services:quay.ceph.io
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| services:quay.ceph.io [2024/03/04 21:29] – zmc | services:quay.ceph.io [2026/10/02 18:58] (current) – [Superuser login] djgalloway | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| ====== quay.ceph.io ====== | ====== quay.ceph.io ====== | ||
| - | ===== Pulling from quay.ceph.io | + | ===== Summary |
| - | In Quay' | + | quay.ceph.io migrated from AWS to the lab on 2026-09-09. |
| - | '' | + | Public path: NS1 A record |
| - | These will work just fine when connected to the Sepia VPN. A public endpoint | + | '' |
| - | '' | + | ===== Admin Tasks ===== |
| + | ==== Superuser login ==== | ||
| + | '' | ||
| - | ===== Operations Summary ===== | + | ==== Renewing the cert ==== |
| - | This is a VM in [[services: | + | The in-pod cert is manual acme.sh - see MIGRATION.md. It does **not** auto-renew. |
| - | SSH only listens | + | ===== Troubleshooting ===== |
| - | + | ==== Pulls fail with 401/ | |
| - | Due to the potentially large number of container images we'd be storing, I opted to use the [[services: | + | cephadm's stored registry login must use the **bare hostname**. |
| - | + | ||
| - | I just chose quay because it was the same software/ | + | |
| - | + | ||
| - | Passwords are in '' | + | |
| - | + | ||
| - | I had some trouble getting the containers to communicate with one another. The Quay docs don't cover setting up the '' | + | |
| - | + | ||
| - | ===== Setup Commands ===== | + | |
| - | From dmick, 3Nov22: apparently this has changed a bit; it looks like the client.container auth doesn' | + | |
| < | < | ||
| - | ## On reesi001 | + | # diagnose without touching secrets |
| - | ceph auth add client.containers mds 'allow rw path=/containers' | + | sudo podman login --get-login --authfile /etc/ceph/podman-auth.json quay.ceph.io |
| - | ceph auth get client.containers | + | # fix: re-run registry-login with url: quay.ceph.io (hostname only) |
| - | # Copy the key output | + | ceph cephadm registry-login -i login.json |
| - | + | ||
| - | ## On quay.front.sepia.ceph.com | + | |
| - | # run the ansible_managed and common roles | + | |
| - | yum localinstall http:// | + | |
| - | yum install | + | |
| - | mkdir /lrc | + | |
| - | echo "172.21.2.201, | + | |
| - | echo " | + | |
| - | mount -a | + | |
| - | + | ||
| - | # Then I just followed https:// | + | |
| </ | </ | ||
| + | On the Quay side, app pod nginx logs show '' | ||
| + | ==== External pulls hang/fail on blob GETs ==== | ||
| + | Quay presign-redirects blob GETs to RGW. Two requirements, | ||
| + | * '' | ||
| + | * The '' | ||
| + | ==== Anonymous CI pulls of mirror/* repos 401 ==== | ||
| + | Proxy-cache repos are born **private**, | ||
| - | ===== Letsencrypt ===== | + | ==== Config bundle changes get reverted |
| - | Since the quay container listens on port 80 and 443, we have to temporarily stop it to renew the cert. | + | The operator force-overrides some keys when the component is managed (e.g. '' |
| + | ==== Who changed something ==== | ||
| + | Console Logs view, **audit tenant**: | ||
| < | < | ||
| - | [root@quay ~]# crontab -l | + | {log_type=" |
| - | # On the first Saturday of Feb, | + | </ |
| - | 0 4 * 2, | + | See [[services: |
| - | [root@quay ~]# cat / | ||
| - | #!/bin/bash | ||
| - | for container in $(docker ps | grep " | ||
| - | certbot renew | ||
| - | docker run --restart=always -p 443:8443 -p 80:8080 --sysctl net.core.somaxconn=4096 --privileged=true -v / | ||
| - | </ | ||
services/quay.ceph.io.1709587750.txt.gz · Last modified: by zmc
