Kubernetes deploying a template with multiple pods with images from DockerHub with blocked DockerHub access

Viewed 34

I'm deploying a system which uses many images from DockerHub and other public registries(eg registry.redhat.io). Our k8s doesn't have access to Docker Hub or others. We use AKS & ACR.

The template has multiple references like this

      - name: some-api
        image: some-vendor/some-api:2.3.2

If I import image some-vendor/some-api:2.3.2 from DockerHub into ACR and change template to use full image name like my-acr-registry.azurecr.io/some-vendor/some-api:2.3.2 then it will pull the image ok, but I'd like avoid touching template. I'd like to do few changes in a namespaces or in the cluster so that it will attempt to find them in ACR.

Is there a way to make AKS to search that image in our ACR without specifying full image name? I'd like to avoid touching the template.

Another example, template also uses some other images from other repositories, eg registry.redhat.io/ubi8/nodejs-14. Is it possible to make it so that it will find it in our ACR if I push it using name my-acr-registry.azurecr.io/registry.redhat.io/ubi8/nodejs-14 without updating template? Is it possible to do that?

Ideally I'd like to add some sort of image resolver, which attempts to pull it as concat("my-acr-registry.azurecr.io/docker.io/", imageName), then if not able to find try to pull it as concat("my-acr-registry.azurecr.io/", imageName) to cater for both cases. Can I do that?

0 Answers
Related