theupdateframework / theupdateframework/specification

Guidance for [[transparent] proxy cache] partial mirrors?

Open
#110 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
405
Forks
59
Avg merge
3d 4h
Merged PRs (30d)
1

Description

Do unofficial/non-blessed downstream mirrors need to do anything special in order to mirror TUF repos? I should read the spec more closely,but guidance on how and whether this should be done would be useful to link to.

Does squid just work (as a transparent caching proxy)?

Can private partial mirrors also host (other) local packages? Does that need to be on a separate server?

Use cases:

  • mirror PyPI
    • devpi, bandersnatch
  • mirror DockerHub
  • mirror a TUF "upstream origin" (?) for CI services; in order to conserve bandwidth

Questions:

  • Ctrl-F the spec for "mirror":
    • mirror role
    • mirrors.json
      • Private/internal mirrors are not listed in mirrors.json, correct?
  • Are these use cases similar to #108 "How do we initialize trust with local metadata, and no access to a remote repository?"?

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reading the TUF specification sections on the mirror role and mirrors.json, then compare them with the use cases listed here: Squid, private partial mirrors, PyPI, and DockerHub. Resolve whether internal mirrors need special configuration, whether they may host local packages, and how this relates to issue #108; done means producing linkable guidance for these cases.

Written by the indexing model from the issue text.

Assessment

Domain
documentation
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.