registry.k8s.io
nix-portable
registry.k8s.io | nix-portable | |
---|---|---|
20 | 11 | |
350 | 717 | |
2.6% | - | |
7.2 | 7.8 | |
4 months ago | 7 days ago | |
Go | Nix | |
Apache License 2.0 | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
registry.k8s.io
-
Pull through cache, like AWS just announced
If you stop to think about, what AWS is selling here, it's quite funny. Most of the infrastructure behind registry.k8s.io is hosted on AWS (and also GCP). So AWS essentially tells you: Don't trust the upstream registry, it might go down, cache it on your own registry, hosted also by us.
- Resilient image cache/mirror
-
Announcing pull through cache for registry.k8s.io in Amazon Elastic Container Registry
For example: if you only allow cluster autoscaler and metrics server from registry.k8s.io you can pull those images through the cache as someone who has create repo IAM privileges. If someone without create repo privileges tries to pull a new image it will fail because they can't create the initial repo.
- How are they doing it?
-
registry.k8s.io down from Paris, France?
https://registry.k8s.io (the root url at /) redirects you to https://github.com/kubernetes/registry.k8s.io where we have an issue tracker.
-
FailedCreatePodSandBox
โ This container is having trouble accessing https://registry.k8s.io
- registry.k8s.io/README.md at main ยท kubernetes/registry.k8s.io ยท GitHub
-
How to own your own Docker Registry address
Hosting a forwarding / redirect server instead of actually hosting images is probably a decent idea.
The K8s proxy is redirecting from only hosting on GCR to community-owned registries - https://kubernetes.io/blog/2023/03/10/image-registry-redirec...
You can view the code here - https://github.com/kubernetes/registry.k8s.io
But because everyone is already pointing at gcr.io (just like many openfaas users point at docker.io/) - they're having to do a huge campaign to announce the new URL - the same would apply with the author's solution here.
I wrote some automation for hosting (not redirects) in arkade with the OSS registry - Get a TLS-enabled Docker registry in 5 minutes - https://blog.alexellis.io/get-a-tls-enabled-docker-registry-...
The registry is also something you can run on a VM if you so wish, and have act as a pull through cache.
Apart from reliability - GitHub's container registry is the current next best option - but we have to ask ourselves, what happens when they start charging or the outages start to last longer or are more frequent than 1-2 times per week as we've seen in Q1 2023.
-
Docker's deleting Open Source images and here's what you need to know
One annoyance with how docker images are specified is they include the location where they are stored. So if you want to change where you store you image you break everyone.
I wonder if what regsitry.k8s.io does could be generalized:
https://github.com/kubernetes/registry.k8s.io/blob/main/cmd/...
The idea is the depending on which cloud you are pulling the image from, they will use the closest blob store to service the request. This also has the effect that you could change the source of truth for the registry without breaking all Dockerfiles.
-
k8s.gcr.io Image Registry Will Be Frozen From the 3rd of April 2023
If you are using updated helm charts then most of them have already replaced with registry.k8s.io, for example nginx ingress so not really breaking change.
nix-portable
-
An independent package manager that every hacker deserves
There is also nix-portable (https://github.com/DavHau/nix-portable), which is basically a drop-in replacement for normal nix that does everything required for no-root operation by itself when needed. Just put the single binary in your PATH and it's ready.
-
Docker's deleting Open Source images and here's what you need to know
level (/nix/store/)
Yes, for cache hits to happen it has to be this way as far as I remember.
There is a project called nix-portable though that I've seen some HPC users report success with:
https://github.com/DavHau/nix-portable
-
The Determinate Nix Installer
Great work Graham and team, I'll be switching to it on OSX.
I wonder if you took a look at some of the modifications done by portable-nix (https://github.com/DavHau/nix-portable), most important ones being:
a) Allowing user to choose the location of the nix folder (for example $HOME/.nix) by using bwrap or proot
- is it possible to install the nix package manager with no root privleges?
-
Day 15 with silverblue, loving how rock stable the whole system feels! Exactly the kind of distro i've always wanted.
you can install it and forget about it. yeah the major downside is that you need to disable selinux unless you use nix portable.
- I found this
-
I made a nix-portable integration for direnv for my friend who doesn't want to install nix on his machine ๐
Yeah sadly nix-portable doesn't support macOS because of missing kernel features. They are also thinking about docker fallback though: https://github.com/DavHau/nix-portable/issues/23 ๐ค๐
-
Introducing Riff, a Nix-based tool for automatically providing external dependencies to Rust projects
There is this: https://github.com/DavHau/nix-portable but I agree we need an official solution
-
We want to make Nix better
Not entirely true, there are many ways in which you can use a custom location and still take advantage of the binary cache. You can do it with chroot, file system namespaces, bind mounts and so on. There's also a nice user friendly tool that does exactly this [1].
[1]: https://github.com/DavHau/nix-portable
-
Nix Development Container
This is cool! In a similar vein, it's worth mentioning nix-portable is a thing. Same idea of containerization except it avoids docker. https://github.com/DavHau/nix-portable
What are some alternatives?
official-images - Primary source of truth for the Docker "Official Images" program
dream2nix - Simplified nix packaging for various programming language ecosystems [maintainer=@DavHau]
cri-o - Open Container Initiative-based implementation of Kubernetes Container Runtime Interface
arion-compose - Run docker-compose with help from Nix/NixOS
one-click-apps - Community Maintained One Click Apps (https://github.com/caprover/caprover)
nix-gaming - Gaming on Nix
docker-registry-mirror - Helm chart for a Docker registry. Successor to stable/docker-registry chart.
Home Manager using Nix - Manage a user environment using Nix [maintainer=@rycee]
ipdr - ๐ IPFS-backed Docker Registry
bob - Bob is a high-level build tool for multi-language projects.
devenv - Fast, Declarative, Reproducible, and Composable Developer Environments
nixpkgs - Nix Packages collection & NixOS