task 1-4
This commit is contained in:
@@ -0,0 +1,8 @@
|
||||
---
|
||||
zot_version: "v2.1.6"
|
||||
zot_port: 5000
|
||||
zot_admin_user: zotadmin
|
||||
# ponytail: PoC-only default password, overridden via inventory/vault for real use.
|
||||
zot_admin_password: "changeme-poc-only"
|
||||
zot_retention_keep_count: 10
|
||||
zot_retention_keep_within: "720h"
|
||||
@@ -0,0 +1,6 @@
|
||||
---
|
||||
- name: Restart zot
|
||||
ansible.builtin.command:
|
||||
cmd: docker compose up -d --force-recreate
|
||||
chdir: /opt/zot
|
||||
changed_when: true
|
||||
@@ -0,0 +1,52 @@
|
||||
---
|
||||
# Deploy Zot OCI registry via Docker Compose, with htpasswd basic auth
|
||||
# and a simple retention policy.
|
||||
# ponytail: single zot instance, no TLS termination here (assumed behind
|
||||
# plain HTTP for the PoC); add a reverse proxy with TLS before any real use.
|
||||
|
||||
- name: Create zot directories
|
||||
ansible.builtin.file:
|
||||
path: "{{ item }}"
|
||||
state: directory
|
||||
mode: "0755"
|
||||
loop:
|
||||
- /opt/zot
|
||||
- /opt/zot/data
|
||||
- /opt/zot/auth
|
||||
|
||||
- name: Ensure apache2-utils (htpasswd) is installed
|
||||
ansible.builtin.apt:
|
||||
name: apache2-utils
|
||||
state: present
|
||||
|
||||
- name: Check if htpasswd file already exists
|
||||
ansible.builtin.stat:
|
||||
path: /opt/zot/auth/htpasswd
|
||||
register: zot_htpasswd_stat
|
||||
|
||||
- name: Generate htpasswd file for zot user
|
||||
ansible.builtin.command:
|
||||
cmd: >-
|
||||
htpasswd -cbB /opt/zot/auth/htpasswd
|
||||
{{ zot_admin_user }} {{ zot_admin_password }}
|
||||
when: not zot_htpasswd_stat.stat.exists
|
||||
changed_when: true
|
||||
|
||||
- name: Deploy zot configuration
|
||||
ansible.builtin.template:
|
||||
src: config.json.j2
|
||||
dest: /opt/zot/config.json
|
||||
mode: "0644"
|
||||
notify: Restart zot
|
||||
|
||||
- name: Deploy zot compose file
|
||||
ansible.builtin.template:
|
||||
src: compose.yaml.j2
|
||||
dest: /opt/zot/compose.yaml
|
||||
mode: "0644"
|
||||
|
||||
- name: Start zot via docker compose
|
||||
ansible.builtin.command:
|
||||
cmd: docker compose up -d
|
||||
chdir: /opt/zot
|
||||
changed_when: true
|
||||
@@ -0,0 +1,11 @@
|
||||
services:
|
||||
zot:
|
||||
image: ghcr.io/project-zot/zot-linux-amd64:{{ zot_version }}
|
||||
restart: unless-stopped
|
||||
ports:
|
||||
- "127.0.0.1:{{ zot_port }}:5000"
|
||||
volumes:
|
||||
- /opt/zot/config.json:/etc/zot/config.json:ro
|
||||
- /opt/zot/auth/htpasswd:/etc/zot/htpasswd:ro
|
||||
- /opt/zot/data:/var/lib/registry
|
||||
command: serve /etc/zot/config.json
|
||||
@@ -0,0 +1,42 @@
|
||||
{
|
||||
"distSpecVersion": "1.1.1",
|
||||
"storage": {
|
||||
"rootDirectory": "/var/lib/registry",
|
||||
"retention": {
|
||||
"dryRun": false,
|
||||
"delay": "24h",
|
||||
"policies": [
|
||||
{
|
||||
"repositories": ["**"],
|
||||
"deleteReferrers": false,
|
||||
"deleteUntagged": true,
|
||||
"keepTags": [
|
||||
{
|
||||
"mostRecentlyPushedCount": {{ zot_retention_keep_count }},
|
||||
"pushedWithin": "{{ zot_retention_keep_within }}"
|
||||
}
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
},
|
||||
"http": {
|
||||
"address": "0.0.0.0",
|
||||
"port": "5000",
|
||||
"auth": {
|
||||
"htpasswd": {
|
||||
"path": "/etc/zot/htpasswd"
|
||||
}
|
||||
},
|
||||
"accessControl": {
|
||||
"repositories": {
|
||||
"**": {
|
||||
"defaultPolicy": ["read", "create", "update", "delete"]
|
||||
}
|
||||
}
|
||||
}
|
||||
},
|
||||
"log": {
|
||||
"level": "info"
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user