mirror of https://github.com/easzlab/kubeasz.git
enable setting trusted insecure registries for containerd
parent
56f0939974
commit
e4e8f1835b
|
@ -47,27 +47,26 @@ ETCD_WAL_DIR: ""
|
||||||
############################
|
############################
|
||||||
# role:runtime [containerd,docker]
|
# role:runtime [containerd,docker]
|
||||||
############################
|
############################
|
||||||
# ------------------------------------------- containerd
|
# [.]启用拉取加速镜像仓库
|
||||||
# [.]启用容器仓库镜像
|
|
||||||
ENABLE_MIRROR_REGISTRY: true
|
ENABLE_MIRROR_REGISTRY: true
|
||||||
|
|
||||||
# [containerd]基础容器镜像
|
# [.]添加信任的私有仓库
|
||||||
|
INSECURE_REG:
|
||||||
|
- "http://easzlab.io.local:5000"
|
||||||
|
- "https://{{ HARBOR_REGISTRY }}"
|
||||||
|
|
||||||
|
# [.]基础容器镜像
|
||||||
SANDBOX_IMAGE: "easzlab.io.local:5000/easzlab/pause:__pause__"
|
SANDBOX_IMAGE: "easzlab.io.local:5000/easzlab/pause:__pause__"
|
||||||
|
|
||||||
# [containerd]容器持久化存储目录
|
# [containerd]容器持久化存储目录
|
||||||
CONTAINERD_STORAGE_DIR: "/var/lib/containerd"
|
CONTAINERD_STORAGE_DIR: "/var/lib/containerd"
|
||||||
|
|
||||||
# ------------------------------------------- docker
|
|
||||||
# [docker]容器存储目录
|
# [docker]容器存储目录
|
||||||
DOCKER_STORAGE_DIR: "/var/lib/docker"
|
DOCKER_STORAGE_DIR: "/var/lib/docker"
|
||||||
|
|
||||||
# [docker]开启Restful API
|
# [docker]开启Restful API
|
||||||
ENABLE_REMOTE_API: false
|
DOCKER_ENABLE_REMOTE_API: false
|
||||||
|
|
||||||
# [docker]信任的HTTP仓库
|
|
||||||
INSECURE_REG:
|
|
||||||
- "http://easzlab.io.local:5000"
|
|
||||||
- "https://{{ HARBOR_REGISTRY }}"
|
|
||||||
|
|
||||||
############################
|
############################
|
||||||
# role:kube-master
|
# role:kube-master
|
||||||
|
|
|
@ -136,19 +136,18 @@ version = 2
|
||||||
[plugins."io.containerd.grpc.v1.cri".registry.auths]
|
[plugins."io.containerd.grpc.v1.cri".registry.auths]
|
||||||
|
|
||||||
[plugins."io.containerd.grpc.v1.cri".registry.configs]
|
[plugins."io.containerd.grpc.v1.cri".registry.configs]
|
||||||
[plugins."io.containerd.grpc.v1.cri".registry.configs."easzlab.io.local:5000".tls]
|
{% for reg in INSECURE_REG %}
|
||||||
insecure_skip_verify = true
|
[plugins."io.containerd.grpc.v1.cri".registry.configs."{{ reg.split('/')[2] }}".tls]
|
||||||
|
|
||||||
[plugins."io.containerd.grpc.v1.cri".registry.configs."{{ HARBOR_REGISTRY }}".tls]
|
|
||||||
insecure_skip_verify = true
|
insecure_skip_verify = true
|
||||||
|
{% endfor %}
|
||||||
|
|
||||||
[plugins."io.containerd.grpc.v1.cri".registry.headers]
|
[plugins."io.containerd.grpc.v1.cri".registry.headers]
|
||||||
|
|
||||||
[plugins."io.containerd.grpc.v1.cri".registry.mirrors]
|
[plugins."io.containerd.grpc.v1.cri".registry.mirrors]
|
||||||
[plugins."io.containerd.grpc.v1.cri".registry.mirrors."easzlab.io.local:5000"]
|
{% for reg in INSECURE_REG %}
|
||||||
endpoint = ["http://easzlab.io.local:5000"]
|
[plugins."io.containerd.grpc.v1.cri".registry.mirrors."{{ reg.split('/')[2] }}"]
|
||||||
[plugins."io.containerd.grpc.v1.cri".registry.mirrors."{{ HARBOR_REGISTRY }}"]
|
endpoint = ["{{ reg }}"]
|
||||||
endpoint = ["https://{{ HARBOR_REGISTRY }}"]
|
{% endfor %}
|
||||||
{% if ENABLE_MIRROR_REGISTRY %}
|
{% if ENABLE_MIRROR_REGISTRY %}
|
||||||
[plugins."io.containerd.grpc.v1.cri".registry.mirrors."docker.io"]
|
[plugins."io.containerd.grpc.v1.cri".registry.mirrors."docker.io"]
|
||||||
endpoint = ["https://docker.nju.edu.cn/", "https://kuamavit.mirror.aliyuncs.com"]
|
endpoint = ["https://docker.nju.edu.cn/", "https://kuamavit.mirror.aliyuncs.com"]
|
||||||
|
@ -187,9 +186,6 @@ version = 2
|
||||||
shim = "containerd-shim"
|
shim = "containerd-shim"
|
||||||
shim_debug = false
|
shim_debug = false
|
||||||
|
|
||||||
[plugins."io.containerd.runtime.v2.task"]
|
|
||||||
platforms = ["linux/amd64"]
|
|
||||||
|
|
||||||
[plugins."io.containerd.service.v1.diff-service"]
|
[plugins."io.containerd.service.v1.diff-service"]
|
||||||
default = ["walking"]
|
default = ["walking"]
|
||||||
|
|
||||||
|
|
|
@ -7,7 +7,7 @@
|
||||||
"https://kuamavit.mirror.aliyuncs.com"
|
"https://kuamavit.mirror.aliyuncs.com"
|
||||||
],
|
],
|
||||||
{% endif %}
|
{% endif %}
|
||||||
{% if ENABLE_REMOTE_API %}
|
{% if DOCKER_ENABLE_REMOTE_API %}
|
||||||
"hosts": ["tcp://0.0.0.0:2376", "unix:///var/run/docker.sock"],
|
"hosts": ["tcp://0.0.0.0:2376", "unix:///var/run/docker.sock"],
|
||||||
{% endif %}
|
{% endif %}
|
||||||
"insecure-registries": {{ INSECURE_REG }},
|
"insecure-registries": {{ INSECURE_REG }},
|
||||||
|
|
Loading…
Reference in New Issue