Skip to content

Commit 7949729

Browse files
jimmidysonsupershal
authored andcommitted
fix: Correctly configure non-mirror registry certificates
CA certificates are now written to `/etc/containerd/certs.d/<registryHost>/ca.crt` as required. Remove non-mirror registry config from `/etc/containerd/certs.d/_default/hosts.toml` which was causing all registries to be configured as mirror registry.
1 parent 506323a commit 7949729

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

pkg/handlers/generic/mutation/mirrors/containerd_files.go

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -68,7 +68,7 @@ func (c containerdConfig) needContainerdConfiguration() bool {
6868
// The upstream registry will be automatically used after all defined mirrors have been tried.
6969
// https://github.com/containerd/containerd/blob/main/docs/hosts.md#setup-default-mirror-for-all-registries
7070
//
71-
// 2. Setting CA certificate for global image registry mirror.
71+
// 2. Setting CA certificate for global image registry mirror and image registries.
7272
func generateContainerdDefaultHostsFile(
7373
configs []containerdConfig,
7474
) (*cabpkv1.File, error) {

0 commit comments

Comments
 (0)