Skip to content

feat(agent): add --plain-http for a registry without TLS (MK8S-445) - #31

Open
ezekiel-alexrod wants to merge 1 commit into
feature/MK8S-434-sentinel-ownerfrom
feature/MK8S-445-plain-http
Open

ezekiel-alexrod wants to merge 1 commit into
feature/MK8S-434-sentinel-ownerfrom
feature/MK8S-445-plain-http

Conversation

@ezekiel-alexrod

Copy link
Copy Markdown
Collaborator

Component

agent, docs

Problem

The MetalK8s registry serves plain HTTP. go-containerregistry only falls back to HTTP for a loopback or private address, so a registry reached by host name or public IP can't be pulled from. That breaks the join on a node (MK8S-394) and the resources created at bootstrap (MK8S-396).

Fix

Stacked on #26, so the diff here is the last commit only. I'd mostly like eyes on the scheme note in agent/DESIGN.md ("Pulling and extraction") and on open in agent/internal/puller/puller.go.

  • The manager and imagecachectl import take --plain-http. It marks the registry insecure (name.Insecure), which is the library's own switch for this.
  • The library still tries HTTPS first. It also tries HTTP when HTTPS fails or takes more than 300ms, and the first answer wins. So with the flag, a certificate error on an HTTPS registry no longer fails the pull. agent/DESIGN.md says it.
  • Off by default, no manifest sets it. The agent logs a warning at startup, the command prints one before it pulls (not for an archive).
  • It excludes --ca-file and --insecure-skip-tls-verify: it's for a registry without TLS, so a certificate setting next to it is a mistake.

Test

Check Result
go test -race ./... with envtest, go vet, golangci-lint after cache clean (Go 1.26.0) OK
HTTP registry reached by host name: refused without the flag (HTTP response to HTTPS client), pulled with it, in puller and through imagecachectl import OK
HTTPS registry pulled with the flag set OK
Flag combined with --ca-file or --insecure-skip-tls-verify refused: imagecachectl names both flags, the manager exits on ErrTLS
make -C agent test-e2e on kind OK, but it doesn't set the flag
RPM tests not run, the RPM isn't touched

Out of scope

  • A per-registry list instead of a global flag. MetalK8s pulls from its own registry only, so one flag is enough today. A site mixing an HTTP registry and one signed by a private CA can't be served until then.
  • Setting the flag from MetalK8s: MK8S-394 and MK8S-396.

  • The docs describing this behaviour are updated in the same pull request: README.md, agent/README.md, DESIGN.md, agent/DESIGN.md, CONTRIBUTING.md, whichever owns it.
  • A change to the cache directory layout (subdirectory scheme, archive names, sentinel, permissions) lands in both halves and in agent/DESIGN.md. Not applicable.

Relates-to: MK8S-445

@ezekiel-alexrod
ezekiel-alexrod requested a review from a team as a code owner October 9, 2026 11:40
A registry that serves plain HTTP under a host name could not be
reached: go-containerregistry only falls back to HTTP for a loopback
or private address. The manager and imagecachectl import now take
--plain-http, which marks every registry insecure. The client still
tries HTTPS first, and tries HTTP too when HTTPS fails or is slow.

It is off by default and no manifest sets it. The agent logs a warning
at startup and the command prints one before it pulls. It excludes
--ca-file and --insecure-skip-tls-verify: it is for a registry without
TLS, so a certificate setting next to it is a mistake.

Relates-to: MK8S-445
@ezekiel-alexrod
ezekiel-alexrod force-pushed the feature/MK8S-445-plain-http branch from 36cd54b to f7d31c7 Compare October 9, 2026 16:23
Comment thread agent/DESIGN.md
`--insecure-skip-tls-verify` turns verification off for test clusters. It
excludes `--ca-file`, so neither setting wins in silence.
- On its own, the library falls back to plain HTTP only for a loopback or a
private address.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

"Only for a loopback or a private address" is incomplete. In go-containerregistry, name.Registry.Scheme() also returns http for a localhost:<port> registry and for any host ending in .local or .localhost. So a registry at registry.local:5000 already works without --plain-http, and this sentence tells the reader it won't. I couldn't open the v0.21.7 source here, so check pkg/name/registry.go.

Suggested change
private address.
private address, or a `localhost` or `*.local` host name.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant