{"slug":"serverless-private-registry","title":"Using a Private Container Registry","description":"By default, Rapids that use the Docker image deployment type pull from public","section":"Features","url":"https://docs.danubedata.ro/serverless-private-registry","markdown_url":"https://docs.danubedata.ro/serverless-private-registry.md","breadcrumbs":[{"title":"Features","slug":null},{"title":"Rapids","slug":"serverless-overview"},{"title":"Private Container Registry","slug":"serverless-private-registry"}],"headings":[{"level":1,"title":"Using a Private Container Registry","id":"using-a-private-container-registry"},{"level":2,"title":"DanubeData also operates a hosted registry","id":"danubedata-also-operates-a-hosted-registry"},{"level":2,"title":"Create a credential","id":"create-a-credential"},{"level":2,"title":"Attach the credential to a Rapid","id":"attach-the-credential-to-a-rapid"},{"level":2,"title":"Rotating a token","id":"rotating-a-token"},{"level":2,"title":"Common errors","id":"common-errors"},{"level":2,"title":"Limitations (v1)","id":"limitations-v1"}],"format":"markdown","word_count":367,"content":"# Using a Private Container Registry\n\nBy default, Rapids that use the **Docker image** deployment type pull from public\nregistries. To deploy a private image (e.g. from `ghcr.io`, Docker Hub private,\nor `registry.gitlab.com`), you create a **Registry Credential** and attach it to\nyour Rapid.\n\n## DanubeData also operates a hosted registry\n\nDanubeData operates a hosted registry at `cr.danubedata.ro` for your team's\nfirst-party images — see [Container Registry](https://docs.danubedata.ro/container-registry).\nThis page covers the **upstream** case where you want a Rapid to pull from\nsomeone else's private registry (GHCR, Docker Hub private, GitLab CR, etc.).\n\n## Create a credential\n\n1. Go to **Security → Registry Credentials → New credential**.\n2. Pick a memorable **Name** (e.g. `ghcr-prod`).\n3. Enter the **Registry host** (e.g. `ghcr.io`).\n4. Enter your **Username** and **Token / Password**. For GHCR, generate a\n   Personal Access Token with the `read:packages` scope.\n5. Save.\n\nYour token is stored encrypted in our database and is never written to our internal GitOps\nrepository — only a reference to the credential is committed.\n\n## Attach the credential to a Rapid\n\nOn the Create or Edit page for a Rapid with deployment type **Docker image**,\nchoose your credential from the **Registry credential** dropdown. Save / deploy.\n\nThe platform creates a `kubernetes.io/dockerconfigjson` Secret in your tenant\nnamespace and references it from the Knative Service's `imagePullSecrets`.\n\n## Rotating a token\n\nEdit the credential and enter a new token. **All Rapids using that credential\npick up the new token on their next deploy or cold start.** Running pods keep\ntheir already-pulled image until the next pod restart — Kubernetes does not\nre-pull mid-run.\n\n## Common errors\n\n- **`ImagePullBackOff` after deploy** — token expired, wrong username, or the\n  image doesn't exist. Check the Rapid's status surface for the underlying\n  Kubernetes event.\n- **`Cannot delete: N Rapid(s) still use this credential`** — detach the\n  credential from each Rapid (set \"Registry credential\" to *None* on Edit and\n  redeploy) before deleting the credential row.\n\n## Limitations (v1)\n\n- Static username + token only. AWS ECR temporary tokens, GCP Workload Identity,\n  and Azure ACR managed identity are not yet supported.\n- A single image cannot pull with two credentials at once.\n- The \"delete credential\" flow blocks until you detach all references. We do\n  not auto-detach.\n","prev":{"title":"Git Deployments","slug":"serverless-git","url":"https://docs.danubedata.ro/serverless-git","markdown_url":"https://docs.danubedata.ro/serverless-git.md","json_url":"https://docs.danubedata.ro/serverless-git.json"},"next":{"title":"Egress IP Addresses","slug":"serverless-egress-ips","url":"https://docs.danubedata.ro/serverless-egress-ips","markdown_url":"https://docs.danubedata.ro/serverless-egress-ips.md","json_url":"https://docs.danubedata.ro/serverless-egress-ips.json"},"index_url":"https://docs.danubedata.ro/index.json"}