Hanzo Registry is a private Docker container registry running Docker Distribution (registry:2) on hanzo-k8s, authenticated via Hanzo IAM token-based auth.
Category: Hanzo Ecosystem Related Skills: hanzo/hanzo-id.md, hanzo/hanzo-platform.md, hanzo/hanzo-universe.md
Hanzo Registry is a private Docker container registry running Docker Distribution (registry:2) on hanzo-k8s, authenticated via Hanzo IAM token-based auth. It carries container images and Helm charts, org-namespaced as <host>/<org>/<app>. Live at oci.hanzo.ai.
hanzo.id/v1/iam/registry/tokenhanzo namespace on hanzo-k8sregistry:2 (Docker Distribution)Repo: hanzoai/registry (Apache 2.0).
hanzo namespacesigning.crt / signing.key) as K8s secret registry-signing-keys3-credentials secret| Item | Value | |------|-------| | Endpoint | oci.hanzo.ai | | Repository path | oci.hanzo.ai/<org>/<app> | | Internal port | 5000 (ClusterIP) | | Auth realm | https://hanzo.id/v1/iam/registry/token | | Auth service | oci.hanzo.ai | | Token issuer | hanzo-iam | | Storage | S3 (hanzoai/s3) | | K8s namespace | hanzo | | Repo | github.com/hanzoai/registry | | License | Apache 2.0 |
# Login (uses Hanzo IAM credentials)
docker login oci.hanzo.ai
# Push an image — repositories are org-namespaced
docker tag myapp:latest oci.hanzo.ai/hanzoai/myapp:latest
docker push oci.hanzo.ai/hanzoai/myapp:latest
# Pull an image
docker pull oci.hanzo.ai/hanzoai/myapp:latest
# Generate a self-signed signing certificate (10-year validity)
make generate-cert
# Create the K8s secret from local cert files
make create-secret
# Deploy to hanzo-k8s
make deploy
# Check deployment status
make status
# Tail logs
make logs
# Restart pods
make restart
┌─────────────────┐ ┌──────────────────┐ ┌─────────────────┐
│ Docker Client │────>│ oci.hanzo.ai │────>│ Hanzo IAM │
│ (push/pull) │ │ (registry:2) │ │ (token realm) │
└─────────────────┘ └────────┬─────────┘ └─────────────────┘
│
┌──────┴─────────┐
│ hanzoai/s3 │
│ (object store) │
└────────────────┘
oci.hanzo.aihanzo.id/v1/iam/registry/token)hanzo-iam)signing.crt mounted from K8s secretThe auth and http stanzas of config.yml — the storage driver is S3, configured from the s3-credentials secret:
version: 0.1
http:
addr: :5000
headers:
X-Content-Type-Options: [nosniff]
Access-Control-Allow-Origin: ['https://oci.hanzo.ai']
Access-Control-Allow-Methods: ['HEAD', 'GET', 'OPTIONS', 'DELETE']
auth:
token:
realm: https://hanzo.id/v1/iam/registry/token
service: oci.hanzo.ai
issuer: hanzo-iam
rootcertbundle: /etc/registry-signing/signing.crt
registry:2 image, 100m/128Mi request, 500m/512Mi limitregistry-signing-key with signing.crt mounted to /etc/registry-signing/s3-credentials (KMS-synced) for the object storeThe deploy.yml workflow triggers on push to main (when k8s/ or config.yml change) or manual dispatch:
doctl kubernetes cluster kubeconfig save hanzo-k8skubectl apply -f k8s/)| Issue | Cause | Solution | |-------|-------|----------| | 401 on push/pull | Missing or expired IAM token | docker login oci.hanzo.ai | | Certificate error | signing.crt not mounted | Verify registry-signing-key secret exists | | Push denied to a bare name | Repositories are org-namespaced | Tag as oci.hanzo.ai/<org>/<app> | | CORS errors | Browser request blocked | Check Access-Control-Allow-Origin in config.yml |
hanzo/hanzo-id.md - IAM and authentication (token realm)hanzo/hanzo-platform.md - PaaS deployment platformhanzo/hanzo-universe.md - Production K8s infrastructurehanzo/hanzo-kms.md - Secret management (deploy credentials)Last Updated: 2026-03-13 Category: Hanzo Ecosystem Related: registry, docker, containers, iam Prerequisites: Docker CLI, Kubernetes, Hanzo IAM credentials