面向系统管理员的Skopeo
Skopeo 用于处理容器镜像和镜像仓库。它不需要守护进程,也不需要root权限。你可以在部署之前检查远程镜像,在不同仓库之间或仓库与本地存储之间复制镜像,镜像整个仓库,以及从仓库删除镜像。
安装Skopeo
Ubuntu提供 skopeo(1):
sudo apt install skopeo
镜像名称
许多Skopeo命令接受带传输方式前缀的镜像名,前缀指定镜像位于何处:
-
docker://:远程仓库中的镜像,例如docker://docker.io/ubuntu:26.04。 -
docker-daemon::本地Docker守护进程存储中的镜像。 -
dir::解包到本地目录的镜像。 -
oci:和oci-archive::OCI布局目录或tar归档中的镜像。
完整列表与每种传输方式的精确语法见 containers-transports(5)。
检查远程镜像
skopeo-inspect(1) 只下载镜像元数据,不下载镜像层,因此你可以在拉取之前检查镜像内容:
skopeo inspect docker://docker.io/ubuntu:26.04
{
"Name": "docker.io/library/ubuntu",
"Digest": "sha256:2260313b31c8c011cd2eebe728008efac1b3982be73eb71348ea2648d2c0e09b",
"RepoTags": [
"24.04",
"25.10",
"26.04",
"latest"
],
"Created": "2026-08-17T09:00:47.315779976Z",
"DockerVersion": "",
"Labels": {
"org.opencontainers.image.created": "2026-08-17T09:02:45.677319+00:00",
"org.opencontainers.image.title": "ubuntu",
"org.opencontainers.image.version": "26.04"
},
"Architecture": "amd64",
"Os": "linux",
"Layers": [
"sha256:06e9d71331fb2b620a4f6c8064e0f84b284bb69a42c7c57b1c962bd4a4cdee76",
"sha256:f3db1cd940786339b09d8a60e47c66fea9502d788e6fab5bec91a4a77d4ced1c"
],
"LayersData": [
{
"MIMEType": "application/vnd.oci.image.layer.v1.tar+gzip",
"Digest": "sha256:06e9d71331fb2b620a4f6c8064e0f84b284bb69a42c7c57b1c962bd4a4cdee76",
"Size": 41569203,
"Annotations": {
"ci.umo.uncompressed_blob_size": "111523840"
}
},
{
"MIMEType": "application/vnd.oci.image.layer.v1.tar+gzip",
"Digest": "sha256:f3db1cd940786339b09d8a60e47c66fea9502d788e6fab5bec91a4a77d4ced1c",
"Size": 393,
"Annotations": {
"ci.umo.uncompressed_blob_size": "10240"
}
}
],
"Env": [
"PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin"
]
}
可以用 skopeo-list-tags(1) 列出仓库中可用的标签。
skopeo list-tags docker://docker.io/ubuntu
{
"Repository": "docker.io/library/ubuntu",
"Tags": [
"22.04",
"24.04",
"26.04",
"latest"
]
}
登录镜像仓库
公共镜像不需要凭据。对于私有仓库,使用 skopeo-login(1) 登录。Skopeo将凭据保存在 ${XDG_RUNTIME_DIR}/containers/auth.json 中,见 containers-auth.json(5):
skopeo login registry.example.com
Username: myuser
Password:
Login Succeeded!
也可以为单个命令传入凭据:inspect 和 delete 使用 --creds user:password,copy 使用 --src-creds 和 --dest-creds。
Skopeo还能自动使用 docker login、podman login 或 buildah login 设置的认证凭据。
复制镜像
在仓库之间复制
使用 skopeo-copy(1) 将镜像复制到内部仓库,不需要本地守护进程,而且复制期间不会解包镜像:
skopeo copy \
docker://docker.io/ubuntu:26.04 \
docker://registry.example.com/mirror/ubuntu:26.04
Getting image source signatures
Copying blob 06e9d71331fb done
Copying blob f3db1cd94078 done
Copying config af52039db3 done
Writing manifest to image destination
默认情况下,Skopeo只复制与你机器架构相符的镜像。添加 --all 可以复制多架构镜像中的所有架构。
copy 与 sync 都能用 --sign-by 或 --sign-by-sigstore 为写入的镜像签名,但只有配置了信任策略,才会检查签名。详情见 containers-policy.json(5) 与 containers-registries.d(5)。
复制到本地存储或从本地存储复制
将远程镜像复制到本地Docker守护进程:
skopeo copy docker://docker.io/ubuntu:26.04 docker-daemon:ubuntu:26.04
也可以保存为OCI归档:
skopeo copy docker://docker.io/ubuntu:26.04 oci-archive:ubuntu-26.04.tar:ubuntu:26.04
同一命令也可反向使用,以归档为源、仓库为目标。
镜像多个镜像
copy 每次处理一个镜像,skopeo-sync(1) 则在一次运行中复制一组镜像,并跳过目标已经拥有的内容。使用 sync 时,通过 --src 和 --dest 指定传输方式,而不是在镜像名称前添加前缀。
将单个镜像或整个仓库同步到内部镜像仓库:
skopeo sync --src docker --dest docker docker.io/ubuntu:26.04 registry.example.com/mirror
INFO[0000] Tag presence check imagename="docker.io/ubuntu:26.04" tagged=true
INFO[0000] Copying image ref 1/1 from="docker://ubuntu:26.04" to="docker://registry.example.com/mirror/ubuntu:26.04"
Getting image source signatures
Copying blob 06e9d71331fb done
Copying blob f3db1cd94078 done
Copying config af52039db3 done
Writing manifest to image destination
INFO[0005] Synced 1 images from 1 sources
源仓库不带标签时,会同步其中的每个标签。
也可以同步到目录。--scoped 选项将源仓库名称保留在路径中,使不同仓库的镜像不会发生冲突:
skopeo sync --src docker --dest dir --scoped docker.io/ubuntu:26.04 /media/usb
这会把镜像写入 /media/usb/docker.io/library/ubuntu:26.04。要将其同步回仓库,使用 --src dir --dest docker。
从YAML文件同步
反复运行同一镜像同步时,可在YAML文件中列出镜像,并传入 --src yaml。可以逐一列出标签,也可以用正则表达式匹配:
docker.io:
images:
ubuntu:
- "24.04"
- "26.04"
images-by-tag-regex:
nginx: ^1\.2[0-9]-alpine$
在实际运行前,用 --dry-run 检查同步将执行哪些操作:
skopeo sync --src yaml --dest docker --dry-run sync.yaml registry.example.com/mirror
INFO[0000] Processing repo registry=docker.io repo=ubuntu
INFO[0000] Processing repo registry=docker.io repo=nginx
INFO[0000] Querying registry for image tags registry=docker.io repo=nginx
INFO[0000] Getting tags image=docker.io/library/nginx
WARN[0001] Running in dry-run mode
INFO[0001] Would have copied image ref 1/2 from="docker://ubuntu:24.04" to="docker://registry.example.com/mirror/ubuntu:24.04"
INFO[0001] Would have copied image ref 2/2 from="docker://ubuntu:26.04" to="docker://registry.example.com/mirror/ubuntu:26.04"
INFO[0001] Would have copied image ref 1/10 from="docker://nginx:1.20-alpine" to="docker://registry.example.com/mirror/nginx:1.20-alpine"
INFO[0001] Would have copied image ref 2/10 from="docker://nginx:1.21-alpine" to="docker://registry.example.com/mirror/nginx:1.21-alpine"
INFO[0001] Would have copied image ref 3/10 from="docker://nginx:1.22-alpine" to="docker://registry.example.com/mirror/nginx:1.22-alpine"
INFO[0001] Would have copied image ref 4/10 from="docker://nginx:1.23-alpine" to="docker://registry.example.com/mirror/nginx:1.23-alpine"
INFO[0001] Would have copied image ref 5/10 from="docker://nginx:1.24-alpine" to="docker://registry.example.com/mirror/nginx:1.24-alpine"
INFO[0001] Would have copied image ref 6/10 from="docker://nginx:1.25-alpine" to="docker://registry.example.com/mirror/nginx:1.25-alpine"
INFO[0001] Would have copied image ref 7/10 from="docker://nginx:1.26-alpine" to="docker://registry.example.com/mirror/nginx:1.26-alpine"
INFO[0001] Would have copied image ref 8/10 from="docker://nginx:1.27-alpine" to="docker://registry.example.com/mirror/nginx:1.27-alpine"
INFO[0001] Would have copied image ref 9/10 from="docker://nginx:1.28-alpine" to="docker://registry.example.com/mirror/nginx:1.28-alpine"
INFO[0001] Would have copied image ref 10/10 from="docker://nginx:1.29-alpine" to="docker://registry.example.com/mirror/nginx:1.29-alpine"
INFO[0001] Would have synced 12 images from 2 sources
如果希望某个镜像失败后同步仍继续,而不是停止,添加 --keep-going。
从仓库删除镜像
使用 skopeo-delete(1) 删除镜像:
skopeo delete docker://registry.example.com/mirror/ubuntu:26.04
这会删除清单,使标签无法再解析。镜像仓库只有在执行垃圾回收时才会回收镜像层。
延伸阅读
原文:Skopeo for system admins,Ubuntu Server文档,最后更新于2026年9月15日。中文译文。原页面版权标识:Copyright © 2026。











暂无评论内容