A container registry is where build systems publish images and Kubernetes retrieves them to start applications. CNCF Distribution provides the server for that storage and delivery path, letting a team operate its own registry endpoint. It is useful when you need control over where images are kept and how clients reach them. A basic registry does not automatically include the enterprise administration, signing or scanning features of a separate registry-management product.
Deployment and operating notes
The old page mixes Docker Trusted Registry’s commercial features with the open-source registry server. Current CNCF Distribution documentation describes a server for storing and distributing container images and other content. LDAP integration, vulnerability scanning and enterprise workflow should not be inferred merely from deploying the registry chart.
Choose whether a basic registry, a registry-management platform or a hosted service fits the required authentication, scanning, replication and support. For an existing registry, inventory storage backend, external URL, authentication service, certificates and client trust configuration. Preserve blob data and metadata, and verify digest-addressed pulls as well as pushes before switching clients. Plan garbage collection with the version-specific procedure; deleting tags and reclaiming blobs are not equivalent operations. Test large or interrupted uploads and deployment pulls from the actual cluster network. Keep the old endpoint available until manifests and referenced layers are confirmed at the destination. A chart rollback does not recreate blobs removed during cleanup.
Historical upstream link check · 2026-10-09
The recorded upstream address responded successfully (HTTP 200) on 2026-10-09. Link availability does not certify the historical installation instructions or current security support. The recovered article mixes the open-source Registry with Docker Trusted Registry; the linked CNCF Distribution documentation applies to the open-source implementation.
Website availability is separate from project, chart and image support. Use the current guidance and primary sources on this page to assess the distribution.
Historical Kubedex content
Preserved for context. Commands, versions, prices and results below reflect the original research.
Docker Trusted Registry (DTR) is a commercial product that enables complete image management workflow, featuring LDAP integration, image signing, security scanning, and integration with Universal Control Plane. DTR is offered as an add-on to Docker Enterprise subscriptions of Standard or higher. The Registry is a stateless, highly scalable server-side application that stores and lets you distribute Docker images. The Registry is open-source, under the permissive Apache license.
Why use it
You should use the Registry if you want to:
tightly control where your images are being stored
fully own your images distribution pipeline
integrate image storage and distribution tightly into your in-house development workflow
Alternatives
Users looking for a zero maintenance, ready-to-go solution are encouraged to head-over to the Docker Hub, which provides a free-to-use, hosted Registry, plus additional features (organization accounts, automated builds, and more).
Users looking for a commercially supported version of the Registry should look into Docker Trusted Registry.
Use cases
Running your own Registry is a great solution to integrate with and complement your CI/CD system. In a typical workflow, a commit to your source revision control system would trigger a build on your CI system, which would then push a new image to your Registry if the build is successful. A notification from the Registry would then trigger a deployment on a staging environment, or notify other systems that a new image is available.
It’s also an essential component if you want to quickly deploy a new image over a large cluster of machines.
Finally, it’s the best way to distribute images inside an isolated network.
Requirements
You absolutely need to be familiar with Docker, specifically with regard to pushing and pulling images. You must understand the difference between the daemon and the cli, and at least grasp basic concepts about networking.
Also, while just starting a registry is fairly easy, operating it in a production environment requires operational skills, just like any other service. You are expected to be familiar with systems availability and scalability, logging and log processing, systems monitoring, and security 101. Strong understanding of http and overall network communications, plus familiarity with golang are certainly useful as well for advanced operations or hacking.
Sources & further reading
Spotted something that needs another look?
Help improve this page →