Deploy Docker Registry | Private, Password Required, Images on a Volume
Private Docker registry on Railway — password required, images on a volume.
Just deployed
/var/lib/registry
Deploy and Host a Docker Registry on Railway
A private Docker registry: the CNCF registry (distribution 3.1) behind a password, with images on a volume. It refuses to start without credentials, so it is never an open file host on a public domain.
Nothing to fill in. The template generates the password; find it in the Registry service's variables.
About Hosting a Docker Registry
One service, built from ak40u/docker-registry-railway-starter:
- Registry: the Docker Registry HTTP API, behind HTTP basic authentication, with image layers on a volume (public)
docker login -u admin
docker tag myapp /myapp:1.0
docker push /myapp:1.0
Common Use Cases
- Private images for your own deployments, pulled by other Railway services or by CI.
- A mirror of the images your builds depend on, so a deploy does not wait on a public registry.
- Sharing images inside a team without a paid registry plan.
Dependencies for Docker Registry Hosting
Deployment Dependencies
registry:3.1.2(CNCF distribution, Apache-2.0) withapache2-utilsforhtpasswd, built from the starter repository's Dockerfile
Implementation Details
- A password is mandatory. The common registry template runs
registry:2with no authentication on a public domain, so anyone who finds the address can push and pull anything. Here the start script exits unless bothAUTH_USERNAMEandAUTH_PASSWORDare set, and writes the bcrypthtpasswdfile the registry requires from them on every start; changing the password is a variable change and a redeploy. - The credentials are not
REGISTRY_*variables. The registry reads everyREGISTRY_*variable as a configuration key, soREGISTRY_PASSWORDwould be logged as an unrecognised setting. htpasswdis installed at build time, so the registry never depends on a package mirror while it starts.- Deletes free space.
REGISTRY_STORAGE_DELETE_ENABLED=truelets you delete manifests through the API and reclaim storage with garbage collection. - No health check path. The registry's API answers 401 without credentials, and Railway's health check expects 200.
Configuration
AUTH_USERNAME defaults to admin; AUTH_PASSWORD is generated. Image layers count toward the volume's size, so watch it if you push large images.
Verification
Deployed from this template into an empty project: the registry started for the generated user and answers an anonymous /v2/ request with 401. Locally, on the same image: a wrong password gets 401, the right one 200, and docker login, docker push and the catalog work; without credentials the container exits with a message naming both variables.
Why Deploy a Docker Registry on Railway?
Railway is a singular platform to deploy your infrastructure stack. Railway will host your infrastructure so you don't have to deal with configuration, while allowing you to vertically and horizontally scale it.
By deploying a Docker Registry on Railway, you are one step closer to supporting a complete full-stack application with minimal burden. Host your servers, databases, AI agents, and more on Railway.
Template Content