hand the registry credentials to the nodes

A node that pulls an image authenticates as nobody unless the task carries
credentials, and the registry counts anonymous pulls per address, so the whole
estate shares one budget. Deployments and image updates now pass
--with-registry-auth, and --rotate-key writes the current credentials into every
service of a stack after the account token has been rotated, without touching
the images.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Marc WäckerlinandClaude Opus 5 committed 2026-09-30 15:30:47 +02:00
1 parent 4a9818c111
commit 469595d357
3 files changed
+35 -3

No files matched your search

+23 -2
View File
@@ -2,6 +2,7 @@
limit=''
force=''
rotate=''
while test $# -gt 0; do
case "$1" in
(-h|--help) cat <<EOF
@@ -12,6 +13,8 @@ OPTIONS
-h, --help show this help
-s, --limit service limit update to given service
-f, --force force update
-r, --rotate-key hand the current registry credentials to the
services and leave their images as they are
FILES…
@@ -22,10 +25,17 @@ DESCRIPTION
Updates the docker images of all services in the given stacks.
A service carries the registry credentials of the moment it was
deployed, and a node uses them when it pulls an image. After the
token of the registry account has been rotated, --rotate-key writes
the credentials of this machine into every service of the stacks,
without touching the image any service runs.
EOF
exit;;
(-l|--limit) shift; limit=$1;;
(-f|--force) force='--force';;
(-r|--rotate-key) rotate='yes';;
(*) break;;
esac
if test $# -lt 1; then
@@ -45,8 +55,19 @@ for f in $*; do
for param in $(sed -n '/^ *\([^:]\+\): *$/{s,,'"${name}"'_\1,;h};/^ *image: */{s///;G;s/\n/ /p}' $file); do
IFS=" "
if [ -z "$limit" ] || [[ "${param}" =~ " ${name}_${limit}" ]]; then
echo "....update $param: docker service update --image $param"
docker service update $force --image $param
# --with-registry-auth hands the credentials of this machine to the
# nodes that pull the image, as docker-deploy does
if test -n "$rotate"; then
# the service name is the second word of the pair, the image
# the first: only the credentials are written, the image of the
# service stays the one it runs
service=${param#* }
echo "....rotate key of $service"
docker service update --with-registry-auth $force $service
else
echo "....update $param: docker service update --image $param"
docker service update --with-registry-auth $force --image $param
fi
fi
done
done