Skip to main content

Registries & Trust

Beyond your own ArtifactRegistry (see Source & Build), you can reference upstream registries and explicitly trust specific repositories from them. This is how ExternalApplications and base images pull vetted third-party containers.

ExternalRegistry​

Declares an upstream registry the platform may pull from.

# manifests/external-registry/docker-io.yaml
apiVersion: lowops.manifests.v1
kind: ExternalRegistry
metadata:
name: docker-io
organization: fincorp
spec:
type: DOCKER
url: docker.io
# manifests/external-registry/gcr-io.yaml
apiVersion: lowops.manifests.v1
kind: ExternalRegistry
metadata:
name: gcr-io
organization: fincorp
spec:
type: DOCKER
url: gcr.io

TrustedRepository​

Whitelists a specific repository under an external registry as trusted for use. Its name is the repository path; it is linked to its registry via metadata.external-registry.

# manifests/external-registry/gcr-io/trusted-repository/grafana.yaml
apiVersion: lowops.manifests.v1
kind: TrustedRepository
metadata:
name: grafana
external-registry: gcr-io
organization: fincorp
spec:
description: "Grafana observability images, trusted for dashboards."
# manifests/external-registry/docker-io/trusted-repository/mccutchen.yaml
apiVersion: lowops.manifests.v1
kind: TrustedRepository
metadata:
# The repository path under the registry — NOT the full image reference.
# This name is joined as <registry publish url>/<name>/<image>.
name: mccutchen
external-registry: docker-io
organization: fincorp
spec:
description: "go-httpbin test server images."

An ExternalApplication then deploys one of these images by setting spec.trustedRepository to the TrustedRepository name and spec.image to the image within it. The engine composes the full reference as <registry publish url>/<trusted repository>/<image> — so docker-io + mccutchen + go-httpbin resolves to docker.io/mccutchen/go-httpbin. See Application Delivery.