From 6e0cfc17dc4942a4d89af70fc93b58e72debc1da Mon Sep 17 00:00:00 2001 From: Olivier Gambier Date: Wed, 10 Jun 2015 20:54:24 -0700 Subject: [PATCH 1/3] Saner default data location Signed-off-by: Olivier Gambier --- cmd/registry/config.yml | 2 +- docs/configuration.md | 14 +++++++------- docs/deploying.md | 2 -- docs/storage-drivers/filesystem.md | 2 +- registry/storage/driver/filesystem/driver.go | 2 +- 5 files changed, 10 insertions(+), 12 deletions(-) diff --git a/cmd/registry/config.yml b/cmd/registry/config.yml index 6d41cc8f2..ba591467e 100644 --- a/cmd/registry/config.yml +++ b/cmd/registry/config.yml @@ -22,7 +22,7 @@ storage: cache: blobdescriptor: redis filesystem: - rootdirectory: /tmp/registry-dev + rootdirectory: /var/lib/registry maintenance: uploadpurging: enabled: false diff --git a/docs/configuration.md b/docs/configuration.md index 68fb54c59..6c423d606 100644 --- a/docs/configuration.md +++ b/docs/configuration.md @@ -21,16 +21,16 @@ configure the `rootdirectory` of the `filesystem` storage backend: ``` storage: filesystem: - rootdirectory: /tmp/registry-dev + rootdirectory: /var/lib/registry ``` To override this value, set an environment variable like this: ``` -REGISTRY_STORAGE_FILESYSTEM_ROOTDIRECTORY=/tmp/registry/test +REGISTRY_STORAGE_FILESYSTEM_ROOTDIRECTORY=/somewhere ``` -This variable overrides the `/tmp/registry-dev` value to the `/tmp/registry/test` +This variable overrides the `/var/lib/registry` value to the `/somewhere` directory. >**Note**: If an environment variable changes a map value into a string, such @@ -72,7 +72,7 @@ log: loglevel: debug # deprecated: use "log" storage: filesystem: - rootdirectory: /tmp/registry-dev + rootdirectory: /var/lib/registry azure: accountname: accountname accountkey: base64encodedaccountkey @@ -284,7 +284,7 @@ Permitted values are `error`, `warn`, `info` and `debug`. The default is ```yaml storage: filesystem: - rootdirectory: /tmp/registry + rootdirectory: /var/lib/registry azure: accountname: accountname accountkey: base64encodedaccountkey @@ -1342,7 +1342,7 @@ log: level: debug storage: filesystem: - rootdirectory: /tmp/registry-dev + rootdirectory: /var/lib/registry http: addr: localhost:5000 secret: asecretforlocaldevelopment @@ -1352,7 +1352,7 @@ http: The above configures the registry instance to run on port `5000`, binding to `localhost`, with the `debug` server enabled. Registry data storage is in the -`/tmp/registry-dev` directory. Logging is in `debug` mode, which is the most +`/var/lib/registry` directory. Logging is in `debug` mode, which is the most verbose. A similar simple configuration is available at diff --git a/docs/deploying.md b/docs/deploying.md index c0f31aacf..1a9e67aad 100644 --- a/docs/deploying.md +++ b/docs/deploying.md @@ -17,7 +17,6 @@ Create a folder for your registry data: Start your registry: $ docker run -d -p 5000:5000 \ - -v `pwd`/registry-data:/tmp/registry-dev \ --restart=always --name registry registry:2 That's it. @@ -62,7 +61,6 @@ docker stop registry && docker rm registry # Start your registry with TLS enabled docker run -d -p 5000:5000 \ - -v `pwd`/registry-data:/tmp/registry-dev \ -v `pwd`/certs:/certs \ -e REGISTRY_HTTP_TLS_CERTIFICATE=/certs/domain.crt \ -e REGISTRY_HTTP_TLS_KEY=/certs/domain.key \ diff --git a/docs/storage-drivers/filesystem.md b/docs/storage-drivers/filesystem.md index fa9f8259e..23d4afbaa 100644 --- a/docs/storage-drivers/filesystem.md +++ b/docs/storage-drivers/filesystem.md @@ -10,4 +10,4 @@ An implementation of the `storagedriver.StorageDriver` interface which uses the ## Parameters -`rootdirectory`: (optional) The root directory tree in which all registry files will be stored. Defaults to `/tmp/registry/storage`. +`rootdirectory`: (optional) The root directory tree in which all registry files will be stored. Defaults to `/var/lib/registry`. diff --git a/registry/storage/driver/filesystem/driver.go b/registry/storage/driver/filesystem/driver.go index 829603144..d5d8708cb 100644 --- a/registry/storage/driver/filesystem/driver.go +++ b/registry/storage/driver/filesystem/driver.go @@ -16,7 +16,7 @@ import ( ) const driverName = "filesystem" -const defaultRootDirectory = "/tmp/registry/storage" +const defaultRootDirectory = "/var/lib/registry" func init() { factory.Register(driverName, &filesystemDriverFactory{}) From 8ed0c66745b73cefa73e79a489f716e2e6139cd4 Mon Sep 17 00:00:00 2001 From: Olivier Gambier Date: Wed, 10 Jun 2015 21:05:13 -0700 Subject: [PATCH 2/3] Enhancing doc to persist data Signed-off-by: Olivier Gambier --- docs/deploying.md | 31 +++++++++++++++++++++++-------- 1 file changed, 23 insertions(+), 8 deletions(-) diff --git a/docs/deploying.md b/docs/deploying.md index 1a9e67aad..9f9950b89 100644 --- a/docs/deploying.md +++ b/docs/deploying.md @@ -8,11 +8,7 @@ IGNORES--> You obviously need to [install Docker](https://docs.docker.com/installation/) (remember you need **Docker version 1.6.0 or newer**). -## Getting started in 2 lines - -Create a folder for your registry data: - - $ mkdir registry-data +## Getting started Start your registry: @@ -30,6 +26,20 @@ Then pull it back: $ docker pull localhost:5000/batman/ubuntu +## Where is my data? + +By default, your registry stores its data on the local filesystem, inside the container. + +In a production environment, it's highly recommended to use [another storage backend](https://github.com/docker/distribution/blob/master/docs/storagedrivers.md), by [configuring it](https://github.com/docker/distribution/blob/master/docs/configuration.md#storage). + +If you want to stick with the local posix filesystem, you should store your data outside of the container. + +This is achieved by mounting a volume into the container: + + $ docker run -d -p 5000:5000 \ + -e REGISTRY_STORAGE_FILESYSTEM_ROOTDIRECTORY=/var/lib/registry \ + -v /myregistrydata:/var/lib/registry \ + --restart=always --name registry registry:2 ## Making your Registry available @@ -40,7 +50,12 @@ Let assume your registry is accessible via the domain name `myregistrydomain.com If you try to `docker pull myregistrydomain.com:5000/batman/ubuntu`, you will see the following error message: ``` -FATA[0000] Error response from daemon: v1 ping attempt failed with error: Get https://myregistrydomain.com:5000/v1/_ping: tls: oversized record received with length 20527. If this private registry supports only HTTP or HTTPS with an unknown CA certificate, please add `--insecure-registry myregistrydomain.com:5000` to the daemon's arguments. In the case of HTTPS, if you have access to the registry's CA certificate, no need for the flag; simply place the CA certificate at /etc/docker/certs.d/myregistrydomain.com:5000/ca.crt +FATA[0000] Error response from daemon: v1 ping attempt failed with error: +Get https://myregistrydomain.com:5000/v1/_ping: tls: oversized record received with length 20527. +If this private registry supports only HTTP or HTTPS with an unknown CA certificate,please add +`--insecure-registry myregistrydomain.com:5000` to the daemon's arguments. +In the case of HTTPS, if you have access to the registry's CA certificate, no need for the flag; +simply place the CA certificate at /etc/docker/certs.d/myregistrydomain.com:5000/ca.crt ``` If trying to reach a non `localhost` registry, Docker requires that you secure it using https, or make it explicit that you want to run an insecure registry. @@ -132,9 +147,9 @@ registry: environment: REGISTRY_HTTP_TLS_CERTIFICATE: /certs/domain.crt REGISTRY_HTTP_TLS_KEY: /certs/domain.key - REGISTRY_STORAGE_FILESYSTEM_ROOTDIRECTORY: /data + REGISTRY_STORAGE_FILESYSTEM_ROOTDIRECTORY: /var/lib/registry volumes: - - /path/registry-data:/data + - /path/registry-data:/var/lib/registry - /path/certs:/certs ``` From ad23a43bc4ab7100b0e5d923406a1c434e56ef40 Mon Sep 17 00:00:00 2001 From: Olivier Gambier Date: Thu, 11 Jun 2015 11:08:16 -0700 Subject: [PATCH 3/3] Enhance building doc to reflect the new data default location Signed-off-by: Olivier Gambier --- docs/building.md | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-) diff --git a/docs/building.md b/docs/building.md index cd534c715..9d4960bdd 100644 --- a/docs/building.md +++ b/docs/building.md @@ -12,7 +12,17 @@ If a Go development environment is setup, one can use `go get` to install the go get github.com/docker/distribution/cmd/registry ``` -The above will install the source repository into the `GOPATH`. The `registry` +The above will install the source repository into the `GOPATH`. + +Now create the directory for the registry data (this might require you to set permissions properly) + +```sh +mkdir -p /var/lib/registry +``` + +... or alternatively `export REGISTRY_STORAGE_FILESYSTEM_ROOTDIRECTORY=/somewhere` if you want to store data into another location. + +The `registry` binary can then be run with the following: ```