Sitelet https://github.com/hakman/kops/commit/2b56ba72e075625dbf01fe4ade32d8eaae9b0da3
Skip to content

Commit 2b56ba7

Browse files
Merge pull request kubernetes#18819 from peter-svensson/fix/containerd-mirror-override-path
containerd: set override_path for registry mirrors with a path
2 parents 4dbb9bd + b9c131f commit 2b56ba7

4 files changed

Lines changed: 64 additions & 1 deletion

File tree

‎nodeup/pkg/model/containerd.go‎

Lines changed: 23 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,6 +21,8 @@ import (
2121
"encoding/csv"
2222
"encoding/json"
2323
"fmt"
24+
"net/url"
25+
"path"
2426
"path/filepath"
2527
"regexp"
2628
"sort"
@@ -658,7 +660,11 @@ func (b *ContainerdBuilder) buildRegistryHosts(c *fi.NodeupModelBuilderContext)
658660
var buf strings.Builder
659661
for _, endpoint := range mirrors[name] {
660662
fmt.Fprintf(&buf, "[host.%q]\n", endpoint)
661-
buf.WriteString(" capabilities = [\"pull\", \"resolve\"]\n\n")
663+
buf.WriteString(" capabilities = [\"pull\", \"resolve\"]\n")
664+
if endpointHasPath(endpoint) {
665+
buf.WriteString(" override_path = true\n")
666+
}
667+
buf.WriteString("\n")
662668
}
663669
// containerd uses the special "_default" directory as the catch-all namespace.
664670
// Translate the kops convention of "*" so users don't end up with a literal
@@ -675,3 +681,19 @@ func (b *ContainerdBuilder) buildRegistryHosts(c *fi.NodeupModelBuilderContext)
675681
}
676682
return nil
677683
}
684+
685+
// endpointHasPath reports whether a mirror endpoint has a non-root path. These endpoints get
686+
// override_path, so containerd uses the path as-is instead of appending /v2, as the legacy
687+
// registry.mirrors config did.
688+
func endpointHasPath(endpoint string) bool {
689+
// Match containerd's parseHostConfig normalization so we check the same path.
690+
if !strings.HasPrefix(endpoint, "http") {
691+
endpoint = "https://" + endpoint
692+
}
693+
694+
u, err := url.Parse(endpoint)
695+
if err != nil {
696+
return false
697+
}
698+
return u.Path != "" && path.Clean(u.Path) != "/"
699+
}

‎nodeup/pkg/model/containerd_test.go‎

Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -324,3 +324,34 @@ func TestAppendGPURuntimeContainerdConfig(t *testing.T) {
324324
t.Error("new config did not match expected new config")
325325
}
326326
}
327+
328+
func TestEndpointHasPath(t *testing.T) {
329+
grid := []struct {
330+
endpoint string
331+
expected bool
332+
}{
333+
{endpoint: "https://mirror.example.com", expected: false},
334+
{endpoint: "https://mirror.example.com/", expected: false},
335+
{endpoint: "https://mirror.example.com//", expected: false},
336+
{endpoint: "http://10.0.0.5:5000", expected: false},
337+
{endpoint: "mirror.example.com", expected: false},
338+
{endpoint: "mirror.example.com:5000", expected: false},
339+
{endpoint: "10.0.0.5", expected: false},
340+
{endpoint: "https://mirror.example.com/v2", expected: true},
341+
{endpoint: "https://123456789012.dkr.ecr.us-east-1.amazonaws.com/v2/docker-hub", expected: true},
342+
{endpoint: "mirror.example.com:5000/v2/docker-hub", expected: true},
343+
{endpoint: "10.0.0.5:5000/v2/docker-hub", expected: true},
344+
{endpoint: "https://mirror.example.com/./", expected: false},
345+
{endpoint: "https://mirror.example.com/v2/..", expected: false},
346+
{endpoint: "https://mirror.example.com/prefix/./v2", expected: true},
347+
{endpoint: "https://mirror.example.com/v2/docker-hub/", expected: true},
348+
{endpoint: "[::1]:5000/v2/x", expected: true},
349+
{endpoint: "https://[fd00::1]:5000", expected: false},
350+
}
351+
352+
for _, g := range grid {
353+
if actual := endpointHasPath(g.endpoint); actual != g.expected {
354+
t.Errorf("endpointHasPath(%q): got %v, expected %v", g.endpoint, actual, g.expected)
355+
}
356+
}
357+
}

‎nodeup/pkg/model/tests/containerdbuilder/complex/cluster.yaml‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -22,6 +22,8 @@ spec:
2222
- https://fallback.example.com
2323
docker.io:
2424
- https://registry-1.docker.io
25+
quay.io:
26+
- https://123456789012.dkr.ecr.us-test-1.amazonaws.com/v2/quay
2527
registry.k8s.io:
2628
- https://mirror.example.com
2729
- https://backup.example.com

‎nodeup/pkg/model/tests/containerdbuilder/complex/tasks.yaml‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -12,6 +12,14 @@ contents: |+
1212
path: /etc/containerd/certs.d/docker.io/hosts.toml
1313
type: file
1414
---
15+
contents: |+
16+
[host."https://123456789012.dkr.ecr.us-test-1.amazonaws.com/v2/quay"]
17+
capabilities = ["pull", "resolve"]
18+
override_path = true
19+
20+
path: /etc/containerd/certs.d/quay.io/hosts.toml
21+
type: file
22+
---
1523
contents: |+
1624
[host."https://mirror.example.com"]
1725
capabilities = ["pull", "resolve"]

0 commit comments

Comments
 (0)