Private images and registry credentials

Reading · 5 min · Module 8, lesson 1 of 660 min left in this module

Module 8 · Deploy as codeLesson 1 of 6

Goal: Deploy an image from a private registry without putting credentials anywhere they can leak.

Key idea

To run a private image, ComputeSphere needs a registry login. Give it a read-only token, and pass it through an environment variable so it never lands in a file or your shell history.

Public images can be pulled by anyone. Most real apps live in private registries such as GitHub Container Registry, private Docker Hub repositories or Azure Container Registry. ComputeSphere needs permission to pull from them, now and every time it starts a spherelet later.

What ComputeSphere needs

  • Registry URL, for example https://ghcr.io.
  • Username to pull as.
  • Password, or better, a token created for pulling only.

Deploy a private image

First put the token in a shell variable without typing it into a command. read -s asks for it without showing what you type:

read -s REGISTRY_PASSWORD
export REGISTRY_PASSWORD

Then deploy:

csph deploy \
  --image ghcr.io/your-org/your-app:1.4.0 \
  --name your-app \
  --port 8080 \
  --registry-url https://ghcr.io \
  --registry-username your-user \
  --registry-password "$REGISTRY_PASSWORD"

csph needs all three registry flags together. It won't write credentials into a manifest, even with --write.

Deploying a private image from the console

When you choose an image for a service in the console, pick Private (“Requires registry credentials”), then fill in Registry URL, Username and Password.

csph assumes a Docker-compatible registry. Add --image-provider if yours needs a different provider.

Use a pull-only token

Don't give ComputeSphere your personal password. Every major registry lets you make a token that can only read images:

  • GitHub Container Registry: a personal access token with only read:packages.
  • Docker Hub: an access token with read-only permission.
  • Cloud registries: a service identity with pull (reader) rights only.

If it leaks, someone can download your images but can't push a malicious one in their place.

Tag every release

:latest changes whenever someone pushes. Use a version or commit tag (:1.4.0, :3f9c2a7) so each version records exactly which image it ran, and a rollback returns to exactly that image.

Check yourself

Why pass the password as $REGISTRY_PASSWORD instead of typing it into the command?

In the docs