services:docker-mirror
Differences
This shows you the differences between two versions of the page.
| Next revision | Previous revision | ||
| services:docker-mirror [2020/06/02 14:26] – created djgalloway | services:docker-mirror [2021/01/20 15:50] (current) – [Renewing the SSL certiciate] djgalloway | ||
|---|---|---|---|
| Line 4: | Line 4: | ||
| I was originally going to create an Ansible playbook to set this up but it was easy enough it wasn't worth the time. | I was originally going to create an Ansible playbook to set this up but it was easy enough it wasn't worth the time. | ||
| + | |||
| + | https:// | ||
| ===== Setup Commands ===== | ===== Setup Commands ===== | ||
| - | <pre> | + | <code> |
| ## On reesi001 | ## On reesi001 | ||
| ceph auth add client.containers mds 'allow rw path=/ | ceph auth add client.containers mds 'allow rw path=/ | ||
| Line 23: | Line 25: | ||
| docker run -it --rm --entrypoint cat registry:2 / | docker run -it --rm --entrypoint cat registry:2 / | ||
| # Used example from https:// | # Used example from https:// | ||
| - | docker run -d --restart=always -p 5000:5000 --name registry-mirror -v / | + | |
| - | </pre> | + | # Then used parts of https:// |
| + | mkdir / | ||
| + | openssl req -newkey rsa:4096 -nodes -sha256 -keyout / | ||
| + | |||
| + | docker run -d --restart=always -p 5000:5000 --name registry-mirror | ||
| + | </code> | ||
| Super simple. | Super simple. | ||
| ===== Using the mirror ===== | ===== Using the mirror ===== | ||
| - | <pre> | + | <code> |
| # Example using grafana | # Example using grafana | ||
| podman pull --tls-verify=false docker-mirror.front.sepia.ceph.com: | podman pull --tls-verify=false docker-mirror.front.sepia.ceph.com: | ||
| - | </pre> | + | </code> |
| + | |||
| + | Or you can also now just run the [[https:// | ||
| + | |||
| + | ===== Admin Tasks ===== | ||
| + | ==== Renewing the SSL certiciate ==== | ||
| + | The first time I created the cert, I accidentally left the date out so the cert was only good for a month. | ||
| + | |||
| + | - '' | ||
| + | - Copy the contents of ''/ | ||
| + | - Run '' | ||
| + | - '' | ||
| + | |||
| + | ===== Other Notes ===== | ||
| + | The mirror logs in to dockerhub using my personal API key. I just have a personal account but docker-mirror was getting rate-limited when anonymous. | ||
| + | |||
| + | < | ||
| + | root@docker-mirror: | ||
| + | version: 0.1 | ||
| + | log: | ||
| + | fields: | ||
| + | service: registry | ||
| + | storage: | ||
| + | cache: | ||
| + | blobdescriptor: | ||
| + | filesystem: | ||
| + | rootdirectory: | ||
| + | http: | ||
| + | addr: :5000 | ||
| + | headers: | ||
| + | X-Content-Type-Options: | ||
| + | health: | ||
| + | | ||
| + | enabled: true | ||
| + | interval: 10s | ||
| + | threshold: 3 | ||
| + | proxy: | ||
| + | remoteurl: https:// | ||
| + | username: XXXXX | ||
| + | password: XXXXX | ||
| + | </code> | ||
services/docker-mirror.1591107967.txt.gz · Last modified: by djgalloway
