> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.ibee.co.in/docs/infrastructure/container-registry/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.ibee.co.in/_mcp/server. # Container Registry > Store Docker and OCI images in private or public registries, push and pull with registry access tokens, and review vulnerability and SBOM data for every image. Container Registry stores Docker and OCI images for a workspace. Each registry has its own namespace on the shared IBEE registry endpoint: ```text registry.ibee.ai//: ``` Any Docker- or OCI-compatible client works, including Docker, Podman, containerd, Kubernetes, and CI systems. Every image you push is scanned for vulnerabilities and gets a software bill of materials (SBOM) automatically. > **Info** > > Container Registry is enabled per organization. If **Container Registry** is not in your sidebar, contact [support](/docs/support/contact-support) to request access. ## Before you begin * An organization with billing set up ([Add billing](/docs/getting-started/account-setup/add-billing)). Each registry is created with a paid storage plan. * A workspace to hold the registry. * Docker (or another OCI client) on the machine that pushes or pulls images. ## Create a registry ### Open Container Registry Select your organization and workspace, then click **Container Registry** under **Infrastructure** in the sidebar. Click **Create registry**. ### Name the registry Enter a **Registry name**. The portal checks availability as you type. * 3–48 characters: lowercase letters, numbers, and hyphens. * Must start with a letter and end with a letter or number. * Names are unique across IBEE and cannot be changed later. A deleted registry's name is never reassigned. * Names that are reserved for the platform, such as names starting with `ibee-`, are rejected. ### Choose visibility | Visibility | Who can pull | Best for | | --------------------- | ----------------------------------------------------- | ------------------------------- | | **Private** (default) | Only clients that log in with a registry access token | Application and internal images | | **Public** | Anyone, without logging in | Images you publish for others | Pushing always requires an access token with push permission, whatever the visibility. Outbound bandwidth from anonymous pulls of a public registry is billed to your workspace. ### Choose a storage plan Pick a **Storage plan**. Each plan is a fixed monthly storage quota; the portal shows the plans available to your organization with their monthly price and the outbound bandwidth price per GB. Storage uses decimal units (1 GB = 1,000,000,000 bytes). ### Create Review the summary at the bottom of the page and click **Create registry**. The registry appears in the list as **Provisioning**, then **Active**. ## Registry list and status The registry list shows each registry's name and endpoint, visibility, status, and creation date. | Status | Meaning | | ---------------- | ---------------------------------------------------------------------------- | | **Provisioning** | The registry is being created. | | **Active** | Ready for pushes and pulls. | | **Updating** | A change such as a plan upgrade is being applied. | | **Deleting** | Deletion has started. | | **Failed** | The last operation did not complete. Contact support if it does not recover. | Click a registry to open it. The detail page has four tabs: **Overview**, **Security**, **Metrics**, and **Settings**. ## Create a registry access token Docker clients authenticate with a **registry access token**, not with your IBEE account password or a platform API token. ### Open registry access tokens On the registry's **Overview** tab, click **Create access token**. This opens **API Tokens → Registry access tokens** at the organization level with the registry preselected. You can also open that tab directly from the organization's **API Tokens** page. ### Fill in the token details | Field | Description | | ------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **Token name** | Lowercase letters, numbers, and hyphens, for example `production-k8s`. Must be unique among the organization's active tokens. | | **Workspace** and **Registry** | The registry the token can access. | | **Registry permission** | **Pull and push** (the default) for developers and CI pipelines that publish images, or **Pull only** for servers and Kubernetes clusters that only run images. | | **Token expiration** | 7 days, 30 days, 90 days (default), 1 year, or **No expiration**. A token without expiration stays valid until you rotate or revoke it. | Click **Create token**. ### Save the credentials The portal shows the **Registry username** and the **Access token**. The access token is shown only once and cannot be recovered. Store both in your password manager or CI secret store, then click **I've saved my access token**. > **Tip** > > Use **Pull only** tokens for anything that only runs images. Give push access only to the pipelines that build them. ### Rotate or revoke a token The **Registry access tokens** tab lists every token with its registry, permission, creation date, and status (**Active**, **Expired**, or **Revoked**). * **Rotate** issues a new access token and immediately stops the current one from working. The new token is shown once. * **Revoke** removes the token's access immediately. Workloads that use it can no longer pull or push. ## Log in, push, and pull Log in with the registry username and access token. The username contains a `$` character, so wrap it in single quotes on the command line: ```bash docker login registry.ibee.ai --username '' # At the Password prompt, paste the registry access token. ``` In CI, keep the token in a secret such as `IBEE_REGISTRY_TOKEN` and pass it on standard input so it never appears in logs or shell history: ```bash printf '%s' "$IBEE_REGISTRY_TOKEN" | docker login registry.ibee.ai \ --username "$IBEE_REGISTRY_USERNAME" \ --password-stdin ``` Build and push an image: ```bash docker build -t registry.ibee.ai//: . docker push registry.ibee.ai//: ``` Push an image you already have locally: ```bash docker tag : registry.ibee.ai//: docker push registry.ibee.ai//: ``` Pull by tag, or by digest for an immutable reference: ```bash docker pull registry.ibee.ai//: docker pull registry.ibee.ai//@sha256: ``` A repository is created automatically on its first push. The **Overview** tab's **Docker instructions** section shows these commands with your registry's endpoint filled in. > **Info** > > `https://registry.ibee.ai/v2/` returns `401 Unauthorized` until a client logs in. That response is expected and confirms the endpoint is reachable. ### Pull from Kubernetes Create an image pull secret from a **Pull only** token and reference it from your workloads: ```bash kubectl create secret docker-registry ibee-registry \ --docker-server=registry.ibee.ai \ --docker-username='' \ --docker-password='' ``` ```yaml spec: imagePullSecrets: - name: ibee-registry containers: - name: app image: registry.ibee.ai//: ``` ## Repositories and images The **Overview** tab lists the registry's repositories with their artifact count, pull count, and last update time. Open a repository to see one row per image digest; tags are shown as aliases of the digest they point to. Open an image to copy its pull command by tag or by digest. ## Review image security Open a registry and click the **Security** tab. Vulnerability scanning and SBOM generation run automatically on every push, so there is nothing to configure. ### Vulnerabilities The summary shows the number of findings by severity. Click a severity to filter by it. You can also filter by: * **CVE or advisory ID** * **Severity** * **Repository** * **Image tag or digest** * **Package** Each finding shows the CVE, severity, repository and image, affected package, installed version, fixed version, and CVSS score. To scan an image again, click **Rescan** on a finding, or **Rescan artifact** in its details. The rescan runs against the exact image digest, and existing results stay visible until it completes. Rescanning requires write access to the workspace. ### SBOMs Select a repository to list its SBOMs, one per image digest. Several tags that point to the same digest share one row. Each row shows the SBOM status, when it was generated, its format (SPDX or CycloneDX), the package count, and the platform. Click **Components** to browse an SBOM. Search by name, version, license, supplier, or package URL, and inspect each package's type, license, supplier, and dependency relationships. ## Monitor usage The **Metrics** tab shows storage used, storage quota, quota utilization, and outbound bandwidth, with a bandwidth chart over the last 24 hours, 7 days, or 30 days. ## Upgrade the storage plan The **Settings** tab shows the current plan, its quota, and the outbound bandwidth price. To get more space, choose a larger plan under **Upgrade storage plan** and click **Upgrade plan**. While the change is applied, the tab shows **Upgrade in progress**. Plans can only be upgraded; downgrades are not supported. ## Billing * **Storage** is billed monthly for the plan you choose. * **Outbound bandwidth** is billed per GB. Private and public registries have separate rates, shown on the create page and on the **Settings** tab. ## Delete a registry In the registry list, click the delete icon on the registry's row and confirm **Delete registry**. Deletion permanently removes the registry's repositories, images, tags, and the access tokens scoped to it, and the registry name cannot be reused. A registry must be empty before it can be deleted. If deletion fails because the registry still contains images, contact [support](/docs/support/contact-support) to empty it. ## Related pages * [API Tokens](/docs/tools/api-tokens) * [Cloud VMs](/docs/infrastructure/cloud-vms) * [Secret Manager](/docs/tools/secret-manager): store registry credentials for deployment pipelines > Store Docker and OCI images in private or public registries, push and pull with registry access tokens, and review vulnerability and SBOM data for every image.