Self-Hosted Registry

Running a Self-Hosted Registry Container

The official registry image is CNCF Distribution 10,629 (github.com/distribution/distribution (https://github.com/distribution/distribution 10,629 ), Apache-2.0), the reference implementation of the OCI Distribution Specification. Its 3 tag is Distribution 3.1.2; registry:2 (2.8.3, used briefly in Manifest Lists) is the older line. Run it with a named volume, on the loopback interface only:

Running BookNest's own registry and pushing to itShell
docker run -d --name l3-registry --restart unless-stopped -p 127.0.0.1:33500:5000 \
  -v l3-registry-data:/var/lib/registry registry:3 >/dev/null
docker exec l3-registry registry --version
docker tag l3-booknest-api:latest localhost:33500/booknest-api:1.3
docker push localhost:33500/booknest-api:1.3 | tail -1
curl -s localhost:33500/v2/_catalog; curl -s localhost:33500/v2/booknest-api/tags/list
Output
registry github.com/distribution/distribution/v3 3.1.2
1.3: digest: sha256:ff7c8911a5d4400d55c18dde397d92d8095f5e3cac3ecc99f7f9a1c9f2ac1f8d size: 856
{"repositories":["booknest-api"]}
{"name":"booknest-api","tags":["1.3"]}

Docker 514 accepts plain HTTP here only because the daemon treats 127.0.0.0/8 as insecure by default; any other host must be listed under insecure-registries in daemon.json. Jenkins 8,793 (Jenkins) and the Kubernetes 5,150 cluster (Kubernetes) use this registry, reaching it by container name over a shared Docker network, for example after docker network connect kind l3-registry.