Container images
Push an image
Push your own images under the names your admin reserved.
You can push when both of these are true:
- Your role is publisher, approver or admin. A pipeline usually pushes with a token that belongs to a publisher account.
- The image name is reserved for your company, like everything under
acme/. A reserved name is never pulled from a public registry, so nobody can publish a lookalike with the same name and have it pulled instead.
Build the image with packages.example.com in front of its name, sign in with the publisher token, and push it:
$ cat Dockerfile FROM packages.example.com/node:22-alpine WORKDIR /app COPY server.js . CMD ["node", "server.js"] $ docker build -t packages.example.com/acme/storefront:1.4.0 . ... #8 exporting to image #8 exporting layers 0.0s done #8 writing image sha256:a78fc97bb96fe2195e45b93ed7d0c17d03074f5b420ce002abf9c4a83600e8be done #8 naming to packages.example.com/acme/storefront:1.4.0 done #8 DONE 0.0s $ echo "$PUBLISH_TOKEN" | docker login packages.example.com -u your-user-name --password-stdin WARNING! Your password will be stored unencrypted in /root/.docker/config.json. Configure a credential helper to remove this warning. See https://docs.docker.com/engine/reference/commandline/login/#credential-stores Login Succeeded $ docker push packages.example.com/acme/storefront:1.4.0 ... b28665727eef: Preparing dbbe8cb33f3c: Preparing 8b919b825a05: Preparing 74d97c428c51: Preparing 74d97c428c51: Waiting 62c29257d759: Pushed 7528ea25b763: Pushed b28665727eef: Pushed dbbe8cb33f3c: Pushed 74d97c428c51: Pushed 8b919b825a05: Pushed 1.4.0: digest: sha256:84d369428612290a8cf291c891e4d93d2f8c501d7f4538171aef252687350889 size: 1571
Captured by running these commands against a real ForgeRepo™.
Tip
In a pipeline, keep the token in a secret variable like PUBLISH_TOKEN. Never put it in the repository or the Dockerfile.
What happens next
- Every layer is scanned for malware before anyone can pull the image. Until the scan is done, a pull says
toomanyrequests: ... is still being scanned for malware. Try again in a few minutes. - A layer the scanner flags is rejected, and a pull says what was found.
- When malware scanning is switched off, an admin releases the image on the Quarantine page before anyone can pull it.
- After that it pulls like any other image. In whitelist mode your admin adds an allow rule for your names.
A pushed tag never moves
Once a tag is pushed, it always means the same image, so the release you tested is the release that runs. Pushing different content under it is refused. Push the change under a new tag, like 1.4.1. The one exception is latest, which moves to whatever you push under it last.
$ docker push packages.example.com/acme/storefront:1.4.0 ... dbbe8cb33f3c: Layer already exists 74d97c428c51: Layer already exists 09952fac6131: Pushed tag invalid: acme/storefront:1.4.0 was pushed before as sha256:84d369428612290a8cf291c891e4d93d2f8c501d7f4538171aef252687350889, and a pushed tag never moves. Push it under a new tag
Captured by running these commands against a real ForgeRepo™.
If the push is refused
$ docker push packages.example.com/acme/storefront:dev ... 62c29257d759: Layer already exists 09952fac6131: Layer already exists 74d97c428c51: Layer already exists denied: your-user-name cannot push here, it needs the publisher, approver or admin role
Captured by running these commands against a real ForgeRepo™.
| The error says | What to do |
|---|---|
| cannot push here, it needs the publisher, approver or admin role | Push with a token owned by a publisher account, or ask an admin to change your role. |
| is not a reserved name | Ask an admin to reserve the name or a namespace like acme/*. |
| a pushed tag never moves | Push under a new tag. |
| pushing needs a token | Run docker login packages.example.com with your user name and a token as the password. |
| nothing is deleted through the registry here | Pushed images are kept. Push a new tag instead of replacing an old one. |