[ci skip] Rebuild docker-registry with nginx serialization on all ports

Replace individual `docker run` commands with Docker Compose stack managed
by systemd. Nginx now fronts all 5 registry ports (5000/5010/5020/5030/5040)
with proxy_cache_lock to serialize concurrent blob pulls and prevent
corrupt partial responses. Adds QEMU guest agent for remote management.
This commit is contained in:
Viktor Barzin 2026-02-22 21:45:53 +00:00
parent 9488af2397
commit 88960ba3a4
No known key found for this signature in database
GPG key ID: 0EB088298288D958
5 changed files with 449 additions and 116 deletions

View file

@ -1,58 +1,220 @@
proxy_cache_path /var/cache/nginx/registry
levels=1:2
keys_zone=registry:500m
max_size=50g
inactive=24h
use_temp_path=off;
worker_processes auto;
error_log /var/log/nginx/error.log warn;
pid /tmp/nginx.pid;
upstream docker_registry {
server 127.0.0.1:5000;
keepalive 32;
events {
worker_connections 1024;
}
server {
listen 5002;
server_name _;
http {
proxy_cache_path /var/cache/nginx/registry
levels=1:2
keys_zone=registry:500m
max_size=50g
inactive=24h
use_temp_path=off;
# Access log
access_log /var/log/nginx/registry.access.log combined;
log_format registry '$remote_addr [$time_local] "$request" '
'$status $body_bytes_sent '
'upstream=$upstream_addr time=$upstream_response_time '
'cache=$upstream_cache_status';
# Error log
error_log /var/log/nginx/registry.error.log warn;
access_log /var/log/nginx/access.log registry;
# Required for large blobs
client_max_body_size 0;
# --- Upstreams ---
# Disable buffering to clients, keep it between nginx<->registry
proxy_request_buffering off;
proxy_buffering on;
upstream dockerhub {
server registry-dockerhub:5000;
keepalive 32;
}
location /v2/ {
proxy_pass http://docker_registry;
upstream ghcr {
server registry-ghcr:5000;
keepalive 32;
}
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header Connection "";
upstream quay {
server registry-quay:5000;
keepalive 32;
}
# --- CRITICAL PART ---
proxy_cache registry;
proxy_cache_lock on;
proxy_cache_lock_timeout 15m;
proxy_cache_lock_age 15m;
proxy_cache_use_stale updating;
upstream k8s {
server registry-k8s:5000;
keepalive 32;
}
# Cache only successful pulls
proxy_cache_valid 200 206 24h;
upstream kyverno {
server registry-kyverno:5000;
keepalive 32;
}
# HEAD requests must not poison cache
proxy_cache_methods GET;
# --- Docker Hub (port 5000) ---
# Do not cache pushes
proxy_no_cache $http_authorization;
proxy_cache_bypass $http_authorization;
server {
listen 5000;
server_name _;
# Prevent partial responses
proxy_read_timeout 900;
proxy_send_timeout 900;
client_max_body_size 0;
proxy_request_buffering off;
proxy_buffering on;
location /v2/ {
proxy_pass http://dockerhub;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header Connection "";
proxy_cache registry;
proxy_cache_lock on;
proxy_cache_lock_timeout 15m;
proxy_cache_lock_age 15m;
proxy_cache_use_stale updating;
proxy_cache_valid 200 206 24h;
proxy_cache_methods GET;
proxy_read_timeout 900;
proxy_send_timeout 900;
}
location / {
return 200 'ok';
add_header Content-Type text/plain;
}
}
# --- GHCR (port 5010) ---
server {
listen 5010;
server_name _;
client_max_body_size 0;
proxy_request_buffering off;
proxy_buffering on;
location /v2/ {
proxy_pass http://ghcr;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header Connection "";
proxy_cache registry;
proxy_cache_lock on;
proxy_cache_lock_timeout 15m;
proxy_cache_lock_age 15m;
proxy_cache_use_stale updating;
proxy_cache_valid 200 206 24h;
proxy_cache_methods GET;
proxy_read_timeout 900;
proxy_send_timeout 900;
}
location / {
return 200 'ok';
add_header Content-Type text/plain;
}
}
# --- Quay (port 5020) ---
server {
listen 5020;
server_name _;
client_max_body_size 0;
proxy_request_buffering off;
proxy_buffering on;
location /v2/ {
proxy_pass http://quay;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header Connection "";
proxy_cache registry;
proxy_cache_lock on;
proxy_cache_lock_timeout 15m;
proxy_cache_lock_age 15m;
proxy_cache_use_stale updating;
proxy_cache_valid 200 206 24h;
proxy_cache_methods GET;
proxy_read_timeout 900;
proxy_send_timeout 900;
}
location / {
return 200 'ok';
add_header Content-Type text/plain;
}
}
# --- registry.k8s.io (port 5030) ---
server {
listen 5030;
server_name _;
client_max_body_size 0;
proxy_request_buffering off;
proxy_buffering on;
location /v2/ {
proxy_pass http://k8s;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header Connection "";
proxy_cache registry;
proxy_cache_lock on;
proxy_cache_lock_timeout 15m;
proxy_cache_lock_age 15m;
proxy_cache_use_stale updating;
proxy_cache_valid 200 206 24h;
proxy_cache_methods GET;
proxy_read_timeout 900;
proxy_send_timeout 900;
}
location / {
return 200 'ok';
add_header Content-Type text/plain;
}
}
# --- reg.kyverno.io (port 5040) ---
server {
listen 5040;
server_name _;
client_max_body_size 0;
proxy_request_buffering off;
proxy_buffering on;
location /v2/ {
proxy_pass http://kyverno;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header Connection "";
proxy_cache registry;
proxy_cache_lock on;
proxy_cache_lock_timeout 15m;
proxy_cache_lock_age 15m;
proxy_cache_use_stale updating;
proxy_cache_valid 200 206 24h;
proxy_cache_methods GET;
proxy_read_timeout 900;
proxy_send_timeout 900;
}
location / {
return 200 'ok';
add_header Content-Type text/plain;
}
}
}