Every image, tag, and layer — explained.
Browse your ECR estate the way you reason about it: repositories, tags, an image's config, and the actual layer filesystem — merged or per-layer, down to reading a file inside. All resolved through the pod's own IRSA role, with no static registry credential anywhere.
See inside the image — not just its metadata.
Most registry views stop at tags and a size. When you actually need to know what's in an image, you pull it, run it, and exec in. Registry lets you look without any of that.
Registry reads your ECR estate through the pod's IRSA role — ecr:DescribeRepositories and a short-lived GetAuthorizationToken, no static password in a secret. It lists repositories and tags, resolves an image's manifest (a multi-arch index resolves to linux/amd64), shows the config and the ordered layers joined to the command that produced each, and then goes further: it unpacks the layer blobs into a filesystem you can browse — a single layer's tar, or the flattened rootfs with whiteouts applied — and reads a file inline. All read-only.
No registry password in a secret. It reads ECR through the pod's IRSA role — keyless by construction.
Every tag, with its digest.
The image list is newest-push-first, each row carrying the immutable sha256 digest, size, and media type. Untagged images aren't hidden — they show up by digest. Values illustrative.
| tag | digest | size | pushed |
|---|---|---|---|
| latest | sha256:9f2c…e401 | 48.6 MB | 2026-07-12 |
| sha-a1b2c3d | sha256:71e0…09aa | 47.9 MB | 2026-07-10 |
| <untagged 4f9ab0c2d3e1> | sha256:4f9a…d3e1 | 12.3 MB | 2026-06-28 |
Each layer, and what made it.
Open an image and every layer is listed bottom-to-top with its digest, size, media type, and the build command from the config history. Then browse the layer's files. Values illustrative.
| # | digest | size | command |
|---|---|---|---|
| 1 | sha256:aa10… | 29.1 MB | ADD file:… in / |
| 2 | sha256:bb24… | 18.4 MB | COPY /botnoc-web /botnoc-web |
| 3 | sha256:cc07… | 1.1 MB | COPY assets /assets |
IRSA → ECR → v2 → filesystem.
Keyless at every step.
Authenticate
The pod assumes its IRSA role (fastverk-registry) — ecr:DescribeRepositories plus a short-lived GetAuthorizationToken. No static key is stored anywhere.
List
DescribeRepositories (filtered to your estate's prefixes) and DescribeImages (newest push first) fill the repository and tag views.
Resolve
For an image, the registry v2 API returns the manifest (an index resolves to linux/amd64), the config, and the ordered layers joined to the command that produced each.
Browse
Layer blobs are unpacked into a filesystem — view a single layer's tar or the flattened rootfs with whiteouts applied, and read a file inline (text capped, images inlined).
Look inside without pulling a thing.
The alternative is a static login, docker history for the commands, and pulling then exec-ing just to read one file.
Untagged images aren't hidden — they show up by digest. A digest is immutable; a tag isn't.
source · github.com/fastverk/plugin-registry
Prove it's safe to merge.
registry is one of 14 plugins in the fastverk console — hosted, or in your own cloud.