Alauda Container Platform Registry Overview

Alauda Container Platform Registry is the integrated image registry for ACP 4.4 clusters. It provides internal image storage, ImageStream metadata, namespace-based access control, managed service account pull credentials, and image pruning.

Integrated Image Registry

The Registry runs as a cluster workload in image-registry-system and is managed by the Image Registry Operator. The image-registry Deployment serves OCI push and pull traffic, while image metadata is served through the aggregated image.alauda.io/v1 Image API.

Image data and image metadata are stored separately:

Data typeStorage location
Image blobs and manifestsThe storage backend configured in Config/cluster.spec.storage: emptyDir, PVC, S3, Swift, GCS, IBMCOS, or Azure.
Image metadata Image API resources such as Image, ImageStream, ImageStreamTag, ImageStreamImage, and ImageSignature.

The Registry integrates with authentication and Kubernetes authorization. Namespace RoleBindings control who can pull, push, delete, or list image content. Image pruning and registry garbage collection are administrator and Operator-managed operations.

Repository Names

Image repositories are namespace-scoped and use the following format:

<registry-host>/<namespace>/<repository>:<tag>

Repository names must not contain additional path segments after the namespace. For example, registry.example.com/team-a/my-app:v1 is valid, but registry.example.com/team-a/backend/my-app:v1 is not supported.

This restriction is enforced by the Image API, not by the registry. The OCI registry accepts a push to team-a/backend/my-app and stores the manifest, but the Image API cannot represent the repository because an ImageStream name must be a DNS-1123 subdomain. Such an image has no ImageStream, Image, or ImageStreamTag metadata and is not visible to Registry workflows. Always use exactly one repository segment after the namespace.

Common Terms

TermMeaning
Image repositoryA namespace-scoped collection of image tags and digests, addressed as <namespace>/<repository>:<tag>.
ImageStream Image API resource that records tag specifications and tag history for a repository.
ImageCluster-scoped image metadata for a digest.
ImagePrunerSingleton custom resource that configures scheduled prune jobs.
Managed pull secretA service account pull credential generated and injected by the Operator.
Registry storageThe backend that stores image blobs and manifests.

Automatic Image Pruning

The Registry uses imagepruners.imageregistry.operator.alauda.io/cluster to configure scheduled pruning. The Operator renders an image-pruner CronJob that runs ac adm prune images with the configured retention policy.

Pruning removes unused image metadata first. Registry garbage collection reclaims storage after metadata is removed.

Operational Notes

  • Registry resources use the API groups image.alauda.io/v1 and imageregistry.operator.alauda.io/v1.
  • The Registry uses Image API resources such as Image, ImageStream, ImageStreamTag, and ImageSignature, plus the Operator resource ImagePruner.
  • Use ac for Registry workflows.