registry

package
v0.136.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 27, 2026 License: Apache-2.0 Imports: 13 Imported by: 0

Documentation

Overview

Package registry asks a container registry whether it will serve an image's manifest to this machine, with the credentials a scanner running here would use.

One request per image, for the manifest and never a layer, so the answer costs what the first step of a pull costs. It answers "can a scan reach this image", not "what is in it".

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type Client

type Client struct {
	// HTTP makes the requests. nil means a client honoring the proxy environment.
	HTTP *http.Client
	// Credential returns the credential for a registry host, or a zero Credential when there is
	// none. nil means the Docker configuration, as Trivy, Grype and Cosign read it.
	Credential func(ctx context.Context, host string) (Credential, error)
}

Client checks images against their registries.

func (*Client) Check

func (c *Client) Check(ctx context.Context, ref string) error

Check reports whether the registry serves ref's manifest to this machine. nil means it does.

type Credential

type Credential struct {
	Username, Password string
	// IdentityToken is a refresh token, exchanged for an access token at the registry's realm.
	IdentityToken string
}

Credential is what a registry is authenticated with. The zero value is anonymous.

func DockerCredential

func DockerCredential(ctx context.Context, host string) (Credential, error)

DockerCredential returns the credential this machine holds for a registry host: from a credential helper named for the host, the configured credential store, or an entry in the file itself, in that order. A zero Credential with no error means none is configured.

type Reference

type Reference struct {
	Host       string
	Repository string
	// Reference is the digest when the image names one, the tag otherwise.
	Reference string
}

Reference is an image reference split the way a registry is addressed.

func Parse

func Parse(ref string) (Reference, error)

Parse splits an image reference, applying the defaults every container tool applies: Docker Hub when no registry is named, `library/` for a one-segment name there, and `latest` when neither a tag nor a digest is.

type StatusError

type StatusError struct {
	Code int
	// Host is the registry, named when no credential was found for it so the reader knows which
	// login is missing.
	Host      string
	Anonymous bool
}

StatusError is a registry refusing the manifest.

func (*StatusError) Error

func (e *StatusError) Error() string

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL