This commit is contained in:
2026-09-18 20:07:04 +02:00
parent 958e22734f
commit 442ddf8816
88 changed files with 2501 additions and 0 deletions
+8
View File
@@ -0,0 +1,8 @@
---
zot_version: "v2.1.6"
zot_port: 5000
zot_admin_user: zotadmin
# ponytail: PoC-only default password, overridden via inventory/vault for real use.
zot_admin_password: "changeme-poc-only"
zot_retention_keep_count: 10
zot_retention_keep_within: "720h"
+6
View File
@@ -0,0 +1,6 @@
---
- name: Restart zot
ansible.builtin.command:
cmd: docker compose up -d --force-recreate
chdir: /opt/zot
changed_when: true
+52
View File
@@ -0,0 +1,52 @@
---
# Deploy Zot OCI registry via Docker Compose, with htpasswd basic auth
# and a simple retention policy.
# ponytail: single zot instance, no TLS termination here (assumed behind
# plain HTTP for the PoC); add a reverse proxy with TLS before any real use.
- name: Create zot directories
ansible.builtin.file:
path: "{{ item }}"
state: directory
mode: "0755"
loop:
- /opt/zot
- /opt/zot/data
- /opt/zot/auth
- name: Ensure apache2-utils (htpasswd) is installed
ansible.builtin.apt:
name: apache2-utils
state: present
- name: Check if htpasswd file already exists
ansible.builtin.stat:
path: /opt/zot/auth/htpasswd
register: zot_htpasswd_stat
- name: Generate htpasswd file for zot user
ansible.builtin.command:
cmd: >-
htpasswd -cbB /opt/zot/auth/htpasswd
{{ zot_admin_user }} {{ zot_admin_password }}
when: not zot_htpasswd_stat.stat.exists
changed_when: true
- name: Deploy zot configuration
ansible.builtin.template:
src: config.json.j2
dest: /opt/zot/config.json
mode: "0644"
notify: Restart zot
- name: Deploy zot compose file
ansible.builtin.template:
src: compose.yaml.j2
dest: /opt/zot/compose.yaml
mode: "0644"
- name: Start zot via docker compose
ansible.builtin.command:
cmd: docker compose up -d
chdir: /opt/zot
changed_when: true
+11
View File
@@ -0,0 +1,11 @@
services:
zot:
image: ghcr.io/project-zot/zot-linux-amd64:{{ zot_version }}
restart: unless-stopped
ports:
- "127.0.0.1:{{ zot_port }}:5000"
volumes:
- /opt/zot/config.json:/etc/zot/config.json:ro
- /opt/zot/auth/htpasswd:/etc/zot/htpasswd:ro
- /opt/zot/data:/var/lib/registry
command: serve /etc/zot/config.json
+42
View File
@@ -0,0 +1,42 @@
{
"distSpecVersion": "1.1.1",
"storage": {
"rootDirectory": "/var/lib/registry",
"retention": {
"dryRun": false,
"delay": "24h",
"policies": [
{
"repositories": ["**"],
"deleteReferrers": false,
"deleteUntagged": true,
"keepTags": [
{
"mostRecentlyPushedCount": {{ zot_retention_keep_count }},
"pushedWithin": "{{ zot_retention_keep_within }}"
}
]
}
]
}
},
"http": {
"address": "0.0.0.0",
"port": "5000",
"auth": {
"htpasswd": {
"path": "/etc/zot/htpasswd"
}
},
"accessControl": {
"repositories": {
"**": {
"defaultPolicy": ["read", "create", "update", "delete"]
}
}
}
},
"log": {
"level": "info"
}
}