diff options
author | Elizabeth Hunt <me@liz.coffee> | 2025-05-28 23:56:55 -0700 |
---|---|---|
committer | Elizabeth Hunt <me@liz.coffee> | 2025-05-28 23:56:55 -0700 |
commit | 6d3cefc29d596fcce0d436391eb6feec16bf2018 (patch) | |
tree | 096b16849467669a3542ee2a3e76c57e4da827dd /playbooks/roles/oci | |
parent | b8ffbfe27eae919750ef4d3facf02393d1004287 (diff) | |
download | infra-6d3cefc29d596fcce0d436391eb6feec16bf2018.tar.gz infra-6d3cefc29d596fcce0d436391eb6feec16bf2018.zip |
CI part one
Diffstat (limited to 'playbooks/roles/oci')
-rw-r--r-- | playbooks/roles/oci/templates/volumes/config.toml | 15 |
1 files changed, 9 insertions, 6 deletions
diff --git a/playbooks/roles/oci/templates/volumes/config.toml b/playbooks/roles/oci/templates/volumes/config.toml index 6d2f199..520d6f6 100644 --- a/playbooks/roles/oci/templates/volumes/config.toml +++ b/playbooks/roles/oci/templates/volumes/config.toml @@ -18,18 +18,21 @@ root_dir = "/images" endpoint = "http://127.0.0.1:4317" sampling_rate = 1.0 -[identity.ci] -username = "ci" -password = "{{ simple_registry_password_argon_encoded }}" +[identity.{{ ci_user }}] +username = "{{ ci_user }}" +password = "{{ ci_user_registry_password_argon_encoded }}" [identity.readonly] username = "readonly" -password = "$argon2i$v=19$m=16,t=2,p=1$TjJyTEdIZUJ6dFZkdlZvSg$qf8vG09O93Z/9vUMCgWNtA" # readonly +password = "$argon2i$v=19$m=16,t=2,p=1$TjJyTEdIZUJ6dFZkdlZvSg$qf8vG09O93Z/9vUMCgWNtA" # hash for "readonly" -[repository."img"] +{% for repo in oci_repos %} +[repository."{{ repo }}"] -[repository."img".access_policy] +[repository."{{ repo }}".access_policy] default_allow = false rules = [ 'request.action.startsWith("get-") || request.action.startsWith("list-") || identity.id == "ci"' ] +{% endfor %} + |