4 ms·
My favorite use of this is peer-to-peer transfer of Docker images. The Docker CLI only allows you to use registries authenticated with HTTPS but there's an exce
by tangotaylor 3mo ago
My favorite use of this is peer-to-peer transfer of Docker images. The Docker CLI only allows you to use registries authenticated with HTTPS but there's an exception where it allows HTTP transfers over localhost.
So, if you use SSH tunneling to forward a port from localhost to a remote, then Docker unwittingly pushes to a remote. This is super useful "off the grid" with robotics/embedded applications where you don't want to bother with a registry and a good Internet connection.
Example, docker pussh: https://github.com/psviderski/unregistry https://github.com/psviderski/unregistry
- Kampfschnitzel 3mo agoiirc there's a setting to allow docker to trust and use http registries i set it up a few years ago for my homelab
- afiori 3mo agoWhich makes me think that I have never heard of signed images/artefacts
- QGQBGdeZREunxLe 3mo agoThis is really useful as you don't have to add an entry under insecure-registries for local registries that don't have valid certificates.
- bitlad 3mo agoYou might as well handover the images to hackers.
- QGQBGdeZREunxLe 3mo agoA tad hyperbolic for a LAN registry
- janmatejka 3mo agoNot really since all it takes is one person with misconfigured device and your LAN is now accessible from who-knows-where unless the LAN is under very strict lockdown.
- QGQBGdeZREunxLe 3mo agoThe SSL being turned off wouldn't matter in that case.
- mmh0000 3mo agoThat's not quite true, you just need to add the `insecure-registries`[1] option with a list of either IP (or ip ranges) or hostnames that you want to allow without TLS. ```/etc/docker/daemon.json { "insecure-registries": ["10.100.0.0/24", "registry.yourmom.example.com:5000"] } ``` [1] https://docs.docker.com/reference/cli/dockerd/#insecure-registries https://docs.docker.com/reference/cli/dockerd/#insecure-regi...
- tangotaylor 3mo agoYes this is true. I should caveat that we distributed the tool among a team and we didn't want to ask them to all edit their daemon.json with an ever-expanding list of IP addresses.
- fragmede 3mo agoCould the tool you distributed update the daemon.json for your users so they don't have to change daemon.json manually?
- ndr 3mo agoThis is what kamal does when you use localhost as registry [0] [1]. Pretty cool thing, I ship plenty of services to my tiny $5/mo vps with it without having to pay for a docker registry. [0] https://kamal-deploy.org/docs/configuration/docker-registry/#using-a-local-container-registry https://kamal-deploy.org/docs/configuration/docker-registry/... [1] https://github.com/basecamp/kamal/blob/eee0083b38661c3707c6b6052cc89e85038a096c/lib/kamal/cli/build/port_forwarding.rb#L34 https://github.com/basecamp/kamal/blob/eee0083b38661c3707c6b...