Registries & Trust
Beyond your own ArtifactRegistry (see Source & Build), you can
reference upstream registries and explicitly trust specific repositories from them. This is how
ExternalApplications and base images pull vetted third-party containers.
ExternalRegistry
Declares an upstream registry the platform may pull from.
# manifests/external-registry/docker-io.yaml
apiVersion: lowops.manifests.v1
kind: ExternalRegistry
metadata:
name: docker-io
organization: fincorp
spec:
type: DOCKER
url: docker.io
# manifests/external-registry/gcr-io.yaml
apiVersion: lowops.manifests.v1
kind: ExternalRegistry
metadata:
name: gcr-io
organization: fincorp
spec:
type: DOCKER
url: gcr.io
TrustedRepository
Whitelists a specific repository under an external registry as trusted for use. Its name is the
repository path; it is linked to its registry via metadata.external-registry.
# manifests/external-registry/gcr-io/trusted-repository/grafana.yaml
apiVersion: lowops.manifests.v1
kind: TrustedRepository
metadata:
name: grafana
external-registry: gcr-io
organization: fincorp
spec:
description: "Grafana observability images, trusted for dashboards."
# manifests/external-registry/docker-io/trusted-repository/mccutchen.yaml
apiVersion: lowops.manifests.v1
kind: TrustedRepository
metadata:
# The repository path under the registry — NOT the full image reference.
# This name is joined as <registry publish url>/<name>/<image>.
name: mccutchen
external-registry: docker-io
organization: fincorp
spec:
description: "go-httpbin test server images."
An
ExternalApplicationthen deploys one of these images by settingspec.trustedRepositoryto theTrustedRepositoryname andspec.imageto the image within it. The engine composes the full reference as<registry publish url>/<trusted repository>/<image>— sodocker-io+mccutchen+go-httpbinresolves todocker.io/mccutchen/go-httpbin. See Application Delivery.