Add a helm registry
Register a chart source so installs can pull from it. Same row can also drive image-pull credentials for private container registries.
When you need this
- You have a private Harbor / GHCR / Quay / ECR with helm charts
- The marketplace package you want to install (or publish) references a registry DT Edge Platform doesn't know yet
- You need image-pull credentials for the install namespace
Add it
Sidebar → Registries → Add registry.
Fill in:
- Name — display name (e.g.
harbor-prod) - URL — the chart endpoint:
- For OCI:
oci://harbor.example.com/charts - For HTTP repo:
https://charts.example.com
- For OCI:
- Type —
ociordefault. Pick OCI for any modern registry;defaultis for legacy ChartMuseum-style HTTP repos - Username + password — basic auth credentials
- Insecure skip TLS verify — only for self-signed Harbor / private CA setups; default off
Save. DT Edge Platform encrypts the password with its master key; you won't see it again.
Image-pull credentials (the same row, two jobs)
Most Harbor / Quay / GHCR setups host charts and images on the same hostname. DT Edge Platform has a flag that lets you reuse the same registry row for both:
- Is image registry — flip this on. At install time, DT Edge Platform
creates a
dockerconfigjsonSecret in the install namespace, patches the default ServiceAccount withimagePullSecrets, and injects helm--setoverrides for both top-levelimagePullSecrets[N].nameAND Bitnami-styleglobal.imagePullSecrets[N].name.
If chart and image hostnames differ (e.g. chart at
charts.acme.com but images at registry.acme.com):
- Image registry host — fill this with the image hostname. Empty → derived from the URL host.
The Secret name is deterministic
(dtedge-pull-<host>-<id8>), so two registry rows pointing at
the same hostname don't collide.
Test the connection
After saving, the row's actions menu has Test — runs a probe against the registry with the configured credentials. Reports success / failure with the upstream's response.
If Test fails:
- 401 Unauthorized — wrong username / password
- Connection refused — URL is wrong, registry is down, or egress firewall is blocking
- TLS error — self-signed cert + insecure_skip_verify not flipped
Edit a registry
Click the row → Edit. You can change anything except the type. The password field stays masked; leave it blank to keep the existing one, or type a new one to replace.
Changes take effect on the next install — releases that already
have an imagePullSecrets Secret in their namespace keep using
it until they're upgraded or reinstalled.
Delete a registry
Row actions → Delete.
DT Edge Platform refuses if any marketplace package or active install currently references this registry. Either re-bind those to another registry first or accept that ongoing installs will be left without their image-pull Secret.
Per-org vs global registries
- Org-scoped registries (the common case) — only members of the owning org see them
- Global registries — super-admins manage these via
Admin → Registries. Only surfaces when the active license
carries
MaxPublicRegistries > 0. Available to every org as install sources.
If you want a registry available to everyone in your install, ask your admin to add it as a global one rather than registering it once per org.
Common errors
pull access deniedduring an install → registry creds wrong; Test the registry, then update if neededx509: certificate signed by unknown authority— flipinsecure_skip_verifyon if you trust the registry; better long-term fix is to install the CA cert on the cluster nodesImagePullBackOffon pods after install — the image registry side wasn't wired in. Did you flipis_image_registryon the right row? Was the chart's image registry actually different (different hostname)?
See also
- How-to: install an application
- How-to: publish a marketplace package
- Reference: Registries page
- Backend docs: Concept → Helm registries