mirror of
https://scm.tikali.ai/tikali/applications/monky/monky-deployd.git
synced 2026-09-18 04:36:15 +00:00
feat: pull private images without a hand docker login; surface the pull error
Design merged first: monky-design-docs !225 (doc 24 §4a). Pairs with monky-tenancy!40, which copies the estate-wide read-only Harbor robot into each environment's own prefix and marks the manifest entry `use: registry-auth`. - That entry is not an env var (it would otherwise land in .env and therefore in every container's environment). The agent parses it — JSON, or `username:password` with the new `registry_host` — and writes `<state_dir>/docker/config.json` 0600 in a directory it owns, with an explicit DOCKER_CONFIG pointing the docker CLI at it. The unit runs as monky-deployd, so a `docker login` by a human or by root is invisible to the agent: that is what made env-dev-01 look like it had no credential at all after the operator had just logged in. - `compose pull` failures now carry the registry's own message ("no basic auth credentials", "manifest unknown", DNS) into the journal and the report instead of `rc=1`. - Tests: both credential shapes, the refusals, 0600/0700 modes, idempotent rewrite, and that the runner never silently falls back to a human's $HOME. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KLB7jieMNRkTsJ2epr4Ds1
This commit is contained in:
@@ -1,6 +1,18 @@
|
||||
<!-- xlate:verbatim-fences -->
|
||||
# Changelog
|
||||
|
||||
## 0.1.7 — registry credential + a pull error you can read (2026-09-08)
|
||||
|
||||
- **No hand `docker login` on a new box** (monky-design-docs !225, doc 24 §4a). A manifest entry marked
|
||||
`use: registry-auth` is the Harbor pull credential, not an env var: it is written to
|
||||
`<state_dir>/docker/config.json` (0600, in a directory the agent owns) and the docker CLI is pointed at it
|
||||
with an explicit **`DOCKER_CONFIG`**. That last part is the trap — the unit runs as `monky-deployd`, so a
|
||||
`docker login` by a human or by root is invisible to the agent and looks exactly like no credential at all
|
||||
(env-dev-01, 2026-09-08). Both seeded shapes are accepted: a JSON object, or `username:password` with the
|
||||
registry from the new `registry_host` config.
|
||||
- **`compose pull` failures carry the registry's own message** instead of `rc=1`. "no basic auth
|
||||
credentials", "manifest unknown" and DNS failures now reach the journal and the report to tenancy.
|
||||
|
||||
## 0.1.6 — 2026-09-07
|
||||
|
||||
- **A valid lease token is reused across applies.** Every apply requested a new lease, so a failing deploy
|
||||
|
||||
Reference in New Issue
Block a user