hand the registry credentials to the nodes
A node that pulls an image authenticates as nobody unless the task carries credentials, and the registry counts anonymous pulls per address, so the whole estate shares one budget. Deployments and image updates now pass --with-registry-auth, and --rotate-key writes the current credentials into every service of a stack after the account token has been rotated, without touching the images. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
1 parent
4a9818c111
commit
469595d357
3 files changed
+35
-3
No files matched your search
@@ -21,11 +21,15 @@ docker-deploy
|
||||
|
||||
Just deploys a docker swarm stack from a yaml compose file. It saves me some typing. It scans the file for the volume pathes and creates them if they do not exist yet. Instead of the two commands `mkdir -p /var/volumes/my-service` and `docker stack deploy --compose-file my-service.yaml my-service`, I have to type only `docker-deploy my-service`. Yes, I am lazy.
|
||||
|
||||
The deployment runs with `--with-registry-auth`, so the registry credentials of the machine you deploy from travel to the nodes with every task. Run `docker login` there first: without credentials every node pulls anonymously, and the registry counts those pulls per address.
|
||||
|
||||
docker-update
|
||||
-------------
|
||||
|
||||
Script to update all or some images within declared in a yaml file. Use it to update the docker image of all or some services in your already deployed docker swarm stack.
|
||||
|
||||
With `--rotate-key` it writes the registry credentials of the machine you run it on into every service of the stack and leaves the images untouched. A service carries the credentials of the moment it was deployed, and a node uses them when it pulls, so after the token of the registry account has been rotated every service needs them once.
|
||||
|
||||
docker-build
|
||||
------------
|
||||
|
||||
|
||||
+8
-1
@@ -19,6 +19,10 @@ DESCRIPTION
|
||||
Deploys stack from yaml files. The stack name is identical to the
|
||||
file name, but wihout path and without .yaml extendsion.
|
||||
|
||||
The deployment carries the registry credentials of this machine to
|
||||
the nodes, so run docker login here before deploying images from a
|
||||
registry that asks for one or counts anonymous pulls.
|
||||
|
||||
EXAMPLS
|
||||
|
||||
The following calls ado the same and deploy a local yaml file:
|
||||
@@ -52,5 +56,8 @@ for f in $*; do
|
||||
for d in $(sed -n 's,^ *source: \(/.*\),\1,p' ${f}.yaml); do
|
||||
test -e $d || mkdir -p $d
|
||||
done
|
||||
docker stack deploy --compose-file ${f}.yaml ${f##*/}
|
||||
# --with-registry-auth hands the credentials of this machine to the swarm
|
||||
# managers, which pass them on with every task: without them each node
|
||||
# pulls anonymously and runs into the pull limit of the registry
|
||||
docker stack deploy --with-registry-auth --compose-file ${f}.yaml ${f##*/}
|
||||
done
|
||||
+23
-2
@@ -2,6 +2,7 @@
|
||||
|
||||
limit=''
|
||||
force=''
|
||||
rotate=''
|
||||
while test $# -gt 0; do
|
||||
case "$1" in
|
||||
(-h|--help) cat <<EOF
|
||||
@@ -12,6 +13,8 @@ OPTIONS
|
||||
-h, --help show this help
|
||||
-s, --limit service limit update to given service
|
||||
-f, --force force update
|
||||
-r, --rotate-key hand the current registry credentials to the
|
||||
services and leave their images as they are
|
||||
|
||||
FILES…
|
||||
|
||||
@@ -22,10 +25,17 @@ DESCRIPTION
|
||||
|
||||
Updates the docker images of all services in the given stacks.
|
||||
|
||||
A service carries the registry credentials of the moment it was
|
||||
deployed, and a node uses them when it pulls an image. After the
|
||||
token of the registry account has been rotated, --rotate-key writes
|
||||
the credentials of this machine into every service of the stacks,
|
||||
without touching the image any service runs.
|
||||
|
||||
EOF
|
||||
exit;;
|
||||
(-l|--limit) shift; limit=$1;;
|
||||
(-f|--force) force='--force';;
|
||||
(-r|--rotate-key) rotate='yes';;
|
||||
(*) break;;
|
||||
esac
|
||||
if test $# -lt 1; then
|
||||
@@ -45,8 +55,19 @@ for f in $*; do
|
||||
for param in $(sed -n '/^ *\([^:]\+\): *$/{s,,'"${name}"'_\1,;h};/^ *image: */{s///;G;s/\n/ /p}' $file); do
|
||||
IFS=" "
|
||||
if [ -z "$limit" ] || [[ "${param}" =~ " ${name}_${limit}" ]]; then
|
||||
echo "....update $param: docker service update --image $param"
|
||||
docker service update $force --image $param
|
||||
# --with-registry-auth hands the credentials of this machine to the
|
||||
# nodes that pull the image, as docker-deploy does
|
||||
if test -n "$rotate"; then
|
||||
# the service name is the second word of the pair, the image
|
||||
# the first: only the credentials are written, the image of the
|
||||
# service stays the one it runs
|
||||
service=${param#* }
|
||||
echo "....rotate key of $service"
|
||||
docker service update --with-registry-auth $force $service
|
||||
else
|
||||
echo "....update $param: docker service update --image $param"
|
||||
docker service update --with-registry-auth $force --image $param
|
||||
fi
|
||||
fi
|
||||
done
|
||||
done
|
||||
|
||||
Reference in new issue
Block a user