Images and publishing
Reserved names and publishing
Protect internal package names from dependency confusion and let CI publish them.
- Settings, Registries, Reserved names: add
@acme/*for npm,acme-*for PyPI,acme/*for Docker andAcme.*for NuGet. - Give your release pipeline a user with the publisher role and a token.
- Add an allow rule for the same names. In whitelist mode even your own packages need one.
- Publish with
npm publish,twine upload,docker pushordotnet nuget push. See the developer topics on publishing and pushing images.
12
- Images under acme/ are pushed here and never pulled from outside
- Pick Docker and add a namespace like acme/*
- A reserved name is never fetched from any upstream, even if a public copy was cached before you reserved it.
- Only reserved names can be published. Versions never change and cannot be unpublished. Use
npm deprecateinstead. - New publishes are held. With malware scanning on, a clean scan releases them. Otherwise an admin releases them on Quarantine. In permissive mode they are served meanwhile with a warning.
Pushed images
- A pushed image is held until every layer is scanned clean, in both quarantine modes. With scanning off, release it on Quarantine.
- A pushed tag never moves, except
latest. Nothing pushed can be deleted through the registry. - Once any image name is reserved, docker is asked to sign in when it first connects. That is how it learns to send its login when it pushes. With Require a token from package managers off, docker still pulls without a login: it gets an anonymous token and carries on.
- An upload belongs to the person who started it. Nobody else can add to it, finish it or read how far it got.
Big layers and the reverse proxy
docker push sends each layer as one request, often hundreds of megabytes. A proxy with a small body limit answers 413 Request Entity Too Large and docker keeps retrying. Give the upload path its own limit and let it stream straight through:
nginx
location ~ ^/v2/.+/blobs/uploads/ {
client_max_body_size 10g;
proxy_request_buffering off;
proxy_read_timeout 3600s;
proxy_send_timeout 3600s;
proxy_pass http://127.0.0.1:4444;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Forwarded-For $remote_addr;
proxy_set_header X-Forwarded-Proto https;
proxy_set_header X-Forwarded-Host $host;
}
The example in nginx/npm-repo.conf.example has it already. A layer can be up to 10 GB.