Docs / Registry
Container registry
Every account and organization has a Docker registry namespace. Images are named<host>/<owner>/<image>, and the image part may have slashes, likethis-site/acme/tools/builder. Layers are stored in object storage and pulls are served from there directly.
Sign in
Docker signs in with your username and a personal access token (passwords are not accepted):
docker login this-site -u <username>
# Password: igp_... (a token with the packages scope)Create a token under Settings / Tokens, or let the CLI do it:ig login sets up Docker for you.
Push
docker tag my-app this-site/<owner>/my-app:1.0
docker push this-site/<owner>/my-app:1.0The first push creates the image. New images are private. You can push under your own name and under any organization you belong to.
Pull
docker pull this-site/<owner>/my-app:1.0Public images can be pulled without signing in. Private images need docker login first.
Visibility
Each image is public or private on its own, independent of any repository. A private repository can publish a public image, and the reverse. Change it on the image's Settings tab, or withig image visibility <owner>/<image> public.
Linking an image to a repository
On the image's Settings tab you can link it to a repository with the same owner. Collaborators of that repository then get the same access to the image (read collaborators can pull, write collaborators can push). The repository's visibility is not inherited.
Tags, versions and cleanup
- Multi-platform images (manifest lists and OCI indexes) are supported; the tags table lists their platforms.
- Deleting a tag keeps the version, which stays pullable by digest. Deleting the image removes everything.
- Layers no image uses any more are removed from storage automatically after a day.
Limits
- Single layers are capped (10 GB by default). Manifests are capped at 4 MB.
- If the site sits behind Cloudflare's proxy, the registry hostname must be DNS-only, since the proxy rejects uploads over 100 MB.