Registries

Some projects reference images from a private container registry — kimbap's own docs/marketing site is a real example: its images live in a private GitLab Container Registry project. Docker needs to be logged in to that registry before it can pull them. kimbap lets you save that login once, from the System page (or via the API/MCP), rather than SSH-ing in to run docker login by hand every time.

Adding a registry

System → Registries → fill in the registry hostname (e.g. registry.gitlab.com), a username, and a password or access token.

kimbap verifies the credential with a real docker login before saving it — if the login fails, nothing is persisted. There's no such thing as a saved-but-untested registry credential in kimbap.

How it actually works

Docker's own CLI keeps a login session per registry (normally in ~/.docker/config.json for whatever user runs docker commands). kimbap runs as a native process — not a container — so when it shells out to docker login <registry>, that login is available to every subsequent docker/docker compose pull/up kimbap runs afterward, automatically. kimbap doesn't inject credentials into individual pulls; it just makes sure the login happened.

Because Docker's own login state doesn't survive a fresh Docker install (or an explicit docker logout), kimbap treats its own database as the source of truth for "which registries this host should be able to pull from," and re-runs docker login for every saved credential once at every kimbap boot. A stale or rotated credential logs a warning and is skipped — it doesn't block kimbap from starting.

Storage

Passwords/tokens are the one class of secret kimbap has to be able to recover in plaintext (to re-run docker login), so — unlike user passwords (argon2id) or API keys/session tokens (SHA-256, never decrypted) — they're encrypted at rest with AES-256-GCM. The encryption key is generated once and kept at <state-dir>/secret.key, mode 0600. Losing that file means losing the ability to decrypt saved registry credentials — you'd need to re-add them (the file isn't needed for anything else; project files, the database, and everything else are unaffected). Back it up alongside the rest of your state directory if that matters to you.

Removing a registry

Removing a credential from kimbap also runs docker logout against that registry, best-effort — if that fails (e.g. the registry is unreachable), the credential is still removed from kimbap; only the host's own Docker session might remain until it naturally expires or you log out by hand.

MCP / API

list_registries, add_registry (admin only, confirm: true), and remove_registry (admin only, confirm: true) are available over both the REST API and MCP — see the API reference and MCP guide.