Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
ed10d96048 | ||
|
|
27315d35cf | ||
|
|
525c639041 | ||
|
|
c0159ca0a1 |
@@ -63,23 +63,6 @@
|
||||
"env": {
|
||||
"REGISTRY_STORAGE_DELETE_ENABLED": "true"
|
||||
}
|
||||
},
|
||||
{
|
||||
"id": "collect",
|
||||
"type": "container",
|
||||
"name": "mesh-registry-collect",
|
||||
"image": "registry@sha256:a3d8aaa63ed8681a604f1dea0aa03f100d5895b6a58ace528858a7b332415373",
|
||||
"volumes": [
|
||||
"/var/lib/mesh-registry:/var/lib/registry"
|
||||
],
|
||||
"args": [
|
||||
"garbage-collect",
|
||||
"/etc/docker/registry/config.yml"
|
||||
],
|
||||
"schedule": "30 3 * * *",
|
||||
"while-stopped": [
|
||||
"store"
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
|
||||
@@ -305,7 +305,7 @@ export class MinioClient {
|
||||
|
||||
// **Neither the access key nor the bucket is derived here any more.** `accessKeyFor` minted an id
|
||||
// of its own until the mesh took that over (ADR 0048: the login is the mesh's, handed to both
|
||||
// ends), and `bucketFor` derived the bucket until the mesh took that over too (ADR 0201: the rule
|
||||
// ends), and `bucketFor` derived the bucket until the mesh took that over too (ADR 0202: the rule
|
||||
// is a line of this module's manifest, filled per consumer and delivered to both ends). Both
|
||||
// survived with no callers, which is the state a rule comes back from; they are gone.
|
||||
|
||||
|
||||
@@ -12,7 +12,7 @@
|
||||
// creates the service account under exactly that access key with exactly that secret — a credential
|
||||
// the provisioner invented is one the consumer could never present.
|
||||
//
|
||||
// **The bucket name is the mesh's too (ADR 0201).** It used to be computed here, from the login,
|
||||
// **The bucket name is the mesh's too (ADR 0202).** It used to be computed here, from the login,
|
||||
// and every consumer transcribed the same rule into its own definition by hand — two copies of
|
||||
// one rule with nothing comparing them, and one of three was wrong for months. Now the rule is a
|
||||
// line of this module's manifest (`serves.s3-bucket.bucket: ${consumer:as:dns}`), the mesh fills
|
||||
@@ -79,7 +79,7 @@ function bucketNamed(derived: Readonly<Record<string, unknown>>): string {
|
||||
if (typeof bucket !== "string" || bucket === "") {
|
||||
throw new Error(
|
||||
"the mesh did not say which bucket this consumer gets: minio's manifest must serve " +
|
||||
"`bucket` under s3-bucket (novox/hq ADR 0201)",
|
||||
"`bucket` under s3-bucket (novox/hq ADR 0202)",
|
||||
);
|
||||
}
|
||||
return bucket;
|
||||
|
||||
Reference in New Issue
Block a user