Using a Private Container Registry

By default, Rapids that use the Docker image deployment type pull from public registries. To deploy a private image (e.g. from ghcr.io, Docker Hub private, or registry.gitlab.com), you create a Registry Credential and attach it to your Rapid.

DanubeData also operates a hosted registry

DanubeData operates a hosted registry at cr.danubedata.ro for your team's first-party images — see Container Registry. This page covers the upstream case where you want a Rapid to pull from someone else's private registry (GHCR, Docker Hub private, GitLab CR, etc.).

Create a credential

  1. Go to Security → Registry Credentials → New credential.
  2. Pick a memorable Name (e.g. ghcr-prod).
  3. Enter the Registry host (e.g. ghcr.io).
  4. Enter your Username and Token / Password. For GHCR, generate a Personal Access Token with the read:packages scope.
  5. Save.

Your token is stored encrypted in our database and is never written to our internal GitOps repository — only a reference to the credential is committed.

Attach the credential to a Rapid

On the Create or Edit page for a Rapid with deployment type Docker image, choose your credential from the Registry credential dropdown. Save / deploy.

The platform creates a kubernetes.io/dockerconfigjson Secret in your tenant namespace and references it from the Knative Service's imagePullSecrets.

Rotating a token

Edit the credential and enter a new token. All Rapids using that credential pick up the new token on their next deploy or cold start. Running pods keep their already-pulled image until the next pod restart — Kubernetes does not re-pull mid-run.

Common errors

  • ImagePullBackOff after deploy — token expired, wrong username, or the image doesn't exist. Check the Rapid's status surface for the underlying Kubernetes event.
  • Cannot delete: N Rapid(s) still use this credential — detach the credential from each Rapid (set "Registry credential" to None on Edit and redeploy) before deleting the credential row.

Limitations (v1)

  • Static username + token only. AWS ECR temporary tokens, GCP Workload Identity, and Azure ACR managed identity are not yet supported.
  • A single image cannot pull with two credentials at once.
  • The "delete credential" flow blocks until you detach all references. We do not auto-detach.