本站支持搜索的镜像仓库:Docker Hub、gcr.io、ghcr.io、quay.io、k8s.gcr.io、registry.gcr.io、elastic.co、mcr.microsoft.com
Current pilot Docker Image from Canonical, based on Ubuntu. Receives security updates and rolls to newer pilot or Ubuntu release. This repository is free to use and exempted from per-user rate limits.
Istio Pilot Discovery provides mesh-wide traffic management, security, and policy capabilities within the Istio Service Mesh. It runs as the discovery service, configuring proxies and managing service registries. For more details, see [***]
!LTS Up to 5 years of free security maintenance on LTS channels.
!ESM Up to 10 years of customer security maintenance from Canonical's restricted repositories.
| Channel Tags | Supported until | Currently | Architectures | |
|---|---|---|---|---|
1.24-24.04_stable | 1-24.04, 1-24.04_beta, 1-24.04_candidate, 1-24.04_edge, 1-24.04_stable, 1.24-24.04, 1.24-24.04_beta, 1.24-24.04_candidate, 1.24-24.04_edge | - | pilot 1.24 on Ubuntu 24.04 LTS | amd64 |
track_risk |
Channel Tags shows the most stable channel for that track ordered stable, candidate, beta, edge. More risky channels are always implicitly available. So if beta is listed, you can also pull edge. If candidate is listed, you can pull beta and edge. When stable is listed, all four are available. Images are guaranteed to progress through the sequence edge, beta, candidate before stable.
If your usage includes commercial redistribution, or requires ESM or unavailable channels/versions, please get in touch with the Canonical team (or using ***).
Launch this image locally:
docker run -d --name istio-pilot-container -e TZ=UTC -p 8080:8080 -p ***:*** -p ***:*** -p ***:*** -p ***:*** ubuntu/istio-pilot:1.24-24.04_stable
Access the Pilot Discovery service at: • HTTP: http://localhost:8080 • HTTPS (Injection/Validation): https://localhost:*** • gRPC (Insecure): localhost:*** • gRPC (Secure): localhost:*** • Monitoring: http://localhost:***
| Parameter | Description |
|---|---|
-e TZ=UTC | Set container timezone. |
CMD pilot-discovery discovery | Launch the Istio Pilot Discovery service with default values. |
CMD --caCertFile /path/to/ca.pem | File containing the x509 Server CA Certificate. (Default: Not set) |
CMD --clusterAliases key1=value1,key2=value2 | Alias names for clusters, provided as comma-separated key=value pairs. (Default: []) |
CMD --clusterID Kubernetes | The ID of the cluster that this Istiod instance resides in. (Default: Kubernetes) |
CMD --clusterRegistriesNamespace istio-system | Namespace for the ConfigMap that stores cluster configurations. (Default: istio-system) |
CMD --cniNamespace istio-system | Namespace where the istio-cni resides. Uses POD_NAMESPACE if not set. (Default: istio-system) |
CMD --configDir /etc/istio/config | Directory to watch for updates to config YAML files, used as the config source instead of a CRD client. (Default: Not set) |
CMD --ctrlz_address localhost | IP address for the ControlZ introspection facility; use '*' for all addresses. (Default: localhost) |
CMD --ctrlz_port 9876 | Port for the ControlZ introspection facility. (Default: 9876) |
CMD --domain cluster.local | DNS domain suffix for the service mesh. (Default: cluster.local) |
CMD --grpcAddr :*** | gRPC address for the discovery service. (Default: :***) |
CMD --httpAddr :8080 | HTTP address for the discovery service. (Default: :8080) |
CMD --httpsAddr :*** | HTTPS address for the injection and validation service. (Default: :***) |
CMD --keepaliveInterval 30s | Interval with no activity after which a keepalive ping is sent. (Default: 30s) |
CMD --keepaliveMaxServerConnectionAge 2562047h47m16.854775807s | Maximum duration a connection is kept open on the server before a graceful close. (Default: 2562047h47m16.854775807s) |
CMD --keepaliveTimeout 10s | Duration to wait after a keepalive ping before closing the connection if no activity is detected. (Default: 10s) |
CMD --kubeconfig /path/to/kubeconfig | Path to a Kubernetes configuration file for out-of-cluster access. (Default: Not set) |
CMD --kubernetesApiBurst 160 | Maximum burst for throttling when communicating with the Kubernetes API. (Default: 160) |
CMD --kubernetesApiQPS 80 | Maximum QPS when communicating with the Kubernetes API. (Default: 80) |
CMD --log_as_json | Format log output as JSON instead of plain text. (Default: false) |
CMD --log_caller ads,adsc,all | List of scopes for which to include caller information in logs. (Default: Not set) |
CMD --log_output_level default:info | Minimum logging level per scope for output, in the format |
CMD --log_stacktrace_level default:none | Minimum logging level per scope at which stack traces are captured. (Default: default:none) |
CMD --log_target stdout | Paths where log output is sent (e.g., stdout, stderr, or file paths). (Default: [stdout]) |
CMD --meshConfig ./etc/istio/config/mesh | File name for the Istio mesh configuration. (Default: ./etc/istio/config/mesh) |
CMD --monitoringAddr :*** | HTTP address for Pilot’s self-monitoring information. (Default: :***) |
CMD --namespace istio-system | Namespace where the controller resides; defaults to POD_NAMESPACE if not set. (Default: istio-system) |
CMD --networksConfig ./etc/istio/config/meshNetworks | File name for the Istio mesh networks configuration. (Default: ./etc/istio/config/meshNetworks) |
CMD --profile | Enable profiling via the web interface at /debug/pprof. (Default: true) |
CMD --registries Kubernetes | Comma separated list of service registries to read from. (Default: [Kubernetes]) |
CMD --secureGRPCAddr :*** | Secured gRPC address for the discovery service. (Default: :***) |
CMD --shutdownDuration 10s | Duration the discovery server needs to terminate gracefully. (Default: 10s) |
CMD --tls-cipher-suites TLS_AES_128_GCM_SHA256 | Comma-separated list of TLS cipher suites for the istiod TLS server. (If omitted, the default Go cipher suites are used.) (Default: Not set) |
CMD --tlsCertFile /path/to/cert.pem | File containing the x509 Server Certificate. (Default: Not set) |
CMD --tlsKeyFile /path/to/key.pem | File containing the x509 private key matching --tlsCertFile. (Default: Not set) |
CMD --vklog 9 | Global log verbosity level (similar to the -v flag). (Default: Not set) |
To debug the container:
docker logs -f istio-pilot-container
To get an interactive shell:
docker exec -it istio-pilot-container /bin/bash
To debug the container:
docker exec -it pilot-container pebble logs -f pilot
To get an interactive shell:
docker exec -it pilot-container /bin/bash
If you find a bug in our image or want to request a specific feature, please file a bug here:
[***]
Please title the bug "istio-pilot: <issue summary>". Make sure to include the digest of the image you are using, from:
docker images --no-trunc --quiet ubuntu/istio-pilot:<tag>
These channels (tags) are not updated anymore. Please upgrade to newer channels, or reach out if you can't upgrade.
| Track | Version | EOL | Upgrade Path |
|---|---|---|---|
track |
免费版仅支持 Docker Hub 加速,不承诺可用性和速度;专业版支持更多镜像源,保证可用性和稳定速度,提供优先客服响应。
免费版仅支持 docker.io;专业版支持 docker.io、gcr.io、ghcr.io、registry.k8s.io、nvcr.io、quay.io、mcr.microsoft.com、docker.elastic.co 等。
当返回 402 Payment Required 错误时,表示流量已耗尽,需要充值流量包以恢复服务。
通常由 Docker 版本过低导致,需要升级到 20.x 或更高版本以支持 V2 协议。
先检查 Docker 版本,版本过低则升级;版本正常则验证镜像信息是否正确。
使用 docker tag 命令为镜像打上新标签,去掉域名前缀,使镜像名称更简洁。
探索更多轩辕镜像的使用方法,找到最适合您系统的配置方式
通过 Docker 登录方式配置轩辕镜像加速服务,包含7个详细步骤
在 Linux 系统上配置轩辕镜像源,支持主流发行版
在 Docker Desktop 中配置轩辕镜像加速,适用于桌面系统
在 Docker Compose 中使用轩辕镜像加速,支持容器编排
在 k8s 中配置 containerd 使用轩辕镜像加速
在宝塔面板中配置轩辕镜像加速,提升服务器管理效率
在 Synology 群晖NAS系统中配置轩辕镜像加速
在飞牛fnOS系统中配置轩辕镜像加速
在极空间NAS中配置轩辕镜像加速
在爱快ikuai系统中配置轩辕镜像加速
在绿联NAS系统中配置轩辕镜像加速
在威联通NAS系统中配置轩辕镜像加速
在 Podman 中配置轩辕镜像加速,支持多系统
配置轩辕镜像加速9大主流镜像仓库,包含详细配置步骤
无需登录即可使用轩辕镜像加速服务,更加便捷高效
需要其他帮助?请查看我们的 常见问题 或 官方QQ群: 13763429