問題文
A user on a compute node tries to pull a framework container from the vendor registry and the pull is refused. The same image name works for a colleague on the same node. The operator wants the first thing to check. Which is it?
選択肢
- Whether the container runtime on the node has been configured to expose accelerators to containers, since an image that references accelerator libraries cannot be unpacked until a matching device is visible on the host.
- Whether the user has authenticated to the registry with a valid key and holds a role that grants access to the organization the image belongs to.
- Whether the node's clock is synchronized, because a manifest is rejected when the node's time differs from the registry's by more than the signing window allows.
- Whether the local disk has room, since a pull that cannot unpack its layers is reported as a permission problem by the runtime that gave up partway through.