Repository navigation
feat(container): support containerd ns query parameter for multi-registry mirroring - #417
Open
yunaremaia wants to merge 1 commit into
Open
yunaremaia wants to merge 1 commit into
yunaremaia wants to merge 1 commit into
Conversation
…stry mirroring
The container handler currently routes /v2/ requests by path only: unprefixed
names go to the default registry, and named upstreams require the reserved
upstream/{name}/ path prefix. containerd's hosts.toml mirror mechanism instead
appends ?ns=<registry-host> to every request, which the handler ignores today.
Add ns support so a single host entry can mirror every configured registry:
- Treat ns as a closed-world lookup key, never a dial target. Docker Hub
aliases (docker.io, index.docker.io, registry-1.docker.io) and the host of
the configured oci_default resolve to the default route; hosts derived from
the existing upstream.oci URLs resolve to their named upstream.
- Unknown ns returns an OCI-error 404 (NAME_UNKNOWN) so containerd falls back
to its next host / server entry. Requests without ns behave exactly as today.
- When ns is present, the path is the verbatim upstream repository; the
reserved upstream/ prefix is rejected on that route.
- ns is stripped before forwarding the tags-list query upstream.
- Cache identities are reused so an image pulled via ns, via upstream/{name}/,
or unprefixed shares cache entries.
- Host matching is case-insensitive and normalizes scheme-default ports.
The ns host index is built after NewContainerHandlerWithRegistry overrides the
default registry URL, otherwise a custom oci_default host would 404.
Closes git-pkgs#303
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The container handler currently routes
/v2/requests by path only: unprefixed names go to the default registry, and named upstreams require the reservedupstream/{name}/path prefix. containerd'shosts.tomlmirror mechanism instead appends?ns=<registry-host>to every request, which the handler ignores today. Multi-registry mirroring therefore needs onehosts.tomlper registry withoverride_path = truepointing at the matching prefix; wildcard setups (certs.d/_default, k3smirrors: "*") cannot work at all, because the mirror never learns which registry a request is for.This PR adds
nssupport so a single host entry can mirror every configured registry.Changes
nsresolves Docker Hub aliases (docker.io,index.docker.io,registry-1.docker.io) and the host of the configuredoci_defaultto the default route, and hosts derived from the existingupstream.ociURLs to their named upstream. No new config keys.nsreturns OCI-error 404 (NAME_UNKNOWN) so containerd falls back to its next host /serverentry. Requests withoutnsbehave exactly as today.nsis present; the reservedupstream/prefix is rejected on that route so ns-routed requests cannot mint cache keys belonging to the prefix route.nsis stripped before forwarding the tags-list query upstream (it previously leaked verbatim).ns, viaupstream/{name}/, or unprefixed shares cache entries; manifest keys already include the resolved registry URL.NewContainerHandlerWithRegistryoverrides the default registry URL, otherwise a customoci_defaulthost would 404.upstream.ocientries (or colliding with the default route) get a startup warning and a deterministic winner rather than a validation error.Test coverage
6 new tests covering:
nsrouting to default and named registriesns→ 404 with no upstream contactnsstripped from upstream queryoci_defaulthostFull handler suite passes (11.6s, 0 failures).
Closes #303