Skip to main content

Registries page

Helm chart sources DT Edge Platform installs releases from. The same row can also drive image-pull credentials for the install namespace.

Sidebar → Registries. Org-scoped. Super-admin's Public counterpart lives at Admin → Registries (only visible when the license carries MaxPublicRegistries > 0).

List view​

Filter chips: search, type (oci / default), is_image_registry.

ColumnMeaning
NameDisplay label
URLChart endpoint (oci://... or https://...)
Typeoci (OCI registry) or default (HTTP repo)
Image registryBadge if the row also serves as image-pull credentials
CreatedTimestamp
ActionsTest / Edit / Upload / Delete

Empty state: "No registries yet" with a primary Add registry CTA.

Add registry drawer​

Fields:

  • Name — display name (e.g. harbor-prod)
  • URL — the chart endpoint:
    • OCI: oci://harbor.example.com/charts
    • HTTP repo: https://charts.example.com
  • Type — oci or default. Modern setups are OCI; default is for legacy ChartMuseum-style repos
  • Username + password — basic auth credentials. Encrypted with the master key on save; you don't see them again.
  • Insecure skip TLS verify — only for self-signed CA setups
  • Is image registry — flip on when the same hostname also hosts container images. DT Edge Platform creates a dockerconfigjson Secret in the install namespace and patches the default ServiceAccount with imagePullSecrets at install time
  • Image registry host — only relevant when is_image_registry is on AND the image hostname differs from the chart URL host. Empty → derived from the URL.

The image-pull Secret is named deterministically (dtedge-pull-<host>-<id8>), so multiple registry rows targeting the same hostname don't collide.

Edit drawer​

Same fields as Add. Type cannot be changed (it's pinned at create). Password stays masked — leave blank to keep, type a new value to replace.

Edits take effect on the next install. Releases that already have an image-pull Secret in their namespace continue using the existing Secret until they're upgraded or reinstalled.

Test action​

Row actions → Test. Probes the registry with the configured credentials. Reports either success ("Connected to registry") or the upstream's error.

Common Test outcomes:

  • 401 Unauthorized — wrong username / password
  • Connection refused — wrong URL, registry down, or egress firewall blocking
  • TLS error: x509: certificate signed by unknown authority — self-signed cert + insecure_skip_verify not flipped on

Upload drawer (OCI only)​

Row actions → Upload. Push a chart .tgz straight from the browser into the OCI registry. Useful for testing or for on-prem operators who don't want to install helm CLI.

  • Chart file — drag-drop or click to pick a .tgz
  • Repository path — defaults to the chart's name from Chart.yaml; override if you need a different artifact name
  • Tag — defaults to the chart version; override for tags like latest

The progress bar shows multi-stage transfer (uploading → manifest upload → signature). Cancel button aborts the in-flight transfer.

Only OCI registries support upload — HTTP repos ignore the button.

Delete​

Row actions → Delete. DT Edge Platform refuses if any marketplace package or active release references this registry. Either re-bind those rows to another registry first, or confirm the warning to proceed (ongoing installs will be left without their image-pull Secret).

Per-org vs Public​

  • Org-scoped (the common case) — only members of the owning org see the registry as an install source
  • Public / global — managed by super-admins via Admin → Registries. Visible to every org as install sources. The license cap MaxPublicRegistries gates how many can exist.

If you find yourself adding the same registry to many orgs, ask your admin to register it once as a public one.

What this page does NOT do​

  • Mirror or proxy charts — DT Edge Platform always pulls live from the registry URL at install time. To pre-mirror, push to the registry yourself with helm push
  • Manage registry retention / cleanup — that's the registry's own job (Harbor's retention policy etc.)
  • Cache image-pull Secrets across namespaces — Secrets are created per release namespace, every install

See also​