信息安全,  容器应用,  系统运维

k8s 通过secret访问harbor私有镜像

  • 配置私有仓库的secret
kubectl create secret docker-registry registry-secret --namespace=default \
--docker-server=https://private-registry.domain.com --docker-username=username \
--docker-password=password --docker-email=username@abcd.com
  • 部署时指定imagePullSecrets
kind: Deployment
apiVersion: extensions/v1beta1
metadata:
  name: service-test
  namespace: default
  labels:
    app: service-test
spec:
  replicas: 2
  template:
    metadata:
      labels:
        app: service-test
    spec:
      containers:
      - image: private-registry.domain.com/test-private/service-test:1
        name: service-test
        ports:
        - containerPort: 80
      imagePullSecrets:
      - name: registry-secret

留言

您的电子邮箱地址不会被公开。 必填项已用*标注

闽ICP备20008591号-1