Container Registry
Container Registry stores Docker and OCI images for a workspace. Each registry has its own namespace on the shared IBEE registry endpoint:
Any Docker- or OCI-compatible client works, including Docker, Podman, containerd, Kubernetes, and CI systems. Every image you push is scanned for vulnerabilities and gets a software bill of materials (SBOM) automatically.
Container Registry is enabled per organization. If Container Registry is not in your sidebar, contact support to request access.
Before you begin
- An organization with billing set up (Add billing). Each registry is created with a paid storage plan.
- A workspace to hold the registry.
- Docker (or another OCI client) on the machine that pushes or pulls images.
Create a registry
Open Container Registry
Select your organization and workspace, then click Container Registry under Infrastructure in the sidebar. Click Create registry.
Name the registry
Enter a Registry name. The portal checks availability as you type.
- 3–48 characters: lowercase letters, numbers, and hyphens.
- Must start with a letter and end with a letter or number.
- Names are unique across IBEE and cannot be changed later. A deleted registry’s name is never reassigned.
- Names that are reserved for the platform, such as names starting with
ibee-, are rejected.
Choose visibility
Pushing always requires an access token with push permission, whatever the visibility. Outbound bandwidth from anonymous pulls of a public registry is billed to your workspace.
Registry list and status
The registry list shows each registry’s name and endpoint, visibility, status, and creation date.
Click a registry to open it. The detail page has four tabs: Overview, Security, Metrics, and Settings.
Create a registry access token
Docker clients authenticate with a registry access token, not with your IBEE account password or a platform API token.
Use Pull only tokens for anything that only runs images. Give push access only to the pipelines that build them.
Rotate or revoke a token
The Registry access tokens tab lists every token with its registry, permission, creation date, and status (Active, Expired, or Revoked).
- Rotate issues a new access token and immediately stops the current one from working. The new token is shown once.
- Revoke removes the token’s access immediately. Workloads that use it can no longer pull or push.
Log in, push, and pull
Log in with the registry username and access token. The username contains a $ character, so wrap it in single quotes on the command line:
In CI, keep the token in a secret such as IBEE_REGISTRY_TOKEN and pass it on standard input so it never appears in logs or shell history:
Build and push an image:
Push an image you already have locally:
Pull by tag, or by digest for an immutable reference:
A repository is created automatically on its first push. The Overview tab’s Docker instructions section shows these commands with your registry’s endpoint filled in.
https://registry.ibee.ai/v2/ returns 401 Unauthorized until a client logs in. That response is expected and confirms the endpoint is reachable.
Pull from Kubernetes
Create an image pull secret from a Pull only token and reference it from your workloads:
Repositories and images
The Overview tab lists the registry’s repositories with their artifact count, pull count, and last update time. Open a repository to see one row per image digest; tags are shown as aliases of the digest they point to. Open an image to copy its pull command by tag or by digest.
Review image security
Open a registry and click the Security tab. Vulnerability scanning and SBOM generation run automatically on every push, so there is nothing to configure.
Vulnerabilities
The summary shows the number of findings by severity. Click a severity to filter by it. You can also filter by:
- CVE or advisory ID
- Severity
- Repository
- Image tag or digest
- Package
Each finding shows the CVE, severity, repository and image, affected package, installed version, fixed version, and CVSS score. To scan an image again, click Rescan on a finding, or Rescan artifact in its details. The rescan runs against the exact image digest, and existing results stay visible until it completes. Rescanning requires write access to the workspace.
SBOMs
Select a repository to list its SBOMs, one per image digest. Several tags that point to the same digest share one row. Each row shows the SBOM status, when it was generated, its format (SPDX or CycloneDX), the package count, and the platform.
Click Components to browse an SBOM. Search by name, version, license, supplier, or package URL, and inspect each package’s type, license, supplier, and dependency relationships.
Monitor usage
The Metrics tab shows storage used, storage quota, quota utilization, and outbound bandwidth, with a bandwidth chart over the last 24 hours, 7 days, or 30 days.
Upgrade the storage plan
The Settings tab shows the current plan, its quota, and the outbound bandwidth price. To get more space, choose a larger plan under Upgrade storage plan and click Upgrade plan. While the change is applied, the tab shows Upgrade in progress. Plans can only be upgraded; downgrades are not supported.
Billing
- Storage is billed monthly for the plan you choose.
- Outbound bandwidth is billed per GB. Private and public registries have separate rates, shown on the create page and on the Settings tab.
Delete a registry
In the registry list, click the delete icon on the registry’s row and confirm Delete registry. Deletion permanently removes the registry’s repositories, images, tags, and the access tokens scoped to it, and the registry name cannot be reused.
A registry must be empty before it can be deleted. If deletion fails because the registry still contains images, contact support to empty it.
Related pages
- API Tokens
- Cloud VMs
- Secret Manager: store registry credentials for deployment pipelines
