Skip to main content

Container Images & Harbor Registry

All DuoKey components are distributed as signed container images from the DuoKey Harbor registry. This page lists the images you need, how to authenticate and pull them, and how to mirror them into your own registry for air-gapped sites.

Registry

registry.duokey.cloud — DuoKey's Harbor container registry. Credentials (a robot/user account and token) are provisioned for your organization during onboarding.

Images to deploy​

The exact, pinned image list for your release is provided with your delivery package. The Cockpit host image path below is the verified production reference; confirm all other paths and tags with DuoKey.

ComponentImageRole
Cockpit hostregistry.duokey.cloud/dke-cockpit/dke-cockpit-hostCockpit backend (DKE / KMS / KMIP endpoints) + admin/user UI
DuoKey MPC KMSprovided in delivery packageDuoKey's own MPC cluster (3+ nodes) — key custody
Supporting servicesPostgreSQL, Redis, OpenBaoDatabase, cache, secrets (community images, mirrorable)

See the Release Notes for the current version tag and image digest.

Pin by digest, not latest

For reproducible, auditable, tamper-evident deployments, pin images by their SHA-256 digest (immutable) rather than a moving tag — and never use latest. Each release provides both a version tag and a digest, e.g. for v1.4:

  • Tag: v1.4.0.20260220.4adff9c8
  • Digest: dke-cockpit/dke-cockpit-host@sha256:816c0ec8f1d1d1f27d7d034a2e8b5728b1364f4f4bb256c478b6c49eca1d7b5d

Step 1 — Authenticate​

docker login registry.duokey.cloud

When prompted:

  • Username: duokey@customer-<name> (provided by DuoKey)
  • Password: the token provided by DuoKey
OpenShift pull secret

For the cluster to pull images, create a pull secret from the same credentials and attach it to the DuoKey namespace's ServiceAccount:

oc create secret docker-registry duokey-harbor \
--docker-server=registry.duokey.cloud \
--docker-username='duokey@customer-<name>' \
--docker-password='<token>' \
-n duokey

oc secrets link default duokey-harbor --for=pull -n duokey

Step 2 — Pull an image​

docker pull registry.duokey.cloud/<project>/<image>:<tag>

Example (v1.4 Cockpit host, pinned by tag):

docker pull registry.duokey.cloud/dke-cockpit/dke-cockpit-host:v1.4.0.20260220.4adff9c8

Or pinned by digest (recommended — immutable):

docker pull registry.duokey.cloud/dke-cockpit/dke-cockpit-host@sha256:816c0ec8f1d1d1f27d7d034a2e8b5728b1364f4f4bb256c478b6c49eca1d7b5d

Air-gapped: mirror into your own registry​

For disconnected environments, mirror the DuoKey images once into your internal registry (your own Harbor, Quay, or the OpenShift internal registry), then have the cluster pull from there.

# On a host with access to both registries.
# Use the exact image list/tags from your DuoKey delivery package.
REL=1.2.0
for img in cockpit cockpit-api; do
docker pull registry.duokey.cloud/duokey/$img:$REL
docker tag registry.duokey.cloud/duokey/$img:$REL \
harbor.corp.example.local/duokey/$img:$REL
docker push harbor.corp.example.local/duokey/$img:$REL
done

Or use oc image mirror / skopeo copy for an automated, repeatable mirror:

skopeo copy --all \
docker://registry.duokey.cloud/duokey/cockpit:1.2.0 \
docker://harbor.corp.example.local/duokey/cockpit:1.2.0

Then point the deployment's image: references (or the Kustomize/Helm registry override) at harbor.corp.example.local.

Image trust & scanning​

DuoKey Harbor images are signed and vulnerability-scanned. On your side:

  • Verify signatures with cosign before admission (see Platform Hardening → Image security).
  • Re-scan mirrored images in your own registry against your CVE policy.
  • Restrict the cluster so it pulls only from your trusted/mirrored registry.

Troubleshooting image pulls​

ErrorCauseFix
unauthorized: unauthorized to access repositoryWrong credentials or expired tokenRe-enter credentials or contact DuoKey
not foundImage or tag does not existConfirm the exact image name and tag with DuoKey
connection refusedNetwork / firewall issueAllow outbound HTTPS (443) toregistry.duokey.cloud, or use your mirror
ImagePullBackOff (in OpenShift)Missing/incorrect pull secretVerify theduokey-harbor pull secret is linked to the ServiceAccount
x509: certificate signed by unknown authorityInternal mirror uses a private CAAdd your CA to the cluster's trusted bundle

Once images are available (directly or mirrored), continue to Installation.