1"use strict";(globalThis.webpackChunkd7y_io||=[]).push([[15466],{78230(e,n,t){t.r(n),t.d(n,{assets:()=>c,contentTitle:()=>o,default:()=>p,frontMatter:()=>a,metadata:()=>r,toc:()=>d});const r=JSON.parse('{"id":"setup/runtime/containerd/containerd-proxy","title":"Http Proxy mode","description":"Use dfget daemon as HTTP proxy for containerd","source":"@site/versioned_docs/version-v2.0.4/setup/runtime/containerd/proxy.md","sourceDirName":"setup/runtime/containerd","slug":"/setup/runtime/containerd/proxy","permalink":"/docs/v2.0.4/setup/runtime/containerd/proxy","draft":false,"unlisted":false,"editUrl":"https://github.com/dragonflyoss/d7y.io/edit/main/docs/setup/runtime/containerd/proxy.md","tags":[],"version":"v2.0.4","lastUpdatedBy":"Josh Soref","lastUpdatedAt":1773306083000,"frontMatter":{"id":"containerd-proxy","title":"Http Proxy mode","slug":"/setup/runtime/containerd/proxy"},"sidebar":"docs","previous":{"title":"Mirror mode","permalink":"/docs/v2.0.4/setup/runtime/containerd/mirror"},"next":{"title":"Docker","permalink":"/docs/v2.0.4/setup/runtime/docker"}}');var s=t(74848),i=t(28453);const a={id:"containerd-proxy",title:"Http Proxy mode",slug:"/setup/runtime/containerd/proxy"},o=void 0,c={},d=[{value:"Quick Start",id:"quick-start",level:2},{value:"Step 1: Generate CA certificate for HTTP proxy",id:"step-1-generate-ca-certificate-for-http-proxy",level:3},{value:"Step 2: Configure dfget daemon",id:"step-2-configure-dfget-daemon",level:3},{value:"Step 3: Configure containerd",id:"step-3-configure-containerd",level:3},{value:"Step 4: Pull images with proxy",id:"step-4-pull-images-with-proxy",level:3}
1,{value:"Custom assets",id:"custom-assets",level:2},{value:"Registry uses a self-signed certificate",id:"registry-uses-a-self-signed-certificate",level:3}];function l(e){const n={code:"code",h2:"h2",h3:"h3",p:"p",pre:"pre",...(0,i.R)(),...e.components};return(0,s.jsxs)(s.Fragment,{children:[(0,s.jsx)(n.p,{children:"Use dfget daemon as HTTP proxy for containerd"}),"\n",(0,s.jsxs)(n.p,{children:["Currently, ",(0,s.jsx)(n.code,{children:"ctr"})," command of containerd doesn't support private registries with ",(0,s.jsx)(n.code,{children:"registry-mirrors"}),",\nin order to do so, we need to use HTTP proxy for containerd."]}),"\n",(0,s.jsx)(n.h2,{id:"quick-start",children:"Quick Start"}),"\n",(0,s.jsx)(n.h3,{id:"step-1-generate-ca-certificate-for-http-proxy",children:"Step 1: Generate CA certificate for HTTP proxy"}),"\n",(0,s.jsx)(n.p,{children:"Generate a CA certificate private key."}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"openssl genrsa -out ca.key 2048\n"})}),"\n",(0,s.jsxs)(n.p,{children:["Open openssl config file ",(0,s.jsx)(n.code,{children:"openssl.conf"}),".\nNote set ",(0,s.jsx)(n.code,{children:"basicConstraints"})," to true, that you can modify the values."]}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-text",children:"[ req ]\n#default_bits = 2048\n#default_md = sha256\n#default_keyfile = privkey.pem\ndistinguished_name = req_distinguished_name\nattributes = req_attributes\nextensions = v3_ca\nreq_extensions = v3_ca\n\n[ req_distinguished_name ]\ncountryName = Country Name (2 letter code)\ncountryName_min = 2\ncountryName_max = 2\nstateOrProvinceName = State or Province Name (full name)\nlocalityName = Locality Name (eg, city)\n0.organizationName = Organization Name (eg, company)\norganizationalUnitName = Organizational Unit Name (eg, section)\ncommonName = Common Name (eg, fully qualified host name)\ncommonName_max = 64\nemailAddress = Email Address\nemailAddress_max = 64\n\n[ req_attributes ]\nchallengePassword = A challenge password\nchallengePassword_min = 4\nchallengePassword_max = 20\n\n[ v3_ca ]\nbasicConstraints = CA:TRUE\n"})}),"\n",(0,s.jsx)(n.p,{children:"Generate the CA certificate."}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"openssl req -new -key ca.key -nodes -out ca.csr -config openssl.conf\nopenssl x509 -req -days 36500 -extfile openssl.conf \\\n -extensions v3_ca -in ca.csr -signkey ca.key -out ca.crt\n"})}),"\n",(0,s.jsx)(n.h3,{id:"step-2-configure-dfget-daemon",children:"Step 2: Configure dfget daemon"}),"\n",(0,s.jsxs)(n.p,{children:["To use dfget daemon as HTTP proxy, first you need to append a proxy rule in\n",(0,s.jsx)(n.code,{children:"/etc/dragonfly/dfget.yaml"}),", This will proxy\n",(0,s.jsx)(n.code,{children:"your.private.registry"}),"'s requests for image layers:"]}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-yaml",children:"proxy:\n security:\n insecure: true\n tcpListen:\n listen: 0.0.0.0\n port: 65001\n proxies:\n - regx: blobs/sha256.*\n hijackHTTPS:\n # CA certificate's path used to hijack https requests\n cert: ca.crt\n key: ca.key\n hosts:\n - regx: your.private.registry\n"})}),"\n",(0,s.jsx)(n.h3,{id:"step-3-configure-containerd",children:"Step 3: Configure containerd"}),"\n",(0,s.jsxs)(n.p,{children:["Set dfget daemon as ",(0,s.jsx)(n.code,{children:"HTTP_PROXY"})," and ",(0,s.jsx)(n.code,{children:"HTTPS_PROXY"})," for containerd in\n",(0,s.jsx)(n.code,{children:"/etc/systemd/system/containerd.service.d/http-proxy.conf"}),":"]}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-toml",children:'[Service]\nEnvironment="HTTP_PROXY=http://127.0.0.1:65001"\nEnvironment="HTTPS_PROXY=http://127.0.0.1:65001"\n'})}),"\n",(0,s.jsx)(n.h3,{id:"step-4-pull-images-with-proxy",children:"Step 4: Pull images with proxy"}),"\n",(0,s.jsx)(n.p,{children:"Through the above steps, we can start to validate if Dragonfly works as expected."}),"\n",(0,s.jsx)(n.p,{children:"And you can pull the image as usual, for example:"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"ctr image pull your.private.registry/namespace/image:latest\n"})}),"\n",(0,s.jsx)(n.h2,{id:"custom-assets",children:"Custom assets"}),"\n",(0,s.jsx)(n.h3,{id:"registry-uses-a-self-signed-certificate",children:"Registry uses a self-signed certificate"}),"\n",(0,s.jsx)(n.p,{children:"If your registry uses a self-signed certificate, you can either choose to\nignore the certificate error with:"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-yaml",children:"proxy:\n security:\n insecure: true\n tcpListen:\n listen: 0.0.0.0\n port: 65001\n proxies:\n - regx: blobs/sha256.*\n hijackHTTP
1S:\n # CA certificate's path used to hijack https requests\n cert: ca.crt\n key: ca.key\n hosts:\n - regx: your.private.registry\n insecure: true\n"})}),"\n",(0,s.jsx)(n.p,{children:"Or provide a certificate with:"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-yaml",children:"proxy:\n security:\n insecure: true\n tcpListen:\n listen: 0.0.0.0\n port: 65001\n proxies:\n - regx: blobs/sha256.*\n hijackHTTPS:\n # CA certificate's path used to hijack https requests\n cert: ca.crt\n key: ca.key\n hosts:\n - regx: your.private.registry\n certs: ['server.crt']\n"})}),"\n",(0,s.jsx)(n.p,{children:"You can get the certificate of your server with:"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"openssl x509 -in <(openssl s_client -showcerts \\\n -servername your.domain.com -connect your.domain.com:443 -prexit 2>/dev/null)\n"})})]})}function p(e={}){const{wrapper:n}={...(0,i.R)(),...e.components};return n?(0,s.jsx)(n,{...e,children:(0,s.jsx)(l,{...e})}):l(e)}},28453(e,n,t){t.d(n,{R:()=>a,x:()=>o});var r=t(96540);const s={},i=r.createContext(s);function a(e){const n=r.useContext(i);return r.useMemo(function(){return"function"==typeof e?e(n):{...n,...e}},[n,e])}function o(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(s):e.components||s:a(e.components),r.createElement(i.Provider,{value:n},e.children)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.