU[0794] hostDir: /etc/docker/certs.d/10.10.10.40:5000 
DEBU[0794] attempting v1 ping for registry endpoint https://10.10.10.40:5000/v1/ 
DEBU[0794] Fallback from error: Get https://10.10.10.40:5000/v1/_ping: http: server gave HTTP response to HTTPS client 
ERRO[0794] Attempting next endpoint for pull after error: Get https://10.10.10.40:5000/v1/_ping: http: server gave HTTP response to HTTPS client 
ERRO[0794] Handler for POST /v1.24/images/create returned error: Get https://10.10.10.40:5000/v1/_ping: http: server gave HTTP response to HTTPS client 
DEBU[1201] clean 2 unused exec commands 

更重要的是,我只是运行一个简单的命令来启动测试私有注册,什么都默认为:

docker run -d -p 5000:5000 --restart=always --name registry -v 'pwd'/data:/var/lib/registry registry:2 

未配置代理。总之,它只是一个安静的测试环境。

+0

好,我也面临同样的错误,但奇怪的是我没有/ etc/sysconfig/docker文件在RHEL 7中,你k现在我可以找到任何类似的文件?这个docker文件的内容是什么?谢谢。 – sai

+0

如果您想更改docker守护程序的运行方式,则此文件包含一些选项。我不知道RHEL7中的确切路径。但是如果使用命令“$ sudo locate docker”执行命令,则会在某处找到该文件 – yuxiaoyu

+0

我最终删除了/etc/docker/daemon.json并重新启动了docker服务,它看起来像是覆盖了/ etc/sysconfig/docker中设置的内容 –

回答

110

我有同样的问题。

这帮助我:

  • 创建或在客户机上修改/etc/docker/daemon.json

    { "insecure-registries":["myregistry.example.com:5000"] }

  • 重启码头工人守护

    sudo /etc/init.d/docker restart

+2

它对我也有帮助!非常感谢你!但是,原因是什么? – yuxiaoyu

+6

在我的情况下,我使用Ubuntu 16.04和/ etc/default/docker(我的配置是)特定于暴发户。 16.04使用systemd。 /etc/docker/daemon.json是平台无关的配置。 https://github.com/docker/docker/issues/23512 https://github.com/docker/docker/issues/23228 – bojtib

+0

这里是文档如何设置不安全的注册表 https://docs.docker。 com/registry/insecure/ –

2

如果您使用的是Windows,你会得到这个错误,你需要在这里创建一个文件:"C:\ProgramData\docker\config\daemon.json"

,做同样的@Bspec上面提到的:

{“不安全 - 登记” :“myregistry.example。COM:

Stop-Service docker 
Start-Service docker 
5

对于Windows用户

添加本地注册表这里和应用:5000" ]}

使用PowerShell命令,然后重启泊坞窗

enter image description here