support http(s) URLs for oci-archive/docker-archive images#517
Conversation
There was a problem hiding this comment.
I tested this locally and it worked fine for both docker-archive and oci-archive, I also got to see the error case a few times when the driver couldn't find or translate my image. But I did leave a first pass of notes on implementation and tests.
And just a reminder that it really helps me save time to have a step-by-step of whatever prep is required in the Testing section. It wasn't too much effort to look up the process of saving docker & podman archive or writing a little serve script. But the time to look up & troubleshoot these little things that we don't do very often can add up.
And any steps you've already done that I can re-use gives me more time with your code. Especially now that we're budgeting our AI usage
Noted. I'll make this my default going forward, every PR with a Testing section will include copy-paste prep so there's nothing to look up or troubleshoot. |
Thanks, @ritesh-harihar! I really appreciate it and also appreciate the job specs and configs you've been including up until now. I hope I didn't phrase that in a way that suggested I didn't recognize that you've already been including more set up context in your PRs than we ordinarily would need when everyone is working on the same big repo where 99% of the set up is just built in to the makefile. |
tehut
left a comment
There was a problem hiding this comment.
One small fix and I think we're there!
<!-- **Merge branch** Make sure you create your PR against the correct **base** branch. For instructions, refer to GitHub's **Change the branch range and destination repository guide** (https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/proposing-changes-to-your-work-with-pull-requests/creating-a-pull-request). If your content is an update to: - Currently published content Choose **base: main** when you are updating published documentation, and you want your changes published when the PR is merged. We publish Nomad content from the `main` branch. - Upcoming Nomad release Choose the branch for the Nomad release that your content is for. Nomad release branches use the `nomad/<exact-release-number>` format. If you are not able to find the upcoming Nomad release branch that you are looking for, contact the tech writer that works with the Nomad team. - Upcoming Nomad release but not sure which one - Choose the `main` branch. - Add the "do not merge" label. - Convert the PR to a DRAFT. - Put an explanation in the **Description** section. The tech writer coordinates with Nomad engineering and updates the docs PR base branch when the code is slotted into an upcoming release. **Backports** This repo stores previous version docs in folders instead of branches. There are no backport labels. If you backported your code PR to previous branches, update the docs content in the corresponding folders. For example, if the current release is 1.10.x and you backported your code to 1.9.x and 1.8.x, update the docs content in the v1.10.x, v1.9.x, and v1.8.x folders. If you can't find the relevant files in previous versions, add a note to your PR description. The tech writer will help ensure that the previous versions receive the correct updates. --> ## Description This PR updates the nomad-driver-podman documentation for the v0.5.0 release. [Ticket](https://hashicorp.atlassian.net/browse/NMD-1628) <!-- Please describe why you're making this change and point out any important details the reviewers should be aware of. A robust description helps the tech writer create a fabulous release note. If your code PR has a splendid description, link to the code PR in the links section so that the tech writer can update this PR's description. Include the target release as well as prior versions if applicable. --> ## Changes <!-- **Please link to the related Nomad repo code PR!** if there is one. The tech writer does look at the code PR description, Jira ticket, and/or GH issue before reviewing docs content. Include links to GitHub issues, documentation, or similar which is relevant to this PR. If this is a docs bug fix, please ensure related issues are linked so they will close when this PR is merged. // GH-Jira integration generates the link and updates the Jira ticket. Jira: [<jira-ticket-number>] // for example, Jira: [NMD-1234] GitHub Issue: <issue-link> Deploy previews: The bot does publish a root-level link to the deploy preview, but the preview URL changes with each build. --> **Image platform overrides ([PR](hashicorp/nomad-driver-podman#514) , [JIRA Ticket](https://hashicorp.atlassian.net/browse/NMD-1320))** - Documents the new os, arch, and variant task config fields that override the platform used when pulling an image (mirroring podman's --os, --arch, --variant flags) - Adds an example and explains the always-pull behavior when any override is set, plus constraint guidance for pinning workloads to compatible nodes **IPC namespace mode ([PR](hashicorp/nomad-driver-podman#515) , [JIRA Ticket](https://hashicorp.atlassian.net/browse/NMD-1582))** - Documents the new ipc_mode task config with all supported values (host, private, shareable, none, container:<id>, ns:<path>, task:<name>) - Adds a task:mps-daemon example and the shm_size compatibility note **Custom Podman network names ([PR](hashicorp/nomad-driver-podman#509) , [JIRA Ticket](https://hashicorp.atlassian.net/browse/NMD-1518 ))** - Documents that network_mode accepts the name of a pre-existing Podman network created with podman network create - Notes the network must already exist and that this requires Podman 4.0 or later; adds a network_mode = "mynet" example **HTTP(S) archive URLs for images ([PR](hashicorp/nomad-driver-podman#517) ,[ JIRA Ticket](https://hashicorp.atlassian.net/browse/NMD-1000))** - Documents that the image field's oci-archive and docker-archive transports accept http(s):// URLs, not just local archive paths - Adds an oci-archive:https://... example ## Contributor checklists Review urgency: - [ ] ASAP: Bug fixes, broken content, imminent releases - [ ] 3 days: Small changes, easy reviews - [ ] 1 week: Default expectation - [ ] Best effort: No urgency Pull request: - [ ] Verify that the PR is set to merge into the correct base branch - [ ] Verify that all status checks passed - [ ] Verify that the preview environment deployed successfully - [ ] Add additional reviewers if they are not part of assigned groups Content: - [ ] I added redirects for any moved or removed pages - [x] I followed the [Education style guide](https://github.com/hashicorp/web-unified-docs/tree/main/docs/style-guide) - [ ] I looked at the local or Vercel build to make sure the content rendered correctly ## Reviewer checklist - [ ] This PR is set to merge into the correct base branch. - [ ] The content does not contain technical inaccuracies. - [ ] The content follows the Education content and style guides. - [ ] I have verified and tested changes to instructions for end users. [NMD-1234]: https://hashicorp.atlassian.net/browse/NMD-1234?atlOrigin=eyJpIjoiNWRkNTljNzYxNjVmNDY3MDlhMDU5Y2ZhYzA5YTRkZjUiLCJwIjoiZ2l0aHViLWNvbS1KU1cifQ
Fixes: #434
Issue
Summary
The podman driver lets you run an image straight from a tar archive using the
oci-archive:anddocker-archive:transports. Previously this only worked for archives on thelocal filesystem. This PR lets the archive also live behind anhttp://orhttps://URL, so a job can pull a one-off image from a web server, object store, or artifact registry.Fix
Detect archive references that point at an
http(s)URL before they reach the path-only parser, and handle them on a dedicated path:oci-archive: / docker-archive: + http(s)://.All existing paths (registry pulls, local archives, short names) are untouched.
Example job config:
Before/ After Flow
Testing
Details
After Fix:
-> job-http-archive.nomad.hcl
Result:
-> job-http-archive-404.nomad.hcl
Result:
-> local-archive.nomad.hcl
Result:
Before: tested for job http-archive
Changes to Security Controls
Are there any changes to security controls (access controls, encryption, logging) in this pull request? If so, explain.