Promoting Images

Retagging and Promoting Images Between Registries

Promotion moves a tested image to the next stage without rebuilding it, so the tested bytes are the bytes that run. docker tag plus docker push needs every layer locally; docker buildx imagetools create copies between registries directly, sending only the blobs the target lacks:

Promoting within the local registry, and copying from ghcr.ioShell
short() { grep -oE 'pushing sha256:.* to .*' | sed -E 's/(sha256:.{12})[0-9a-f]+/\1.../'; }
docker buildx imagetools create --tag localhost:33500/booknest-api:prod \
  localhost:33500/booknest-api:1.3 2>&1 | short
docker buildx imagetools create --tag localhost:33500/booknest:ghcr-latest \
  ghcr.io/binarybehemoth/booknest:latest 2>&1 | short
curl -s localhost:33500/v2/_catalog
Output
pushing sha256:ff7c8911a5d4... to localhost:33500/booknest-api:prod
pushing sha256:9246566c7182... to localhost:33500/booknest:ghcr-latest
{"repositories":["booknest","booknest-api"]}

prod has the same digest as 1.3, and the image built on GitHub 29 now also lives in the private registry. Two daemonless tools do the same in CI: crane 4,061 from github.com/google/go-containerregistry (https://github.com/google/go-containerregistry 4,061 ) (crane copy SRC DST) and skopeo 11,267 from github.com/containers/skopeo (https://github.com/containers/skopeo 11,267 ) (skopeo copy docker://SRC docker://DST, installed with sudo apt install skopeo).