Level 3 — Registries · wrap-up
Cheat sheet & self-check
Every command from this section on one page.
Tag, push, pull
docker tag shop/api:1.4 registry.lab.local:5000/shop/api:1.4 | Add a name that points at another registry |
docker push registry.lab.local:5000/shop/api:1.4 | Upload the image (only missing layers are sent) |
docker pull registry.lab.local:5000/shop/api:1.4 | Download it on another host |
docker pull nginx@sha256:<digest> | Pull an exact, immutable image by digest |
docker images --digests | Show local images with their digests |
docker buildx imagetools inspect nginx:1.27 | Digest and platforms of a remote image |
Log in
docker login registry.lab.local:5000 | Log in to a private registry (prompts for password) |
echo "$TOKEN" | docker login -u ci-bot --password-stdin ghcr.io | Non-interactive login for CI |
aws ecr get-login-password --region eu-west-1 | docker login -u AWS --password-stdin <acct>.dkr.ecr.eu-west-1.amazonaws.com | Log in to Amazon ECR |
docker logout registry.lab.local:5000 | Remove stored credentials |
cat ~/.docker/config.json | Where logins are stored (check for credsStore) |
Save / load without a registry
docker save -o api-1.4.tar shop/api:1.4 | Export an image to a tar file |
docker load -i api-1.4.tar | Import it on an air-gapped host |
Certificate & password
openssl req -x509 -newkey rsa:4096 -sha256 -days 365 -nodes -keyout certs/domain.key -out certs/domain.crt -subj "/CN=registry.lab.local" -addext "subjectAltName=DNS:registry.lab.local,IP:192.168.56.10" | Self-signed certificate with SANs (lab) |
docker run --rm --entrypoint htpasswd httpd:2 -Bbn ci-bot 'S3cret!' > auth/htpasswd | Create a bcrypt htpasswd entry |
openssl x509 -in certs/domain.crt -noout -text | grep -A1 'Subject Alternative Name' | Check the SANs in a certificate |
Registry API
curl -u ci-bot https://registry.lab.local:5000/v2/_catalog | List repositories |
curl -u ci-bot https://registry.lab.local:5000/v2/shop/api/tags/list | List tags of one repository |
curl -u ci-bot -I -H 'Accept: application/vnd.oci.image.index.v1+json, application/vnd.docker.distribution.manifest.v2+json' https://registry.lab.local:5000/v2/shop/api/manifests/1.4 | Get the manifest digest (Docker-Content-Digest header) |
Clean up
curl -u ci-bot -X DELETE https://registry.lab.local:5000/v2/shop/api/manifests/sha256:<digest> | Delete a manifest (needs delete enabled) |
docker compose exec registry registry garbage-collect --delete-untagged /etc/docker/registry/config.yml | Free the disk space of deleted images (registry:2 path; registry:3 uses /etc/distribution/config.yml) |