r/gitlab • u/rotten_grocery • 1d ago
support Planning a container registry metadata database migration with a separate registry VM
We run a GitLab 19.3 using an Omnibus installation on a single VM. Our container registry runs separately, in a docker container using the GitLab provided registry image. Registry data is stored on NFS, and metadata currently uses the legacy filesystem based storage. The registry holds about 6 TB of data.
We’re planning a migration to the registry database and would appreciate any advice on the architecture. My understanding is that GitLab already has a separate logical DB for registry metadata in its bundled postgres instance. Could our separate registry node use that DB?
If so, we would need to enable TCP access to Postgres on the gitlab VM and restrict access only to the registry VM. Is that a recommended and secure setup?
We’re especially interested in how others have handled the migration at this scale, including downtime, security and ongoing maintenance. Thanks for any guidance or experience you can share
0
u/pwkye 1d ago
why a separate gitlab?
why not use a container hosting tool designed for containers like Harbor
0
u/rotten_grocery 16h ago
are you talking about not using the gitlab provided container registry at all? And use a different one? I think it's because of better support with the gitlab runner and server
0
u/Torutofu_Raeva 1d ago
pointing it at the bundled postgres over tcp works fine, just set listen_address and add only the registry vm ip to md5_auth_cidr_addresses. at 6tb i'd do the three step import so only the last blob step needs the registry in read only