Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

docker service update --image no longer resolves tags to digests in v29

未关闭
#7,302 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 1 天内回复

@locker95 已经在做这个了。

开始于 2026年9月14日。

  • #7305 来自 @locker95 —— 未关闭

评估

难度
3/5
预计耗时
1-2 天
新手友好度
68/100
Issue 类型
缺陷
描述清晰度
基本清楚
活跃度
活跃
技术栈
go
领域
cli

调研方向

首先使用 docker service update --image 运行单节点 Swarm 和本地 registry 的复现,然后跟踪 Docker CLI 中 service-update 的入口点。比较带有和不带有 --no-resolve-image 时的行为;完成标准是默认路径发送带有新 digest 的更新 tag,并且 Swarm 替换 task,而显式 flag 保留 tag。

由索引模型根据 Issue 内容生成。

描述

kind/bug status/0-triage
Description

docker service update --image no longer asks the registry to resolve the supplied image tag to a digest in Docker CLI v29.

When a service already stores a mutable image reference such as localhost:5000/test:latest, pushing new content to that tag and running docker service update --image localhost:5000/test:latest test leaves the service specification unchanged. No task is recreated, even though the registry now returns a different digest.

The command reports that the service has converged, but it continues running the previous image. This appears to be a Docker CLI regression rather than Swarm or registry behavior.

Actual result

The service image remains localhost:5000/test:latest. The tag is not resolved to its new digest. Because the resulting service specification is unchanged, Swarm does not create a new task.

Adding --force recreates the task, but the service is still not pinned to a digest and --force should not be required when the resolved digest changed.

Reproduce

The following example uses a single-node Swarm and a local registry.

docker swarm init

docker run -d --name registry --restart always -p 5000:5000 registry:2

docker pull alpine:3.20
docker tag alpine:3.20 localhost:5000/test:latest
docker push localhost:5000/test:latest

docker service create \
  --name test \
  --no-resolve-image \
  localhost:5000/test:latest \
  sleep 1d

docker pull alpine:3.21
docker tag alpine:3.21 localhost:5000/test:latest
docker push localhost:5000/test:latest

docker service update \
  --image localhost:5000/test:latest \
  test

docker service inspect \
  --format '{{.Spec.TaskTemplate.ContainerSpec.Image}}' \
  test

docker service ps --no-trunc test

The inspected image remains the bare tag and the existing task is not replaced.

Expected behavior

Unless --no-resolve-image is explicitly supplied, the CLI should query the registry and send an update containing localhost:5000/test:latest@sha256:<new-digest>. The changed digest should cause Swarm to roll out a new task.

docker version
Client:
 Version:           29.1.3
 API version:       1.52
 OS/Arch:           linux/amd64

Server:
 Engine:
  Version:          29.1.3
  API version:      1.52
  OS/Arch:          linux/amd64
docker info
Server Version: 29.1.3
OSType: linux
Architecture: x86_64
Swarm: active
 Is Manager: true

Internal registry, node, and network details have been omitted.
主要语言
Go
星标
6.1k
派生
2.2k
平均合并
2 天 2 小时
30 天内合并 PR
28

环境准备

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

docker/cli 的其他 Issue

查看 docker/cli 的全部 Issue

相似的 Issue

更多 Go Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。