Welcome to the Inedo Forums! Check out the Forums Guide for help getting started.
If you are experiencing any issues with the forum software, please visit the Contact Form on our website and let us know!
Docker Migration from Nexus – Feature Not Working
-
Hi @rhessinger ,
Thanks for your help! I’m fine waiting until the release next Friday.
-
Hi @koksime-yap_5909,
Sounds good. The fix will be released on Friday December 19th.
Thanks,
rich -
Hi @rhessinger ,
Thanks for the support. I am now able to import container images from Nexus.
However, I notice that images with OCI media type are not imported. Is that expected?
Output of execution:
INFO: Importing example:0.0.1... WARN Docker image "example:0.0.1" not found.The
example:0.0.1has the following value returned from thehttps://«NEXUS_HOST_AND_PORT»/service/rest/v1/components?repository=«REPOSITORY_NAME»API:"contentType" : "application/vnd.oci.image.manifest.v1+json", -
Hi @koksime-yap_5909,
There are certain types of OCI images that are not supported in ProGet (covered in this forums post), but the
application/vnd.oci.image.manifest.v1+jsonimage type manifest is supported. I'm guessing this is a quirk with Artifactory. What I have learned through implementing this importer is that Artifactory is very dependent on the order of accept headers. It is possible that the order is not quite right. Our order for the importers are:private static HttpRequestMessage CreateDockerHttpRequest(HttpMethod method, string url) { var request = new HttpRequestMessage(method, url); // Order matters here, especially with Artifactory request.Headers.Accept.Add(new("application/vnd.docker.distribution.manifest.v2+json")); request.Headers.Accept.Add(new("application/vnd.docker.distribution.manifest.list.v2+json")); request.Headers.Accept.Add(new("application/vnd.docker.distribution.manifest.v1+prettyjws")); request.Headers.Accept.Add(new("application/json")); request.Headers.Accept.Add(new("application/vnd.oci.image.manifest.v1+json")); request.Headers.Accept.Add(new("application/vnd.oci.image.index.v1+json")); return request; }Is it possible to share an example Docker file that we could build an image that has this import image? That way I can verify it mixed with standard Docker images.
Thanks,
Rich -
Hi @rhessinger ,
Unfortunately I do not have an example of Dockerfile to build the image.
However, after further investigation, I noticed that this only happens when the top-level
mediaTypeis missing in the image when I used thedocker manifest inspect <image>to check the manifest.After I updated the manifest with top-level
mediaTypemanually, the ProGet is able to identify the image and migrate it from the Nexus. -
Hi @koksime-yap_5909,
Ah ok. It make sense that we would not be able to pull those based on the accept headers. How many images do you have without a media type? Are these mostly old images or are there new ones missing this as well? Do you know how to recreate an image in Nexus without a media type?
Thanks,
Rich -
Hi @rhessinger,
I currently do not have an overview on how many images without top-level
mediaType.To have an image in Nexus without top-level
mediaType, you can use theorasCLI tool to manipulate the manifest.For my testing, I used
skopeoto copy an OCI image (e.g. alpine/git:v2.52.0) to Nexus.skopeo copy --dest-creds <user>:<password> --dest-tls-verify=false docker://alpine/git:v2.52.0 docker://registry.nexus.example/docker/alpine/git:v2.52.0Then I used the
orasto:-
fetch the manifest
oras manifest fetch --insecure registry.nexus.example/docker/alpine/git:v2.52.0 > manifest.json -
Edit the
manifest.json, and remove the top-levelmediaType -
Push the manifest back to the registry
oras manifest push --insecure --media-type application/vnd.oci.image.manifest.v1+json registry.nexus.example/docker/alpine/git:v2.52.0 manifest.json
After that, when inspecting the manifest with
docker manifest inspect, the top-levelmediaTypeshould be missing from the image. And when trying to do migration in ProGet, it will show that the image is not found.I hope the information shared above is useful. Thank you.
-
-
Hi @koksime-yap_5909,
Thanks for sharing the steps. I'm going to attempt to reproduce this and I'll let you know what i find!
Thanks,
Rich -
Hi @rhessinger ,
Just checking in to see if you had a chance to look into this.
And I’d like to know whether a product fix is planned, or if I should rely on the workaround.
Thanks.
-
Hi @koksime-yap_5909,
I apologize for the delay. This is next on my list to review and I will have an update for you on Monday.
Thanks,
Rich -
Hi @koksime-yap_5909,
After looking into this further, although we can fix the import to handle the images without a media type, it will still be broken when you attempt to pull those images using the Docker client. This is because ProGet will only send the manifest as it is stored in ProGet, where Nexus will manipulate it to match the accept headers of the client. Since it is only returning the manifest as it is stored, the media type will be null which will cause the Docker client to fail with a missing or empty Content-Type header.
Since we cannot assume what the mediaType should be, I think it would be better to resolve those prior to importing into ProGet. The nice thing is you can use the import logs to identify what images are missing the media type. You can run the import multiple times and it will only import the missing images and layers.
Thanks,
Rich -
Hi @rhessinger,
Thanks for taking the time to investigate this and for the detailed update.
Given that the fix likely won’t work, I’ll proceed with the workaround on my side.
Appreciate the help.
-
Hi @koksime-yap_5909,
No problem! Happy to help!
Thanks,
Rich
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login