5.2. 使用 Containerfile 将自定义证书导入到镜像
包含使用 Containerfile
安装自定义证书根的说明。
流程
创建
Containerfile
:FROM <internal_repository>/<image> # Add certificate to the input set of anchors COPY additional-certificate-root.pem /etc/pki/ca-trust/source/anchors RUN update-ca-trust
FROM <internal_repository>/<image> # Add certificate to the input set of anchors COPY additional-certificate-root.pem /etc/pki/ca-trust/source/anchors RUN update-ca-trust
Copy to Clipboard Copied! 构建自定义镜像:
podman build -t <your_image> .
# podman build -t <your_image> .
Copy to Clipboard Copied! 运行 <
;your_image>
:podman run -it --rm <your_image>
# podman run -it --rm <your_image>
Copy to Clipboard Copied!
验证
验证您的证书是否在生成的合并存储中:
cat etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem ...
# cat etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem ...
Copy to Clipboard Copied!