> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tensor9.com/llms.txt
> Use this file to discover all available pages before exploring further.

# ECR Public

> AWS ECR Public. Hosts container images that anyone can pull without credentials, published under public.ecr.aws and listed in the ECR Public Gallery.

**On this page**

* [Coverage by target cloud](#coverage-by-target-cloud)
* [How the targets compare](#how-the-targets-compare)
  * [Infrastructure-only adaptation](#infrastructure-only-adaptation)
* [On Google Cloud](#on-google-cloud)
* [On Azure](#on-azure)
* [On OCI](#on-oci)
* [On Private Kubernetes](#on-private-kubernetes)
  * [Via Zot](#via-zot)
  * [Via Distribution](#via-distribution)
  * [Via Harbor](#via-harbor)

## Coverage by target cloud

| Target             | Available |
| ------------------ | --------- |
| Google Cloud       | ✓         |
| Azure              | ✓         |
| OCI                | ✓         |
| Private Kubernetes | ✓         |

## How the targets compare

Each row compares a capability of ECR Public with its adaptation on each target.
A dash means this row is not stated for that target.

### Infrastructure-only adaptation

| Capability                       | ECR Public                                       | Google Cloud                                                                                 | Azure                                                                                        | OCI                                                                                          | Private Kubernetes · Zot                                                                     | Private Kubernetes · Distribution                                                            | Private Kubernetes · Harbor                                                                  |
| -------------------------------- | ------------------------------------------------ | -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- |
| Adaptation mechanism             | AWS public registry and management APIs          | Infrastructure only: native public registry                                                  | Infrastructure only: native public registry                                                  | Infrastructure only: native public registry                                                  | Infrastructure only: native public registry                                                  | Infrastructure only: native public registry                                                  | Infrastructure only: native public registry                                                  |
| Anonymous image pull             | Yes                                              | Yes - Selected images at the new public HTTPS URL                                            | Yes - Selected images at the new public HTTPS URL                                            | Yes - Selected images at the new public HTTPS URL                                            | Yes - Selected images at the new public HTTPS URL                                            | Yes - Selected images at the new public HTTPS URL                                            | Yes - Selected images at the new public HTTPS URL                                            |
| Publisher authentication         | AWS credentials and ECR Public authorization     | Native principal; repository writer                                                          | Native repository-scoped credentials                                                         | Native credentials; selected-repository permissions                                          | Named users: read/create/update                                                              | docker\_auth: exact pull/push scopes                                                         | Project robot with pull and push                                                             |
| Public and private isolation     | Separate AWS public and private registries       | Dedicated public repositories; private repositories separate                                 | Separate public-only registry; all its repositories public                                   | Explicitly public repositories; private repositories separate                                | Exact anonymous-read ACLs; separate public deployment                                        | Exact pull-only public ACL; separate registry and trust                                      | Dedicated public project; private deployment separate                                        |
| Repository topology              | Public repositories under the AWS registry alias | One standard Docker repository per source repository                                         | One dedicated registry with selected repository paths                                        | Public repository per source repository in selected region                                   | Dedicated Zot registry with selected repository paths                                        | Public Distribution registry plus token issuer                                               | Public project containing selected repository paths                                          |
| Image and index digests          | Content-addressed manifests, indexes and layers  | Selected supported content copied without digest changes; fail if preservation is impossible | Selected supported content copied without digest changes; fail if preservation is impossible | Selected supported content copied without digest changes; fail if preservation is impossible | Selected supported content copied without digest changes; fail if preservation is impossible | Selected supported content copied without digest changes; fail if preservation is impossible | Selected supported content copied without digest changes; fail if preservation is impossible |
| AWS management and token APIs    | Yes                                              | No - Native registry APIs; no AWS request adapter                                            | No - Native registry APIs; no AWS request adapter                                            | No - Native registry APIs; no AWS request adapter                                            | No - Native registry APIs; no AWS request adapter                                            | No - Native registry APIs; no AWS request adapter                                            | No - Native registry APIs; no AWS request adapter                                            |
| AWS Gallery and registry aliases | Yes                                              | No - New public registry URL                                                                 | No - New public registry URL                                                                 | No - New public registry URL                                                                 | No - New public registry URL                                                                 | No - New public registry URL                                                                 | No - New public registry URL                                                                 |
| Retention, scanning and recovery | AWS service configuration and operating model    | Native cleanup/scanning; no AWS policy transfer                                              | Native cleanup/scanning; no AWS policy transfer                                              | Native retention/scanning; regional copies planned separately                                | Zot retention/extensions configured separately                                               | Public delete disabled; operator cleanup and recovery                                        | Harbor retention/scanning configured separately                                              |
| API coverage                     | full                                             | partial                                                                                      | partial                                                                                      | partial                                                                                      | partial                                                                                      | partial                                                                                      | partial                                                                                      |

## On Google Cloud

| Operation                                   | Area               | Support      | Depth        | Notes                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ------------------------------------------- | ------------------ | ------------ | ------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| AWS ECR Public management and token APIs    | AWS API boundary   | Out of scope | Full surface | Native registry access does not serve AWS CreateRepository, DescribeRepositories, PutImage, layer-upload calls or GetAuthorizationToken; no STS GetServiceBearerToken operation is added.                                                                                                                                                                                                                                                                                                                 |
| Anonymous image pull                        | Image distribution | Supported    | Common       | Readers pull selected images from the new public HTTPS registry URL without an AWS identity or target credential.                                                                                                                                                                                                                                                                                                                                                                                         |
| Authenticated image publication             | Image distribution | Supported    | Common       | Grant Artifact Registry Reader to allUsers on each selected repository. Publishers authenticate with a target principal granted write access to that repository; a public reader receives no write grant.                                                                                                                                                                                                                                                                                                 |
| Continuous replication from AWS             | Migration          | Out of scope | Full surface | The initial selected image transfer does not continuously copy later changes from the AWS public registry.                                                                                                                                                                                                                                                                                                                                                                                                |
| Historical images and attached artifacts    | Migration          | Partial      | Most usage   | The selected images do not include an unbounded registry history or continued replication of later AWS changes. Signatures, attestations, referrers, SBOMs and scanning history need their own transfer scope. Foreign layers fetched from external URLs are outside the initial self-contained copy guarantee. Preserving an image digest does not preserve repository identity or signature trust.                                                                                                      |
| Selected image and digest transfer          | Migration          | Supported    | Common       | Select the source images and tags to transfer and freeze each selected tag to its source digest. Copy supported Docker schema-2 or OCI manifests and layers without changing their bytes. A retained multi-platform index includes all its referenced platform images. Verify the destination digests; a copy that requires media-type conversion or cannot preserve a required digest fails. Update only the image references the mapping controls. External users must change their old AWS image URLs. |
| Native retention and scanning configuration | Operations         | Partial      | Most usage   | Configure Artifact Registry cleanup separately and retain releases needed for rollback. This mapping does not translate AWS repository policies or import scanning findings. Optional native scanning is a separate target configuration.                                                                                                                                                                                                                                                                 |
| AWS Gallery and registry aliases            | Public identity    | Out of scope | Full surface | The target registry has a different hostname and repository path; the Public Gallery and public.ecr.aws aliases are not preserved.                                                                                                                                                                                                                                                                                                                                                                        |
| Public repository provisioning              | Repositories       | Supported    | Common       | Each selected ECR Public repository becomes a dedicated standard Docker repository in the target project and location. The image URL includes the location, project, repository and image path.                                                                                                                                                                                                                                                                                                           |

#### Public images on Artifact Registry

Each selected ECR Public repository becomes a dedicated standard Docker repository in the target project and location. The image URL includes the location, project, repository and image path.

Clients use the target registry directly at Infrastructure-only adaptation. AWS ECR Public management and authorization-token APIs, the Public Gallery and public.ecr.aws registry aliases are outside this mapping. Native push and pull do not implement AWS PutImage, layer-upload APIs or GetAuthorizationToken. No Max request adapter or additional STS operation is implied.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MDAiIGhlaWdodD0iMjE1IiB2aWV3Qm94PSIwIDAgODAwIDIxNSIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBbm9ueW1vdXMgcmVhZGVycyBwdWxsIGZyb20gQXJ0aWZhY3QgUmVnaXN0cnk7IGF1dGhlbnRpY2F0ZWQgcHVibGlzaGVycyB3cml0ZSBzZWxlY3RlZCBwdWJsaWMgcmVwb3NpdG9yaWVzLiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6IzMzNDE1NX08L3N0eWxlPgo8ZyBmaWxsPSJjdXJyZW50Q29sb3IiIGZvbnQtZmFtaWx5PSJBcmlhbCwgc2Fucy1zZXJpZiIgZm9udC1zaXplPSIxNCI+CjxyZWN0IHg9IjI1IiB5PSI2NSIgd2lkdGg9IjE5NSIgaGVpZ2h0PSI2MCIgcng9IjgiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIvPgo8dGV4dCB4PSIxMjIiIHk9IjkxIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIj5Bbm9ueW1vdXMgcmVhZGVyczwvdGV4dD4KPHRleHQgeD0iMTIyIiB5PSIxMTIiIHRleHQtYW5jaG9yPSJtaWRkbGUiIGZvbnQtc2l6ZT0iMTIiPm5ldyBwdWJsaWMgaW1hZ2UgVVJMPC90ZXh0Pgo8cmVjdCB4PSIyOTIiIHk9IjU1IiB3aWR0aD0iMjE2IiBoZWlnaHQ9IjgwIiByeD0iOCIgZmlsbD0ibm9uZSIgc3Ryb2tlPSIjNjQ3NDhiIi8+Cjx0ZXh0IHg9IjQwMCIgeT0iODIiIHRleHQtYW5jaG9yPSJtaWRkbGUiPkFydGlmYWN0IFJlZ2lzdHJ5PC90ZXh0Pgo8dGV4dCB4PSI0MDAiIHk9IjEwNyIgdGV4dC1hbmNob3I9Im1pZGRsZSIgZm9udC1zaXplPSIxMiI+RGVkaWNhdGVkIHB1YmxpYyByZXBvc2l0b3J5PC90ZXh0Pgo8cmVjdCB4PSI1ODAiIHk9IjY1IiB3aWR0aD0iMTk1IiBoZWlnaHQ9IjYwIiByeD0iOCIgZmlsbD0ibm9uZSIgc3Ryb2tlPSIjNjQ3NDhiIi8+Cjx0ZXh0IHg9IjY3NyIgeT0iOTEiIHRleHQtYW5jaG9yPSJtaWRkbGUiPkF1dGhlbnRpY2F0ZWQgcHVibGlzaGVyczwvdGV4dD4KPHRleHQgeD0iNjc3IiB5PSIxMTIiIHRleHQtYW5jaG9yPSJtaWRkbGUiIGZvbnQtc2l6ZT0iMTIiPnNlbGVjdGVkIHJlcG9zaXRvcnkgc2NvcGU8L3RleHQ+CjxwYXRoIGQ9Ik0yMjAgOTUgSDI4NiBNMjc5IDkwIEwyODcgOTUgTDI3OSAxMDAgTTU4MCA5NSBINTE0IE01MjEgOTAgTDUxMyA5NSBMNTIxIDEwMCIgZmlsbD0ibm9uZSIgc3Ryb2tlPSIjNjQ3NDhiIiBzdHJva2Utd2lkdGg9IjEuNSIvPgo8dGV4dCB4PSIyNTUiIHk9Ijc5IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBmb250LXNpemU9IjEyIj5wdWxsPC90ZXh0Pgo8dGV4dCB4PSI1NDUiIHk9Ijc5IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBmb250LXNpemU9IjEyIj5wdXNoPC90ZXh0Pgo8dGV4dCB4PSI0MDAiIHk9IjE2NSIgdGV4dC1hbmNob3I9Im1pZGRsZSI+UHVibGljIGltYWdlIHN0b3JhZ2Ugb24gR29vZ2xlIENsb3VkPC90ZXh0Pgo8dGV4dCB4PSI0MDAiIHk9IjE5MCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgZm9udC1zaXplPSIxMiI+UHJpdmF0ZSBpbWFnZXMgcmVtYWluIG91dHNpZGUgdGhpcyBwdWJsaWMgc2NvcGU7IG5vIEFXUyBBUEkgYWRhcHRlci48L3RleHQ+Cgo8L2c+PC9zdmc+" alt="Anonymous readers pull from Artifact Registry; authenticated publishers write selected public repositories." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MDAiIGhlaWdodD0iMjE1IiB2aWV3Qm94PSIwIDAgODAwIDIxNSIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBbm9ueW1vdXMgcmVhZGVycyBwdWxsIGZyb20gQXJ0aWZhY3QgUmVnaXN0cnk7IGF1dGhlbnRpY2F0ZWQgcHVibGlzaGVycyB3cml0ZSBzZWxlY3RlZCBwdWJsaWMgcmVwb3NpdG9yaWVzLiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6I2NiZDVlMX08L3N0eWxlPgo8ZyBmaWxsPSJjdXJyZW50Q29sb3IiIGZvbnQtZmFtaWx5PSJBcmlhbCwgc2Fucy1zZXJpZiIgZm9udC1zaXplPSIxNCI+CjxyZWN0IHg9IjI1IiB5PSI2NSIgd2lkdGg9IjE5NSIgaGVpZ2h0PSI2MCIgcng9IjgiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIvPgo8dGV4dCB4PSIxMjIiIHk9IjkxIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIj5Bbm9ueW1vdXMgcmVhZGVyczwvdGV4dD4KPHRleHQgeD0iMTIyIiB5PSIxMTIiIHRleHQtYW5jaG9yPSJtaWRkbGUiIGZvbnQtc2l6ZT0iMTIiPm5ldyBwdWJsaWMgaW1hZ2UgVVJMPC90ZXh0Pgo8cmVjdCB4PSIyOTIiIHk9IjU1IiB3aWR0aD0iMjE2IiBoZWlnaHQ9IjgwIiByeD0iOCIgZmlsbD0ibm9uZSIgc3Ryb2tlPSIjNjQ3NDhiIi8+Cjx0ZXh0IHg9IjQwMCIgeT0iODIiIHRleHQtYW5jaG9yPSJtaWRkbGUiPkFydGlmYWN0IFJlZ2lzdHJ5PC90ZXh0Pgo8dGV4dCB4PSI0MDAiIHk9IjEwNyIgdGV4dC1hbmNob3I9Im1pZGRsZSIgZm9udC1zaXplPSIxMiI+RGVkaWNhdGVkIHB1YmxpYyByZXBvc2l0b3J5PC90ZXh0Pgo8cmVjdCB4PSI1ODAiIHk9IjY1IiB3aWR0aD0iMTk1IiBoZWlnaHQ9IjYwIiByeD0iOCIgZmlsbD0ibm9uZSIgc3Ryb2tlPSIjNjQ3NDhiIi8+Cjx0ZXh0IHg9IjY3NyIgeT0iOTEiIHRleHQtYW5jaG9yPSJtaWRkbGUiPkF1dGhlbnRpY2F0ZWQgcHVibGlzaGVyczwvdGV4dD4KPHRleHQgeD0iNjc3IiB5PSIxMTIiIHRleHQtYW5jaG9yPSJtaWRkbGUiIGZvbnQtc2l6ZT0iMTIiPnNlbGVjdGVkIHJlcG9zaXRvcnkgc2NvcGU8L3RleHQ+CjxwYXRoIGQ9Ik0yMjAgOTUgSDI4NiBNMjc5IDkwIEwyODcgOTUgTDI3OSAxMDAgTTU4MCA5NSBINTE0IE01MjEgOTAgTDUxMyA5NSBMNTIxIDEwMCIgZmlsbD0ibm9uZSIgc3Ryb2tlPSIjNjQ3NDhiIiBzdHJva2Utd2lkdGg9IjEuNSIvPgo8dGV4dCB4PSIyNTUiIHk9Ijc5IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBmb250LXNpemU9IjEyIj5wdWxsPC90ZXh0Pgo8dGV4dCB4PSI1NDUiIHk9Ijc5IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBmb250LXNpemU9IjEyIj5wdXNoPC90ZXh0Pgo8dGV4dCB4PSI0MDAiIHk9IjE2NSIgdGV4dC1hbmNob3I9Im1pZGRsZSI+UHVibGljIGltYWdlIHN0b3JhZ2Ugb24gR29vZ2xlIENsb3VkPC90ZXh0Pgo8dGV4dCB4PSI0MDAiIHk9IjE5MCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgZm9udC1zaXplPSIxMiI+UHJpdmF0ZSBpbWFnZXMgcmVtYWluIG91dHNpZGUgdGhpcyBwdWJsaWMgc2NvcGU7IG5vIEFXUyBBUEkgYWRhcHRlci48L3RleHQ+Cgo8L2c+PC9zdmc+" alt="Anonymous readers pull from Artifact Registry; authenticated publishers write selected public repositories." />
</div>

#### Anonymous reads and authenticated publication

Grant Artifact Registry Reader to allUsers on each selected repository. Publishers authenticate with a target principal granted write access to that repository; a public reader receives no write grant.

Public access is repository-scoped. Keep private ECR images in their separate repositories and never grant project-wide public access to satisfy this mapping. Organization policy must permit anonymous readers.

#### Selected images and changed references

Select the source images and tags to transfer and freeze each selected tag to its source digest. Copy supported Docker schema-2 or OCI manifests and layers without changing their bytes. A retained multi-platform index includes all its referenced platform images. Verify the destination digests; a copy that requires media-type conversion or cannot preserve a required digest fails. Update only the image references the mapping controls. External users must change their old AWS image URLs.

The selected images do not include an unbounded registry history or continued replication of later AWS changes. Signatures, attestations, referrers, SBOMs and scanning history need their own transfer scope. Foreign layers fetched from external URLs are outside the initial self-contained copy guarantee. Preserving an image digest does not preserve repository identity or signature trust.

#### Operating the public registry

Google operates the registry. You own its repository permissions, publisher identity, image retention and public traffic costs. Set request quotas appropriate for anonymous clients; a quota or provider outage can interrupt new pulls.

Configure Artifact Registry cleanup separately and retain releases needed for rollback. This mapping does not translate AWS repository policies or import scanning findings. Optional native scanning is a separate target configuration.

#### Limits of this mapping

* The source AWS registry alias and ECR Public Gallery listing do not follow the image to its new URL.
* A remote or virtual repository is not a substitute for the dedicated repository containing the selected copied images.
* A project policy that forbids allUsers makes this public choice unavailable; a private repository is not an equivalent public result.
* Public distribution requires reachable public HTTPS and permissions for anonymous readers. A policy that forbids that access must reject this choice, not silently produce a private registry.

## On Azure

| Operation                                   | Area               | Support      | Depth        | Notes                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ------------------------------------------- | ------------------ | ------------ | ------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| AWS ECR Public management and token APIs    | AWS API boundary   | Out of scope | Full surface | Native registry access does not serve AWS CreateRepository, DescribeRepositories, PutImage, layer-upload calls or GetAuthorizationToken; no STS GetServiceBearerToken operation is added.                                                                                                                                                                                                                                                                                                                 |
| Anonymous image pull                        | Image distribution | Supported    | Common       | Readers pull selected images from the new public HTTPS registry URL without an AWS identity or target credential.                                                                                                                                                                                                                                                                                                                                                                                         |
| Authenticated image publication             | Image distribution | Supported    | Common       | Enable anonymous pull for the public registry. Publishers use authenticated native credentials scoped to read and write their selected repository paths; public access does not grant publishing rights.                                                                                                                                                                                                                                                                                                  |
| Continuous replication from AWS             | Migration          | Out of scope | Full surface | The initial selected image transfer does not continuously copy later changes from the AWS public registry.                                                                                                                                                                                                                                                                                                                                                                                                |
| Historical images and attached artifacts    | Migration          | Partial      | Most usage   | The selected images do not include an unbounded registry history or continued replication of later AWS changes. Signatures, attestations, referrers, SBOMs and scanning history need their own transfer scope. Foreign layers fetched from external URLs are outside the initial self-contained copy guarantee. Preserving an image digest does not preserve repository identity or signature trust.                                                                                                      |
| Selected image and digest transfer          | Migration          | Supported    | Common       | Select the source images and tags to transfer and freeze each selected tag to its source digest. Copy supported Docker schema-2 or OCI manifests and layers without changing their bytes. A retained multi-platform index includes all its referenced platform images. Verify the destination digests; a copy that requires media-type conversion or cannot preserve a required digest fails. Update only the image references the mapping controls. External users must change their old AWS image URLs. |
| Native retention and scanning configuration | Operations         | Partial      | Most usage   | Configure native cleanup and any optional scanning independently. AWS repository policies, scan results and continuous replication are not imported. Retain current releases and rollback digests before deleting old content.                                                                                                                                                                                                                                                                            |
| AWS Gallery and registry aliases            | Public identity    | Out of scope | Full surface | The target registry has a different hostname and repository path; the Public Gallery and public.ecr.aws aliases are not preserved.                                                                                                                                                                                                                                                                                                                                                                        |
| Public repository provisioning              | Repositories       | Supported    | Common       | Use a dedicated public-only Standard or Premium Azure Container Registry. Selected public repositories become distinct image paths under its azurecr.io hostname.                                                                                                                                                                                                                                                                                                                                         |

#### Public images on Azure Container Registry

Use a dedicated public-only Standard or Premium Azure Container Registry. Selected public repositories become distinct image paths under its azurecr.io hostname.

Clients use the target registry directly at Infrastructure-only adaptation. AWS ECR Public management and authorization-token APIs, the Public Gallery and public.ecr.aws registry aliases are outside this mapping. Native push and pull do not implement AWS PutImage, layer-upload APIs or GetAuthorizationToken. No Max request adapter or additional STS operation is implied.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MDAiIGhlaWdodD0iMjE1IiB2aWV3Qm94PSIwIDAgODAwIDIxNSIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBbm9ueW1vdXMgcmVhZGVycyBwdWxsIGZyb20gQXp1cmUgQ29udGFpbmVyIFJlZ2lzdHJ5OyBhdXRoZW50aWNhdGVkIHB1Ymxpc2hlcnMgd3JpdGUgc2VsZWN0ZWQgcHVibGljIHJlcG9zaXRvcmllcy4iPjxzdHlsZT50ZXh0e2ZvbnQtZmFtaWx5OkludGVyLC1hcHBsZS1zeXN0ZW0sQmxpbmtNYWNTeXN0ZW1Gb250LCdTZWdvZSBVSScsUm9ib3RvLCdIZWx2ZXRpY2EgTmV1ZScsQXJpYWwsc2Fucy1zZXJpZjtmaWxsOiMzMzQxNTV9PC9zdHlsZT4KPGcgZmlsbD0iY3VycmVudENvbG9yIiBmb250LWZhbWlseT0iQXJpYWwsIHNhbnMtc2VyaWYiIGZvbnQtc2l6ZT0iMTQiPgo8cmVjdCB4PSIyNSIgeT0iNjUiIHdpZHRoPSIxOTUiIGhlaWdodD0iNjAiIHJ4PSI4IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiLz4KPHRleHQgeD0iMTIyIiB5PSI5MSIgdGV4dC1hbmNob3I9Im1pZGRsZSI+QW5vbnltb3VzIHJlYWRlcnM8L3RleHQ+Cjx0ZXh0IHg9IjEyMiIgeT0iMTEyIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBmb250LXNpemU9IjEyIj5uZXcgcHVibGljIGltYWdlIFVSTDwvdGV4dD4KPHJlY3QgeD0iMjkyIiB5PSI1NSIgd2lkdGg9IjIxNiIgaGVpZ2h0PSI4MCIgcng9IjgiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIvPgo8dGV4dCB4PSI0MDAiIHk9IjgyIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIj5BenVyZSBDb250YWluZXIgUmVnaXN0cnk8L3RleHQ+Cjx0ZXh0IHg9IjQwMCIgeT0iMTA3IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBmb250LXNpemU9IjEyIj5EZWRpY2F0ZWQgcHVibGljLW9ubHkgcmVnaXN0cnk8L3RleHQ+CjxyZWN0IHg9IjU4MCIgeT0iNjUiIHdpZHRoPSIxOTUiIGhlaWdodD0iNjAiIHJ4PSI4IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiLz4KPHRleHQgeD0iNjc3IiB5PSI5MSIgdGV4dC1hbmNob3I9Im1pZGRsZSI+QXV0aGVudGljYXRlZCBwdWJsaXNoZXJzPC90ZXh0Pgo8dGV4dCB4PSI2NzciIHk9IjExMiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgZm9udC1zaXplPSIxMiI+c2VsZWN0ZWQgcmVwb3NpdG9yeSBzY29wZTwvdGV4dD4KPHBhdGggZD0iTTIyMCA5NSBIMjg2IE0yNzkgOTAgTDI4NyA5NSBMMjc5IDEwMCBNNTgwIDk1IEg1MTQgTTUyMSA5MCBMNTEzIDk1IEw1MjEgMTAwIiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMS41Ii8+Cjx0ZXh0IHg9IjI1NSIgeT0iNzkiIHRleHQtYW5jaG9yPSJtaWRkbGUiIGZvbnQtc2l6ZT0iMTIiPnB1bGw8L3RleHQ+Cjx0ZXh0IHg9IjU0NSIgeT0iNzkiIHRleHQtYW5jaG9yPSJtaWRkbGUiIGZvbnQtc2l6ZT0iMTIiPnB1c2g8L3RleHQ+Cjx0ZXh0IHg9IjQwMCIgeT0iMTY1IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIj5QdWJsaWMgaW1hZ2Ugc3RvcmFnZSBvbiBBenVyZTwvdGV4dD4KPHRleHQgeD0iNDAwIiB5PSIxOTAiIHRleHQtYW5jaG9yPSJtaWRkbGUiIGZvbnQtc2l6ZT0iMTIiPlByaXZhdGUgaW1hZ2VzIHJlbWFpbiBvdXRzaWRlIHRoaXMgcHVibGljIHNjb3BlOyBubyBBV1MgQVBJIGFkYXB0ZXIuPC90ZXh0PgoKPC9nPjwvc3ZnPg==" alt="Anonymous readers pull from Azure Container Registry; authenticated publishers write selected public repositories." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MDAiIGhlaWdodD0iMjE1IiB2aWV3Qm94PSIwIDAgODAwIDIxNSIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBbm9ueW1vdXMgcmVhZGVycyBwdWxsIGZyb20gQXp1cmUgQ29udGFpbmVyIFJlZ2lzdHJ5OyBhdXRoZW50aWNhdGVkIHB1Ymxpc2hlcnMgd3JpdGUgc2VsZWN0ZWQgcHVibGljIHJlcG9zaXRvcmllcy4iPjxzdHlsZT50ZXh0e2ZvbnQtZmFtaWx5OkludGVyLC1hcHBsZS1zeXN0ZW0sQmxpbmtNYWNTeXN0ZW1Gb250LCdTZWdvZSBVSScsUm9ib3RvLCdIZWx2ZXRpY2EgTmV1ZScsQXJpYWwsc2Fucy1zZXJpZjtmaWxsOiNjYmQ1ZTF9PC9zdHlsZT4KPGcgZmlsbD0iY3VycmVudENvbG9yIiBmb250LWZhbWlseT0iQXJpYWwsIHNhbnMtc2VyaWYiIGZvbnQtc2l6ZT0iMTQiPgo8cmVjdCB4PSIyNSIgeT0iNjUiIHdpZHRoPSIxOTUiIGhlaWdodD0iNjAiIHJ4PSI4IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiLz4KPHRleHQgeD0iMTIyIiB5PSI5MSIgdGV4dC1hbmNob3I9Im1pZGRsZSI+QW5vbnltb3VzIHJlYWRlcnM8L3RleHQ+Cjx0ZXh0IHg9IjEyMiIgeT0iMTEyIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBmb250LXNpemU9IjEyIj5uZXcgcHVibGljIGltYWdlIFVSTDwvdGV4dD4KPHJlY3QgeD0iMjkyIiB5PSI1NSIgd2lkdGg9IjIxNiIgaGVpZ2h0PSI4MCIgcng9IjgiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIvPgo8dGV4dCB4PSI0MDAiIHk9IjgyIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIj5BenVyZSBDb250YWluZXIgUmVnaXN0cnk8L3RleHQ+Cjx0ZXh0IHg9IjQwMCIgeT0iMTA3IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBmb250LXNpemU9IjEyIj5EZWRpY2F0ZWQgcHVibGljLW9ubHkgcmVnaXN0cnk8L3RleHQ+CjxyZWN0IHg9IjU4MCIgeT0iNjUiIHdpZHRoPSIxOTUiIGhlaWdodD0iNjAiIHJ4PSI4IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiLz4KPHRleHQgeD0iNjc3IiB5PSI5MSIgdGV4dC1hbmNob3I9Im1pZGRsZSI+QXV0aGVudGljYXRlZCBwdWJsaXNoZXJzPC90ZXh0Pgo8dGV4dCB4PSI2NzciIHk9IjExMiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgZm9udC1zaXplPSIxMiI+c2VsZWN0ZWQgcmVwb3NpdG9yeSBzY29wZTwvdGV4dD4KPHBhdGggZD0iTTIyMCA5NSBIMjg2IE0yNzkgOTAgTDI4NyA5NSBMMjc5IDEwMCBNNTgwIDk1IEg1MTQgTTUyMSA5MCBMNTEzIDk1IEw1MjEgMTAwIiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMS41Ii8+Cjx0ZXh0IHg9IjI1NSIgeT0iNzkiIHRleHQtYW5jaG9yPSJtaWRkbGUiIGZvbnQtc2l6ZT0iMTIiPnB1bGw8L3RleHQ+Cjx0ZXh0IHg9IjU0NSIgeT0iNzkiIHRleHQtYW5jaG9yPSJtaWRkbGUiIGZvbnQtc2l6ZT0iMTIiPnB1c2g8L3RleHQ+Cjx0ZXh0IHg9IjQwMCIgeT0iMTY1IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIj5QdWJsaWMgaW1hZ2Ugc3RvcmFnZSBvbiBBenVyZTwvdGV4dD4KPHRleHQgeD0iNDAwIiB5PSIxOTAiIHRleHQtYW5jaG9yPSJtaWRkbGUiIGZvbnQtc2l6ZT0iMTIiPlByaXZhdGUgaW1hZ2VzIHJlbWFpbiBvdXRzaWRlIHRoaXMgcHVibGljIHNjb3BlOyBubyBBV1MgQVBJIGFkYXB0ZXIuPC90ZXh0PgoKPC9nPjwvc3ZnPg==" alt="Anonymous readers pull from Azure Container Registry; authenticated publishers write selected public repositories." />
</div>

#### Anonymous reads and authenticated publication

Enable anonymous pull for the public registry. Publishers use authenticated native credentials scoped to read and write their selected repository paths; public access does not grant publishing rights.

Anonymous pull exposes every repository in this registry, including repositories with separate permission settings. Never reuse the private ECR registry or turn it public. Private ECR images must remain in a different registry.

#### Selected images and changed references

Select the source images and tags to transfer and freeze each selected tag to its source digest. Copy supported Docker schema-2 or OCI manifests and layers without changing their bytes. A retained multi-platform index includes all its referenced platform images. Verify the destination digests; a copy that requires media-type conversion or cannot preserve a required digest fails. Update only the image references the mapping controls. External users must change their old AWS image URLs.

The selected images do not include an unbounded registry history or continued replication of later AWS changes. Signatures, attestations, referrers, SBOMs and scanning history need their own transfer scope. Foreign layers fetched from external URLs are outside the initial self-contained copy guarantee. Preserving an image digest does not preserve repository identity or signature trust.

#### Operating the public registry

Azure operates the registry. You own its SKU, public endpoint, publisher scopes, credentials and storage/egress costs. A Private Link-only or otherwise private-only endpoint cannot supply anonymous internet distribution.

Configure native cleanup and any optional scanning independently. AWS repository policies, scan results and continuous replication are not imported. Retain current releases and rollback digests before deleting old content.

#### Limits of this mapping

* Anonymous pull requires the Standard or Premium service tier; it is not a Basic-tier public option.
* The public-access switch is registry-wide, not an anonymous exception for one selected repository.
* Public traffic can be throttled. Network restrictions must still allow the readers this mapping is intended to serve.
* Public distribution requires reachable public HTTPS and permissions for anonymous readers. A policy that forbids that access must reject this choice, not silently produce a private registry.

## On OCI

| Operation                                   | Area               | Support      | Depth        | Notes                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ------------------------------------------- | ------------------ | ------------ | ------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| AWS ECR Public management and token APIs    | AWS API boundary   | Out of scope | Full surface | Native registry access does not serve AWS CreateRepository, DescribeRepositories, PutImage, layer-upload calls or GetAuthorizationToken; no STS GetServiceBearerToken operation is added.                                                                                                                                                                                                                                                                                                                 |
| Anonymous image pull                        | Image distribution | Supported    | Common       | Readers pull selected images from the new public HTTPS registry URL without an AWS identity or target credential.                                                                                                                                                                                                                                                                                                                                                                                         |
| Authenticated image publication             | Image distribution | Supported    | Common       | Anyone who can reach the public URL can pull the selected images without credentials. Publishers authenticate with native credentials and permissions to read and update the selected repositories.                                                                                                                                                                                                                                                                                                       |
| Continuous replication from AWS             | Migration          | Out of scope | Full surface | The initial selected image transfer does not continuously copy later changes from the AWS public registry.                                                                                                                                                                                                                                                                                                                                                                                                |
| Historical images and attached artifacts    | Migration          | Partial      | Most usage   | The selected images do not include an unbounded registry history or continued replication of later AWS changes. Signatures, attestations, referrers, SBOMs and scanning history need their own transfer scope. Foreign layers fetched from external URLs are outside the initial self-contained copy guarantee. Preserving an image digest does not preserve repository identity or signature trust.                                                                                                      |
| Selected image and digest transfer          | Migration          | Supported    | Common       | Select the source images and tags to transfer and freeze each selected tag to its source digest. Copy supported Docker schema-2 or OCI manifests and layers without changing their bytes. A retained multi-platform index includes all its referenced platform images. Verify the destination digests; a copy that requires media-type conversion or cannot preserve a required digest fails. Update only the image references the mapping controls. External users must change their old AWS image URLs. |
| Native retention and scanning configuration | Operations         | Partial      | Most usage   | Use OCIR retention and optional scanning as separate target controls. The mapping does not transfer AWS scanning history or repository policy semantics. Additional regional copies require an explicit image-delivery plan.                                                                                                                                                                                                                                                                              |
| AWS Gallery and registry aliases            | Public identity    | Out of scope | Full surface | The target registry has a different hostname and repository path; the Public Gallery and public.ecr.aws aliases are not preserved.                                                                                                                                                                                                                                                                                                                                                                        |
| Public repository provisioning              | Repositories       | Supported    | Common       | Create an explicitly public OCIR repository for each selected public source repository. Consumers use the target region, tenancy namespace and mapped repository path.                                                                                                                                                                                                                                                                                                                                    |

#### Public images on OCI Container Registry

Create an explicitly public OCIR repository for each selected public source repository. Consumers use the target region, tenancy namespace and mapped repository path.

Clients use the target registry directly at Infrastructure-only adaptation. AWS ECR Public management and authorization-token APIs, the Public Gallery and public.ecr.aws registry aliases are outside this mapping. Native push and pull do not implement AWS PutImage, layer-upload APIs or GetAuthorizationToken. No Max request adapter or additional STS operation is implied.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MDAiIGhlaWdodD0iMjE1IiB2aWV3Qm94PSIwIDAgODAwIDIxNSIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBbm9ueW1vdXMgcmVhZGVycyBwdWxsIGZyb20gT0NJIENvbnRhaW5lciBSZWdpc3RyeTsgYXV0aGVudGljYXRlZCBwdWJsaXNoZXJzIHdyaXRlIHNlbGVjdGVkIHB1YmxpYyByZXBvc2l0b3JpZXMuIj48c3R5bGU+dGV4dHtmb250LWZhbWlseTpJbnRlciwtYXBwbGUtc3lzdGVtLEJsaW5rTWFjU3lzdGVtRm9udCwnU2Vnb2UgVUknLFJvYm90bywnSGVsdmV0aWNhIE5ldWUnLEFyaWFsLHNhbnMtc2VyaWY7ZmlsbDojMzM0MTU1fTwvc3R5bGU+CjxnIGZpbGw9ImN1cnJlbnRDb2xvciIgZm9udC1mYW1pbHk9IkFyaWFsLCBzYW5zLXNlcmlmIiBmb250LXNpemU9IjE0Ij4KPHJlY3QgeD0iMjUiIHk9IjY1IiB3aWR0aD0iMTk1IiBoZWlnaHQ9IjYwIiByeD0iOCIgZmlsbD0ibm9uZSIgc3Ryb2tlPSIjNjQ3NDhiIi8+Cjx0ZXh0IHg9IjEyMiIgeT0iOTEiIHRleHQtYW5jaG9yPSJtaWRkbGUiPkFub255bW91cyByZWFkZXJzPC90ZXh0Pgo8dGV4dCB4PSIxMjIiIHk9IjExMiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgZm9udC1zaXplPSIxMiI+bmV3IHB1YmxpYyBpbWFnZSBVUkw8L3RleHQ+CjxyZWN0IHg9IjI5MiIgeT0iNTUiIHdpZHRoPSIyMTYiIGhlaWdodD0iODAiIHJ4PSI4IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiLz4KPHRleHQgeD0iNDAwIiB5PSI4MiIgdGV4dC1hbmNob3I9Im1pZGRsZSI+T0NJIENvbnRhaW5lciBSZWdpc3RyeTwvdGV4dD4KPHRleHQgeD0iNDAwIiB5PSIxMDciIHRleHQtYW5jaG9yPSJtaWRkbGUiIGZvbnQtc2l6ZT0iMTIiPkV4cGxpY2l0bHkgcHVibGljIHJlcG9zaXRvcmllczwvdGV4dD4KPHJlY3QgeD0iNTgwIiB5PSI2NSIgd2lkdGg9IjE5NSIgaGVpZ2h0PSI2MCIgcng9IjgiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIvPgo8dGV4dCB4PSI2NzciIHk9IjkxIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIj5BdXRoZW50aWNhdGVkIHB1Ymxpc2hlcnM8L3RleHQ+Cjx0ZXh0IHg9IjY3NyIgeT0iMTEyIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBmb250LXNpemU9IjEyIj5zZWxlY3RlZCByZXBvc2l0b3J5IHNjb3BlPC90ZXh0Pgo8cGF0aCBkPSJNMjIwIDk1IEgyODYgTTI3OSA5MCBMMjg3IDk1IEwyNzkgMTAwIE01ODAgOTUgSDUxNCBNNTIxIDkwIEw1MTMgOTUgTDUyMSAxMDAiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIxLjUiLz4KPHRleHQgeD0iMjU1IiB5PSI3OSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgZm9udC1zaXplPSIxMiI+cHVsbDwvdGV4dD4KPHRleHQgeD0iNTQ1IiB5PSI3OSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgZm9udC1zaXplPSIxMiI+cHVzaDwvdGV4dD4KPHRleHQgeD0iNDAwIiB5PSIxNjUiIHRleHQtYW5jaG9yPSJtaWRkbGUiPlB1YmxpYyBpbWFnZSBzdG9yYWdlIG9uIE9DSTwvdGV4dD4KPHRleHQgeD0iNDAwIiB5PSIxOTAiIHRleHQtYW5jaG9yPSJtaWRkbGUiIGZvbnQtc2l6ZT0iMTIiPlByaXZhdGUgaW1hZ2VzIHJlbWFpbiBvdXRzaWRlIHRoaXMgcHVibGljIHNjb3BlOyBubyBBV1MgQVBJIGFkYXB0ZXIuPC90ZXh0PgoKPC9nPjwvc3ZnPg==" alt="Anonymous readers pull from OCI Container Registry; authenticated publishers write selected public repositories." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MDAiIGhlaWdodD0iMjE1IiB2aWV3Qm94PSIwIDAgODAwIDIxNSIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBbm9ueW1vdXMgcmVhZGVycyBwdWxsIGZyb20gT0NJIENvbnRhaW5lciBSZWdpc3RyeTsgYXV0aGVudGljYXRlZCBwdWJsaXNoZXJzIHdyaXRlIHNlbGVjdGVkIHB1YmxpYyByZXBvc2l0b3JpZXMuIj48c3R5bGU+dGV4dHtmb250LWZhbWlseTpJbnRlciwtYXBwbGUtc3lzdGVtLEJsaW5rTWFjU3lzdGVtRm9udCwnU2Vnb2UgVUknLFJvYm90bywnSGVsdmV0aWNhIE5ldWUnLEFyaWFsLHNhbnMtc2VyaWY7ZmlsbDojY2JkNWUxfTwvc3R5bGU+CjxnIGZpbGw9ImN1cnJlbnRDb2xvciIgZm9udC1mYW1pbHk9IkFyaWFsLCBzYW5zLXNlcmlmIiBmb250LXNpemU9IjE0Ij4KPHJlY3QgeD0iMjUiIHk9IjY1IiB3aWR0aD0iMTk1IiBoZWlnaHQ9IjYwIiByeD0iOCIgZmlsbD0ibm9uZSIgc3Ryb2tlPSIjNjQ3NDhiIi8+Cjx0ZXh0IHg9IjEyMiIgeT0iOTEiIHRleHQtYW5jaG9yPSJtaWRkbGUiPkFub255bW91cyByZWFkZXJzPC90ZXh0Pgo8dGV4dCB4PSIxMjIiIHk9IjExMiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgZm9udC1zaXplPSIxMiI+bmV3IHB1YmxpYyBpbWFnZSBVUkw8L3RleHQ+CjxyZWN0IHg9IjI5MiIgeT0iNTUiIHdpZHRoPSIyMTYiIGhlaWdodD0iODAiIHJ4PSI4IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiLz4KPHRleHQgeD0iNDAwIiB5PSI4MiIgdGV4dC1hbmNob3I9Im1pZGRsZSI+T0NJIENvbnRhaW5lciBSZWdpc3RyeTwvdGV4dD4KPHRleHQgeD0iNDAwIiB5PSIxMDciIHRleHQtYW5jaG9yPSJtaWRkbGUiIGZvbnQtc2l6ZT0iMTIiPkV4cGxpY2l0bHkgcHVibGljIHJlcG9zaXRvcmllczwvdGV4dD4KPHJlY3QgeD0iNTgwIiB5PSI2NSIgd2lkdGg9IjE5NSIgaGVpZ2h0PSI2MCIgcng9IjgiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIvPgo8dGV4dCB4PSI2NzciIHk9IjkxIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIj5BdXRoZW50aWNhdGVkIHB1Ymxpc2hlcnM8L3RleHQ+Cjx0ZXh0IHg9IjY3NyIgeT0iMTEyIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBmb250LXNpemU9IjEyIj5zZWxlY3RlZCByZXBvc2l0b3J5IHNjb3BlPC90ZXh0Pgo8cGF0aCBkPSJNMjIwIDk1IEgyODYgTTI3OSA5MCBMMjg3IDk1IEwyNzkgMTAwIE01ODAgOTUgSDUxNCBNNTIxIDkwIEw1MTMgOTUgTDUyMSAxMDAiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIxLjUiLz4KPHRleHQgeD0iMjU1IiB5PSI3OSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgZm9udC1zaXplPSIxMiI+cHVsbDwvdGV4dD4KPHRleHQgeD0iNTQ1IiB5PSI3OSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgZm9udC1zaXplPSIxMiI+cHVzaDwvdGV4dD4KPHRleHQgeD0iNDAwIiB5PSIxNjUiIHRleHQtYW5jaG9yPSJtaWRkbGUiPlB1YmxpYyBpbWFnZSBzdG9yYWdlIG9uIE9DSTwvdGV4dD4KPHRleHQgeD0iNDAwIiB5PSIxOTAiIHRleHQtYW5jaG9yPSJtaWRkbGUiIGZvbnQtc2l6ZT0iMTIiPlByaXZhdGUgaW1hZ2VzIHJlbWFpbiBvdXRzaWRlIHRoaXMgcHVibGljIHNjb3BlOyBubyBBV1MgQVBJIGFkYXB0ZXIuPC90ZXh0PgoKPC9nPjwvc3ZnPg==" alt="Anonymous readers pull from OCI Container Registry; authenticated publishers write selected public repositories." />
</div>

#### Anonymous reads and authenticated publication

Anyone who can reach the public URL can pull the selected images without credentials. Publishers authenticate with native credentials and permissions to read and update the selected repositories.

Publicity is set on each selected repository. Keep private repositories private and separate. Scope publisher policy to the selected repositories rather than granting blanket registry administration across the tenancy.

#### Selected images and changed references

Select the source images and tags to transfer and freeze each selected tag to its source digest. Copy supported Docker schema-2 or OCI manifests and layers without changing their bytes. A retained multi-platform index includes all its referenced platform images. Verify the destination digests; a copy that requires media-type conversion or cannot preserve a required digest fails. Update only the image references the mapping controls. External users must change their old AWS image URLs.

The selected images do not include an unbounded registry history or continued replication of later AWS changes. Signatures, attestations, referrers, SBOMs and scanning history need their own transfer scope. Foreign layers fetched from external URLs are outside the initial self-contained copy guarantee. Preserving an image digest does not preserve repository identity or signature trust.

#### Operating the public registry

Oracle operates the regional registry. You own the public repository settings, publisher credentials, cleanup and traffic costs. Copy required release and rollback images to the selected region before directing clients there.

Use OCIR retention and optional scanning as separate target controls. The mapping does not transfer AWS scanning history or repository policy semantics. Additional regional copies require an explicit image-delivery plan.

#### Limits of this mapping

* Region and tenancy namespace are part of the image reference. Replace AWS account and registry-alias URLs with the target image reference.
* A private service-gateway path does not replace the public URL required by external anonymous readers.
* A selected regional copy does not establish continuous cross-region or AWS-to-OCI replication.
* Public distribution requires reachable public HTTPS and permissions for anonymous readers. A policy that forbids that access must reject this choice, not silently produce a private registry.

## On Private Kubernetes

### Via Zot

| Operation                                   | Area               | Support      | Depth        | Notes                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ------------------------------------------- | ------------------ | ------------ | ------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| AWS ECR Public management and token APIs    | AWS API boundary   | Out of scope | Full surface | Native registry access does not serve AWS CreateRepository, DescribeRepositories, PutImage, layer-upload calls or GetAuthorizationToken; no STS GetServiceBearerToken operation is added.                                                                                                                                                                                                                                                                                                                 |
| Anonymous image pull                        | Image distribution | Supported    | Common       | Readers pull selected images from the new public HTTPS registry URL without an AWS identity or target credential.                                                                                                                                                                                                                                                                                                                                                                                         |
| Authenticated image publication             | Image distribution | Supported    | Common       | For each selected path, grant anonymousPolicy read only. Named authenticated publishers receive read, create and update actions. Deny mutation to other users and anonymous clients; do not install a global create/update or administrator grant as a default.                                                                                                                                                                                                                                           |
| Continuous replication from AWS             | Migration          | Out of scope | Full surface | The initial selected image transfer does not continuously copy later changes from the AWS public registry.                                                                                                                                                                                                                                                                                                                                                                                                |
| Historical images and attached artifacts    | Migration          | Partial      | Most usage   | The selected images do not include an unbounded registry history or continued replication of later AWS changes. Signatures, attestations, referrers, SBOMs and scanning history need their own transfer scope. Foreign layers fetched from external URLs are outside the initial self-contained copy guarantee. Preserving an image digest does not preserve repository identity or signature trust.                                                                                                      |
| Selected image and digest transfer          | Migration          | Supported    | Common       | Select the source images and tags to transfer and freeze each selected tag to its source digest. Copy supported Docker schema-2 or OCI manifests and layers without changing their bytes. A retained multi-platform index includes all its referenced platform images. Verify the destination digests; a copy that requires media-type conversion or cannot preserve a required digest fails. Update only the image references the mapping controls. External users must change their old AWS image URLs. |
| Native retention and scanning configuration | Operations         | Partial      | Most usage   | Configure Zot retention independently of AWS policies. Optional native extensions do not import ECR Public scanning results or history. Retain manifests and layers referenced by current releases and rollback images.                                                                                                                                                                                                                                                                                   |
| AWS Gallery and registry aliases            | Public identity    | Out of scope | Full surface | The target registry has a different hostname and repository path; the Public Gallery and public.ecr.aws aliases are not preserved.                                                                                                                                                                                                                                                                                                                                                                        |
| Public repository provisioning              | Repositories       | Supported    | Common       | Use a dedicated public Zot deployment with persistent image storage and a trusted public HTTPS endpoint. Keep selected repository paths explicit instead of exposing the private registry deployment.                                                                                                                                                                                                                                                                                                     |

#### Public images on Zot

Use a dedicated public Zot deployment with persistent image storage and a trusted public HTTPS endpoint. Keep selected repository paths explicit instead of exposing the private registry deployment.

Clients use the target registry directly at Infrastructure-only adaptation. AWS ECR Public management and authorization-token APIs, the Public Gallery and public.ecr.aws registry aliases are outside this mapping. Native push and pull do not implement AWS PutImage, layer-upload APIs or GetAuthorizationToken. No Max request adapter or additional STS operation is implied.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MDAiIGhlaWdodD0iMjE1IiB2aWV3Qm94PSIwIDAgODAwIDIxNSIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBbm9ueW1vdXMgcmVhZGVycyBwdWxsIGZyb20gWm90OyBhdXRoZW50aWNhdGVkIHB1Ymxpc2hlcnMgd3JpdGUgc2VsZWN0ZWQgcHVibGljIHJlcG9zaXRvcmllcy4iPjxzdHlsZT50ZXh0e2ZvbnQtZmFtaWx5OkludGVyLC1hcHBsZS1zeXN0ZW0sQmxpbmtNYWNTeXN0ZW1Gb250LCdTZWdvZSBVSScsUm9ib3RvLCdIZWx2ZXRpY2EgTmV1ZScsQXJpYWwsc2Fucy1zZXJpZjtmaWxsOiMzMzQxNTV9PC9zdHlsZT4KPGcgZmlsbD0iY3VycmVudENvbG9yIiBmb250LWZhbWlseT0iQXJpYWwsIHNhbnMtc2VyaWYiIGZvbnQtc2l6ZT0iMTQiPgo8cmVjdCB4PSIyNSIgeT0iNjUiIHdpZHRoPSIxOTUiIGhlaWdodD0iNjAiIHJ4PSI4IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiLz4KPHRleHQgeD0iMTIyIiB5PSI5MSIgdGV4dC1hbmNob3I9Im1pZGRsZSI+QW5vbnltb3VzIHJlYWRlcnM8L3RleHQ+Cjx0ZXh0IHg9IjEyMiIgeT0iMTEyIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBmb250LXNpemU9IjEyIj5uZXcgcHVibGljIGltYWdlIFVSTDwvdGV4dD4KPHJlY3QgeD0iMjkyIiB5PSI1NSIgd2lkdGg9IjIxNiIgaGVpZ2h0PSI4MCIgcng9IjgiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIvPgo8dGV4dCB4PSI0MDAiIHk9IjgyIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIj5ab3Q8L3RleHQ+Cjx0ZXh0IHg9IjQwMCIgeT0iMTA3IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBmb250LXNpemU9IjEyIj5EZWRpY2F0ZWQgcHVibGljIFpvdCBzdG9yYWdlPC90ZXh0Pgo8cmVjdCB4PSI1ODAiIHk9IjY1IiB3aWR0aD0iMTk1IiBoZWlnaHQ9IjYwIiByeD0iOCIgZmlsbD0ibm9uZSIgc3Ryb2tlPSIjNjQ3NDhiIi8+Cjx0ZXh0IHg9IjY3NyIgeT0iOTEiIHRleHQtYW5jaG9yPSJtaWRkbGUiPkF1dGhlbnRpY2F0ZWQgcHVibGlzaGVyczwvdGV4dD4KPHRleHQgeD0iNjc3IiB5PSIxMTIiIHRleHQtYW5jaG9yPSJtaWRkbGUiIGZvbnQtc2l6ZT0iMTIiPnNlbGVjdGVkIHJlcG9zaXRvcnkgc2NvcGU8L3RleHQ+CjxwYXRoIGQ9Ik0yMjAgOTUgSDI4NiBNMjc5IDkwIEwyODcgOTUgTDI3OSAxMDAgTTU4MCA5NSBINTE0IE01MjEgOTAgTDUxMyA5NSBMNTIxIDEwMCIgZmlsbD0ibm9uZSIgc3Ryb2tlPSIjNjQ3NDhiIiBzdHJva2Utd2lkdGg9IjEuNSIvPgo8dGV4dCB4PSIyNTUiIHk9Ijc5IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBmb250LXNpemU9IjEyIj5wdWxsPC90ZXh0Pgo8dGV4dCB4PSI1NDUiIHk9Ijc5IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBmb250LXNpemU9IjEyIj5wdXNoPC90ZXh0Pgo8dGV4dCB4PSI0MDAiIHk9IjE2NSIgdGV4dC1hbmNob3I9Im1pZGRsZSI+UHVibGljIGltYWdlIHN0b3JhZ2Ugb24gUHJpdmF0ZSBLdWJlcm5ldGVzPC90ZXh0Pgo8dGV4dCB4PSI0MDAiIHk9IjE5MCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgZm9udC1zaXplPSIxMiI+UHJpdmF0ZSBpbWFnZXMgcmVtYWluIG91dHNpZGUgdGhpcyBwdWJsaWMgc2NvcGU7IG5vIEFXUyBBUEkgYWRhcHRlci48L3RleHQ+Cgo8L2c+PC9zdmc+" alt="Anonymous readers pull from Zot; authenticated publishers write selected public repositories." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MDAiIGhlaWdodD0iMjE1IiB2aWV3Qm94PSIwIDAgODAwIDIxNSIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBbm9ueW1vdXMgcmVhZGVycyBwdWxsIGZyb20gWm90OyBhdXRoZW50aWNhdGVkIHB1Ymxpc2hlcnMgd3JpdGUgc2VsZWN0ZWQgcHVibGljIHJlcG9zaXRvcmllcy4iPjxzdHlsZT50ZXh0e2ZvbnQtZmFtaWx5OkludGVyLC1hcHBsZS1zeXN0ZW0sQmxpbmtNYWNTeXN0ZW1Gb250LCdTZWdvZSBVSScsUm9ib3RvLCdIZWx2ZXRpY2EgTmV1ZScsQXJpYWwsc2Fucy1zZXJpZjtmaWxsOiNjYmQ1ZTF9PC9zdHlsZT4KPGcgZmlsbD0iY3VycmVudENvbG9yIiBmb250LWZhbWlseT0iQXJpYWwsIHNhbnMtc2VyaWYiIGZvbnQtc2l6ZT0iMTQiPgo8cmVjdCB4PSIyNSIgeT0iNjUiIHdpZHRoPSIxOTUiIGhlaWdodD0iNjAiIHJ4PSI4IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiLz4KPHRleHQgeD0iMTIyIiB5PSI5MSIgdGV4dC1hbmNob3I9Im1pZGRsZSI+QW5vbnltb3VzIHJlYWRlcnM8L3RleHQ+Cjx0ZXh0IHg9IjEyMiIgeT0iMTEyIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBmb250LXNpemU9IjEyIj5uZXcgcHVibGljIGltYWdlIFVSTDwvdGV4dD4KPHJlY3QgeD0iMjkyIiB5PSI1NSIgd2lkdGg9IjIxNiIgaGVpZ2h0PSI4MCIgcng9IjgiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIvPgo8dGV4dCB4PSI0MDAiIHk9IjgyIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIj5ab3Q8L3RleHQ+Cjx0ZXh0IHg9IjQwMCIgeT0iMTA3IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBmb250LXNpemU9IjEyIj5EZWRpY2F0ZWQgcHVibGljIFpvdCBzdG9yYWdlPC90ZXh0Pgo8cmVjdCB4PSI1ODAiIHk9IjY1IiB3aWR0aD0iMTk1IiBoZWlnaHQ9IjYwIiByeD0iOCIgZmlsbD0ibm9uZSIgc3Ryb2tlPSIjNjQ3NDhiIi8+Cjx0ZXh0IHg9IjY3NyIgeT0iOTEiIHRleHQtYW5jaG9yPSJtaWRkbGUiPkF1dGhlbnRpY2F0ZWQgcHVibGlzaGVyczwvdGV4dD4KPHRleHQgeD0iNjc3IiB5PSIxMTIiIHRleHQtYW5jaG9yPSJtaWRkbGUiIGZvbnQtc2l6ZT0iMTIiPnNlbGVjdGVkIHJlcG9zaXRvcnkgc2NvcGU8L3RleHQ+CjxwYXRoIGQ9Ik0yMjAgOTUgSDI4NiBNMjc5IDkwIEwyODcgOTUgTDI3OSAxMDAgTTU4MCA5NSBINTE0IE01MjEgOTAgTDUxMyA5NSBMNTIxIDEwMCIgZmlsbD0ibm9uZSIgc3Ryb2tlPSIjNjQ3NDhiIiBzdHJva2Utd2lkdGg9IjEuNSIvPgo8dGV4dCB4PSIyNTUiIHk9Ijc5IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBmb250LXNpemU9IjEyIj5wdWxsPC90ZXh0Pgo8dGV4dCB4PSI1NDUiIHk9Ijc5IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBmb250LXNpemU9IjEyIj5wdXNoPC90ZXh0Pgo8dGV4dCB4PSI0MDAiIHk9IjE2NSIgdGV4dC1hbmNob3I9Im1pZGRsZSI+UHVibGljIGltYWdlIHN0b3JhZ2Ugb24gUHJpdmF0ZSBLdWJlcm5ldGVzPC90ZXh0Pgo8dGV4dCB4PSI0MDAiIHk9IjE5MCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgZm9udC1zaXplPSIxMiI+UHJpdmF0ZSBpbWFnZXMgcmVtYWluIG91dHNpZGUgdGhpcyBwdWJsaWMgc2NvcGU7IG5vIEFXUyBBUEkgYWRhcHRlci48L3RleHQ+Cgo8L2c+PC9zdmc+" alt="Anonymous readers pull from Zot; authenticated publishers write selected public repositories." />
</div>

#### Anonymous reads and authenticated publication

For each selected path, grant anonymousPolicy read only. Named authenticated publishers receive read, create and update actions. Deny mutation to other users and anonymous clients; do not install a global create/update or administrator grant as a default.

Keep private images in the separate private deployment. Use the configuration schema for the deployed Zot release and verify exact repository matching and more-specific path precedence before exposing the endpoint.

#### Selected images and changed references

Select the source images and tags to transfer and freeze each selected tag to its source digest. Copy supported Docker schema-2 or OCI manifests and layers without changing their bytes. A retained multi-platform index includes all its referenced platform images. Verify the destination digests; a copy that requires media-type conversion or cannot preserve a required digest fails. Update only the image references the mapping controls. External users must change their old AWS image URLs.

The selected images do not include an unbounded registry history or continued replication of later AWS changes. Signatures, attestations, referrers, SBOMs and scanning history need their own transfer scope. Foreign layers fetched from external URLs are outside the initial self-contained copy guarantee. Preserving an image digest does not preserve repository identity or signature trust.

#### Operating the public registry

You operate storage capacity, backups, publisher authentication, public ingress and TLS renewal. A fresh anonymous client must pull without a cached credential or layer. Restore and credential-rotation procedures must retain the read/write boundary.

Configure Zot retention independently of AWS policies. Optional native extensions do not import ECR Public scanning results or history. Retain manifests and layers referenced by current releases and rollback images.

#### Limits of this mapping

* The public endpoint must be reachable by intended internet readers; cluster-local DNS alone is insufficient.
* Anonymous read and authenticated publication are separate ACLs. A broad authenticated default write rule would defeat publisher isolation.
* The mapping does not promise AWS lifecycle-policy translation, AWS scanning equivalence or continuous replication.
* Public distribution requires reachable public HTTPS and permissions for anonymous readers. A policy that forbids that access must reject this choice, not silently produce a private registry.

### Via Distribution

| Operation                                   | Area               | Support      | Depth        | Notes                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ------------------------------------------- | ------------------ | ------------ | ------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| AWS ECR Public management and token APIs    | AWS API boundary   | Out of scope | Full surface | Native registry access does not serve AWS CreateRepository, DescribeRepositories, PutImage, layer-upload calls or GetAuthorizationToken; no STS GetServiceBearerToken operation is added.                                                                                                                                                                                                                                                                                                                 |
| Anonymous image pull                        | Image distribution | Supported    | Common       | Readers pull selected images from the new public HTTPS registry URL without an AWS identity or target credential.                                                                                                                                                                                                                                                                                                                                                                                         |
| Authenticated image publication             | Image distribution | Supported    | Common       | The token issuer grants anonymous clients pull only for the exact public repositories. Authenticated publishers receive pull and push only for their assigned repositories. Requested scopes are intersected with the ordered ACL; asking for push cannot enlarge anonymous rights.                                                                                                                                                                                                                       |
| Continuous replication from AWS             | Migration          | Out of scope | Full surface | The initial selected image transfer does not continuously copy later changes from the AWS public registry.                                                                                                                                                                                                                                                                                                                                                                                                |
| Historical images and attached artifacts    | Migration          | Partial      | Most usage   | The selected images do not include an unbounded registry history or continued replication of later AWS changes. Signatures, attestations, referrers, SBOMs and scanning history need their own transfer scope. Foreign layers fetched from external URLs are outside the initial self-contained copy guarantee. Preserving an image digest does not preserve repository identity or signature trust.                                                                                                      |
| Selected image and digest transfer          | Migration          | Supported    | Common       | Select the source images and tags to transfer and freeze each selected tag to its source digest. Copy supported Docker schema-2 or OCI manifests and layers without changing their bytes. A retained multi-platform index includes all its referenced platform images. Verify the destination digests; a copy that requires media-type conversion or cannot preserve a required digest fails. Update only the image references the mapping controls. External users must change their old AWS image URLs. |
| Native retention and scanning configuration | Operations         | Partial      | Most usage   | Public deletion is disabled by default. Retirement and garbage collection are separate operator procedures with writes stopped or read-only as required by the selected release. Back up storage, ACL configuration and signing material. AWS cleanup policies, scanning findings and automatic replication are outside this mapping.                                                                                                                                                                     |
| AWS Gallery and registry aliases            | Public identity    | Out of scope | Full surface | The target registry has a different hostname and repository path; the Public Gallery and public.ecr.aws aliases are not preserved.                                                                                                                                                                                                                                                                                                                                                                        |
| Public repository provisioning              | Repositories       | Supported    | Common       | Deploy a dedicated public Distribution registry and a separate Cesanta docker\_auth token issuer. Both have public trusted HTTPS endpoints; the registry keeps its own persistent image storage.                                                                                                                                                                                                                                                                                                          |

#### Public images on Distribution

Deploy a dedicated public Distribution registry and a separate Cesanta docker\_auth token issuer. Both have public trusted HTTPS endpoints; the registry keeps its own persistent image storage.

Clients use the target registry directly at Infrastructure-only adaptation. AWS ECR Public management and authorization-token APIs, the Public Gallery and public.ecr.aws registry aliases are outside this mapping. Native push and pull do not implement AWS PutImage, layer-upload APIs or GetAuthorizationToken. No Max request adapter or additional STS operation is implied.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MDAiIGhlaWdodD0iMzAwIiB2aWV3Qm94PSIwIDAgODAwIDMwMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBbm9ueW1vdXMgcmVhZGVycyBwdWxsIGZyb20gRGlzdHJpYnV0aW9uOyBhdXRoZW50aWNhdGVkIHB1Ymxpc2hlcnMgd3JpdGUgc2VsZWN0ZWQgcHVibGljIHJlcG9zaXRvcmllcy4iPjxzdHlsZT50ZXh0e2ZvbnQtZmFtaWx5OkludGVyLC1hcHBsZS1zeXN0ZW0sQmxpbmtNYWNTeXN0ZW1Gb250LCdTZWdvZSBVSScsUm9ib3RvLCdIZWx2ZXRpY2EgTmV1ZScsQXJpYWwsc2Fucy1zZXJpZjtmaWxsOiMzMzQxNTV9PC9zdHlsZT4KPGcgZmlsbD0iY3VycmVudENvbG9yIiBmb250LWZhbWlseT0iQXJpYWwsIHNhbnMtc2VyaWYiIGZvbnQtc2l6ZT0iMTQiPgo8cmVjdCB4PSIyNSIgeT0iNjUiIHdpZHRoPSIxOTUiIGhlaWdodD0iNjAiIHJ4PSI4IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiLz4KPHRleHQgeD0iMTIyIiB5PSI5MSIgdGV4dC1hbmNob3I9Im1pZGRsZSI+QW5vbnltb3VzIHJlYWRlcnM8L3RleHQ+Cjx0ZXh0IHg9IjEyMiIgeT0iMTEyIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBmb250LXNpemU9IjEyIj5uZXcgcHVibGljIGltYWdlIFVSTDwvdGV4dD4KPHJlY3QgeD0iMjkyIiB5PSI1NSIgd2lkdGg9IjIxNiIgaGVpZ2h0PSI4MCIgcng9IjgiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIvPgo8dGV4dCB4PSI0MDAiIHk9IjgyIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIj5EaXN0cmlidXRpb248L3RleHQ+Cjx0ZXh0IHg9IjQwMCIgeT0iMTA3IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBmb250LXNpemU9IjEyIj5SZWdpc3RyeSBwbHVzIHRva2VuIGlzc3VlcjwvdGV4dD4KPHJlY3QgeD0iNTgwIiB5PSI2NSIgd2lkdGg9IjE5NSIgaGVpZ2h0PSI2MCIgcng9IjgiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIvPgo8dGV4dCB4PSI2NzciIHk9IjkxIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIj5BdXRoZW50aWNhdGVkIHB1Ymxpc2hlcnM8L3RleHQ+Cjx0ZXh0IHg9IjY3NyIgeT0iMTEyIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBmb250LXNpemU9IjEyIj5zZWxlY3RlZCByZXBvc2l0b3J5IHNjb3BlPC90ZXh0Pgo8cGF0aCBkPSJNMjIwIDk1IEgyODYgTTI3OSA5MCBMMjg3IDk1IEwyNzkgMTAwIE01ODAgOTUgSDUxNCBNNTIxIDkwIEw1MTMgOTUgTDUyMSAxMDAiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIxLjUiLz4KPHRleHQgeD0iMjU1IiB5PSI3OSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgZm9udC1zaXplPSIxMiI+cHVsbDwvdGV4dD4KPHRleHQgeD0iNTQ1IiB5PSI3OSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgZm9udC1zaXplPSIxMiI+cHVzaDwvdGV4dD4KPHRleHQgeD0iNDAwIiB5PSIxNjUiIHRleHQtYW5jaG9yPSJtaWRkbGUiPlB1YmxpYyBpbWFnZSBzdG9yYWdlIG9uIFByaXZhdGUgS3ViZXJuZXRlczwvdGV4dD4KPHRleHQgeD0iNDAwIiB5PSIxOTAiIHRleHQtYW5jaG9yPSJtaWRkbGUiIGZvbnQtc2l6ZT0iMTIiPlByaXZhdGUgaW1hZ2VzIHJlbWFpbiBvdXRzaWRlIHRoaXMgcHVibGljIHNjb3BlOyBubyBBV1MgQVBJIGFkYXB0ZXIuPC90ZXh0PgoKPHBhdGggZD0iTTEyNSAxMjUgVjI1MCBIMzIwIiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMS41IiBzdHJva2UtZGFzaGFycmF5PSI1IDQiLz4KPHBhdGggZD0iTTY3NSAxMjUgVjI1MCBINDgwIiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMS41IiBzdHJva2UtZGFzaGFycmF5PSI1IDQiLz4KPHJlY3QgeD0iMzIwIiB5PSIyMjEiIHdpZHRoPSIxNjAiIGhlaWdodD0iNjAiIHJ4PSI4IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiLz4KPHRleHQgeD0iNDAwIiB5PSIyNDUiIHRleHQtYW5jaG9yPSJtaWRkbGUiPmRvY2tlcl9hdXRoPC90ZXh0Pgo8dGV4dCB4PSI0MDAiIHk9IjI2NiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgZm9udC1zaXplPSIxMiI+c2NvcGVkIGJlYXJlciB0b2tlbnM8L3RleHQ+Cjx0ZXh0IHg9IjE2OCIgeT0iMjQxIiBmb250LXNpemU9IjEyIj5hbm9ueW1vdXMgcHVsbCB0b2tlbjwvdGV4dD4KPHRleHQgeD0iNDg2IiB5PSIyNDEiIGZvbnQtc2l6ZT0iMTIiPnB1Ymxpc2hlciB0b2tlbjwvdGV4dD4KCjwvZz48L3N2Zz4=" alt="Anonymous readers pull from Distribution; authenticated publishers write selected public repositories." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MDAiIGhlaWdodD0iMzAwIiB2aWV3Qm94PSIwIDAgODAwIDMwMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBbm9ueW1vdXMgcmVhZGVycyBwdWxsIGZyb20gRGlzdHJpYnV0aW9uOyBhdXRoZW50aWNhdGVkIHB1Ymxpc2hlcnMgd3JpdGUgc2VsZWN0ZWQgcHVibGljIHJlcG9zaXRvcmllcy4iPjxzdHlsZT50ZXh0e2ZvbnQtZmFtaWx5OkludGVyLC1hcHBsZS1zeXN0ZW0sQmxpbmtNYWNTeXN0ZW1Gb250LCdTZWdvZSBVSScsUm9ib3RvLCdIZWx2ZXRpY2EgTmV1ZScsQXJpYWwsc2Fucy1zZXJpZjtmaWxsOiNjYmQ1ZTF9PC9zdHlsZT4KPGcgZmlsbD0iY3VycmVudENvbG9yIiBmb250LWZhbWlseT0iQXJpYWwsIHNhbnMtc2VyaWYiIGZvbnQtc2l6ZT0iMTQiPgo8cmVjdCB4PSIyNSIgeT0iNjUiIHdpZHRoPSIxOTUiIGhlaWdodD0iNjAiIHJ4PSI4IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiLz4KPHRleHQgeD0iMTIyIiB5PSI5MSIgdGV4dC1hbmNob3I9Im1pZGRsZSI+QW5vbnltb3VzIHJlYWRlcnM8L3RleHQ+Cjx0ZXh0IHg9IjEyMiIgeT0iMTEyIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBmb250LXNpemU9IjEyIj5uZXcgcHVibGljIGltYWdlIFVSTDwvdGV4dD4KPHJlY3QgeD0iMjkyIiB5PSI1NSIgd2lkdGg9IjIxNiIgaGVpZ2h0PSI4MCIgcng9IjgiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIvPgo8dGV4dCB4PSI0MDAiIHk9IjgyIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIj5EaXN0cmlidXRpb248L3RleHQ+Cjx0ZXh0IHg9IjQwMCIgeT0iMTA3IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBmb250LXNpemU9IjEyIj5SZWdpc3RyeSBwbHVzIHRva2VuIGlzc3VlcjwvdGV4dD4KPHJlY3QgeD0iNTgwIiB5PSI2NSIgd2lkdGg9IjE5NSIgaGVpZ2h0PSI2MCIgcng9IjgiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIvPgo8dGV4dCB4PSI2NzciIHk9IjkxIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIj5BdXRoZW50aWNhdGVkIHB1Ymxpc2hlcnM8L3RleHQ+Cjx0ZXh0IHg9IjY3NyIgeT0iMTEyIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBmb250LXNpemU9IjEyIj5zZWxlY3RlZCByZXBvc2l0b3J5IHNjb3BlPC90ZXh0Pgo8cGF0aCBkPSJNMjIwIDk1IEgyODYgTTI3OSA5MCBMMjg3IDk1IEwyNzkgMTAwIE01ODAgOTUgSDUxNCBNNTIxIDkwIEw1MTMgOTUgTDUyMSAxMDAiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIxLjUiLz4KPHRleHQgeD0iMjU1IiB5PSI3OSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgZm9udC1zaXplPSIxMiI+cHVsbDwvdGV4dD4KPHRleHQgeD0iNTQ1IiB5PSI3OSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgZm9udC1zaXplPSIxMiI+cHVzaDwvdGV4dD4KPHRleHQgeD0iNDAwIiB5PSIxNjUiIHRleHQtYW5jaG9yPSJtaWRkbGUiPlB1YmxpYyBpbWFnZSBzdG9yYWdlIG9uIFByaXZhdGUgS3ViZXJuZXRlczwvdGV4dD4KPHRleHQgeD0iNDAwIiB5PSIxOTAiIHRleHQtYW5jaG9yPSJtaWRkbGUiIGZvbnQtc2l6ZT0iMTIiPlByaXZhdGUgaW1hZ2VzIHJlbWFpbiBvdXRzaWRlIHRoaXMgcHVibGljIHNjb3BlOyBubyBBV1MgQVBJIGFkYXB0ZXIuPC90ZXh0PgoKPHBhdGggZD0iTTEyNSAxMjUgVjI1MCBIMzIwIiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMS41IiBzdHJva2UtZGFzaGFycmF5PSI1IDQiLz4KPHBhdGggZD0iTTY3NSAxMjUgVjI1MCBINDgwIiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMS41IiBzdHJva2UtZGFzaGFycmF5PSI1IDQiLz4KPHJlY3QgeD0iMzIwIiB5PSIyMjEiIHdpZHRoPSIxNjAiIGhlaWdodD0iNjAiIHJ4PSI4IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiLz4KPHRleHQgeD0iNDAwIiB5PSIyNDUiIHRleHQtYW5jaG9yPSJtaWRkbGUiPmRvY2tlcl9hdXRoPC90ZXh0Pgo8dGV4dCB4PSI0MDAiIHk9IjI2NiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgZm9udC1zaXplPSIxMiI+c2NvcGVkIGJlYXJlciB0b2tlbnM8L3RleHQ+Cjx0ZXh0IHg9IjE2OCIgeT0iMjQxIiBmb250LXNpemU9IjEyIj5hbm9ueW1vdXMgcHVsbCB0b2tlbjwvdGV4dD4KPHRleHQgeD0iNDg2IiB5PSIyNDEiIGZvbnQtc2l6ZT0iMTIiPnB1Ymxpc2hlciB0b2tlbjwvdGV4dD4KCjwvZz48L3N2Zz4=" alt="Anonymous readers pull from Distribution; authenticated publishers write selected public repositories." />
</div>

#### Anonymous reads and authenticated publication

The token issuer grants anonymous clients pull only for the exact public repositories. Authenticated publishers receive pull and push only for their assigned repositories. Requested scopes are intersected with the ordered ACL; asking for push cannot enlarge anonymous rights.

Use an exact publisher/repository rule followed by the exact public-read rule and deny everything else. Keep the private registry and its signing trust separate. Do not copy example localhost, bridge-network or administrator wildcard grants into the public ACL.

#### Selected images and changed references

Select the source images and tags to transfer and freeze each selected tag to its source digest. Copy supported Docker schema-2 or OCI manifests and layers without changing their bytes. A retained multi-platform index includes all its referenced platform images. Verify the destination digests; a copy that requires media-type conversion or cannot preserve a required digest fails. Update only the image references the mapping controls. External users must change their old AWS image URLs.

The selected images do not include an unbounded registry history or continued replication of later AWS changes. Signatures, attestations, referrers, SBOMs and scanning history need their own transfer scope. Foreign layers fetched from external URLs are outside the initial self-contained copy guarantee. Preserving an image digest does not preserve repository identity or signature trust.

#### Operating the public registry

You operate the registry, token issuer, TLS certificates, protected publisher credentials and token-signing trust. Use a reviewed docker\_auth release and compatible Distribution image. Match issuer and audience and configure trusted signing material. Rotate keys with a bounded verification overlap; new token issuance depends on issuer availability.

Public deletion is disabled by default. Retirement and garbage collection are separate operator procedures with writes stopped or read-only as required by the selected release. Back up storage, ACL configuration and signing material. AWS cleanup policies, scanning findings and automatic replication are outside this mapping.

#### Limits of this mapping

* An anonymous bearer token is native registry access machinery, not an AWS ECR Public authorization token or an AWS identity.
* Publisher pull/push grants do not include deletion, other repository namespaces or token-service administration.
* Operating the separate token issuer is part of this choice. Existing valid tokens do not establish availability of future token requests.
* Public distribution requires reachable public HTTPS and permissions for anonymous readers. A policy that forbids that access must reject this choice, not silently produce a private registry.

### Via Harbor

| Operation                                   | Area               | Support      | Depth        | Notes                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ------------------------------------------- | ------------------ | ------------ | ------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| AWS ECR Public management and token APIs    | AWS API boundary   | Out of scope | Full surface | Native registry access does not serve AWS CreateRepository, DescribeRepositories, PutImage, layer-upload calls or GetAuthorizationToken; no STS GetServiceBearerToken operation is added.                                                                                                                                                                                                                                                                                                                 |
| Anonymous image pull                        | Image distribution | Supported    | Common       | Readers pull selected images from the new public HTTPS registry URL without an AWS identity or target credential.                                                                                                                                                                                                                                                                                                                                                                                         |
| Authenticated image publication             | Image distribution | Supported    | Common       | Anonymous clients can pull from the public project. A project robot authenticates publication with pull and push permissions. Do not give anonymous clients or publisher robots project administration or deletion permissions.                                                                                                                                                                                                                                                                           |
| Continuous replication from AWS             | Migration          | Out of scope | Full surface | The initial selected image transfer does not continuously copy later changes from the AWS public registry.                                                                                                                                                                                                                                                                                                                                                                                                |
| Historical images and attached artifacts    | Migration          | Partial      | Most usage   | The selected images do not include an unbounded registry history or continued replication of later AWS changes. Signatures, attestations, referrers, SBOMs and scanning history need their own transfer scope. Foreign layers fetched from external URLs are outside the initial self-contained copy guarantee. Preserving an image digest does not preserve repository identity or signature trust.                                                                                                      |
| Selected image and digest transfer          | Migration          | Supported    | Common       | Select the source images and tags to transfer and freeze each selected tag to its source digest. Copy supported Docker schema-2 or OCI manifests and layers without changing their bytes. A retained multi-platform index includes all its referenced platform images. Verify the destination digests; a copy that requires media-type conversion or cannot preserve a required digest fails. Update only the image references the mapping controls. External users must change their old AWS image URLs. |
| Native retention and scanning configuration | Operations         | Partial      | Most usage   | Harbor offers its own retention and scanning controls, which need separate configuration. This mapping does not import AWS policy rules, findings or Gallery metadata. Ensure cleanup retains the image digests used by running deployments and rollback plans.                                                                                                                                                                                                                                           |
| AWS Gallery and registry aliases            | Public identity    | Out of scope | Full surface | The target registry has a different hostname and repository path; the Public Gallery and public.ecr.aws aliases are not preserved.                                                                                                                                                                                                                                                                                                                                                                        |
| Public repository provisioning              | Repositories       | Supported    | Common       | Deploy Harbor behind a public DNS name and trusted HTTPS endpoint. Place the selected images in a dedicated public project; repository names remain distinct within that project.                                                                                                                                                                                                                                                                                                                         |

#### Public images on Harbor

Deploy Harbor behind a public DNS name and trusted HTTPS endpoint. Place the selected images in a dedicated public project; repository names remain distinct within that project.

Clients use the target registry directly at Infrastructure-only adaptation. AWS ECR Public management and authorization-token APIs, the Public Gallery and public.ecr.aws registry aliases are outside this mapping. Native push and pull do not implement AWS PutImage, layer-upload APIs or GetAuthorizationToken. No Max request adapter or additional STS operation is implied.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MDAiIGhlaWdodD0iMjE1IiB2aWV3Qm94PSIwIDAgODAwIDIxNSIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBbm9ueW1vdXMgcmVhZGVycyBwdWxsIGZyb20gSGFyYm9yOyBhdXRoZW50aWNhdGVkIHB1Ymxpc2hlcnMgd3JpdGUgc2VsZWN0ZWQgcHVibGljIHJlcG9zaXRvcmllcy4iPjxzdHlsZT50ZXh0e2ZvbnQtZmFtaWx5OkludGVyLC1hcHBsZS1zeXN0ZW0sQmxpbmtNYWNTeXN0ZW1Gb250LCdTZWdvZSBVSScsUm9ib3RvLCdIZWx2ZXRpY2EgTmV1ZScsQXJpYWwsc2Fucy1zZXJpZjtmaWxsOiMzMzQxNTV9PC9zdHlsZT4KPGcgZmlsbD0iY3VycmVudENvbG9yIiBmb250LWZhbWlseT0iQXJpYWwsIHNhbnMtc2VyaWYiIGZvbnQtc2l6ZT0iMTQiPgo8cmVjdCB4PSIyNSIgeT0iNjUiIHdpZHRoPSIxOTUiIGhlaWdodD0iNjAiIHJ4PSI4IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiLz4KPHRleHQgeD0iMTIyIiB5PSI5MSIgdGV4dC1hbmNob3I9Im1pZGRsZSI+QW5vbnltb3VzIHJlYWRlcnM8L3RleHQ+Cjx0ZXh0IHg9IjEyMiIgeT0iMTEyIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBmb250LXNpemU9IjEyIj5uZXcgcHVibGljIGltYWdlIFVSTDwvdGV4dD4KPHJlY3QgeD0iMjkyIiB5PSI1NSIgd2lkdGg9IjIxNiIgaGVpZ2h0PSI4MCIgcng9IjgiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIvPgo8dGV4dCB4PSI0MDAiIHk9IjgyIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIj5IYXJib3I8L3RleHQ+Cjx0ZXh0IHg9IjQwMCIgeT0iMTA3IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBmb250LXNpemU9IjEyIj5EZWRpY2F0ZWQgcHVibGljIHByb2plY3Q8L3RleHQ+CjxyZWN0IHg9IjU4MCIgeT0iNjUiIHdpZHRoPSIxOTUiIGhlaWdodD0iNjAiIHJ4PSI4IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiLz4KPHRleHQgeD0iNjc3IiB5PSI5MSIgdGV4dC1hbmNob3I9Im1pZGRsZSI+QXV0aGVudGljYXRlZCBwdWJsaXNoZXJzPC90ZXh0Pgo8dGV4dCB4PSI2NzciIHk9IjExMiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgZm9udC1zaXplPSIxMiI+c2VsZWN0ZWQgcmVwb3NpdG9yeSBzY29wZTwvdGV4dD4KPHBhdGggZD0iTTIyMCA5NSBIMjg2IE0yNzkgOTAgTDI4NyA5NSBMMjc5IDEwMCBNNTgwIDk1IEg1MTQgTTUyMSA5MCBMNTEzIDk1IEw1MjEgMTAwIiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMS41Ii8+Cjx0ZXh0IHg9IjI1NSIgeT0iNzkiIHRleHQtYW5jaG9yPSJtaWRkbGUiIGZvbnQtc2l6ZT0iMTIiPnB1bGw8L3RleHQ+Cjx0ZXh0IHg9IjU0NSIgeT0iNzkiIHRleHQtYW5jaG9yPSJtaWRkbGUiIGZvbnQtc2l6ZT0iMTIiPnB1c2g8L3RleHQ+Cjx0ZXh0IHg9IjQwMCIgeT0iMTY1IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIj5QdWJsaWMgaW1hZ2Ugc3RvcmFnZSBvbiBQcml2YXRlIEt1YmVybmV0ZXM8L3RleHQ+Cjx0ZXh0IHg9IjQwMCIgeT0iMTkwIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBmb250LXNpemU9IjEyIj5Qcml2YXRlIGltYWdlcyByZW1haW4gb3V0c2lkZSB0aGlzIHB1YmxpYyBzY29wZTsgbm8gQVdTIEFQSSBhZGFwdGVyLjwvdGV4dD4KCjwvZz48L3N2Zz4=" alt="Anonymous readers pull from Harbor; authenticated publishers write selected public repositories." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MDAiIGhlaWdodD0iMjE1IiB2aWV3Qm94PSIwIDAgODAwIDIxNSIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBbm9ueW1vdXMgcmVhZGVycyBwdWxsIGZyb20gSGFyYm9yOyBhdXRoZW50aWNhdGVkIHB1Ymxpc2hlcnMgd3JpdGUgc2VsZWN0ZWQgcHVibGljIHJlcG9zaXRvcmllcy4iPjxzdHlsZT50ZXh0e2ZvbnQtZmFtaWx5OkludGVyLC1hcHBsZS1zeXN0ZW0sQmxpbmtNYWNTeXN0ZW1Gb250LCdTZWdvZSBVSScsUm9ib3RvLCdIZWx2ZXRpY2EgTmV1ZScsQXJpYWwsc2Fucy1zZXJpZjtmaWxsOiNjYmQ1ZTF9PC9zdHlsZT4KPGcgZmlsbD0iY3VycmVudENvbG9yIiBmb250LWZhbWlseT0iQXJpYWwsIHNhbnMtc2VyaWYiIGZvbnQtc2l6ZT0iMTQiPgo8cmVjdCB4PSIyNSIgeT0iNjUiIHdpZHRoPSIxOTUiIGhlaWdodD0iNjAiIHJ4PSI4IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiLz4KPHRleHQgeD0iMTIyIiB5PSI5MSIgdGV4dC1hbmNob3I9Im1pZGRsZSI+QW5vbnltb3VzIHJlYWRlcnM8L3RleHQ+Cjx0ZXh0IHg9IjEyMiIgeT0iMTEyIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBmb250LXNpemU9IjEyIj5uZXcgcHVibGljIGltYWdlIFVSTDwvdGV4dD4KPHJlY3QgeD0iMjkyIiB5PSI1NSIgd2lkdGg9IjIxNiIgaGVpZ2h0PSI4MCIgcng9IjgiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIvPgo8dGV4dCB4PSI0MDAiIHk9IjgyIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIj5IYXJib3I8L3RleHQ+Cjx0ZXh0IHg9IjQwMCIgeT0iMTA3IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBmb250LXNpemU9IjEyIj5EZWRpY2F0ZWQgcHVibGljIHByb2plY3Q8L3RleHQ+CjxyZWN0IHg9IjU4MCIgeT0iNjUiIHdpZHRoPSIxOTUiIGhlaWdodD0iNjAiIHJ4PSI4IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiLz4KPHRleHQgeD0iNjc3IiB5PSI5MSIgdGV4dC1hbmNob3I9Im1pZGRsZSI+QXV0aGVudGljYXRlZCBwdWJsaXNoZXJzPC90ZXh0Pgo8dGV4dCB4PSI2NzciIHk9IjExMiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgZm9udC1zaXplPSIxMiI+c2VsZWN0ZWQgcmVwb3NpdG9yeSBzY29wZTwvdGV4dD4KPHBhdGggZD0iTTIyMCA5NSBIMjg2IE0yNzkgOTAgTDI4NyA5NSBMMjc5IDEwMCBNNTgwIDk1IEg1MTQgTTUyMSA5MCBMNTEzIDk1IEw1MjEgMTAwIiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMS41Ii8+Cjx0ZXh0IHg9IjI1NSIgeT0iNzkiIHRleHQtYW5jaG9yPSJtaWRkbGUiIGZvbnQtc2l6ZT0iMTIiPnB1bGw8L3RleHQ+Cjx0ZXh0IHg9IjU0NSIgeT0iNzkiIHRleHQtYW5jaG9yPSJtaWRkbGUiIGZvbnQtc2l6ZT0iMTIiPnB1c2g8L3RleHQ+Cjx0ZXh0IHg9IjQwMCIgeT0iMTY1IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIj5QdWJsaWMgaW1hZ2Ugc3RvcmFnZSBvbiBQcml2YXRlIEt1YmVybmV0ZXM8L3RleHQ+Cjx0ZXh0IHg9IjQwMCIgeT0iMTkwIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBmb250LXNpemU9IjEyIj5Qcml2YXRlIGltYWdlcyByZW1haW4gb3V0c2lkZSB0aGlzIHB1YmxpYyBzY29wZTsgbm8gQVdTIEFQSSBhZGFwdGVyLjwvdGV4dD4KCjwvZz48L3N2Zz4=" alt="Anonymous readers pull from Harbor; authenticated publishers write selected public repositories." />
</div>

#### Anonymous reads and authenticated publication

Anonymous clients can pull from the public project. A project robot authenticates publication with pull and push permissions. Do not give anonymous clients or publisher robots project administration or deletion permissions.

Every repository placed in the public project is public. Do not flip an existing private project to public or load private ECR images into it. Keep the private registry deployment and its image population separate.

#### Selected images and changed references

Select the source images and tags to transfer and freeze each selected tag to its source digest. Copy supported Docker schema-2 or OCI manifests and layers without changing their bytes. A retained multi-platform index includes all its referenced platform images. Verify the destination digests; a copy that requires media-type conversion or cannot preserve a required digest fails. Update only the image references the mapping controls. External users must change their old AWS image URLs.

The selected images do not include an unbounded registry history or continued replication of later AWS changes. Signatures, attestations, referrers, SBOMs and scanning history need their own transfer scope. Foreign layers fetched from external URLs are outside the initial self-contained copy guarantee. Preserving an image digest does not preserve repository identity or signature trust.

#### Operating the public registry

You operate Harbor, its registry storage and backing state, the public ingress and certificate renewal. Preserve robot secrets when issued, rotate them through the operator workflow and account for credential expiry. Back up configuration and stored content together and verify recovery.

Harbor offers its own retention and scanning controls, which need separate configuration. This mapping does not import AWS policy rules, findings or Gallery metadata. Ensure cleanup retains the image digests used by running deployments and rollback plans.

#### Limits of this mapping

* Private Kubernetes describes the hosting environment; anonymous internet distribution still needs a deliberately public endpoint.
* Project publicity is broader than a single image tag; all repositories added to the public project share that exposure.
* Native retention, scanning and replication capabilities do not imply equivalent AWS policies, results or ongoing replication.
* Public distribution requires reachable public HTTPS and permissions for anonymous readers. A policy that forbids that access must reject this choice, not silently produce a private registry.

[Service Catalog](/service-adapters/catalog).
