mirror of
https://github.com/labring/sealos.git
synced 2026-09-24 15:46:19 +08:00
How to deploy the registry service
sealos registry design:
sequenceDiagram
participant u as User
participant sh as sealos Hub
participant sa as sealos hub Auth
par Login
u->>sh: sealos login using '-k kubeconfig'
sh->>sa: Check account
sa->>sh: Have account
sh->>sh: Create token
sh->>u: Return token
end
par Push
u->>sh: sealos push image
sh->>sa: Check account and rbac
sa->>sa: check image/repo/org access
sa->>sh: Have access rights
sh->>sh: Save image info and blobs
sh->>u: Return push status
end
par Pull
u->>sh: sealos pull image
sh->>sa: Check account and rbac
sa->>sa: check image/repo/org exists
sa->>sh: Exists!
sh->>sh: return image info and blobs meta
sh->>u: Return pull status
end
Pre-Requirements
- Sealos Cloud for auth.
- Sealos Cluster for registry.
A running sealos kubernetes cluster
with at least svc(s) below:
- kubernetes
- calico
- service-hub(@see service-hub)
Base applications requirements
-
At least one storage Provider, here we use aliyun OSS and CDN. Or, you can use openebs.
AliOSS: read thisopenebs:sealos run labring/openebs:v1.9.0
-
One Domain name with admin access
ACMEDNS,Akamai,AzureDNS,CloudFlare,Google,Route53,DigitalOcean,RFC2136- Any cert-manager supported
dns01webhooks: github-link
Articles below assume the usage of sealos cloud's godaddy webhook as example.
Please Prepare domain access key&secret for further usage
Choice what network gateway to use:
Modification of config.yml
-
Example(@see deploy.yaml)
-
Read docker registry docs about config
-
Edit
auth, use your own auth server. -
The image:
registry:2does not supportAliCDN, if you need use image:ghcr.dockerproxy.com/labring/registry:mainwhich is build from distribution
Troublesome and Tips
- registry config
- http.secret If you are building a cluster of registries behind a load balancer, you MUST ensure the secret is the same for all registries.