Skip to content

Pull the Docker Compose images through registry.defectdojo.com - #16121

Open
devGregA wants to merge 1 commit into
DefectDojo:devfrom
devGregA:devgrega/compose-registry-gateway
Open

devGregA wants to merge 1 commit into
DefectDojo:devfrom
devGregA:devgrega/compose-registry-gateway

Conversation

@devGregA

@devGregA devGregA commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary

docker-compose.yml now pulls the DefectDojo images through registry.defectdojo.com:

image: "${DD_IMAGE_REGISTRY:-registry.defectdojo.com}/defectdojo/defectdojo-django:${DJANGO_VERSION:-latest}"

registry.defectdojo.com redirects every request to the same images on Docker Hub. Nothing is stored or changed there. Clients that drop credentials across a redirect (podman, CRI-O) get the same Docker Hub responses relayed. Each pull is logged (time, image, tag, client and requesting network) so the project can see where DefectDojo is installed. Only the public defectdojo/* images are served; any other name gets a 404.

Opting out is one variable. DD_IMAGE_REGISTRY=docker.io pulls straight from Docker Hub, and a mirror's host pulls from the mirror. docker compose build tags images with the name the file resolves to, so building and running locally works the same either way.

CI stays on Docker Hub. Every workflow that runs Docker Compose sets DD_IMAGE_REGISTRY: docker.io: ci-warm-caches, fetch-oas, integration-tests, performance-tests and rest-framework-tests. The integration, performance and REST framework tests docker load images CI built itself, tagged defectdojo/... (the same reference as docker.io/defectdojo/...). Compose therefore keeps using those builds, and never pulls a published image in their place. CI pulls also never count as installs.

readme-docs/DOCKER.md gains an "Image registry" section explaining the registry and the opt-out.

Helm is unchanged: the chart's image references and the Helm repository URL stay as they are.

Testing

  • docker compose config --images resolves to registry.defectdojo.com/defectdojo/defectdojo-{django,nginx}:latest by default, and to docker.io/defectdojo/defectdojo-django:debian with DD_IMAGE_REGISTRY=docker.io DJANGO_VERSION=debian.
  • The five workflows parse and carry the variable at workflow level.
  • Against the live gateway:
    • docker pull registry.defectdojo.com/defectdojo/defectdojo-nginx:latest succeeds. The pulled digest (sha256:2804d871…) is identical to Docker Hub's for defectdojo/defectdojo-nginx:latest.
    • docker compose pull nginx pulls through the gateway by default and straight from Docker Hub with DD_IMAGE_REGISTRY=docker.io; both names resolve to the same local image.
    • helm repo add … https://charts.defectdojo.com lists the published charts.
    • library/* and anything outside the defectdojo namespace returns 404.

🤖 Generated with Claude Code

docker-compose.yml now names its DefectDojo images
${DD_IMAGE_REGISTRY:-registry.defectdojo.com}/defectdojo/defectdojo-*.
registry.defectdojo.com redirects every request to the same images on
Docker Hub; nothing is stored or changed there. It logs each pull so the
project can see where DefectDojo is installed.

DD_IMAGE_REGISTRY switches it off: docker.io pulls straight from Docker
Hub, and a mirror's host pulls from the mirror. `docker compose build`
tags images with the same name the file resolves to, so building and
running works either way.

CI sets DD_IMAGE_REGISTRY=docker.io in every workflow that runs Docker
Compose. The integration, performance and REST framework tests load
images CI built itself, tagged defectdojo/... (the same reference as
docker.io/defectdojo/...), so compose keeps using those builds instead of
pulling published images, and CI pulls never count as installs.

readme-docs/DOCKER.md documents the registry and the opt-out.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@devGregA devGregA added this to the 3.4.0 milestone Sep 29, 2026
@devGregA
devGregA marked this pull request as ready for review September 29, 2026 03:39
@devGregA
devGregA enabled auto-merge (squash) September 29, 2026 03:39

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant