Docker 镜像加速与私有仓库配置

Docker 镜像加速与私有仓库配置

1 配置镜像加速器

国内访问 Docker Hub 时常超时,可在 /etc/docker/daemon.json 中配置 registry-mirrors,使用加速镜像源。

1.1 修改 /etc/docker/daemon.json

{ "registry-mirrors": [ "https://registry.docker-cn.com" ] }

常见的加速器(按需选取):

  • 阿里云个人镜像加速器:https://<你的专属ID>.mirror.aliyuncs.com(登录容器镜像服务控制台获取)
  • Docker 官方 China:https://registry.docker-cn.com
  • USTC:https://docker.mirrors.ustc.edu.cn

1.2 重启 docker 服务

sudo systemctl daemon-reload sudo systemctl restart docker

香港/内地节点有时可通过 https://c.163yun.com/hub/ 等公共镜像中心拉取常用镜像。

2 配置 insecure-registries(非安全私有仓库)

自建镜像仓库如果走 HTTP(未配置 TLS),需要把仓库地址加入 insecure-registries:

2.1 修改 /etc/docker/daemon.json

{ "insecure-registries": [ "docker-registry.example.com:5000", "registry.example.com" ], "live-restore": true, "hosts": ["unix:///var/run/docker.sock", "tcp://0.0.0.0:2376"], "data-root": "/home/docker" }

2.2 重启 docker

/etc/init.d/docker start

2.3 检查是否生效

docker info

daemon.json 各项含义:

配置项 作用
insecure-registries 私有非安全仓库地址(HTTP 或自签证书)
live-restore 支持 docker daemon 重启过程中容器保持运行
hosts docker daemon 监听的地址(unix socket + tcp 端口)
data-root 存放 images/volumes/cluster state 的目录,默认为 /var/lib/docker

参考:https://docs.docker.com/engine/reference/commandline/dockerd/#daemon-configuration-file

3 常见镜像中心

4 登录私有仓库并推送镜像

docker login registry.example.com docker tag hello-web registry.example.com/example/hello-web:v1 docker push registry.example.com/example/hello-web:v1
阅读 — · 全站 —
🎸 我的歌单 0 首