Docker Hub 514 is the default registry: postgres:18 means docker.io/library/postgres:18. Its free tier is rate-limited, and Docker 514 's own pages disagree about the numbers: the usage documentation says 100 pulls per 6 hours per IP address anonymously and 200 with a free account, while the pricing page says 100 per hour for a free Personal account. The registry reports the limit it actually enforces in response headers, and the documented probe uses HEAD, which does not count as a pull:
AUTH="https://auth.docker.io/token?service=registry.docker.io"
TOKEN=$(curl -s "$AUTH&scope=repository:ratelimitpreview/test:pull" | jq -r .token)
curl -s --head -H "Authorization: Bearer $TOKEN" \
https://registry-1.docker.io/v2/ratelimitpreview/test/manifests/latest \
| grep -iE '^(ratelimit|docker-ratelimit)' | sed 's/source: .*/source: <your public IP>/'docker-ratelimit-source: <your public IP> ratelimit-limit: 100;w=3600 ratelimit-remaining: 97;w=3600
w=3600 is the window in seconds: 100 anonymous pulls per hour, counted per public IP address and therefore shared by everyone behind the same NAT, which is why an office or a CI farm hits the limit first. Paid plans lift it:
| Plan | Price per user per month | Docker Hub pulls | Private repositories |
|---|---|---|---|
| Personal | $0 | 100 per hour | 1 |
| Pro | $9 yearly, $11 monthly | Unlimited (fair use) | Unlimited |
| Team | $15 yearly, $16 monthly | Unlimited (fair use) | Unlimited |
| Business | $24 | Unlimited (fair use) | Unlimited |
Logging in, a pull-through cache and digest-pinned base images all keep CI under the limit.