{ "module": "distribution", "version": "1", "provides": [ { "name": "artifact-store", "scope": "mesh" }, { "name": "artifact-storage", "scope": "node" } ], "claims": [ { "name": "the-artifact-store", "scope": "mesh" } ], "capabilities": [ "container-runtime" ], "emits": [ "module.registry.image.pushed" ], "own-secrets": { "broker": "/var/lib/mesh/registry/broker" }, "serves": { "artifact-store": { "port": 5000 }, "artifact-storage": { "volume": "mesh-registry-data" } }, "listens": [ { "port": 5000, "protocol": "tcp", "from": "mesh", "why": "every machine pulls images and artifacts from here" } ], "resources": [ { "id": "state", "type": "directory", "path": "/var/lib/mesh/registry", "mode": "0700" }, { "id": "config", "type": "file", "path": "/var/lib/mesh/registry/config.yml", "mode": "0644", "content": "# The registry's configuration, written by the mesh from the module's manifest.\n#\n# Carried over from the predecessor's registry.yml where it changed behaviour (novox/hq ADR 0082,\n# the registry hand-over):\n# - no storage.delete: the predecessor enabled DELETE, but this door is reached by the whole\n# private network with no account (ADR 0082), and a delete anything on the overlay may send\n# is not a setting to carry. The public door, behind the registry's own auth, keeps it —\n# tag retention and garbage collection run there.\n# - no storage.cache: the image's default keeps an in-memory blob-descriptor cache, which is\n# right for one process and wrong for two on one store — the mesh door and the public door\n# are two registry processes sharing this filesystem, and a descriptor cached by one and\n# deleted through the other would say a blob exists that does not.\n# Dropped: the CORS headers, which served the browser interface that is being retired.\nversion: 0.1\nlog:\n fields:\n service: registry\nstorage:\n filesystem:\n rootdirectory: /var/lib/registry\nhttp:\n addr: :5000\n headers:\n X-Content-Type-Options: [nosniff]\nhealth:\n storagedriver:\n enabled: true\n interval: 10s\n threshold: 3\n" }, { "id": "store", "type": "container", "name": "mesh-registry", "image": "registry@sha256:a3d8aaa63ed8681a604f1dea0aa03f100d5895b6a58ace528858a7b332415373", "ports": [ "5000:5000" ], "volumes": [ "mesh-registry-data:/var/lib/registry", "/var/lib/mesh/registry/config.yml:/etc/docker/registry/config.yml:ro" ], "restart-on": [ "config" ] } ] }