Files
42_124/CT124_Registry使用_20260622.md
Timmy 2dbcc65951 新增 CT124 私有 Registry 使用說明
推拉流程、內外網存取、刪除回收、維運;並註記無帳密驗證。

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-22 21:33:19 +08:00

83 lines
2.7 KiB
Markdown
Raw Blame History

This file contains invisible Unicode characters
This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# CT124 私有 Docker Registry — 使用說明
> 主機:CT124192.168.42.124Ubuntu 24.04 LXC | 位置:`/opt/registry`
> 元件:`registry:2`:5000+ `joxit/docker-registry-ui`:8081
---
## 一、架構
| 元件 | 容器 | Port | 對外網址NPM 反代,HTTPS |
|---|---|---|---|
| Registry | `registry` | `5000` | `https://registry.lotimmy.com` |
| Web UI | `registry-ui` | `8081` | `https://registry-ui.lotimmy.com` |
- UI 不直接打 registry,而是在 Docker 內網 `NGINX_PROXY_PASS_URL=http://registry:5000` 取資料。
- 開了 `REGISTRY_STORAGE_DELETE_ENABLED=true` + UI `DELETE_IMAGES=true`**可從 UI 刪 image**
- 資料存在 `./registry_data`(對應容器 `/var/lib/registry`)。
## 二、兩種存取路徑
**A. 對外 / 跨機(推薦):走 HTTPS,免設定**
```
registry.lotimmy.com/<image>
```
**B. 內網直連 :5000(HTTP):用戶端需先信任這個 insecure registry**
```jsonc
// /etc/docker/daemon.jsonCT124 本機已設好;其他機器要推才需加)
{ "insecure-registries": ["192.168.42.124:5000"] }
```
改完 `systemctl restart docker`
## 三、推送 image
```bash
# 1. tag 成 registry 的命名空間
docker tag my-app registry.lotimmy.com/my-app
# 或內網:docker tag my-app 192.168.42.124:5000/my-app
# 2. push
docker push registry.lotimmy.com/my-app
# 3. 別台機器拉
docker pull registry.lotimmy.com/my-app
```
## 四、查詢
```bash
# 所有 repo
curl https://registry.lotimmy.com/v2/_catalog
# 某 repo 的 tags
curl https://registry.lotimmy.com/v2/my-app/tags/list
```
或直接開 UI:`https://registry-ui.lotimmy.com`
(目前內容:`files-to-prompt``speedtest-ookla`
## 五、刪 image 與回收空間
刪 tag/manifest(UI 按刪除,或 API)只是標記,**不會真的釋放磁碟**。要回收:
```bash
# 在 CT124 上
docker exec registry registry garbage-collect /etc/docker/registry/config.yml
# 視版本可能要重啟讓 UI 同步
docker restart registry
```
## 六、維運
```bash
cd /opt/registry
docker compose up -d # 啟動 / 套用變更start_docker_registry.sh 也是做這件事)
docker compose logs -f registry
docker compose restart
```
## 七、注意事項
- **沒有帳號密碼驗證**:registry 本身未設 htpasswd,對外安全完全靠 NPM 反代那層。內網 `:5000` 等於對 LAN 全開,push/pull/delete 都不擋。要鎖就在 registry 加 `REGISTRY_AUTH=htpasswd` 或在 NPM 上加 basic auth。
- 對外 443 經 NPM → 依賴 docker daemon 與 NPM 容器(見 [`CT124_故障復原_20260529.md`](CT124_故障復原_20260529.md) 的相依鏈);docker 掛了 `registry.lotimmy.com` 也會跟著不通,內網 `:5000` 仍可用。
- `myfile.txt` 是舊的手記草稿,正式說明以本文為準。