One store per mesh, and no DELETE on the door nothing authenticates to
Review of the registry hand-over. The store's seat was node-scoped, so a gate assigned to a machine without the store pulled a second, empty store in beside it — behind the real credentials and the public name, and offering `artifact-store` a second time so every consumer elsewhere refused. `the-artifact-store` is one per mesh: a second store anywhere, however it got there, is refused by name. storage.delete.enabled was carried onto the store's own door, which the whole private network reaches with no account (hq ADR 0082); anything on the overlay could have deleted a manifest. Nothing needs it there — garbage collection was not carried. It stays on the gate only, behind the registry's own auth, where tag retention runs. hq ADR 0082/0104, the registry hand-over.
This commit is contained in:
@@ -14,7 +14,7 @@
|
|||||||
"claims": [
|
"claims": [
|
||||||
{
|
{
|
||||||
"name": "the-artifact-store",
|
"name": "the-artifact-store",
|
||||||
"scope": "node"
|
"scope": "mesh"
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"capabilities": [
|
"capabilities": [
|
||||||
@@ -54,7 +54,7 @@
|
|||||||
"type": "file",
|
"type": "file",
|
||||||
"path": "/var/lib/mesh/registry/config.yml",
|
"path": "/var/lib/mesh/registry/config.yml",
|
||||||
"mode": "0644",
|
"mode": "0644",
|
||||||
"content": "# The registry's configuration, written by the mesh from the module's manifest.\n#\n# Carried over from the predecessor's registry.yml where it changed behaviour (novox/hq ADR 0082,\n# the registry hand-over):\n# - storage.delete.enabled: the image's default refuses DELETE on a manifest; the predecessor\n# enabled it, and tag retention and garbage collection depend on it.\n# - no storage.cache: the image's default keeps an in-memory blob-descriptor cache, which is\n# right for one process and wrong for two on one store — the mesh door and the public door\n# are two registry processes sharing this filesystem, and a descriptor cached by one and\n# deleted through the other would say a blob exists that does not.\n# Dropped: the CORS headers, which served the browser interface that is being retired.\nversion: 0.1\nlog:\n fields:\n service: registry\nstorage:\n delete:\n enabled: true\n filesystem:\n rootdirectory: /var/lib/registry\nhttp:\n addr: :5000\n headers:\n X-Content-Type-Options: [nosniff]\nhealth:\n storagedriver:\n enabled: true\n interval: 10s\n threshold: 3\n"
|
"content": "# The registry's configuration, written by the mesh from the module's manifest.\n#\n# Carried over from the predecessor's registry.yml where it changed behaviour (novox/hq ADR 0082,\n# the registry hand-over):\n# - no storage.delete: the predecessor enabled DELETE, but this door is reached by the whole\n# private network with no account (ADR 0082), and a delete anything on the overlay may send\n# is not a setting to carry. The public door, behind the registry's own auth, keeps it —\n# tag retention and garbage collection run there.\n# - no storage.cache: the image's default keeps an in-memory blob-descriptor cache, which is\n# right for one process and wrong for two on one store — the mesh door and the public door\n# are two registry processes sharing this filesystem, and a descriptor cached by one and\n# deleted through the other would say a blob exists that does not.\n# Dropped: the CORS headers, which served the browser interface that is being retired.\nversion: 0.1\nlog:\n fields:\n service: registry\nstorage:\n filesystem:\n rootdirectory: /var/lib/registry\nhttp:\n addr: :5000\n headers:\n X-Content-Type-Options: [nosniff]\nhealth:\n storagedriver:\n enabled: true\n interval: 10s\n threshold: 3\n"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "store",
|
"id": "store",
|
||||||
|
|||||||
Reference in New Issue
Block a user