Using a Private Container Registry
By default, Rapids that use the Docker image deployment type pull from public registries. To deploy a private image (e.g. from ghcr.io, Docker Hub private, or registry.gitlab.com), you create a Registry Credential and attach it to your Rapid.
DanubeData also operates a hosted registry
DanubeData operates a hosted registry at cr.danubedata.ro for your team's first-party images — see Container Registry. This page covers the upstream case where you want a Rapid to pull from someone else's private registry (GHCR, Docker Hub private, GitLab CR, etc.).
Create a credential
- Go to Security → Registry Credentials → New credential.
- Pick a memorable Name (e.g.
ghcr-prod). - Enter the Registry host (e.g.
ghcr.io). - Enter your Username and Token / Password. For GHCR, generate a Personal Access Token with the
read:packagesscope. - Save.
Your token is stored encrypted in our database and is never written to our internal GitOps repository — only a reference to the credential is committed.
Attach the credential to a Rapid
On the Create or Edit page for a Rapid with deployment type Docker image, choose your credential from the Registry credential dropdown. Save / deploy.
The platform creates a kubernetes.io/dockerconfigjson Secret in your tenant namespace and references it from the Knative Service's imagePullSecrets.
Rotating a token
Edit the credential and enter a new token. All Rapids using that credential pick up the new token on their next deploy or cold start. Running pods keep their already-pulled image until the next pod restart — Kubernetes does not re-pull mid-run.
Common errors
ImagePullBackOffafter deploy — token expired, wrong username, or the image doesn't exist. Check the Rapid's status surface for the underlying Kubernetes event.Cannot delete: N Rapid(s) still use this credential— detach the credential from each Rapid (set "Registry credential" to None on Edit and redeploy) before deleting the credential row.
Limitations (v1)
- Static username + token only. AWS ECR temporary tokens, GCP Workload Identity, and Azure ACR managed identity are not yet supported.
- A single image cannot pull with two credentials at once.
- The "delete credential" flow blocks until you detach all references. We do not auto-detach.