|
|
||
|---|---|---|
| README.md | ||
Atticl Docker Registry
Private Docker image registry hosted and managed by Atticl.
Overview
The registry provides private storage for Docker images and is accessible through:
Registry & Web UI: https://registry.cvrf.space
The same URL is used for both the Docker Registry API and the web interface.
Architecture
Internet
│
│ HTTPS
▼
registry.cvrf.space
│
▼
Nginx Proxy Manager
│
▼
Docker Registry UI
│
│ Internal Docker network
▼
Docker Registry
│
▼
./data
The browser only communicates with registry.cvrf.space.
The Registry UI communicates with the Docker Registry internally through the Docker network. This avoids browser mixed-content and CORS problems.
Access
Web interface
Open:
https://registry.cvrf.space
The web interface allows you to browse repositories and tags.
Authentication is required.
Docker Registry API
The Registry API is available at:
https://registry.cvrf.space/v2/
Docker clients use this endpoint automatically when pushing and pulling images.
Authentication
The registry uses HTTP Basic Authentication with an htpasswd file.
Docker clients authenticate with:
docker login registry.cvrf.space
Enter the registry username and password when prompted.
A successful login displays:
Login Succeeded
Do not store registry passwords in this repository.
Pushing Images
Images use the following naming format:
registry.cvrf.space/<project>/<image>:<tag>
For example:
registry.cvrf.space/test/nginx:stable-trixie
Example
Pull an image from Docker Hub:
docker pull nginx:stable-trixie
Tag it for the private registry:
docker tag nginx:stable-trixie registry.cvrf.space/test/nginx:stable-trixie
Push it:
docker push registry.cvrf.space/test/nginx:stable-trixie
A successful push will return a digest similar to:
digest: sha256:...
Pulling Images
Authenticate first:
docker login registry.cvrf.space
Then pull an image:
docker pull registry.cvrf.space/test/nginx:stable-trixie
Run it normally:
docker run registry.cvrf.space/test/nginx:stable-trixie
Repository Naming
Repositories should use a logical project name.
Examples:
registry.cvrf.space/crowware/api:latest
registry.cvrf.space/crowware/frontend:latest
registry.cvrf.space/hostwatch:latest
registry.cvrf.space/servers/minecraft:latest
registry.cvrf.space/test/nginx:stable-trixie
Recommended format:
registry.cvrf.space/<project>/<image>:<tag>
Use descriptive tags where possible.
For example:
:latest
:1.0.0
:1.2.3
:dev
:testing
Avoid relying exclusively on latest for production deployments.
Web UI
The registry uses Joxit's Docker Registry UI.
The UI is available from:
https://registry.cvrf.space
The UI is configured to communicate with the Registry internally rather than exposing the internal Registry address to the browser.
This is important because the public site uses HTTPS.
The browser must not attempt to access:
http://192.168.8.11:5000
Doing so causes a mixed-content error because the main page was loaded over HTTPS.
Reverse Proxy
Nginx Proxy Manager provides the public HTTPS endpoint.
The public hostname is:
registry.cvrf.space
The reverse proxy forwards requests to the Registry UI.
The UI then internally proxies Registry API requests to the Docker Registry.
Conceptually:
Client
│
│ HTTPS
▼
registry.cvrf.space
│
▼
Nginx Proxy Manager
│
▼
Registry UI
│
│ HTTP - internal Docker network
▼
Docker Registry
CORS
The Registry previously required CORS configuration when the browser directly accessed the Registry using:
http://192.168.8.11:5000
This caused problems when the UI was served over HTTPS.
The current configuration avoids this by using the Registry UI's internal reverse proxy.
The browser communicates with a single origin:
https://registry.cvrf.space
Therefore, separate browser-to-registry CORS configuration is not required for the current architecture.
Testing
Test authentication
Log out:
docker logout registry.cvrf.space
Then attempt to pull a private image:
docker pull registry.cvrf.space/test/nginx:stable-trixie
An unauthenticated client should not be able to access the private image.
Log back in:
docker login registry.cvrf.space
Then pull the image again:
docker pull registry.cvrf.space/test/nginx:stable-trixie
The pull should succeed.
Test pushing
Tag an image:
docker tag nginx:stable-trixie registry.cvrf.space/test/nginx:stable-trixie
Push:
docker push registry.cvrf.space/test/nginx:stable-trixie
If the push completes and returns a digest, the registry is functioning correctly.
Existing Test Image
The registry has been tested using:
registry.cvrf.space/test/nginx:stable-trixie
The image was successfully pushed through the HTTPS endpoint.
The registry also contains the alpine test repository.
Troubleshooting
Mixed Content Error
If the browser reports:
Mixed Content
check that the UI is not configured to use:
http://192.168.8.11:5000
The Registry UI should proxy requests internally instead.
The browser should only communicate with:
https://registry.cvrf.space
Docker Login Fails
Check the hostname:
docker login registry.cvrf.space
Make sure the username and password are correct.
Also verify that the HTTPS endpoint is reachable.
Push Fails
First verify authentication:
docker login registry.cvrf.space
Then retry the push:
docker push registry.cvrf.space/<project>/<image>:<tag>
If large image pushes fail, check the reverse proxy configuration and its maximum request/body size.
Image Doesn't Appear in the UI
Verify that the push completed successfully.
Then refresh the Registry UI:
https://registry.cvrf.space
Also verify that the image was pushed to the expected repository name.
For example:
registry.cvrf.space/test/nginx
is different from:
registry.cvrf.space/nginx
Security
The registry should be accessed through HTTPS.
Do not expose the registry's unauthenticated HTTP endpoint directly to the internet.
Registry credentials should never be committed to Git.
The htpasswd file contains password hashes and should be protected.
The registry's image storage should also be backed up if the images are important.
Future Improvements
Potential future additions:
- Automated image builds through Forgejo Actions
- Automatic Docker image publishing after Git pushes
- Image cleanup policies
- Automated backups
- Separate development and production repositories
- Image vulnerability scanning
- Resource monitoring
- Automated registry updates
Quick Reference
Login
docker login registry.cvrf.space
Tag
docker tag <local-image> registry.cvrf.space/<project>/<image>:<tag>
Push
docker push registry.cvrf.space/<project>/<image>:<tag>
Pull
docker pull registry.cvrf.space/<project>/<image>:<tag>
Web UI
https://registry.cvrf.space
Registry API
https://registry.cvrf.space/v2/