insecure_skip_verify = true #跳过认证 ca_file = "/etc/containerd/myharbor-minio.com/ca.crt" [plugins."io.containerd.grpc.v1.cri".registry.configs."myharbor-minio.com".auth] username = "admin" password = "Harbor12345" [plugins."io.containerd.grpc.v1.cri".registry.headers] [plugins."i...
REGISTRY_PORT=${REGISTRY_PORT:-35000} if [ ! -e $REGISTRY_DIR ]; then sudo mkdir $REGISTRY_DIR fi echo "===> Start registry" sudo /usr/local/bin/nerdctl --insecure-registry=true run -d \ --network host \ -e REGISTRY_HTTP_ADDR=0.0.0.0:${REGISTRY_PORT} \ --restart always \ -...
root@k8s-master01:~# nerdctl login --insecure-registry https://harbor.magedu.netWARN[0000] skipping verifying HTTPS certsfor"harbor.magedu.net"WARNING: Your password will be stored unencryptedin/root/.docker/config.json. Configure a credential helper to remove this warning. See https://docs.doc...
FATA[0000] failed to resolve reference "osci-deploy:5000/coreos/flannel:v0.14.0-amd64": failed to do request: Head "https://osci-deploy:5000/v2/coreos/flannel/manifests/v0.14.0-amd64": http: server gave HTTP response to HTTPS client if i use --insecure-registry # nerdctl pull osci-...
[/etc/containerd/certs.d,/etc/docker/certs.d]) --insecure-registry skips verifying HTTPS certs, and allows falling back to plain HTTP -n, --n string Alias of --namespace (default "default") --namespace string containerd namespace, such as "moby" for Docker, "k8s.io" for Kubernetes ...
--insecure-registry skips verifying HTTPS certs, and allows falling back to plain HTTP (default:false) --help, -h showhelp(default:false) --version, -vprintthe version (default:false) [root@containerd ~]# 1、Run&Exec 🐳nerdctl run ...
$nerdctl --insecure-registry run --rm 192.168.12.34:5000/foo Specifying certificates ⚡ Requirementnerdctl >= 0.16 Create~/.config/containerd/certs.d/<HOST:PORT>/hosts.toml(or/etc/containerd/certs.d/...for rootful) to specifycacertificates. ...
insecure_registry = true EOF } # 安装buildkit install_buildkit() { # 下载buildkit ## -c 断点续传 ## —P 下载到指定目录 wget -c -P /usr/local/src/ https://github.com/moby/buildkit/releases/download/v$buildkit_VERSION/buildkit-v$buildkit_VERSION.linux-amd64.tar.gz ...
#第一种方式:使用--insecure-registry nerdctl login --resecure-registry harbor.wyh.net #第二种方式:将证书拿到客户端,让客户端信任证书 mkdir /etc/containerd/certs.d/harbor.wyh.net -p 在harbor服务器将crt转换成cert openssl x509 -inform PEM -inharbor.wyh.net.crt -outharbor.wyh.net.cert ...
加上--insecure-registry参数就可以了