fix: remove the bundled registry from every host, and stop starting it #5

Merged
christianmanivong merged 1 commits from fix/retire-registry into main 2026-10-07 14:19:29 +00:00
Owner

Summary

netOrk's docker-compose.yml shipped a registry:2 for the satellite image, and deploy.sh started it on every deploy as infrastructure. Satellites pull from registry.netork.io. On 172.22.8.50 the registry held one old image, nothing had pulled from it in 30 days, and it accepted anonymous pushes on port 5000 of every instance (NetOrk/netork#763).

Changes

  • registry leaves INFRA_SERVICES.
  • New step "Removing retired services": removes the container netork-registry-1, then the volume netork_registry_data, where a host still has them.
    • docker compose up never removes a container whose service left the compose file, so without this step each host would keep it.
    • The step is idempotent and works with the old and the new netOrk compose file, so it can go out before netOrk drops the service.
  • README step 4 says so.

Related Issue

NetOrk/netork#763.

Testing

  • tests/test_deploy_retired_services.py was red first and is green now. Against the fake ssh it checks that the removal command is sent, container before volume, and that the infrastructure reconcile no longer names registry. All 26 tests pass.
  • shellcheck (shellcheck-py==0.11.0.1, as in CI) and ruff are clean.
  • Ran the exact remote command against a stub docker with the container present and the volume absent: exit code 0, output removed container netork-registry-1.
## Summary netOrk's `docker-compose.yml` shipped a `registry:2` for the satellite image, and `deploy.sh` started it on every deploy as infrastructure. Satellites pull from registry.netork.io. On 172.22.8.50 the registry held one old image, nothing had pulled from it in 30 days, and it accepted anonymous pushes on port 5000 of every instance (NetOrk/netork#763). ## Changes - `registry` leaves `INFRA_SERVICES`. - **New step "Removing retired services":** removes the container `netork-registry-1`, then the volume `netork_registry_data`, where a host still has them. - `docker compose up` never removes a container whose service left the compose file, so without this step each host would keep it. - The step is idempotent and works with the old and the new netOrk compose file, so it can go out before netOrk drops the service. - README step 4 says so. ## Related Issue NetOrk/netork#763. ## Testing - `tests/test_deploy_retired_services.py` was red first and is green now. Against the fake `ssh` it checks that the removal command is sent, container before volume, and that the infrastructure reconcile no longer names `registry`. All 26 tests pass. - shellcheck (`shellcheck-py==0.11.0.1`, as in CI) and ruff are clean. - Ran the exact remote command against a stub `docker` with the container present and the volume absent: exit code 0, output `removed container netork-registry-1`.
christianmanivong added 1 commit 2026-10-07 14:17:23 +00:00
netOrk's docker-compose.yml shipped a registry:2 for the satellite image,
and this script started it on every deploy as infrastructure. Satellites
pull from registry.netork.io; on 172.22.8.50 the registry held one old
image, nothing had pulled from it in 30 days, and it accepted anonymous
pushes on port 5000 of every instance (NetOrk/netork#763).

- registry leaves INFRA_SERVICES.
- A new step removes services netOrk no longer ships: the container
  netork-registry-1, then the volume netork_registry_data. `docker
  compose up` never removes a container whose service left the compose
  file, so without this each host would keep it until someone removed it
  by hand. The step is idempotent and works with the old compose file as
  well as the new one, so it can go out before netOrk drops the service.
christianmanivong merged commit 0effa93895 into main 2026-10-07 14:19:29 +00:00
Sign in to join this conversation.