跳转至

实验镜像清单与国内下载指引

用途:授课/环境准备时对照本表预拉镜像;标注了每个镜像的下载难度与国内可拉方案(2026-08 在 3 节点阿里云环境逐镜像实测)。 原则:除两个标注"受限"的镜像外,其余在国内均可正常拉取(docker.io 系走 containerd 加速配置,见实验 01 步骤 3;registry.k8s.io 走阿里云 google_containers;quay.io 走 daocloud 加速)。

一、镜像难度总览

难度 含义 镜像
✅ 可拉 docker.io 主流镜像,配了加速即可 busybox、nginx(1.25/1.26/1.27/latest)、mysql:5.7、wordpress:php8.2-apache、redis:7、ubuntu、memcached、registry:2、netshoot、ubuntu-bc、perl
🟡 需配置 非 docker.io 源,需按实验 01 的加速方案 registry.k8s.io 控制面全家(kube-apiserver 等)、calico、metrics-server、ingress-nginx、coredns、etcd、pause、local-path、dashboard、quay.io 监控系(prometheus/grafana/alertmanager/node-exporter)
🔴 受限 实测国内公共渠道拉不动 nginx:1.7.9(已弃用,03 章改用 1.25→1.26→1.27 链)、ghcr.io/kedacore/*(KEDA,可选实验,可跳过)

二、按实验分组的镜像清单

实验 01 集群安装(必做)

镜像 来源 难度 说明
kube-apiserver / kube-controller-manager / kube-scheduler / kube-proxy / pause registry.k8s.io 🟡 阿里云 registry.aliyuncs.com/google_containers 替代(01 章已教)
etcd registry.k8s.io 🟡 同上
coredns registry.k8s.io 🟡 同上
calico/cni、calico/node、calico/kube-controllers docker.io/calico ✅ 或 quay.io/calico(daocloud 加速)
metrics-server registry.k8s.io/metrics-server 🟡 阿里云替代或 docker.io 镜像
ingress-nginx-controller、kube-webhook-certgen registry.k8s.io/ingress-nginx 🟡 用 dyrnq 镜像或阿里云替代(07 章已教)
rancher/local-path-provisioner docker.io ✅ 08 章
busybox docker.io/library ✅ 全程通用

实验 02 Pod(12 Lab,必做为主)

busybox、nginx、memcached、redis —— 全部 ✅ docker.io

实验 03 工作负载调度(8 Lab)

  • nginx:1.25 / nginx:1.26 / nginx:1.27 —— ✅(升级链演示,2026-08 从 1.7.9/1.8/1.9.1 更换,老镜像公共渠道拉不动)
  • resouer/ubuntu-bc(Job pi 计算)—— ✅(实测 1panel 可拉)
  • nginx:latest、nginx:1.16.0 —— ✅

实验 04 资源调度(9 Lab)

nginx —— ✅

实验 05 性能与监控(6 Lab)

busybox、redis:7 —— ✅;KEDA(ghcr.io)—— 🔴 可选·进阶,可跳过

实验 06 ConfigMap/Secret(8 Lab)

busybox、mysql:5.7、registry:2(本地私有仓库实验)—— ✅

实验 07 网络与服务(7 Lab)

busybox、busybox:1.28、nginx —— ✅;ingress-nginx(见 01)

实验 08 存储(7 Lab)

busybox、nginx、mysql:5.7 —— ✅

实验 09 认证与授权(12 Lab)

nginx、busybox、kubernetesui/dashboard + kubernetesui/metrics-scraper(Lab 6)—— ✅ docker.io

实验 10 故障排查(8 Lab)

busybox、nginx:1.27、nginx:notexist(故意写错的 tag,用于排障演示,不要预拉)、ubuntu、nicolaka/netshoot —— ✅(netshoot 实测 daocloud 加速可拉)

实验 11 WordPress 综合(6 Lab)

wordpress:php8.2-apache、mysql:5.7、nginx —— ✅

实验 12 集群维护(4 Lab)

nginx —— ✅

实验 13 Helm 交付(3 Lab)

nginx(helm create 骨架默认值)—— ✅

实验 14 可观测性(3 Lab,可选·进阶)

镜像 来源 难度 说明
quay.io/prometheus/prometheus、alertmanager、node-exporter quay.io 🟡 daocloud 加速(quay.m.daocloud.io),14 章已注记
grafana/grafana docker.io ✅
registry.k8s.io/kube-state-metrics、ingress-nginx/kube-webhook-certgen registry.k8s.io 子路径 🔴 14 章注记:禁用 kubeStateMetrics 或预拉替代
docker.elastic.co/beats/filebeat docker.elastic.co 🟡 实测可拉(无加速也通),无保障时预拉一次

三、预拉/离线准备建议

  1. 不需要离线包:除 nginx:1.7.9(已弃用)和 KEDA(可选跳过)外,全部镜像国内可拉。
  2. 授课前预拉:在每台节点上按本表把 ✅/🟡 镜像 crictl pull 一遍(一条 for 循环即可),上课时零等待。
  3. 可选实验镜像(Prometheus 全套、filebeat)按需预拉;KEDA 跳过。
  4. nginx:notexist 是排障演示用假 tag——不要预拉,否则演示"拉不到镜像"的效果就没了。

配套:containerd 加速配置(hosts.toml:docker.io→1panel/daocloud、registry.k8s.io→阿里云、quay.io→daocloud)见实验 01 步骤 3 与 14 章注记。