openssl x509 -req -days 3650 -in ~/certs/$signdomain.csr -signkey ~/certs/$signdomain.key -out ~/certs/$signdomain.crt
#==>運(yùn)行docker registry v2
docker run -d -p 5000:5000 --restart=always --name registry \
-v ~/certs:/certs \
-e REGISTRY_HTTP_TLS_CERTIFICATE=/certs/$signdomain.crt \
-e REGISTRY_HTTP_TLS_KEY=/certs/$signdomain.key \
registry:2
#==>嘗試 push 鏡像
docker tag ubuntu a.b.cn:5000/ubuntu
docker push a.b.cn:5000/ubuntu
#==>出現(xiàn)如下錯(cuò)誤:
The push refers to a repository [a.b.cn:5000/ubuntu] (len: 1)
unable to ping registry endpoint https://a.b.cn:5000/v0/
v2 ping attempt failed with error: Get https://a.b.cn:5000/v2/: x509: certificate signed by unknown authority
v1 ping attempt failed with error: Get https://a.b.cn:5000/v1/_ping: x509: certificate signed by unknown authority
#==>錯(cuò)誤是由于沒有權(quán)威認(rèn)證的自簽名證書引起,在將crt復(fù)制docker Damon 的節(jié)點(diǎn)上如下目錄(以當(dāng)前節(jié)點(diǎn)示例,其它節(jié)點(diǎn)類似 scp 過去):
mkdir /etc/docker/certs.d/$signdomain:5000
cp ~/certs/$signdomain.crt /etc/docker/certs.d/$signdomain:5000/ca.crt
#==>驗(yàn)證 pull 和 push
docker pull a.b.cn:5000/ubuntu
整體:
#導(dǎo)入registry v2 鏡像包
sudo docker load < registry.2.tar
#設(shè)置registry所在主機(jī)域名或主機(jī)名
signdomain=docker-1
#設(shè)置registry認(rèn)證文件目錄
sudo mkdir ~/certs
#openssl生成認(rèn)證文件
sudo openssl req -nodes -subj "/C=CN/ST=ZheJiang/L=HangZhou/CN=$signdomain" -newkey rsa:4096 -keyout ~/certs/$signdomain.key -out ~/certs/$signdomain.csr
sudo openssl x509 -req -days 3650 -in ~/certs/$signdomain.csr -signkey ~/certs/$signdomain.key -out ~/certs/$signdomain.crt
#運(yùn)行registry容器
sudo docker run -d -p 5000:5000 --name registry -v ~/certs:/certs -e REGISTRY_HTTP_TLS_CERTIFICATE=/certs/$signdomain.crt -e REGISTRY_HTTP_TLS_KEY=/certs/$signdomain.key registry:2
#將crt文件復(fù)制到各docker Damon所在主機(jī)的/etc/docker/cert.d/$signdomain:5000目錄(不存在先新建)
sudo mkdir /etc/docker/certs.d/
sudo mkdir /etc/docker/certs.d/$signdomain:5000
sudo cp ~/certs/$signdomain.crt /etc/docker/certs.d/$signdomain:5000/ca.crt
#測試registry服務(wù)
sudo docker tag registry:2 docker-1:5000/registry:2
sudo docker push docker-1:5000/registry:2
關(guān)于怎么實(shí)現(xiàn)Docker私有倉庫Registry 搭建問題的解答就分享到這里了,希望以上內(nèi)容可以對大家有一定的幫助,如果你還有很多疑惑沒有解開,可以關(guān)注創(chuàng)新互聯(lián)行業(yè)資訊頻道了解更多相關(guān)知識。
文章題目:怎么實(shí)現(xiàn)Docker私有倉庫Registry搭建
文章轉(zhuǎn)載: