Repository navigation
feat(container): support containerd ns query parameter for multi-registry mirroring - #417
yunaremaia wants to merge 1 commit into
Conversation
…stry mirroring
The container handler currently routes /v2/ requests by path only: unprefixed
names go to the default registry, and named upstreams require the reserved
upstream/{name}/ path prefix. containerd's hosts.toml mirror mechanism instead
appends ?ns=<registry-host> to every request, which the handler ignores today.
Add ns support so a single host entry can mirror every configured registry:
- Treat ns as a closed-world lookup key, never a dial target. Docker Hub
aliases (docker.io, index.docker.io, registry-1.docker.io) and the host of
the configured oci_default resolve to the default route; hosts derived from
the existing upstream.oci URLs resolve to their named upstream.
- Unknown ns returns an OCI-error 404 (NAME_UNKNOWN) so containerd falls back
to its next host / server entry. Requests without ns behave exactly as today.
- When ns is present, the path is the verbatim upstream repository; the
reserved upstream/ prefix is rejected on that route.
- ns is stripped before forwarding the tags-list query upstream.
- Cache identities are reused so an image pulled via ns, via upstream/{name}/,
or unprefixed shares cache entries.
- Host matching is case-insensitive and normalizes scheme-default ports.
The ns host index is built after NewContainerHandlerWithRegistry overrides the
default registry URL, otherwise a custom oci_default host would 404.
Closes git-pkgs#303
|
Closing as a duplicate of #405, which implements the same Comparing the two: #405 covers the same closed-world lookup, Docker Hub aliases, case-insensitive host matching, Nothing in this PR is unique enough to keep open. Thanks for the review exchange on #405 — the |
Summary
The container handler currently routes
/v2/requests by path only: unprefixed names go to the default registry, and named upstreams require the reservedupstream/{name}/path prefix. containerd'shosts.tomlmirror mechanism instead appends?ns=<registry-host>to every request, which the handler ignores today. Multi-registry mirroring therefore needs onehosts.tomlper registry withoverride_path = truepointing at the matching prefix; wildcard setups (certs.d/_default, k3smirrors: "*") cannot work at all, because the mirror never learns which registry a request is for.This PR adds
nssupport so a single host entry can mirror every configured registry.Changes
nsresolves Docker Hub aliases (docker.io,index.docker.io,registry-1.docker.io) and the host of the configuredoci_defaultto the default route, and hosts derived from the existingupstream.ociURLs to their named upstream. No new config keys.nsreturns OCI-error 404 (NAME_UNKNOWN) so containerd falls back to its next host /serverentry. Requests withoutnsbehave exactly as today.nsis present; the reservedupstream/prefix is rejected on that route so ns-routed requests cannot mint cache keys belonging to the prefix route.nsis stripped before forwarding the tags-list query upstream (it previously leaked verbatim).ns, viaupstream/{name}/, or unprefixed shares cache entries; manifest keys already include the resolved registry URL.NewContainerHandlerWithRegistryoverrides the default registry URL, otherwise a customoci_defaulthost would 404.upstream.ocientries (or colliding with the default route) get a startup warning and a deterministic winner rather than a validation error.Test coverage
6 new tests covering:
nsrouting to default and named registriesns→ 404 with no upstream contactnsstripped from upstream queryoci_defaulthostFull handler suite passes (11.6s, 0 failures).
Closes #303