"x509: certificate signed by unknown authority"
echo -n | openssl s_client -showcerts -connect k8s.gcr.io:443 2>/dev/null | sed -ne '/-BEGIN CERTIFICATE-/,/-END CERTIFICATE-/p' > /etc/ssl/certs/k8s.gcr.io.crt
After that restart the docker service: systemctl restart docker
reference: