docker service update --image no longer resolves tags to digests in v29
维护者通常 1 天内回复
评估
调研方向
首先使用 docker service update --image 运行单节点 Swarm 和本地 registry 的复现,然后跟踪 Docker CLI 中 service-update 的入口点。比较带有和不带有 --no-resolve-image 时的行为;完成标准是默认路径发送带有新 digest 的更新 tag,并且 Swarm 替换 task,而显式 flag 保留 tag。
由索引模型根据 Issue 内容生成。
描述
Description
docker service update --image no longer asks the registry to resolve the supplied image tag to a digest in Docker CLI v29.
When a service already stores a mutable image reference such as localhost:5000/test:latest, pushing new content to that tag and running docker service update --image localhost:5000/test:latest test leaves the service specification unchanged. No task is recreated, even though the registry now returns a different digest.
The command reports that the service has converged, but it continues running the previous image. This appears to be a Docker CLI regression rather than Swarm or registry behavior.
Actual result
The service image remains localhost:5000/test:latest. The tag is not resolved to its new digest. Because the resulting service specification is unchanged, Swarm does not create a new task.
Adding --force recreates the task, but the service is still not pinned to a digest and --force should not be required when the resolved digest changed.
Reproduce
The following example uses a single-node Swarm and a local registry.
docker swarm init
docker run -d --name registry --restart always -p 5000:5000 registry:2
docker pull alpine:3.20
docker tag alpine:3.20 localhost:5000/test:latest
docker push localhost:5000/test:latest
docker service create \
--name test \
--no-resolve-image \
localhost:5000/test:latest \
sleep 1d
docker pull alpine:3.21
docker tag alpine:3.21 localhost:5000/test:latest
docker push localhost:5000/test:latest
docker service update \
--image localhost:5000/test:latest \
test
docker service inspect \
--format '{{.Spec.TaskTemplate.ContainerSpec.Image}}' \
test
docker service ps --no-trunc test
The inspected image remains the bare tag and the existing task is not replaced.
Expected behavior
Unless --no-resolve-image is explicitly supplied, the CLI should query the registry and send an update containing localhost:5000/test:latest@sha256:<new-digest>. The changed digest should cause Swarm to roll out a new task.
docker version
Client:
Version: 29.1.3
API version: 1.52
OS/Arch: linux/amd64
Server:
Engine:
Version: 29.1.3
API version: 1.52
OS/Arch: linux/amd64
docker info
Server Version: 29.1.3
OSType: linux
Architecture: x86_64
Swarm: active
Is Manager: true
Internal registry, node, and network details have been omitted.
- 主要语言
- Go
- 星标
- 6.1k
- 派生
- 2.2k
- 平均合并
- 2 天 2 小时
- 30 天内合并 PR
- 28
环境准备
- 提供 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
docker/cli 的其他 Issue
-
[v29.9.0-rc.1 regression] e2e: TestRunAttachedFromRemoteImageAndRemove failing with v29.9.0-rc.1可能已有人在做 @thaJeztah 于 1 天前认领。 未关闭area/testing kind/bug
难度 2/5 1-3 小时 新手友好度 76/100
docker/cli#7352 · 3 条评论 · 已指派 1 人 ·
维护者通常 1 天内回复
-
`docker context export` writes a truncated tar archive可能已有人在做 @2arian3 于 9 天前认领。 未关闭
难度 2/5 1-3 小时 新手友好度 92/100
维护者通常 1 天内回复
-
`docker logout docker.io` does not remove Docker Hub credentials可能已有人在做 @yin2hao 于 11 天前认领。 未关闭kind/bug status/0-triage
难度 2/5 1-3 小时 新手友好度 75/100
维护者通常 1 天内回复
-
Truncating log lines at 75 characters makes them useless.可能已有人在做 @locker95 于 53 天前认领。 未关闭kind/bug status/0-triage
难度 2/5 1-3 小时 新手友好度 72/100
维护者通常 1 天内回复
-
cli-plugins/hooks: max-message enforcement is off by one可能已有人在做 @fallintoplace 于 132 天前认领。 未关闭
难度 2/5 1-3 小时 新手友好度 74/100
维护者通常 1 天内回复
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 78/100
prime-radiant-inc/evener#3726 ·
维护者通常 1 天内回复
-
[BUG] Async engine endpoint-label relationship counts include pending relationships of every type未关闭
难度 2/5 1-3 小时 新手友好度 78/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 86/100
modelcontextprotocol/go-sdk#1340 ·
维护者通常 1 天内回复
-
🪲 bug
难度 2/5 1-3 小时 新手友好度 82/100
binwiederhier/ntfy#1992 ·
维护者通常 2 天内回复
-
难度 2/5 1-3 小时 新手友好度 84/100
维护者通常 1 天内回复