From 964a4fdfbcacd38170fc4da880e8c87aee5bb349 Mon Sep 17 00:00:00 2001 From: jochen Date: Mon, 5 Oct 2026 22:17:16 +0200 Subject: [PATCH] docker: trust the mesh's registry from the runtime's own module (hq issue 190) The controller's private network writes insecure-registries into daemon.json, a file this module owns. The runtime's module states it instead, through ${seat:mesh-artifact-store:reach} (hq ADR 0222), so the controller can stop generating its registry-trust resources. --- modules/docker/README.md | 39 +++++++++++++++++++++++++------------- modules/docker/module.json | 2 +- 2 files changed, 27 insertions(+), 14 deletions(-) diff --git a/modules/docker/README.md b/modules/docker/README.md index 411ec2c..24815f6 100644 --- a/modules/docker/README.md +++ b/modules/docker/README.md @@ -14,7 +14,7 @@ tools below are the module's own. | `socket` | `docker.socket` running, enabled at boot | given back as found when the module goes (ADR 0118) | | `prune-service`, `prune-timer` | `/etc/systemd/system/docker-prune.{service,timer}`, written whole | removed with the module | | `prune` | `docker-prune.timer` running, enabled at boot; restarted when either file changes | stopped and disabled with the module (the mesh made the unit) | -| `daemon` | `live-restore` written into `/etc/docker/daemon.json`, beside other keys | the key given back as found when the module goes | +| `daemon` | `live-restore` and the mesh's registry in `insecure-registries` written into `/etc/docker/daemon.json`, beside other keys | each key given back as found when the module goes; only the member this module added leaves the list | | `runtime` | `docker.service` running, enabled at boot; reloaded, never restarted, when `daemon` changes | given back as found (ADR 0118) | The weekly prune takes **dangling images and build cache unused for a week, and nothing else**. It @@ -26,16 +26,26 @@ while the machine was off happens at the next boot. `container-runtime`: under ADR 0165, which is still proposed, that word means a running daemon, and the module that installs the daemon cannot require it. -## The runtime's own file and service (issue 190, hq ADR 0196) +## The runtime's own file and service (issue 190, hq ADR 0196, ADR 0222) -This module writes one key into `/etc/docker/daemon.json` (`into: json`, ADR 0102): `live-restore`. -`dnsmasq` used to write it, beside `dns`; it no longer writes either. Under ADR 0196 a container -copies its machine's resolvers, so no module writes `dns`. +This module writes two keys into `/etc/docker/daemon.json` (`into: json`, ADR 0102): `live-restore` +and `insecure-registries`. `dnsmasq` used to write `live-restore`, beside `dns`; it no longer writes +either. Under ADR 0196 a container copies its machine's resolvers, so no module writes `dns`. The +controller's private network wrote `insecure-registries`; under ADR 0222 the controller writes +nothing into this file, and this module states the registry itself (the order below). -- `daemon`: `{"live-restore": true}`, merged into the file beside the keys others write. +- `daemon`: `{"live-restore": true, "insecure-registries": ["${seat:mesh-artifact-store:reach}"]}`, + merged into the file beside the keys others write. +- `${seat:mesh-artifact-store:reach}` is where this machine reaches the mesh's artifact store + (host:port), filled in by the controller: no binding, no credential, the same address the mesh + composes into every image it built. Trusting it in the clear is ADR 0082's decision: every path to + it is inside the private network's encryption. While no machine on the network holds the store the + answer is empty, and the controller drops the empty member, so the list gets nothing. +- `insecure-registries` is a list, and the host adds to it rather than replacing it: a machine's own + trusted registries stay, and undeclaring takes out only the member this module added. - `runtime`: `docker.service` running, enabled at boot, and **reloaded, never restarted**, when - `daemon` changes. A restart stops every container. A reload turns `live-restore` on, and with it on - a later restart keeps every container running. + `daemon` changes. A restart stops every container. A reload turns `live-restore` on and takes the + trusted registries, and with `live-restore` on a later restart keeps every container running. In the apply that moves the key, the host first gives back `dnsmasq`'s resources, then applies this module's: `live-restore` is set again in the same apply, and the daemon is reloaded once. @@ -44,13 +54,16 @@ module's: `live-restore` is set again in the same apply, and the daemon is reloa container keeps the resolvers it was created with. Each container pinned to a machine's own resolver is restarted before that machine's `dnsmasq` goes (ADR 0194, step 4). +**The order it lands in.** The controller that fills `${seat:…:reach}` is deployed first: one that +does not know the placeholder would send it through unfilled. Then this module. Then the controller +stops generating the private network's `registry-trust` and `registry-trust-reload` and refuses a +generated resource that collides with a module's (issue 190, steps 2 and 5). In the apply that moves +the member, the host removes the private network's record first (the member leaves the list) and +then applies this module's (it is added back, recorded as this module's); the daemon is reloaded +once, for `daemon`. The address is the same one, so the runtime's trust does not change. + Still elsewhere: -- **The private network**, generated by the controller (`internal/overlay/generator.go`), writes - `insecure-registries`. The collision check does not see generated resources. **Later:** the - controller hands the registry to this module as a value, and the overlay stops generating its two - resources (issue 190, steps 2 and 5). The host merges disjoint keys correctly; the mesh-host - `into.go` record is per resource. - **Nobody** writes log rotation. One machine has `log-driver` and `log-opts` by hand; they are left as they are until a size is chosen for every machine. diff --git a/modules/docker/module.json b/modules/docker/module.json index cdf7056..0a66a63 100644 --- a/modules/docker/module.json +++ b/modules/docker/module.json @@ -56,7 +56,7 @@ "path": "/etc/docker/daemon.json", "mode": "0644", "into": "json", - "content": "{\"live-restore\": true}\n" + "content": "{\"live-restore\": true, \"insecure-registries\": [\"${seat:mesh-artifact-store:reach}\"]}\n" }, { "id": "runtime",