You need Docker running (set up in lesson 3.1.1), the Learn samples you cloned in lesson 3.4.5, and a Docker Hub or GitHub account.
Which registry?
Either works for every lab in this path. Pick Docker Hub if you already have an account there, GHCR if your code lives on GitHub. Wherever this lesson says <you>, use your username in lowercase.
Build the image
You'll push
compose-web, the small web app you'll run with Compose in the next module. Lesson 3.4.5 left you inlearn/labs/bloated-app, so from there:cd ../compose-stack/app docker build --platform linux/amd64 -t compose-web:1.0.0 .Starting fresh?
git clone https://github.com/computesphere-samples/learn.git, thencd learn/labs/compose-stack/app.--platform linux/amd64builds for the processors most servers use, ComputeSphere's included. Built on an Apple Silicon Mac without it, the image won't start on ComputeSphere.You should seeA build that ends with naming to docker.io/library/compose-web:1.0.0.
Make a token
In Docker Hub, create a repository named
compose-weband set it to Public. Then go to Account settings, Personal access tokens, Generate new token, with read and write access.On GitHub, go to Settings, Developer settings, Personal access tokens, Tokens (classic), and generate one with the
write:packagesscope. GHCR doesn't accept fine-grained tokens.You should seeA token copied somewhere safe; it's shown only once.
Sign in
read -s CR_PAT # paste the token, then Enterecho "$CR_PAT" | docker login -u <you> --password-stdinecho "$CR_PAT" | docker login ghcr.io -u <you> --password-stdinThen
unset CR_PAT, so the token doesn't linger in your shell.You should seeLogin Succeeded
Tag it for the registry
docker tag compose-web:1.0.0 <you>/compose-web:1.0.0docker tag compose-web:1.0.0 ghcr.io/<you>/compose-web:1.0.0docker image lsA tag is a second name for the same image, so nothing is copied.
You should seeTwo names with the same image ID.
Push it
docker push <you>/compose-web:1.0.0 # Docker Hub docker push ghcr.io/<you>/compose-web:1.0.0 # GHCROnly layers the registry doesn't already have are uploaded, so the next push of a small change is quick.
You should seeThe layers upload, then a line with 1.0.0 and a sha256 digest.
Make it public
Docker Hub: open your
compose-webrepository; it's already public.GHCR: on GitHub open Your profile, then Packages, then
compose-web. Choose Package settings, then Change visibility under Danger Zone, and pick Public. A public package can't be made private again.You should seeThe image page shows the 1.0.0 tag and Public.
Pull it back as a stranger
Sign out, delete your local copies, and run it from the registry.
<image>is the full name you pushed. The app listens on 3000; if port 3000 is taken on your machine, use-p 3001:3000andlocalhost:3001.docker logout # add ghcr.io for GHCR docker rmi compose-web:1.0.0 <image> docker run -d --rm --name compose-web --platform linux/amd64 -p 3000:3000 <image> curl localhost:3000/healthz docker rm -f compose-webDocker pulls it with no credentials, so ComputeSphere can too.
--platform linux/amd64matters on an Apple Silicon Mac: you built the image for amd64 in step 1, and without the flag Docker stops withno matching manifest for linux/arm64/v8. With it, Docker runs the image in emulation. On other machines the flag changes nothing.Check yourself
You should see{"status":"ok"}