diff --git a/README.md b/README.md index a7841b8..bfdc505 100644 --- a/README.md +++ b/README.md @@ -21,11 +21,15 @@ docker-deploy Just deploys a docker swarm stack from a yaml compose file. It saves me some typing. It scans the file for the volume pathes and creates them if they do not exist yet. Instead of the two commands `mkdir -p /var/volumes/my-service` and `docker stack deploy --compose-file my-service.yaml my-service`, I have to type only `docker-deploy my-service`. Yes, I am lazy. +The deployment runs with `--with-registry-auth`, so the registry credentials of the machine you deploy from travel to the nodes with every task. Run `docker login` there first: without credentials every node pulls anonymously, and the registry counts those pulls per address. + docker-update ------------- Script to update all or some images within declared in a yaml file. Use it to update the docker image of all or some services in your already deployed docker swarm stack. +With `--rotate-key` it writes the registry credentials of the machine you run it on into every service of the stack and leaves the images untouched. A service carries the credentials of the moment it was deployed, and a node uses them when it pulls, so after the token of the registry account has been rotated every service needs them once. + docker-build ------------ diff --git a/docker-deploy b/docker-deploy index 2debd69..5d7e28c 100755 --- a/docker-deploy +++ b/docker-deploy @@ -19,6 +19,10 @@ DESCRIPTION Deploys stack from yaml files. The stack name is identical to the file name, but wihout path and without .yaml extendsion. + The deployment carries the registry credentials of this machine to + the nodes, so run docker login here before deploying images from a + registry that asks for one or counts anonymous pulls. + EXAMPLS The following calls ado the same and deploy a local yaml file: @@ -52,5 +56,8 @@ for f in $*; do for d in $(sed -n 's,^ *source: \(/.*\),\1,p' ${f}.yaml); do test -e $d || mkdir -p $d done - docker stack deploy --compose-file ${f}.yaml ${f##*/} + # --with-registry-auth hands the credentials of this machine to the swarm + # managers, which pass them on with every task: without them each node + # pulls anonymously and runs into the pull limit of the registry + docker stack deploy --with-registry-auth --compose-file ${f}.yaml ${f##*/} done diff --git a/docker-update b/docker-update index 18137c1..eb18535 100755 --- a/docker-update +++ b/docker-update @@ -2,6 +2,7 @@ limit='' force='' +rotate='' while test $# -gt 0; do case "$1" in (-h|--help) cat <