Skip to main content

Add a helm registry

Register a chart source so installs can pull from it. Same row can also drive image-pull credentials for private container registries.

When you need this​

  • You have a private Harbor / GHCR / Quay / ECR with helm charts
  • The marketplace package you want to install (or publish) references a registry DT Edge Platform doesn't know yet
  • You need image-pull credentials for the install namespace

Add it​

Sidebar → Registries → Add registry.

Fill in:

  • Name — display name (e.g. harbor-prod)
  • URL — the chart endpoint:
    • For OCI: oci://harbor.example.com/charts
    • For HTTP repo: https://charts.example.com
  • Type — oci or default. Pick OCI for any modern registry; default is for legacy ChartMuseum-style HTTP repos
  • Username + password — basic auth credentials
  • Insecure skip TLS verify — only for self-signed Harbor / private CA setups; default off

Save. DT Edge Platform encrypts the password with its master key; you won't see it again.

Image-pull credentials (the same row, two jobs)​

Most Harbor / Quay / GHCR setups host charts and images on the same hostname. DT Edge Platform has a flag that lets you reuse the same registry row for both:

  • Is image registry — flip this on. At install time, DT Edge Platform creates a dockerconfigjson Secret in the install namespace, patches the default ServiceAccount with imagePullSecrets, and injects helm --set overrides for both top-level imagePullSecrets[N].name AND Bitnami-style global.imagePullSecrets[N].name.

If chart and image hostnames differ (e.g. chart at charts.acme.com but images at registry.acme.com):

  • Image registry host — fill this with the image hostname. Empty → derived from the URL host.

The Secret name is deterministic (dtedge-pull-<host>-<id8>), so two registry rows pointing at the same hostname don't collide.

Test the connection​

After saving, the row's actions menu has Test — runs a probe against the registry with the configured credentials. Reports success / failure with the upstream's response.

If Test fails:

  • 401 Unauthorized — wrong username / password
  • Connection refused — URL is wrong, registry is down, or egress firewall is blocking
  • TLS error — self-signed cert + insecure_skip_verify not flipped

Edit a registry​

Click the row → Edit. You can change anything except the type. The password field stays masked; leave it blank to keep the existing one, or type a new one to replace.

Changes take effect on the next install — releases that already have an imagePullSecrets Secret in their namespace keep using it until they're upgraded or reinstalled.

Delete a registry​

Row actions → Delete.

DT Edge Platform refuses if any marketplace package or active install currently references this registry. Either re-bind those to another registry first or accept that ongoing installs will be left without their image-pull Secret.

Per-org vs global registries​

  • Org-scoped registries (the common case) — only members of the owning org see them
  • Global registries — super-admins manage these via Admin → Registries. Only surfaces when the active license carries MaxPublicRegistries > 0. Available to every org as install sources.

If you want a registry available to everyone in your install, ask your admin to add it as a global one rather than registering it once per org.

Common errors​

  • pull access denied during an install → registry creds wrong; Test the registry, then update if needed
  • x509: certificate signed by unknown authority — flip insecure_skip_verify on if you trust the registry; better long-term fix is to install the CA cert on the cluster nodes
  • ImagePullBackOff on pods after install — the image registry side wasn't wired in. Did you flip is_image_registry on the right row? Was the chart's image registry actually different (different hostname)?

See also​