Docker & Containers — Level by Level›Level 3 · Cheat sheet & self-check

Level 3 — Registries · wrap-up

Cheat sheet & self-check

Every command from this section on one page.

06 · Registries: tag, push & pull

Tag, push, pull

docker tag shop/api:1.4 registry.lab.local:5000/shop/api:1.4Add a name that points at another registry
docker push registry.lab.local:5000/shop/api:1.4Upload the image (only missing layers are sent)
docker pull registry.lab.local:5000/shop/api:1.4Download it on another host
docker pull nginx@sha256:<digest>Pull an exact, immutable image by digest
docker images --digestsShow local images with their digests
docker buildx imagetools inspect nginx:1.27Digest and platforms of a remote image

Log in

docker login registry.lab.local:5000Log in to a private registry (prompts for password)
echo "$TOKEN" | docker login -u ci-bot --password-stdin ghcr.ioNon-interactive login for CI
aws ecr get-login-password --region eu-west-1 | docker login -u AWS --password-stdin <acct>.dkr.ecr.eu-west-1.amazonaws.comLog in to Amazon ECR
docker logout registry.lab.local:5000Remove stored credentials
cat ~/.docker/config.jsonWhere logins are stored (check for credsStore)

Save / load without a registry

docker save -o api-1.4.tar shop/api:1.4Export an image to a tar file
docker load -i api-1.4.tarImport it on an air-gapped host

07 · Run your own private registry

Certificate & password

openssl req -x509 -newkey rsa:4096 -sha256 -days 365 -nodes -keyout certs/domain.key -out certs/domain.crt -subj "/CN=registry.lab.local" -addext "subjectAltName=DNS:registry.lab.local,IP:192.168.56.10"Self-signed certificate with SANs (lab)
docker run --rm --entrypoint htpasswd httpd:2 -Bbn ci-bot 'S3cret!' > auth/htpasswdCreate a bcrypt htpasswd entry
openssl x509 -in certs/domain.crt -noout -text | grep -A1 'Subject Alternative Name'Check the SANs in a certificate

Registry API

curl -u ci-bot https://registry.lab.local:5000/v2/_catalogList repositories
curl -u ci-bot https://registry.lab.local:5000/v2/shop/api/tags/listList tags of one repository
curl -u ci-bot -I -H 'Accept: application/vnd.oci.image.index.v1+json, application/vnd.docker.distribution.manifest.v2+json' https://registry.lab.local:5000/v2/shop/api/manifests/1.4Get the manifest digest (Docker-Content-Digest header)

Clean up

curl -u ci-bot -X DELETE https://registry.lab.local:5000/v2/shop/api/manifests/sha256:<digest>Delete a manifest (needs delete enabled)
docker compose exec registry registry garbage-collect --delete-untagged /etc/docker/registry/config.ymlFree the disk space of deleted images (registry:2 path; registry:3 uses /etc/distribution/config.yml)