Write the registry's trust into the runtime's file and reload the runtime instead of restarting it; prefix reload-on like restart-on (hq ADR 0102)

This commit is contained in:
2026-09-22 17:51:38 +02:00
parent c93128d82f
commit 28b7fb81ba
4 changed files with 71 additions and 11 deletions
+10 -8
View File
@@ -140,18 +140,20 @@ func (g *Generator) Resources(node string) ([]map[string]any, bool, error) {
}
resources = append(resources,
map[string]any{
// Merged, not owned: the runtime's daemon file is the machine's, and this states
// one fact into it. The registry speaks plain HTTP because every path to it is
// already inside the overlay's encryption (ADR 0082) — this line is the runtime
// being told what the mesh already means.
// Written into, not over (novox/hq ADR 0102): the runtime's daemon file is the
// machine's — its data directory, its logging, whatever a predecessor set — and
// this states one fact in it. The host sets this key and keeps every other.
// ("merge" is the operator's settings merged into this content; "into" is the
// content written into the machine's file.) The registry speaks plain HTTP
// because every path to it is already inside the overlay's encryption (ADR 0082).
"id": "registry-trust", "type": "file", "path": "/etc/docker/daemon.json",
"content": string(trust) + "\n", "mode": "0644", "merge": "json",
"content": string(trust) + "\n", "mode": "0644", "merge": "json", "into": "json",
},
map[string]any{
// The runtime reloads nothing for this setting, so it is restarted when the fact
// changes — once, at joining, before the machine runs anything that would mind.
// Reloaded, not restarted: the runtime re-reads its trusted registries on a reload,
// and a restart stops every container on the machine (measured; ADR 0102).
"id": "registry-trust-reload", "type": "service", "unit": "docker.service",
"state": "running", "restart-on": []string{"registry-trust"},
"state": "running", "reload-on": []string{"registry-trust"},
})
}
return resources, true, nil