Container Registry Management

aj-geddes/useful-ai-prompts/skills/container-registry-management

by aj-geddes3f5182cfd739No license355 starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated 7 months ago

Manage container registries (Docker Hub, ECR, GCR) with image scanning, retention policies, and access control.

Includes scriptsDevOps & CloudSecurity
AI-generated overview

Manages container registries such as Docker Hub, ECR and GCR, covering image scanning, retention, access control and signing.

What it does
Provides guidance and configuration for operating container registries, including repository setup, image build and push workflows, vulnerability scanning, retention and cleanup policies, access control, image signing with Notary, monitoring and multi-region replication. It ships a configuration validation script and a starter YAML template, and points to reference guides for detailed implementations.
When to use it
Use it when storing and distributing container images, enforcing scanning and compliance, cleaning up old images, controlling registry access, or handling multi-region deployments and image signing.
Requirements
Requires a container registry account and credentials (for example AWS ECR, Docker Hub or GCR), registry CLI tooling such as the AWS CLI or Docker, and network access to the registry. It ships an executable script (scripts/validate-config.sh) and a YAML template.

Container Registry Management

Table of Contents

Overview

Implement comprehensive container registry management including image scanning, vulnerability detection, retention policies, access control, and multi-region replication.

When to Use

  • Container image storage and distribution
  • Security scanning and compliance
  • Image retention and cleanup
  • Registry access control
  • Multi-region deployments
  • Image signing and verification
  • Cost optimization

Quick Start

Minimal working example:

yaml
# ecr-setup.yamlapiVersion: v1kind: ConfigMapmetadata:  name: ecr-management  namespace: operationsdata:  setup-ecr.sh: |    #!/bin/bash    set -euo pipefail
    REGISTRY_NAME="myapp"    REGION="us-east-1"    ACCOUNT_ID="123456789012"
    echo "Setting up ECR repository..."
    # Create ECR repository    aws ecr create-repository \      --repository-name "$REGISTRY_NAME" \      --region "$REGION" \      --encryption-configuration encryptionType=KMS,kmsKey=arn:aws:kms:$REGION:$ACCOUNT_ID:key/12345678-1234-1234-1234-123456789012 \      --image-tag-mutability IMMUTABLE \      --image-scanning-configuration scanOnPush=true || true
// ... (see reference guides for full implementation)

Reference Guides

Detailed implementations in the references/ directory:

GuideContents
AWS ECR Setup and Management [blocked]AWS ECR Setup and Management
Container Image Build and Push [blocked]Container Image Build and Push
Image Signing with Notary [blocked]Image Signing with Notary
Registry Access Control [blocked]Registry Access Control
Registry Monitoring [blocked]Registry Monitoring

Best Practices

✅ DO

  • Scan images before deployment
  • Use image tag immutability
  • Implement retention policies
  • Control registry access with IAM
  • Sign images for verification
  • Replicate across regions
  • Monitor registry storage
  • Use private registries

❌ DON'T

  • Push to public registries
  • Use latest tag in production
  • Allow anonymous pulls
  • Store secrets in images
  • Keep old images indefinitely
  • Push without scanning
  • Use default credentials
  • Share registry credentials

Source and attribution

Source:aj-geddes/useful-ai-promptsinskills/container-registry-managementat commit3f5182c

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal

Container Registry Management · skills/container-registry-management Agent Skill | SourceWeft