Skip to content

Feature request: Support 3rd party private container registries + authentication like EKS #432

Description

Problem

Substrate's atelet currently only supports GCP Application Default Credentials for authenticating image pulls (--gcp-auth-for-image-pulls). Users running on other cloud providers — EKS (AWS ECR), AKS (Azure ACR), or self-hosted registries — have no way to pull images from private registries.

Current behavior

  • GCP ADC auth is supported via --gcp-auth-for-image-pulls
  • Local/localhost registry rewrites are supported via --localhost-registry-replacement
  • No support for AWS ECR, Azure ACR, GHCR, or generic Docker credential helpers

Proposed solution

Add pluggable registry authentication so operators can configure credentials for any OCI-compatible private registry. At minimum:

  • AWS ECR — IAM Roles for Service Accounts (IRSA) / instance profile token refresh
  • Azure ACR — Workload Identity / managed identity
  • Generic — static imagePullSecrets-style config (username/password or token) for self-hosted registries (Harbor, Artifactory, GHCR, etc.)

This likely maps to adding new flags or a credentials config file to atelet, and wiring additional authenticators into the go-containerregistry keychain used during image pulls (cmd/atelet/main.go).

Why it matters

Many teams run AI agent workloads on EKS or AKS and store their agent images in ECR/ACR. Without this, Substrate is effectively GCP-only for private image use cases.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions