èªåã®ã¤ã¡ã¼ã¸ã管çããããã«ãDocker Hubã使ãã®ã§ã¯ãªãç¬èªã«docker-registryãç«ã¦ããå ´åã¯å°ãªããªãã¨æãã¾ãã
ãã®éããªãã¼ã¹ãããã·ã¨åããã¹ãã§docker-registryãåããã®ãªããTCPã§ã¯ãªãUNIXãã¡ã¤ã³ã½ã±ããã使ãããã§ãããã
ãªãã以ä¸ã®è¨å®ã§ã³ã³ããã¯ä½¿ãã¾ãã(ç¬)
docker-registryã®ã¤ã³ã¹ãã¼ã«
docker-registryã¯æ¢ã«Debianã®ããã±ã¼ã¸ã«ãªã£ã¦ããã®ã§ãããããã®ã¾ã¾ä½¿ãã¾ãã
apt install docker-registry
TCP(HTTP)ã¢ã¯ã»ã¹ã§è¯ããã°ããã§çµäºã§ã(ç¬) TCPã®5000çªãã¼ãã§ã¢ã¯ã»ã¹ã§ãã¾ãã
UNIXãã¡ã¤ã³ã½ã±ããã®è¨å®
docker-registryã®Debianããã±ã¼ã¸ãã¤ã³ã¹ãã¼ã«ããã¨ããã®å®è¡ãã¡ã¤ã«ã¯docker-registry:docker-registry
ã¨ããã¦ã¼ã¶åã»ã°ã«ã¼ãåã§åä½ãã¾ãã
ã½ã±ãããã¡ã¤ã«ãã¦ã¼ã¶docker-registry
ã§ä½æãããã¨ã«ãªããããããã§ã¯systemdã®æ©è½ã使ã£ã¦/run/docker-registry
ã¨ãããã£ã¬ã¯ããª(ãã®ææè
ã¯docker-registry:docker-registry
ã«ãªãã¾ã)ãä½æããã½ã±ãããã¡ã¤ã«ã¯ãã®ä¸ã«ä½æããããã«ãã¾ãã
ãã®ããã«ãã¾ã
systemctl edit docker-registry.service
ãå®è¡ãã
[Service] RuntimeDirectory=docker-registry UMask=002
ã¨ããè¡ã追å ãã¾ãã ããã§ã¯docker-registryã°ã«ã¼ãã«å±ããã¦ã¼ã¶ããã®ã½ã±ãããã¡ã¤ã«ã¸ã®ã¢ã¯ã»ã¹ã許å¯ããããã«UMaskãè¨å®ãã¦ãã¾ãã
ã¾ãã/etc/docker/registry/config.yml
ã®http:
ã®é¨åã
http: addr: /run/docker-registry/http.sock net: unix host: https://registry.example.com headers: X-Content-Type-Options: [nosniff]
ã®ããã«å¤æ´ãã¾ãã
ããã§host:
ã®URLã¯é©å®ä¿®æ£ãã¦ãã ããã
åæã«ãåããã¡ã¤ã«ã«ããauth:
ã®é¨åãã³ã¡ã³ãã¢ã¦ãã¾ãã¯åé¤ãã¾ãã
(ãããUNIXãã¡ã¤ã³ã½ã±ããã使ãããæ大ã®çç±ã§ãã®ã§ã)
æå¾ã«docker-registryãåèµ·åãã¾ãã
systemctl restart docker-registry.service
(ãã¾ã) Apacheã§ååãã¼ã¹ã®ãã¼ãã£ã«ãã¹ãã使ãå ´åã®ãªãã¼ã¹ãããã·è¨å®ã®ä¾
<VirtualHost _default_:443> ServerName registry.example.com ErrorLog ${APACHE_LOG_DIR}/error.log CustomLog ${APACHE_LOG_DIR}/access.log combined SSLEngine on SSLCertificateFile /etc/letsencrypt/live/registry.example.com/fullchain.pem SSLCertificateKeyFile /etc/letsencrypt/live/registry.example.com/privkey.pem <IfModule mod_proxy.c> ProxyPass / unix:/run/docker-registry/http.sock|http://registry.example.com/ </IfModule> <Location "/"> AuthType Basic AuthName "Please enter username and password" AuthUserFile /etc/docker-registry/passwd Require valid-user </Location> </VirtualHost>
ãã®éãApacheããdocker-registryã®ã½ã±ããã«ã¢ã¯ã»ã¹ã§ãããããã¦ã¼ã¶www-data
ãã°ã«ã¼ãdocker-registry
ã«è¿½å ãã¦ãã ããã
ã¡ãªã¿ã«ãProxyPassReverseã¯è¨å®ä¸è¦ã ã¨æãã¾ãã