4 ms·
There's lots of examples of folks packaging non-container-image things and stuffing them in a registry: - cosign signatures, SBOMs, attestations: https://docs.
by ImJasonH 4y ago
There's lots of examples of folks packaging non-container-image things and stuffing them in a registry:
- cosign signatures, SBOMs, attestations: https://docs.sigstore.dev/cosign/overview/ https://docs.sigstore.dev/cosign/overview/
- Istio wasm plugins: https://istio.io/latest/docs/reference/config/proxy_extensions/wasm-plugin/ https://istio.io/latest/docs/reference/config/proxy_extensio...
- OPA bundles: https://www.openpolicyagent.org/docs/v0.13.5/bundles/ https://www.openpolicyagent.org/docs/v0.13.5/bundles/
- Tekton bundles: https://github.com/tektoncd/resolution/tree/main/bundleresolver https://github.com/tektoncd/resolution/tree/main/bundleresol...
There's even a demo (plug: in a talk I co-presented) of running a RISC-V emulator where its memory is stored in an OCI registry: https://www.youtube.com/watch?v=Xt_G-pUArTM https://www.youtube.com/watch?v=Xt_G-pUArTM
These all tend to include a CLI to collect/generate/validate resources and push/move/pull them, but the underlying implementation is roughly the same -- package content in a tarball, generate some JSON pointing to it, push that JSON to the registry (with auth).
The real benefit to this is that basically everyone has access to a registry these days -- in their cloud provider, on-prem, whatever -- with exactly the same APIs and mostly sane auth and client tooling.
If you're interested in exploring it for your use case let me know, I'd be happy to give you some pointers.
- qbasic_forever 4y agoHelm can store kubernetes charts in an OCI/docker registry too: https://helm.sh/blog/storing-charts-in-oci/ https://helm.sh/blog/storing-charts-in-oci/
- notatoad 4y agothank. helm links to https://oras.land/ https://oras.land/, which seems like a pretty cool generalization of all this.