Loading
fix(platform): registry OOM (audit #46) + loopback hostPort — the node-side pull path
Two changes to the registry Deployment, both prerequisite to GC-durable images: - Dedicated resource template: the control plane's 256Mi memory limit was a live-bite bug (#46) — pushing a 475MB layer OOM-killed the registry mid-upload (dmesg oom-kill, oom_score_adj 989) and the push failed; the same push completes in 2s with 2Gi. Registry limits are now 1 CPU / 2Gi. - The container port carries hostPort 127.0.0.1:5000. Node containerd cannot reach the Service VIP (live stack: "Empty reply"), so the node-side pull path is a registries.yaml mirror rewriting registry.<ns>.svc:5000 onto http://127.0.0.1:5000, which lands on this hostPort. Loopback-only keeps the plain-HTTP registry off every other interface. Tests pin both: exactly one port with hostIP 127.0.0.1, and a memory limit >= 2Gi (exceeding the control-plane template) with the #46 evidence cited.