Skip to content

feat(server): add registry commands to manage Docker logins - #100

Merged
andrasbacsai merged 1 commit into
mainfrom
server-docker-registries
Oct 6, 2026
Merged

andrasbacsai merged 1 commit into
mainfrom
server-docker-registries

Conversation

@andrasbacsai

Copy link
Copy Markdown
Member

Summary

  • Adds a new coolify server registry command group (alias registries) for managing Docker registry logins on servers:
    • list <server_uuid> shows the registries the server is logged in to, their status (Logged in / Credential helper / Not logged in), and a summary of which resources use them, such as "3 applications, 1 database". Usernames are hidden in table output unless -s is passed. JSON output includes the full used_by details. If the API returns an error field, it is printed as a warning. This command needs a token with read:sensitive.
    • login <server_uuid> [<server_uuid>...] runs docker login on one or more servers using --registry and -u/--username. When logging in to several servers, each result is reported separately and the command fails with a summary if any server failed.
    • check <server_uuid> <registry> checks that the saved login still works.
    • logout <server_uuid> <registry> runs docker logout. It asks for confirmation unless -f/--force is given.
  • Password handling: there is no flag for the password. It is read from stdin with --password-stdin, which strips only one trailing newline like docker login. Otherwise it is read from a hidden prompt when running in a terminal. The password is sent only in the JSON request body and is capped at 20,000 bytes to match the API limit.
  • Registry input is normalized before use, so https://GHCR.io/ becomes ghcr.io. Registry values are escaped as a single URL path segment, and hosts with ports like registry.example.com:5000 work.
  • Debug logging now redacts password fields as well as token fields.
  • Updates README.md and llms-full.txt with the new commands.
  • Adds tests for the service layer and the commands: table, JSON and sensitive output, stdin and TTY password input, validation, multi-server login, logout confirmation and API error messages.

Add `coolify server registry` with list, login, check and logout
subcommands for managing Docker registry logins on servers.

- list shows the registries each server is logged in to and the
  resources that use them. Usernames are masked unless -s is given.
- login runs docker login on one or more servers. The password is read
  from --password-stdin or prompted without echo, and is limited to
  20000 bytes.
- check confirms that a saved login still works.
- logout runs docker logout, with -f to skip the confirmation prompt.
- Registry input is normalized (scheme, case and path are stripped)
  before it is used as a URL path segment.
- Debug logs of API requests now redact "password" fields.
@andrasbacsai
andrasbacsai merged commit eed511d into main Oct 6, 2026
5 checks passed
@andrasbacsai
andrasbacsai deleted the server-docker-registries branch October 6, 2026 17:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant