{ "module": "distribution-gate", "version": "1", "capabilities": [ "container-runtime" ], "requires": [ "artifact-storage", "route" ], "contributes": { "route": { "label": "registry-api", "port": 5001, "max-request-body": 21474836480 } }, "own-secrets": { "htpasswd": "/var/lib/mesh/registry-gate/htpasswd" }, "listens": [ { "port": 5001, "protocol": "tcp", "from": "mesh", "why": "the artifact store's public door: the same store behind the registry's own basic auth, reached by the proxy under its public name; the mesh itself pulls from the store's own port and never from here" } ], "resources": [ { "id": "state", "type": "directory", "path": "/var/lib/mesh/registry-gate", "mode": "0700" }, { "id": "config", "type": "file", "path": "/var/lib/mesh/registry-gate/config.yml", "mode": "0644", "content": "# The registry's configuration, written by the mesh from the module's manifest.\n#\n# Carried over from the predecessor's registry.yml where it changed behaviour (novox/hq ADR 0082,\n# the registry hand-over):\n# - storage.delete.enabled: the image's default refuses DELETE on a manifest; the predecessor\n# enabled it, and tag retention and garbage collection depend on it.\n# - no storage.cache: the image's default keeps an in-memory blob-descriptor cache, which is\n# right for one process and wrong for two on one store — the mesh door and the public door\n# are two registry processes sharing this filesystem, and a descriptor cached by one and\n# deleted through the other would say a blob exists that does not.\n# Dropped: the CORS headers, which served the browser interface that is being retired.\nversion: 0.1\nlog:\n fields:\n service: registry\nstorage:\n delete:\n enabled: true\n filesystem:\n rootdirectory: /var/lib/registry\nhttp:\n addr: :5001\n headers:\n X-Content-Type-Options: [nosniff]\nhealth:\n storagedriver:\n enabled: true\n interval: 10s\n threshold: 3\n# The public door's lock, as the predecessor kept it: the registry itself checks basic auth\n# against an htpasswd file — bcrypt entries, one user — under the realm the predecessor\n# announced, so a client that logged in to the old name logs in to this one unchanged.\nauth:\n htpasswd:\n realm: basic-realm\n path: /etc/docker/registry/htpasswd\n" }, { "id": "gate", "type": "container", "name": "mesh-registry-gate", "image": "registry@sha256:a3d8aaa63ed8681a604f1dea0aa03f100d5895b6a58ace528858a7b332415373", "ports": [ "5001:5001" ], "volumes": [ "mesh-registry-data:/var/lib/registry", "/var/lib/mesh/registry-gate/config.yml:/etc/docker/registry/config.yml:ro", "/var/lib/mesh/registry-gate/htpasswd:/etc/docker/registry/htpasswd:ro" ], "restart-on": [ "config", "needs-htpasswd" ] } ] }