agent-substrate / agent-substrate/substrate

Feature request: Support 3rd party private container registries + authentication like EKS

未關閉
#432 3 則留言 4 個 reaction 已指派 0 人 在 GitHub 檢視
area/identity kind/feature
主要語言
Go
星號
1.8k
分支
316
平均合併
2 天 43 分鐘
30 天內合併 PR
287

描述

Problem

Substrate's atelet currently only supports GCP Application Default Credentials for authenticating image pulls (--gcp-auth-for-image-pulls). Users running on other cloud providers — EKS (AWS ECR), AKS (Azure ACR), or self-hosted registries — have no way to pull images from private registries.

Current behavior

- GCP ADC auth is supported via --gcp-auth-for-image-pulls
- Local/localhost registry rewrites are supported via --localhost-registry-replacement
- No support for AWS ECR, Azure ACR, GHCR, or generic Docker credential helpers

Proposed solution

Add pluggable registry authentication so operators can configure credentials for any OCI-compatible private registry. At minimum:

- AWS ECR — IAM Roles for Service Accounts (IRSA) / instance profile token refresh
- Azure ACR — Workload Identity / managed identity
- Generic — static imagePullSecrets-style config (username/password or token) for self-hosted registries (Harbor, Artifactory, GHCR, etc.)

This likely maps to adding new flags or a credentials config file to atelet, and wiring additional authenticators into the go-containerregistry keychain used during image pulls (cmd/atelet/main.go).

Why it matters

Many teams run AI agent workloads on EKS or AKS and store their agent images in ECR/ACR. Without this, Substrate is effectively GCP-only for private image use cases.

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。