Move the serving Zot registry and registrar to ARM #69

Merged
binjovi-bot merged 3 commits from codex/zot-serving-arm into trunk 2026-09-10 22:07:06 +00:00
Owner

Select ARM workers for Zot and the Hydra client registrar. Pin the registrar to the verified multi-architecture pipeline-tools v16 image, and let the image warm-up hook tolerate the same node taint as Zot. Keep the existing portable Hetzner data claim; Kubernetes replaces only the temporary sync cache. Update the RustFS and ARM move documentation.

Validation: the warm-up taint regression failed before the fix; all repository checks now pass. The exact Zot and Alpine images ran successfully on the ARM worker before this move. The prior ARM canary verified RustFS reads and scoped OCI writes. The deployment will verify the volume attachment, ARM registrar, readiness, and authenticated write/read gate.

The native CI run also exposed two PyYAML imports after the shared validator update. Both checks now read JSON from the existing yq tool; their assertions and negative controls are unchanged. All repository checks pass locally, including those controls. The exact pipeline-tools v16 image also completed kubectl, curl and jq checks on the ARM worker as UID 65532 with a read-only root filesystem.

Select ARM workers for Zot and the Hydra client registrar. Pin the registrar to the verified multi-architecture pipeline-tools v16 image, and let the image warm-up hook tolerate the same node taint as Zot. Keep the existing portable Hetzner data claim; Kubernetes replaces only the temporary sync cache. Update the RustFS and ARM move documentation. Validation: the warm-up taint regression failed before the fix; all repository checks now pass. The exact Zot and Alpine images ran successfully on the ARM worker before this move. The prior ARM canary verified RustFS reads and scoped OCI writes. The deployment will verify the volume attachment, ARM registrar, readiness, and authenticated write/read gate. The native CI run also exposed two PyYAML imports after the shared validator update. Both checks now read JSON from the existing yq tool; their assertions and negative controls are unchanged. All repository checks pass locally, including those controls. The exact pipeline-tools v16 image also completed kubectl, curl and jq checks on the ARM worker as UID 65532 with a read-only root filesystem.
Move the serving Zot registry and registrar to ARM
Some checks failed
binjovi/ci Binjovi failed the frozen plan
86599f8b47
Record the ARM registrar tool check
Some checks failed
binjovi/ci Binjovi failed the frozen plan
89a06777d6
Read registry guard input with the existing YAML tool
All checks were successful
binjovi/ci Binjovi completed the frozen plan
7a61263e8c
binjovi-bot deleted branch codex/zot-serving-arm 2026-09-10 22:07:07 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
sean/zot!69
No description provided.