services:quay.ceph.io
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| services:quay.ceph.io [2020/08/06 19:39] – [Letsencrypt] djgalloway | services:quay.ceph.io [2026/10/02 18:58] (current) – [Superuser login] djgalloway | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| ====== quay.ceph.io ====== | ====== quay.ceph.io ====== | ||
| ===== Summary ===== | ===== Summary ===== | ||
| - | This is a VM in [[services: | + | quay.ceph.io migrated from AWS to the lab on 2026-09-09. |
| - | SSH only listens on the front interface at quay.front.sepia.ceph.com. | + | Public path: NS1 A record -> 192.86.31.16 -> edge proxy -> the OpenShift route. There is deliberately **no Anubis** in front of it - registry clients can't answer challenges. |
| - | Due to the potentially large number of container images we'd be storing, I opted to use the [[services: | + | '' |
| - | I just chose quay because it was the same software/ | + | ===== Admin Tasks ===== |
| + | ==== Superuser login ==== | ||
| + | '' | ||
| - | Passwords are in '' | + | ==== Renewing the cert ==== |
| + | The in-pod cert is manual acme.sh - see MIGRATION.md. | ||
| - | I had some trouble getting | + | ===== Troubleshooting ===== |
| - | ===== Setup Commands ===== | + | ==== Pulls fail with 401/ |
| + | cephadm' | ||
| < | < | ||
| - | ## On reesi001 | + | # diagnose without touching secrets |
| - | ceph auth add client.containers mds 'allow rw path=/containers' | + | sudo podman login --get-login --authfile /etc/ceph/podman-auth.json quay.ceph.io |
| - | ceph auth get client.containers | + | # fix: re-run registry-login with url: quay.ceph.io (hostname only) |
| - | # Copy the key output | + | ceph cephadm registry-login -i login.json |
| + | </ | ||
| + | On the Quay side, app pod nginx logs show '' | ||
| - | ## On quay.front.sepia.ceph.com | + | ==== External pulls hang/fail on blob GETs ==== |
| - | # run the ansible_managed and common roles | + | Quay presign-redirects blob GETs to RGW. Two requirements, |
| - | yum localinstall http:// | + | * '' |
| - | yum install ceph-common | + | * The '' |
| - | mkdir /lrc | + | |
| - | echo "172.21.2.201, | + | |
| - | echo " | + | |
| - | mount -a | + | |
| - | # Then I just followed https://access.redhat.com/documentation/ | + | ==== Anonymous CI pulls of mirror/* repos 401 ==== |
| - | </ | + | Proxy-cache repos are born **private**, |
| - | ===== Letsencrypt ===== | + | ==== Config bundle changes get reverted |
| - | Since the quay container listens on port 80 and 443, we have to temporarily stop it to renew the cert. | + | The operator force-overrides some keys when the component is managed (e.g. '' |
| + | ==== Who changed something ==== | ||
| + | Console Logs view, **audit tenant**: | ||
| < | < | ||
| - | [root@quay ~]# crontab -l | + | {log_type=" |
| - | # On the first Saturday of Feb, | + | |
| - | 0 4 * 2, | + | |
| - | + | ||
| - | [root@quay ~]# cat / | + | |
| - | # | + | |
| - | for container in $(docker ps | grep "quay\.io" | awk '{ print $1 }'); do docker stop $container; done | + | |
| - | certbot renew | + | |
| - | docker run --restart=always -p 443:8443 -p 80:8080 --sysctl net.core.somaxconn=4096 --privileged=true -v /etc/quay:/ | + | |
| </ | </ | ||
| + | See [[services: | ||
| + | |||
services/quay.ceph.io.1596742798.txt.gz · Last modified: by djgalloway
