Container Registry Management

aj-geddes/useful-ai-prompts/skills/container-registry-management

作者 aj-geddes3f5182cfd739無授權條款355 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫7 個月前更新

Manage container registries (Docker Hub, ECR, GCR) with image scanning, retention policies, and access control.

AI 產生的概覽

管理 Docker Hub、ECR、GCR 等容器映像登錄檔,涵蓋映像掃描、保留原則、存取控制與簽署。

功能
提供容器映像登錄檔維運的指引與設定,包括儲存庫建立、映像建置與推送流程、弱點掃描、保留與清理原則、存取控制、使用 Notary 進行映像簽署、監控以及多區域複寫。此技能附帶設定驗證指令碼與起始 YAML 範本,並指向參考指南以取得完整實作。
適用情境
適用於儲存與散布容器映像、執行掃描與合規要求、清理舊映像、控管登錄檔存取權限,以及處理多區域部署與映像簽署等情境。
執行需求
需要容器映像登錄檔帳號與憑證(例如 AWS ECR、Docker Hub 或 GCR)、登錄檔命令列工具(如 AWS CLI 或 Docker),以及存取登錄檔的網路連線。此技能附帶可執行指令碼(scripts/validate-config.sh)與 YAML 範本。

Container Registry Management

Table of Contents

Overview

Implement comprehensive container registry management including image scanning, vulnerability detection, retention policies, access control, and multi-region replication.

When to Use

  • Container image storage and distribution
  • Security scanning and compliance
  • Image retention and cleanup
  • Registry access control
  • Multi-region deployments
  • Image signing and verification
  • Cost optimization

Quick Start

Minimal working example:

yaml
# ecr-setup.yamlapiVersion: v1kind: ConfigMapmetadata:  name: ecr-management  namespace: operationsdata:  setup-ecr.sh: |    #!/bin/bash    set -euo pipefail
    REGISTRY_NAME="myapp"    REGION="us-east-1"    ACCOUNT_ID="123456789012"
    echo "Setting up ECR repository..."
    # Create ECR repository    aws ecr create-repository \      --repository-name "$REGISTRY_NAME" \      --region "$REGION" \      --encryption-configuration encryptionType=KMS,kmsKey=arn:aws:kms:$REGION:$ACCOUNT_ID:key/12345678-1234-1234-1234-123456789012 \      --image-tag-mutability IMMUTABLE \      --image-scanning-configuration scanOnPush=true || true
// ... (see reference guides for full implementation)

Reference Guides

Detailed implementations in the references/ directory:

GuideContents
AWS ECR Setup and Management [blocked]AWS ECR Setup and Management
Container Image Build and Push [blocked]Container Image Build and Push
Image Signing with Notary [blocked]Image Signing with Notary
Registry Access Control [blocked]Registry Access Control
Registry Monitoring [blocked]Registry Monitoring

Best Practices

✅ DO

  • Scan images before deployment
  • Use image tag immutability
  • Implement retention policies
  • Control registry access with IAM
  • Sign images for verification
  • Replicate across regions
  • Monitor registry storage
  • Use private registries

❌ DON'T

  • Push to public registries
  • Use latest tag in production
  • Allow anonymous pulls
  • Store secrets in images
  • Keep old images indefinitely
  • Push without scanning
  • Use default credentials
  • Share registry credentials

來源與署名

來源:aj-geddes/useful-ai-prompts位於skills/container-registry-management提交3f5182c

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架