Glossary · Automation software engineering and architecture
Container registry
Also known as: Image registry
German: Container-Registry
In software engineering, a container registry is a server or service that stores and distributes container images, organized in repositories and identified by tags and content digests, with access control for pushing and pulling images.
- Software engineering
In one sentence
A container registry stores and distributes container images, identified by tags and digests, with access control for push and pull.
Example
Edge devices in the plant pull approved images only from the company's internal container registry, which mirrors vetted versions from public sources.
How it applies
- Engineering: The Build pipeline pushes images to the registry; deployment tools pull them. Registries can scan images for known vulnerabilities and enforce signature checks.
- Operation and security: For OT environments, a local or mirrored registry avoids direct internet access from production networks and keeps approved images available during outages. Access rights should separate who may publish from who may deploy.
- Documentation: Document registry locations, naming conventions, retention rules and the approval process for images. Deployment and service instructions should name the exact image references to use, so field staff do not pull unapproved versions.
Container registry vs. artifact repository
A container registry is a specialized Artifact repository for container images. Many artifact repository products also act as container registries, so one system can hold firmware, libraries and images under a common access and retention policy.