registry

package
v0.0.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 5, 2026 License: Apache-2.0 Imports: 0 Imported by: 0

Documentation

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func HandleAuthz

func HandleAuthz(w http.ResponseWriter, r *http.Request, deps Dependencies)

func HandleRegistryCredentialItem

func HandleRegistryCredentialItem(w http.ResponseWriter, r *http.Request, deps CredentialDependencies)

func HandleRegistryCredentials

func HandleRegistryCredentials(w http.ResponseWriter, r *http.Request, deps CredentialDependencies)

func PrincipalCanAccessRegistryPath

func PrincipalCanAccessRegistryPath(p apiauth.Principal, r *http.Request, cfg *AuthzConfig) bool

PrincipalCanAccessRegistryPath resolves the repository scope from the forwarded registry path.

func PrincipalCanAccessRegistryScope

func PrincipalCanAccessRegistryScope(p apiauth.Principal, scope string, cfg *AuthzConfig) bool

func RegistryForwardedPath

func RegistryForwardedPath(r *http.Request) string

func RegistryPathScope

func RegistryPathScope(r *http.Request) (string, bool)

func RegistryRepoFromPath

func RegistryRepoFromPath(rest string) string

Types

type AuthzConfig

type AuthzConfig struct {
	// contains filtered or unexported fields
}

func NewAuthzConfigFromEnv

func NewAuthzConfigFromEnv() *AuthzConfig

NewAuthzConfigFromEnv builds registry Traefik forward-auth settings from platform env.

type CredentialDependencies

type CredentialDependencies struct {
	Platform             *platformstore.Store
	PrincipalFromContext func(context.Context) (apiauth.Principal, bool)
	WriteJSON            func(http.ResponseWriter, int, any)
	WriteBodyDecodeError func(http.ResponseWriter, error)
	RequestIP            func(*http.Request) string
	AuditSource          func(*http.Request, apiauth.Principal) string
	AuditIdentityLabel   func(apiauth.Principal) string
}

type Dependencies

type Dependencies struct {
	AuthenticateRequest             func(*http.Request) (apiauth.Principal, bool, error)
	RegistryCredentialAuthenticator RegistryCredentialAuthenticator
	RegistryAuthzSettings           func() *AuthzConfig
	PrincipalCanAccessRegistryPath  func(apiauth.Principal, *http.Request) bool
}

type RegistryCredentialAuthenticator

type RegistryCredentialAuthenticator interface {
	AuthenticateRegistryCredential(ctx context.Context, username, password string) (apiauth.Principal, bool, error)
}

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL