Container Registry
A container registry is a service that stores, versions and distributes container images, letting build pipelines push images and container runtimes or Kubernetes nodes pull them through a standard API.
A container registry is a storage and distribution service for container images. Build systems push images to a registry, and container runtimes and Kubernetes nodes pull them when starting workloads. Registries organise images into repositories, track tags and digests, and implement the OCI Distribution Specification, the standard API that tools use to push and pull images.
Public registries such as Docker Hub host open-source and vendor images, while organisations typically run private registries for their own software, either as managed cloud services such as Amazon ECR, Azure Container Registry and Google Artifact Registry, or self-hosted with projects such as Harbor. Sites with limited or no internet connectivity, including many plant networks, use local registry mirrors so that edge clusters can still pull approved images.
The registry is part of the software supply chain, so access should be controlled with role-based permissions and short-lived credentials. Common controls include vulnerability scanning on push, image signing and verification, retention rules that remove unused images, and immutable tags so that a released version cannot be silently overwritten. Pull rate limits on public registries are another reason to cache dependencies locally.
Key points
- Implements the OCI Distribution Specification for pushing and pulling images
- Managed options include Amazon ECR, Azure Container Registry and Google Artifact Registry
- Local mirrors let sites with restricted connectivity pull approved images
- Scanning, signing and immutable tags protect the software supply chain
Where AiVibe comes in
AiVibe Software Services delivers cloud solutions on AWS, Microsoft Azure, Google Cloud or on-premise, together with cloud security, legacy modernisation, data analytics and AI and machine learning services.