docker: trust the mesh's registry from the runtime's own module (hq issue 190)

The controller's private network writes insecure-registries into daemon.json, a file this
module owns. The runtime's module states it instead, through ${seat:mesh-artifact-store:reach}
(hq ADR 0222), so the controller can stop generating its registry-trust resources.
This commit is contained in:
jochen
2026-10-05 22:17:16 +02:00
parent 20603b63e6
commit 964a4fdfbc
2 changed files with 27 additions and 14 deletions
+26 -13
View File
@@ -14,7 +14,7 @@ tools below are the module's own.
| `socket` | `docker.socket` running, enabled at boot | given back as found when the module goes (ADR 0118) |
| `prune-service`, `prune-timer` | `/etc/systemd/system/docker-prune.{service,timer}`, written whole | removed with the module |
| `prune` | `docker-prune.timer` running, enabled at boot; restarted when either file changes | stopped and disabled with the module (the mesh made the unit) |
| `daemon` | `live-restore` written into `/etc/docker/daemon.json`, beside other keys | the key given back as found when the module goes |
| `daemon` | `live-restore` and the mesh's registry in `insecure-registries` written into `/etc/docker/daemon.json`, beside other keys | each key given back as found when the module goes; only the member this module added leaves the list |
| `runtime` | `docker.service` running, enabled at boot; reloaded, never restarted, when `daemon` changes | given back as found (ADR 0118) |
The weekly prune takes **dangling images and build cache unused for a week, and nothing else**. It
@@ -26,16 +26,26 @@ while the machine was off happens at the next boot.
`container-runtime`: under ADR 0165, which is still proposed, that word means a running daemon, and
the module that installs the daemon cannot require it.
## The runtime's own file and service (issue 190, hq ADR 0196)
## The runtime's own file and service (issue 190, hq ADR 0196, ADR 0222)
This module writes one key into `/etc/docker/daemon.json` (`into: json`, ADR 0102): `live-restore`.
`dnsmasq` used to write it, beside `dns`; it no longer writes either. Under ADR 0196 a container
copies its machine's resolvers, so no module writes `dns`.
This module writes two keys into `/etc/docker/daemon.json` (`into: json`, ADR 0102): `live-restore`
and `insecure-registries`. `dnsmasq` used to write `live-restore`, beside `dns`; it no longer writes
either. Under ADR 0196 a container copies its machine's resolvers, so no module writes `dns`. The
controller's private network wrote `insecure-registries`; under ADR 0222 the controller writes
nothing into this file, and this module states the registry itself (the order below).
- `daemon`: `{"live-restore": true}`, merged into the file beside the keys others write.
- `daemon`: `{"live-restore": true, "insecure-registries": ["${seat:mesh-artifact-store:reach}"]}`,
merged into the file beside the keys others write.
- `${seat:mesh-artifact-store:reach}` is where this machine reaches the mesh's artifact store
(host:port), filled in by the controller: no binding, no credential, the same address the mesh
composes into every image it built. Trusting it in the clear is ADR 0082's decision: every path to
it is inside the private network's encryption. While no machine on the network holds the store the
answer is empty, and the controller drops the empty member, so the list gets nothing.
- `insecure-registries` is a list, and the host adds to it rather than replacing it: a machine's own
trusted registries stay, and undeclaring takes out only the member this module added.
- `runtime`: `docker.service` running, enabled at boot, and **reloaded, never restarted**, when
`daemon` changes. A restart stops every container. A reload turns `live-restore` on, and with it on
a later restart keeps every container running.
`daemon` changes. A restart stops every container. A reload turns `live-restore` on and takes the
trusted registries, and with `live-restore` on a later restart keeps every container running.
In the apply that moves the key, the host first gives back `dnsmasq`'s resources, then applies this
module's: `live-restore` is set again in the same apply, and the daemon is reloaded once.
@@ -44,13 +54,16 @@ module's: `live-restore` is set again in the same apply, and the daemon is reloa
container keeps the resolvers it was created with. Each container pinned to a machine's own resolver
is restarted before that machine's `dnsmasq` goes (ADR 0194, step 4).
**The order it lands in.** The controller that fills `${seat:…:reach}` is deployed first: one that
does not know the placeholder would send it through unfilled. Then this module. Then the controller
stops generating the private network's `registry-trust` and `registry-trust-reload` and refuses a
generated resource that collides with a module's (issue 190, steps 2 and 5). In the apply that moves
the member, the host removes the private network's record first (the member leaves the list) and
then applies this module's (it is added back, recorded as this module's); the daemon is reloaded
once, for `daemon`. The address is the same one, so the runtime's trust does not change.
Still elsewhere:
- **The private network**, generated by the controller (`internal/overlay/generator.go`), writes
`insecure-registries`. The collision check does not see generated resources. **Later:** the
controller hands the registry to this module as a value, and the overlay stops generating its two
resources (issue 190, steps 2 and 5). The host merges disjoint keys correctly; the mesh-host
`into.go` record is per resource.
- **Nobody** writes log rotation. One machine has `log-driver` and `log-opts` by hand; they are left
as they are until a size is chosen for every machine.
+1 -1
View File
@@ -56,7 +56,7 @@
"path": "/etc/docker/daemon.json",
"mode": "0644",
"into": "json",
"content": "{\"live-restore\": true}\n"
"content": "{\"live-restore\": true, \"insecure-registries\": [\"${seat:mesh-artifact-store:reach}\"]}\n"
},
{
"id": "runtime",