From 53e8f40aea19095187a2e50a23fe2a7391d3c06c Mon Sep 17 00:00:00 2001 From: Benjamin Date: Fri, 27 Mar 2026 13:20:33 +0000 Subject: [PATCH 1/4] Add ECIR project and robot account creation to the registry documentation --- docs/images/registry/CreateECIRProject.png | Bin 0 -> 11280 bytes docs/services/registry/working-with.md | 40 +++++++++++++++------ 2 files changed, 30 insertions(+), 10 deletions(-) create mode 100644 docs/images/registry/CreateECIRProject.png diff --git a/docs/images/registry/CreateECIRProject.png b/docs/images/registry/CreateECIRProject.png new file mode 100644 index 0000000000000000000000000000000000000000..9a7305102cb6e8000f025d7dbf200f63225b033a GIT binary patch literal 11280 zcmb_?bzGE9_xBRQ(%k|}iXh$HrII4ujdXW+w<2BAAt2qTbV_&k5>iX^E_bNU^ZfpN z_cOaY*UUL*&V0|rnK@UuqP#R3GBGj$06>$Kkx&Kz;7Or*Q6K{JHv?e-1^_@VwGbCq zlob~TDLUAiT3DF?05ajp9}rdEXyEuAc`|3f1Cf9-NSwH$d@%VzWD#fd^b|;#Kvsl+ z2ptV=e>_PE_=zW261dvQl%=`qpL1tEXQNaX73~{#hHUzFP=F78?;nI8(j7;pqu@{HgwMf8UOr%-p*H0|?Gd|2DE=lI?{{N+l4^fda@kZ3&^#NU(47W7CPi4|7=N zDSUm>%kxZ*1%Z7Phv+c4nhyZa_JKhT#?LBjj%c<8mjiv4#DsxWk4}on8^MN%DDsjn z&)pwsk4n^CK!{EqbVHLiXoYbwDXd}Oe&pbCIe{WUZc{%uFrEG! zgM4}?^DeWEPH}iGzmek2iw%WK1-p_#;dc@4A9a7eNq-)(@|rbkpOh|^DwTxed!LwI zV=PM~4)6DX*I8lD-!mb9*p_?mQB|12kWnG}o{Xlx5Si!XlD9aX^-VfsR3<|uqadZ- zT+b_;5B*)6mRMnT0)?m7{SXSOQ)Wv7hYiOXWvaW)n~sbMJ&>tF&tO#YbT@(9&FdS9 zzB?L?%oA;FrJ@Br&`IJvdkqzodh{!=Ah$|esKtWc=yL@B4uqMUujKG1Nbh5^lvZkG zs$bK;mK`$uJf=mfZ}&}LKm(P8fdmoIeFWZ!ck{GfV-nkw9p}Q*Or-Mouo`1QGJ@x4 zddB};O>RD=6EIo=*lFlbl&yJYy*`bk4}(OP(~d|if=CF!(f3!~0%-do9>c(Z;3Wch zJ_C+L=z9UmpW({@mZD^IfV567MRb=yL49%_AbOyx-P3f0?M@Rr(gg$z5n)1D<_@46 zMmGr9C5{`0U?I{Jhh>aDEApZj?ZiJI+l~(XWsow6l{!#WWIqSCh>$+CB->+$V299& zxCwYJ0?CFkC-i{x4#7%69XGI^AQ0U44v16&Jl#THcVv{H*WvG6{I8kuN`)tshAO(IMWkHR4 z(*0yTHoWVYC6cw2B{;=lQ0O(v){8A#QviFwRmdm(+Rt0+W-ky)BIP=nI=2j7Rn^Xz zf_cH#V9X0a^w2k7S?yzZe6^o4q18WC3!4wO?8@jmUqP_Xa}&^ovyE~69=g(a`NE6L z2k{=z2ImVW9P}Wg2-?B60=5OY1*CkAQG7Y0z$4or>h_Y5iXJCAZ1@`{WmZF!xDs+kh6N} zjoGUSc>P~c*-}o&E5skgFDujG8bu(|WF|mFY`3th!+t}i0%38 zN$#=ZwM0}!#3Jj_sF}p}6D5lhi?L_BkGXw0|3W;+JBLXsZT5rrjKc%w4%C_^lv|Sf zu8_FANu^foJm_6Jajt1uw-Qb_92!bn$%{F5sS8T*{of*L~eH9t<{f^T75?La=Y?P zP0ueC=F#u=&2KDTeQ`C<8uKa6D_GA-EO?XasBEVGpmXvQBWKa%mgP=({b4nSWz@ z$vI~;VRF`)V)4|drL$r3lITrFpTQOjNs2cuE{<#BciKtX`q%aaFUFn5GYY1M^w~XY zRBDiGEVn*41~!g*6}peS0KX{ISksuS@nG!5w~DliM2LiW#W?^PaDHF@zS5LrI3}yr z#AO<6t9qeISxQ`rI7L4NGqqnfU%ot(GJ9-AZ)G#9Y~^jOHeWZ}R>xkCGjmYgY^hL# zQMatWZ1FJJIVQR{y2AoC-$~g~-<=uAtr61*E<=%5f2L44Dc_SJ#LLfP#!K#UKmNUo zX3?a5poVvlH-MMZ5kco%r?KK~#hndmy+nQ1;`QSBLgV4&VXPpkz$IBNnZj%VnBxNG zfh9x zB%&ssvuPG>b#ryenMAw&W4u)ztS@1~ST|Hl(jHRyl0so@;R%w?QVf#MB&MZ(!+yp* zkJ*jQAZ=#5a7Z^zXQ^N$BPS=-BN65sFch-4;LkqwwadTneZ!nx!F{< z^u0{Y)NAD(nim9Z@}~;(85b0S)U8Z+&2&-|Nus?ngFLjVScQ=zOg}WfI4Q+`(@uD{ zs|Rjzn_t7S$o|5G)1RI-`(9EyEsuc>XBMN{->M!Q0gio@`{Aj^OC5S$50j6x)zJf) zTbEm4ofwT_t))gW+wXIDa165yrK+N(398N&T`h_-(-_Gm{Nkp01sTBf==YZCaaZ zlgifGI!%c6&pbyGQ+HA;TFY9`Yg22V)avbjbH2Ojf@GAtmQ^lS*0vYH*u-(7lFRVe z-DN{M>!c#POK58g0>oG1z@w*n*uIU9JjZt1SX1%cc~a60X%<6QjEV!*@8hQ?rta$+ z>N1UBdidsb=F)s?Z)*=5mVQRylst=&Pmtfryj_YPXZ3jLu(!FJG#;3N!cU$aF6g*# zH8XqY=)cXB4iWS%h+Les?>z7N897W4t7EA1t`%(8xEXPmyj6Okmex$#q*cMIYuSA0 z)Y@t$Khj5X$SuEo*5-bXzdf}%?`R8I2yb$%=gz5rV0t*L@yzwCJThA*_xxOdG5_H~ z@ycMAs$6=q{p0=A#L=j)VTb2R|9V&t27-Gav(L!w-GJgDPJiN$!X}0NtXTnmAuzw! z-BruBI5RbKx9--R=w04Pa$jklug9&s3AKyyPVLz_gge-lb7`uz#&epNnD2VWyZfdJ zv*6DZ^joz_de_N`L^#lH8`H^Qg+ex{ z;2$ehIHNU}4oCISO!jGYQF(IvhW6&Ned105ZA0my;Ngiw48nT_f>L9s_o`~5E^8_$ z2cU=MfdH6L3jjPc2X$xx#LzDQ0GAK~K!pBdL%$N)u>aP=lV-#Hn+J$K5{kYNmz9P7 zzcF$!F|lzpw{;>NPpN{6nzB$)cT$&o&1Yn5&17I~YiPpcW^MP#0uXTHgJ!KwoD4v2 z)>bx-d~Sl2e^Ky3^N+>Ml%T&zoGb+?)#VgH;;9zXZrz|1$ z4?FZpkkZ`A$&Qbi+11sR$(5bS*1?RKm6w;7nT3s+jg1jX!RY92<7D8*XyZurw~&A3 zNSHVpIat^^S=icu9_1Ps+B!Q4Qc^xP^y~Ato+fS018qZyi&Nk)^8cy$-QXXL>c1ITSvcAMWc{P+zggcpnmCBt zT0@(368deKf0+NQ{D)D1`LXAJAn`ZMf0aUU7D5(a{$(>EzQ$)bdOBF-85Eaq=wUjz;L=DPC8a7OadlPPdCgHgXEmqt$X3eSfYz!A z9T=;#hOif z(gF(;1`E?)8)vkAym1L8ni-Z7^iR4{$Y%0&#NQAmD_4Y<5c!`3B7iq`>V4uI{ror2 zFXkaX5hZ8KZ_#3ue^rjUA?+;hb~kgUegua3{gXIcVJC@6lg4uzg()@Lfng#>w2B`t zo4Q+=hUETeE&C^C(ZDOFU^R|R?}^v{mm-zG-kmtL`Qq=tME}l+tW$vU#Mft0h9v%w z`EPGdBK)Gz-D@*6qkgOPiV{AR-k?+a9d>7ltYd0IIJ!+)1+w zdTST+S(Ei@kp*&ocWoCIX8NfrHW;Wc*rG78|7C{3>U{zethN!*)Q$Tn3xU?J)1Vu| z#>2sKk&Yf}A1-KiMDxpllyMBu-fu*-bmRR+OerGsgbY1lOV+P-n<(xVMqwgMkKm*1 z5x;qampBf<`xIAs%&&uFRuL>X;`ayW4x-t!#H4HXkS((bIuc%od`9gC76Py%-xh}O zt^Nl+pGLv6QE}c3=?X;Oi&?XS+(@QsjT+NU4|-xf`1iyxG|}4c%+p@?cp#(>s#@g! zqiLKg{2pVxv4+OS)`$BWF8ehJ&%5(!>kQ|qs)M@uVGqcmHADFqD~9kF zA@A#%gT%Vn%b*6pp&ebXx%)E^RxuL2RWVp;(5P7yjI|>fMk?(bDts`i1 zJ+fh_Xvnp$n>C%PHW?^uE@nI`L$pIPU^5>D`3|6QFDS06ZVC9@y3M=HTQj6r4t+3r zuhESzbg6H9HVbXUa$GVQqV2lq9Aa-a#5w(iK-Vp&zpjbyzi0WCO!lx8Vizs~Dq$Q4 zk5$bOR~;12xoJILYu5$)Q1APz?K&tfbC6|UTRQi1Mm?XaPu{mbd+H`twI+-9->PbS zZ@XMW@x{n|5-qCe$M1RwPCjftYMWQs{f48!flAGP@a0XbynQIC%jc`pZ4xqg&iJ{L ziax@zIye2N&J#)(-6Xa%rIl^(+HX%HA=$;uM^T96UZX6jlS$%EF&|?-QjKgaG&-_# zj=BGy1CPrcbS7BBI#1Opl}N>s9Z;O_O%8;rYJ2Q{x<_M1CJo4y0efLCsgQf0jn#D% zTdFs^9Dp0vV``vwWz^=v)mkz>Jza}r_V|>Di8hB$$~S?}sJUTu+<3p_d31F{=6$BL z>;s;uy5~ne@9>ASUXSLkQ-875O62Bwe{pVAFiCb<=P< z%zsclz*KWSr8N>7!lHJKf_)+iZiOt}U&rtt?rfiLXEA9_8zOmkZk5#xpE#Ncz3pS| zdAi=p*&Ri+&Kpw40)*|MiWT?~+kAh$KTl+qZoqCj2>fvO%+sO&dEq51(ilj^zvapC zn!rgfRV-l$;&6@=6=8%r!+wZHz0D%{dcU&%uhy8GhC% zR!{&D)mT*M?(7Y@2OMIiQp)R8j_2AJSuCB26asJpW}neU`k;UuIfjg;*kMiaxgD<{ zd+$X4_k7vl_fKuzk{35R+34$gv_Ux@K0a+bj)VPbFadGDn}tQO@WUYch?^wiY%gi{ z#%UmBIAxT<3KZcBxv*Vn3vm|RY>8a+iq?y{KCV?_$cmD`5^QXw#dyKh&E3%Rtf10WC(5q$KqLT+CdjiB6|L=PVF%~YhlLZU^p_G5#fiHp-jPfrp66y;S2tw zmi6rcf(v%7-Pszm>gN=kh-7a1Qp4aQQAE;>9&~QG6qe3Q3P>+>r0he&&#T_wUCfVg z-|UrET7A%Qkv&hn|%I2 z2UZZi`vR#39l>F@a234%n83lK?Ks4_loCK0xgscXA5oO;maBeRaJ%3*60KX}6lEXM zX!rsNnJ=1!QeqY>q*KdF04Ig~pt5O?ewjSNj)iAM2e6F7)Q}wjt8Jn0y0-a2Prj~G zF(79(>*2QWpk_p9Nna7~XyX2uxC0nK03!v2U+*!?^4^O5=_J}a;s+6}>&k?uAdpm1 z=3S@ouYzm**-g^Q8u5-4h{r!u>g2HGzU}T~M^g`<&T0c9)Wyua(zoNe+DH^+Kotgh zcCz~!1b(Ipa_(YxgTG3=rupwh6Y3Xb2$CumVB(gpt*z0=%VqF!7S9+)0sCl_`eonu zYTc*=c6=w$13QYv5v)yV+17s0_2^UU1!2J1u0su~A-r`mz?@aqA(9LyhOM}wl#R5w z!qZ#7>_dV+?vwi>qy*va1_H@Mb9NEkWVl51sfrgSUd!^c$9XW zU}>-rd7svbrr)N#c8aY_HV%3=TSvwglWf3n0hW>bTpEl_XUUveZYHbAXPPjx;A3Lj zK^JeWUibKL*AppM5xQ^Cy(>)s&qS0>67>zm#8#X*y6mCeNk|gh<=40fy3X+cGql*i zqI?JRWIC3Y!4etA4Od%ftxEoFEKB*w-2_3~^iQD+&s^5m#MSLAU-^(TyM$v*FY}%JdjqscHZqM;`Iq&DMtna^~Kd)ZCkD3qb zAz-X!ov8Y~cyQ3bI&<+^Rei@_dYi#LL_Jtq@{Q`HR$NgjZ`G-&(A5TxmO(IHmzw2x zf!s+-{Rkmx361~)a34f2Y7PHMNG24Wv?~X~)iF*1L_&Y_WF(*nvpTLkJEi&p6Tiz< z0720&Z(qK?B0J6~T_iv>)JQ;H@q%^F7`s31WQy!7x-Jn#D2y(h$|z7OY-m#;Yu~LgwuJ7LoVQ9sM) zlU706q(t_u6O#e--|ZG=9WFu)f>{0g@s!qkbX*rrL>n>I5p3bHrE>|_{5tTqIqZx95pAt!{GqPAga0w(!9j#~=3K znK8u7dJ{!up6naR6({g9N#Ua+2FXa!P%lOin?NtMGdfNqLM4H*AnqrtjBY0#f6xRx0psJ?^#BTZBFYhsvsNR#50ZaUyH{mCj3H{wlhu?I$a#l=A4>e zVwMIRa71Scw7H;ofL-o86>*SF;wS-tT4rNCh%OT+Z;_GdZ0p2 z+mw^Yo4z}dO;lVPRPH>f=$Ca}enI)`8CFTFfILY|0a8qQyP&qNTBj_Pd!F6=M6Y0+ zsk9-%Gx1HdAc=TFMNCw3LM2QwY2_zh(ZXM2^%om%=)Vp^2H8n9xg6{XUr9C~1lR|@ zBp?ixQ4SBXqnbf93T@BUqa2k0YJc|4;pVvo=Z;U2e;Ji0)G-Y_WU66gQa4||v#OIH zNI7Uyx_*e(|7>2yc2VxYzd`SdD`^4Pw!AT0-_8?|CIY@kT*$IhCWLWQg^;_$YF z4K*K<=D+#D7@?x5Jgi(HM~(1qKV5cpT9!?X05@)D_OY@^#gU6s!penrWNK006WC7- zeNrVJ%lpaGajAH?2E0B>H+P)&qfEPq#eR^wFC}>ievnEgTt(=$eug_sF#TZ$to0In z$M6b_N@$xy^K3e4=7np<%@UEWq0St289qjah7|#MiuuTP6v->A#9Ex`DQy~4 zg$z9_z2&3^NbNu*JF#f)`X@3RWKkK3ZBCp!Q%#ia(0K(X%SNWE_X>;Y(!3bqMJ<9Y zGqik1aiG~j`{-nxeSPaPa{OoDO!d=`o_HRnXZ7W$OgU(}9N-7E{=k@URJZ+bF+y1l%#m_j>ODw)6xcWgCP5Nstfp^;)v5LMSL%Z1`DOdiZ9!Ji%-GX6m>y1($Lq7`n`*}?`e9Z@~f!p9IhHfiff-8>R z=ieMN0_U5@*O*@PSw*o+VaABMbz5fjSZ{8oOLxKqyGTI3J^0k=a+`8rFjwQfXZ2jv zdDy#YD6dUL*=zviG$`EWFSKQ*5oV332{YF>w(}`a7P`igXj^GD9fuJeX7=fQFZbS0 zS#*3C9}kyHyH>K&q}*`Z{>)yjpmss{^UTGr<_a21WmDsidyx;8YkJR^Sp~}GC`}pF zWSo+Qp0W-`wbNC_*!o7?w4i+^^svhzt$CFr_mK!t7%S z!go!us2(>Pu8TRCGj2-15QxC*!*#ED>V1<|!P-co81VCb5eCIY<^sGZaQPCt2en8` zmM9a?O>E*g5k5U;E2`u)<|h~9S0^U}j@26Q05h=&y^d)=3VC~+lnbxYZcG=w)R*FU zlEXyE$|g&H^!k8DVYc5N4)K~cikuNibJF|V9!-3rOrz%3BXa^T?zK)1D$PDCmAaN8+#vWRtE;YZW4*yOJl;&GFpT5R%PmJ8pLWV*J)1;&6 zy%bWI(F1dZWs{|7^FbhqMPjA=_~g@fu7l`O-v%vfD>+Gb@nRc_4i zwKWt#g>|FU#{@Z1zHM@L>7zr$BU;5PykoG(urA^eh3$o;uNr1CykcC`l*zwZqxsIY zk62TV@XQULueomni)LzW7Oz=X{oV3CVLfw(G-60<^oWl6?BGwz?N<9avfzt}4F~@F zx^L-xys;=PG^WgCmXr9VE$>>??#*uz`fo1571P|4X462n$5eL9ifzBiW(#zBrp>HETzw1e5i;&EnfYXzKS zaa+%n`wmP1nI-~RlU@1H6Q3z?b&-hKU~Gxx4u;?+-KoG4CUXQ3z&qw_n3m|jMmAt5 zp6-HJWx)_Vg=O{T!h;=Po>CxS8XKxfy?(3kqA_Qi7Rfe*xjou*U2I3+-%`v$LI9>n zrc(h0;?f>!+1}m1CGZ5B@uzynPMmy`v+SAR=Kcw?_qfaY_f>-3!*%UtYZR-mb>HzF zb(|cGSTIWLv~N2S8poNM-s`5(b~n2(B=F!IHlBWxbh-Blt_ywT!fU#gV7ZVr^tApc zY3GAoGU)i77K*r1gI?C}Tf5N|;6(FS4l82??{F}7d{W@IM860;!lytz3JARWGd`!C z(QNf&ug(<_I%HWUq$hp2bE9!MUqOPEM0# z9Aid3Y=GFXLW$Kz6kL#@z*fIHwz3jVCkcSa-FWjMx_m>7rzA0s-7u#H$LrX6AtXj; z%>wH%y29l2BK)V2om5Pb*Uq8j@d+V2tH*aDj_Q@ZVeV29&8@6|5+w&KV&>=acUQjVuM)ouSd$GCygmqsie?r?>=gIR@0hQqW;#E96CezE4;4}iU>ONQPwg^z? z=VJ}x*eI(lp8e2kxGqZV zxO|SZc^&S^FkfiPThWWY>~9w~n2EWbK>;(n7%VqvCky&Ia!5ijBchfJLlG1}Pbj^l zV!E#5@G?R2@QdhoAtWP_Ilgsi%oApippIUSo)D|*nd2(XIU_TZ?knF93#{}M6ts>C z$yQsJhiBjTayR){cN8}R7w~1&g&Rr#P;+zwsB-_Ry0~2A^znKZ21}hDp2>k1-DNI& zrhPHX;ca;IP4>dp9d^C94rfG6X%E;HVtU`bt-OFr$?o3swzUIuwDr~CGc&Kv8V7<9 zMScE?*zF*9Be*5ZwDLqcBHqsDhn~%B897cSJIKu812=ec@%;D=Z0V9hyBp^tFRH&b z;mu&GZRRxZAJxp->(S%|mg@hUX--B1k1 zUvfF#hHCX-4ZAt!o*wRiv2EoujHb-?VJ$Zk-UwYv8IlI+cBJmtlj&_FI5U;3SjY2K zv_<|KZ-53EC>0+n1Bu7?I0*i_>+t8pnz589_TG8Paq>Q+{#qrfW97K<%}Kq>+oxSx zm;LmvT}7joZpB!sBJx4wo&+9&U!By33>BuC#l9n)@F`xOq2rQ47HJ+(;`Q=6B4Rly)<8g}`3 zc`$?EqNX}`IK9H5hWS1}RfqI)L#=jvTdoAOyZ74-2foh5-jJGEo8d4~yy!`7N;xr+ z5aH@?+3eTBl5J(%Fj{yG5-E7CjJcNoaRTOoJ=bNcsbW+-ecTxRy=dd)u5#y+24D9? zB_s|smEgB*R$9D`ge4#nJ&_V1|FOwr-Y7OG1K?eB$AKPX-I(@$e6Cv!QRwx`HnDZ( zopo_Kfyz~qcRogp8x9?Sc>3i9?KL!tG(AODQE@Iu?cu6V`R2XB@pIfXd!i!t~o#G;(xS{3r9P7QpE(YcBo#wyFMKob6eU)xLKS|nny~#{uwNz;jNpzXn z=zB7pIwpa1i>hzN#=^j-I>a!IJX>^>~>W%{X&tumx( zW*9-Z^MN<5zce&{3=)Agia$NV%OMLZeWb0=_})6<&2;|0KfrT@9rTBzq>VYMN70yF z!TOh27$nr4x8~)lN%i7zl(s73RS*HVKR|^BkcdbfM0JcJps`=6nA;qZ^e-V*K<&}W_#}F zsdYfe-*$qoMaS@G*Wwrfe`!wz+b}yY*+yjD@SgtnT^cVfNFns8tzQVie`55P>*qxS z4fwSkmQDRSKmQxiglYlh%oC5{7Ww*nRroyu+OXrsDD+%a_p$#Eu}^WJl|3ZctB*ka zR|4rhTCS46)cKbY{)mvpJXWrwjUNBrCVpuYR|y|cqBV2&v8L2AcmHn!Ug~V$LPwyU z_@6qe$YyKii9>_7C14SPzg2LM1_TD)XAG12M!)!t&5*x{j;_P=mRw!|3eCKKXWp+) z`T;lmpfOKgzY2=~qa)e8m~mq{yx{7o{|Wazf(L?vhn{UI^M8z9b987l*c`pNjPr49 g{8th|2i^*^_u-F3zU6;>-xnY&DKAkWrXTSC0Nwm9!vFvP literal 0 HcmV?d00001 diff --git a/docs/services/registry/working-with.md b/docs/services/registry/working-with.md index a31f2741f..5901f7333 100644 --- a/docs/services/registry/working-with.md +++ b/docs/services/registry/working-with.md @@ -13,6 +13,20 @@ User tokens can be accessed from the User Profile from the dropdown under your U See the FAQ section ['Unauthorised' error when logging into the registry from Docker](./faq.md#unauthorised-error-when-logging-into-the-registry-from-docker) for help with token expiry and authorisation issues. +## Creating a Project Repository + +Each EIDF project can have a private space on the registry, this is called an Edinburgh Container Image Registry (ECIR) project. An ECIR project can be used to store images and artifacts that are private to the project. + +To create an ECIR project: + +1. Navigate to your EIDF project in the EIDF portal. +2. Find the **Container Registry Project** section. +3. Click the **Create Project** button. + +This will generate the ECIR project, which will be accessible from the registry interface within a few minutes. The project will be named with the same name as your EIDF project. +![CreateECIRProject](../../images/registry/CreateECIRProject.png){: class="border-img"} + *Example Create ECIR Project* + ## Push Commands In your project, there is a PUSH Command option which will give you the command templates for pushing to the Project repositories from different clients. @@ -26,6 +40,20 @@ Each repository in a project has a COPY PULL button option once an image/artifac Clicking on a tag in a repository will open up the information on the artifact, this can include an overview of the image, vulnerability summary, SBOM and build history. +## Creating Robot Accounts for the Registry + +If you are regularly using a repository from a project where you are sharing resources and need automated, read-only access (for example, pulling images into compute jobs), it is recommended to create a robot account with limited pull-only privileges. + +If you also need to publish images (for example, as part of an automated build or CI/CD pipeline), you should instead create a robot account with pull and push (read and write) permissions for the project. + +Robot accounts can be added by a project administrator as follows: + +1. In the ECIR project, click the **+ pull robot** or **+ push robot** button within the project. +2. Wait a few minutes for the robot account to be created. +3. Go to the **Robot Account** section of the project to access the credentials, which include a username and a CLI Secret for logging into the registry from Docker and other container services. + +Robot accounts with pull and push permissions have a default validity period of 30 days, after which they will expire and need to be renewed. This is to ensure that access is regularly reviewed and maintained. + ## Using from the Command Line with Docker Important: Run these commands on a system that has Docker installed and has access to the ECIR. @@ -61,20 +89,12 @@ https://docs.docker.com/engine/reference/commandline/login/#credentials-store Login Succeeded ``` - +To pull images from the registry, from private or authenticated projects, you will need to add a secret to the namespace you are using and reference it in your job definition. Note that user tokens have a limited validity period and therefore, robot accounts are recommended for long-term use. See the section on [Creating a Robot Account](#creating-robot-accounts-for-the-registry) for more details. From your command line, you can now push and pull images to the registry. ## Kubernetes/GPU Service Access -To pull images from the registry, from private or authenticated projects, you will need to add a secret to the namespace you are using and reference it in your job definition. Note that user tokens have a limited validity period. - -If you are regularly using a repository from a project where you are sharing resources, it is recommended to create a robot account with limited read only privileges, this can be requested via a Helpdesk Request for your project. - -!!! important "Portal Management" - - There will be new functionality soon added to the EIDF Portal to allow for project users to create read only robot accounts and for PI/Managers to create read/write robot accounts for use in CI/CD pipelines for image building. - -This is then treated like a normal user secret when you have the robot credentials. +To pull images from the registry, from private or authenticated projects, you will need to add a secret to the namespace you are using and reference it in your job definition. Note that user tokens have a limited validity period and hence robots are recommended for long term use. See the section on [Creating a Robot Account](#creating-robot-accounts-for-the-registry) for more details. Secrets can be created in one of two ways, as detailed below, either directly via kubectl from your Docker config.json file, or by creating a YAML file. From df2d2657c6ccb5be785f57233d83aa153d4eaad4 Mon Sep 17 00:00:00 2001 From: Benjamin Date: Wed, 8 Apr 2026 11:24:06 +0100 Subject: [PATCH 2/4] fix: project creation is to be done by EIDF admins if not already avaliable also precommit issues --- docs/services/registry/working-with.md | 15 ++++----------- 1 file changed, 4 insertions(+), 11 deletions(-) diff --git a/docs/services/registry/working-with.md b/docs/services/registry/working-with.md index 5901f7333..c249e7287 100644 --- a/docs/services/registry/working-with.md +++ b/docs/services/registry/working-with.md @@ -17,15 +17,7 @@ See the FAQ section ['Unauthorised' error when logging into the registry from Do Each EIDF project can have a private space on the registry, this is called an Edinburgh Container Image Registry (ECIR) project. An ECIR project can be used to store images and artifacts that are private to the project. -To create an ECIR project: - -1. Navigate to your EIDF project in the EIDF portal. -2. Find the **Container Registry Project** section. -3. Click the **Create Project** button. - -This will generate the ECIR project, which will be accessible from the registry interface within a few minutes. The project will be named with the same name as your EIDF project. -![CreateECIRProject](../../images/registry/CreateECIRProject.png){: class="border-img"} - *Example Create ECIR Project* +By default new EIDF projects will have an ECIR project created with the same name. If you have an existing project without a registry project, you can request one by contacting the EIDF Service Desk. ## Push Commands @@ -49,8 +41,8 @@ If you also need to publish images (for example, as part of an automated build o Robot accounts can be added by a project administrator as follows: 1. In the ECIR project, click the **+ pull robot** or **+ push robot** button within the project. -2. Wait a few minutes for the robot account to be created. -3. Go to the **Robot Account** section of the project to access the credentials, which include a username and a CLI Secret for logging into the registry from Docker and other container services. +1. Wait a few minutes for the robot account to be created. +1. Go to the **Robot Account** section of the project to access the credentials, which include a username and a CLI Secret for logging into the registry from Docker and other container services. Robot accounts with pull and push permissions have a default validity period of 30 days, after which they will expire and need to be renewed. This is to ensure that access is regularly reviewed and maintained. @@ -89,6 +81,7 @@ https://docs.docker.com/engine/reference/commandline/login/#credentials-store Login Succeeded ``` + To pull images from the registry, from private or authenticated projects, you will need to add a secret to the namespace you are using and reference it in your job definition. Note that user tokens have a limited validity period and therefore, robot accounts are recommended for long-term use. See the section on [Creating a Robot Account](#creating-robot-accounts-for-the-registry) for more details. From your command line, you can now push and pull images to the registry. From 9365fb6c5052010c4bc0b8ed93175e3c50dec3a1 Mon Sep 17 00:00:00 2001 From: Benjamin Date: Tue, 4 Aug 2026 11:39:49 +0100 Subject: [PATCH 3/4] feat: update robot account docs for robot usage and admin --- docs/services/registry/faq.md | 10 +++++++ docs/services/registry/projects.md | 4 +++ docs/services/registry/working-with.md | 41 ++++++++++++++++++++++---- 3 files changed, 50 insertions(+), 5 deletions(-) diff --git a/docs/services/registry/faq.md b/docs/services/registry/faq.md index 152473b4e..7f1a6fe0d 100644 --- a/docs/services/registry/faq.md +++ b/docs/services/registry/faq.md @@ -1,5 +1,15 @@ # FAQ +## What credentials can I use for the registry in an automation? + +To access the registry in an automation, you should create a robot account for your project. Robot accounts are service accounts that can be used to access the registry without needing to use your personal credentials. They are configured with specific permissions (e.g., read-only, read-write) and have a limited validity period for security purposes. + +Instructions for using a robot account can be found in the [Working with the Registry](working-with.md#robot-accounts-for-automations-in-the-ecir) documentation. + +## My Robot Account credentials have been compromised, what should I do? + +If you believe your robot account credentials have been compromised, you should immediately refresh the robot account secret to invalidate the compromised secret. This can be done by a project PI or manager in the Image Registry section of your project. Instructions for refreshing the robot account secret can be found in the [Working with the Registry](working-with.md#robot-accounts-for-automations-in-the-ecir) documentation. + ## Known Issues ### Unauthorised error when logging into the registry from Docker diff --git a/docs/services/registry/projects.md b/docs/services/registry/projects.md index 749d0e830..e2cd78f90 100644 --- a/docs/services/registry/projects.md +++ b/docs/services/registry/projects.md @@ -51,6 +51,10 @@ ECIR Project maintainers **do not** have the permissions to: * Edit project configuration * Delete projects. +If you are intending to use the ECIR in an automation you should make use of a robot account for your project. Robot accounts are service accounts that can be used to access the registry without needing to use your personal credentials. They are configured with specific permissions (e.g., read-only or read-write) and have a limited validity period for security purposes. To read more see [Working with the Registry](working-with.md#robot-accounts-for-automations-in-the-ecir) documentation. + +If you require a robot account with specific permissions you should submit a request via the [EIDF Portal](https://portal.eidf.ac.uk/queries/submit). + ## The Library and Public Caches ECIR provides a common library of standard images. ECIR provides cache projects for four major registries which allow images to be stored for 7 days after use in ECIR for convenient access. diff --git a/docs/services/registry/working-with.md b/docs/services/registry/working-with.md index c249e7287..dbec6eafa 100644 --- a/docs/services/registry/working-with.md +++ b/docs/services/registry/working-with.md @@ -32,19 +32,50 @@ Each repository in a project has a COPY PULL button option once an image/artifac Clicking on a tag in a repository will open up the information on the artifact, this can include an overview of the image, vulnerability summary, SBOM and build history. -## Creating Robot Accounts for the Registry +## Robot Accounts for Automations in the ECIR If you are regularly using a repository from a project where you are sharing resources and need automated, read-only access (for example, pulling images into compute jobs), it is recommended to create a robot account with limited pull-only privileges. If you also need to publish images (for example, as part of an automated build or CI/CD pipeline), you should instead create a robot account with pull and push (read and write) permissions for the project. +!!! Note + + Project Robot account management is only available to PIs and project administrators. If you are not a PI or project administrator, please contact your PI to request a robot account. + +### Creating Robot Accounts for the Registry + Robot accounts can be added by a project administrator as follows: -1. In the ECIR project, click the **+ pull robot** or **+ push robot** button within the project. -1. Wait a few minutes for the robot account to be created. -1. Go to the **Robot Account** section of the project to access the credentials, which include a username and a CLI Secret for logging into the registry from Docker and other container services. +!!! Note + + Only available in the new project interface. If you are using the old project interface, please select "Try new view" in the top right corner of the project page. + +1. Navigate to the Image Registry section of your project +1. Select "Add Pull Only Token" or "Add Pull and Push Token" depending on your needs as described above +1. A form will appear which allows you to trigger creation of the robot account, progress of which will be shown in the Image Registry section of your project. You will not be able to add, delete or refresh robot secrets whilst this action is in progress. +1. Once the robot account has been created, you will be able to view the robot account and its secret in the Image Registry section of your project. The secret will be visible whenever you return to this page. + +### Refreshing the Token of Robot Accounts + +!!! Note + + Only available in the new project interface. If you are using the old project interface, please select "Try new view" in the top right corner of the project page. + +Robot accounts with pull and push permissions have a default validity period of 30 days after which they will expire and need to be renewed. This is to ensure that access is regularly reviewed and maintained. Should the robot account's credentials be compromised the secret can be refreshed to invalidate the compromised secret preventing its use. + +When a robot push pull account is created, it will have a default validity period of 30 days. The expiry date of the robot account is shown in the Image Registry section of a project. When the robot account expires the date will be displayed in red. On expiry the existing robot account's secret will be invalidated and the robot account will need to be refreshed to continue use. + +The robot account can be refreshed by a project PI or manager by selecting the "Refresh" button next to the robot account. When the robot account is refreshed a job will run to create a new secret for the robot account. If the robot account is refreshed before the expiry date, the existing secret will be invalidated and only the new secret will be usable to authenticate the robot account to the registry. After the job has completed the new secret will be displayed and the expiry date will be updated. The new secret will need to be used in any jobs or scripts that use the robot account to access the registry. + +### Deleting a Robot Account + +If a robot account is no longer required it should be deleted to reduce the risk of unauthorised access to your Harbor project. + +!!! Note + + Only available in the new project interface. If you are using the old project interface, please select "Try new view" in the top right corner of the project page. -Robot accounts with pull and push permissions have a default validity period of 30 days, after which they will expire and need to be renewed. This is to ensure that access is regularly reviewed and maintained. + A robot account can be deleted by a project PI or manager by selecting the "Delete" button next to the robot account. When a robot account is deleted, it will no longer be able to access the registry and any existing secrets will be invalidated. If a robot account is deleted in error, a new robot account can be created to replace it. ## Using from the Command Line with Docker From 9a5b3b6b3e806411bd33694ec4f9833e2067967c Mon Sep 17 00:00:00 2001 From: Benjamin Date: Tue, 4 Aug 2026 13:44:21 +0100 Subject: [PATCH 4/4] feat: update docs to consolidate formatting and names --- docs/services/registry/faq.md | 6 +++--- docs/services/registry/index.md | 2 +- docs/services/registry/projects.md | 6 +++--- docs/services/registry/working-with.md | 10 +++++----- mkdocs.yml | 8 ++++---- 5 files changed, 16 insertions(+), 16 deletions(-) diff --git a/docs/services/registry/faq.md b/docs/services/registry/faq.md index 7f1a6fe0d..f58d97ad9 100644 --- a/docs/services/registry/faq.md +++ b/docs/services/registry/faq.md @@ -1,10 +1,10 @@ -# FAQ +# FAQ about the EIDF Container Image Registry ## What credentials can I use for the registry in an automation? -To access the registry in an automation, you should create a robot account for your project. Robot accounts are service accounts that can be used to access the registry without needing to use your personal credentials. They are configured with specific permissions (e.g., read-only, read-write) and have a limited validity period for security purposes. +To access the registry in an automation, you should create a robot account for your project. Robot accounts are service accounts that can be used to access the registry without needing to use your personal credentials. They are configured with specific permissions (e.g., pull-only, push-pull) and have a limited validity period for security purposes. -Instructions for using a robot account can be found in the [Working with the Registry](working-with.md#robot-accounts-for-automations-in-the-ecir) documentation. +Instructions for using a robot account can be found in the [Working with the EIDF Container Image Registry](working-with.md#robot-accounts-for-automations-in-the-ecir) documentation. ## My Robot Account credentials have been compromised, what should I do? diff --git a/docs/services/registry/index.md b/docs/services/registry/index.md index 3478f38d1..867711c1e 100644 --- a/docs/services/registry/index.md +++ b/docs/services/registry/index.md @@ -1,4 +1,4 @@ -# Overview +# Overview of the EIDF Container Image Registry EIDF Container Image Registry (ECIR) is an image registry for use in EIDF, EPCC and related services. ECIR uses [Harbor](https://goharbor.io) to provide services for image storage, vulnerability scanning and Software Bill of Materials (SBOM) generation. diff --git a/docs/services/registry/projects.md b/docs/services/registry/projects.md index e2cd78f90..81e5982ec 100644 --- a/docs/services/registry/projects.md +++ b/docs/services/registry/projects.md @@ -1,8 +1,8 @@ -# Projects +# EIDF Container Image Registry Projects and Caches ## Projects within EIDF -Every EIDF project can request that a ECIR project is created for them. An ECIR project is a namespace within the registry which contains repositories for container images private to users of that EIDF project. +Every EIDF project can request that an EIDF Container Image Registry (ECIR) project is created for them. An ECIR project is a namespace within the registry which contains repositories for container images private to users of that EIDF project. !!! important "ECIR Projects" @@ -51,7 +51,7 @@ ECIR Project maintainers **do not** have the permissions to: * Edit project configuration * Delete projects. -If you are intending to use the ECIR in an automation you should make use of a robot account for your project. Robot accounts are service accounts that can be used to access the registry without needing to use your personal credentials. They are configured with specific permissions (e.g., read-only or read-write) and have a limited validity period for security purposes. To read more see [Working with the Registry](working-with.md#robot-accounts-for-automations-in-the-ecir) documentation. +If you are intending to use the ECIR in an automation you should make use of a robot account for your project. Robot accounts are service accounts that can be used to access the registry without needing to use your personal credentials. They are configured with specific permissions (e.g., pull-only or push-pull) and have a limited validity period for security purposes. To read more see [Working with the EIDF Container Image Registry](working-with.md#robot-accounts-for-automations-in-the-ecir) documentation. If you require a robot account with specific permissions you should submit a request via the [EIDF Portal](https://portal.eidf.ac.uk/queries/submit). diff --git a/docs/services/registry/working-with.md b/docs/services/registry/working-with.md index dbec6eafa..4ade24fb2 100644 --- a/docs/services/registry/working-with.md +++ b/docs/services/registry/working-with.md @@ -1,6 +1,6 @@ -# Working with ECIR +# Working with EIDF Container Image Registry (ECIR) -## The Registry Interface and Accounts +## The ECIR Interface and Accounts EIDF Users can access the registry through their SAFE account. @@ -36,7 +36,7 @@ Clicking on a tag in a repository will open up the information on the artifact, If you are regularly using a repository from a project where you are sharing resources and need automated, read-only access (for example, pulling images into compute jobs), it is recommended to create a robot account with limited pull-only privileges. -If you also need to publish images (for example, as part of an automated build or CI/CD pipeline), you should instead create a robot account with pull and push (read and write) permissions for the project. +If you also need to publish images (for example, as part of an automated build or CI/CD pipeline), you should instead create a robot account with push-pull permissions for the project. !!! Note @@ -61,9 +61,9 @@ Robot accounts can be added by a project administrator as follows: Only available in the new project interface. If you are using the old project interface, please select "Try new view" in the top right corner of the project page. -Robot accounts with pull and push permissions have a default validity period of 30 days after which they will expire and need to be renewed. This is to ensure that access is regularly reviewed and maintained. Should the robot account's credentials be compromised the secret can be refreshed to invalidate the compromised secret preventing its use. +Robot accounts with push-pull permissions have a default validity period of 30 days after which they will expire and need to be renewed. This is to ensure that access is regularly reviewed and maintained. Should the robot account's credentials be compromised the secret can be refreshed to invalidate the compromised secret preventing its use. -When a robot push pull account is created, it will have a default validity period of 30 days. The expiry date of the robot account is shown in the Image Registry section of a project. When the robot account expires the date will be displayed in red. On expiry the existing robot account's secret will be invalidated and the robot account will need to be refreshed to continue use. +When a robot push-pull account is created, it will have a default validity period of 30 days. The expiry date of the robot account is shown in the Image Registry section of a project. When the robot account expires the date will be displayed in red. On expiry the existing robot account's secret will be invalidated and the robot account will need to be refreshed to continue use. The robot account can be refreshed by a project PI or manager by selecting the "Refresh" button next to the robot account. When the robot account is refreshed a job will run to create a new secret for the robot account. If the robot account is refreshed before the expiry date, the existing secret will be invalidated and only the new secret will be usable to authenticate the robot account to the registry. After the job has completed the new secret will be displayed and the expiry date will be updated. The new secret will need to be used in any jobs or scripts that use the robot account to access the registry. diff --git a/mkdocs.yml b/mkdocs.yml index 3377bb132..170317e07 100644 --- a/mkdocs.yml +++ b/mkdocs.yml @@ -98,10 +98,10 @@ nav: - "Code Collaboration": - "Gitlab Overview": services/gitlab/index.md - "Gitlab Quickstart": services/gitlab/quickstart.md - - "Container Image Registry Overview": services/registry/index.md - - "Container Image Registry Projects and Caches": services/registry/projects.md - - "Container Image Registry Use": services/registry/working-with.md - - "Container Image Registry FAQ": services/registry/faq.md + - "EIDF Container Image Registry Overview": services/registry/index.md + - "EIDF Container Image Registry Projects and Caches": services/registry/projects.md + - "Working with the EIDF Container Image Registry": services/registry/working-with.md + - "EIDF Container Image Registry FAQ": services/registry/faq.md - "Safe Haven Services": - "Overview": safe-haven-services/overview.md - "Access": safe-haven-services/safe-haven-access.md