Documentation
Find a file
cvrf 6ac81ea4e7 Im stupid okay?
Signed-off-by: cvrf <cvrf@cvrf.space>
2026-10-08 07:50:09 +00:00
README.md Im stupid okay? 2026-10-08 07:50:09 +00:00

Atticl Docker Registry

Private Docker image registry hosted and managed by Atticl.

Overview

The registry provides private storage for Docker images and is accessible through:

Registry & Web UI: https://registry.cvrf.space

The same URL is used for both the Docker Registry API and the web interface.

Architecture

                         Internet
                            │
                            │ HTTPS
                            ▼
                 registry.cvrf.space
                            │
                            ▼
                  Nginx Proxy Manager
                            │
                            ▼
                  Docker Registry UI
                            │
                            │ Internal Docker network
                            ▼
                    Docker Registry
                            │
                            ▼
                         ./data

The browser only communicates with registry.cvrf.space.

The Registry UI communicates with the Docker Registry internally through the Docker network. This avoids browser mixed-content and CORS problems.

Access

Web interface

Open:

https://registry.cvrf.space

The web interface allows you to browse repositories and tags.

Authentication is required.

Docker Registry API

The Registry API is available at:

https://registry.cvrf.space/v2/

Docker clients use this endpoint automatically when pushing and pulling images.

Authentication

The registry uses HTTP Basic Authentication with an htpasswd file.

Docker clients authenticate with:

docker login registry.cvrf.space

Enter the registry username and password when prompted.

A successful login displays:

Login Succeeded

Do not store registry passwords in this repository.

Pushing Images

Images use the following naming format:

registry.cvrf.space/<project>/<image>:<tag>

For example:

registry.cvrf.space/test/nginx:stable-trixie

Example

Pull an image from Docker Hub:

docker pull nginx:stable-trixie

Tag it for the private registry:

docker tag nginx:stable-trixie registry.cvrf.space/test/nginx:stable-trixie

Push it:

docker push registry.cvrf.space/test/nginx:stable-trixie

A successful push will return a digest similar to:

digest: sha256:...

Pulling Images

Authenticate first:

docker login registry.cvrf.space

Then pull an image:

docker pull registry.cvrf.space/test/nginx:stable-trixie

Run it normally:

docker run registry.cvrf.space/test/nginx:stable-trixie

Repository Naming

Repositories should use a logical project name.

Examples:

registry.cvrf.space/crowware/api:latest
registry.cvrf.space/crowware/frontend:latest
registry.cvrf.space/hostwatch:latest
registry.cvrf.space/servers/minecraft:latest
registry.cvrf.space/test/nginx:stable-trixie

Recommended format:

registry.cvrf.space/<project>/<image>:<tag>

Use descriptive tags where possible.

For example:

:latest
:1.0.0
:1.2.3
:dev
:testing

Avoid relying exclusively on latest for production deployments.

Web UI

The registry uses Joxit's Docker Registry UI.

The UI is available from:

https://registry.cvrf.space

The UI is configured to communicate with the Registry internally rather than exposing the internal Registry address to the browser.

This is important because the public site uses HTTPS.

The browser must not attempt to access:

http://192.168.8.11:5000

Doing so causes a mixed-content error because the main page was loaded over HTTPS.

Reverse Proxy

Nginx Proxy Manager provides the public HTTPS endpoint.

The public hostname is:

registry.cvrf.space

The reverse proxy forwards requests to the Registry UI.

The UI then internally proxies Registry API requests to the Docker Registry.

Conceptually:

Client
  │
  │ HTTPS
  ▼
registry.cvrf.space
  │
  ▼
Nginx Proxy Manager
  │
  ▼
Registry UI
  │
  │ HTTP - internal Docker network
  ▼
Docker Registry

CORS

The Registry previously required CORS configuration when the browser directly accessed the Registry using:

http://192.168.8.11:5000

This caused problems when the UI was served over HTTPS.

The current configuration avoids this by using the Registry UI's internal reverse proxy.

The browser communicates with a single origin:

https://registry.cvrf.space

Therefore, separate browser-to-registry CORS configuration is not required for the current architecture.

Testing

Test authentication

Log out:

docker logout registry.cvrf.space

Then attempt to pull a private image:

docker pull registry.cvrf.space/test/nginx:stable-trixie

An unauthenticated client should not be able to access the private image.

Log back in:

docker login registry.cvrf.space

Then pull the image again:

docker pull registry.cvrf.space/test/nginx:stable-trixie

The pull should succeed.

Test pushing

Tag an image:

docker tag nginx:stable-trixie registry.cvrf.space/test/nginx:stable-trixie

Push:

docker push registry.cvrf.space/test/nginx:stable-trixie

If the push completes and returns a digest, the registry is functioning correctly.

Existing Test Image

The registry has been tested using:

registry.cvrf.space/test/nginx:stable-trixie

The image was successfully pushed through the HTTPS endpoint.

The registry also contains the alpine test repository.

Troubleshooting

Mixed Content Error

If the browser reports:

Mixed Content

check that the UI is not configured to use:

http://192.168.8.11:5000

The Registry UI should proxy requests internally instead.

The browser should only communicate with:

https://registry.cvrf.space

Docker Login Fails

Check the hostname:

docker login registry.cvrf.space

Make sure the username and password are correct.

Also verify that the HTTPS endpoint is reachable.

Push Fails

First verify authentication:

docker login registry.cvrf.space

Then retry the push:

docker push registry.cvrf.space/<project>/<image>:<tag>

If large image pushes fail, check the reverse proxy configuration and its maximum request/body size.

Image Doesn't Appear in the UI

Verify that the push completed successfully.

Then refresh the Registry UI:

https://registry.cvrf.space

Also verify that the image was pushed to the expected repository name.

For example:

registry.cvrf.space/test/nginx

is different from:

registry.cvrf.space/nginx

Security

The registry should be accessed through HTTPS.

Do not expose the registry's unauthenticated HTTP endpoint directly to the internet.

Registry credentials should never be committed to Git.

The htpasswd file contains password hashes and should be protected.

The registry's image storage should also be backed up if the images are important.

Future Improvements

Potential future additions:

  • Automated image builds through Forgejo Actions
  • Automatic Docker image publishing after Git pushes
  • Image cleanup policies
  • Automated backups
  • Separate development and production repositories
  • Image vulnerability scanning
  • Resource monitoring
  • Automated registry updates

Quick Reference

Login

docker login registry.cvrf.space

Tag

docker tag <local-image> registry.cvrf.space/<project>/<image>:<tag>

Push

docker push registry.cvrf.space/<project>/<image>:<tag>

Pull

docker pull registry.cvrf.space/<project>/<image>:<tag>

Web UI

https://registry.cvrf.space

Registry API

https://registry.cvrf.space/v2/