Registry Access
Dalet Flex is micro-services based software stack where most of the components run in containerized environments. This extend the deployment and upgrade capabilities while adding an extra layer of resources isolation and security.
Flex containers images are pulled from a container registry, a placeholder containing all software images and associated versions.
By default, Flex container images are pulled from Dalet public registry:
https://registry.services.ooflex.net/
This registry is publicly exposed over Internet, yet requires appropriate authentication to pull from.
Requesting Access
Dalet registry is restricted to customers with active subscription.
You need to reach out to your Dalet account manager to provide you with a valid, nominative access token.
Once received, the token is recommended to be declared as an encrypted secret variable, later to be ingested by Ansible's deployment framework.
Registry access token have a limited lifespan corresponding to subscription's duration.
Registry Proxy
Sometimes, server instances will run in an air-gapped, Internet-isolated environment, with no possible direct access to Dalet public registry.
In such case, you'd need to:
- Setup your own registry (Harbor would do great)
- Configure Dalet registry as a proxy, with the appropriate access token.
- Optionnally configure a dedicated robot account (recommended) to access the proxy or keep it 'public' for all private LAN clients.
It is recommended to configure the registry as a proxy instead of a mirror.
A mirror will pre-download all possible container images from upstream registry (including all possible versions, even if unused) and can quickly lead to several hundreds of GB of disk usage.
A proxy will download requested container images on the fly, leading to less disk usage. Downloaded images will however be cached on the local registry, preventing excessive re-downloads.