feat: containerd add default cert config path (#2821)

feat: containerd add default cert config path

Signed-off-by: xuesongzuo@yunify.com <xuesongzuo@yunify.com>
This commit is contained in:
zuoxuesong-worker 2025-10-23 15:06:27 +08:00 committed by GitHub
parent 63043005d2
commit 75d8ea38bd
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

View File

@ -47,6 +47,7 @@ state = "/run/containerd"
max_conf_num = 1
conf_template = ""
[plugins."io.containerd.grpc.v1.cri".registry]
config_path = "/etc/containerd/certs.d"
[plugins."io.containerd.grpc.v1.cri".registry.mirrors]
{{- if .cri.registry.mirrors | empty | not }}
[plugins."io.containerd.grpc.v1.cri".registry.mirrors."docker.io"]
@ -63,15 +64,6 @@ state = "/run/containerd"
username = "{{ .image_registry.auth.username }}"
password = "{{ .image_registry.auth.password }}"
[plugins."io.containerd.grpc.v1.cri".registry.configs."{{ .image_registry.auth.registry }}".tls]
{{- if .image_registry.auth.ca_file | empty | not }}
ca_file = "/etc/containerd/certs.d/{{ .image_registry.auth.registry }}/ca.crt"
{{- end }}
{{- if .image_registry.auth.cert_file | empty | not }}
cert_file = "/etc/containerd/certs.d/{{ .image_registry.auth.registry }}/server.crt"
{{- end }}
{{- if .image_registry.auth.key_file | empty | not }}
key_file = "/etc/containerd/certs.d/{{ .image_registry.auth.registry }}/server.key"
{{- end }}
insecure_skip_verify = {{ .image_registry.auth.insecure | default true }}
{{- if .cri.registry.auths | empty | not }}
{{- range .cri.registry.auths }}