ЁЯПл The SchoolтА║ЁЯН▒ DockerтА║ЁЯПм рдзрдбрд╛ 09 тАФ Registries: рдЧреЛрдард▓реЗрд▓реНрдпрд╛ рдбрдмреНрдпрд╛рдВрдЪреЗ рдЧреЛрджрд╛рдо
ЁЯЦ╝я╕П See the drawing + lab ЁЯПа Course home ЁЯМ┐ Branch on GitHub тЬПя╕П View source
ЁЯЦ╝я╕П рдЖрдХреГрддреА рдЖрдгрд┐ labThe drawing + lab рдкреВрд░реНрдг рдкрд╛рдирд╛рд╡рд░ рдЙрдШрдбрд╛ тЖЧOpen full page тЖЧ

ЁЯПм рдзрдбрд╛ 09 тАФ Registries: рдЧреЛрдард▓реЗрд▓реНрдпрд╛ рдбрдмреНрдпрд╛рдВрдЪреЗ рдЧреЛрджрд╛рдо

ЁЯУН рддреБрдореНрд╣реА рдЗрдереЗ рдЖрд╣рд╛рдд: 12 рдкреИрдХреА рдзрдбрд╛ 09 тАФ рднрд╛рдЧ 2 рд╕реБрд░реВ! ┬╖ рдорд╛рдЧреЗ: lesson-08-image-hygiene ┬╖ рдкреБрдвреЗ: lesson-10-ecr-setup


ЁЯУж рдпрд╛ рдмреНрд░рдБрдЪрдордзреНрдпреЗ рдХрд╛рдп рдЖрд╣реЗ

рдзрдбреЗ 01тАУ08, рдЖрдгрд┐ рддреНрдпрд╛рд╢рд┐рд╡рд╛рдп: laptop рдкрд╛рд╕реВрди cloud рдкрд░реНрдпрдВрддрдЪрд╛ рдкреВрд▓ тАФ registry рдореНрд╣рдгрдЬреЗ рдХрд╛рдп, рдЖрдгрд┐ рднрд╛рдЧ 2 рдЬреНрдпрд╛рд╡рд░ рдЪрд╛рд▓рддреЛ рддреЛ pull/push/tag/digest рдЪрд╛ рд╢рдмреНрджрд╕рдВрдЧреНрд░рд╣.

ЁЯзТ 5 рд╡рд░реНрд╖рд╛рдВрдЪреНрдпрд╛ рдореБрд▓рд╛рд▓рд╛ рд╕рдордЬрд╛рд╡рд▓реНрдпрд╛рд╕рд╛рд░рдЦреЗ

рддреБрдордЪрд╛ рдбрдмрд╛ рдЕрдЧрджреА рдкрд░рд┐рдкреВрд░реНрдг рдЖрд╣реЗ тАФ рдкрдг рддреЛ рддреБрдордЪреНрдпрд╛ fridge рдордзреНрдпреЗ рдЖрд╣реЗ. рд╢рд╛рд│реЗрдЪреЗ рдХреЕрдиреНрдЯреАрди (рдПрдХ server), рддреБрдордЪреА рд╕рд╣рдХрд╛рд░реА, рднреБрдХреЗрд▓реНрдпрд╛ рдорд╢реАрдирдЪрд╛ рд╕рдВрдкреВрд░реНрдг clusterтАж рдпрд╛рдкреИрдХреА рдХреЛрдгреАрд╣реА рддреБрдордЪреНрдпрд╛ fridge рдкрд░реНрдпрдВрдд рдкреЛрд╣реЛрдЪреВ рд╢рдХрдд рдирд╛рд╣реА. ЁЯзКЁЯЪл

рдЖрддрд╛ рдпреЗрддреЗ рдЧреЛрдард▓реЗрд▓реНрдпрд╛ рдбрдмреНрдпрд╛рдВрдЪреЗ рдЧреЛрджрд╛рдо ЁЯПм (рдПрдХ registry):

рддреБрдореНрд╣реА рдЖрддрд╛рдкрд░реНрдпрдВрдд рдЧреЛрджрд╛рдордЪ рд╡рд╛рдкрд░рдд рд╣реЛрддрд╛! FROM node:20-alpine рд╣реЗ Docker Hub рд╡рд░реВрди pull рдХрд░рддреЗ тАФ рдкреНрд░рдЪрдВрдб рдореЛрдареЗ рд╕рд╛рд░реНрд╡рдЬрдирд┐рдХ рдЧреЛрджрд╛рдо. рднрд╛рдЧ 2 рддреБрдордЪреЗ рд╕реНрд╡рддрдГрдЪреЗ рдЦрд╛рдЬрдЧреА рдЧреЛрджрд╛рдо (ECR) рдорд┐рд│рд╡рдгреНрдпрд╛рдмрджреНрджрд▓ рдЖрд╣реЗ, рдХрд╛рд░рдг рддреБрдордЪреНрдпрд╛ рдХрдВрдкрдиреАрдЪреЗ рдЬреЗрд╡рдг рдЕрдиреЛрд│рдЦреА рд▓реЛрдХрд╛рдВрд╕рд╛рдареА рдирд╛рд╣реА. ЁЯФР

ЁЯЧ║я╕П рдЖрдХреГрддреА

flowchart LR
    lap["ЁЯзСтАНЁЯТ╗ your laptop<br/>image built locally"]
    subgraph reg["ЁЯПм registry - the warehouse"]
        shelf["ЁЯУЪ repository: hello-school<br/>one shelf, all versions"]
        tags["ЁЯП╖я╕П tags: v1, v2, abc123<br/>ЁЯФв digests: sha256:тАж fingerprints"]
        shelf --- tags
    end
    eks["тШ╕я╕П cluster<br/>pulls at deploy"]
    mate["ЁЯТ╗ teammate<br/>docker pull"]
    lap -->|"1 docker push - once"| reg
    reg -->|"2 pull - anywhere, many times"| eks
    reg --> mate

тЭУ рдХрд╛рдп

ЁЯза рдЙрддрд░рдВрдб тАФ registry тЙа repository

Registry        (the warehouse тАФ one host)
   тЖУ
Repository      (one shelf тАФ one application)
   тЖУ
Image           (one box тАФ one build)
   тЖУ
Tag / Digest    (the sticker / the fingerprint)
123456789012.dkr.ecr.ap-south-1.amazonaws.com/    тЖР registry
    my-app                                         тЖР repository
       тФЬтФАтФА v1.0.0                                  тЖР tags
       тФЬтФАтФА v1.1.0
       тФФтФАтФА latest    (a sticker тАФ it moves)

Registry рд╣реА service рдЖрд╣реЗ; repository рдореНрд╣рдгрдЬреЗ рддрд┐рдЪреНрдпрд╛ рдЖрддрд▓рд╛ рдПрдХрд╛ ре▓рдкрдЪрд╛ рдХрдкреНрдкрд╛. ECR рдордзреНрдпреЗ "repository рдмрдирд╡рд╛" рдореНрд╣рдгрдЬреЗ рддреБрдордЪреНрдпрд╛рдХрдбреЗ рдЖрдзреАрдЪ рдЕрд╕рд▓реЗрд▓реНрдпрд╛ рдЧреЛрджрд╛рдорд╛рдд рдПрдХ рдХрдкреНрдкрд╛ рдЬреЛрдбрдгреЗ.

ЁЯдФ рдХрд╛

Registry рд╣рд╛ рд╕рдВрдкреВрд░реНрдг trilogy рдЪрд╛ рд╣рд╕реНрддрд╛рдВрддрд░рдгрд╛рдЪрд╛ рдмрд┐рдВрджреВ рдЖрд╣реЗ: рд╣рд╛ рдХреЛрд░реНрд╕ рддреНрдпрд╛рд╡рд░ push рдХрд░рддреЛ, k8s рдХреЛрд░реНрд╕рдЪреЗ Deployments рддреНрдпрд╛рд╡рд░реВрди pull рдХрд░рддрд╛рдд, ArgoCD рдХреЛрд░реНрд╕ рддреНрдпрд╛рдЪреЗ рдкрддреНрддреЗ git рдордзреНрдпреЗ commit рдХрд░рддреЛ. рддреА рдиреИрд╕рд░реНрдЧрд┐рдХ security рд╕реАрдорд╛ рд╣реА рдЖрд╣реЗ (рдХреЛрдг push рдХрд░реВ рд╢рдХрддреЗ? рдХреЛрдг pull рдХрд░реВ рд╢рдХрддреЗ?) рдЖрдгрд┐ рдЕрд╕рд╛ cache рд╣реА, рдЬреНрдпрд╛рдореБрд│реЗ 50 рдорд╢реАрдирдЪрд╛ cluster рддреБрдордЪреНрдпрд╛ laptop рд╡рд░реВрди download рдХрд░рдд рдирд╛рд╣реА.

ЁЯзк рдХрд░реВрди рдкрд╛рд╣рд╛

# you already speak registry тАФ see today's pulls:
docker pull node:20-alpine                 # from Docker Hub, layer by layer
docker pull node:20-alpine                 # again: "Already exists" тАФ layer cache!

# read image ADDRESSES like a pro:
docker image inspect node:20-alpine --format '{{index .RepoDigests 0}}'
# тЖТ docker.io/library/node@sha256:тАж  тЖР warehouse/shelf@fingerprint

# a real private-warehouse dry run тАФ run a registry IN a container (how meta):
docker run -d -p 5000:5000 --name warehouse registry:2
docker tag hello-school:v1 localhost:5000/hello-school:v1     # readdress the box
docker push localhost:5000/hello-school:v1                    # deliver
docker rmi localhost:5000/hello-school:v1
docker pull localhost:5000/hello-school:v1                    # collect тАФ full circle ЁЯОЙ
docker rm -f warehouse

тЪая╕П рдиреЗрд╣рдореАрдЪреНрдпрд╛ рдЪреБрдХрд╛

тПня╕П рдкреБрдвреЗ

рдЖрддрд╛ рдЦрд░реА рдЧреЛрд╖реНрдЯ: AWS рдмрдБрдХреЗрддрд▓рд╛ рддреБрдордЪрд╛ рд╕реНрд╡рддрдГрдЪрд╛ locker тАФ ECR repository рдмрдирд╡рдгреЗ рдЖрдгрд┐ рддреНрдпрд╛рдЪреНрдпрд╛ рдкреБрдврдЪреНрдпрд╛ рджрд╛рд░рд╛рддреВрди рдЖрдд рдЬрд╛рдгреЗ.

git checkout lesson-10-ecr-setup

ЁЯПм Lesson 09 тАФ Registries: the frozen-lunchbox warehouse

ЁЯУН You are here: Lesson 09 of 12 тАФ Part 2 begins! ┬╖ Previous: lesson-08-image-hygiene ┬╖ Next: lesson-10-ecr-setup


ЁЯУж What's in this branch

Lessons 01тАУ08, plus: the bridge from laptop to cloud тАФ what a registry is, and the pull/push/tag/digest vocabulary Part 2 lives on.

ЁЯзТ Explain like I'm 5

Your lunchbox is perfect тАФ but it's in YOUR fridge. The school cafeteria (a server), your teammate, a whole cluster of hungry machinesтАж none of them can reach your fridge. ЁЯзКЁЯЪл

Enter the frozen-lunchbox warehouse ЁЯПм (a registry):

You've been using a warehouse all along! FROM node:20-alpine pulls from Docker Hub тАФ the giant public warehouse. Part 2 is about getting your own private one (ECR), because your company's lunches aren't for strangers. ЁЯФР

ЁЯЧ║я╕П Diagram

flowchart LR
    lap["ЁЯзСтАНЁЯТ╗ your laptop<br/>image built locally"]
    subgraph reg["ЁЯПм registry - the warehouse"]
        shelf["ЁЯУЪ repository: hello-school<br/>one shelf, all versions"]
        tags["ЁЯП╖я╕П tags: v1, v2, abc123<br/>ЁЯФв digests: sha256:тАж fingerprints"]
        shelf --- tags
    end
    eks["тШ╕я╕П cluster<br/>pulls at deploy"]
    mate["ЁЯТ╗ teammate<br/>docker pull"]
    lap -->|"1 docker push - once"| reg
    reg -->|"2 pull - anywhere, many times"| eks
    reg --> mate

тЭУ What

ЁЯза The hierarchy тАФ registry тЙа repository

Registry        (the warehouse тАФ one host)
   тЖУ
Repository      (one shelf тАФ one application)
   тЖУ
Image           (one box тАФ one build)
   тЖУ
Tag / Digest    (the sticker / the fingerprint)
123456789012.dkr.ecr.ap-south-1.amazonaws.com/    тЖР registry
    my-app                                         тЖР repository
       тФЬтФАтФА v1.0.0                                  тЖР tags
       тФЬтФАтФА v1.1.0
       тФФтФАтФА latest    (a sticker тАФ it moves)

A registry is the service; a repository is one app's shelf inside it. "Create a repository" in ECR means adding a shelf to the warehouse you already have.

ЁЯдФ Why

The registry is the handoff point of the entire trilogy: this course pushes to it, the k8s course's Deployments pull from it, the ArgoCD course commits its addresses into git. It's also the natural security boundary (who may push? who may pull?) and the cache that makes a 50-machine cluster not download from your laptop.

ЁЯзк Try it

# you already speak registry тАФ see today's pulls:
docker pull node:20-alpine                 # from Docker Hub, layer by layer
docker pull node:20-alpine                 # again: "Already exists" тАФ layer cache!

# read image ADDRESSES like a pro:
docker image inspect node:20-alpine --format '{{index .RepoDigests 0}}'
# тЖТ docker.io/library/node@sha256:тАж  тЖР warehouse/shelf@fingerprint

# a real private-warehouse dry run тАФ run a registry IN a container (how meta):
docker run -d -p 5000:5000 --name warehouse registry:2
docker tag hello-school:v1 localhost:5000/hello-school:v1     # readdress the box
docker push localhost:5000/hello-school:v1                    # deliver
docker rmi localhost:5000/hello-school:v1
docker pull localhost:5000/hello-school:v1                    # collect тАФ full circle ЁЯОЙ
docker rm -f warehouse

тЪая╕П Common mistakes

тПня╕П Next

Now the real thing: your own locker at the AWS bank тАФ creating an ECR repository and getting through its front door.

git checkout lesson-10-ecr-setup
тЖР Previousimage hygieneNext тЖТecr setup

This page is the lesson's README from the lesson-09-registries branch, shown here so the whole School stays on one site. Code files open on GitHub at the same branch.