4 ms·
Shameless plug but this might be a good time to install Spegel in your Kubernetes clusters if you have critical dependencies on Docker Hub. https://spegel.dev/
by phillebaba 1y ago
Shameless plug but this might be a good time to install Spegel in your Kubernetes clusters if you have critical dependencies on Docker Hub.
https://spegel.dev/ https://spegel.dev/
- deleted 1y ago[deleted]
- CaptainOfCoit 1y agoThere is a couple of alternatives that mirrors more than just Docker Hub too, most of them pretty bloated and enterprisey, but they do what they say on the tin and saved me more than once. Artifactory, Nexus Repository, Cloudsmith and ProGet are some of them.
- phillebaba 1y agoSpegel does not only mirror Docker Hub, and works a lot differently than the alternatives you suggested. Instead of being yet another failure point closer to your production environment, it runs a distributed stateless registry inside of your Kubernetes cluster. By piggy backing off of Containerds image store it will distribute already pulled images inside of the cluster.
- CaptainOfCoit 1y agoI'll be honest and say I hadn't heard of Spegel before, and just read the landing page which says "Speed up container pulls and minimize downtime with a stateless peer-to-peer OCI registry mirror for efficient image distribution", so it isn't exactly clear you can use it for more things than container images.
- scuff3d 1y agoWhat exactly does "stateless" mean in this context?
- phillebaba 1y agoSpegel itself does not manage state as a normal registry would. Maybe ephemeral would be a better word to describe it. A normal registry would require some stateful storage solution along with a database to store image that clients push to it. Spegel exploits the fact that images used by containers will be stored on disk by Containerd for its benefit. Any image currently being used by a pod in a cluster will be available for all other nodes in the cluster to pull.
- scuff3d 1y agoGotcha. That's definitely an important point and seems difficult to communicate in a single word or quick blurb. I can see why you went with stateless. It's just a little confusing in this context (for me at least).
- osivertsson 1y agoIf it really is fully open-source please make that more visible on your landing page. It is a huge deal if I can start investigating and deploying such a solution as a techie right away, compared to having to go through all the internal hoops for a software purchase.
- mocko 1y agoAfter some digging - https://github.com/spegel-org/spegel/blob/main/LICENSE https://github.com/spegel-org/spegel/blob/main/LICENSE says MIT
- CaptainOfCoit 1y agoHow hard is it to go to the GitHub repository and open the LICENSE file that is in almost every repository? Would have taken you less time than writing that comment, and showed you it's under MIT.
- rplnt 1y agoIt's not entirely uncommon to only have parts of the solution open. So a license on one repo might not be the whole story and looking further would take more time than giving a good suggestion to the author.
- giobox 1y agoAgreed. For all the people arguing "just click the link and the license is there!!", I have been burned several times before where a technical solution has a prominent open permissive license github repo (MIT or similar etc) based component as its primary home, only to discover later on that essential parts of the system are in other less permissive or private repos behind subscriptions or fees.
- CaptainOfCoit 1y agoThe rest of us get around that particular issue by going through the source code and all the tradeoffs before we download, include and adopt a dependency, not after.
- storm1er 1y agoWhat's the difference with kuik? Spegel seems too complicated for my homelab, but could be a nice upgrade for my company Kuik: https://github.com/enix/kube-image-keeper?tab=readme-ov-file#architecture-and-components https://github.com/enix/kube-image-keeper?tab=readme-ov-file...
- phillebaba 1y agoIt's been a while since I looked at kuik, but I would say the main difference is that Spegel doesn't do any of the pulling or storage of images. Instead it relies on Containerd to do it for you. This also means that Spegel does not have to manage garbage collection. The nice thing with this is that it doesn't change how images are initially pulled from upstream and is able to serve images that exist on the node before Spegel runs. Also it looks kuik uses CRDs to store information about where images are cached, while Spegel uses its own p2p solution to do the routing of traffic between nodes. If you are running k3s in your homelab you can enable Spegel with a flag as it is an embedded feature.
- mike-cardwell 1y agoThis looks good, but we're using GKE and it looks like it only works there with some hacks. Is there a timeline to make it work with GKE properly?
- phillebaba 1y agoI am having some discussions about getting things working on GKE but I can't give an ETA as it really depends on how things align with deployment schedules. I am positive however that this will soon be resolved.
- mike-cardwell 1y agoThanks. I will keep an eye on your project as it looks great and something we would definitely benefit from. P.S. Your blog could do with an rss feed ;). I will track https://github.com/spegel-org/spegel/releases.atom https://github.com/spegel-org/spegel/releases.atom for now
- 0xbadcafebee 1y agoGoogle Cloud has its own cache of Docker Hub that you can use for free, AWS does as well
- mike-cardwell 1y agoOur images are in a private docker registry on quay.io
- deleted 1y ago[deleted]