CONTAINERS / A CONCEPT NOTE

Container Registry

where container images are stored, versioned, and scanned

~70 sec read

Overview · mechanism
pitfall · examples

01 / THE SHORT VERSION

The idea in a few sentences.

A container registry stores and serves Docker images. Docker Hub, ECR, GCR, GHCR, and self-hosted registries like Harbor. Images are tagged by version or commit SHA, and registries typically offer vulnerability scanning, access control, and retention policies. Your CI pushes images here; your CD pulls them for deployment.

02 / FOLLOW THE MECHANISM

How a registry serves an image

  1. CI pipeline

    builds an image and pushes it with docker push ghcr.io/myorg/myapp:v1.2.3.

  2. Registry

    stores each layer as a content-addressed blob. The manifest maps layer digests to the tag.

  3. Scanner

    compares layer contents against CVE databases (Trivy, Grype, Snyk) and generates a report.

  4. CD pipeline

    pulls the exact image digest (myapp@sha256:abc...) for deployment — not the mutable tag.

04 / COMMAND NOTES

Read the command, then the result.

Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.

EXAMPLE 01 · INCOMPLETE SKETCH

pull an image by digest

docker pull ghcr.io/myorg/myapp@sha256:abc123...

The ellipsis omits required code or values. This sketch is not runnable as written.

EXAMPLE 02 · REFERENCE

scan an image for vulnerabilities

trivy image ghcr.io/myorg/myapp:v1.2.3

Explore command anatomy in the CLI lab