nixos/docker-registry: cleanup module definition & enhance testcase

The following changes have been applied:

- the property `http.headers.X-Content-Type-Options` must a list of
  strings rather than a serialized list
- instead of `/etc/docker/registry/config.yml` the configuration will be
  written with `pkgs.writeText` and the store path will be used to run
  the registry. This reduces the risk of possible impurities by relying
  on the Nix store only.
- cleaned up the property paths to easy readability and reduce the
  verbosity.
- enhanced the testcase to ensure that digests can be deleted as well
- the `services.docker-registry.extraConfig` object will be merged with
  `registryConfig`

/cc @ironpinguin
This commit is contained in:
Maximilian Bosch
2018-05-01 15:23:39 +02:00
parent f5c0b3f887
commit 593dc45141
3 changed files with 32 additions and 40 deletions
+18 -39
View File
@@ -5,40 +5,26 @@ with lib;
let
cfg = config.services.dockerRegistry;
blogCache = if cfg.enableRedisCache
then "redis"
else "inmemory";
blobCache = if cfg.enableRedisCache
then "redis"
else "inmemory";
registryConfig = {
version = "0.1";
log = {
fields = {
service = "registry";
};
};
log.fields.service = "registry";
storage = {
cache = {
blobdescriptor = "${blogCache}";
};
filesystem = {
rootdirectory = "/var/lib/registry";
};
delete = {
enabled = cfg.enableDelete;
};
cache.blobdescriptor = blobCache;
filesystem.rootdirectory = cfg.storagePath;
delete.enabled = cfg.enableDelete;
};
http = {
addr = ":5000";
headers = {
X-Content-Type-Options = "[nosniff]";
};
addr = ":${builtins.toString cfg.port}";
headers.X-Content-Type-Options = ["nosniff"];
};
health = {
storagedriver = {
enabled = true;
interval = "10s";
threshold = 3;
};
health.storagedriver = {
enabled = true;
interval = "10s";
threshold = 3;
};
};
@@ -98,7 +84,7 @@ in {
redisPassword = mkOption {
type = types.str;
default = "asecret";
default = "";
description = "Set redis password.";
};
@@ -112,21 +98,14 @@ in {
};
config = mkIf cfg.enable {
environment.etc."docker/registry/config.yml".text = builtins.toJSON registryConfig;
systemd.services.docker-registry = {
description = "Docker Container Registry";
wantedBy = [ "multi-user.target" ];
after = [ "network.target" ];
environment = {
REGISTRY_HTTP_ADDR = "${cfg.listenAddress}:${toString cfg.port}";
REGISTRY_STORAGE_FILESYSTEM_ROOTDIRECTORY = cfg.storagePath;
} // cfg.extraConfig;
script = ''
${pkgs.docker-distribution}/bin/registry serve \
/etc/docker/registry/config.yml
script = let
configFile = pkgs.writeText "docker-registry-config.yml" (builtins.toJSON (registryConfig // cfg.extraConfig));
in ''
${pkgs.docker-distribution}/bin/registry serve ${configFile}
'';
serviceConfig = {