Private container registries
Store registry credentials and deploy private container images on Openstead.
Connect a container registry when your service deploys an image that requires authentication. Credentials are scoped to the workspace and kept encrypted.
Requirements
- An owner or admin account in the workspace.
- An authorized, deployed paid service that enables private registry access.
- A public HTTPS registry on port 443.
- A registry username and read-only token permitted to pull the image.
Openstead accepts registry hostnames rather than IP addresses, localhost, or private-network names. Supported endpoint shapes include the HTTPS origin and an optional /v2/ suffix.
Add credentials
- Open Container Registry Credentials in the dashboard.
- Select Add Credential and enter a descriptive name.
- Enter the registry URL, such as
https://ghcr.io. - Enter the registry username and a pull-scoped token.
- Enable Allow use for image deployments and save.
The saved token is hidden. Leave the credential field blank during an edit to retain it. Changing the registry host or username requires a new credential.
Deploy an image
Create or edit a supported service with an image source. Enter an image reference such as:
ghcr.io/example/example-api:2026-09Choose the registry credential saved in this workspace. Set the container's application port and any required variables, complete checkout for the service if needed, then deploy.
The equivalent service configuration fields are:
{
"sourceType": "image",
"buildMethod": "image",
"image": "ghcr.io/example/example-api:2026-09",
"registryId": "00000000-0000-4000-8000-000000000001",
"port": 8000
}Replace the example registryId with the actual UUID returned for your saved registry. The selected credential's host must match the image host. A mismatch is rejected before credentials are sent.
Release and credential management
Use immutable tags or digests for reproducible releases. A moving tag can resolve to different images on later deployments.
Release snapshots retain encrypted registry credentials for rollback. If a registry token is revoked, an older release may no longer be pullable. Rotate credentials, deploy successfully with the replacement, and check rollback requirements before removing access to old images.
Remove registry references from active service configurations before deleting the credential. Disabling a credential prevents its use for new image deployments.
Troubleshooting
| Problem | Check |
|---|---|
| Registry cannot be selected | Workspace entitlement, credential enabled state, and current role. |
| Host mismatch | Image hostname and saved registry URL, including Docker Hub aliases. |
| Image pull denied | Token pull permissions, organization access, repository visibility, and image tag. |
| Container starts but fails health checks | Application port, bind address, required variables, and runtime logs. |
For a source repository, use GitHub deployments instead of storing a GitHub source-access credential in the registry form.