【registry】CentOS7.x上 registry server的安裝使用

一羊精、實驗背景

當執(zhí)行 docker pull 的時候替裆,你可能會比較好奇体谒,docker 會去哪兒查找并下載鏡像呢?

它實際上是從 registry.hub.docker.com 這個地址去查找翻默,這就是Docker公司為我們提供的公共倉庫缸沃,上面的鏡像,大家都可以看到修械,也可以使用趾牧。所以,我們也可以帶上倉庫地址去拉取鏡像肯污,如:docker pull registry.hub.docker.com/library/alpine翘单,不過要注意,這種方式下載的鏡像的默認名稱就會長一些仇箱。


如果要在公司中使用 Docker县恕,我們基本不可能把商業(yè)項目上傳到公共倉庫中,那如果要多個機器共享剂桥,又能怎么辦呢? 正因為這種需要属提,所以私有倉庫也就有用武之地了权逗。 所謂私有倉庫,也就是在本地(局域網(wǎng))搭建的一個類似公共倉庫的東西冤议,搭建好之后斟薇,我們可以將鏡像提交到私有倉庫中。這樣我們既能使用 Docker 來運行我們的項目鏡像恕酸,也避免了商業(yè)項目暴露出去的風險堪滨。


# ping? registry.hub.docker.com

# echo > /dev/tcp/3.224.62.138/80

# echo > /dev/tcp/3.224.62.138/443

# echo? > /dev/tcp/registry.hub.docker.com/80

# echo? > /dev/tcp/registry.hub.docker.com/443

# curl -I? http://registry.hub.docker.com

# curl -I? https://registry.hub.docker.com



# docker search alpine

# docker pull? alpine

# docker pull registry.hub.docker.com/library/alpine

# docker images

二、實驗環(huán)境


操作系統(tǒng): CentOS7.5 Minimal

registryServer: 192.168.1.105

registryClient: 192.168.1.102


三蕊温、安裝docker


在registryServer和registryClient服務器


下載docker二進制安裝包

# yum? -y install? wget

# wget? https://download.docker.com/linux/static/stable/x86_64/docker-18.06.0-ce.tgz

#? tar -zxf? docker-18.06.0-ce.tgz

#? ll? ./docker

# cp ./docker/docker*? /usr/bin

創(chuàng)建docker服務的unit文件

# vim? /etc/systemd/system/docker.service

##############################################################

[Unit]

Description=Docker Application Container Engine

Documentation=https://docs.docker.com

After=network-online.target firewalld.service

Wants=network-online.target

[Service]

Type=notify

# the default is not to use systemd for cgroups because the delegate issues still

# exists and systemd currently does not support the cgroup feature set required

# for containers run by docker

ExecStart=/usr/bin/dockerd

ExecReload=/bin/kill -s HUP $MAINPID

# Having non-zero Limit*s causes performance problems due to accounting overhead

# in the kernel. We recommend using cgroups to do container-local accounting.

LimitNOFILE=infinity

LimitNPROC=infinity

LimitCORE=infinity

# Uncomment TasksMax if your systemd version supports it.

# Only systemd 226 and above support this version.

#TasksMax=infinity

TimeoutStartSec=0

# set delegate yes so that systemd does not reset the cgroups of docker containers

Delegate=yes

# kill only the docker process, not all processes in the cgroup

KillMode=process

# restart the docker process if it exits prematurely

Restart=on-failure

StartLimitBurst=3

StartLimitInterval=60s

[Install]

WantedBy=multi-user.target

#######################################################

啟動docker服務袱箱,設置開機自啟

# systemctl daemon-reload

# systemctl start docker

# systemctl? status docker

# systemctl enable docker

# docker? info

# docker? version

設置鏡像加速

#? curl -sSL https://get.daocloud.io/daotools/set_mirror.sh | sh -s http://f1361db2.m.daocloud.io

#? systemctl restart docker


四、安裝 registry server


拉取docker registry官方鏡像

# docker pull registry

# docker run? -it --rm registry? ? cat /etc/shells

# docker run? -it --rm registry? ? cat /etc/issue

# docker run? -it --rm registry? ? sh? -c "registry? -h"

# docker run? -it --rm registry? ? sh? -c "registry? -v"

創(chuàng)建registry server相關目錄

#? mkdir? -p? /opt/registry/data

#? mkdir? -p? /opt/registry/config

#? mkdir -p? /opt/registry/certs

# mnkir? -p? /opt/registry/auth


生產(chǎn)外掛配置文件

# docker run? -it? --rm? registry? sh? -c? 'cat /etc/docker/registry/config.yml'? >? /opt/registry/config/config.yml

#? cat? /opt/registry/config/config.yml

自建CA义矛,生成自簽名證書

##########################################################

# openssl req -x509 \

? -nodes \

? -newkey rsa:4096 \

? -days 3650 \

? -sha256 \

? -subj "/C=CN/ST=Gunagdong/L=Shenzhen/O=CA/OU=CA/CN=www.ca.com" \

? -keyout /opt/registry/certs/ca.key \

? -out? ? /opt/registry/certs/ca.crt


# openssl req \

? -nodes \

? -newkey rsa:4096 \

? -sha256 \

? -subj "/C=CN/ST=Gunagdong/L=Shenzhen/O=Test/OU=Test/CN=www.registry.com" \

? -keyout /opt/registry/certs/registry.key \

? -out? ? /opt/registry/certs/registry.csr

echo "

authorityKeyIdentifier=keyid,issuer

basicConstraints=CA:FALSE

keyUsage = digitalSignature, nonRepudiation, keyEncipherment, dataEncipherment

subjectAltName=IP:192.168.1.105,DNS:www.registry.com

" > extfile.cnf


# openssl x509 -req \

? -days 3650 \

? -CAcreateserial \

? -CA? ? /opt/registry/certs/ca.crt \

? -CAkey /opt/registry/certs/ca.key \

? -extfile extfile.cnf \

? -in? /opt/registry/certs/registry.csr \

? -out /opt/registry/certs/registry.crt

#####################################################################

#? ls -l? /opt/registry/certs

生成認證用賬號密碼文件

# docker run? --entrypoint? htpasswd? registry? -Bbn? test? Test@123? >? /opt/registry/auth/htpasswd

# cat? /opt/registry/auth/htpasswd

創(chuàng)建服務的service文件

#? vim? /etc/systemd/system/registry.service?

################################################

[Unit]

Description=Registry Server

After=network-online.target docker.service

Requires=docker.service

[Service]

ExecStartPre=-/usr/bin/docker rm -f registry

ExecStart=/usr/bin/docker run \

? --name registry \

? -v /opt/registry/data:/var/lib/registry \

? -v /opt/registry/config/config.yml:/etc/docker/registry/config.yml \

? -v /opt/registry/certs:/certs \

? -e REGISTRY_HTTP_ADDR=0.0.0.0:443 \

? -e REGISTRY_HTTP_TLS_CERTIFICATE=/certs/registry.crt \

? -e REGISTRY_HTTP_TLS_KEY=/certs/registry.key \

? -v /opt/registry/auth:/auth \

? -e "REGISTRY_AUTH=htpasswd" \

? -e "REGISTRY_AUTH_HTPASSWD_REALM=Registry Realm" \

? -e REGISTRY_AUTH_HTPASSWD_PATH=/auth/htpasswd \

? -p 443:443 \

? registry

ExecStop=/usr/bin/docker stop registry

LimitNOFILE=65535

Restart=on-failure

StartLimitBurst=3

StartLimitInterval=60s

[Install]

WantedBy=multi-user.target

################################################

啟動服務发笔,設置開機自啟

# systemctl? daemon-reload

# systemctl? start registry

# systemctl? enable? registry

# systemctl? status? registry


# docker ps -a

# docker exec -it registry? sh? -c? "ps aux | grep registry"

# docker exec -it registry? sh? -c? "netstat -anpltu"


五、registryClient客戶端測試


方式一:通過獲取registryServer的CA證書

將服務端證書/opt/registry/certs/ca.crt 拷貝到了客戶端的 /etc/pki/ca-trust/source/anchors目錄下

在registryClient服務器上

#? scp? root@192.168.1.105:/opt/registry/certs/ca.crt? /etc/pki/ca-trust/source/anchors/

# update-ca-trust

# systemctl? restart docker

# cat? /etc/pki/ca-trust/source/anchors/ca.crt

# openssl x509 -noout -text? -in? /etc/pki/ca-trust/source/anchors/ca.crt


方式二:不通過CA證書凉翻,設置客戶端docker信任倉庫

# systemctl? status docker

# vim? /etc/systemd/system/docker.service

#####################################################

ExecStart=/usr/bin/dockerd? --insecure-registry 192.168.1.105:443

######################################################

# systemctl? daemon-reload

# systemctl? restart? docker


六了讨、登錄創(chuàng)建的docker倉庫


在registryClient服務器上


測試registryserver上443端口的連通性

# echo? > /dev/tcp/192.168.1.105/443

# curl -v? http://192.168.1.105:443



# docker login 192.168.1.105:443? -u test? -p? "Test@123"

# cat /root/.docker/config.json


測試鏡像的pull/push

# docker pull busybox:latest

# docker tag? busybox:latest? 192.168.1.105:443/test/busybox:1.0.1-RC1

# docker push 192.168.1.105:443/test/busybox:1.0.1-RC1




七、參考


registry

https://hub.docker.com/_/registry

https://docs.docker.com/registry/deploying


用registry快速搭建私有鏡像倉庫

https://blog.51cto.com/ganbing/2080140


用docker registry 鏡像搭建私有測試倉庫

http://www.reibang.com/p/7337aa3f227b


用nginx 反向代理docker 私有 registry

http://www.reibang.com/p/143255035496


x509: cannot validate certificate for xx.xx.xx.xx because it doesn't contain any IP SANs

https://stackoverflow.com/questions/54622879/cannot-validate-certificate-for-ip-address-because-it-doesnt-contain-any-ip-s


x509: certificate signed by unknown authority

https://stackoverflow.com/questions/50768317/docker-pull-certificate-signed-by-unknown-authority


docker registry 私有倉庫 安裝配置、查詢前计、刪除

https://www.cnblogs.com/elvi/p/8384604.html

https://www.cnblogs.com/elvi/p/8384675.html


Docker私有倉庫搭建及鏡像刪除

http://www.louisvv.com/archives/1130.html


docker registry 鏡像刪除

https://blog.51cto.com/132408/1946401


docker私有倉庫刪除image

https://blog.51cto.com/302876016/1966816

https://blog.csdn.net/l6807718/article/details/52886546


Docker Registry之刪除鏡像胞谭、垃圾回收

https://blog.csdn.net/u010884123/article/details/56838644


What is the difference between an image and a repository?

https://stackoverflow.com/questions/31115098/what-is-the-difference-between-an-image-and-a-repository


What is the Differences between Docker registry and repository?

https://stackoverflow.com/questions/34004076/difference-between-docker-registry-and-repository


How To Set Up a Private Docker Registry on Ubuntu 18.04?

https://www.digitalocean.com/community/tutorials/how-to-set-up-a-private-docker-registry-on-ubuntu-18-04

最后編輯于
?著作權歸作者所有,轉(zhuǎn)載或內(nèi)容合作請聯(lián)系作者
  • 序言:七十年代末男杈,一起剝皮案震驚了整個濱河市韭赘,隨后出現(xiàn)的幾起案子,更是在濱河造成了極大的恐慌势就,老刑警劉巖泉瞻,帶你破解...
    沈念sama閱讀 219,539評論 6 508
  • 序言:濱河連續(xù)發(fā)生了三起死亡事件,死亡現(xiàn)場離奇詭異苞冯,居然都是意外死亡袖牙,警方通過查閱死者的電腦和手機,發(fā)現(xiàn)死者居然都...
    沈念sama閱讀 93,594評論 3 396
  • 文/潘曉璐 我一進店門舅锄,熙熙樓的掌柜王于貴愁眉苦臉地迎上來鞭达,“玉大人,你說我怎么就攤上這事皇忿〕氩洌” “怎么了?”我有些...
    開封第一講書人閱讀 165,871評論 0 356
  • 文/不壞的土叔 我叫張陵鳍烁,是天一觀的道長叨襟。 經(jīng)常有香客問我,道長幔荒,這世上最難降的妖魔是什么糊闽? 我笑而不...
    開封第一講書人閱讀 58,963評論 1 295
  • 正文 為了忘掉前任,我火速辦了婚禮爹梁,結果婚禮上右犹,老公的妹妹穿的比我還像新娘。我一直安慰自己姚垃,他們只是感情好念链,可當我...
    茶點故事閱讀 67,984評論 6 393
  • 文/花漫 我一把揭開白布。 她就那樣靜靜地躺著积糯,像睡著了一般掂墓。 火紅的嫁衣襯著肌膚如雪。 梳的紋絲不亂的頭發(fā)上絮宁,一...
    開封第一講書人閱讀 51,763評論 1 307
  • 那天梆暮,我揣著相機與錄音,去河邊找鬼绍昂。 笑死啦粹,一個胖子當著我的面吹牛偿荷,可吹牛的內(nèi)容都是我干的。 我是一名探鬼主播唠椭,決...
    沈念sama閱讀 40,468評論 3 420
  • 文/蒼蘭香墨 我猛地睜開眼跳纳,長吁一口氣:“原來是場噩夢啊……” “哼!你這毒婦竟也來了贪嫂?” 一聲冷哼從身側響起寺庄,我...
    開封第一講書人閱讀 39,357評論 0 276
  • 序言:老撾萬榮一對情侶失蹤,失蹤者是張志新(化名)和其女友劉穎力崇,沒想到半個月后斗塘,有當?shù)厝嗽跇淞掷锇l(fā)現(xiàn)了一具尸體,經(jīng)...
    沈念sama閱讀 45,850評論 1 317
  • 正文 獨居荒郊野嶺守林人離奇死亡亮靴,尸身上長有42處帶血的膿包…… 初始之章·張勛 以下內(nèi)容為張勛視角 年9月15日...
    茶點故事閱讀 38,002評論 3 338
  • 正文 我和宋清朗相戀三年馍盟,在試婚紗的時候發(fā)現(xiàn)自己被綠了。 大學時的朋友給我發(fā)了我未婚夫和他白月光在一起吃飯的照片茧吊。...
    茶點故事閱讀 40,144評論 1 351
  • 序言:一個原本活蹦亂跳的男人離奇死亡贞岭,死狀恐怖,靈堂內(nèi)的尸體忽然破棺而出搓侄,到底是詐尸還是另有隱情瞄桨,我是刑警寧澤,帶...
    沈念sama閱讀 35,823評論 5 346
  • 正文 年R本政府宣布讶踪,位于F島的核電站芯侥,受9級特大地震影響,放射性物質(zhì)發(fā)生泄漏俊柔。R本人自食惡果不足惜筹麸,卻給世界環(huán)境...
    茶點故事閱讀 41,483評論 3 331
  • 文/蒙蒙 一、第九天 我趴在偏房一處隱蔽的房頂上張望雏婶。 院中可真熱鬧,春花似錦白指、人聲如沸留晚。這莊子的主人今日做“春日...
    開封第一講書人閱讀 32,026評論 0 22
  • 文/蒼蘭香墨 我抬頭看了看天上的太陽错维。三九已至,卻和暖如春橄唬,著一層夾襖步出監(jiān)牢的瞬間赋焕,已是汗流浹背。 一陣腳步聲響...
    開封第一講書人閱讀 33,150評論 1 272
  • 我被黑心中介騙來泰國打工仰楚, 沒想到剛下飛機就差點兒被人妖公主榨干…… 1. 我叫王不留隆判,地道東北人犬庇。 一個月前我還...
    沈念sama閱讀 48,415評論 3 373
  • 正文 我出身青樓,卻偏偏與公主長得像侨嘀,于是被迫代替她去往敵國和親臭挽。 傳聞我的和親對象是個殘疾皇子,可洞房花燭夜當晚...
    茶點故事閱讀 45,092評論 2 355

推薦閱讀更多精彩內(nèi)容