Registries
Some projects reference images from a private container registry —
kimbap's own docs/marketing site is a real example: its images live in a
private GitLab Container Registry project. Docker needs to be logged in to
that registry before it can pull them. kimbap lets you save that login once,
from the System page (or via the API/MCP), rather than SSH-ing in to run
docker login by hand every time.
Adding a registry
System → Registries → fill in the registry hostname (e.g.
registry.gitlab.com), a username, and a password or access token.
kimbap verifies the credential with a real docker login before saving
it — if the login fails, nothing is persisted. There's no such thing as a
saved-but-untested registry credential in kimbap.
How it actually works
Docker's own CLI keeps a login session per registry (normally in
~/.docker/config.json for whatever user runs docker commands). kimbap
runs as a native process — not a container — so when it shells out to
docker login <registry>, that login is available to every subsequent
docker/docker compose pull/up kimbap runs afterward, automatically.
kimbap doesn't inject credentials into individual pulls; it just makes sure
the login happened.
Because Docker's own login state doesn't survive a fresh Docker install (or
an explicit docker logout), kimbap treats its own database as the source
of truth for "which registries this host should be able to pull from," and
re-runs docker login for every saved credential once at every kimbap boot.
A stale or rotated credential logs a warning and is skipped — it doesn't
block kimbap from starting.
Storage
Passwords/tokens are the one class of secret kimbap has to be able to
recover in plaintext (to re-run docker login), so — unlike user passwords
(argon2id) or API keys/session tokens (SHA-256, never decrypted) — they're
encrypted at rest with AES-256-GCM. The encryption key is generated once and
kept at <state-dir>/secret.key, mode 0600. Losing that file means
losing the ability to decrypt saved registry credentials — you'd need to
re-add them (the file isn't needed for anything else; project files, the
database, and everything else are unaffected). Back it up alongside the rest
of your state directory if that matters to you.
Removing a registry
Removing a credential from kimbap also runs docker logout against that
registry, best-effort — if that fails (e.g. the registry is unreachable),
the credential is still removed from kimbap; only the host's own Docker
session might remain until it naturally expires or you log out by hand.
MCP / API
list_registries, add_registry (admin only, confirm: true), and
remove_registry (admin only, confirm: true) are available over both the
REST API and MCP — see the API reference and MCP
guide.