# Using a Private Container Registry

By default, Rapids that use the **Docker image** deployment type pull from public
registries. To deploy a private image (e.g. from `ghcr.io`, Docker Hub private,
or `registry.gitlab.com`), you create a **Registry Credential** and attach it to
your Rapid.

## DanubeData also operates a hosted registry

DanubeData operates a hosted registry at `cr.danubedata.ro` for your team's
first-party images — see [Container Registry](https://docs.danubedata.ro/container-registry).
This page covers the **upstream** case where you want a Rapid to pull from
someone else's private registry (GHCR, Docker Hub private, GitLab CR, etc.).

## Create a credential

1. Go to **Security → Registry Credentials → New credential**.
2. Pick a memorable **Name** (e.g. `ghcr-prod`).
3. Enter the **Registry host** (e.g. `ghcr.io`).
4. Enter your **Username** and **Token / Password**. For GHCR, generate a
   Personal Access Token with the `read:packages` scope.
5. Save.

Your token is stored encrypted in our database and is never written to our internal GitOps
repository — only a reference to the credential is committed.

## Attach the credential to a Rapid

On the Create or Edit page for a Rapid with deployment type **Docker image**,
choose your credential from the **Registry credential** dropdown. Save / deploy.

The platform creates a `kubernetes.io/dockerconfigjson` Secret in your tenant
namespace and references it from the Knative Service's `imagePullSecrets`.

## Rotating a token

Edit the credential and enter a new token. **All Rapids using that credential
pick up the new token on their next deploy or cold start.** Running pods keep
their already-pulled image until the next pod restart — Kubernetes does not
re-pull mid-run.

## Common errors

- **`ImagePullBackOff` after deploy** — token expired, wrong username, or the
  image doesn't exist. Check the Rapid's status surface for the underlying
  Kubernetes event.
- **`Cannot delete: N Rapid(s) still use this credential`** — detach the
  credential from each Rapid (set "Registry credential" to *None* on Edit and
  redeploy) before deleting the credential row.

## Limitations (v1)

- Static username + token only. AWS ECR temporary tokens, GCP Workload Identity,
  and Azure ACR managed identity are not yet supported.
- A single image cannot pull with two credentials at once.
- The "delete credential" flow blocks until you detach all references. We do
  not auto-detach.
