image registry

Every image, tag, and layer — explained.

Browse your ECR estate the way you reason about it: repositories, tags, an image's config, and the actual layer filesystem — merged or per-layer, down to reading a file inside. All resolved through the pod's own IRSA role, with no static registry credential anywhere.

available
Lists your estate's ECR repos + tagsDrills into an image's config and ordered layersBrowse the real layer filesystem — merged or per-layerRead a file inside an image, inlineKeyless — reads via the pod's IRSA role, no static credential
keyless
reads via IRSA
no static registry credential
layers
browse the filesystem
per-layer tar + flattened rootfs
sha256
every image, by digest
immutable identity
read-only
explore, never mutate
DescribeImages + registry v2
why it's different

See inside the image — not just its metadata.

Most registry views stop at tags and a size. When you actually need to know what's in an image, you pull it, run it, and exec in. Registry lets you look without any of that.

Registry reads your ECR estate through the pod's IRSA role — ecr:DescribeRepositories and a short-lived GetAuthorizationToken, no static password in a secret. It lists repositories and tags, resolves an image's manifest (a multi-arch index resolves to linux/amd64), shows the config and the ordered layers joined to the command that produced each, and then goes further: it unpacks the layer blobs into a filesystem you can browse — a single layer's tar, or the flattened rootfs with whiteouts applied — and reads a file inline. All read-only.

No registry password in a secret. It reads ECR through the pod's IRSA role — keyless by construction.

plugin-registry · reads via IRSA
the console

Every tag, with its digest.

The image list is newest-push-first, each row carrying the immutable sha256 digest, size, and media type. Untagged images aren't hidden — they show up by digest. Values illustrative.

Images · botnoc-web
registry.v1.RegistryExplorer · ListTags
tagdigestsizepushed
latest sha256:9f2c…e401 48.6 MB 2026-07-12
sha-a1b2c3d sha256:71e0…09aa 47.9 MB 2026-07-10
<untagged 4f9ab0c2d3e1> sha256:4f9a…d3e1 12.3 MB 2026-06-28
index → : resolves to linux/amd64 on openfilter: your estate's repo prefixes
inside an image

Each layer, and what made it.

Open an image and every layer is listed bottom-to-top with its digest, size, media type, and the build command from the config history. Then browse the layer's files. Values illustrative.

botnoc-web@sha256:9f2c… · layers
Manifest · ordered layers · config history
#digestsizecommand
1 sha256:aa10… 29.1 MB ADD file:… in /
2 sha256:bb24… 18.4 MB COPY /botnoc-web /botnoc-web
3 sha256:cc07… 1.1 MB COPY assets /assets
browse: per-layer tar or flattened rootfs (whiteouts applied)files: read a file inside, inline
the pipeline

IRSA → ECR → v2 → filesystem.

Keyless at every step.

01

Authenticate

The pod assumes its IRSA role (fastverk-registry) — ecr:DescribeRepositories plus a short-lived GetAuthorizationToken. No static key is stored anywhere.

02

List

DescribeRepositories (filtered to your estate's prefixes) and DescribeImages (newest push first) fill the repository and tag views.

03

Resolve

For an image, the registry v2 API returns the manifest (an index resolves to linux/amd64), the config, and the ordered layers joined to the command that produced each.

04

Browse

Layer blobs are unpacked into a filesystem — view a single layer's tar or the flattened rootfs with whiteouts applied, and read a file inline (text capped, images inlined).

vs pull-run-exec

Look inside without pulling a thing.

The alternative is a static login, docker history for the commands, and pulling then exec-ing just to read one file.

fastverk registry
docker CLI spelunking
Access
✓ Keyless via IRSA
docker login with a static credential
Layers
✓ Browse the actual filesystem, merged or per-layer
docker history — commands only
Files
✓ Read a file inside an image, inline
Pull, run, exec, cat
Estate
✓ Your whole ECR estate in one console
One image at a time on your laptop
Identity
✓ Every image addressed by its sha256 digest
Tags that move under you

Untagged images aren't hidden — they show up by digest. A digest is immutable; a tag isn't.

plugin-registry · read-only, keyless

source · github.com/fastverk/plugin-registry

Prove it's safe to merge.

registry is one of 14 plugins in the fastverk console — hosted, or in your own cloud.