Skip to content

refac(gcp): resolve the container registry once for all data centers - #630

Open
NJona wants to merge 1 commit into
multi-dc-07-thread-datacenter-configfrom
multi-dc-08-shared-registry
Open

refac(gcp): resolve the container registry once for all data centers#630
NJona wants to merge 1 commit into
multi-dc-07-thread-datacenter-configfrom
multi-dc-08-shared-registry

Conversation

@NJona

@NJona NJona commented Jul 31, 2026

Copy link
Copy Markdown
Member

The registry was written straight into the single install config, so which registry the nodes pull from was decided per config rather than per project. It now resolves onto the environment (ContainerRegistryURL plus credentials) and updateInstallConfig applies it to every data center's config and vault. All three registry types go through the same field, which also fixes the artifact registry never recording its URI on the create path.

EnsureLocalContainerRegistry is split in two, because it early-returned when the registry was already running and thereby skipped distributing the registry certificate. A re-run that adds a data center hits exactly that path, and its nodes would then fail every pull with x509: certificate signed by unknown authority.

Review notes

Starting the registry stays conditional; distributing the certificate now always runs, over every data center's cluster nodes. That is safe because it is idempotent, and it is covered by a regression test ("distributes the registry certificate even when the registry is already running").

Part of the oms beta bootstrap-gcp --multi-dc stack (10 PRs). Merge in order; each PR is based on its predecessor.

The registry was written straight into the single install config, so
which registry the nodes pull from was decided per config rather than
per project. It now resolves onto the environment
(ContainerRegistryURL plus credentials) and updateInstallConfig applies
it to every data center's config and vault. All three registry types go
through the same field, which also fixes the artifact registry never
recording its URI on the create path.

EnsureLocalContainerRegistry is split in two, because it early-returned
when the registry was already running and thereby skipped distributing
the registry certificate. A re-run that adds a data center hits exactly
that path, and its nodes would then fail every pull with "certificate
signed by unknown authority". Starting the registry stays conditional;
distributing the certificate now always runs, over every data center's
cluster nodes, which is safe because it is idempotent.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Jona Neef <Jona.Neef.97@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant