Registry
Every realm has a container image registry. You push images to it with podman or docker, and your apps and jobs run them by the same name. It is private: nobody pulls an image of yours unless you allow it.
Names
An image is named after the realm’s address, then whose it is:
| Namespace | Whose |
|---|---|
<realm>/u-<you>/<name>:<tag> | Yours, for example cloud.example.se/u-anna/web:1 |
<realm>/o-<org>/<name>:<tag> | An organisation’s |
The Registry window shows your exact namespace, and each organisation’s. A name keeps pointing at the same owner if a handle is renamed.
Push an image
- In API keys, make a key with the scope Registry: push and delete images (for pulling only: Registry: pull images). Copy the secret: it is shown once.
- Sign in with the key as the password. The user name is not used for anything:
podman login <realm> -u <you> -p <api key> - Name the image and push it:
podman tag localhost/web:1 <realm>/u-<you>/web:1 podman push <realm>/u-<you>/web:1
The registry is reached over the realm’s own HTTPS address, so the key never crosses the network in the clear. While the realm still uses the certificate it made for itself, add --tls-verify=false to login and push; the Registry window’s commands say when.
To push to an organisation’s namespace, your key needs the push permission in that organisation.
Run it
Give an app or a job the same image name, <realm>/u-<you>/web:1. The realm’s servers pull it themselves with a short-lived token for that one image, so the app needs no login of its own. An app may only name images its owner may pull, or public ones.
Repositories and tags
The Registry window lists your repositories with their tags, sizes and who pushed each tag.
- Public: anyone who can reach the registry may pull it without signing in. Pushing still needs a key.
- Immutable tags: a pushed tag can’t be moved to another image or deleted.
- Delete tag: the tag goes at once; the image’s data goes at the next sweep, unless another tag still uses it. Apps already running it keep running.
- Signatures and SBOMs attached with
cosignororasare kept beside the image they belong to.
Space
Each person and organisation has a quota, set by your operator. Layers shared between images count once. When the space is used up, new pushes are refused until you delete tags.