[root@support ~]# oc rsh image-registry-8548787bc4-wsvvp sh-4.4$ ls registry/ sh-4.4$
可知,内部并没有缓存。
随后使用该 is 继续创建应用:
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18
[root@support ~]# oc get is NAME IMAGE REPOSITORY TAGS UPDATED hello-ocp default-route-openshift-image-registry.apps.ocp4.ocp.icu/is-test/hello-ocp latest 8 minutes ago [root@support ~]# oc new-app --name hello-2 -i hello-ocp --> Found image 7af3297 (6 years old) in image stream "is-test/hello-ocp" under tag "latest"for"hello-ocp"
--> Creating resources ... deployment.apps "hello-2" created service "hello-2" created --> Success Application is not exposed. You can expose services to the outside world by executing one or more of the commands below: 'oc expose service/hello-2' Run 'oc status' to view your app.
[root@support ~]# oc get pods -o wide NAME READY STATUS RESTARTS AGE IP NODE NOMINATED NODE READINESS GATES hello-2-6d89f9f58f-k8h87 1/1 Running 0 70s 10.129.2.9 worker03.ocp4.ocp.icu <none> <none> hello-ocp-cd8888b5c-t44gm 1/1 Running 0 9m44s 10.128.2.18 worker02.ocp4.ocp.icu <none> <none>
[root@support ~]# oc project openshift-image-registry Now using project "openshift-image-registry" on server "https://api.ocp4.ocp.icu:6443". [root@support ~]# oc rsh image-registry-8548787bc4-wsvvp sh-4.4$ ls registry/ sh-4.4$
[root@support ~]# oc rsh image-registry-8548787bc4-wsvvp sh-4.4$ ls registry/ sh-4.4$
也为空!
使用 local reference policy 的 is 创建应用:
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16
[root@support ~]# oc new-app --name hello-3 -i hello-ocp:local --> Found image 7af3297 (6 years old) in image stream "is-test/hello-ocp" under tag "local"for"hello-ocp:local"
--> Creating resources ... deployment.apps "hello-3" created service "hello-3" created --> Success Application is not exposed. You can expose services to the outside world by executing one or more of the commands below: 'oc expose service/hello-3' Run 'oc status' to view your app.
[root@support ~]# oc get pods -o wide NAME READY STATUS RESTARTS AGE IP NODE NOMINATED NODE READINESS GATES hello-2-6d89f9f58f-k8h87 1/1 Running 0 8m3s 10.129.2.9 worker03.ocp4.ocp.icu <none> <none> hello-3-5cd95fc76c-6wj7f 1/1 Running 0 31s 10.128.2.21 worker02.ocp4.ocp.icu <none> <none> hello-ocp-cd8888b5c-t44gm 1/1 Running 0 16m 10.128.2.18 worker02.ocp4.ocp.icu <none> <none>
验证内部 registry 内容:
1 2 3 4 5
[root@support ~]# oc project openshift-image-registry Now using project "openshift-image-registry" on server "https://api.ocp4.ocp.icu:6443". [root@support ~]# oc rsh image-registry-8548787bc4-wsvvp sh-4.4$ ls /registry/docker/registry/v2/repositories/is-test/hello-ocp/_layers/sha256/ 7af3297a3fb4487b740ed6798163f618e6eddea1ee5fa0ba340329fcae31c8f6
还有一种例外,如果使用 is 对应的内部镜像仓库地址使用 reference policy 为 source 的也将缓存到内部 registry。
归纳:
image stream 的 reference policy 默认为 source
使用 source reference policy 的 is 创建应用时,将直接访问源 registry,并且不会缓存
使用 local reference policy 的 is 在导入时不会缓存,当使用该 is 创建应用时,它会缓存
OpenShift 文档对于 Reference Policy 的解释:
The Reference Policy allows you to specify from where resources that reference this image stream tag pulls the image. It applies to only images that you import from external registries. There are two options to choose from: Local and Source. The Source policy instructs clients to pull directly from the source registry of the image. The integrated registry is not involved unless the image is managed by the cluster. (It is not an external image.) This is the default policy. The Local policy instructs clients to always pull from the integrated registry. This is useful if you want to pull from external insecure registries without modifying Docker daemon settings. This policy only affects the use of the image stream tag. Components or operations that directly reference or pull the image using its external registry location is not redirected to the internal registry. The pull-through feature of the registry serves the remote image to the client. This feature, which is on by default, must be enabled for the local reference policy to be used. Additionally, by default, all the blobs are mirrored for faster access later. You can set the policy in a specification of image stream tag as referencePolicy.type.
评论· · · · · ·