Secure vs insecure image pruning#4471
Conversation
|
@legionus PTAL |
|
@soltysh PTAL |
admin_guide/pruning_resources.adoc
Outdated
There was a problem hiding this comment.
xref:using-insecure-connection-against-secured-registry[the one below]
admin_guide/pruning_resources.adoc
Outdated
There was a problem hiding this comment.
`certificate-authority`
`registry-url`
admin_guide/pruning_resources.adoc
Outdated
There was a problem hiding this comment.
`prune` command
s/with error similar to/with an error similar to
admin_guide/pruning_resources.adoc
Outdated
There was a problem hiding this comment.
s/config/configuration file
s/-/--
admin_guide/pruning_resources.adoc
Outdated
There was a problem hiding this comment.
I would move the code block to just before "By default...." so that the first sentence does not get broken up.
admin_guide/pruning_resources.adoc
Outdated
admin_guide/pruning_resources.adoc
Outdated
There was a problem hiding this comment.
Perhaps we can use a discrete heading here instead?
admin_guide/pruning_resources.adoc
Outdated
There was a problem hiding this comment.
Perhaps we can use a discrete heading here instead?
admin_guide/pruning_resources.adoc
Outdated
There was a problem hiding this comment.
I'd move the last sentence as a NOTE below. Additionally, reword this to something like:
Whenever possible use --certificate-authority, instead. Use of this option is strongly discouraged.
There was a problem hiding this comment.
I've ditched it. There is plenty of other places advocating the same. Instead, I've put (Dangerous) at the beginning.
admin_guide/pruning_resources.adoc
Outdated
There was a problem hiding this comment.
Don't encourage using --force-insecure anywhere, so drop the last sentence. It's already explained and that's it, it should not be used anywhere, though.
admin_guide/pruning_resources.adoc
Outdated
There was a problem hiding this comment.
Suggestion:
The secure connection is the preferred and recommended approach.
It's the recommended as a rule, not only for production.
admin_guide/pruning_resources.adoc
Outdated
admin_guide/pruning_resources.adoc
Outdated
There was a problem hiding this comment.
Add info in parenthesis this is not recommended.
admin_guide/pruning_resources.adoc
Outdated
There was a problem hiding this comment.
Add not recommended at the end in parens.
|
Now blocked on openshift/origin#14405. I will need to update error messages once it lands. |
|
|
1bb8a53 to
cecc1f6
Compare
|
Thanks for all the comments. They should be addressed now. The dependency PR is still waiting for the unblocked merge queue. |
cecc1f6 to
d82651d
Compare
|
No longer blocked. @ahardin-rh could you please review once more? |
d82651d to
3b0ca97
Compare
|
I'd like to make some corrections for earlier releases. Shall I re-open this against |
|
@miminar if we label this PR for 3.5 and 3.6, the changes will be applied there. if 3.5 and 3.6 need a different set of doc, then you'll need to open a separate PR and only label it for 3.5 and 3.6. |
|
@miminar so which versions is this specific PR appropriate for? |
|
@bparees 3.6 - latest; I'll re-submit new PRs for 3.4 and 3.5 |
admin_guide/pruning_resources.adoc
Outdated
admin_guide/pruning_resources.adoc
Outdated
There was a problem hiding this comment.
Using a Secure Connection Against an Insecure Registry
admin_guide/pruning_resources.adoc
Outdated
There was a problem hiding this comment.
If you see a message similar to the following in the output of the oadm prune images command, then your registry is not secured and the oadm prune images client will attempt to use a secure connection:
admin_guide/pruning_resources.adoc
Outdated
There was a problem hiding this comment.
you can force the client to use an insecure
admin_guide/pruning_resources.adoc
Outdated
There was a problem hiding this comment.
Using an Insecure Connection Against a Secured Registry
admin_guide/pruning_resources.adoc
Outdated
admin_guide/pruning_resources.adoc
Outdated
There was a problem hiding this comment.
Using the Wrong Certificate Authority
admin_guide/pruning_resources.adoc
Outdated
admin_guide/pruning_resources.adoc
Outdated
admin_guide/pruning_resources.adoc
Outdated
admin_guide/pruning_resources.adoc
Outdated
admin_guide/pruning_resources.adoc
Outdated
|
@miminar Thanks! Just a few minor comments from me. Just a heads-up that, given our new docs workflow, if you want to submit separate PRs for 3.4 and 3.5, be sure to do so against enterprise-3.4-stage and enterprise-3.5-stage respectively. Thanks again! |
da31247 to
63089db
Compare
|
@ahardin-rh thanks a lot! Comments should be addressed now. |
Document new options related to secure connection to integrated docker registry and a mechanism that decides whether to fall-back to insecure connection. Signed-off-by: Michal Minář <miminar@redhat.com>
63089db to
338e0bd
Compare
|
@miminar Excellent. Thank you! |
|
[rev_history] |
Document new options related to secure connection to integrated docker registry and a mechanism that decides whether to fall-back to insecure connection.
Resolves #4232
Resolves bz#1469654
Is blocked on openshift/origin#14114?No longer blocked.