Skip to content
Install docker-registry in OpenShift

Install docker-registry in OpenShift

Written in 2015 for OpenShift Origin 3 (oadm, oc volume). Current OpenShift versions work differently.

There are plenty of docs about the installation; here are just the commands with short comments.

  1. Create the registry service account if it doesn’t exist: echo '{"kind":"ServiceAccount","apiVersion":"v1","metadata":{"name":"registry"}}' | oc create -n default -f -

  2. Add system:serviceaccount:default:registry under users in the privileged SCC: oc edit scc privileged

  3. Create the registry using the new service account: oadm registry --service-account=registry --config=/etc/origin/master/admin.kubeconfig --credentials=/etc/origin/master/openshift-registry.kubeconfig --latest-images

  4. If you store the registry on GlusterFS (as I do), create a Gluster endpoint file gluster_endpoint.yml:

    apiVersion: v1
    kind: Endpoints
    metadata:
      name: gluster
    subsets:
      - addresses:
          - ip: <gluster server>
        ports:
          - port: 1

    and apply it: oc create -f gluster_endpoint.yml

  5. Attach the GlusterFS volume to the registry: oc volume dc/docker-registry --add --overwrite --name=registry-storage --mount-path=/registry --source='{"glusterfs": { "endpoints": "gluster", "path": "/gluster/volume/name"}}'

  6. Run the registry as a privileged container – set privileged: true in the docker-registry deployment config: oc edit dc docker-registry

  7. Make it reachable from outside – add hostNetwork: true to the same deployment config (after dnsPolicy: ClusterFirst): oc edit dc docker-registry

  8. Once the new pod is running, test the registry:

    oc login
    oc whoami -t
    docker login -u username -e any_email_address -p token_value docker_registry_host:5000
    docker pull docker.io/ubuntu
    docker tag docker.io/ubuntu docker_registry_host:5000/current_namespace/ubuntu
    docker push docker_registry_host:5000/current_namespace/ubuntu

Links

Last updated on