hand the registry credentials to the nodes

A node that pulls an image authenticates as nobody unless the task carries
credentials, and the registry counts anonymous pulls per address, so the whole
estate shares one budget. Deployments and image updates now pass
--with-registry-auth, and --rotate-key writes the current credentials into every
service of a stack after the account token has been rotated, without touching
the images.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Marc WäckerlinandClaude Opus 5 committed 2026-09-30 15:30:47 +02:00
1 parent 4a9818c111
commit 469595d357
3 files changed
+35 -3

No files matched your search

+8 -1
View File
@@ -19,6 +19,10 @@ DESCRIPTION
Deploys stack from yaml files. The stack name is identical to the
file name, but wihout path and without .yaml extendsion.
The deployment carries the registry credentials of this machine to
the nodes, so run docker login here before deploying images from a
registry that asks for one or counts anonymous pulls.
EXAMPLS
The following calls ado the same and deploy a local yaml file:
@@ -52,5 +56,8 @@ for f in $*; do
for d in $(sed -n 's,^ *source: \(/.*\),\1,p' ${f}.yaml); do
test -e $d || mkdir -p $d
done
docker stack deploy --compose-file ${f}.yaml ${f##*/}
# --with-registry-auth hands the credentials of this machine to the swarm
# managers, which pass them on with every task: without them each node
# pulls anonymously and runs into the pull limit of the registry
docker stack deploy --with-registry-auth --compose-file ${f}.yaml ${f##*/}
done