Configure hosts for mirror registry access
To configure a MicroShift host to use a mirror registry, you must give the MicroShift host access to the registry by creating a configuration file that maps the Red Hat registry host names to the mirror.
-
Your mirror host has access to the internet.
-
The mirror host can access the mirror registry.
-
You configured the mirror registry for use in your restricted network.
-
You downloaded the pull secret and modified it to include authentication to your mirror repository.
-
Log in to your MicroShift host.
-
Enable the SSL certificate trust on any host accessing the mirror registry by completing the following steps:
-
Copy the
rootCA.pemfile from the mirror registry, for example,<registry_path>/quay-rootCA, to the MicroShift host at the/etc/pki/ca-trust/source/anchorsdirectory. -
Enable the certificate in the system-wide truststore configuration by running the following command:
$ sudo update-ca-trust
-
-
Create the
/etc/containers/registries.conf.d/999-microshift-mirror.confconfiguration file that maps the Red Hat registry host names to the mirror registry:Example mirror configuration file[[registry]] prefix = "" location = "<registry_host>:<port>" mirror-by-digest-only = true insecure = false [[registry]] prefix = "" location = "quay.io" mirror-by-digest-only = true [[registry.mirror]] location = "<registry_host>:<port>" insecure = false [[registry]] prefix = "" location = "registry.redhat.io" mirror-by-digest-only = true [[registry.mirror]] location = "<registry_host>:<port>" insecure = false [[registry]] prefix = "" location = "registry.access.redhat.com" mirror-by-digest-only = true [[registry.mirror]] location = "<registry_host>:<port>" insecure = false-
Replace
<registry_host>:<port>with the hostname and port of your mirror registry server, for example,<microshift-quay:8443>.
-
-
Enable the MicroShift service by running the following command:
$ sudo systemctl enable microshift -
Reboot the host by running the following command:
$ sudo reboot