netOrk's docker-compose.yml shipped a registry:2 for the satellite image, and deploy.sh started it on every deploy as infrastructure. Satellites pull from registry.netork.io. On 172.22.8.50 the registry held one old image, nothing had pulled from it in 30 days, and it accepted anonymous pushes on port 5000 of every instance (NetOrk/netork#763).
Changes
registry leaves INFRA_SERVICES.
New step "Removing retired services": removes the container netork-registry-1, then the volume netork_registry_data, where a host still has them.
docker compose up never removes a container whose service left the compose file, so without this step each host would keep it.
The step is idempotent and works with the old and the new netOrk compose file, so it can go out before netOrk drops the service.
tests/test_deploy_retired_services.py was red first and is green now. Against the fake ssh it checks that the removal command is sent, container before volume, and that the infrastructure reconcile no longer names registry. All 26 tests pass.
shellcheck (shellcheck-py==0.11.0.1, as in CI) and ruff are clean.
Ran the exact remote command against a stub docker with the container present and the volume absent: exit code 0, output removed container netork-registry-1.
## Summary
netOrk's `docker-compose.yml` shipped a `registry:2` for the satellite image, and `deploy.sh` started it on every deploy as infrastructure. Satellites pull from registry.netork.io. On 172.22.8.50 the registry held one old image, nothing had pulled from it in 30 days, and it accepted anonymous pushes on port 5000 of every instance (NetOrk/netork#763).
## Changes
- `registry` leaves `INFRA_SERVICES`.
- **New step "Removing retired services":** removes the container `netork-registry-1`, then the volume `netork_registry_data`, where a host still has them.
- `docker compose up` never removes a container whose service left the compose file, so without this step each host would keep it.
- The step is idempotent and works with the old and the new netOrk compose file, so it can go out before netOrk drops the service.
- README step 4 says so.
## Related Issue
NetOrk/netork#763.
## Testing
- `tests/test_deploy_retired_services.py` was red first and is green now. Against the fake `ssh` it checks that the removal command is sent, container before volume, and that the infrastructure reconcile no longer names `registry`. All 26 tests pass.
- shellcheck (`shellcheck-py==0.11.0.1`, as in CI) and ruff are clean.
- Ran the exact remote command against a stub `docker` with the container present and the volume absent: exit code 0, output `removed container netork-registry-1`.
netOrk's docker-compose.yml shipped a registry:2 for the satellite image,
and this script started it on every deploy as infrastructure. Satellites
pull from registry.netork.io; on 172.22.8.50 the registry held one old
image, nothing had pulled from it in 30 days, and it accepted anonymous
pushes on port 5000 of every instance (NetOrk/netork#763).
- registry leaves INFRA_SERVICES.
- A new step removes services netOrk no longer ships: the container
netork-registry-1, then the volume netork_registry_data. `docker
compose up` never removes a container whose service left the compose
file, so without this each host would keep it until someone removed it
by hand. The step is idempotent and works with the old compose file as
well as the new one, so it can go out before netOrk drops the service.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Summary
netOrk's
docker-compose.ymlshipped aregistry:2for the satellite image, anddeploy.shstarted it on every deploy as infrastructure. Satellites pull from registry.netork.io. On 172.22.8.50 the registry held one old image, nothing had pulled from it in 30 days, and it accepted anonymous pushes on port 5000 of every instance (NetOrk/netork#763).Changes
registryleavesINFRA_SERVICES.netork-registry-1, then the volumenetork_registry_data, where a host still has them.docker compose upnever removes a container whose service left the compose file, so without this step each host would keep it.Related Issue
NetOrk/netork#763.
Testing
tests/test_deploy_retired_services.pywas red first and is green now. Against the fakesshit checks that the removal command is sent, container before volume, and that the infrastructure reconcile no longer namesregistry. All 26 tests pass.shellcheck-py==0.11.0.1, as in CI) and ruff are clean.dockerwith the container present and the volume absent: exit code 0, outputremoved container netork-registry-1.