feat(registry): 开启 manifest 删除,GC sidecar 在 gate 只读窗口内回收 blob
This commit is contained in:
9 files changed
+806
-22
No files matched your search
+18
-1
@@ -2869,10 +2869,27 @@ push_image_to_registry() {
|
||||
esac
|
||||
log "mirroring ${ref} into the internal registry"
|
||||
docker tag "$ref" "$push_ref" || die "could not tag ${ref} as ${push_ref} — is docker healthy?"
|
||||
docker --config "$REGISTRY_DOCKER_CONFIG" push "$push_ref" || die "could not mirror ${ref} into the internal registry — check the registry Deployment/pod (both the registry and registry-gate containers) and its PVC"
|
||||
local attempt=1
|
||||
until docker --config "$REGISTRY_DOCKER_CONFIG" push "$push_ref"; do
|
||||
# The gate answers writes 503 while the registry-gc sidecar sweeps; wait
|
||||
# that out, and fail at once on anything else.
|
||||
if [ "$attempt" -ge 40 ] || ! registry_read_only; then
|
||||
die "could not mirror ${ref} into the internal registry — check the registry Deployment/pod (the registry, registry-gate and registry-gc containers) and its PVC"
|
||||
fi
|
||||
warn "the registry is read-only for garbage collection; retrying the push of ${push_ref} in 30s (${attempt}/40)"
|
||||
attempt=$((attempt + 1))
|
||||
sleep 30
|
||||
done
|
||||
docker rmi "$push_ref" >/dev/null 2>&1 || true
|
||||
}
|
||||
|
||||
# registry_read_only asks the gate, over its pod-loopback maintenance listener,
|
||||
# whether a garbage-collection window is open.
|
||||
registry_read_only() {
|
||||
kubectl -n "$CONTROL_NS" exec deploy/registry -c registry-gc -- \
|
||||
wget -q -O /dev/null "http://127.0.0.1:$((${REGISTRY_URL##*:} + 2))/readonly" >/dev/null 2>&1
|
||||
}
|
||||
|
||||
# registry_docker_login logs a throwaway docker config into the registry gate as
|
||||
# the platform principal: writes are refused anonymously, and this identity is
|
||||
# the only one allowed under felis/. The config lives in a 0700 temp dir that the
|
||||
|
||||
Reference in new issue
Block a user