Accessing a private repository from a docker container

Viewed 532

I am trying to build a docker image using a dockerfile

the problem is when the instruction apt-get update get executed I get this error

Err:8 https://artifactory-name bionic-updates Release
  Certificate verification failed: The certificate is NOT trusted. The certificate issuer is unknown.  Could not handshake: Error in the certificate verification. [IP: artifactory-ip]

So I want to know if the docker container reuse the certificates configured in my host machine

or there is a configuration i must add in order to access the artifactory from my container.

Ps: my host machine is ubuntu and I have no problem accessing the artifactory

2 Answers

Try to install ca-certificates before: sudo apt install ca-certificates or if you want to bypass the security add [trusted=yes] in the sources.list

It's quite common that docker base images have root CA certificates that are out of date. (root CA certs are the ones that browsers and operating systems have built-in so they are always trusted, those certs still change but are usually updated automatically).

So it's common to start a Dockerfile with commands needed to bring those certs up to date. Here are two commands for Debian based images:

RUN apt-get update \
    && apt-get install -y --no-install-recommends \
       apt-transport-https

RUN apt-get update \
    && apt-get install -y --no-install-recommends \
       ca-certificates \

The first ensures that apt can read SSL/TLS sources. The second updates those root CA certs.

Related