openstead
Developer tools & integrations

Private container registries

Store registry credentials and deploy private container images on Openstead.

Suggest a change

Connect a container registry when your service deploys an image that requires authentication. Credentials are scoped to the workspace and kept encrypted.

Requirements

  • An owner or admin account in the workspace.
  • An authorized, deployed paid service that enables private registry access.
  • A public HTTPS registry on port 443.
  • A registry username and read-only token permitted to pull the image.

Openstead accepts registry hostnames rather than IP addresses, localhost, or private-network names. Supported endpoint shapes include the HTTPS origin and an optional /v2/ suffix.

Add credentials

  1. Open Container Registry Credentials in the dashboard.
  2. Select Add Credential and enter a descriptive name.
  3. Enter the registry URL, such as https://ghcr.io.
  4. Enter the registry username and a pull-scoped token.
  5. Enable Allow use for image deployments and save.

The saved token is hidden. Leave the credential field blank during an edit to retain it. Changing the registry host or username requires a new credential.

Deploy an image

Create or edit a supported service with an image source. Enter an image reference such as:

ghcr.io/example/example-api:2026-09

Choose the registry credential saved in this workspace. Set the container's application port and any required variables, complete checkout for the service if needed, then deploy.

The equivalent service configuration fields are:

{
  "sourceType": "image",
  "buildMethod": "image",
  "image": "ghcr.io/example/example-api:2026-09",
  "registryId": "00000000-0000-4000-8000-000000000001",
  "port": 8000
}

Replace the example registryId with the actual UUID returned for your saved registry. The selected credential's host must match the image host. A mismatch is rejected before credentials are sent.

Release and credential management

Use immutable tags or digests for reproducible releases. A moving tag can resolve to different images on later deployments.

Release snapshots retain encrypted registry credentials for rollback. If a registry token is revoked, an older release may no longer be pullable. Rotate credentials, deploy successfully with the replacement, and check rollback requirements before removing access to old images.

Remove registry references from active service configurations before deleting the credential. Disabling a credential prevents its use for new image deployments.

Troubleshooting

ProblemCheck
Registry cannot be selectedWorkspace entitlement, credential enabled state, and current role.
Host mismatchImage hostname and saved registry URL, including Docker Hub aliases.
Image pull deniedToken pull permissions, organization access, repository visibility, and image tag.
Container starts but fails health checksApplication port, bind address, required variables, and runtime logs.

For a source repository, use GitHub deployments instead of storing a GitHub source-access credential in the registry form.

Need a hand? Contact Openstead support.

On this page