面向系统管理员的Skopeo

面向系统管理员的Skopeo

Skopeo 用于处理容器镜像和镜像仓库。它不需要守护进程,也不需要root权限。你可以在部署之前检查远程镜像,在不同仓库之间或仓库与本地存储之间复制镜像,镜像整个仓库,以及从仓库删除镜像。

安装Skopeo

Ubuntu提供 skopeo(1):

sudo apt install skopeo

镜像名称

许多Skopeo命令接受带传输方式前缀的镜像名,前缀指定镜像位于何处:

  • docker://:远程仓库中的镜像,例如 docker://docker.io/ubuntu:26.04。

  • docker-daemon::本地Docker守护进程存储中的镜像。

  • containers-storage::Podman 和 Buildah 使用的本地存储中的镜像。

  • dir::解包到本地目录的镜像。

  • oci: 和 oci-archive::OCI布局目录或 tar 归档中的镜像。

完整列表与每种传输方式的精确语法见 containers-transports(5)。

检查远程镜像

skopeo-inspect(1) 只下载镜像元数据,不下载镜像层,因此你可以在拉取之前检查镜像内容:

skopeo inspect docker://docker.io/ubuntu:26.04
{
    "Name": "docker.io/library/ubuntu",
    "Digest": "sha256:2260313b31c8c011cd2eebe728008efac1b3982be73eb71348ea2648d2c0e09b",
    "RepoTags": [
        "24.04",
        "25.10",
        "26.04",
        "latest"
    ],
    "Created": "2026-08-17T09:00:47.315779976Z",
    "DockerVersion": "",
    "Labels": {
        "org.opencontainers.image.created": "2026-08-17T09:02:45.677319+00:00",
        "org.opencontainers.image.title": "ubuntu",
        "org.opencontainers.image.version": "26.04"
    },
    "Architecture": "amd64",
    "Os": "linux",
    "Layers": [
        "sha256:06e9d71331fb2b620a4f6c8064e0f84b284bb69a42c7c57b1c962bd4a4cdee76",
        "sha256:f3db1cd940786339b09d8a60e47c66fea9502d788e6fab5bec91a4a77d4ced1c"
    ],
    "LayersData": [
        {
            "MIMEType": "application/vnd.oci.image.layer.v1.tar+gzip",
            "Digest": "sha256:06e9d71331fb2b620a4f6c8064e0f84b284bb69a42c7c57b1c962bd4a4cdee76",
            "Size": 41569203,
            "Annotations": {
                "ci.umo.uncompressed_blob_size": "111523840"
            }
        },
        {
            "MIMEType": "application/vnd.oci.image.layer.v1.tar+gzip",
            "Digest": "sha256:f3db1cd940786339b09d8a60e47c66fea9502d788e6fab5bec91a4a77d4ced1c",
            "Size": 393,
            "Annotations": {
                "ci.umo.uncompressed_blob_size": "10240"
            }
        }
    ],
    "Env": [
        "PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin"
    ]
}

可以用 skopeo-list-tags(1) 列出仓库中可用的标签。

skopeo list-tags docker://docker.io/ubuntu

{
    "Repository": "docker.io/library/ubuntu",
    "Tags": [
        "22.04",
        "24.04",
        "26.04",
        "latest"
    ]
}

登录镜像仓库

公共镜像不需要凭据。对于私有仓库,使用 skopeo-login(1) 登录。Skopeo将凭据保存在 ${XDG_RUNTIME_DIR}/containers/auth.json 中,见 containers-auth.json(5):

skopeo login registry.example.com

Username: myuser
Password:
Login Succeeded!

也可以为单个命令传入凭据:inspect 和 delete 使用 --creds user:password,copy 使用 --src-creds 和 --dest-creds。

Skopeo还能自动使用 docker login、podman login 或 buildah login 设置的认证凭据。

复制镜像

在仓库之间复制

使用 skopeo-copy(1) 将镜像复制到内部仓库,不需要本地守护进程,而且复制期间不会解包镜像:

skopeo copy \
docker://docker.io/ubuntu:26.04 \
docker://registry.example.com/mirror/ubuntu:26.04

Getting image source signatures
Copying blob 06e9d71331fb done
Copying blob f3db1cd94078 done
Copying config af52039db3 done
Writing manifest to image destination

默认情况下,Skopeo只复制与你机器架构相符的镜像。添加 --all 可以复制多架构镜像中的所有架构。

copy 与 sync 都能用 --sign-by 或 --sign-by-sigstore 为写入的镜像签名,但只有配置了信任策略,才会检查签名。详情见 containers-policy.json(5) 与 containers-registries.d(5)。

复制到本地存储或从本地存储复制

将远程镜像复制到本地Docker守护进程:

skopeo copy docker://docker.io/ubuntu:26.04 docker-daemon:ubuntu:26.04

也可以保存为OCI归档:

skopeo copy docker://docker.io/ubuntu:26.04 oci-archive:ubuntu-26.04.tar:ubuntu:26.04

同一命令也可反向使用,以归档为源、仓库为目标。

镜像多个镜像

copy 每次处理一个镜像,skopeo-sync(1) 则在一次运行中复制一组镜像,并跳过目标已经拥有的内容。使用 sync 时,通过 --src 和 --dest 指定传输方式,而不是在镜像名称前添加前缀。

将单个镜像或整个仓库同步到内部镜像仓库:

skopeo sync --src docker --dest docker docker.io/ubuntu:26.04 registry.example.com/mirror
INFO[0000] Tag presence check                            imagename="docker.io/ubuntu:26.04" tagged=true
INFO[0000] Copying image ref 1/1                         from="docker://ubuntu:26.04" to="docker://registry.example.com/mirror/ubuntu:26.04"
Getting image source signatures
Copying blob 06e9d71331fb done
Copying blob f3db1cd94078 done
Copying config af52039db3 done
Writing manifest to image destination
INFO[0005] Synced 1 images from 1 sources

源仓库不带标签时,会同步其中的每个标签。

也可以同步到目录。--scoped 选项将源仓库名称保留在路径中,使不同仓库的镜像不会发生冲突:

skopeo sync --src docker --dest dir --scoped docker.io/ubuntu:26.04 /media/usb

这会把镜像写入 /media/usb/docker.io/library/ubuntu:26.04。要将其同步回仓库,使用 --src dir --dest docker。

从YAML文件同步

反复运行同一镜像同步时,可在YAML文件中列出镜像,并传入 --src yaml。可以逐一列出标签,也可以用正则表达式匹配:

docker.io:
  images:
    ubuntu:
      - "24.04"
      - "26.04"
  images-by-tag-regex:
    nginx: ^1\.2[0-9]-alpine$

在实际运行前,用 --dry-run 检查同步将执行哪些操作:

skopeo sync --src yaml --dest docker --dry-run sync.yaml registry.example.com/mirror
INFO[0000] Processing repo                               registry=docker.io repo=ubuntu
INFO[0000] Processing repo                               registry=docker.io repo=nginx
INFO[0000] Querying registry for image tags              registry=docker.io repo=nginx
INFO[0000] Getting tags                                  image=docker.io/library/nginx
WARN[0001] Running in dry-run mode
INFO[0001] Would have copied image ref 1/2               from="docker://ubuntu:24.04" to="docker://registry.example.com/mirror/ubuntu:24.04"
INFO[0001] Would have copied image ref 2/2               from="docker://ubuntu:26.04" to="docker://registry.example.com/mirror/ubuntu:26.04"
INFO[0001] Would have copied image ref 1/10              from="docker://nginx:1.20-alpine" to="docker://registry.example.com/mirror/nginx:1.20-alpine"
INFO[0001] Would have copied image ref 2/10              from="docker://nginx:1.21-alpine" to="docker://registry.example.com/mirror/nginx:1.21-alpine"
INFO[0001] Would have copied image ref 3/10              from="docker://nginx:1.22-alpine" to="docker://registry.example.com/mirror/nginx:1.22-alpine"
INFO[0001] Would have copied image ref 4/10              from="docker://nginx:1.23-alpine" to="docker://registry.example.com/mirror/nginx:1.23-alpine"
INFO[0001] Would have copied image ref 5/10              from="docker://nginx:1.24-alpine" to="docker://registry.example.com/mirror/nginx:1.24-alpine"
INFO[0001] Would have copied image ref 6/10              from="docker://nginx:1.25-alpine" to="docker://registry.example.com/mirror/nginx:1.25-alpine"
INFO[0001] Would have copied image ref 7/10              from="docker://nginx:1.26-alpine" to="docker://registry.example.com/mirror/nginx:1.26-alpine"
INFO[0001] Would have copied image ref 8/10              from="docker://nginx:1.27-alpine" to="docker://registry.example.com/mirror/nginx:1.27-alpine"
INFO[0001] Would have copied image ref 9/10              from="docker://nginx:1.28-alpine" to="docker://registry.example.com/mirror/nginx:1.28-alpine"
INFO[0001] Would have copied image ref 10/10             from="docker://nginx:1.29-alpine" to="docker://registry.example.com/mirror/nginx:1.29-alpine"
INFO[0001] Would have synced 12 images from 2 sources

如果希望某个镜像失败后同步仍继续,而不是停止,添加 --keep-going。

从仓库删除镜像

使用 skopeo-delete(1) 删除镜像:

skopeo delete docker://registry.example.com/mirror/ubuntu:26.04

这会删除清单,使标签无法再解析。镜像仓库只有在执行垃圾回收时才会回收镜像层。

延伸阅读


原文:Skopeo for system admins,Ubuntu Server文档,最后更新于2026年9月15日。中文译文。原页面版权标识:Copyright © 2026。

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享
评论 抢沙发

请登录后发表评论

    暂无评论内容