Browse Source

add containerd registry mirror certificate configuration (#11857)

Signed-off-by: KubeKyrie <shaolong.qin@daocloud.io>
pull/11883/head
kyrie 4 months ago
committed by GitHub
parent
commit
1f186ed451
No known key found for this signature in database GPG Key ID: B5690EEEBB952194
2 changed files with 8 additions and 0 deletions
  1. 2
      roles/container-engine/containerd/defaults/main.yml
  2. 6
      roles/container-engine/containerd/templates/hosts.toml.j2

2
roles/container-engine/containerd/defaults/main.yml

@ -62,6 +62,8 @@ containerd_registries_mirrors:
- host: https://registry-1.docker.io
capabilities: ["pull", "resolve"]
skip_verify: false
# ca: ["/etc/certs/mirror.pem"]
# client: [["/etc/certs/client.pem", ""],["/etc/certs/client.cert", "/etc/certs/client.key"]]
containerd_max_container_log_line_size: 16384

6
roles/container-engine/containerd/templates/hosts.toml.j2

@ -4,4 +4,10 @@ server = "{{ item.server | default("https://" + item.prefix) }}"
capabilities = ["{{ ([ mirror.capabilities ] | flatten ) | join('","') }}"]
skip_verify = {{ mirror.skip_verify | default('false') | string | lower }}
override_path = {{ mirror.override_path | default('false') | string | lower }}
{% if mirror.ca is defined %}
ca = ["{{ ([ mirror.ca ] | flatten ) | join('","') }}"]
{% endif %}
{% if mirror.client is defined %}
client = [{% for pair in mirror.client %}["{{ pair[0] }}", "{{ pair[1] }}"]{% if not loop.last %},{% endif %}{% endfor %}]
{% endif %}
{% endfor %}
Loading…
Cancel
Save