Skip to content

Commit 9e62e19

Browse files
author
Keerthan Reddy Mala
committed
feat(registry): remove the documentation specifying insecure registry
1 parent b19b066 commit 9e62e19

4 files changed

Lines changed: 11 additions & 18 deletions

File tree

src/installing-workflow/system-requirements.md

Lines changed: 3 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -26,14 +26,10 @@ application footprint as well.
2626
Running smaller machines will likely result in increased system load and has been known to result in component failures
2727
and instability.
2828

29-
## Docker Insecure Registry
29+
!!! warning
3030

31-
The on-cluster Docker registry is not deployed with TLS enabled. As such, all Kubernetes worker nodes must have their
32-
Docker daemons configured to use an **insecure registry**. The configured subnet should encompass any private networks
33-
used by your worker nodes, including overlay networks.
34-
35-
Depending on your Kubernetes and Docker configuration, setting `EXTRA_DOCKER_OPTS="--insecure-registry=10.0.0.0/8"` may
36-
be sufficient.
31+
Versions prior to 2.2 require '--insecure-registry' to function properly. Depending on your Kubernetes and Docker configuration,
32+
setting `EXTRA_DOCKER_OPTS="--insecure-registry=10.0.0.0/8"` may be sufficient.
3733

3834
## SELinux + OverlayFS
3935

src/quickstart/provider/aws/boot.md

Lines changed: 0 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -51,11 +51,6 @@ LICENSES README.md Vagrantfile cluster/ contrib/ docs/ ex
5151
Before calling the Kubernetes setup scripts, we need to change a few defaults so that Deis Workflow works best. Type
5252
each of these commands into your terminal application before calling `kube-up.sh`.
5353

54-
First, enable insecure registry support for Docker:
55-
```
56-
$ export KUBE_ENABLE_INSECURE_REGISTRY=true
57-
```
58-
5954
Next, pick the AWS Availability Zone you would like to use. The boot script will create a new VPC in that region.
6055

6156
```

src/quickstart/provider/vagrant/boot.md

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -39,9 +39,8 @@ LICENSES README.md Vagrantfile cluster/ contrib/ docs/ ex
3939
Before calling the Kubernetes setup scripts, we need to change a few defaults so that Deis Workflow works best. Type
4040
each of these commands into your terminal application before calling `kube-up.sh`.
4141

42-
First, enable insecure registry support for Docker and use Vagrant as the provider:
42+
First, set Vagrant as the provider:
4343
```
44-
$ export KUBE_ENABLE_INSECURE_REGISTRY=true
4544
$ export KUBERNETES_PROVIDER=vagrant
4645
```
4746

@@ -57,7 +56,6 @@ Double check the configured environment variables:
5756

5857
```
5958
$ env | grep KUBE
60-
KUBE_ENABLE_INSECURE_REGISTRY=true
6159
KUBERNETES_PROVIDER=vagrant
6260
KUBERNETES_NODE_MEMORY=4096
6361
KUBERNETES_MASTER_MEMORY=1536

src/understanding-workflow/components.md

Lines changed: 7 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -93,9 +93,13 @@ configure minio to use persistent storage available in your environment.
9393
**Project Location:** [deis/registry](https://github.com/deis/registry)
9494

9595
The registry component is a managed docker registry which holds application
96-
images generated from the builder component. Registry persists the Docker image
97-
iamges to either local storage (in development mode) or to object storage
98-
configured for the cluster.
96+
images generated from the builder component. Registry persists the Docker
97+
images to either local storage (in development mode) or to object storage
98+
configured for the cluster. Starting with release v2.2.0, the component also runs a
99+
[proxy](https://github.com/kubernetes/kubernetes/tree/master/cluster/addons/registry/images)
100+
daemon to expose the registry service as `localhost` on each node. The proxy daemon uses
101+
[HAProxy](http://www.haproxy.org/) to route the incoming registry requests on `localhost` to the
102+
registry service removing the necessity of setting `--insecure-registry` for docker daemon.
99103

100104
## Router
101105

0 commit comments

Comments
 (0)