fix: 远端与镜像注册表统一改用 HTTPS
git.iwali.top 有 Let's Encrypt 通配证书(*.iwali.top),HTTPS 全程可用: https://git.iwali.top/api/v1/version -> 200 https://git.iwali.top/v2/ -> 401(Bearer 认证,正常) 证书链校验 ssl_verify_result=0(受信),因此: - git remote 改为 https://git.iwali.top/...(原为 http://) - 镜像名 git.iwali.top/... 由 Docker 默认按 HTTPS 访问, **不再需要 daemon.json 配 insecure-registries**(明文传输会暴露 Token) - DEPLOYMENT.md 5.1 改写为「默认走 HTTPS」,HTTP + insecure 降级为补充说明 - Dockerfile 的 image.source 标签、README/DEPLOYMENT 的 clone 地址同步改 https
这个提交包含在:
+3
-1
@@ -9,9 +9,11 @@
|
||||
# 设计要点:
|
||||
# * Token **只从环境变量读**,绝不写进 .git/config、URL 或任何文件。
|
||||
# * 用 `-c credential.helper=` 屏蔽已配置的凭据助手(GCM),
|
||||
# 否则在非交互会话里 GCM 会挂住等弹窗。
|
||||
# 否则在非交互会话里 GCM 会挂住等弹窗(连 /dev/tty 都拿不到,直接失败)。
|
||||
# * 用 `http.extraHeader` 传 Basic 认证,比把 token 拼进 URL 更安全
|
||||
# (不会落到 reflog / 进程列表里)。
|
||||
# * git.iwali.top 有 Let's Encrypt 通配证书,**HTTPS 可用**,
|
||||
# 所以镜像不需要配 insecure-registries。
|
||||
# =============================================================================
|
||||
set -eu
|
||||
|
||||
|
||||
在新工单中引用
屏蔽一个用户