Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
67 commits
Select commit Hold shift + click to select a range
e4373a8
updated securityContext to include all values from values.yaml
Mar 23, 2023
b91518d
.
Mar 23, 2023
a277e5d
updated cronjob.yaml securityContext
Mar 24, 2023
533551b
added securityContext to containers
Mar 24, 2023
ca801de
added secretRef to secret.yaml
Mar 24, 2023
a1ef866
added base64end to secretRef
Mar 24, 2023
bc507bd
bug
Mar 24, 2023
eae3454
specified a containerSecurityContext for containers
Mar 25, 2023
ed363d7
added missing fields for securityContext
Mar 28, 2023
57e4a02
allow specifying the override for accesskey and secretkey names
tchinmai7 Apr 24, 2023
9786410
Adds more s3-related parameters
srager13 Aug 23, 2023
e71e90c
Fix redirect parameter
srager13 Aug 23, 2023
bb0ebe3
Add default values for new parameters
srager13 Aug 23, 2023
765f362
Remove redirect parameter
srager13 Aug 23, 2023
6e22508
Merge pull request #1 from srager13/main
tchinmai7 Aug 24, 2023
805e52e
Update templates/deployment.yaml
erikfuego Nov 27, 2023
987b061
Add back Tarun's changes (#3)
erikfuego Feb 1, 2024
d8c0cfb
Add extraContainers value
glennpratt Jul 9, 2024
9fcf29c
Merge branch 'extraContainers' of github.com:glennpratt/docker-regist…
glennpratt Jul 10, 2024
065f6c5
Bump helm/chart-releaser-action from 1.6.0 to 1.7.0
dependabot[bot] Jan 21, 2025
5af937b
Bump marocchino/sticky-pull-request-comment from 2.2.0 to 2.9.2
dependabot[bot] Apr 10, 2025
e73d9e8
Update gargagecollect cronjob
Mercbot7 Apr 14, 2025
88ccbc1
Update values.yaml to match cronjob updates and minor spacing fixes
Mercbot7 Apr 14, 2025
f4811a4
Merge pull request #162 from twuni/dependabot/github_actions/marocchi…
joshsizer Apr 14, 2025
d6224c8
refactor logic for lapels and annotations and fix resources
Mercbot7 Apr 14, 2025
64d7c68
Merge pull request #155 from twuni/dependabot/github_actions/helm/cha…
joshsizer Apr 14, 2025
9bba24a
reorder merge for proper preference
Mercbot7 Apr 15, 2025
113ddd1
Merge pull request #164 from Mercbot7/update-garbagecollect-cronjob
joshsizer Apr 15, 2025
53e594b
🏁 v2.3.0 Release
joshsizer Apr 16, 2025
14fc7bb
Update README.md for garbageCollect
Mercbot7 Apr 16, 2025
127e415
Merge pull request #166 from Mercbot7/update-readme-for-cronjob-updates
joshsizer Apr 16, 2025
791c161
Merge pull request #165 from joshsizer/release-2.3.0
joshsizer Apr 17, 2025
e3a6eb4
Updated chart to accept configPath to fix distribution's 3.0.0 breaki…
Clovel Jun 3, 2025
ec17067
Add the ability to force path style for s3 storage
TheAceMan Jun 3, 2025
458381c
Merge pull request #169 from TheAceMan/main
joshsizer Jun 7, 2025
8b8e964
Add the ability to skip verifying the TLS cert for s3 storage
TheAceMan Jun 7, 2025
60cac04
Merge pull request #168 from Clovel/feature/config-path
joshsizer Jun 8, 2025
d344f36
Change name to match the config variable
TheAceMan Jun 9, 2025
55527bf
Fix spacing
TheAceMan Jun 9, 2025
1f5763b
Fix merge conflict
glennpratt Jun 19, 2025
195a762
fix labels
glennpratt Jun 19, 2025
8ff1707
Bump marocchino/sticky-pull-request-comment from 2.9.2 to 2.9.3
dependabot[bot] Jun 23, 2025
3b0905d
debug
glennpratt Jun 27, 2025
cb1e3c9
quote
glennpratt Jun 27, 2025
d939a3b
better
glennpratt Jun 27, 2025
4e90482
anno
glennpratt Jun 27, 2025
b5028e2
ds
glennpratt Jun 27, 2025
4e6b389
Merge pull request #174 from twuni/dependabot/github_actions/marocchi…
joshsizer Jun 28, 2025
0f196d6
Merge pull request #171 from TheAceMan/main
joshsizer Jun 28, 2025
d68d07b
local registry hosting
glennpratt Jun 30, 2025
ced4b92
proxy opt out
glennpratt Jun 30, 2025
8e6b72b
Better host setup
glennpratt Jul 1, 2025
8662c4f
🏁 v3.0.0 Release
weisjohn Jul 29, 2025
ab431e8
Merge pull request #178 from weisjohn/main
joshsizer Jul 29, 2025
43ed263
Update repo URL in README
canterberry Sep 10, 2025
8d4e020
Add repo migration and deprecation notice to README
canterberry Sep 10, 2025
7382b1d
remove debug
glennpratt Oct 8, 2025
803018a
Merge pull request #182 from twuni/readme-install-via-gh-pages
canterberry Nov 3, 2025
f6da008
Merge upstream main into kpp-main-scott
srager13 Sep 10, 2026
592139a
Merge pull request #1 from srager13/kpp-main-scott
glennpratt Sep 22, 2026
3662b2e
ci: publish Helm chart to GHCR on kpp prerelease tags
glennpratt Sep 22, 2026
d6175c0
Merge tag 'kpp-2024-07-10' into gpratt-ghcr-workflow
glennpratt Sep 22, 2026
b149be7
Merge tag 'kpp-2025-11-19' into gpratt-ghcr-workflow
glennpratt Sep 22, 2026
fb87216
feat: local registry hosting via daemonset
glennpratt Sep 22, 2026
6093db5
Merge branch 'kpp-main' into gpratt-ghcr-workflow
glennpratt Sep 22, 2026
87bcfde
Merge branch 'gpratt-ghcr-workflow' into gpratt-local-registry
glennpratt Sep 22, 2026
c8d5d25
Merge v2.2.3-kpp-2025-11-19 release commit (b149be7) into gpratt-loca…
glennpratt Sep 22, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/helm_release.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ jobs:
git config user.email "$GITHUB_ACTOR@users.noreply.github.com"

- name: Install chart-releaser
uses: helm/chart-releaser-action@v1.6.0
uses: helm/chart-releaser-action@v1.7.0
with:
install_only: true

Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/pr_diff.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -44,7 +44,7 @@ jobs:
echo 'HELM_DIFF<<EOF' >> $GITHUB_ENV
echo "$(diff -ur before after)" >> $GITHUB_ENV
echo 'EOF' >> $GITHUB_ENV
- uses: marocchino/sticky-pull-request-comment@39c5b5dc7717447d0cba270cd115037d32d28443
- uses: marocchino/sticky-pull-request-comment@d2ad0de260ae8b0235ce059e63f2949ba9e05943
with:
message: |
Running a `helm template` smoketest on commit ${{ github.ref }} results in the following diff against `${{ github.base_ref }}`:
Expand Down
43 changes: 43 additions & 0 deletions .github/workflows/publish-chart.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
name: Publish Helm Chart to GHCR

on:
push:
tags:
- '*-kpp*'
- 'v*-kpp*'

jobs:
publish:
runs-on: ubuntu-latest
permissions:
contents: read
packages: write
steps:
- name: Checkout
uses: actions/checkout@v4

- name: Install Helm
uses: azure/setup-helm@v4

- name: Package and Push to GHCR
env:
HELM_EXPERIMENTAL_OCI: 1
run: |
# GHCR requires repository and owner names to be strictly lowercase
OWNER=$(echo "${{ github.repository_owner }}" | tr '[:upper:]' '[:lower:]')
TAG="${{ github.ref_name }}"

# Strip optional leading 'v' to get valid SemVer (e.g. v2.2.2-kpp-2023-08-24 -> 2.2.2-kpp-2023-08-24)
VERSION="${TAG#v}"

echo "Packaging chart version: ${VERSION}"
mkdir -p dist
helm package . --version "${VERSION}" --destination dist/

# Log in to GHCR
echo "${{ secrets.GITHUB_TOKEN }}" | helm registry login ghcr.io -u "${{ github.actor }}" --password-stdin

# Push to GHCR
PKG=$(find dist -name "*.tgz" | head -n 1)
echo "Pushing ${PKG} to oci://ghcr.io/${OWNER}..."
helm push "${PKG}" "oci://ghcr.io/${OWNER}"
4 changes: 2 additions & 2 deletions Chart.yaml
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
apiVersion: v1
description: A Helm chart for Docker Registry
name: docker-registry
version: 2.2.3
appVersion: 2.8.1
version: 3.0.0
appVersion: 3.0.0
home: https://hub.docker.com/_/registry/
icon: https://helm.twun.io/docker-registry.png
maintainers:
Expand Down
30 changes: 27 additions & 3 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,13 +11,29 @@ This directory contains a Kubernetes chart to deploy a private Docker Registry.
This chart will do the following:

* Implement a Docker registry deployment
* Optionally deploy a DaemonSet to add registry service names to /etc/hosts on each node

## ⚠️ Repo Migration and Deprecation Notice

The following change only affects attempts to install or update the chart via the https://helm.twun.io repo.

The https://helm.twun.io repo has been migrated to https://twuni.github.io/docker-registry.helm.

To update your configuration, remove and re-add the repo with the new URL:

```console
helm repo remove twuni
helm repo add twuni https://twuni.github.io/docker-registry.helm
```

The deprecated repo URL, https://helm.twun.io, may become unavailable as early as **October 16, 2025**.

## Installing the Chart

First, add the repo:

```console
helm repo add twuni https://helm.twun.io
helm repo add twuni https://twuni.github.io/docker-registry.helm
```

To install the chart, use the following:
Expand All @@ -37,6 +53,9 @@ their default values.
| `image.repository` | Container image to use | `registry` |
| `image.tag` | Container image tag to deploy | `2.8.1` |
| `imagePullSecrets` | Specify image pull secrets | `nil` (does not add image pull secrets to deployed pods) |
| `daemonset.enabled` | Deploy a DaemonSet that adds registry service domain names to /etc/hosts on each node | `false` |
| `daemonset.priorityClassName` | Priority class for the hosts updater DaemonSet pods | `""` |
| `daemonset.annotations` | Annotations to add to the DaemonSet | `{}` |
| `persistence.accessMode` | Access mode to use for PVC | `ReadWriteOnce` |
| `persistence.enabled` | Whether to use a PVC for the Docker storage | `false` |
| `persistence.deleteEnabled` | Enable the deletion of image blobs and manifests by digest | `nil` |
Expand All @@ -57,8 +76,8 @@ their default values.
| `service.sessionAffinityConfig` | service session affinity config | `nil` |
| `replicaCount` | k8s replicas | `1` |
| `updateStrategy` | update strategy for deployment | `{}` |
| `podAnnotations` | Annotations for pod | `{}` |
| `podLabels` | Labels for pod | `{}` |
| `podAnnotations` | Annotations for deployment pod, and `garbageCollect` pod unless set explicitly there. See `garbageCollect` | `{}` |
| `podLabels` | Labels for deployment pod, and `garbageCollect` pod unless set explicitly there. See `garbageCollect` | `{}` |
| `podDisruptionBudget` | Pod disruption budget | `{}` |
| `resources.limits.cpu` | Container requested CPU | `nil` |
| `resources.limits.memory` | Container requested memory | `nil` |
Expand All @@ -79,12 +98,15 @@ their default values.
| `secrets.swift.password` | Password for Swift configuration | `nil` |
| `secrets.haSharedSecret` | Shared secret for Registry | `nil` |
| `configData` | Configuration hash for docker | `nil` |
| `configPath` | Configuration mount point in docker, `/etc/docker/registry` for registry version 2, `/etc/distribution` for version 3 | `/etc/docker/registry` |
| `s3.region` | S3 region | `nil` |
| `s3.regionEndpoint` | S3 region endpoint | `nil` |
| `s3.bucket` | S3 bucket name | `nil` |
| `s3.rootdirectory` | S3 prefix that is applied to allow you to segment data | `nil` |
| `s3.encrypt` | Store images in encrypted format | `nil` |
| `s3.secure` | Use HTTPS | `nil` |
| `s3.forcepathstyle` | Use path-style addressing, needed for some s3 compatible storage (minio) | `nil` |
| `s3.skipverify` | Allows connection to s3 storage using TLS with untrusted/self-signed certificate | `nil` |
| `swift.authurl` | Swift authurl | `nil` |
| `swift.container` | Swift container | `nil` |
| `proxy.enabled` | If true, registry will function as a proxy/mirror | `false` |
Expand Down Expand Up @@ -119,6 +141,8 @@ their default values.
| `garbageCollect.enabled` | If true, will deploy garbage-collector cronjob | `false` |
| `garbageCollect.deleteUntagged` | If true, garbage-collector will delete manifests that are not currently referenced via tag | `true` |
| `garbageCollect.schedule` | CronTab schedule, please use standard crontab format | `0 1 * * *` |
| `garbageCollect.podAnnotations` | CronJob pod Annotations. If left empty and chart `podAnnotations` are set, will use those. If both are set, these take precedence for the `garbageCollect` pods. | `{}` |
| `garbageCollect.podLabels` | CronJob pod Annotations. If left empty and chart `podLabels` are set, will use those. If both are set, these take precedence for the `garbageCollect` pods. | `{}` |
| `garbageCollect.resources` | garbage-collector requested resources | `{}` |

Specify each parameter using the `--set key=value[,key=value]` argument to
Expand Down
112 changes: 112 additions & 0 deletions files/host-setup.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,112 @@
#!/usr/bin/env sh

set -xeu

CONFIG_FILE="/host/etc/containerd/config.toml"
BACKUP_FILE="/host/etc/containerd/config.toml.backup.$(date +%Y%m%d-%H%M%S)"
CONFIG_PATH="/etc/containerd/certs.d"

# Check if config file exists
if [ ! -f "$CONFIG_FILE" ]; then
echo "Error: $CONFIG_FILE not found"
exit 1
fi

# Create backup
echo "Creating backup: $BACKUP_FILE"
cp "$CONFIG_FILE" "$BACKUP_FILE"

restart_needed=1
if grep -q "config_path.*=.*\"$CONFIG_PATH\"" "$CONFIG_FILE"; then
restart_needed=0
echo "config_path is already set correctly in $CONFIG_FILE"
elif grep -q '^\[plugins\."io\.containerd\.grpc\.v1\.cri"\.registry\]' "$CONFIG_FILE"; then
echo "Registry section found, checking for config_path..."

# Check if config_path exists but with wrong value
if grep -q "config_path.*=" "$CONFIG_FILE"; then
echo "Updating existing config_path..."
sed -i "s|config_path.*=.*|config_path = \"$CONFIG_PATH\"|" "$CONFIG_FILE"
else
echo "Adding config_path to existing registry section..."
# Add config_path after the registry section line
sed -i '/^\[plugins\."io\.containerd\.grpc\.v1\.cri"\.registry\]/a\ config_path = "'"$CONFIG_PATH"'"' "$CONFIG_FILE"
fi
else
echo "Registry section not found, adding complete section..."
# Add the entire registry section at the end
cat >> "$CONFIG_FILE" << EOF

[plugins."io.containerd.grpc.v1.cri".registry]
config_path = "$CONFIG_PATH"
EOF
fi

if [ "$restart_needed" -eq 1 ]; then
echo "Containerd configuration changed, restart may be required."
else
echo "No changes made to containerd configuration, restart not needed."
fi

echo "Configuration updated successfully!"

# Show the relevant section
echo ""
echo "Current registry configuration:"
grep -A 5 '^\[plugins\."io\.containerd\.grpc\.v1\.cri"\.registry\]' "$CONFIG_FILE" || echo "Section not found in output"

# Verify required environment variables
if [ -z "$NAMESPACE" ]; then
echo "ERROR: NAMESPACE environment variable is not set or empty"
exit 1
fi

if [ -z "$SERVICE_NAME" ]; then
echo "ERROR: SERVICE_NAME environment variable is not set or empty"
exit 1
fi

if [ -z "$SERVICE_PORT" ]; then
echo "ERROR: SERVICE_PORT environment variable is not set or empty"
exit 1
fi

echo "Using NAMESPACE=$NAMESPACE, SERVICE_NAME=$SERVICE_NAME, SERVICE_PORT=$SERVICE_PORT"

# Extract cluster domain from pod resolv.conf
cluster_domain="cluster.local"
if search_line=$(grep -E "^search|^domain" /etc/resolv.conf | head -1); then
if echo "$search_line" | grep -q "${NAMESPACE}.svc"; then
cluster_domain=$(echo "$search_line" | grep -o "${NAMESPACE}.svc.[^ ]*" | sed "s/${NAMESPACE}.svc.//")
fi
fi
echo "Detected cluster domain: ${cluster_domain}"

prefixes="${SERVICE_NAME} ${SERVICE_NAME}.${NAMESPACE} ${SERVICE_NAME}.${NAMESPACE}.svc ${SERVICE_NAME}.${NAMESPACE}.svc.${cluster_domain}"

hosts_entry="127.0.0.1 ${prefixes}"

# Create a new hosts file without the old entries and with the new entry
grep -v "${SERVICE_NAME}" /host/etc/hosts > /tmp/hosts.new
echo "$hosts_entry" >> /tmp/hosts.new

# Replace the hosts file with the new content
cat /tmp/hosts.new > /host/etc/hosts
rm /tmp/hosts.new

echo "Added/Updated hosts entries for registry service: $hosts_entry"

echo "Configuring containerd to allow insecure registries..."

for prefix in $prefixes; do
cert_dir="/host/${CONFIG_PATH}/${prefix}:${SERVICE_PORT}"
echo "Creating directory: ${cert_dir}"
mkdir -p "${cert_dir}"

echo "Writing hosts.toml for ${prefix}:${SERVICE_PORT}"
echo "[host.\"http://${prefix}:${SERVICE_PORT}\"]" > "${cert_dir}/hosts.toml"
echo "capabilities = [\"pull\", \"resolve\"]" >> "${cert_dir}/hosts.toml"
echo "plain-http = true" >> "${cert_dir}/hosts.toml"
done

sleep infinity
40 changes: 37 additions & 3 deletions templates/_helpers.tpl
Original file line number Diff line number Diff line change
Expand Up @@ -75,12 +75,12 @@ We truncate at 63 chars because some Kubernetes name fields are limited to this
valueFrom:
secretKeyRef:
name: {{ if .Values.secrets.s3.secretRef }}{{ .Values.secrets.s3.secretRef }}{{ else }}{{ template "docker-registry.fullname" . }}-secret{{ end }}
key: s3AccessKey
key: {{ if .Values.secrets.s3.accessKeyName }}{{ .Values.secrets.s3.accessKeyName }}{{ else }} s3AccessKey {{ end }}
- name: REGISTRY_STORAGE_S3_SECRETKEY
valueFrom:
secretKeyRef:
name: {{ if .Values.secrets.s3.secretRef }}{{ .Values.secrets.s3.secretRef }}{{ else }}{{ template "docker-registry.fullname" . }}-secret{{ end }}
key: s3SecretKey
key: {{ if .Values.secrets.s3.secretKeyName}}{{ .Values.secrets.s3.secretKeyName}}{{ else }} s3SecretKey {{ end }}
{{- end -}}

{{- if .Values.s3.regionEndpoint }}
Expand All @@ -103,6 +103,36 @@ We truncate at 63 chars because some Kubernetes name fields are limited to this
value: {{ .Values.s3.secure | quote }}
{{- end -}}

{{- if .Values.s3.chunksize }}
- name: REGISTRY_STORAGE_S3_CHUNKSIZE
value: {{ .Values.s3.chunksize | quote }}
{{- end -}}

{{- if .Values.s3.multipartcopychunksize }}
- name: REGISTRY_STORAGE_S3_MULTIPARTCOPYCHUNKSIZE
value: {{ .Values.s3.multipartcopychunksize | quote }}
{{- end -}}

{{- if .Values.s3.multipartcopymaxconcurrency }}
- name: REGISTRY_STORAGE_S3_MULTIPARTCOPYMAXCONCURRENCY
value: {{ .Values.s3.multipartcopymaxconcurrency | quote }}
{{- end -}}

{{- if .Values.s3.multipartcopythresholdsize }}
- name: REGISTRY_STORAGE_S3_MULTIPARTCOPYTHRESHOLDSIZE
value: {{ .Values.s3.multipartcopythresholdsize | quote }}
{{- end -}}

{{- if .Values.s3.forcepathstyle }}
- name: REGISTRY_STORAGE_S3_FORCEPATHSTYLE
value: {{ .Values.s3.forcepathstyle | quote }}
{{- end -}}

{{- if .Values.s3.skipverify }}
- name: REGISTRY_STORAGE_S3_SKIPVERIFY
value: {{ .Values.s3.skipverify | quote }}
{{- end -}}

{{- else if eq .Values.storage "swift" }}
- name: REGISTRY_STORAGE_SWIFT_AUTHURL
value: {{ required ".Values.swift.authurl is required" .Values.swift.authurl }}
Expand All @@ -123,16 +153,20 @@ We truncate at 63 chars because some Kubernetes name fields are limited to this
{{- if .Values.proxy.enabled }}
- name: REGISTRY_PROXY_REMOTEURL
value: {{ required ".Values.proxy.remoteurl is required" .Values.proxy.remoteurl }}
{{- if .Values.proxy.username }}
- name: REGISTRY_PROXY_USERNAME
valueFrom:
secretKeyRef:
name: {{ if .Values.proxy.secretRef }}{{ .Values.proxy.secretRef }}{{ else }}{{ template "docker-registry.fullname" . }}-secret{{ end }}
key: proxyUsername
{{- end }}
{{- if .Values.proxy.password }}
- name: REGISTRY_PROXY_PASSWORD
valueFrom:
secretKeyRef:
name: {{ if .Values.proxy.secretRef }}{{ .Values.proxy.secretRef }}{{ else }}{{ template "docker-registry.fullname" . }}-secret{{ end }}
key: proxyPassword
{{- end }}
{{- end -}}

{{- if .Values.persistence.deleteEnabled }}
Expand All @@ -148,7 +182,7 @@ We truncate at 63 chars because some Kubernetes name fields are limited to this

{{- define "docker-registry.volumeMounts" -}}
- name: "{{ template "docker-registry.fullname" . }}-config"
mountPath: "/etc/docker/registry"
mountPath: {{ .Values.configPath }}

{{- if .Values.secrets.htpasswd }}
- name: auth
Expand Down
2 changes: 1 addition & 1 deletion templates/configmap.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ metadata:
namespace: {{ .Values.namespace | default .Release.Namespace }}
labels:
app: {{ template "docker-registry.name" . }}
chart: {{ .Chart.Name }}-{{ .Chart.Version }}
chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }}
heritage: {{ .Release.Service }}
release: {{ .Release.Name }}
data:
Expand Down
21 changes: 17 additions & 4 deletions templates/cronjob.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -17,16 +17,26 @@ spec:
app: {{ template "docker-registry.name" . }}
release: {{ .Release.Name }}
{{- with .Values.podLabels }}
{{ toYaml . | nindent 8 }}
{{- toYaml . | nindent 8 }}
{{- end }}
annotations:
checksum/config: {{ include (print $.Template.BasePath "/configmap.yaml") . | sha256sum }}
checksum/secret: {{ include (print $.Template.BasePath "/secret.yaml") . | sha256sum }}
{{- if .Values.podAnnotations }}
{{ toYaml .Values.podAnnotations | nindent 8 }}
{{- toYaml .Values.podAnnotations | nindent 8 }}
{{- end }}
spec:
template:
metadata:
labels:
release: {{ .Release.Name }}
{{- if or .Values.podLabels .Values.garbageCollect.podLabels }}
{{- toYaml (merge (.Values.garbageCollect.podLabels | default (dict)) (.Values.podLabels | default (dict))) | nindent 12 }}
{{- end }}
{{- if or .Values.podAnnotations .Values.garbageCollect.podAnnotations }}
annotations:
{{- toYaml (merge (.Values.garbageCollect.podAnnotations | default (dict)) (.Values.podAnnotations | default (dict))) | nindent 12 }}
{{- end}}
spec:
{{- if or (eq .Values.serviceAccount.create true) (ne .Values.serviceAccount.name "") }}
serviceAccountName: {{ .Values.serviceAccount.name | default (include "docker-registry.fullname" .) }}
Expand All @@ -48,8 +58,11 @@ spec:
- /bin/registry
- garbage-collect
- --delete-untagged={{ .Values.garbageCollect.deleteUntagged }}
- /etc/docker/registry/config.yml
resources: {{ toYaml .Values.garbageCollect.resources | nindent 12 }}
- {{ .Values.configPath }}/config.yml
{{- if .Values.garbageCollect.resources }}
resources:
{{- toYaml .Values.garbageCollect.resources | nindent 16 }}
{{- end }}
env: {{ include "docker-registry.envs" . | nindent 16 }}
{{- if .Values.containerSecurityContext.enabled }}
securityContext: {{ omit .Values.containerSecurityContext "enabled" | toYaml | nindent 16 }}
Expand Down
Loading
Loading