Add --oci-skip-registry-validation flag for custom registry proxies
#1975
+29
−21
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Summary
This PR adds the
--oci-skip-registry-validationflag to source-controller, enabling the use of custom OCI registry proxies/gateways with cloud provider workload identity authentication.Problem
Organizations using custom OCI registry proxies cannot use cloud provider authentication (GCP, AWS, Azure) because the auth package validates that registry domains match official patterns.
Example error:
Solution
Add support for the new
--oci-skip-registry-validationflag fromfluxcd/pkg/auththat bypasses domain validation for all cloud providers.Changes
main.goociSkipRegistryValidationvariable--oci-skip-registry-validationauth.SetOCISkipRegistryValidation(true)when flag is enabledUsage
Deploy source-controller with:
Or via Helm values:
Security Considerations
Dependencies
ControllerFlagOCISkipRegistryValidationsupport (Add--oci-skip-registry-validationflag for custom registry proxies pkg#1083)Related
--oci-skip-registry-validationflag for custom registry proxies pkg#1083