获取镜像
docker pull registry
创建相应目录
mkdir -p /etc/docker/registry
mkdir -p /var/lib/registry
mkdir -p /opt/app/registry
配置允许跨域访问
vi /etc/docker/registry/config.yml
version: 0.1
log:
fields:
service: registry
storage:
cache:
blobdescriptor: inmemory
filesystem:
rootdirectory: /var/lib/registry
http:
addr: :5000
secret: abcdfg
headers:
X-Content-Type-Options: [nosniff]
Access-Control-Allow-Headers: ['Origin,Accept,Content-Type,Authorization']
Access-Control-Allow-Origin: ['*']
Access-Control-Allow-Methods: ['GET,POST,PUT,DELETE']
health:
storagedriver:
enabled: true
interval: 10s
threshold: 3
运行Registry Docker
docker run -d -p 5000:5000 --restart=always \
-v /opt/app/registry/:/var/lib/registry/ \
-v /etc/docker/registry/config.yml:/etc/docker/registry/config.yml \
--name registry \
registry
报错
docker: Error response from daemon: driver failed programming external connectivity on endpoint registry (...docker id...): (iptables failed: iptables --wait -t nat -A DOCKER -p tcp -d 0/0 --dport 5000 -j DNAT --to-destination 172.17.0.2:5000 ! -i docker0: iptables: No chain/target/match by that name.
解决方法:
service docker restart
重启Docker服务后:
iptables -L
可以看到iptables里面多出了Chain Docker的信息。
如不能解决,参考 博文 。