Skip to navigation

Container Registry

Container Registry stores Docker and OCI images for a workspace. Each registry has its own namespace on the shared IBEE registry endpoint:

registry.ibee.ai/<registry-name>/<repository>:<tag>

Any Docker- or OCI-compatible client works, including Docker, Podman, containerd, Kubernetes, and CI systems. Every image you push is scanned for vulnerabilities and gets a software bill of materials (SBOM) automatically.

Container Registry is enabled per organization. If Container Registry is not in your sidebar, contact support to request access.

Before you begin

  • An organization with billing set up (Add billing). Each registry is created with a paid storage plan.
  • A workspace to hold the registry.
  • Docker (or another OCI client) on the machine that pushes or pulls images.

Create a registry

1

Open Container Registry

Select your organization and workspace, then click Container Registry under Infrastructure in the sidebar. Click Create registry.

2

Name the registry

Enter a Registry name. The portal checks availability as you type.

  • 3–48 characters: lowercase letters, numbers, and hyphens.
  • Must start with a letter and end with a letter or number.
  • Names are unique across IBEE and cannot be changed later. A deleted registry’s name is never reassigned.
  • Names that are reserved for the platform, such as names starting with ibee-, are rejected.
3

Choose visibility

VisibilityWho can pullBest for
Private (default)Only clients that log in with a registry access tokenApplication and internal images
PublicAnyone, without logging inImages you publish for others

Pushing always requires an access token with push permission, whatever the visibility. Outbound bandwidth from anonymous pulls of a public registry is billed to your workspace.

4

Choose a storage plan

Pick a Storage plan. Each plan is a fixed monthly storage quota; the portal shows the plans available to your organization with their monthly price and the outbound bandwidth price per GB. Storage uses decimal units (1 GB = 1,000,000,000 bytes).

5

Create

Review the summary at the bottom of the page and click Create registry. The registry appears in the list as Provisioning, then Active.

Registry list and status

The registry list shows each registry’s name and endpoint, visibility, status, and creation date.

StatusMeaning
ProvisioningThe registry is being created.
ActiveReady for pushes and pulls.
UpdatingA change such as a plan upgrade is being applied.
DeletingDeletion has started.
FailedThe last operation did not complete. Contact support if it does not recover.

Click a registry to open it. The detail page has four tabs: Overview, Security, Metrics, and Settings.

Create a registry access token

Docker clients authenticate with a registry access token, not with your IBEE account password or a platform API token.

1

Open registry access tokens

On the registry’s Overview tab, click Create access token. This opens API Tokens → Registry access tokens at the organization level with the registry preselected. You can also open that tab directly from the organization’s API Tokens page.

2

Fill in the token details

FieldDescription
Token nameLowercase letters, numbers, and hyphens, for example production-k8s. Must be unique among the organization’s active tokens.
Workspace and RegistryThe registry the token can access.
Registry permissionPull and push (the default) for developers and CI pipelines that publish images, or Pull only for servers and Kubernetes clusters that only run images.
Token expiration7 days, 30 days, 90 days (default), 1 year, or No expiration. A token without expiration stays valid until you rotate or revoke it.

Click Create token.

3

Save the credentials

The portal shows the Registry username and the Access token. The access token is shown only once and cannot be recovered. Store both in your password manager or CI secret store, then click I’ve saved my access token.

Use Pull only tokens for anything that only runs images. Give push access only to the pipelines that build them.

Rotate or revoke a token

The Registry access tokens tab lists every token with its registry, permission, creation date, and status (Active, Expired, or Revoked).

  • Rotate issues a new access token and immediately stops the current one from working. The new token is shown once.
  • Revoke removes the token’s access immediately. Workloads that use it can no longer pull or push.

Log in, push, and pull

Log in with the registry username and access token. The username contains a $ character, so wrap it in single quotes on the command line:

docker login registry.ibee.ai --username '<registry-username>'
# At the Password prompt, paste the registry access token.

In CI, keep the token in a secret such as IBEE_REGISTRY_TOKEN and pass it on standard input so it never appears in logs or shell history:

printf '%s' "$IBEE_REGISTRY_TOKEN" | docker login registry.ibee.ai \
--username "$IBEE_REGISTRY_USERNAME" \
--password-stdin

Build and push an image:

docker build -t registry.ibee.ai/<registry-name>/<repository>:<tag> .
docker push registry.ibee.ai/<registry-name>/<repository>:<tag>

Push an image you already have locally:

docker tag <local-image>:<local-tag> registry.ibee.ai/<registry-name>/<repository>:<tag>
docker push registry.ibee.ai/<registry-name>/<repository>:<tag>

Pull by tag, or by digest for an immutable reference:

docker pull registry.ibee.ai/<registry-name>/<repository>:<tag>
docker pull registry.ibee.ai/<registry-name>/<repository>@sha256:<digest>

A repository is created automatically on its first push. The Overview tab’s Docker instructions section shows these commands with your registry’s endpoint filled in.

https://registry.ibee.ai/v2/ returns 401 Unauthorized until a client logs in. That response is expected and confirms the endpoint is reachable.

Pull from Kubernetes

Create an image pull secret from a Pull only token and reference it from your workloads:

kubectl create secret docker-registry ibee-registry \
--docker-server=registry.ibee.ai \
--docker-username='<registry-username>' \
--docker-password='<access-token>'
spec:
imagePullSecrets:
- name: ibee-registry
containers:
- name: app
image: registry.ibee.ai/<registry-name>/<repository>:<tag>

Repositories and images

The Overview tab lists the registry’s repositories with their artifact count, pull count, and last update time. Open a repository to see one row per image digest; tags are shown as aliases of the digest they point to. Open an image to copy its pull command by tag or by digest.

Review image security

Open a registry and click the Security tab. Vulnerability scanning and SBOM generation run automatically on every push, so there is nothing to configure.

Vulnerabilities

The summary shows the number of findings by severity. Click a severity to filter by it. You can also filter by:

  • CVE or advisory ID
  • Severity
  • Repository
  • Image tag or digest
  • Package

Each finding shows the CVE, severity, repository and image, affected package, installed version, fixed version, and CVSS score. To scan an image again, click Rescan on a finding, or Rescan artifact in its details. The rescan runs against the exact image digest, and existing results stay visible until it completes. Rescanning requires write access to the workspace.

SBOMs

Select a repository to list its SBOMs, one per image digest. Several tags that point to the same digest share one row. Each row shows the SBOM status, when it was generated, its format (SPDX or CycloneDX), the package count, and the platform.

Click Components to browse an SBOM. Search by name, version, license, supplier, or package URL, and inspect each package’s type, license, supplier, and dependency relationships.

Monitor usage

The Metrics tab shows storage used, storage quota, quota utilization, and outbound bandwidth, with a bandwidth chart over the last 24 hours, 7 days, or 30 days.

Upgrade the storage plan

The Settings tab shows the current plan, its quota, and the outbound bandwidth price. To get more space, choose a larger plan under Upgrade storage plan and click Upgrade plan. While the change is applied, the tab shows Upgrade in progress. Plans can only be upgraded; downgrades are not supported.

Billing

  • Storage is billed monthly for the plan you choose.
  • Outbound bandwidth is billed per GB. Private and public registries have separate rates, shown on the create page and on the Settings tab.

Delete a registry

In the registry list, click the delete icon on the registry’s row and confirm Delete registry. Deletion permanently removes the registry’s repositories, images, tags, and the access tokens scoped to it, and the registry name cannot be reused.

A registry must be empty before it can be deleted. If deletion fails because the registry still contains images, contact support to empty it.