feat(registry): api 定期删除无引用 manifest,gate 提供 manifest 索引

This commit is contained in:
Lemon-miaow committed 2026-09-24 22:58:07 +08:00
1 parent 05e8c64e47
commit 151c9d2e30
14 files changed
+1061 -8

No files matched your search

+16
View File
@@ -151,6 +151,16 @@ const (
// [smtp] password_ref defaults to this name.
SMTPPasswordEnv = "FELIS_SMTP_PASSWORD"
// RegistryPruneTokenEnv carries the registry gate's prune principal token into
// felis-api, whose pruner deletes the manifests nothing references
// (internal/registryprune). It comes from the prune key of
// naming.RegistryAuthSecretName, optionally: that Secret lives in the registry
// namespace, which is the control namespace on every install the bootstrap
// makes, and an install that splits them or predates the key runs without the
// pruner.
RegistryPruneTokenEnv = "FELIS_REGISTRY_PRUNE_TOKEN"
registryPruneTokenKey = "prune"
// worldsMountPath is where the reaper CronJob mounts the worlds-root (read-only).
// It is the default of `felis reaper --worlds-root`; the resolver then reads each
// world at <worldsMountPath>/<pvc>. Single-sourced with cmd/felis/reaper.go.
@@ -339,6 +349,9 @@ func APIDeployment(p Params) *appsv1.Deployment {
corev1.EnvVar{Name: SMTPPasswordEnv, ValueFrom: &corev1.EnvVarSource{SecretKeyRef: &corev1.SecretKeySelector{
LocalObjectReference: corev1.LocalObjectReference{Name: SMTPSecretName}, Key: SMTPSecretPasswordKey, Optional: optional,
}}},
corev1.EnvVar{Name: RegistryPruneTokenEnv, ValueFrom: &corev1.EnvVarSource{SecretKeyRef: &corev1.SecretKeySelector{
LocalObjectReference: corev1.LocalObjectReference{Name: naming.RegistryAuthSecretName}, Key: registryPruneTokenKey, Optional: optional,
}}},
)
container := corev1.Container{
@@ -869,6 +882,8 @@ func registryDeployment(p Params) *appsv1.Deployment {
"--auth-dir=" + registryAuthMountPath,
fmt.Sprintf("--maint-listen=127.0.0.1:%d", registryMaintPort(p)),
"--maint-dir=" + registryMaintMountPath,
// The manifest index felis-api's pruner reads (registrygate/index.go).
"--data-dir=" + registryDataPath,
},
Ports: []corev1.ContainerPort{
{
@@ -881,6 +896,7 @@ func registryDeployment(p Params) *appsv1.Deployment {
VolumeMounts: []corev1.VolumeMount{
{Name: registryAuthVolume, MountPath: registryAuthMountPath, ReadOnly: true},
{Name: registryMaintVolume, MountPath: registryMaintMountPath},
{Name: registryVolume, MountPath: registryDataPath, ReadOnly: true},
},
// /healthz answers 200 only while registry:2 answers GET /v2/ on loopback,
// so a registry whose storage broke shows up as an unready pod instead of a