What’s New with Docker Trusted Registry
(v1.4.0)?
Jon Chu & Rajat Goel
PM, Enterprise
Director of Engineering, Enterprise
Docker Trusted Registry Recap
2
Registry for building, storing and managing images securely, within
your firewall
Maintain control over Docker images to meet your security or
regulatory compliance requirements.
Content is King…to Build-Ship-Run
Run
Trusted Registry
Base Image Tested Production
Development Test Staging Production Scale Out
Build Ship
DTR Primary Usage Scenarios
CI/CD with
Docker
• Centrally located base images
• Store individual build images
• Pull tested images to production
Containers as
a Service
• Deploy Jenkins executors or Hadoop nodes
• Instant-on developer environment
• Selected curated apps from a catalog
• Dynamic composition of micro-services (“PAAS”)
Pre DTR 1.4
General
Features
• Admin & Health UI
• Registry Storage Status
• LDAP/AD Integration
• RBAC API (Admin, R/W, R/O)
• User actions/API audit logs
• Registry v2 API & v2 Image Support
• One click install/upgrade
Platform
Features
• Storage drivers for filesystem, s3, and azure
• Support Tooling
• Support for Ubuntu, RHEL, CentOS
• Tested at 300 concurrent pulls/instance
DTR 1.4 Release
General
Features
• Orgs, Teams & Repo permissions UI
• Search index, API & UI
• Interactive API documentation
• Image deletion from index
• Image garbage collection
Experimental • Docker Content Trust: View Docker Notary signatures in DTR
Architecture
Datastore
Storage
Drivers
Admin UIAudit and
Event logs
Directory
Services
Load
Balancer
Registry ServersAdmin
Server
Auth
Server
Log Aggregator
Docker Engines
PostgreSQL
LDAPS 636Local Syslog
Docker
Client
> docker
HTTPS 443
Demo Time
8
9
Deep Dive: Delete
10
Deep Dive: Delete
11
Deep Dive: Garbage Collection
12
Overview: Docker Content Trust
● Built on TUF
● Designed to make good security easy!
● Validates the publisher, not the safety of their
content!
13
Overview: Docker Content Trust
● Built on TUF
● Designed to make good security easy!
● Validates the publisher, not the safety of their
content!
14
Overview: Docker Content Trust
Image Forgery
15
Overview: Docker Content Trust
Why not GPG?
Replay Attacks
TOFUs
13
17
Docker Content Trust
Integration
Docker Universal Control
Plane Integration
Future Plans and Features
Docker Universal Control Plane Integration
● End-to-end authn integration with LDAP/AD
● Cross product RBAC across orgs
● Complete CI/CD visibility
Description
DCT: Image Promotion & Policy
Enforcement
● Cryptographically signed layers
● Promote images through signatures
● dev signed -> QA signed -> prod signed
● Policy enforcement through integrations
Description
Sysadmin
Dev
Prod
Ops
International Availability
Docker Subscription available for Europe
Hourly and annual
subscriptions available
from AWS Marketplace
Subscription licenses available
L1 and L2 support for US and
Europe
Bring your own license to
deploy Docker VHD in
Azure Marketplace to
European zones
www.docker.com/aws www.docker.com/ibm www.docker.com/microsoft
30 day free trial
www.docker.com/try-dtr
Thank you!
Jon & Rajat
@chu_jon, jon.chu@docker.com
@rajat_g, rajat.goel@docker.com

More Related Content

PDF
A vision of persistence
PDF
Activision's Skypilot: Delivering Amazing Game Experiences Through Containeri...
PPTX
DockerCon EU 2015: Speed Up Deployment: Building a Distributed Docker Registr...
PPTX
DockerCon EU 2015: It's in the game: the path to micro-services at Electronic...
PDF
It takes a Village to do the Impossible - Jeff Lindsay
PPTX
Experiences with AWS immutable deploys and job processing
PPTX
DockerCon EU 2015: The Missing Piece: when Docker networking unleashing soft ...
PDF
DockerCon EU 2015: Trading Bitcoin with Docker
A vision of persistence
Activision's Skypilot: Delivering Amazing Game Experiences Through Containeri...
DockerCon EU 2015: Speed Up Deployment: Building a Distributed Docker Registr...
DockerCon EU 2015: It's in the game: the path to micro-services at Electronic...
It takes a Village to do the Impossible - Jeff Lindsay
Experiences with AWS immutable deploys and job processing
DockerCon EU 2015: The Missing Piece: when Docker networking unleashing soft ...
DockerCon EU 2015: Trading Bitcoin with Docker

What's hot (20)

PDF
Docker on docker leveraging kubernetes in docker ee
PDF
DCSF 19 Data Center Networking with Containers
PDF
Docker Platform Internals: Taking runtimes and image creation to the next lev...
PDF
DockerCon EU 2015: The Latest in Docker Engine
PDF
Docker Networking in Production at Visa - Sasi Kannappan, Visa and Mark Churc...
PDF
Production Ready Containers from IBM and Docker
PPTX
DockerCon EU 2015: Docker Universal Control Plane (Gordon's Special Session)
PDF
DCEU 18: Docker Containers in a Serverless World
PDF
DockerCon 2017 - Cilium - Network and Application Security with BPF and XDP
PDF
DCSF19 How To Build Your Containerization Strategy
PDF
Docker Online Meetup #22: Docker Networking
PDF
Automated hardware testing using docker for space
PDF
Docker Birthday #3 - Intro to Docker Slides
PDF
Taking Docker from Local to Production at Intuit JanJaap Lahpor, Intuit and H...
PDF
DCSF19 How Docker Simplifies Kubernetes for the Masses
PDF
Docker?!?! But I'm a SysAdmin
PDF
Docker on Docker
PDF
DCSF19 Deploying Istio as an Ingress Controller
PPTX
Enabling Production Grade Containerized Applications through Policy Based Inf...
PPTX
DockerCon EU 2015: Placing a container on a train at 200mph
Docker on docker leveraging kubernetes in docker ee
DCSF 19 Data Center Networking with Containers
Docker Platform Internals: Taking runtimes and image creation to the next lev...
DockerCon EU 2015: The Latest in Docker Engine
Docker Networking in Production at Visa - Sasi Kannappan, Visa and Mark Churc...
Production Ready Containers from IBM and Docker
DockerCon EU 2015: Docker Universal Control Plane (Gordon's Special Session)
DCEU 18: Docker Containers in a Serverless World
DockerCon 2017 - Cilium - Network and Application Security with BPF and XDP
DCSF19 How To Build Your Containerization Strategy
Docker Online Meetup #22: Docker Networking
Automated hardware testing using docker for space
Docker Birthday #3 - Intro to Docker Slides
Taking Docker from Local to Production at Intuit JanJaap Lahpor, Intuit and H...
DCSF19 How Docker Simplifies Kubernetes for the Masses
Docker?!?! But I'm a SysAdmin
Docker on Docker
DCSF19 Deploying Istio as an Ingress Controller
Enabling Production Grade Containerized Applications through Policy Based Inf...
DockerCon EU 2015: Placing a container on a train at 200mph
Ad

Viewers also liked (20)

PDF
Docker Advanced registry usage
PDF
Docker Registry V2
PDF
containerd summit - Deep Dive into containerd
PDF
containerd and CRI
PDF
DockerCon EU 2015: Deploying and Managing Containers for Developers
PDF
DockerCon EU 2015: Official Repos and Project Nautilus
PDF
Docker Orchestration at Production Scale
PPTX
Docker Ecosystem: Part V - Docker Registry
PPTX
Docker Hub: Past, Present and Future by Ken Cochrane & BC Wong
PPTX
Docker 101 - Nov 2016
PPTX
Docker Overview - AWS Tech Connect - Seattle 10/28
PDF
Standalone Spark Deployment for Stability and Performance
PDF
Docker Registry + Basic Auth
PDF
Innovating Out In The Open - OSCON 2016
PDF
Docker registry入門 第五回コンテナ型仮想化の情報交換会
PDF
【dots. IT勉強会】開発環境のDocker化
PDF
Distributed, Real-time Web Apps
PPTX
OpenStack Boston
PDF
DockerCon EU 2015: Finding a Theory of the Universe with Docker and Volunteer...
PPTX
DockerCon SF 2015: How to talk to humans
Docker Advanced registry usage
Docker Registry V2
containerd summit - Deep Dive into containerd
containerd and CRI
DockerCon EU 2015: Deploying and Managing Containers for Developers
DockerCon EU 2015: Official Repos and Project Nautilus
Docker Orchestration at Production Scale
Docker Ecosystem: Part V - Docker Registry
Docker Hub: Past, Present and Future by Ken Cochrane & BC Wong
Docker 101 - Nov 2016
Docker Overview - AWS Tech Connect - Seattle 10/28
Standalone Spark Deployment for Stability and Performance
Docker Registry + Basic Auth
Innovating Out In The Open - OSCON 2016
Docker registry入門 第五回コンテナ型仮想化の情報交換会
【dots. IT勉強会】開発環境のDocker化
Distributed, Real-time Web Apps
OpenStack Boston
DockerCon EU 2015: Finding a Theory of the Universe with Docker and Volunteer...
DockerCon SF 2015: How to talk to humans
Ad

Similar to DockerCon EU 2015: What's New with Docker Trusted Registry (20)

PPTX
Docker Online Meetup #30: Docker Trusted Registry 1.4.1
PDF
DCEU 18: Docker Container Security
PDF
Building a Secure App with Docker - Ying Li and David Lawrence, Docker
PDF
DockerCon SF 2015: DHE/DTR
PPTX
Docker Roadshow 2016
PDF
Docker EE Deep Dive
PDF
Docker for Ops - Scott Coulton, Puppet
PDF
Docker Container-Introduction and Features
PPTX
Docker Security workshop slides
PDF
How Docker EE is Finnish Railway’s Ticket to App Modernization
PPTX
DockerCon EU 2015 Barcelona
PDF
Docker Enterprise Edition: Building a Secure Supply Chain for the Enterprise ...
PDF
Dockercon EU 2015 Recap
PDF
Docker Security and Content Trust
PDF
Containers, docker, and security: state of the union (Bay Area Infracoders Me...
PPTX
Docker Datacenter Overview and Production Setup Slides
PDF
What's hot docker con eu 2015 & what's new on docker 1.9
PDF
Containers, Docker, and Security: State Of The Union (LinuxCon and ContainerC...
PDF
Introduction to Docker, Devops Virtualization and configuration management
PDF
Docker security - TASK Jan 2016
Docker Online Meetup #30: Docker Trusted Registry 1.4.1
DCEU 18: Docker Container Security
Building a Secure App with Docker - Ying Li and David Lawrence, Docker
DockerCon SF 2015: DHE/DTR
Docker Roadshow 2016
Docker EE Deep Dive
Docker for Ops - Scott Coulton, Puppet
Docker Container-Introduction and Features
Docker Security workshop slides
How Docker EE is Finnish Railway’s Ticket to App Modernization
DockerCon EU 2015 Barcelona
Docker Enterprise Edition: Building a Secure Supply Chain for the Enterprise ...
Dockercon EU 2015 Recap
Docker Security and Content Trust
Containers, docker, and security: state of the union (Bay Area Infracoders Me...
Docker Datacenter Overview and Production Setup Slides
What's hot docker con eu 2015 & what's new on docker 1.9
Containers, Docker, and Security: State Of The Union (LinuxCon and ContainerC...
Introduction to Docker, Devops Virtualization and configuration management
Docker security - TASK Jan 2016

More from Docker, Inc. (20)

PDF
Containerize Your Game Server for the Best Multiplayer Experience
PDF
How to Improve Your Image Builds Using Advance Docker Build
PDF
Build & Deploy Multi-Container Applications to AWS
PDF
Securing Your Containerized Applications with NGINX
PDF
How To Build and Run Node Apps with Docker and Compose
PDF
Hands-on Helm
PDF
Distributed Deep Learning with Docker at Salesforce
PDF
The First 10M Pulls: Building The Official Curl Image for Docker Hub
PDF
Monitoring in a Microservices World
PDF
COVID-19 in Italy: How Docker is Helping the Biggest Italian IT Company Conti...
PDF
Predicting Space Weather with Docker
PDF
Become a Docker Power User With Microsoft Visual Studio Code
PDF
How to Use Mirroring and Caching to Optimize your Container Registry
PDF
Monolithic to Microservices + Docker = SDLC on Steroids!
PDF
Kubernetes at Datadog Scale
PDF
Labels, Labels, Labels
PDF
Using Docker Hub at Scale to Support Micro Focus' Delivery and Deployment Model
PDF
Build & Deploy Multi-Container Applications to AWS
PDF
From Fortran on the Desktop to Kubernetes in the Cloud: A Windows Migration S...
PDF
Developing with Docker for the Arm Architecture
Containerize Your Game Server for the Best Multiplayer Experience
How to Improve Your Image Builds Using Advance Docker Build
Build & Deploy Multi-Container Applications to AWS
Securing Your Containerized Applications with NGINX
How To Build and Run Node Apps with Docker and Compose
Hands-on Helm
Distributed Deep Learning with Docker at Salesforce
The First 10M Pulls: Building The Official Curl Image for Docker Hub
Monitoring in a Microservices World
COVID-19 in Italy: How Docker is Helping the Biggest Italian IT Company Conti...
Predicting Space Weather with Docker
Become a Docker Power User With Microsoft Visual Studio Code
How to Use Mirroring and Caching to Optimize your Container Registry
Monolithic to Microservices + Docker = SDLC on Steroids!
Kubernetes at Datadog Scale
Labels, Labels, Labels
Using Docker Hub at Scale to Support Micro Focus' Delivery and Deployment Model
Build & Deploy Multi-Container Applications to AWS
From Fortran on the Desktop to Kubernetes in the Cloud: A Windows Migration S...
Developing with Docker for the Arm Architecture

Recently uploaded (20)

PDF
Taming the Chaos: How to Turn Unstructured Data into Decisions
PPTX
observCloud-Native Containerability and monitoring.pptx
PDF
TrustArc Webinar - Click, Consent, Trust: Winning the Privacy Game
PDF
Developing a website for English-speaking practice to English as a foreign la...
PDF
Getting started with AI Agents and Multi-Agent Systems
PPTX
Tartificialntelligence_presentation.pptx
PDF
Hindi spoken digit analysis for native and non-native speakers
PDF
A Late Bloomer's Guide to GenAI: Ethics, Bias, and Effective Prompting - Boha...
PPT
Geologic Time for studying geology for geologist
PDF
Hybrid horned lizard optimization algorithm-aquila optimizer for DC motor
PDF
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
PPTX
The various Industrial Revolutions .pptx
PDF
Hybrid model detection and classification of lung cancer
PDF
Transform Your ITIL® 4 & ITSM Strategy with AI in 2025.pdf
PDF
A novel scalable deep ensemble learning framework for big data classification...
PDF
August Patch Tuesday
PPTX
Web Crawler for Trend Tracking Gen Z Insights.pptx
PDF
1 - Historical Antecedents, Social Consideration.pdf
PDF
From MVP to Full-Scale Product A Startup’s Software Journey.pdf
PPTX
Modernising the Digital Integration Hub
Taming the Chaos: How to Turn Unstructured Data into Decisions
observCloud-Native Containerability and monitoring.pptx
TrustArc Webinar - Click, Consent, Trust: Winning the Privacy Game
Developing a website for English-speaking practice to English as a foreign la...
Getting started with AI Agents and Multi-Agent Systems
Tartificialntelligence_presentation.pptx
Hindi spoken digit analysis for native and non-native speakers
A Late Bloomer's Guide to GenAI: Ethics, Bias, and Effective Prompting - Boha...
Geologic Time for studying geology for geologist
Hybrid horned lizard optimization algorithm-aquila optimizer for DC motor
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
The various Industrial Revolutions .pptx
Hybrid model detection and classification of lung cancer
Transform Your ITIL® 4 & ITSM Strategy with AI in 2025.pdf
A novel scalable deep ensemble learning framework for big data classification...
August Patch Tuesday
Web Crawler for Trend Tracking Gen Z Insights.pptx
1 - Historical Antecedents, Social Consideration.pdf
From MVP to Full-Scale Product A Startup’s Software Journey.pdf
Modernising the Digital Integration Hub

DockerCon EU 2015: What's New with Docker Trusted Registry

  • 1. What’s New with Docker Trusted Registry (v1.4.0)? Jon Chu & Rajat Goel PM, Enterprise Director of Engineering, Enterprise
  • 2. Docker Trusted Registry Recap 2 Registry for building, storing and managing images securely, within your firewall Maintain control over Docker images to meet your security or regulatory compliance requirements.
  • 3. Content is King…to Build-Ship-Run Run Trusted Registry Base Image Tested Production Development Test Staging Production Scale Out Build Ship
  • 4. DTR Primary Usage Scenarios CI/CD with Docker • Centrally located base images • Store individual build images • Pull tested images to production Containers as a Service • Deploy Jenkins executors or Hadoop nodes • Instant-on developer environment • Selected curated apps from a catalog • Dynamic composition of micro-services (“PAAS”)
  • 5. Pre DTR 1.4 General Features • Admin & Health UI • Registry Storage Status • LDAP/AD Integration • RBAC API (Admin, R/W, R/O) • User actions/API audit logs • Registry v2 API & v2 Image Support • One click install/upgrade Platform Features • Storage drivers for filesystem, s3, and azure • Support Tooling • Support for Ubuntu, RHEL, CentOS • Tested at 300 concurrent pulls/instance
  • 6. DTR 1.4 Release General Features • Orgs, Teams & Repo permissions UI • Search index, API & UI • Interactive API documentation • Image deletion from index • Image garbage collection Experimental • Docker Content Trust: View Docker Notary signatures in DTR
  • 7. Architecture Datastore Storage Drivers Admin UIAudit and Event logs Directory Services Load Balancer Registry ServersAdmin Server Auth Server Log Aggregator Docker Engines PostgreSQL LDAPS 636Local Syslog Docker Client > docker HTTPS 443
  • 11. 11 Deep Dive: Garbage Collection
  • 12. 12 Overview: Docker Content Trust ● Built on TUF ● Designed to make good security easy! ● Validates the publisher, not the safety of their content!
  • 13. 13 Overview: Docker Content Trust ● Built on TUF ● Designed to make good security easy! ● Validates the publisher, not the safety of their content!
  • 14. 14 Overview: Docker Content Trust Image Forgery
  • 15. 15 Overview: Docker Content Trust Why not GPG? Replay Attacks
  • 17. 17 Docker Content Trust Integration Docker Universal Control Plane Integration Future Plans and Features
  • 18. Docker Universal Control Plane Integration ● End-to-end authn integration with LDAP/AD ● Cross product RBAC across orgs ● Complete CI/CD visibility Description
  • 19. DCT: Image Promotion & Policy Enforcement ● Cryptographically signed layers ● Promote images through signatures ● dev signed -> QA signed -> prod signed ● Policy enforcement through integrations Description Sysadmin Dev Prod Ops
  • 20. International Availability Docker Subscription available for Europe Hourly and annual subscriptions available from AWS Marketplace Subscription licenses available L1 and L2 support for US and Europe Bring your own license to deploy Docker VHD in Azure Marketplace to European zones www.docker.com/aws www.docker.com/ibm www.docker.com/microsoft 30 day free trial www.docker.com/try-dtr