Skip to content

Allow pulls from an insecure registry - #490

Merged
aanand merged 3 commits into
docker:masterfrom
LuminosoInsight:insecure-pull
Oct 1, 2014
Merged

Allow pulls from an insecure registry#490
aanand merged 3 commits into
docker:masterfrom
LuminosoInsight:insecure-pull

Conversation

@jbalonso

Copy link
Copy Markdown

We maintain a private docker registry without SSL (it isn't necessary). This PR adds an -i option to fig pull that enables insecure mode.

@thaJeztah

Copy link
Copy Markdown
Member

I wonder if this should be a short ( -i) flag, or be more explicit (--insecure)?

@dnephin

Copy link
Copy Markdown

+1, I hit this as well, I'd be fine with either short or long option

@bfirsh

Copy link
Copy Markdown

+1 long flag. And it should be --allow-insecure-ssl: https://github.com/docker/docker/pull/2687/files

@jbalonso

Copy link
Copy Markdown
Author

Ok. A commit with --alow-insecure-ssl is forthcoming. Also, sign-offs, and using insecure_registry as the keyword argument instead of insecure for consistency with docker-py.

@bfirsh

Copy link
Copy Markdown

Great, thanks! Original commit still needs signing off though. You can squash all of this with git rebase -i master and signoff the single commit with git commit --amend --signoff.

@jbalonso

Copy link
Copy Markdown
Author

I took care of the signoff in the squash, and I believe the ball is back in your court.

@bfirsh

Copy link
Copy Markdown

Great stuff, thanks!

@dnephin

Copy link
Copy Markdown

I just realized that this kwarg (insecure_registry) was only added to docker-py in 0.5.0, but right now in setup.py the minimum version is 0.3.2. I think for this change to be safe you need to change the docker-py requirement to:
docker-py >= 0.5, < 0.6

@dnephin

Copy link
Copy Markdown

Not sure why the travis build hasn't run on this branch, but I'm also getting a couple flake8 errors

@bfirsh

Copy link
Copy Markdown

Oops.

We've replaced Travis with Wercker, so this needs rebasing to get CI run on it.

@jbalonso

Copy link
Copy Markdown
Author

I've fixed the docker-py dependency. I'll worry about rebasing (where should I rebase to? I see an "All is well -- build finished" on the PR) and figuring out the flakes tomorrow.

@bfirsh

Copy link
Copy Markdown

We only recently added the file that makes the build work. If you rebase on to the current master, it'll get the wercker.yml file to make the build work. You can run nosetests and flake8 fig locally to verify the things the build runs.

@jbalonso

Copy link
Copy Markdown
Author

I've rebased, but I'm still cleaning up the branch.

Jason Bernardino Alonso added 2 commits September 26, 2014 16:36
Signed-off-by: Jason Bernardino Alonso <jalonso@luminoso.com>
Signed-off-by: Jason Bernardino Alonso <jalonso@luminoso.com>
@jbalonso

Copy link
Copy Markdown
Author

Ok. A third force-push later, I believe I have cleaned up this PR.

@bfirsh

Copy link
Copy Markdown

LGTM

@bfirsh

Copy link
Copy Markdown

Don't think it's easy to test this without mocking out docker-py. :/

@dnephin

Copy link
Copy Markdown

At the very least a simple unit test that asserts the right docker.client function was called wouldn't hurt. ServiceTest already creates a mock_client

@bfirsh

Copy link
Copy Markdown

Oh cool, forgot about that. @jbalonso – would be great to get a test!

@bfirshbfirsh added this to the 1.0.0 milestone Sep 30, 2014
Signed-off-by: Moss Collum <mcollum@luminoso.com>
@moss

moss commented Oct 1, 2014

Copy link
Copy Markdown

I've added the missing unit test to ServiceTest. Please let me know if it needs any cleanup.

@bfirsh

Copy link
Copy Markdown

LGTM

aanand added a commit that referenced this pull request Oct 1, 2014
@aanand
aanand merged commit 431fdaa into docker:masterOct 1, 2014
@jbalonso
jbalonso deleted the insecure-pull branch October 9, 2014 19:49
@tjrivera

Copy link
Copy Markdown

Hey guys, it seems like Fig will also attempt to pull needed images when running fig up -- not just when fig pull is run explicitly. The insecure flag in this case would have to be also passed at Project.up then through here: https://github.com/docker/fig/blob/master/fig/project.py#L175 and ultimately out to here: https://github.com/docker/fig/blob/master/fig/service.py#L182 where pull is being run again. I can work on a PR if this makes sense.

@jbalonso

Copy link
Copy Markdown
Author

I kinda feel responsible for not catching that in my PR. I'll mention that I'm out of bandwidth to work on it myself at the moment.

@dnephin

Copy link
Copy Markdown

I've run into this as well. I got around it for now by always doing a fig pull --allow-insecure-ssl first but it would be nice to not have to do that.

I think your solution sounds appropriate.

@torbjornvatn

Copy link
Copy Markdown

I've also run into this, and I really would like to call fig pull --allow-insecure-ssl directly. Are you working on a PR @tjrivera or should I try to fix this at work tomorrow?

@tjrivera

Copy link
Copy Markdown

@torbjornvatn I was planning on submitting a PR tomorrow morning

@torbjornvatn

Copy link
Copy Markdown

@tjrivera Nice!

yuval-k pushed a commit to yuval-k/compose that referenced this pull request Apr 10, 2015
Allow pulls from an insecure registry
Signed-off-by: Yuval Kohavi <yuval.kohavi@gmail.com>
yuval-k pushed a commit to yuval-k/compose that referenced this pull request Apr 10, 2015
PR docker#490 Provides the ability to pull from an insecure registry by passing --allow-insecure-ssl. This commit extends the work done in docker#490 and adds the ability to pass --allow-insecure-ssl to the up and run commands which will attempt to pull dependent images if they do not exist.
Signed-off-by: Tyler Rivera <riverat2@email.chop.edu>
Signed-off-by: Yuval Kohavi <yuval.kohavi@gmail.com>
infraAnchor pushed a commit to infraAnchor/compose that referenced this pull request Mar 6, 2026
Signed-off-by: Brian Brazil <brian.brazil@robustperception.io>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants

@jbalonso@thaJeztah@dnephin@bfirsh@moss@tjrivera@torbjornvatn@aanand
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Allow pulls from an insecure registry by jbalonso · Pull Request #490 · docker/compose · GitHub
Skip to content

Allow pulls from an insecure registry - #490

Merged
aanand merged 3 commits into
docker:masterfrom
LuminosoInsight:insecure-pull
Oct 1, 2014
Merged

Allow pulls from an insecure registry#490
aanand merged 3 commits into
docker:masterfrom
LuminosoInsight:insecure-pull

Conversation

@jbalonso

Copy link
Copy Markdown

We maintain a private docker registry without SSL (it isn't necessary). This PR adds an -i option to fig pull that enables insecure mode.

@thaJeztah

Copy link
Copy Markdown
Member

I wonder if this should be a short ( -i) flag, or be more explicit (--insecure)?

@dnephin

Copy link
Copy Markdown

+1, I hit this as well, I'd be fine with either short or long option

@bfirsh

Copy link
Copy Markdown

+1 long flag. And it should be --allow-insecure-ssl: https://github.com/docker/docker/pull/2687/files

@jbalonso

Copy link
Copy Markdown
Author

Ok. A commit with --alow-insecure-ssl is forthcoming. Also, sign-offs, and using insecure_registry as the keyword argument instead of insecure for consistency with docker-py.

@bfirsh

Copy link
Copy Markdown

Great, thanks! Original commit still needs signing off though. You can squash all of this with git rebase -i master and signoff the single commit with git commit --amend --signoff.

@jbalonso

Copy link
Copy Markdown
Author

I took care of the signoff in the squash, and I believe the ball is back in your court.

@bfirsh

Copy link
Copy Markdown

Great stuff, thanks!

@dnephin

Copy link
Copy Markdown

I just realized that this kwarg (insecure_registry) was only added to docker-py in 0.5.0, but right now in setup.py the minimum version is 0.3.2. I think for this change to be safe you need to change the docker-py requirement to:
docker-py >= 0.5, < 0.6

@dnephin

Copy link
Copy Markdown

Not sure why the travis build hasn't run on this branch, but I'm also getting a couple flake8 errors

@bfirsh

Copy link
Copy Markdown

Oops.

We've replaced Travis with Wercker, so this needs rebasing to get CI run on it.

@jbalonso

Copy link
Copy Markdown
Author

I've fixed the docker-py dependency. I'll worry about rebasing (where should I rebase to? I see an "All is well -- build finished" on the PR) and figuring out the flakes tomorrow.

@bfirsh

Copy link
Copy Markdown

We only recently added the file that makes the build work. If you rebase on to the current master, it'll get the wercker.yml file to make the build work. You can run nosetests and flake8 fig locally to verify the things the build runs.

@jbalonso

Copy link
Copy Markdown
Author

I've rebased, but I'm still cleaning up the branch.

Jason Bernardino Alonso added 2 commits September 26, 2014 16:36
Signed-off-by: Jason Bernardino Alonso <jalonso@luminoso.com>
Signed-off-by: Jason Bernardino Alonso <jalonso@luminoso.com>
@jbalonso

Copy link
Copy Markdown
Author

Ok. A third force-push later, I believe I have cleaned up this PR.

@bfirsh

Copy link
Copy Markdown

LGTM

@bfirsh

Copy link
Copy Markdown

Don't think it's easy to test this without mocking out docker-py. :/

@dnephin

Copy link
Copy Markdown

At the very least a simple unit test that asserts the right docker.client function was called wouldn't hurt. ServiceTest already creates a mock_client

@bfirsh

Copy link
Copy Markdown

Oh cool, forgot about that. @jbalonso – would be great to get a test!

@bfirshbfirsh added this to the 1.0.0 milestone Sep 30, 2014
Signed-off-by: Moss Collum <mcollum@luminoso.com>
@moss

moss commented Oct 1, 2014

Copy link
Copy Markdown

I've added the missing unit test to ServiceTest. Please let me know if it needs any cleanup.

@bfirsh

Copy link
Copy Markdown

LGTM

aanand added a commit that referenced this pull request Oct 1, 2014
@aanand
aanand merged commit 431fdaa into docker:masterOct 1, 2014
@jbalonso
jbalonso deleted the insecure-pull branch October 9, 2014 19:49
@tjrivera

Copy link
Copy Markdown

Hey guys, it seems like Fig will also attempt to pull needed images when running fig up -- not just when fig pull is run explicitly. The insecure flag in this case would have to be also passed at Project.up then through here: https://github.com/docker/fig/blob/master/fig/project.py#L175 and ultimately out to here: https://github.com/docker/fig/blob/master/fig/service.py#L182 where pull is being run again. I can work on a PR if this makes sense.

@jbalonso

Copy link
Copy Markdown
Author

I kinda feel responsible for not catching that in my PR. I'll mention that I'm out of bandwidth to work on it myself at the moment.

@dnephin

Copy link
Copy Markdown

I've run into this as well. I got around it for now by always doing a fig pull --allow-insecure-ssl first but it would be nice to not have to do that.

I think your solution sounds appropriate.

@torbjornvatn

Copy link
Copy Markdown

I've also run into this, and I really would like to call fig pull --allow-insecure-ssl directly. Are you working on a PR @tjrivera or should I try to fix this at work tomorrow?

@tjrivera

Copy link
Copy Markdown

@torbjornvatn I was planning on submitting a PR tomorrow morning

@torbjornvatn

Copy link
Copy Markdown

@tjrivera Nice!

yuval-k pushed a commit to yuval-k/compose that referenced this pull request Apr 10, 2015
Allow pulls from an insecure registry
Signed-off-by: Yuval Kohavi <yuval.kohavi@gmail.com>
yuval-k pushed a commit to yuval-k/compose that referenced this pull request Apr 10, 2015
PR docker#490 Provides the ability to pull from an insecure registry by passing --allow-insecure-ssl. This commit extends the work done in docker#490 and adds the ability to pass --allow-insecure-ssl to the up and run commands which will attempt to pull dependent images if they do not exist.
Signed-off-by: Tyler Rivera <riverat2@email.chop.edu>
Signed-off-by: Yuval Kohavi <yuval.kohavi@gmail.com>
infraAnchor pushed a commit to infraAnchor/compose that referenced this pull request Mar 6, 2026
Signed-off-by: Brian Brazil <brian.brazil@robustperception.io>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants

@jbalonso@thaJeztah@dnephin@bfirsh@moss@tjrivera@torbjornvatn@aanand
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Allow pulls from an insecure registry by jbalonso · Pull Request #490 · docker/compose · GitHub
Skip to content

Allow pulls from an insecure registry - #490

Merged
aanand merged 3 commits into
docker:masterfrom
LuminosoInsight:insecure-pull
Oct 1, 2014
Merged

Allow pulls from an insecure registry#490
aanand merged 3 commits into
docker:masterfrom
LuminosoInsight:insecure-pull

Conversation

@jbalonso

Copy link
Copy Markdown

We maintain a private docker registry without SSL (it isn't necessary). This PR adds an -i option to fig pull that enables insecure mode.

@thaJeztah

Copy link
Copy Markdown
Member

I wonder if this should be a short ( -i) flag, or be more explicit (--insecure)?

@dnephin

Copy link
Copy Markdown

+1, I hit this as well, I'd be fine with either short or long option

@bfirsh

Copy link
Copy Markdown

+1 long flag. And it should be --allow-insecure-ssl: https://github.com/docker/docker/pull/2687/files

@jbalonso

Copy link
Copy Markdown
Author

Ok. A commit with --alow-insecure-ssl is forthcoming. Also, sign-offs, and using insecure_registry as the keyword argument instead of insecure for consistency with docker-py.

@bfirsh

Copy link
Copy Markdown

Great, thanks! Original commit still needs signing off though. You can squash all of this with git rebase -i master and signoff the single commit with git commit --amend --signoff.

@jbalonso

Copy link
Copy Markdown
Author

I took care of the signoff in the squash, and I believe the ball is back in your court.

@bfirsh

Copy link
Copy Markdown

Great stuff, thanks!

@dnephin

Copy link
Copy Markdown

I just realized that this kwarg (insecure_registry) was only added to docker-py in 0.5.0, but right now in setup.py the minimum version is 0.3.2. I think for this change to be safe you need to change the docker-py requirement to:
docker-py >= 0.5, < 0.6

@dnephin

Copy link
Copy Markdown

Not sure why the travis build hasn't run on this branch, but I'm also getting a couple flake8 errors

@bfirsh

Copy link
Copy Markdown

Oops.

We've replaced Travis with Wercker, so this needs rebasing to get CI run on it.

@jbalonso

Copy link
Copy Markdown
Author

I've fixed the docker-py dependency. I'll worry about rebasing (where should I rebase to? I see an "All is well -- build finished" on the PR) and figuring out the flakes tomorrow.

@bfirsh

Copy link
Copy Markdown

We only recently added the file that makes the build work. If you rebase on to the current master, it'll get the wercker.yml file to make the build work. You can run nosetests and flake8 fig locally to verify the things the build runs.

@jbalonso

Copy link
Copy Markdown
Author

I've rebased, but I'm still cleaning up the branch.

Jason Bernardino Alonso added 2 commits September 26, 2014 16:36
Signed-off-by: Jason Bernardino Alonso <jalonso@luminoso.com>
Signed-off-by: Jason Bernardino Alonso <jalonso@luminoso.com>
@jbalonso

Copy link
Copy Markdown
Author

Ok. A third force-push later, I believe I have cleaned up this PR.

@bfirsh

Copy link
Copy Markdown

LGTM

@bfirsh

Copy link
Copy Markdown

Don't think it's easy to test this without mocking out docker-py. :/

@dnephin

Copy link
Copy Markdown

At the very least a simple unit test that asserts the right docker.client function was called wouldn't hurt. ServiceTest already creates a mock_client

@bfirsh

Copy link
Copy Markdown

Oh cool, forgot about that. @jbalonso – would be great to get a test!

@bfirshbfirsh added this to the 1.0.0 milestone Sep 30, 2014
Signed-off-by: Moss Collum <mcollum@luminoso.com>
@moss

moss commented Oct 1, 2014

Copy link
Copy Markdown

I've added the missing unit test to ServiceTest. Please let me know if it needs any cleanup.

@bfirsh

Copy link
Copy Markdown

LGTM

aanand added a commit that referenced this pull request Oct 1, 2014
@aanand
aanand merged commit 431fdaa into docker:masterOct 1, 2014
@jbalonso
jbalonso deleted the insecure-pull branch October 9, 2014 19:49
@tjrivera

Copy link
Copy Markdown

Hey guys, it seems like Fig will also attempt to pull needed images when running fig up -- not just when fig pull is run explicitly. The insecure flag in this case would have to be also passed at Project.up then through here: https://github.com/docker/fig/blob/master/fig/project.py#L175 and ultimately out to here: https://github.com/docker/fig/blob/master/fig/service.py#L182 where pull is being run again. I can work on a PR if this makes sense.

@jbalonso

Copy link
Copy Markdown
Author

I kinda feel responsible for not catching that in my PR. I'll mention that I'm out of bandwidth to work on it myself at the moment.

@dnephin

Copy link
Copy Markdown

I've run into this as well. I got around it for now by always doing a fig pull --allow-insecure-ssl first but it would be nice to not have to do that.

I think your solution sounds appropriate.

@torbjornvatn

Copy link
Copy Markdown

I've also run into this, and I really would like to call fig pull --allow-insecure-ssl directly. Are you working on a PR @tjrivera or should I try to fix this at work tomorrow?

@tjrivera

Copy link
Copy Markdown

@torbjornvatn I was planning on submitting a PR tomorrow morning

@torbjornvatn

Copy link
Copy Markdown

@tjrivera Nice!

yuval-k pushed a commit to yuval-k/compose that referenced this pull request Apr 10, 2015
Allow pulls from an insecure registry
Signed-off-by: Yuval Kohavi <yuval.kohavi@gmail.com>
yuval-k pushed a commit to yuval-k/compose that referenced this pull request Apr 10, 2015
PR docker#490 Provides the ability to pull from an insecure registry by passing --allow-insecure-ssl. This commit extends the work done in docker#490 and adds the ability to pass --allow-insecure-ssl to the up and run commands which will attempt to pull dependent images if they do not exist.
Signed-off-by: Tyler Rivera <riverat2@email.chop.edu>
Signed-off-by: Yuval Kohavi <yuval.kohavi@gmail.com>
infraAnchor pushed a commit to infraAnchor/compose that referenced this pull request Mar 6, 2026
Signed-off-by: Brian Brazil <brian.brazil@robustperception.io>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants

@jbalonso@thaJeztah@dnephin@bfirsh@moss@tjrivera@torbjornvatn@aanand
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Allow pulls from an insecure registry by jbalonso · Pull Request #490 · docker/compose · GitHub
Skip to content

Allow pulls from an insecure registry - #490

Merged
aanand merged 3 commits into
docker:masterfrom
LuminosoInsight:insecure-pull
Oct 1, 2014
Merged

Allow pulls from an insecure registry#490
aanand merged 3 commits into
docker:masterfrom
LuminosoInsight:insecure-pull

Conversation

@jbalonso

Copy link
Copy Markdown

We maintain a private docker registry without SSL (it isn't necessary). This PR adds an -i option to fig pull that enables insecure mode.

@thaJeztah

Copy link
Copy Markdown
Member

I wonder if this should be a short ( -i) flag, or be more explicit (--insecure)?

@dnephin

Copy link
Copy Markdown

+1, I hit this as well, I'd be fine with either short or long option

@bfirsh

Copy link
Copy Markdown

+1 long flag. And it should be --allow-insecure-ssl: https://github.com/docker/docker/pull/2687/files

@jbalonso

Copy link
Copy Markdown
Author

Ok. A commit with --alow-insecure-ssl is forthcoming. Also, sign-offs, and using insecure_registry as the keyword argument instead of insecure for consistency with docker-py.

@bfirsh

Copy link
Copy Markdown

Great, thanks! Original commit still needs signing off though. You can squash all of this with git rebase -i master and signoff the single commit with git commit --amend --signoff.

@jbalonso

Copy link
Copy Markdown
Author

I took care of the signoff in the squash, and I believe the ball is back in your court.

@bfirsh

Copy link
Copy Markdown

Great stuff, thanks!

@dnephin

Copy link
Copy Markdown

I just realized that this kwarg (insecure_registry) was only added to docker-py in 0.5.0, but right now in setup.py the minimum version is 0.3.2. I think for this change to be safe you need to change the docker-py requirement to:
docker-py >= 0.5, < 0.6

@dnephin

Copy link
Copy Markdown

Not sure why the travis build hasn't run on this branch, but I'm also getting a couple flake8 errors

@bfirsh

Copy link
Copy Markdown

Oops.

We've replaced Travis with Wercker, so this needs rebasing to get CI run on it.

@jbalonso

Copy link
Copy Markdown
Author

I've fixed the docker-py dependency. I'll worry about rebasing (where should I rebase to? I see an "All is well -- build finished" on the PR) and figuring out the flakes tomorrow.

@bfirsh

Copy link
Copy Markdown

We only recently added the file that makes the build work. If you rebase on to the current master, it'll get the wercker.yml file to make the build work. You can run nosetests and flake8 fig locally to verify the things the build runs.

@jbalonso

Copy link
Copy Markdown
Author

I've rebased, but I'm still cleaning up the branch.

Jason Bernardino Alonso added 2 commits September 26, 2014 16:36
Signed-off-by: Jason Bernardino Alonso <jalonso@luminoso.com>
Signed-off-by: Jason Bernardino Alonso <jalonso@luminoso.com>
@jbalonso

Copy link
Copy Markdown
Author

Ok. A third force-push later, I believe I have cleaned up this PR.

@bfirsh

Copy link
Copy Markdown

LGTM

@bfirsh

Copy link
Copy Markdown

Don't think it's easy to test this without mocking out docker-py. :/

@dnephin

Copy link
Copy Markdown

At the very least a simple unit test that asserts the right docker.client function was called wouldn't hurt. ServiceTest already creates a mock_client

@bfirsh

Copy link
Copy Markdown

Oh cool, forgot about that. @jbalonso – would be great to get a test!

@bfirshbfirsh added this to the 1.0.0 milestone Sep 30, 2014
Signed-off-by: Moss Collum <mcollum@luminoso.com>
@moss

moss commented Oct 1, 2014

Copy link
Copy Markdown

I've added the missing unit test to ServiceTest. Please let me know if it needs any cleanup.

@bfirsh

Copy link
Copy Markdown

LGTM

aanand added a commit that referenced this pull request Oct 1, 2014
@aanand
aanand merged commit 431fdaa into docker:masterOct 1, 2014
@jbalonso
jbalonso deleted the insecure-pull branch October 9, 2014 19:49
@tjrivera

Copy link
Copy Markdown

Hey guys, it seems like Fig will also attempt to pull needed images when running fig up -- not just when fig pull is run explicitly. The insecure flag in this case would have to be also passed at Project.up then through here: https://github.com/docker/fig/blob/master/fig/project.py#L175 and ultimately out to here: https://github.com/docker/fig/blob/master/fig/service.py#L182 where pull is being run again. I can work on a PR if this makes sense.

@jbalonso

Copy link
Copy Markdown
Author

I kinda feel responsible for not catching that in my PR. I'll mention that I'm out of bandwidth to work on it myself at the moment.

@dnephin

Copy link
Copy Markdown

I've run into this as well. I got around it for now by always doing a fig pull --allow-insecure-ssl first but it would be nice to not have to do that.

I think your solution sounds appropriate.

@torbjornvatn

Copy link
Copy Markdown

I've also run into this, and I really would like to call fig pull --allow-insecure-ssl directly. Are you working on a PR @tjrivera or should I try to fix this at work tomorrow?

@tjrivera

Copy link
Copy Markdown

@torbjornvatn I was planning on submitting a PR tomorrow morning

@torbjornvatn

Copy link
Copy Markdown

@tjrivera Nice!

yuval-k pushed a commit to yuval-k/compose that referenced this pull request Apr 10, 2015
Allow pulls from an insecure registry
Signed-off-by: Yuval Kohavi <yuval.kohavi@gmail.com>
yuval-k pushed a commit to yuval-k/compose that referenced this pull request Apr 10, 2015
PR docker#490 Provides the ability to pull from an insecure registry by passing --allow-insecure-ssl. This commit extends the work done in docker#490 and adds the ability to pass --allow-insecure-ssl to the up and run commands which will attempt to pull dependent images if they do not exist.
Signed-off-by: Tyler Rivera <riverat2@email.chop.edu>
Signed-off-by: Yuval Kohavi <yuval.kohavi@gmail.com>
infraAnchor pushed a commit to infraAnchor/compose that referenced this pull request Mar 6, 2026
Signed-off-by: Brian Brazil <brian.brazil@robustperception.io>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants

@jbalonso@thaJeztah@dnephin@bfirsh@moss@tjrivera@torbjornvatn@aanand
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' Allow pulls from an insecure registry by jbalonso · Pull Request #490 · docker/compose · GitHub
Skip to content

Allow pulls from an insecure registry - #490

Merged
aanand merged 3 commits into
docker:masterfrom
LuminosoInsight:insecure-pull
Oct 1, 2014
Merged

Allow pulls from an insecure registry#490
aanand merged 3 commits into
docker:masterfrom
LuminosoInsight:insecure-pull

Conversation

@jbalonso

Copy link
Copy Markdown

We maintain a private docker registry without SSL (it isn't necessary). This PR adds an -i option to fig pull that enables insecure mode.

@thaJeztah

Copy link
Copy Markdown
Member

I wonder if this should be a short ( -i) flag, or be more explicit (--insecure)?

@dnephin

Copy link
Copy Markdown

+1, I hit this as well, I'd be fine with either short or long option

@bfirsh

Copy link
Copy Markdown

+1 long flag. And it should be --allow-insecure-ssl: https://github.com/docker/docker/pull/2687/files

@jbalonso

Copy link
Copy Markdown
Author

Ok. A commit with --alow-insecure-ssl is forthcoming. Also, sign-offs, and using insecure_registry as the keyword argument instead of insecure for consistency with docker-py.

@bfirsh

Copy link
Copy Markdown

Great, thanks! Original commit still needs signing off though. You can squash all of this with git rebase -i master and signoff the single commit with git commit --amend --signoff.

@jbalonso

Copy link
Copy Markdown
Author

I took care of the signoff in the squash, and I believe the ball is back in your court.

@bfirsh

Copy link
Copy Markdown

Great stuff, thanks!

@dnephin

Copy link
Copy Markdown

I just realized that this kwarg (insecure_registry) was only added to docker-py in 0.5.0, but right now in setup.py the minimum version is 0.3.2. I think for this change to be safe you need to change the docker-py requirement to:
docker-py >= 0.5, < 0.6

@dnephin

Copy link
Copy Markdown

Not sure why the travis build hasn't run on this branch, but I'm also getting a couple flake8 errors

@bfirsh

Copy link
Copy Markdown

Oops.

We've replaced Travis with Wercker, so this needs rebasing to get CI run on it.

@jbalonso

Copy link
Copy Markdown
Author

I've fixed the docker-py dependency. I'll worry about rebasing (where should I rebase to? I see an "All is well -- build finished" on the PR) and figuring out the flakes tomorrow.

@bfirsh

Copy link
Copy Markdown

We only recently added the file that makes the build work. If you rebase on to the current master, it'll get the wercker.yml file to make the build work. You can run nosetests and flake8 fig locally to verify the things the build runs.

@jbalonso

Copy link
Copy Markdown
Author

I've rebased, but I'm still cleaning up the branch.

Jason Bernardino Alonso added 2 commits September 26, 2014 16:36
Signed-off-by: Jason Bernardino Alonso <jalonso@luminoso.com>
Signed-off-by: Jason Bernardino Alonso <jalonso@luminoso.com>
@jbalonso

Copy link
Copy Markdown
Author

Ok. A third force-push later, I believe I have cleaned up this PR.

@bfirsh

Copy link
Copy Markdown

LGTM

@bfirsh

Copy link
Copy Markdown

Don't think it's easy to test this without mocking out docker-py. :/

@dnephin

Copy link
Copy Markdown

At the very least a simple unit test that asserts the right docker.client function was called wouldn't hurt. ServiceTest already creates a mock_client

@bfirsh

Copy link
Copy Markdown

Oh cool, forgot about that. @jbalonso – would be great to get a test!

@bfirshbfirsh added this to the 1.0.0 milestone Sep 30, 2014
Signed-off-by: Moss Collum <mcollum@luminoso.com>
@moss

moss commented Oct 1, 2014

Copy link
Copy Markdown

I've added the missing unit test to ServiceTest. Please let me know if it needs any cleanup.

@bfirsh

Copy link
Copy Markdown

LGTM

aanand added a commit that referenced this pull request Oct 1, 2014
@aanand
aanand merged commit 431fdaa into docker:masterOct 1, 2014
@jbalonso
jbalonso deleted the insecure-pull branch October 9, 2014 19:49
@tjrivera

Copy link
Copy Markdown

Hey guys, it seems like Fig will also attempt to pull needed images when running fig up -- not just when fig pull is run explicitly. The insecure flag in this case would have to be also passed at Project.up then through here: https://github.com/docker/fig/blob/master/fig/project.py#L175 and ultimately out to here: https://github.com/docker/fig/blob/master/fig/service.py#L182 where pull is being run again. I can work on a PR if this makes sense.

@jbalonso

Copy link
Copy Markdown
Author

I kinda feel responsible for not catching that in my PR. I'll mention that I'm out of bandwidth to work on it myself at the moment.

@dnephin

Copy link
Copy Markdown

I've run into this as well. I got around it for now by always doing a fig pull --allow-insecure-ssl first but it would be nice to not have to do that.

I think your solution sounds appropriate.

@torbjornvatn

Copy link
Copy Markdown

I've also run into this, and I really would like to call fig pull --allow-insecure-ssl directly. Are you working on a PR @tjrivera or should I try to fix this at work tomorrow?

@tjrivera

Copy link
Copy Markdown

@torbjornvatn I was planning on submitting a PR tomorrow morning

@torbjornvatn

Copy link
Copy Markdown

@tjrivera Nice!

yuval-k pushed a commit to yuval-k/compose that referenced this pull request Apr 10, 2015
Allow pulls from an insecure registry
Signed-off-by: Yuval Kohavi <yuval.kohavi@gmail.com>
yuval-k pushed a commit to yuval-k/compose that referenced this pull request Apr 10, 2015
PR docker#490 Provides the ability to pull from an insecure registry by passing --allow-insecure-ssl. This commit extends the work done in docker#490 and adds the ability to pass --allow-insecure-ssl to the up and run commands which will attempt to pull dependent images if they do not exist.
Signed-off-by: Tyler Rivera <riverat2@email.chop.edu>
Signed-off-by: Yuval Kohavi <yuval.kohavi@gmail.com>
infraAnchor pushed a commit to infraAnchor/compose that referenced this pull request Mar 6, 2026
Signed-off-by: Brian Brazil <brian.brazil@robustperception.io>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants

@jbalonso@thaJeztah@dnephin@bfirsh@moss@tjrivera@torbjornvatn@aanand
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Allow pulls from an insecure registry by jbalonso · Pull Request #490 · docker/compose · GitHub
Skip to content

Allow pulls from an insecure registry - #490

Merged
aanand merged 3 commits into
docker:masterfrom
LuminosoInsight:insecure-pull
Oct 1, 2014
Merged

Allow pulls from an insecure registry#490
aanand merged 3 commits into
docker:masterfrom
LuminosoInsight:insecure-pull

Conversation

@jbalonso

Copy link
Copy Markdown

We maintain a private docker registry without SSL (it isn't necessary). This PR adds an -i option to fig pull that enables insecure mode.

@thaJeztah

Copy link
Copy Markdown
Member

I wonder if this should be a short ( -i) flag, or be more explicit (--insecure)?

@dnephin

Copy link
Copy Markdown

+1, I hit this as well, I'd be fine with either short or long option

@bfirsh

Copy link
Copy Markdown

+1 long flag. And it should be --allow-insecure-ssl: https://github.com/docker/docker/pull/2687/files

@jbalonso

Copy link
Copy Markdown
Author

Ok. A commit with --alow-insecure-ssl is forthcoming. Also, sign-offs, and using insecure_registry as the keyword argument instead of insecure for consistency with docker-py.

@bfirsh

Copy link
Copy Markdown

Great, thanks! Original commit still needs signing off though. You can squash all of this with git rebase -i master and signoff the single commit with git commit --amend --signoff.

@jbalonso

Copy link
Copy Markdown
Author

I took care of the signoff in the squash, and I believe the ball is back in your court.

@bfirsh

Copy link
Copy Markdown

Great stuff, thanks!

@dnephin

Copy link
Copy Markdown

I just realized that this kwarg (insecure_registry) was only added to docker-py in 0.5.0, but right now in setup.py the minimum version is 0.3.2. I think for this change to be safe you need to change the docker-py requirement to:
docker-py >= 0.5, < 0.6

@dnephin

Copy link
Copy Markdown

Not sure why the travis build hasn't run on this branch, but I'm also getting a couple flake8 errors

@bfirsh

Copy link
Copy Markdown

Oops.

We've replaced Travis with Wercker, so this needs rebasing to get CI run on it.

@jbalonso

Copy link
Copy Markdown
Author

I've fixed the docker-py dependency. I'll worry about rebasing (where should I rebase to? I see an "All is well -- build finished" on the PR) and figuring out the flakes tomorrow.

@bfirsh

Copy link
Copy Markdown

We only recently added the file that makes the build work. If you rebase on to the current master, it'll get the wercker.yml file to make the build work. You can run nosetests and flake8 fig locally to verify the things the build runs.

@jbalonso

Copy link
Copy Markdown
Author

I've rebased, but I'm still cleaning up the branch.

Jason Bernardino Alonso added 2 commits September 26, 2014 16:36
Signed-off-by: Jason Bernardino Alonso <jalonso@luminoso.com>
Signed-off-by: Jason Bernardino Alonso <jalonso@luminoso.com>
@jbalonso

Copy link
Copy Markdown
Author

Ok. A third force-push later, I believe I have cleaned up this PR.

@bfirsh

Copy link
Copy Markdown

LGTM

@bfirsh

Copy link
Copy Markdown

Don't think it's easy to test this without mocking out docker-py. :/

@dnephin

Copy link
Copy Markdown

At the very least a simple unit test that asserts the right docker.client function was called wouldn't hurt. ServiceTest already creates a mock_client

@bfirsh

Copy link
Copy Markdown

Oh cool, forgot about that. @jbalonso – would be great to get a test!

@bfirshbfirsh added this to the 1.0.0 milestone Sep 30, 2014
Signed-off-by: Moss Collum <mcollum@luminoso.com>
@moss

moss commented Oct 1, 2014

Copy link
Copy Markdown

I've added the missing unit test to ServiceTest. Please let me know if it needs any cleanup.

@bfirsh

Copy link
Copy Markdown

LGTM

aanand added a commit that referenced this pull request Oct 1, 2014
@aanand
aanand merged commit 431fdaa into docker:masterOct 1, 2014
@jbalonso
jbalonso deleted the insecure-pull branch October 9, 2014 19:49
@tjrivera

Copy link
Copy Markdown

Hey guys, it seems like Fig will also attempt to pull needed images when running fig up -- not just when fig pull is run explicitly. The insecure flag in this case would have to be also passed at Project.up then through here: https://github.com/docker/fig/blob/master/fig/project.py#L175 and ultimately out to here: https://github.com/docker/fig/blob/master/fig/service.py#L182 where pull is being run again. I can work on a PR if this makes sense.

@jbalonso

Copy link
Copy Markdown
Author

I kinda feel responsible for not catching that in my PR. I'll mention that I'm out of bandwidth to work on it myself at the moment.

@dnephin

Copy link
Copy Markdown

I've run into this as well. I got around it for now by always doing a fig pull --allow-insecure-ssl first but it would be nice to not have to do that.

I think your solution sounds appropriate.

@torbjornvatn

Copy link
Copy Markdown

I've also run into this, and I really would like to call fig pull --allow-insecure-ssl directly. Are you working on a PR @tjrivera or should I try to fix this at work tomorrow?

@tjrivera

Copy link
Copy Markdown

@torbjornvatn I was planning on submitting a PR tomorrow morning

@torbjornvatn

Copy link
Copy Markdown

@tjrivera Nice!

yuval-k pushed a commit to yuval-k/compose that referenced this pull request Apr 10, 2015
Allow pulls from an insecure registry
Signed-off-by: Yuval Kohavi <yuval.kohavi@gmail.com>
yuval-k pushed a commit to yuval-k/compose that referenced this pull request Apr 10, 2015
PR docker#490 Provides the ability to pull from an insecure registry by passing --allow-insecure-ssl. This commit extends the work done in docker#490 and adds the ability to pass --allow-insecure-ssl to the up and run commands which will attempt to pull dependent images if they do not exist.
Signed-off-by: Tyler Rivera <riverat2@email.chop.edu>
Signed-off-by: Yuval Kohavi <yuval.kohavi@gmail.com>
infraAnchor pushed a commit to infraAnchor/compose that referenced this pull request Mar 6, 2026
Signed-off-by: Brian Brazil <brian.brazil@robustperception.io>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants

@jbalonso@thaJeztah@dnephin@bfirsh@moss@tjrivera@torbjornvatn@aanand
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Allow pulls from an insecure registry by jbalonso · Pull Request #490 · docker/compose · GitHub
Skip to content

Allow pulls from an insecure registry - #490

Merged
aanand merged 3 commits into
docker:masterfrom
LuminosoInsight:insecure-pull
Oct 1, 2014
Merged

Allow pulls from an insecure registry#490
aanand merged 3 commits into
docker:masterfrom
LuminosoInsight:insecure-pull

Conversation

@jbalonso

Copy link
Copy Markdown

We maintain a private docker registry without SSL (it isn't necessary). This PR adds an -i option to fig pull that enables insecure mode.

@thaJeztah

Copy link
Copy Markdown
Member

I wonder if this should be a short ( -i) flag, or be more explicit (--insecure)?

@dnephin

Copy link
Copy Markdown

+1, I hit this as well, I'd be fine with either short or long option

@bfirsh

Copy link
Copy Markdown

+1 long flag. And it should be --allow-insecure-ssl: https://github.com/docker/docker/pull/2687/files

@jbalonso

Copy link
Copy Markdown
Author

Ok. A commit with --alow-insecure-ssl is forthcoming. Also, sign-offs, and using insecure_registry as the keyword argument instead of insecure for consistency with docker-py.

@bfirsh

Copy link
Copy Markdown

Great, thanks! Original commit still needs signing off though. You can squash all of this with git rebase -i master and signoff the single commit with git commit --amend --signoff.

@jbalonso

Copy link
Copy Markdown
Author

I took care of the signoff in the squash, and I believe the ball is back in your court.

@bfirsh

Copy link
Copy Markdown

Great stuff, thanks!

@dnephin

Copy link
Copy Markdown

I just realized that this kwarg (insecure_registry) was only added to docker-py in 0.5.0, but right now in setup.py the minimum version is 0.3.2. I think for this change to be safe you need to change the docker-py requirement to:
docker-py >= 0.5, < 0.6

@dnephin

Copy link
Copy Markdown

Not sure why the travis build hasn't run on this branch, but I'm also getting a couple flake8 errors

@bfirsh

Copy link
Copy Markdown

Oops.

We've replaced Travis with Wercker, so this needs rebasing to get CI run on it.

@jbalonso

Copy link
Copy Markdown
Author

I've fixed the docker-py dependency. I'll worry about rebasing (where should I rebase to? I see an "All is well -- build finished" on the PR) and figuring out the flakes tomorrow.

@bfirsh

Copy link
Copy Markdown

We only recently added the file that makes the build work. If you rebase on to the current master, it'll get the wercker.yml file to make the build work. You can run nosetests and flake8 fig locally to verify the things the build runs.

@jbalonso

Copy link
Copy Markdown
Author

I've rebased, but I'm still cleaning up the branch.

Jason Bernardino Alonso added 2 commits September 26, 2014 16:36
Signed-off-by: Jason Bernardino Alonso <jalonso@luminoso.com>
Signed-off-by: Jason Bernardino Alonso <jalonso@luminoso.com>
@jbalonso

Copy link
Copy Markdown
Author

Ok. A third force-push later, I believe I have cleaned up this PR.

@bfirsh

Copy link
Copy Markdown

LGTM

@bfirsh

Copy link
Copy Markdown

Don't think it's easy to test this without mocking out docker-py. :/

@dnephin

Copy link
Copy Markdown

At the very least a simple unit test that asserts the right docker.client function was called wouldn't hurt. ServiceTest already creates a mock_client

@bfirsh

Copy link
Copy Markdown

Oh cool, forgot about that. @jbalonso – would be great to get a test!

@bfirshbfirsh added this to the 1.0.0 milestone Sep 30, 2014
Signed-off-by: Moss Collum <mcollum@luminoso.com>
@moss

moss commented Oct 1, 2014

Copy link
Copy Markdown

I've added the missing unit test to ServiceTest. Please let me know if it needs any cleanup.

@bfirsh

Copy link
Copy Markdown

LGTM

aanand added a commit that referenced this pull request Oct 1, 2014
@aanand
aanand merged commit 431fdaa into docker:masterOct 1, 2014
@jbalonso
jbalonso deleted the insecure-pull branch October 9, 2014 19:49
@tjrivera

Copy link
Copy Markdown

Hey guys, it seems like Fig will also attempt to pull needed images when running fig up -- not just when fig pull is run explicitly. The insecure flag in this case would have to be also passed at Project.up then through here: https://github.com/docker/fig/blob/master/fig/project.py#L175 and ultimately out to here: https://github.com/docker/fig/blob/master/fig/service.py#L182 where pull is being run again. I can work on a PR if this makes sense.

@jbalonso

Copy link
Copy Markdown
Author

I kinda feel responsible for not catching that in my PR. I'll mention that I'm out of bandwidth to work on it myself at the moment.

@dnephin

Copy link
Copy Markdown

I've run into this as well. I got around it for now by always doing a fig pull --allow-insecure-ssl first but it would be nice to not have to do that.

I think your solution sounds appropriate.

@torbjornvatn

Copy link
Copy Markdown

I've also run into this, and I really would like to call fig pull --allow-insecure-ssl directly. Are you working on a PR @tjrivera or should I try to fix this at work tomorrow?

@tjrivera

Copy link
Copy Markdown

@torbjornvatn I was planning on submitting a PR tomorrow morning

@torbjornvatn

Copy link
Copy Markdown

@tjrivera Nice!

yuval-k pushed a commit to yuval-k/compose that referenced this pull request Apr 10, 2015
Allow pulls from an insecure registry
Signed-off-by: Yuval Kohavi <yuval.kohavi@gmail.com>
yuval-k pushed a commit to yuval-k/compose that referenced this pull request Apr 10, 2015
PR docker#490 Provides the ability to pull from an insecure registry by passing --allow-insecure-ssl. This commit extends the work done in docker#490 and adds the ability to pass --allow-insecure-ssl to the up and run commands which will attempt to pull dependent images if they do not exist.
Signed-off-by: Tyler Rivera <riverat2@email.chop.edu>
Signed-off-by: Yuval Kohavi <yuval.kohavi@gmail.com>
infraAnchor pushed a commit to infraAnchor/compose that referenced this pull request Mar 6, 2026
Signed-off-by: Brian Brazil <brian.brazil@robustperception.io>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants

@jbalonso@thaJeztah@dnephin@bfirsh@moss@tjrivera@torbjornvatn@aanand
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); Allow pulls from an insecure registry by jbalonso · Pull Request #490 · docker/compose · GitHub
Skip to content

Allow pulls from an insecure registry - #490

Merged
aanand merged 3 commits into
docker:masterfrom
LuminosoInsight:insecure-pull
Oct 1, 2014
Merged

Allow pulls from an insecure registry#490
aanand merged 3 commits into
docker:masterfrom
LuminosoInsight:insecure-pull

Conversation

@jbalonso

Copy link
Copy Markdown

We maintain a private docker registry without SSL (it isn't necessary). This PR adds an -i option to fig pull that enables insecure mode.

@thaJeztah

Copy link
Copy Markdown
Member

I wonder if this should be a short ( -i) flag, or be more explicit (--insecure)?

@dnephin

Copy link
Copy Markdown

+1, I hit this as well, I'd be fine with either short or long option

@bfirsh

Copy link
Copy Markdown

+1 long flag. And it should be --allow-insecure-ssl: https://github.com/docker/docker/pull/2687/files

@jbalonso

Copy link
Copy Markdown
Author

Ok. A commit with --alow-insecure-ssl is forthcoming. Also, sign-offs, and using insecure_registry as the keyword argument instead of insecure for consistency with docker-py.

@bfirsh

Copy link
Copy Markdown

Great, thanks! Original commit still needs signing off though. You can squash all of this with git rebase -i master and signoff the single commit with git commit --amend --signoff.

@jbalonso

Copy link
Copy Markdown
Author

I took care of the signoff in the squash, and I believe the ball is back in your court.

@bfirsh

Copy link
Copy Markdown

Great stuff, thanks!

@dnephin

Copy link
Copy Markdown

I just realized that this kwarg (insecure_registry) was only added to docker-py in 0.5.0, but right now in setup.py the minimum version is 0.3.2. I think for this change to be safe you need to change the docker-py requirement to:
docker-py >= 0.5, < 0.6

@dnephin

Copy link
Copy Markdown

Not sure why the travis build hasn't run on this branch, but I'm also getting a couple flake8 errors

@bfirsh

Copy link
Copy Markdown

Oops.

We've replaced Travis with Wercker, so this needs rebasing to get CI run on it.

@jbalonso

Copy link
Copy Markdown
Author

I've fixed the docker-py dependency. I'll worry about rebasing (where should I rebase to? I see an "All is well -- build finished" on the PR) and figuring out the flakes tomorrow.

@bfirsh

Copy link
Copy Markdown

We only recently added the file that makes the build work. If you rebase on to the current master, it'll get the wercker.yml file to make the build work. You can run nosetests and flake8 fig locally to verify the things the build runs.

@jbalonso

Copy link
Copy Markdown
Author

I've rebased, but I'm still cleaning up the branch.

Jason Bernardino Alonso added 2 commits September 26, 2014 16:36
Signed-off-by: Jason Bernardino Alonso <jalonso@luminoso.com>
Signed-off-by: Jason Bernardino Alonso <jalonso@luminoso.com>
@jbalonso

Copy link
Copy Markdown
Author

Ok. A third force-push later, I believe I have cleaned up this PR.

@bfirsh

Copy link
Copy Markdown

LGTM

@bfirsh

Copy link
Copy Markdown

Don't think it's easy to test this without mocking out docker-py. :/

@dnephin

Copy link
Copy Markdown

At the very least a simple unit test that asserts the right docker.client function was called wouldn't hurt. ServiceTest already creates a mock_client

@bfirsh

Copy link
Copy Markdown

Oh cool, forgot about that. @jbalonso – would be great to get a test!

@bfirshbfirsh added this to the 1.0.0 milestone Sep 30, 2014
Signed-off-by: Moss Collum <mcollum@luminoso.com>
@moss

moss commented Oct 1, 2014

Copy link
Copy Markdown

I've added the missing unit test to ServiceTest. Please let me know if it needs any cleanup.

@bfirsh

Copy link
Copy Markdown

LGTM

aanand added a commit that referenced this pull request Oct 1, 2014
@aanand
aanand merged commit 431fdaa into docker:masterOct 1, 2014
@jbalonso
jbalonso deleted the insecure-pull branch October 9, 2014 19:49
@tjrivera

Copy link
Copy Markdown

Hey guys, it seems like Fig will also attempt to pull needed images when running fig up -- not just when fig pull is run explicitly. The insecure flag in this case would have to be also passed at Project.up then through here: https://github.com/docker/fig/blob/master/fig/project.py#L175 and ultimately out to here: https://github.com/docker/fig/blob/master/fig/service.py#L182 where pull is being run again. I can work on a PR if this makes sense.

@jbalonso

Copy link
Copy Markdown
Author

I kinda feel responsible for not catching that in my PR. I'll mention that I'm out of bandwidth to work on it myself at the moment.

@dnephin

Copy link
Copy Markdown

I've run into this as well. I got around it for now by always doing a fig pull --allow-insecure-ssl first but it would be nice to not have to do that.

I think your solution sounds appropriate.

@torbjornvatn

Copy link
Copy Markdown

I've also run into this, and I really would like to call fig pull --allow-insecure-ssl directly. Are you working on a PR @tjrivera or should I try to fix this at work tomorrow?

@tjrivera

Copy link
Copy Markdown

@torbjornvatn I was planning on submitting a PR tomorrow morning

@torbjornvatn

Copy link
Copy Markdown

@tjrivera Nice!

yuval-k pushed a commit to yuval-k/compose that referenced this pull request Apr 10, 2015
Allow pulls from an insecure registry
Signed-off-by: Yuval Kohavi <yuval.kohavi@gmail.com>
yuval-k pushed a commit to yuval-k/compose that referenced this pull request Apr 10, 2015
PR docker#490 Provides the ability to pull from an insecure registry by passing --allow-insecure-ssl. This commit extends the work done in docker#490 and adds the ability to pass --allow-insecure-ssl to the up and run commands which will attempt to pull dependent images if they do not exist.
Signed-off-by: Tyler Rivera <riverat2@email.chop.edu>
Signed-off-by: Yuval Kohavi <yuval.kohavi@gmail.com>
infraAnchor pushed a commit to infraAnchor/compose that referenced this pull request Mar 6, 2026
Signed-off-by: Brian Brazil <brian.brazil@robustperception.io>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants

@jbalonso@thaJeztah@dnephin@bfirsh@moss@tjrivera@torbjornvatn@aanand