Merge pull request #3270 from riverzhang/fix-registry
Add insecure_registry config to docker options
This commit is contained in:
commit
0a720b35af
5 changed files with 94 additions and 33 deletions
|
@ -1,35 +1,61 @@
|
||||||
## Uncomment this if you want to force overlay/overlay2 as docker storage driver
|
## Uncomment this if you want to force overlay/overlay2 as docker storage driver
|
||||||
## Please note that overlay2 is only supported on newer kernels
|
## Please note that overlay2 is only supported on newer kernels
|
||||||
|
|
||||||
#docker_storage_options: -s overlay2
|
#docker_storage_options: -s overlay2
|
||||||
|
|
||||||
## Uncomment this if you have more than 3 nameservers, then we'll only use the first 3.
|
## Enable docker_container_storage_setup, it will configure devicemapper driver on Centos7 or RedHat7.
|
||||||
|
docker_container_storage_setup: false
|
||||||
|
|
||||||
#docker_dns_servers_strict: false
|
## It must be define a disk path for docker_container_storage_setup_devs.
|
||||||
|
## Otherwise docker-storage-setup will be executed incorrectly.
|
||||||
|
#docker_container_storage_setup_devs: /dev/vdb
|
||||||
|
|
||||||
|
## Uncomment this if you have more than 3 nameservers, then we'll only use the first 3.
|
||||||
|
docker_dns_servers_strict: false
|
||||||
|
|
||||||
# Path used to store Docker data
|
# Path used to store Docker data
|
||||||
docker_daemon_graph: "/var/lib/docker"
|
docker_daemon_graph: "/var/lib/docker"
|
||||||
|
|
||||||
## Used to set docker daemon iptables options to true
|
## Used to set docker daemon iptables options to true
|
||||||
#docker_iptables_enabled: "true"
|
docker_iptables_enabled: "false"
|
||||||
|
|
||||||
## A string of extra options to pass to the docker daemon.
|
# Docker log options
|
||||||
## This string should be exactly as you wish it to appear.
|
# Rotate container stderr/stdout logs at 50m and keep last 5
|
||||||
## An obvious use case is allowing insecure-registry access
|
docker_log_opts: "--log-opt max-size=50m --log-opt max-file=5"
|
||||||
## to self hosted registries like so:
|
|
||||||
docker_options: >-
|
|
||||||
--insecure-registry={{ kube_service_addresses }} --graph={{ docker_daemon_graph }} {{ docker_log_opts }}
|
|
||||||
{%- if ansible_architecture == "aarch64" and ansible_os_family == "RedHat" %}
|
|
||||||
--add-runtime docker-runc=/usr/libexec/docker/docker-runc-current
|
|
||||||
--default-runtime=docker-runc --exec-opt native.cgroupdriver=systemd
|
|
||||||
--userland-proxy-path=/usr/libexec/docker/docker-proxy-current --signature-verification=false
|
|
||||||
{%- endif -%}
|
|
||||||
|
|
||||||
|
# define docker bin_dir
|
||||||
docker_bin_dir: "/usr/bin"
|
docker_bin_dir: "/usr/bin"
|
||||||
|
|
||||||
|
## An obvious use case is allowing insecure-registry access to self hosted registries.
|
||||||
|
## Can be ipddress and domain_name.
|
||||||
|
## example define 172.19.16.11 or mirror.registry.io
|
||||||
|
#docker_insecure_registries:
|
||||||
|
# - mirror.registry.io
|
||||||
|
# - 172.19.16.11
|
||||||
|
|
||||||
|
## Add other registry,example China registry mirror.
|
||||||
|
#docker_registry_mirrors:
|
||||||
|
# - https://registry.docker-cn.com
|
||||||
|
# - https://mirror.aliyuncs.com
|
||||||
|
|
||||||
## If non-empty will override default system MounFlags value.
|
## If non-empty will override default system MounFlags value.
|
||||||
## This option takes a mount propagation flag: shared, slave
|
## This option takes a mount propagation flag: shared, slave
|
||||||
## or private, which control whether mounts in the file system
|
## or private, which control whether mounts in the file system
|
||||||
## namespace set up for docker will receive or propagate mounts
|
## namespace set up for docker will receive or propagate mounts
|
||||||
## and unmounts. Leave empty for system default
|
## and unmounts. Leave empty for system default
|
||||||
docker_mount_flags:
|
#docker_mount_flags:
|
||||||
|
|
||||||
|
## A string of extra options to pass to the docker daemon.
|
||||||
|
## This string should be exactly as you wish it to appear.
|
||||||
|
docker_options: >-
|
||||||
|
{%- if docker_insecure_registries is defined -%}
|
||||||
|
{{ docker_insecure_registries | map('regex_replace', '^(.*)$', '--insecure-registry=\1' ) | list | join(' ') }}
|
||||||
|
{%- endif %}
|
||||||
|
{% if docker_registry_mirrors is defined -%}
|
||||||
|
{{ docker_registry_mirrors | map('regex_replace', '^(.*)$', '--registry-mirror=\1' ) | list | join(' ') }}
|
||||||
|
{%- endif %}
|
||||||
|
--graph={{ docker_daemon_graph }} {{ docker_log_opts }}
|
||||||
|
{%- if ansible_architecture == "aarch64" and ansible_os_family == "RedHat" %}
|
||||||
|
--add-runtime docker-runc=/usr/libexec/docker/docker-runc-current
|
||||||
|
--default-runtime=docker-runc --exec-opt native.cgroupdriver=systemd
|
||||||
|
--userland-proxy-path=/usr/libexec/docker/docker-proxy-current --signature-verification=false
|
||||||
|
{%- endif -%}
|
||||||
|
|
2
roles/docker/.gitignore
vendored
2
roles/docker/.gitignore
vendored
|
@ -1,2 +0,0 @@
|
||||||
.*.swp
|
|
||||||
.vagrant
|
|
|
@ -40,6 +40,3 @@ dockerproject_rh_repo_base_url: 'https://yum.dockerproject.org/repo/main/centos/
|
||||||
dockerproject_rh_repo_gpgkey: 'https://yum.dockerproject.org/gpg'
|
dockerproject_rh_repo_gpgkey: 'https://yum.dockerproject.org/gpg'
|
||||||
dockerproject_apt_repo_base_url: 'https://apt.dockerproject.org/repo'
|
dockerproject_apt_repo_base_url: 'https://apt.dockerproject.org/repo'
|
||||||
dockerproject_apt_repo_gpgkey: 'https://apt.dockerproject.org/gpg'
|
dockerproject_apt_repo_gpgkey: 'https://apt.dockerproject.org/gpg'
|
||||||
|
|
||||||
# Used to set docker daemon iptables options
|
|
||||||
docker_iptables_enabled: "false"
|
|
||||||
|
|
|
@ -61,6 +61,13 @@ kubeadm_checksum: 422a7a32ed9a7b1eaa2a4f9d121674dfbe80eb41e206092c13017d097f75aa
|
||||||
vault_binary_checksum: 3c4d70ba71619a43229e65c67830e30e050eab7a81ac6b28325ff707e5914188
|
vault_binary_checksum: 3c4d70ba71619a43229e65c67830e30e050eab7a81ac6b28325ff707e5914188
|
||||||
|
|
||||||
# Containers
|
# Containers
|
||||||
|
# In some cases, we need a way to set --registry-mirror or --insecure-registry for docker,
|
||||||
|
# it helps a lot for local private development or bare metal environment.
|
||||||
|
# So you need define --registry-mirror or --insecure-registry, and modify the following url address.
|
||||||
|
# example:
|
||||||
|
# You need to deploy kubernetes cluster on local private development.
|
||||||
|
# Also provide the address of your own private registry.
|
||||||
|
# And use --insecure-registry options for docker
|
||||||
etcd_image_repo: "quay.io/coreos/etcd"
|
etcd_image_repo: "quay.io/coreos/etcd"
|
||||||
etcd_image_tag: "{{ etcd_version }}{%- if image_arch != 'amd64' -%}-{{ image_arch }}{%- endif -%}"
|
etcd_image_tag: "{{ etcd_version }}{%- if image_arch != 'amd64' -%}-{{ image_arch }}{%- endif -%}"
|
||||||
flannel_image_repo: "quay.io/coreos/flannel"
|
flannel_image_repo: "quay.io/coreos/flannel"
|
||||||
|
|
|
@ -142,31 +142,64 @@ kube_api_aggregator_routing: false
|
||||||
# Container for runtime
|
# Container for runtime
|
||||||
container_manager: docker
|
container_manager: docker
|
||||||
|
|
||||||
|
## Uncomment this if you want to force overlay/overlay2 as docker storage driver
|
||||||
|
## Please note that overlay2 is only supported on newer kernels
|
||||||
|
# docker_storage_options: -s overlay2
|
||||||
|
|
||||||
|
## Enable docker_container_storage_setup, it will configure devicemapper driver on Centos7 or RedHat7.
|
||||||
|
docker_container_storage_setup: false
|
||||||
|
|
||||||
|
## It must be define a disk path for docker_container_storage_setup_devs.
|
||||||
|
## Otherwise docker-storage-setup will be executed incorrectly.
|
||||||
|
# docker_container_storage_setup_devs: /dev/vdb
|
||||||
|
|
||||||
|
## Uncomment this if you have more than 3 nameservers, then we'll only use the first 3.
|
||||||
|
docker_dns_servers_strict: false
|
||||||
|
|
||||||
# Path used to store Docker data
|
# Path used to store Docker data
|
||||||
docker_daemon_graph: "/var/lib/docker"
|
docker_daemon_graph: "/var/lib/docker"
|
||||||
|
|
||||||
|
## Used to set docker daemon iptables options to true
|
||||||
|
docker_iptables_enabled: "false"
|
||||||
|
|
||||||
# Docker log options
|
# Docker log options
|
||||||
# Rotate container stderr/stdout logs at 50m and keep last 5
|
# Rotate container stderr/stdout logs at 50m and keep last 5
|
||||||
docker_log_opts: "--log-opt max-size=50m --log-opt max-file=5"
|
docker_log_opts: "--log-opt max-size=50m --log-opt max-file=5"
|
||||||
|
|
||||||
## A string of extra options to pass to the docker daemon.
|
## An obvious use case is allowing insecure-registry access to self hosted registries.
|
||||||
## This string should be exactly as you wish it to appear.
|
## Can be ipddress and domain_name.
|
||||||
## An obvious use case is allowing insecure-registry access
|
## example define 172.19.16.11 or mirror.registry.io
|
||||||
## to self hosted registries like so:
|
# docker_insecure_registries:
|
||||||
docker_options: >
|
# - mirror.registry.io
|
||||||
--insecure-registry={{ kube_service_addresses }} --graph={{ docker_daemon_graph }} {{ docker_log_opts }}
|
# - 172.19.16.11
|
||||||
{% if ansible_architecture == "aarch64" and ansible_os_family == "RedHat" %}
|
|
||||||
--add-runtime docker-runc=/usr/libexec/docker/docker-runc-current
|
## Add other registry,example China registry mirror.
|
||||||
--default-runtime=docker-runc --exec-opt native.cgroupdriver=systemd
|
# docker_registry_mirrors:
|
||||||
--userland-proxy-path=/usr/libexec/docker/docker-proxy-current --signature-verification=false
|
# - https://registry.docker-cn.com
|
||||||
{% endif %}
|
# - https://mirror.aliyuncs.com
|
||||||
|
|
||||||
## If non-empty will override default system MounFlags value.
|
## If non-empty will override default system MounFlags value.
|
||||||
## This option takes a mount propagation flag: shared, slave
|
## This option takes a mount propagation flag: shared, slave
|
||||||
## or private, which control whether mounts in the file system
|
## or private, which control whether mounts in the file system
|
||||||
## namespace set up for docker will receive or propagate mounts
|
## namespace set up for docker will receive or propagate mounts
|
||||||
## and unmounts. Leave empty for system default
|
## and unmounts. Leave empty for system default
|
||||||
docker_mount_flags:
|
# docker_mount_flags:
|
||||||
|
|
||||||
|
## A string of extra options to pass to the docker daemon.
|
||||||
|
## This string should be exactly as you wish it to appear.
|
||||||
|
docker_options: >-
|
||||||
|
{%- if docker_insecure_registries is defined -%}
|
||||||
|
{{ docker_insecure_registries | map('regex_replace', '^(.*)$', '--insecure-registry=\1' ) | list | join(' ') }}
|
||||||
|
{%- endif %}
|
||||||
|
{% if docker_registry_mirrors is defined -%}
|
||||||
|
{{ docker_registry_mirrors | map('regex_replace', '^(.*)$', '--registry-mirror=\1' ) | list | join(' ') }}
|
||||||
|
{%- endif %}
|
||||||
|
--graph={{ docker_daemon_graph }} {{ docker_log_opts }}
|
||||||
|
{%- if ansible_architecture == "aarch64" and ansible_os_family == "RedHat" %}
|
||||||
|
--add-runtime docker-runc=/usr/libexec/docker/docker-runc-current
|
||||||
|
--default-runtime=docker-runc --exec-opt native.cgroupdriver=systemd
|
||||||
|
--userland-proxy-path=/usr/libexec/docker/docker-proxy-current --signature-verification=false
|
||||||
|
{%- endif -%}
|
||||||
|
|
||||||
# Settings for containerized control plane (etcd/kubelet/secrets)
|
# Settings for containerized control plane (etcd/kubelet/secrets)
|
||||||
etcd_deployment_type: docker
|
etcd_deployment_type: docker
|
||||||
|
|
Loading…
Reference in a new issue