summaryrefslogtreecommitdiff
path: root/playbooks/roles/oci
diff options
context:
space:
mode:
authorElizabeth Hunt <me@liz.coffee>2025-05-28 23:56:55 -0700
committerElizabeth Hunt <me@liz.coffee>2025-05-28 23:56:55 -0700
commit6d3cefc29d596fcce0d436391eb6feec16bf2018 (patch)
tree096b16849467669a3542ee2a3e76c57e4da827dd /playbooks/roles/oci
parentb8ffbfe27eae919750ef4d3facf02393d1004287 (diff)
downloadinfra-6d3cefc29d596fcce0d436391eb6feec16bf2018.tar.gz
infra-6d3cefc29d596fcce0d436391eb6feec16bf2018.zip
CI part one
Diffstat (limited to 'playbooks/roles/oci')
-rw-r--r--playbooks/roles/oci/templates/volumes/config.toml15
1 files changed, 9 insertions, 6 deletions
diff --git a/playbooks/roles/oci/templates/volumes/config.toml b/playbooks/roles/oci/templates/volumes/config.toml
index 6d2f199..520d6f6 100644
--- a/playbooks/roles/oci/templates/volumes/config.toml
+++ b/playbooks/roles/oci/templates/volumes/config.toml
@@ -18,18 +18,21 @@ root_dir = "/images"
endpoint = "http://127.0.0.1:4317"
sampling_rate = 1.0
-[identity.ci]
-username = "ci"
-password = "{{ simple_registry_password_argon_encoded }}"
+[identity.{{ ci_user }}]
+username = "{{ ci_user }}"
+password = "{{ ci_user_registry_password_argon_encoded }}"
[identity.readonly]
username = "readonly"
-password = "$argon2i$v=19$m=16,t=2,p=1$TjJyTEdIZUJ6dFZkdlZvSg$qf8vG09O93Z/9vUMCgWNtA" # readonly
+password = "$argon2i$v=19$m=16,t=2,p=1$TjJyTEdIZUJ6dFZkdlZvSg$qf8vG09O93Z/9vUMCgWNtA" # hash for "readonly"
-[repository."img"]
+{% for repo in oci_repos %}
+[repository."{{ repo }}"]
-[repository."img".access_policy]
+[repository."{{ repo }}".access_policy]
default_allow = false
rules = [
'request.action.startsWith("get-") || request.action.startsWith("list-") || identity.id == "ci"'
]
+{% endfor %}
+