Container Images & Harbor Registry
All DuoKey components are distributed as signed container images from the DuoKey Harbor registry. This page lists the images you need, how to authenticate and pull them, and how to mirror them into your own registry for air-gapped sites.
registry.duokey.cloud — DuoKey's Harbor container registry. Credentials
(a robot/user account and token) are provisioned for your organization during
onboarding.
Images to deploy
The exact, pinned image list for your release is provided with your delivery package. The Cockpit host image path below is the verified production reference; confirm all other paths and tags with DuoKey.
| Component | Image | Role |
|---|---|---|
| Cockpit host | registry.duokey.cloud/dke-cockpit/dke-cockpit-host | Cockpit backend (DKE / KMS / KMIP endpoints) + admin/user UI |
| DuoKey MPC KMS | provided in delivery package | DuoKey's own MPC cluster (3+ nodes) — key custody |
| Supporting services | PostgreSQL, Redis, OpenBao | Database, cache, secrets (community images, mirrorable) |
See the Release Notes for the current version tag and image digest.
latestFor reproducible, auditable, tamper-evident deployments, pin images by their
SHA-256 digest (immutable) rather than a moving tag — and never use latest.
Each release provides both a version tag and a digest, e.g. for v1.4:
- Tag:
v1.4.0.20260220.4adff9c8 - Digest:
dke-cockpit/dke-cockpit-host@sha256:816c0ec8f1d1d1f27d7d034a2e8b5728b1364f4f4bb256c478b6c49eca1d7b5d
Step 1 — Authenticate
docker login registry.duokey.cloud
When prompted:
- Username:
duokey@customer-<name>(provided by DuoKey) - Password: the token provided by DuoKey
For the cluster to pull images, create a pull secret from the same credentials and attach it to the DuoKey namespace's ServiceAccount:
oc create secret docker-registry duokey-harbor \
--docker-server=registry.duokey.cloud \
--docker-username='duokey@customer-<name>' \
--docker-password='<token>' \
-n duokey
oc secrets link default duokey-harbor --for=pull -n duokey
Step 2 — Pull an image
docker pull registry.duokey.cloud/<project>/<image>:<tag>
Example (v1.4 Cockpit host, pinned by tag):
docker pull registry.duokey.cloud/dke-cockpit/dke-cockpit-host:v1.4.0.20260220.4adff9c8
Or pinned by digest (recommended — immutable):
docker pull registry.duokey.cloud/dke-cockpit/dke-cockpit-host@sha256:816c0ec8f1d1d1f27d7d034a2e8b5728b1364f4f4bb256c478b6c49eca1d7b5d
Air-gapped: mirror into your own registry
For disconnected environments, mirror the DuoKey images once into your internal registry (your own Harbor, Quay, or the OpenShift internal registry), then have the cluster pull from there.
# On a host with access to both registries.
# Use the exact image list/tags from your DuoKey delivery package.
REL=1.2.0
for img in cockpit cockpit-api; do
docker pull registry.duokey.cloud/duokey/$img:$REL
docker tag registry.duokey.cloud/duokey/$img:$REL \
harbor.corp.example.local/duokey/$img:$REL
docker push harbor.corp.example.local/duokey/$img:$REL
done
Or use oc image mirror / skopeo copy for an automated, repeatable mirror:
skopeo copy --all \
docker://registry.duokey.cloud/duokey/cockpit:1.2.0 \
docker://harbor.corp.example.local/duokey/cockpit:1.2.0
Then point the deployment's image: references (or the Kustomize/Helm registry
override) at harbor.corp.example.local.
Image trust & scanning
DuoKey Harbor images are signed and vulnerability-scanned. On your side:
- Verify signatures with cosign before admission (see Platform Hardening → Image security).
- Re-scan mirrored images in your own registry against your CVE policy.
- Restrict the cluster so it pulls only from your trusted/mirrored registry.
Troubleshooting image pulls
| Error | Cause | Fix |
|---|---|---|
unauthorized: unauthorized to access repository | Wrong credentials or expired token | Re-enter credentials or contact DuoKey |
not found | Image or tag does not exist | Confirm the exact image name and tag with DuoKey |
connection refused | Network / firewall issue | Allow outbound HTTPS (443) toregistry.duokey.cloud, or use your mirror |
ImagePullBackOff (in OpenShift) | Missing/incorrect pull secret | Verify theduokey-harbor pull secret is linked to the ServiceAccount |
x509: certificate signed by unknown authority | Internal mirror uses a private CA | Add your CA to the cluster's trusted bundle |
Once images are available (directly or mirrored), continue to Installation.