3 ms·
>Once the cluster is stable and you are comfortable bringing it up and tearing it down >K8s wants a docker container registry, you really don't want to run that
by johnsoft 6y ago
>Once the cluster is stable and you are comfortable bringing it up and tearing it down
>K8s wants a docker container registry, you really don't want to run that on your cluster in the beginning, but once your cluster's secure, why not!
I'm betraying my ignorance here, but how does this work? If you're running the registry in your cluster, and you tear down your cluster (and the registry with it), how do you rebuild the cluster without being able to pull images?
- hardwaresofton 6y agoUsually the important images are hosted somewhere else (ex. you're probably not hosting the controller-manager which is normally pulled from k8s.gcr.io), but for the ones that were hosted in your cluster, the pods will basically fail (and start to back off) until your local registry comes up and you'll see pull related errors. The rest of the pods that don't reference images from your cluster-local registry will start up just fine. Assuming that you rebuild your cluster and restore your registry from backup (or simply reconnect it to some object store that it was connected to before, like S3), your registry pod (in a Deployment/Stateful/DaemonSet) will come up, and then the cluster will be able to connect to it, and the pods that were failing to start will start succeeding and you're back where you started.