Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-44432

ImageStream ignores ITMS NeverContactSource policy

XMLWordPrintable

    • None
    • False
    • Hide

      None

      Show
      None

      Description of problem:

      ImageStream cannot import image tags when ImageTagMirrorSet is set to NeverContactSource. The same issue does not apply for pods

      Version-Release number of selected component (if applicable):

      4.15.35

      Steps to Reproduce:

          1. Create a disconnected cluster with no internet access
          2. Create a "pull-through" image registry  [1]   
          3. Create the following ImageTagMirrorSet and ImageDigestMirrorSet
      
      ~~~
      apiVersion: config.openshift.io/v1
      kind: ImageDigestMirrorSet
      metadata:
        name: image-mirrors
      spec:
        imageDigestMirrors:
          - mirrorSourcePolicy: NeverContactSource 
            mirrors:
              - <local-registry-url>/docker-remote
            source: docker.io
          - mirrorSourcePolicy: NeverContactSource 
            mirrors:
              - <local-registry-url>/registry.access.redhat.com
            source: registry.access.redhat.com
          - mirrorSourcePolicy: NeverContactSource 
            mirrors:
              - <local-registry-url>/quay.io
            source: quay.io
          - mirrorSourcePolicy: NeverContactSource 
            mirrors:
              - <local-registry-url>/registry.redhat.io
            source: registry.redhat.io
          - mirrorSourcePolicy: NeverContactSource 
            mirrors:
              - <local-registry-url>/gcr.io
            source: gcr.io
          - mirrorSourcePolicy: NeverContactSource 
            mirrors:
              - <local-registry-url>/ghcr.io
            source: ghcr.io
          - mirrorSourcePolicy: NeverContactSource 
            mirrors:
              - <local-registry-url>/com.redhat.connect.registry
            source: registry.connect.redhat.com
          - mirrorSourcePolicy: NeverContactSource 
            mirrors:
              - <local-registry-url>/nvcr.io
            source: nvcr.io
      ---
      apiVersion: config.openshift.io/v1
      kind: ImageTagMirrorSet
      metadata:
        name: image-mirrors
      spec:
        imageTagMirrors:
          - mirrorSourcePolicy: NeverContactSource 
            mirrors:
              - <local-registry-url>/docker-remote
            source: docker.io
          - mirrorSourcePolicy: NeverContactSource 
            mirrors:
              - <local-registry-url>/registry.access.redhat.com
            source: registry.access.redhat.com
          - mirrorSourcePolicy: NeverContactSource 
            mirrors:
              - <local-registry-url>/quay.io
            source: quay.io
          - mirrorSourcePolicy: NeverContactSource 
            mirrors:
              - <local-registry-url>/registry.redhat.io
            source: registry.redhat.io
          - mirrorSourcePolicy: NeverContactSource 
            mirrors:
              - <local-registry-url>/gcr.io
            source: gcr.io
          - mirrorSourcePolicy: NeverContactSource 
            mirrors:
              - <local-registry-url>/ghcr.io
            source: ghcr.io
          - mirrorSourcePolicy: NeverContactSource 
            mirrors:
              - <local-registry-url>/com.redhat.connect.registry
            source: registry.connect.redhat.com
          - mirrorSourcePolicy: NeverContactSource 
            mirrors:
              - <local-registry-url>/nvcr.io
            source: nvcr.io
      ~~~
      
          4. Import an image [2]
      
      [1] https://docs.redhat.com/en/documentation/red_hat_quay/3.13/html/use_red_hat_quay/quay-as-cache-proxy
      [2] https://docs.openshift.com/container-platform/4.15/openshift_images/image-streams-manage.html#images-imagestream-import-images-image-streams

      Actual results:

      Unable to import images

      Expected results:

      Being able to import images 

      A similar issue is reported in OCPBUGS-17975

              fmissi Flavian Missi
              rhn-support-ggeraci Giovanni Geraci
              XiuJuan Wang XiuJuan Wang
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated: