Conversation
docker-compose.yml now names its DefectDojo images
${DD_IMAGE_REGISTRY:-registry.defectdojo.com}/defectdojo/defectdojo-*.
registry.defectdojo.com redirects every request to the same images on
Docker Hub; nothing is stored or changed there. It logs each pull so the
project can see where DefectDojo is installed.
DD_IMAGE_REGISTRY switches it off: docker.io pulls straight from Docker
Hub, and a mirror's host pulls from the mirror. `docker compose build`
tags images with the same name the file resolves to, so building and
running works either way.
CI sets DD_IMAGE_REGISTRY=docker.io in every workflow that runs Docker
Compose. The integration, performance and REST framework tests load
images CI built itself, tagged defectdojo/... (the same reference as
docker.io/defectdojo/...), so compose keeps using those builds instead of
pulling published images, and CI pulls never count as installs.
readme-docs/DOCKER.md documents the registry and the opt-out.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
devGregA
marked this pull request as ready for review
September 29, 2026 03:39
devGregA
enabled auto-merge (squash)
September 29, 2026 03:39
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
docker-compose.ymlnow pulls the DefectDojo images throughregistry.defectdojo.com:registry.defectdojo.comredirects every request to the same images on Docker Hub. Nothing is stored or changed there. Clients that drop credentials across a redirect (podman, CRI-O) get the same Docker Hub responses relayed. Each pull is logged (time, image, tag, client and requesting network) so the project can see where DefectDojo is installed. Only the publicdefectdojo/*images are served; any other name gets a 404.Opting out is one variable.
DD_IMAGE_REGISTRY=docker.iopulls straight from Docker Hub, and a mirror's host pulls from the mirror.docker compose buildtags images with the name the file resolves to, so building and running locally works the same either way.CI stays on Docker Hub. Every workflow that runs Docker Compose sets
DD_IMAGE_REGISTRY: docker.io:ci-warm-caches,fetch-oas,integration-tests,performance-testsandrest-framework-tests. The integration, performance and REST framework testsdocker loadimages CI built itself, taggeddefectdojo/...(the same reference asdocker.io/defectdojo/...). Compose therefore keeps using those builds, and never pulls a published image in their place. CI pulls also never count as installs.readme-docs/DOCKER.mdgains an "Image registry" section explaining the registry and the opt-out.Helm is unchanged: the chart's image references and the Helm repository URL stay as they are.
Testing
docker compose config --imagesresolves toregistry.defectdojo.com/defectdojo/defectdojo-{django,nginx}:latestby default, and todocker.io/defectdojo/defectdojo-django:debianwithDD_IMAGE_REGISTRY=docker.io DJANGO_VERSION=debian.docker pull registry.defectdojo.com/defectdojo/defectdojo-nginx:latestsucceeds. The pulled digest (sha256:2804d871…) is identical to Docker Hub's fordefectdojo/defectdojo-nginx:latest.docker compose pull nginxpulls through the gateway by default and straight from Docker Hub withDD_IMAGE_REGISTRY=docker.io; both names resolve to the same local image.helm repo add … https://charts.defectdojo.comlists the published charts.library/*and anything outside thedefectdojonamespace returns 404.🤖 Generated with Claude Code