services:docker-mirror
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| services:docker-mirror [2020/11/18 14:21] – djgalloway | services:docker-mirror [2021/01/20 15:50] (current) – [Renewing the SSL certiciate] djgalloway | ||
|---|---|---|---|
| Line 28: | Line 28: | ||
| # Then used parts of https:// | # Then used parts of https:// | ||
| mkdir /lrc/certs | mkdir /lrc/certs | ||
| - | openssl req -newkey rsa:4096 -nodes -sha256 -keyout / | + | openssl req -newkey rsa:4096 -nodes -sha256 -keyout / |
| docker run -d --restart=always -p 5000:5000 --name registry-mirror -e REGISTRY_HTTP_TLS_CERTIFICATE=/ | docker run -d --restart=always -p 5000:5000 --name registry-mirror -e REGISTRY_HTTP_TLS_CERTIFICATE=/ | ||
| Line 39: | Line 39: | ||
| # Example using grafana | # Example using grafana | ||
| podman pull --tls-verify=false docker-mirror.front.sepia.ceph.com: | podman pull --tls-verify=false docker-mirror.front.sepia.ceph.com: | ||
| + | </ | ||
| + | |||
| + | Or you can also now just run the [[https:// | ||
| + | |||
| + | ===== Admin Tasks ===== | ||
| + | ==== Renewing the SSL certiciate ==== | ||
| + | The first time I created the cert, I accidentally left the date out so the cert was only good for a month. | ||
| + | |||
| + | - '' | ||
| + | - Copy the contents of ''/ | ||
| + | - Run '' | ||
| + | - '' | ||
| + | |||
| + | ===== Other Notes ===== | ||
| + | The mirror logs in to dockerhub using my personal API key. I just have a personal account but docker-mirror was getting rate-limited when anonymous. | ||
| + | |||
| + | < | ||
| + | root@docker-mirror: | ||
| + | version: 0.1 | ||
| + | log: | ||
| + | fields: | ||
| + | service: registry | ||
| + | storage: | ||
| + | cache: | ||
| + | blobdescriptor: | ||
| + | filesystem: | ||
| + | rootdirectory: | ||
| + | http: | ||
| + | addr: :5000 | ||
| + | headers: | ||
| + | X-Content-Type-Options: | ||
| + | health: | ||
| + | | ||
| + | enabled: true | ||
| + | interval: 10s | ||
| + | threshold: 3 | ||
| + | proxy: | ||
| + | remoteurl: https:// | ||
| + | username: XXXXX | ||
| + | password: XXXXX | ||
| </ | </ | ||
services/docker-mirror.1605709297.txt.gz · Last modified: by djgalloway
