You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在K8s集群部署的Docker Registry中配置清理CronJob及同Pod部署?

在Kubernetes的Docker Registry同Pod中部署镜像清理任务

核心思路

要在Docker Registry所在Pod内实现定时清理30天以上镜像,需通过sidecar容器与Registry主容器共享存储和网络,定时执行镜像删除+垃圾回收操作(替代独立CronJob资源,满足同Pod部署要求)。

步骤1:准备Registry配置文件(开启删除权限)

创建ConfigMap存储Registry的配置,允许删除操作:

apiVersion: v1
kind: ConfigMap
metadata:
  name: registry-config
data:
  config.yml: |
    version: 0.1
    storage:
      filesystem:
        rootdirectory: /var/lib/registry
      delete:
        enabled: true  # 必须开启,否则无法删除镜像
    http:
      addr: :5000

步骤2:编写镜像清理脚本

创建ConfigMap存储清理脚本,实现按时间筛选删除+垃圾回收:

apiVersion: v1
kind: ConfigMap
metadata:
  name: registry-cleanup-script
data:
  cleanup.sh: |
    #!/bin/sh
    set -e

    # 计算30天前的时间戳(Unix秒数)
    THRESHOLD=$(date -d "-30 days" +%s)
    # 访问同Pod内的Registry API
    REGISTRY_URL="http://localhost:5000"

    # 获取所有镜像仓库列表
    REPOSITORIES=$(curl -s $REGISTRY_URL/v2/_catalog | jq -r '.repositories[]')

    for repo in $REPOSITORIES; do
      # 获取当前仓库的所有标签
      TAGS_RESP=$(curl -s $REGISTRY_URL/v2/$repo/tags/list)
      # 跳过无标签的仓库
      if [ $(echo $TAGS_RESP | jq -r '.tags') = "null" ]; then
        continue
      fi
      TAGS=$(echo $TAGS_RESP | jq -r '.tags[]')
      
      for tag in $TAGS; do
        # 获取镜像清单,提取创建时间
        MANIFEST=$(curl -s -H "Accept: application/vnd.docker.distribution.manifest.v2+json" $REGISTRY_URL/v2/$repo/manifests/$tag)
        if [ -z "$MANIFEST" ]; then
          continue
        fi
        CREATED=$(echo $MANIFEST | jq -r '.history[0].v1Compatibility' | jq -r '.created')
        CREATED_TIMESTAMP=$(date -d "$CREATED" +%s)
        
        # 删除30天前的镜像
        if [ $CREATED_TIMESTAMP -lt $THRESHOLD ]; then
          echo "Deleting outdated image: $repo:$tag"
          DIGEST=$(echo $MANIFEST | jq -r '.config.digest')
          curl -X DELETE $REGISTRY_URL/v2/$repo/manifests/$DIGEST
        fi
      done
    done

    # 执行垃圾回收,清理磁盘上未引用的存储文件
    registry garbage-collect /etc/docker/registry/config.yml

步骤3:部署带清理sidecar的Registry

编写Deployment配置,包含Registry主容器和清理sidecar容器,两者共享存储、配置和网络:

apiVersion: apps/v1
kind: Deployment
metadata:
  name: docker-registry
spec:
  replicas: 1
  selector:
    matchLabels:
      app: docker-registry
  template:
    metadata:
      labels:
        app: docker-registry
    spec:
      volumes:
        # 共享存储卷,存储Registry镜像数据
        - name: registry-storage
          persistentVolumeClaim:
            claimName: registry-pvc  # 需提前创建对应的PVC
        # 挂载Registry配置
        - name: registry-config
          configMap:
            name: registry-config
        # 挂载清理脚本
        - name: cleanup-script
          configMap:
            name: registry-cleanup-script
      containers:
        # Registry主容器
        - name: registry
          image: registry:2
          ports:
            - containerPort: 5000
          volumeMounts:
            - name: registry-storage
              mountPath: /var/lib/registry
            - name: registry-config
              mountPath: /etc/docker/registry
        # 清理sidecar容器
        - name: cleanup-sidecar
          image: alpine:latest
          command: ["/bin/sh", "-c"]
          args:
            - |
              # 安装依赖工具
              apk add --no-cache curl jq registry
              # 每天执行一次清理(86400秒=24小时)
              while true; do
                chmod +x /scripts/cleanup.sh
                /scripts/cleanup.sh
                sleep 86400
              done
          volumeMounts:
            - name: registry-storage
              mountPath: /var/lib/registry
            - name: registry-config
              mountPath: /etc/docker/registry
            - name: cleanup-script
              mountPath: /scripts

关键说明

  • 同Pod共享资源:sidecar与主容器共享PVC存储,确保清理操作能访问Registry的镜像数据;共享网络,可直接通过localhost:5000调用Registry API。
  • 时间筛选逻辑:通过Unix时间戳对比镜像创建时间,精准筛选30天以上的镜像。
  • 清理流程:先删除镜像的manifest(Registry API),再执行garbage-collect清理磁盘上的无效文件,避免磁盘空间浪费。
  • 定时执行:用while true + sleep实现每日定时任务,无需单独创建CronJob资源,满足同Pod部署要求。

内容的提问来源于stack exchange,提问作者Najeemdeen Shosan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.24 04:35:23