Skip to content

[3.5] Secure vs insecure image pruning#5535

Merged
bmcelvee merged 1 commit intoopenshift:enterprise-3.5-stagefrom
miminar:secure-image-pruning-3.5
Oct 5, 2017
Merged

[3.5] Secure vs insecure image pruning#5535
bmcelvee merged 1 commit intoopenshift:enterprise-3.5-stagefrom
miminar:secure-image-pruning-3.5

Conversation

@miminar
Copy link

@miminar miminar commented Oct 5, 2017

Document new options related to secure connection to integrated docker
registry and a mechanism that decides whether to fall-back to insecure
connection.

Backports #4471

Copy link
Contributor

@bparees bparees left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

a few nits, but you'll probably want to wait for @openshift/team-documentation to review as well and then make all the same changes to your 3.4 PR.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

a secure connection

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

recommended

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

"then your registry is not secured and the oadm prune images client
will attempt to use secure connection"

should be

"then your registry is not secured and the oadm prune images client
attempted to use secure connection" ?

Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yes

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

recommended

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

we probably shouldn't be documenting bugs (especially ones that are fixed) in our official documentation.

Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

removing

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

s/this/a standard prune/

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

the registry's service account name

@bparees
Copy link
Contributor

bparees commented Oct 5, 2017

@openshift/team-documentation ptal

@bparees bparees self-assigned this Oct 5, 2017
@bmcelvee bmcelvee self-assigned this Oct 5, 2017
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We may want to add an additional warning for this option following the table. @bparees what do you think?

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

sure.

Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I believe I've covered the danger in the [pruning-images-secure-or-insecure] section which is already recommended to read. I would rather refrain from clogging the doc with redundant information.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

s/an alternative route that works needs to be provided using this flag/use this flag to provide an alternate route.

Document new options related to secure connection to integrated docker
registry and a mechanism that decides whether to fall-back to insecure
connection.

Signed-off-by: Michal Minář <miminar@redhat.com>
@miminar miminar force-pushed the secure-image-pruning-3.5 branch from a1ae9d4 to 683cc46 Compare October 5, 2017 14:10
@miminar
Copy link
Author

miminar commented Oct 5, 2017

Thank you! Comments addressed. If approved, I'll apply the changes to 3.4 as well.

@bmcelvee
Copy link
Contributor

bmcelvee commented Oct 5, 2017

Thanks, @miminar! LGTM. @bparees do you have any additional changes?

@bparees
Copy link
Contributor

bparees commented Oct 5, 2017

@bmcelvee nope

@bmcelvee
Copy link
Contributor

bmcelvee commented Oct 5, 2017

[rev_history]
|xref:../admin_guide/pruning_resources.adoc#admin-guide-pruning-resources[Pruning Objects]
|Added details on secure versus insecure image pruning, and hard pruning the registry.
%

@bmcelvee bmcelvee merged commit 1145d37 into openshift:enterprise-3.5-stage Oct 5, 2017
@bmcelvee bmcelvee added this to the Next Release milestone Oct 5, 2017
@adellape adellape modified the milestones: Next Release, Staging Oct 9, 2017
@vikram-redhat vikram-redhat modified the milestones: Staging, Published - 10/11/2017 Oct 12, 2017
@miminar miminar deleted the secure-image-pruning-3.5 branch April 9, 2018 12:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants