Öйú±±¾© ¨C 2024Äê3ÔÂ25ÈÕ ¨C ÊÀ½çÁìÏȵĿªÔ´½â¾ö·½°¸¹©Ó¦É̺ìñ¹«Ë¾ÈÕǰÐû²¼ºìñQuay 3.11½«ÓÚ±¾ÔÂÕýÊ½ÍÆ³ö¡£¸Ã°æ±¾½«¸üÐÂȨÏÞ¹ÜÀíºÍ¾µÏñÉúÃüÖÜÆÚ×Ô¶¯»¯¹¦ÄÜ£¬ÒÔʵÏÖ¸ü¸ßЧµÄÈ«Ãæ¹ÜÀí¡£
ÖØÒª¸üÐÂÄÚÈݰüÀ¨£º
¡¤ ÍŶÓÓëOIDC£¨OpenID Connect£©Ð¡×éµÄͬ²½
¡¤ ÔÚ´æ´¢¿â¼¶±ðÐÞÕû²ßÂÔ
¡¤ еÄÓû§½çÃæÌṩ¸ü¶àQuay¹¦ÄÜ
¡¤ ͨÓÃAWS STSÖ§³Ö
¡¤ Quay²Ù×÷Æ÷ÔöÇ¿
ÔöÇ¿Óû§×é¿ØÖÆ
½èÖúQuay 3.11£¬Óû§¿ÉÒÔ¸ù¾ÝOIDCÌṩÉÌ·þÎñ£¨ÈçAzure Active Directory Service£©Ëù¶¨ÒåµÄ·Ö×éÀ´¹ÜÀíȨÏÞ¡£´Ë¸üÐÂʹQuay ¹ÜÀíÔ±ºÍ×éÖ¯¸ºÔðÈË¿ÉÒÔ¸üÓÐЧµØ¶¨Òå·ÃÎʼ¶±ð£ºOIDCÖеÄȺ×é³ÉÔ±¿ÉÒÔ¼¯ÖÐʶ±ð¶à¸öϵͳÖеÄÓû§¼°Æä½ÇÉ«£¬ÔÚQuayÖУ¬²»ÂÛÓû§×鹿ģÈçºÎ£¬¶¼ÄÜÇáËÉÏòÓû§×éÌí¼Ó»òɾ³ýȨÏÞ¡£ÀýÈ磬ÃûΪ¡°developer¡±µÄOIDC×é¿ÉÓÃÓÚй¤³ÌʦÍŶÓÊÚÓèʹÓÃCI/CD¹ÜµÀºÍÏòÆäQuay×éÖ¯ÍÆË;µÏñµÄȨÏÞ£¬¶ø²»¸ü¸ÄQuayÖеÄ×éÖ¯ÉèÖá£

ÔÚQuay×éÖ¯ÖУ¬ÍŶÓÊÇÒ»×éÓû§£¬ËûÃÇ¿ÉÒÔ¸ù¾Ý×Ô¼ºµÄ½ÇÉ«ÀÈ¡¡¢ÍÆËÍ¡¢¸üоµÏñ»ò¹ÜÀí×éÖ¯¡£OIDC×éͬ²½¹¦Äܿɽ«ÍŶӶ¨ÒåÓëOIDCÌṩÉÌÖеÄ×éÃû½øÐжԱȣ¬ÒÔ×Ô¶¯Ê¶±ðÍŶӳÉÔ±¡£
Áé»îʵÏÖ×Ô¶¯»¯¾µÏñÉúÃüÖÜÆÚ¹ÜÀí
ÔÚÉÏÒ»°æ±¾µÄ»ù´¡ÉÏ£¬Quay 3.11ÒýÈëÁË´æ´¢¿âÌØ¶¨µÄ¹æÔò£¬ÓÃÓÚÐÞÕû×éÖ¯¼¶²ßÂÔÖ®ÍâµÄ²ßÂÔ£¬»òÕßÈ¡´ú×éÖ¯¼¶²ßÂÔ¡£Õâ½øÒ»²½Ï¸»¯Á˾µÏñÉúÃüÖÜÆÚµÄ¶¨Òå¡£ÀýÈ磬ÔÚÒ»¸ö×éÖ¯ÄÚ²¿£¬¶à¸ö´æ´¢¿âÍйÜÓ¦ÓöÑÕ»µÄ²»Í¬×é¼þ¡£ÐÞÕû²ßÂÔ¿ÉÒÔÔÚ×éÖ¯¼¶±ð¶¨Ò壬ÒÔ±ãÔÚ¾µÏñʹÓó¬¹ýÒ»Äêºó×Ô¶¯É¾³ý¡£½èÖúºìñQuay 3.11£¬Óû§ÏÖÔÚ¿ÉÒÔΪ´æ·Å²âÊÔºÍÔÝ´æ¾µÏñµÄ´æ´¢¿â¶¨Òå¶îÍâµÄ²ßÂÔ£¬ÕâЩ²ßÂÔ¿ÉÄÜ»á¹æ¶¨ÔÚ30ÈÕºóɾ³ýÒ¹¼ä¹¹½¨µÄ¾µÏñ¡£ÕâÒ²½«¼õÉÙÔÚ¹ýÆÚ¾µÏñÖз¢Ïֵĩ¶´£¬´Ó¶øÌá¸ß°²È«ÐÔ¡£
ÔÚÐÂÓû§½çÃæÖÐ̽Ë÷¸ü¶à¹¦ÄÜ
¸Ã°æ±¾»¹ÔÚÐÂÓû§½çÃæÖмÓÈëÁ˸ü¶àQuay¹¦ÄÜ£¬ÒÔÖ§³Ö¸ü¶à¹¤×÷Á÷¡£ÏÖÔÚ£¬Óû§¿ÉÒÔ¹ÜÀí×Ô¼ºµÄ¾µÏñ¹¹½¨£¬Ò²¿ÉÒԲ鿴×éÖ¯ÄÚµÄÉóºËʼþ¡£

ÕâÒ»¸üа汾»¹ÒýÈëÁËʹÓÃÕýÔò±í´ïʽ¶Ô¶à¸ö±êÇ©¡¢´æ´¢¿âºÍ×éÖ¯½øÐиßЧËÑË÷µÄ¹¦ÄÜ¡£´ËÍ⣬Óû§»¹¿ÉÒÔÔÚеÄÓû§½çÃæÖÐʹÓøù¾ÝÓû§µÄϵͳÉèÖÃ×Ô¶¯ÆôÓõÄÒ¹¼äģʽ¡£
ͨ¹ýAWS·þÎñÔöÇ¿°²È«ÐÔ
ÏÖÔÚ£¬Óû§¿ÉÒÔͨ¹ýAWSµÄ°²È«ÁîÅÆ·þÎñ (Secure Token Service)¸ü°²È«µØ½«QuayÓëAWS S3Á¬½Ó¡£Í¨¹ýSTS£¬Óû§²»ÔÙÐèÒª½èÖú³¤ÆÚÒÔÀ´Ò»Ö±Ê¹ÓõÄAWS·ÃÎÊÃÜÔ¿ºÍÃØÔ¿²ÅÄÜÈÃQuay·ÃÎÊAWS·þÎñ£¬¶øÊÇ¿ÉÒÔÒÀ¿¿ºìñQuayºÍAWS IAMϵͳ֮¼äµÄ×Ô¶¯ÁîÅÆ½»»»»úÖÆ¡£ÕâЩÁîÅÆÓÐʱЧÐÔ£¬²¢ÓÉQuay×Ô¶¯Ë¢Ð£¬Òò´Ë£¬ÁîÅÆÐ¹Â¶Ôì³ÉµÄÓ°ÏìÓÐÏÞ¡£ÕâÊǺìñQuayÍŶӸù¾Ý¿Í»§·´À¡£¨ÒªÇóÔÚËûÃǵĻ·¾³ÖÐÇ¿ÖÆÊ¹ÓÃSTS£©¶øÊµÏֵġ£
²Ù×÷ÔöÇ¿
Quay²Ù×÷Æ÷ÏÖÔÚ¿ÉÓÃÓÚÔÚKubernetes²ãÃæÎ¢µ÷×ÊÔ´ÏûºÄÇëÇóºÍÏÞÖÆ¡£Quay¶ÑÕ»ÖеÄÿ¸öÊܹÜ×é¼þ£¨°üÀ¨Quay×ÔÉí¡¢Clair¡¢¶þÕßµÄPostgreSQLʵÀý¡¢RedisºÍ¾µÏñ¹¤×÷Æ÷£©¶¼¿ÉÒÔÅäÖõ¥¶ÀµÄ×ÊÔ´ÇëÇóºÍÏÞÖÆÖµ£º
spec:
components:
- kind: clair
managed: true
overrides:
resources:
limits:
cpu: "5" # Limiting to 5 CPUs (vs. 4 default)
memory: "18Gi" # Limiting to 18 Gibibytes of memory (vs. 16 Gi default)
requests:
cpu: "4" # Requesting 4 CPUs (vs. 2 default)
ÕâÓÐÖúÓÚµ÷ÕûQuay×é¼þÔËÐÐËùÐèÏò¼¯ÈºÇëÇóµÄ×îµÍ×ÊÔ´£¬Ò»°ãÀ´Ëµ£¬Õâ¶ÔÔÚ¸üС¡¢×ÊÔ´¸ü½ôÕŵļ¯ÈºÉÏÔËÐзdz£ÓÐÓá£ÏÞÖµÒ²¿ÉÒÔµ÷Õû£¬ÕâÊÊÓÃÓÚ¼«´ó¹æÄ£µÄ²¿ÊðÏîÄ¿£¬ÈçÉÏÀýËùʾ¡£
ºìñQuay 3.11°æ±¾»¹½â¾öÁ˲Ù×÷Æ÷¹ÜÀíµÄQuay²¿Êð×é¼þµÄ×Ô¶¨Ò帱±¾ÉèÖÃÓëPodˮƽ×Ô¶¯À©ËõÆ÷ÉèÖÃÏà³åÍ»µÄÎÊÌâ¡£ÏÖÔÚ£¬ÕâЩÉèÖö¼¿ÉÒÔµ÷Õû£¬¶øÇÒHPA Ò²»áÏàÓ¦µØ×ñÊØÕâЩÉèÖá£ÕâÑù£¬Èç¹ûÐèÒª³¬³öĬÈÏÊýÁ¿µÄQuayºÍClair PodʵÀý£¬²»ÔÙ±ØÐë½ûÓÃ×Ô¶¯À©Ëõ¹¦ÄÜ¡£¡£
ÆäËûÔöÇ¿
ÐèÒª²¿Êð´óÐÍÏîÄ¿µÄ¿Í»§Í¨³£Ï£ÍûÔÚPostgreSQL¶ËʹÓÃQuay½«Á¬½Ó»ã¼¯µ½Ò»Æð¡£pgBouncerÊǹãÊÜ»¶ÓµÄPostgreSQLÁ¬½Ó³ØÖ®Ò»£¬¶øÇÒÓû§Ò²Ï£ÍûÈ·ÈÏpgBounceerÄܹ»ÓëQuayÒ»ÆðʹÓ᣺ìñQuay 3.11Ö§³ÖʹÓÃpgBouncer£¬¶øÇÒÎÒÃǵÄQAÍŶÓʹÓÃCrunchyDB Postgres¶ÔÆä½øÐÐÁ˲âÊÔ¡£QuayµÄ¾²Ì¬Â©¶´·ÖÎöÆ÷µÄÄÜÁ¦Ò²µÃµ½ÁËÔöÇ¿£¬Ö¼ÔÚÌá¸ß×ÊÔ´ÀûÓÃÂÊ¡£
δÀ´Õ¹Íû
QuayÔÚ2024ÄêÖ®ºóµÄ·Ïßͼ·Ç³£ÖµµÃ¹Ø×¢¡£ÎÒÃÇÏ£ÍûÔÚ½ñÄêÍê³ÉÏòÐÂÓû§½çÃæµÄÇ¨ÒÆ£¬²¢ÍêÈ«ÒÆ³ý»ùÓÚAngularµÄ¾É½çÃæ¡£ÎÒÃǼƻ®ÔöÇ¿ºËÐÄ×¢²á±í¹¦ÄÜ£¬ÒԸĽøÈÝÆ÷¾µÏñÉúÃüÖÜÆÚºÍ¹¤×÷Á÷¹ÜÀí£¬²¢ÊµÏÖ×Ô¶¯»¯£¬ÀýÈç²»¿É±ä±êÇ©¡¢Ä¬ÈϱêÇ©¹ýÆÚ²ßÂÔ£¬ÒÔ¼°»ùÓÚ©¶´»ò²»ÕýÈ·/ȱʧǩÃû¾Ü¾øÀÈ¡µÄ²ßÂÔ¡£ÎÒÃÇ»¹¼Æ»®ÔÚQuay¶Ë¸Ä½øOpenShift¼¯ÈºÉÏÓû§ºÍ¹¤×÷¸ºÔصĴó¹æÄ£Éí·ÝÑéÖ¤¡£×îºó£¬ÎÒÃÇÏ£ÍûÔÚQuayºÍClair¶Ï¿ªÔËÐÐʱ£¬ÄܸüÇáËɵؽ«Â©¶´Êý¾Ý¿â×ªÒÆµ½ÀëÏß»·¾³¡£
ÏêϸÁ˽âºìñQuay