Registries page
Helm chart sources DT Edge Platform installs releases from. The same row can also drive image-pull credentials for the install namespace.
Sidebar → Registries. Org-scoped. Super-admin's Public
counterpart lives at Admin → Registries (only visible when
the license carries MaxPublicRegistries > 0).
List view
Filter chips: search, type (oci / default),
is_image_registry.
| Column | Meaning |
|---|---|
| Name | Display label |
| URL | Chart endpoint (oci://... or https://...) |
| Type | oci (OCI registry) or default (HTTP repo) |
| Image registry | Badge if the row also serves as image-pull credentials |
| Created | Timestamp |
| Actions | Test / Edit / Upload / Delete |
Empty state: "No registries yet" with a primary Add registry CTA.
Add registry drawer
Fields:
- Name — display name (e.g.
harbor-prod) - URL — the chart endpoint:
- OCI:
oci://harbor.example.com/charts - HTTP repo:
https://charts.example.com
- OCI:
- Type —
ociordefault. Modern setups are OCI;defaultis for legacy ChartMuseum-style repos - Username + password — basic auth credentials. Encrypted with the master key on save; you don't see them again.
- Insecure skip TLS verify — only for self-signed CA setups
- Is image registry — flip on when the same hostname also
hosts container images. DT Edge Platform creates a
dockerconfigjsonSecret in the install namespace and patches the default ServiceAccount withimagePullSecretsat install time - Image registry host — only relevant when
is_image_registryis on AND the image hostname differs from the chart URL host. Empty → derived from the URL.
The image-pull Secret is named deterministically
(dtedge-pull-<host>-<id8>), so multiple registry rows targeting
the same hostname don't collide.
Edit drawer
Same fields as Add. Type cannot be changed (it's pinned at create). Password stays masked — leave blank to keep, type a new value to replace.
Edits take effect on the next install. Releases that already have an image-pull Secret in their namespace continue using the existing Secret until they're upgraded or reinstalled.
Test action
Row actions → Test. Probes the registry with the configured credentials. Reports either success ("Connected to registry") or the upstream's error.
Common Test outcomes:
- 401 Unauthorized — wrong username / password
- Connection refused — wrong URL, registry down, or egress firewall blocking
- TLS error: x509: certificate signed by unknown authority —
self-signed cert +
insecure_skip_verifynot flipped on
Upload drawer (OCI only)
Row actions → Upload. Push a chart .tgz straight from the
browser into the OCI registry. Useful for testing or for
on-prem operators who don't want to install helm CLI.
- Chart file — drag-drop or click to pick a
.tgz - Repository path — defaults to the chart's
namefrom Chart.yaml; override if you need a different artifact name - Tag — defaults to the chart
version; override for tags likelatest
The progress bar shows multi-stage transfer (uploading → manifest upload → signature). Cancel button aborts the in-flight transfer.
Only OCI registries support upload — HTTP repos ignore the button.
Delete
Row actions → Delete. DT Edge Platform refuses if any marketplace package or active release references this registry. Either re-bind those rows to another registry first, or confirm the warning to proceed (ongoing installs will be left without their image-pull Secret).
Per-org vs Public
- Org-scoped (the common case) — only members of the owning org see the registry as an install source
- Public / global — managed by super-admins via
Admin → Registries. Visible to every org as install
sources. The license cap
MaxPublicRegistriesgates how many can exist.
If you find yourself adding the same registry to many orgs, ask your admin to register it once as a public one.
What this page does NOT do
- Mirror or proxy charts — DT Edge Platform always pulls live from the
registry URL at install time. To pre-mirror, push to the
registry yourself with
helm push - Manage registry retention / cleanup — that's the registry's own job (Harbor's retention policy etc.)
- Cache image-pull Secrets across namespaces — Secrets are created per release namespace, every install