docs(build): 修正上下文存储与构建镜像拉取的过时描述

This commit is contained in:
Lemon-miaow committed 2026-09-24 22:26:29 +08:00
1 parent e836a73a8a
commit a27d76ae1d
3 files changed
+17 -21

No files matched your search

+6 -5
View File
@@ -470,11 +470,12 @@ installer).
### 8e. Build Pods never start: executor images and air-gapped installs
The build Job runs Kaniko and Trivy from external registries by default
(`gcr.io/kaniko-project/executor:latest`, `aquasec/trivy:latest`). On a box whose
build namespace cannot reach those registries (the egress policy allows only
DNS, the internal registry and `--package-cidr` mirrors — and an air-gapped box
has no route at all), the Pods sit in `ImagePullBackOff`/`ErrImagePull` and the
build stays `building` until its deadline. Point the overrides at images **in
(`gcr.io/kaniko-project/executor:latest`, `aquasec/trivy:latest`). The kubelet
pulls those images over the node's own network, so the build namespace's egress
policy does not apply to the pull; what blocks it is a node without a route to
those registries (an air-gapped box, a firewall, a rate-limited Docker Hub).
The Pods then sit in `ImagePullBackOff`/`ErrImagePull` and the build stays
`building` until its deadline. Point the overrides at images **in
the internal registry** — the one pull source that survives an image GC (a bare
node-containerd import does not: kubelet's image GC collects unused images under
disk pressure, and an air-gapped box then has nothing to restore them from) —