fix: remove the bundled registry from every host, and stop starting it
CI / check (pull_request) Successful in 16s
CI / check (pull_request) Successful in 16s
netOrk's docker-compose.yml shipped a registry:2 for the satellite image, and this script started it on every deploy as infrastructure. Satellites pull from registry.netork.io; on 172.22.8.50 the registry held one old image, nothing had pulled from it in 30 days, and it accepted anonymous pushes on port 5000 of every instance (NetOrk/netork#763). - registry leaves INFRA_SERVICES. - A new step removes services netOrk no longer ships: the container netork-registry-1, then the volume netork_registry_data. `docker compose up` never removes a container whose service left the compose file, so without this each host would keep it until someone removed it by hand. The step is idempotent and works with the old compose file as well as the new one, so it can go out before netOrk drops the service.
This commit is contained in:
@@ -252,7 +252,7 @@ deploy_steps() {
|
||||
# Containers on upstream images. Reconciled, not force-recreated (below).
|
||||
# postgres and redis are deliberately absent: restarting a database on every
|
||||
# deploy would be worse than any compose change one could miss.
|
||||
local INFRA_SERVICES="registry apt-cacher-ng signal-api"
|
||||
local INFRA_SERVICES="apt-cacher-ng signal-api"
|
||||
|
||||
echo "[${SERVER}] Pulling images..."
|
||||
run_remote "$SERVER" "pulling images for ${SERVER_VERSION}" 'Pulled|Already|Error' \
|
||||
@@ -311,6 +311,24 @@ deploy_steps() {
|
||||
docker compose -f docker-compose.yml -f docker-compose.registry.yml \
|
||||
up -d --no-deps ${INFRA_SERVICES}" || true
|
||||
|
||||
# Services netOrk no longer ships, with the data only they used. `docker
|
||||
# compose up` never removes a container whose service has left the compose
|
||||
# file, so each would keep running on every host until someone removed it by
|
||||
# hand. Idempotent: a host that never had one, or was cleaned already, passes
|
||||
# untouched. Containers first; a volume still in use cannot be removed.
|
||||
# registry (netork-registry-1, netork_registry_data): the bundled registry:2
|
||||
# for satellite images. Satellites pull from registry.netork.io; it held one
|
||||
# old image, nothing had pulled from it in 30 days, and it accepted
|
||||
# anonymous pushes on port 5000 (NetOrk/netork#763).
|
||||
local RETIRED_CONTAINERS="netork-registry-1"
|
||||
local RETIRED_VOLUMES="netork_registry_data"
|
||||
echo "[${SERVER}] Removing retired services..."
|
||||
run_remote "$SERVER" "removing ${RETIRED_CONTAINERS} ${RETIRED_VOLUMES}" "" \
|
||||
"for c in ${RETIRED_CONTAINERS}; do \
|
||||
docker rm -f \$c >/dev/null 2>&1 && echo \"removed container \$c\"; done; \
|
||||
for v in ${RETIRED_VOLUMES}; do \
|
||||
docker volume rm \$v >/dev/null 2>&1 && echo \"removed volume \$v\"; done; true" || true
|
||||
|
||||
# Verify the containers actually run the image we just pulled. `docker
|
||||
# compose up -d` reports "Running" (not "Started") when it decides nothing
|
||||
# changed, and `pull` prints "Pulled" even when the tag was already local —
|
||||
|
||||
Reference in New Issue
Block a user