docker: trust the mesh's registry from the runtime's own module (hq issue 190)

The controller's private network writes insecure-registries into daemon.json, a file this
module owns. The runtime's module states it instead, through ${seat:mesh-artifact-store:reach}
(hq ADR 0222), so the controller can stop generating its registry-trust resources.
This commit is contained in:
jochen
2026-10-05 22:17:16 +02:00
parent 20603b63e6
commit 964a4fdfbc
2 changed files with 27 additions and 14 deletions
+1 -1
View File
@@ -56,7 +56,7 @@
"path": "/etc/docker/daemon.json",
"mode": "0644",
"into": "json",
"content": "{\"live-restore\": true}\n"
"content": "{\"live-restore\": true, \"insecure-registries\": [\"${seat:mesh-artifact-store:reach}\"]}\n"
},
{
"id": "runtime",