Skip to main content

A container registry that’s
simple to run and a pleasure to use

Angos is an OCI registry you configure in one file and run without a database. Its web UI shows what is inside every image, layer by layer, with scan reports and pull history alongside.

An image's merged filesystem, layer by layer, with any file open beside it.An image's merged filesystem, layer by layer, with any file open beside it.

An image's merged filesystem, layer by layer, with any file open beside it.

Operations

Little to look after

There is no database or lock service to run beside Angos. Everything it knows lives in the storage that holds your images.

How it works →

Servers are disposable

Start another instance on the same storage and it serves everything the last one did.

Scale by adding replicas

Replicas share the same bucket, with nothing to coordinate them.

Maintenance while it serves

Garbage collection, scrub and prune run beside the live registry.

Changes without restarts

The configuration and TLS certificates reload when their files change.

Comparison

How it compares

Harbor and Zot bring a UI and policies, with more to operate as you scale. Distribution needs almost nothing and leaves the rest to you. Angos keeps the small footprint and brings the rest.

Harbor

9 containers
nginxportalcorejobserviceregistryregistryctllogredispostgresql
Database
PostgreSQL and Redis
Scaling
Over an HA PostgreSQL and Redis
Garbage collection
Online
Web UI
Built in
Access control
Projects with RBAC roles

Zot

1 binary
zotDynamoDB or Redis, once shared
Database
Embedded BoltDB; DynamoDB or Redis once shared
Scaling
Repositories hashed across members
Garbage collection
Online
Web UI
Built in
Access control
Per-repository policies

Distribution

1 binary
registryAuth proxy or token server
Database
None; Redis optional as a cache
Scaling
Replicas on shared storage
Garbage collection
Registry read-only or stopped
Web UI
None
Access control
htpasswd, a token server or an auth proxy

Angos

1 binary
angos
Database
None; Redis optional as a cache
Scaling
Replicas on shared storage
Garbage collection
Online
Web UI
Built in, down to image files
Access control
CEL policies and webhooks

Harbor offers multi-tenant projects and a long track record, Zot a broad set of extensions, and Distribution is the reference implementation others build on. Figures are from Harbor 2.15.2's default install and the Zot 2.1.21 and Distribution 3.1.1 documentation.

Configuration

Rules you can read

Access and retention are CEL expressions in one TOML file, reloaded on save. Here only main-branch builds of your organization's repositories may push to production, and its twenty newest images are kept.

Expression reference →
config.toml
[auth.oidc.github-actions]
issuer = "https://token.actions.githubusercontent.com"

[repository."production".access_policy]
default = "deny"
rules = ['''
identity.oidc != null &&
identity.oidc.claims["ref"] == "refs/heads/main" &&
identity.oidc.claims["repository"].startsWith("myorg/")
''']

[repository."production".retention_policy]
rules = ['image.tag == "latest"', 'top_pushed(20)']

Get started

Running in five minutes

  1. Download the binary for your platform.
  2. Write a configuration naming a storage and a repository.
  3. Start the server and push an image.
terminal
curl -LO https://github.com/project-angos/angos/releases/latest/download/angos-linux-amd64
chmod +x angos-linux-amd64

cat > config.toml << 'EOF'
[server]
bind_address = "0.0.0.0"

[blob_store.fs]
root_dir = "./registry-data"

[global.access_policy]
default = "allow"

[repository."test"]
EOF

./angos-linux-amd64 -c config.toml server &
docker tag alpine:latest localhost:8000/test/alpine:latest
docker push localhost:8000/test/alpine:latest

Nobody here speaks ancient Greek. Angos (ἄγγος) just sounded good, and means vessel.