docker pull issue with artifactory and microsoft

Viewed 318

I have a strange problem with docker and pulling microsoft images.

Used command docker pull mcr.microsoft.com/dotnet/sdk:6.0

  • Server 1: no issue
  • Server 2: Error response from daemon: Get "https://mcr.microsoft.com/v2/": dial tcp 13.69.64.80:443: connect: connection refused

Both servers are

  • behind the firewall
  • configured with same /etc/docker/daemon.json whicht points to the internal artifactory instance
  • commands like docker pull sonarsource/sonar-scanner-cli works on both servers without an issue
  • also pulling privat images from artifactory works on both servers

any idea on that behavior?

1 Answers

Is your remote repo proxying mcr.microsoft.com and is configured to cache foreign layers?

If there is a local image, when the docker client builds the image and publishes it to Artifactory, Artifactory gets the manifest but has reference to foreign layers which are remote, so Artifactory is not going out and fetch them in a local repository. This behavior we observed appears to be related to this RTFACT-22938 Jira. If the foreign layers from the base image are not cached locally, Artifactory will not fetch these layers. In order for Artifactory to retrieve the foreign layers as well, all of the base image’s layers need to be cached in Artifactory.

Since Microsoft changes the tags of the images constantly, and the manifest is changing, the layers that were pulled will not be used since they are no longer referenced in the manifest. Re-tagging the images with custom tags can be one way to avoid this situation.

Related