[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"docs:\u002Fdocs\u002Fguides\u002Fregistry":3,"docs:nav":381,"docs:surround:\u002Fdocs\u002Fguides\u002Fregistry":593},{"id":4,"title":5,"body":6,"description":371,"extension":372,"launchGate":373,"meta":374,"navigation":375,"path":376,"seo":377,"stem":378,"stub":379,"__hash__":380},"docs_en\u002Fdocs\u002F3.guides\u002F6.registry.md","Registry",{"type":7,"value":8,"toc":362},"minimark",[9,22,27,30,74,81,85,242,257,260,264,271,275,280,317,321,344,351,355,358],[10,11,12,13,17,18,21],"p",{},"Every realm has a container image registry. You push images to it with ",[14,15,16],"code",{},"podman"," or ",[14,19,20],{},"docker",", and your apps and jobs run them by the same name. It is private: nobody pulls an image of yours unless you allow it.",[23,24,26],"h2",{"id":25},"names","Names",[10,28,29],{},"An image is named after the realm’s address, then whose it is:",[31,32,33,46],"table",{},[34,35,36],"thead",{},[37,38,39,43],"tr",{},[40,41,42],"th",{},"Namespace",[40,44,45],{},"Whose",[47,48,49,64],"tbody",{},[37,50,51,57],{},[52,53,54],"td",{},[14,55,56],{},"\u003Crealm>\u002Fu-\u003Cyou>\u002F\u003Cname>:\u003Ctag>",[52,58,59,60,63],{},"Yours, for example ",[14,61,62],{},"cloud.example.se\u002Fu-4f1c9a2e7b3d5068\u002Fweb:1",", after your account id",[37,65,66,71],{},[52,67,68],{},[14,69,70],{},"\u003Crealm>\u002Fo-\u003Corg>\u002F\u003Cname>:\u003Ctag>",[52,72,73],{},"An organisation’s",[10,75,76,77,80],{},"The ",[78,79,5],"strong",{}," window shows your exact namespace, and each organisation’s. A name keeps pointing at the same owner if a handle is renamed.",[23,82,84],{"id":83},"push-an-image","Push an image",[86,87,88,104,173],"ol",{},[89,90,91,92,95,96,99,100,103],"li",{},"In ",[78,93,94],{},"API keys",", make a key with the scope ",[78,97,98],{},"Registry: push and delete images"," (for pulling only: ",[78,101,102],{},"Registry: pull images","). Copy the secret: it is shown once.",[89,105,106,107],{},"Sign in with the key as the password. The user name is not used for anything:",[108,109,114],"pre",{"className":110,"code":111,"language":112,"meta":113,"style":113},"language-bash shiki shiki-themes github-light-high-contrast github-light-high-contrast github-dark-high-contrast","podman login \u003Crealm> -u \u003Cyou> -p \u003Capi key>\n","bash","",[14,115,116],{"__ignoreMap":113},[117,118,121,124,128,132,135,139,142,146,148,151,154,156,159,161,164,167,170],"span",{"class":119,"line":120},"line",1,[117,122,16],{"class":123},"szw1H",[117,125,127],{"class":126},"semJd"," login",[117,129,131],{"class":130},"sklAV"," \u003C",[117,133,134],{"class":126},"real",[117,136,138],{"class":137},"s7iLA","m",[117,140,141],{"class":130},">",[117,143,145],{"class":144},"ssYy9"," -u",[117,147,131],{"class":130},[117,149,150],{"class":126},"yo",[117,152,153],{"class":137},"u",[117,155,141],{"class":130},[117,157,158],{"class":144}," -p",[117,160,131],{"class":130},[117,162,163],{"class":126},"api",[117,165,166],{"class":126}," ke",[117,168,169],{"class":137},"y",[117,171,172],{"class":130},">\n",[89,174,175,176],{},"Name the image and push it:",[108,177,179],{"className":110,"code":178,"language":112,"meta":113,"style":113},"podman tag localhost\u002Fweb:1 \u003Crealm>\u002Fu-\u003Cyou>\u002Fweb:1\npodman push \u003Crealm>\u002Fu-\u003Cyou>\u002Fweb:1\n",[14,180,181,214],{"__ignoreMap":113},[117,182,183,185,188,191,193,195,197,199,202,205,207,209,211],{"class":119,"line":120},[117,184,16],{"class":123},[117,186,187],{"class":126}," tag",[117,189,190],{"class":126}," localhost\u002Fweb:1",[117,192,131],{"class":130},[117,194,134],{"class":126},[117,196,138],{"class":137},[117,198,141],{"class":130},[117,200,201],{"class":126},"\u002Fu-",[117,203,204],{"class":130},"\u003C",[117,206,150],{"class":126},[117,208,153],{"class":137},[117,210,141],{"class":130},[117,212,213],{"class":126},"\u002Fweb:1\n",[117,215,217,219,222,224,226,228,230,232,234,236,238,240],{"class":119,"line":216},2,[117,218,16],{"class":123},[117,220,221],{"class":126}," push",[117,223,131],{"class":130},[117,225,134],{"class":126},[117,227,138],{"class":137},[117,229,141],{"class":130},[117,231,201],{"class":126},[117,233,204],{"class":130},[117,235,150],{"class":126},[117,237,153],{"class":137},[117,239,141],{"class":130},[117,241,213],{"class":126},[10,243,244,245,248,249,252,253,256],{},"The registry is reached over the realm’s own HTTPS address, so the key never crosses the network in the clear. While the realm still uses the certificate it made for itself, add ",[14,246,247],{},"--tls-verify=false"," to ",[14,250,251],{},"login"," and ",[14,254,255],{},"push","; the Registry window’s commands say when.",[10,258,259],{},"To push to an organisation’s namespace, your key needs the push permission in that organisation.",[23,261,263],{"id":262},"run-it","Run it",[10,265,266,267,270],{},"Give an app or a job the same image name, ",[14,268,269],{},"\u003Crealm>\u002Fu-\u003Cyou>\u002Fweb:1",". The realm’s servers pull it themselves with a short-lived token for that one image, so the app needs no login of its own. An app may only name images its owner may pull, or public ones.",[23,272,274],{"id":273},"repositories-and-tags","Repositories and tags",[10,276,76,277,279],{},[78,278,5],{}," window lists your repositories with their tags, sizes and who pushed each tag.",[281,282,283,289,295,301,307],"ul",{},[89,284,285,288],{},[78,286,287],{},"Public:"," anyone who can reach the registry may pull it without signing in. Pushing still needs a key.",[89,290,291,294],{},[78,292,293],{},"Immutable tags:"," a pushed tag can’t be moved to another image or deleted.",[89,296,297,300],{},[78,298,299],{},"Delete tag:"," the tag goes at once; the image’s data goes at the next sweep, unless another tag still uses it. Apps already running it keep running.",[89,302,303,306],{},[78,304,305],{},"Operators"," can remove a whole repository, anyone’s, and the removal is recorded.",[89,308,309,310,17,313,316],{},"Signatures and SBOMs attached with ",[14,311,312],{},"cosign",[14,314,315],{},"oras"," are kept beside the image they belong to.",[23,318,320],{"id":319},"from-ci","From CI",[10,322,323,324,329,330,333,334,333,337,333,340,343],{},"A CI run on a Git server connected to Velrix gets a registry key of its own, made for that run and dropped when it ends (",[325,326,328],"a",{"href":327},"\u002Fdocs\u002Fguides\u002Fapps#deploy-from-your-own-git","Apps: deploy from your own Git","). It may push only to the repositories the commit’s deploy rules name, and to their build cache; a commit no rule names gets a key that can only pull. The run finds the address, the key and the cache in its environment (",[14,331,332],{},"VELRIX_REGISTRY",", ",[14,335,336],{},"VELRIX_REGISTRY_USER",[14,338,339],{},"VELRIX_REGISTRY_PASSWORD",[14,341,342],{},"VELRIX_BUILD_CACHE",").",[10,345,346,347,350],{},"The build cache is a repository beside the image’s, ending in ",[14,348,349],{},"\u002Fbuildcache",". Velrix keeps it small: by default, tags older than 14 days go, then the oldest until it holds no more than 5 GB. It counts toward your quota.",[23,352,354],{"id":353},"space","Space",[10,356,357],{},"Each person and organisation has a quota, set by your operator. Layers shared between images count once. When the space is used up, new pushes are refused until you delete tags.",[359,360,361],"style",{},"html pre.shiki code .szw1H, html code.shiki .szw1H{--shiki-light:#702C00;--shiki-default:#702C00;--shiki-dark:#FFB757}html pre.shiki code .semJd, html code.shiki .semJd{--shiki-light:#032563;--shiki-default:#032563;--shiki-dark:#ADDCFF}html pre.shiki code .sklAV, html code.shiki .sklAV{--shiki-light:#A0111F;--shiki-default:#A0111F;--shiki-dark:#FF9492}html pre.shiki code .s7iLA, html code.shiki .s7iLA{--shiki-light:#0E1116;--shiki-default:#0E1116;--shiki-dark:#F0F3F6}html pre.shiki code .ssYy9, html code.shiki .ssYy9{--shiki-light:#023B95;--shiki-default:#023B95;--shiki-dark:#91CBFF}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":113,"searchDepth":216,"depth":363,"links":364},3,[365,366,367,368,369,370],{"id":25,"depth":216,"text":26},{"id":83,"depth":216,"text":84},{"id":262,"depth":216,"text":263},{"id":273,"depth":216,"text":274},{"id":319,"depth":216,"text":320},{"id":353,"depth":216,"text":354},"Your own image registry: push and pull images, namespaces for you and your organisations, quotas.","md",null,{},true,"\u002Fdocs\u002Fguides\u002Fregistry",{"title":5,"description":371},"docs\u002F3.guides\u002F6.registry",false,"vIX6w_THoT4mMXQ1Rnn2xvxlIsUyF2lCEyY7FOmCPJU",[382],{"title":383,"path":384,"stem":385,"children":386,"page":-1},"Docs","\u002Fdocs","docs",[387,391,421,448,479,550,564,586],{"title":388,"path":384,"stem":389,"stub":379,"launchGate":373,"icon":390},"Overview","docs\u002Findex","i-lucide-house",{"title":392,"stub":379,"launchGate":373,"icon":393,"path":394,"stem":395,"children":396,"page":379},"Get started","i-lucide-rocket","\u002Fdocs\u002Fget-started","docs\u002F1.get-started",[397,401,405,409,413,417],{"title":398,"path":399,"stem":400,"stub":379,"launchGate":373},"What Velrix is","\u002Fdocs\u002Fget-started\u002Fwhat-is-velrix","docs\u002F1.get-started\u002F1.what-is-velrix",{"title":402,"path":403,"stem":404,"stub":379,"launchGate":373},"Ways to run Velrix","\u002Fdocs\u002Fget-started\u002Fways-to-run","docs\u002F1.get-started\u002F2.ways-to-run",{"title":406,"path":407,"stem":408,"stub":379,"launchGate":373},"Install from USB","\u002Fdocs\u002Fget-started\u002Finstall","docs\u002F1.get-started\u002F3.install",{"title":410,"path":411,"stem":412,"stub":379,"launchGate":373},"The setup wizard","\u002Fdocs\u002Fget-started\u002Fsetup-wizard","docs\u002F1.get-started\u002F4.setup-wizard",{"title":414,"path":415,"stem":416,"stub":379,"launchGate":373},"Your first app","\u002Fdocs\u002Fget-started\u002Ffirst-app","docs\u002F1.get-started\u002F5.first-app",{"title":418,"path":419,"stem":420,"stub":379,"launchGate":373},"Your first VM","\u002Fdocs\u002Fget-started\u002Ffirst-vm","docs\u002F1.get-started\u002F6.first-vm",{"title":422,"stub":379,"launchGate":373,"icon":423,"path":424,"stem":425,"children":426,"page":379},"Concepts","i-lucide-lightbulb","\u002Fdocs\u002Fconcepts","docs\u002F2.concepts",[427,431,435,439,443],{"title":428,"path":429,"stem":430,"stub":375,"launchGate":373},"Realms","\u002Fdocs\u002Fconcepts\u002Frealms","docs\u002F2.concepts\u002F1.realms",{"title":432,"path":433,"stem":434,"stub":375,"launchGate":373},"Instances and hosts","\u002Fdocs\u002Fconcepts\u002Finstances-and-hosts","docs\u002F2.concepts\u002F2.instances-and-hosts",{"title":436,"path":437,"stem":438,"stub":375,"launchGate":373},"Modules and the mesh","\u002Fdocs\u002Fconcepts\u002Fmodules-and-the-mesh","docs\u002F2.concepts\u002F3.modules-and-the-mesh",{"title":440,"path":441,"stem":442,"stub":375,"launchGate":373},"Organisations, projects and permissions","\u002Fdocs\u002Fconcepts\u002Forgs-projects-permissions","docs\u002F2.concepts\u002F4.orgs-projects-permissions",{"title":444,"path":445,"stem":446,"stub":375,"launchGate":447},"Host pools","\u002Fdocs\u002Fconcepts\u002Fhost-pools","docs\u002F2.concepts\u002F5.host-pools","A1",{"title":449,"stub":379,"launchGate":373,"icon":450,"path":451,"stem":452,"children":453,"page":379},"Guides for users","i-lucide-book-open","\u002Fdocs\u002Fguides","docs\u002F3.guides",[454,458,462,466,470,474,475],{"title":455,"path":456,"stem":457,"stub":379,"launchGate":373},"Apps","\u002Fdocs\u002Fguides\u002Fapps","docs\u002F3.guides\u002F1.apps",{"title":459,"path":460,"stem":461,"stub":375,"launchGate":373},"Machines","\u002Fdocs\u002Fguides\u002Fmachines","docs\u002F3.guides\u002F2.machines",{"title":463,"path":464,"stem":465,"stub":375,"launchGate":373},"Volumes","\u002Fdocs\u002Fguides\u002Fvolumes","docs\u002F3.guides\u002F3.volumes",{"title":467,"path":468,"stem":469,"stub":379,"launchGate":373},"Stacks","\u002Fdocs\u002Fguides\u002Fstacks","docs\u002F3.guides\u002F4.stacks",{"title":471,"path":472,"stem":473,"stub":375,"launchGate":373},"Terminal and cloud shells","\u002Fdocs\u002Fguides\u002Fterminal","docs\u002F3.guides\u002F5.terminal",{"title":5,"path":376,"stem":378,"stub":379,"launchGate":373},{"title":476,"path":477,"stem":478,"stub":375,"launchGate":373},"Kubernetes","\u002Fdocs\u002Fguides\u002Fkubernetes","docs\u002F3.guides\u002F7.kubernetes",{"title":480,"stub":379,"launchGate":373,"icon":481,"path":482,"stem":483,"children":484,"page":379},"Guides for operators","i-lucide-server-cog","\u002Fdocs\u002Foperators","docs\u002F4.operators",[485,489,493,497,501,505,509,513,517,521,526,530,534,538,542,546],{"title":486,"path":487,"stem":488,"stub":379,"launchGate":373},"Updates and maintenance windows","\u002Fdocs\u002Foperators\u002Fupdates","docs\u002F4.operators\u002F1.updates",{"title":490,"path":491,"stem":492,"stub":379,"launchGate":373},"Migrate: moving VMs from VMware","\u002Fdocs\u002Foperators\u002Fmigrate","docs\u002F4.operators\u002F10.migrate",{"title":494,"path":495,"stem":496,"stub":379,"launchGate":373},"Hardware","\u002Fdocs\u002Foperators\u002Fhardware","docs\u002F4.operators\u002F11.hardware",{"title":498,"path":499,"stem":500,"stub":379,"launchGate":373},"Billing","\u002Fdocs\u002Foperators\u002Fbilling","docs\u002F4.operators\u002F12.billing",{"title":502,"path":503,"stem":504,"stub":379,"launchGate":373},"Policies","\u002Fdocs\u002Foperators\u002Fpolicies","docs\u002F4.operators\u002F13.policies",{"title":506,"path":507,"stem":508,"stub":379,"launchGate":373},"Running the realm","\u002Fdocs\u002Foperators\u002Frealm-ops","docs\u002F4.operators\u002F14.realm-ops",{"title":510,"path":511,"stem":512,"stub":379,"launchGate":373},"Public address and app hostnames","\u002Fdocs\u002Foperators\u002Fpublic-address","docs\u002F4.operators\u002F15.public-address",{"title":514,"path":515,"stem":516,"stub":379,"launchGate":373},"Library","\u002Fdocs\u002Foperators\u002Flibrary","docs\u002F4.operators\u002F16.library",{"title":518,"path":519,"stem":520,"stub":379,"launchGate":373},"Backups","\u002Fdocs\u002Foperators\u002Fbackups","docs\u002F4.operators\u002F2.backups",{"title":522,"path":523,"stem":524,"stub":375,"launchGate":525},"Availability and drain","\u002Fdocs\u002Foperators\u002Favailability","docs\u002F4.operators\u002F3.availability","A1, A2, A3",{"title":527,"path":528,"stem":529,"stub":375,"launchGate":373},"Federation","\u002Fdocs\u002Foperators\u002Ffederation","docs\u002F4.operators\u002F4.federation",{"title":531,"path":532,"stem":533,"stub":375,"launchGate":373},"Licensing","\u002Fdocs\u002Foperators\u002Flicensing","docs\u002F4.operators\u002F5.licensing",{"title":535,"path":536,"stem":537,"stub":375,"launchGate":373},"Branding: look and design","\u002Fdocs\u002Foperators\u002Fbranding","docs\u002F4.operators\u002F6.branding",{"title":539,"path":540,"stem":541,"stub":375,"launchGate":373},"Connectivity","\u002Fdocs\u002Foperators\u002Fconnectivity","docs\u002F4.operators\u002F7.connectivity",{"title":543,"path":544,"stem":545,"stub":375,"launchGate":373},"Logs","\u002Fdocs\u002Foperators\u002Flogs","docs\u002F4.operators\u002F8.logs",{"title":547,"path":548,"stem":549,"stub":379,"launchGate":373},"Directory sync: Entra ID and Okta","\u002Fdocs\u002Foperators\u002Fdirectory-sync","docs\u002F4.operators\u002F9.directory-sync",{"title":551,"stub":379,"launchGate":373,"icon":552,"path":553,"stem":554,"children":555,"page":379},"Reference","i-lucide-library","\u002Fdocs\u002Freference","docs\u002F5.reference",[556,560],{"title":557,"path":558,"stem":559,"stub":379,"launchGate":373},"The API reference in your realm","\u002Fdocs\u002Freference\u002Fin-your-realm","docs\u002F5.reference\u002F1.in-your-realm",{"title":561,"path":562,"stem":563,"stub":379,"launchGate":373},"The velrix command","\u002Fdocs\u002Freference\u002Fcli","docs\u002F5.reference\u002F2.cli",{"title":565,"stub":379,"launchGate":373,"icon":566,"path":567,"stem":568,"children":569,"page":379},"Security and compliance","i-lucide-shield-check","\u002Fdocs\u002Fsecurity","docs\u002F6.security",[570,574,578,582],{"title":571,"path":572,"stem":573,"stub":375,"launchGate":373},"Post-quantum","\u002Fdocs\u002Fsecurity\u002Fpost-quantum","docs\u002F6.security\u002F1.post-quantum",{"title":575,"path":576,"stem":577,"stub":375,"launchGate":373},"GDPR","\u002Fdocs\u002Fsecurity\u002Fgdpr","docs\u002F6.security\u002F2.gdpr",{"title":579,"path":580,"stem":581,"stub":375,"launchGate":373},"NIS2 support","\u002Fdocs\u002Fsecurity\u002Fnis2","docs\u002F6.security\u002F3.nis2",{"title":583,"path":584,"stem":585,"stub":375,"launchGate":373},"Data residency","\u002Fdocs\u002Fsecurity\u002Fdata-residency","docs\u002F6.security\u002F4.data-residency",{"title":587,"path":588,"stem":589,"children":590,"stub":379,"launchGate":373,"icon":592},"Release notes","\u002Fdocs\u002Frelease-notes","docs\u002F7.release-notes\u002Findex",[591],{"title":587,"path":588,"stem":589,"stub":379,"launchGate":373},"i-lucide-scroll-text",[594,596],{"title":471,"path":472,"stem":473,"description":595,"children":-1},"Shells in the browser: into your apps and machines, or a cloud shell already signed in to Velrix.",{"title":476,"path":477,"stem":478,"description":597,"children":-1},"Managed RKE2 or k3s clusters on your machines, and the Kubernetes-compatible API for kubectl."]