Skip to content
Start here

Configure a private external image registry

client.Containers.Registries.New(ctx, params) (*RegistryNewResponse, error)
POST/accounts/{account_id}/containers/registries

Registers credentials for a supported private external image registry so Containers can pull images from it. This endpoint does not create a registry or upload an image. Public Docker Hub images and images in the Cloudflare managed registry do not require this configuration.

Refer to Image management for supported registries and instructions for storing registry credentials.

Security
API Token

The preferred authorization scheme for interacting with the Cloudflare API. Create a token.

Example:Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY
API Email + API Key

The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

Example:X-Auth-Email: user@example.com

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

Example:X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194
Accepted Permissions (at least one required)
Workers Containers Write
ParametersExpand Collapse
params RegistryNewParams
AccountID param.Field[string]

Path param: Account identifier.

Auth param.Field[RegistryNewParamsAuth]

Body param: Credentials for authenticating to a private external image registry. Store the private credential in Secrets Store before calling the API. Refer to Image management for the credential required by each supported registry provider.

PrivateCredential RegistryNewParamsAuthPrivateCredential

A reference to the private registry credential in Secrets Store. The referenced secret must have the containers scope. Raw secret values are not accepted.

SecretName string

Name of the secret within the store.

maxLength255
minLength1
StoreID string

Identifier of the Secrets Store containing the secret.

maxLength32
minLength32
PublicCredential string

The non-secret part of the registry credential: an AWS access key ID for ECR, a username for Docker Hub, or a service account email for Google Artifact Registry.

Domain param.Field[string]

Body param: Hostname of the private registry, without a scheme or image path. Supported hostnames are docker.io, AWS ECR hostnames, and Google Artifact Registry *-docker.pkg.dev hostnames.

Kind param.Field[RegistryNewParamsKind]

Body param: Registry provider. This must match domain: DockerHub for docker.io, ECR for AWS ECR, or GAR for Google Artifact Registry.

const RegistryNewParamsKindEcr RegistryNewParamsKind = "ECR"
const RegistryNewParamsKindDockerHub RegistryNewParamsKind = "DockerHub"
const RegistryNewParamsKindGar RegistryNewParamsKind = "GAR"
IsPublic param.Field[RegistryNewParamsIsPublic]Optional

Body param: Omit this field or set it to false. Public Docker Hub images do not require registry configuration and cannot be added with this endpoint.

const RegistryNewParamsIsPublicFalse RegistryNewParamsIsPublic = false
ReturnsExpand Collapse
type RegistryNewResponse struct{…}

An image registry added in a customer account.

CreatedAt string

UTC timestamp string in ISO 8601 format.

Domain string

A string representation of a domain name. See RFC-1034 (https://www.ietf.org/rfc/rfc1034.txt). Consider that the limit of a domain name is min 3 and max 253 ASCII characters.

Kind RegistryNewResponseKindOptional

The type of registry that is being configured.

One of the following:
const RegistryNewResponseKindEcr RegistryNewResponseKind = "ECR"
const RegistryNewResponseKindDockerHub RegistryNewResponseKind = "DockerHub"
const RegistryNewResponseKindGar RegistryNewResponseKind = "GAR"
const RegistryNewResponseKindDefault RegistryNewResponseKind = "default"
PublicKey stringOptional

Public component of the registry credentials. For managed registries this is a base64-encoded public key; for external registries the format depends on the registry provider.

Configure a private external image registry

package main

import (
  "context"
  "fmt"

  "github.com/cloudflare/cloudflare-go"
  "github.com/cloudflare/cloudflare-go/containers"
  "github.com/cloudflare/cloudflare-go/option"
)

func main() {
  client := cloudflare.NewClient(
    option.WithAPIToken("Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY"),
  )
  registry, err := client.Containers.Registries.New(context.TODO(), containers.RegistryNewParams{
    AccountID: cloudflare.F("account-123"),
    Auth: cloudflare.F(containers.RegistryNewParamsAuth{
      PrivateCredential: cloudflare.F(containers.RegistryNewParamsAuthPrivateCredential{
        SecretName: cloudflare.F("API_KEY"),
        StoreID: cloudflare.F("14758f1afd44c09b7992073ccf00b43d"),
      }),
      PublicCredential: cloudflare.F("example-user"),
    }),
    Domain: cloudflare.F("docker.io"),
    Kind: cloudflare.F(containers.RegistryNewParamsKindEcr),
  })
  if err != nil {
    panic(err.Error())
  }
  fmt.Printf("%+v\n", registry.CreatedAt)
}
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "result": {
    "created_at": "2021-04-01T12:32:41.488Z",
    "domain": "docker.io",
    "kind": "ECR",
    "public_key": "public_key"
  },
  "success": true
}
Returns Examples
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "result": {
    "created_at": "2021-04-01T12:32:41.488Z",
    "domain": "docker.io",
    "kind": "ECR",
    "public_key": "public_key"
  },
  "success": true
}