agent-substrate / agent-substrate/substrate

Feature request: Support 3rd party private container registries + authentication like EKS

オープン
#432 コメント 3 件 リアクション 4 件 担当者 0 名 GitHub で見る
area/identity kind/feature
主要言語
Go
スター
1.8k
フォーク
316
平均マージ
2日 43分
マージ済み PR(30日)
287

説明

Problem

Substrate's atelet currently only supports GCP Application Default Credentials for authenticating image pulls (--gcp-auth-for-image-pulls). Users running on other cloud providers — EKS (AWS ECR), AKS (Azure ACR), or self-hosted registries — have no way to pull images from private registries.

Current behavior

- GCP ADC auth is supported via --gcp-auth-for-image-pulls
- Local/localhost registry rewrites are supported via --localhost-registry-replacement
- No support for AWS ECR, Azure ACR, GHCR, or generic Docker credential helpers

Proposed solution

Add pluggable registry authentication so operators can configure credentials for any OCI-compatible private registry. At minimum:

- AWS ECR — IAM Roles for Service Accounts (IRSA) / instance profile token refresh
- Azure ACR — Workload Identity / managed identity
- Generic — static imagePullSecrets-style config (username/password or token) for self-hosted registries (Harbor, Artifactory, GHCR, etc.)

This likely maps to adding new flags or a credentials config file to atelet, and wiring additional authenticators into the go-containerregistry keychain used during image pulls (cmd/atelet/main.go).

Why it matters

Many teams run AI agent workloads on EKS or AKS and store their agent images in ECR/ACR. Without this, Substrate is effectively GCP-only for private image use cases.

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。