Conversation
Allow UpdateServiceCmd to forward registry credentials through the X-Registry-Auth header. Cover header serialization with focused tests and verify service updates can pull an image from an authenticated private registry.
Author
|
@eddumelendez Please review when you have a moment. Thank you. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds registry authentication support to UpdateServiceCmd, bringing service updates in line with the authentication support already available when creating services.
Problem
A service update can change its container image. When the new image is hosted in a private registry, Docker requires registry credentials in the X-Registry-Auth request header. UpdateServiceCmd did not expose an AuthConfig option, so callers could not provide those credentials and Swarm could not pull the private image during an update.
Implementation
Running the registry in the Swarm Docker-in-Docker daemon is important because localhost:5050 must resolve to the registry from the worker performing the image pull.
Compatibility
Verification
The executor tests verify both the serialized authentication header and its omission when authentication is not configured.
The integration test starts a service with a public image, pushes that image to an authenticated local registry, removes the local private-image tag, and then updates the service with AuthConfig. It waits until the replacement Swarm task is running the private image, ensuring the update really authenticated and pulled from the registry.