在Kubernetes集群中配置ExternalIPs并部署Docker Registry的技术问询
Alright, since you've already validated the ExternalIPs approach with Nginx, adapting that to deploy a Docker Registry on port 5000 is straightforward. Let's break this down into concrete configurations and steps:
1. Docker Registry Service Configuration
First, we'll create a Service that exposes the Registry on your cluster's external IPs at port 5000. This follows the same pattern as your Nginx test, but tailored to the Registry's default port:
apiVersion: v1 kind: Service metadata: name: docker-registry spec: type: ClusterIP ports: - name: registry protocol: TCP port: 5000 # External port your clients will connect to targetPort: 5000 # Internal port the Registry container listens on (default is 5000) selector: app: docker-registry externalIPs: - 1.2.3.4 - 2.3.4.5 - 3.4.5.6
2. Docker Registry Deployment Configuration
Next, we need a Deployment to run the Registry container. Critical note: the Registry requires persistent storage to retain images between restarts. I'll include a PersistentVolumeClaim (PVC) setup for production use, plus an alternative hostPath option for quick testing.
Production-ready Deployment (with PVC):
apiVersion: apps/v1 kind: Deployment metadata: name: docker-registry spec: replicas: 1 selector: matchLabels: app: docker-registry template: metadata: labels: app: docker-registry spec: containers: - name: registry image: registry:2 # Official Docker Registry image (version 2 is stable) ports: - containerPort: 5000 volumeMounts: - name: registry-storage mountPath: /var/lib/registry # Where the Registry stores images internally volumes: - name: registry-storage persistentVolumeClaim: claimName: registry-pvc # You'll need to create this PVC first
To create the required PVC, use this configuration:
apiVersion: v1 kind: PersistentVolumeClaim metadata: name: registry-pvc spec: accessModes: - ReadWriteOnce resources: requests: storage: 10Gi # Adjust based on your storage needs
Testing Deployment (with hostPath):
If you just want to test without setting up PVCs, replace the volumes section in the Deployment with:
volumes: - name: registry-storage hostPath: path: /data/registry type: DirectoryOrCreate # Creates the directory if it doesn't exist
Note: hostPath is not recommended for production since it ties storage to a single node.
3. Deploy and Validate
Apply the configurations with:
kubectl apply -f registry-service.yaml -f registry-deployment.yaml -f registry-pvc.yaml # Omit the PVC file if using hostPath
Check that the Service is correctly exposing the ExternalIPs:
kubectl get service docker-registry
Verify the Registry Pod is running:
kubectl get pods -l app=docker-registry
4. Test Registry Functionality
To push/pull images, you'll need to configure your Docker daemon to allow insecure HTTP access (unless you set up TLS for the Registry). Add these lines to your Docker daemon config (/etc/docker/daemon.json on Linux):
{ "insecure-registries": ["1.2.3.4:5000", "2.3.4.5:5000", "3.4.5.6:5000"] }
Restart Docker after making this change, then test with:
# Tag a test image docker tag alpine 1.2.3.4:5000/my-alpine # Push to your Registry docker push 1.2.3.4:5000/my-alpine # Pull back to verify docker pull 1.2.3.4:5000/my-alpine
内容的提问来源于stack exchange,提问作者blablabla

