docker: trust the mesh's registry from the runtime's own module (hq issue 190)
The controller's private network writes insecure-registries into daemon.json, a file this
module owns. The runtime's module states it instead, through ${seat:mesh-artifact-store:reach}
(hq ADR 0222), so the controller can stop generating its registry-trust resources.
This commit is contained in:
+26
-13
@@ -14,7 +14,7 @@ tools below are the module's own.
|
||||
| `socket` | `docker.socket` running, enabled at boot | given back as found when the module goes (ADR 0118) |
|
||||
| `prune-service`, `prune-timer` | `/etc/systemd/system/docker-prune.{service,timer}`, written whole | removed with the module |
|
||||
| `prune` | `docker-prune.timer` running, enabled at boot; restarted when either file changes | stopped and disabled with the module (the mesh made the unit) |
|
||||
| `daemon` | `live-restore` written into `/etc/docker/daemon.json`, beside other keys | the key given back as found when the module goes |
|
||||
| `daemon` | `live-restore` and the mesh's registry in `insecure-registries` written into `/etc/docker/daemon.json`, beside other keys | each key given back as found when the module goes; only the member this module added leaves the list |
|
||||
| `runtime` | `docker.service` running, enabled at boot; reloaded, never restarted, when `daemon` changes | given back as found (ADR 0118) |
|
||||
|
||||
The weekly prune takes **dangling images and build cache unused for a week, and nothing else**. It
|
||||
@@ -26,16 +26,26 @@ while the machine was off happens at the next boot.
|
||||
`container-runtime`: under ADR 0165, which is still proposed, that word means a running daemon, and
|
||||
the module that installs the daemon cannot require it.
|
||||
|
||||
## The runtime's own file and service (issue 190, hq ADR 0196)
|
||||
## The runtime's own file and service (issue 190, hq ADR 0196, ADR 0222)
|
||||
|
||||
This module writes one key into `/etc/docker/daemon.json` (`into: json`, ADR 0102): `live-restore`.
|
||||
`dnsmasq` used to write it, beside `dns`; it no longer writes either. Under ADR 0196 a container
|
||||
copies its machine's resolvers, so no module writes `dns`.
|
||||
This module writes two keys into `/etc/docker/daemon.json` (`into: json`, ADR 0102): `live-restore`
|
||||
and `insecure-registries`. `dnsmasq` used to write `live-restore`, beside `dns`; it no longer writes
|
||||
either. Under ADR 0196 a container copies its machine's resolvers, so no module writes `dns`. The
|
||||
controller's private network wrote `insecure-registries`; under ADR 0222 the controller writes
|
||||
nothing into this file, and this module states the registry itself (the order below).
|
||||
|
||||
- `daemon`: `{"live-restore": true}`, merged into the file beside the keys others write.
|
||||
- `daemon`: `{"live-restore": true, "insecure-registries": ["${seat:mesh-artifact-store:reach}"]}`,
|
||||
merged into the file beside the keys others write.
|
||||
- `${seat:mesh-artifact-store:reach}` is where this machine reaches the mesh's artifact store
|
||||
(host:port), filled in by the controller: no binding, no credential, the same address the mesh
|
||||
composes into every image it built. Trusting it in the clear is ADR 0082's decision: every path to
|
||||
it is inside the private network's encryption. While no machine on the network holds the store the
|
||||
answer is empty, and the controller drops the empty member, so the list gets nothing.
|
||||
- `insecure-registries` is a list, and the host adds to it rather than replacing it: a machine's own
|
||||
trusted registries stay, and undeclaring takes out only the member this module added.
|
||||
- `runtime`: `docker.service` running, enabled at boot, and **reloaded, never restarted**, when
|
||||
`daemon` changes. A restart stops every container. A reload turns `live-restore` on, and with it on
|
||||
a later restart keeps every container running.
|
||||
`daemon` changes. A restart stops every container. A reload turns `live-restore` on and takes the
|
||||
trusted registries, and with `live-restore` on a later restart keeps every container running.
|
||||
|
||||
In the apply that moves the key, the host first gives back `dnsmasq`'s resources, then applies this
|
||||
module's: `live-restore` is set again in the same apply, and the daemon is reloaded once.
|
||||
@@ -44,13 +54,16 @@ module's: `live-restore` is set again in the same apply, and the daemon is reloa
|
||||
container keeps the resolvers it was created with. Each container pinned to a machine's own resolver
|
||||
is restarted before that machine's `dnsmasq` goes (ADR 0194, step 4).
|
||||
|
||||
**The order it lands in.** The controller that fills `${seat:…:reach}` is deployed first: one that
|
||||
does not know the placeholder would send it through unfilled. Then this module. Then the controller
|
||||
stops generating the private network's `registry-trust` and `registry-trust-reload` and refuses a
|
||||
generated resource that collides with a module's (issue 190, steps 2 and 5). In the apply that moves
|
||||
the member, the host removes the private network's record first (the member leaves the list) and
|
||||
then applies this module's (it is added back, recorded as this module's); the daemon is reloaded
|
||||
once, for `daemon`. The address is the same one, so the runtime's trust does not change.
|
||||
|
||||
Still elsewhere:
|
||||
|
||||
- **The private network**, generated by the controller (`internal/overlay/generator.go`), writes
|
||||
`insecure-registries`. The collision check does not see generated resources. **Later:** the
|
||||
controller hands the registry to this module as a value, and the overlay stops generating its two
|
||||
resources (issue 190, steps 2 and 5). The host merges disjoint keys correctly; the mesh-host
|
||||
`into.go` record is per resource.
|
||||
- **Nobody** writes log rotation. One machine has `log-driver` and `log-opts` by hand; they are left
|
||||
as they are until a size is chosen for every machine.
|
||||
|
||||
|
||||
@@ -56,7 +56,7 @@
|
||||
"path": "/etc/docker/daemon.json",
|
||||
"mode": "0644",
|
||||
"into": "json",
|
||||
"content": "{\"live-restore\": true}\n"
|
||||
"content": "{\"live-restore\": true, \"insecure-registries\": [\"${seat:mesh-artifact-store:reach}\"]}\n"
|
||||
},
|
||||
{
|
||||
"id": "runtime",
|
||||
|
||||
Reference in New Issue
Block a user