harden pull-through cache: intercept errors, reduce lock timeout, add healthz

- Add proxy_intercept_errors + error_page for 502/503/504 on blob locations
  to prevent caching truncated upstream responses (root cause of repeated
  ImagePullBackOff across services)
- Reduce proxy_cache_lock_timeout from 15m to 5m — fail fast, let containerd
  retry instead of all concurrent pulls waiting on a failed first download
- Add proxy_cache_valid any 0 — never cache error responses
- Add /healthz endpoints on Docker Hub and GHCR servers
- Add draintimeout and proxy.ttl to registry proxy configs
This commit is contained in:
Viktor Barzin 2026-03-23 11:33:06 +02:00
parent 1639910043
commit 3f0ecda737
3 changed files with 40 additions and 4 deletions

View file

@ -17,6 +17,7 @@ storage:
dryrun: false
http:
addr: :5000
draintimeout: 60s
headers:
X-Content-Type-Options: [nosniff]
health:
@ -26,3 +27,4 @@ health:
threshold: 3
proxy:
remoteurl: ${remote_url}
ttl: 168h