CONTAINERS / A CONCEPT NOTE
Container Registry
where container images are stored, versioned, and scanned
Overview · mechanism
pitfall · examples
01 / THE SHORT VERSION
The idea in a few sentences.
A container registry stores and serves Docker images. Docker Hub, ECR, GCR, GHCR, and self-hosted registries like Harbor. Images are tagged by version or commit SHA, and registries typically offer vulnerability scanning, access control, and retention policies. Your CI pushes images here; your CD pulls them for deployment.
02 / FOLLOW THE MECHANISM
How a registry serves an image
CI pipeline
builds an image and pushes it with
docker push ghcr.io/myorg/myapp:v1.2.3.Registry
stores each layer as a content-addressed blob. The manifest maps layer digests to the tag.
Scanner
compares layer contents against CVE databases (Trivy, Grype, Snyk) and generates a report.
CD pipeline
pulls the exact image digest (
myapp@sha256:abc...) for deployment — not the mutable tag.
04 / COMMAND NOTES
Read the command, then the result.
Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.
pull an image by digest
docker pull ghcr.io/myorg/myapp@sha256:abc123...The ellipsis omits required code or values. This sketch is not runnable as written.
scan an image for vulnerabilities
trivy image ghcr.io/myorg/myapp:v1.2.305 / CHECK YOURSELF
Could you explain Container Registry to a teammate?
Try it out loud in two sentences: what it is, and the one detail that changes the picture. If you stall, the gap is the part to reread.
Up next in Containers & KubernetesKubernetes Ingressrouting external traffic to services inside your cluster