Skip to content

Private Registries for BYOC PrivateLink

This guide describes artifact connectivity for BYOC PrivateLink deployments with private-registry artifact delivery enabled and without internet access. Each artifact source must be reachable from the component that downloads it.

There are two separate artifact paths:

  • Omnistrate-managed artifacts include the dataplane agent, Terraform executor, endpoint monitor, platform helper images, and managed deployment-cell amenities. Omnistrate publishes and synchronizes these artifacts to the configured private ECR registry.
  • SaaS Product artifacts include your application images, Helm charts, Operators, action-hook images, Terraform source, and Terraform or OpenTofu dependencies. Omnistrate does not automatically copy or proxy these artifacts into that registry.

Use the following references to configure your artifacts:

Artifact How It Is Supplied Private-Network Requirement
Dataplane agent and Omnistrate system images Managed automatically by Omnistrate No Plan change. The deployment cell needs ECR and S3 connectivity for the configured registry's region.
Managed deployment-cell amenity Managed automatically by Omnistrate No registry credentials needed in the amenity template.
SaaS Product Helm chart in private Amazon ECR Enable private ECR Helm chart pull The deployment cell needs access to the chart's ECR region.
SaaS Product container image Reference the image in the Plan or chart values; see image registry access The worker nodes need access to the registry and its layer-download hosts.
Local Helm or Terraform artifact Local Helm artifacts or Terraform source configuration The deployment cell needs access to Omnistrate deployment-artifact storage.
Git-based Terraform root source Follow Terraform source configuration The Git repository must be reachable from the control-plane worker.
Terraform or OpenTofu provider or module Use the dependency sources configured in your Terraform stack The configured dependency sources must be reachable from the executor.

Network Requirements

IAM permissions and registry credentials do not configure DNS, routes, VPC endpoints, or security-group rules. For endpoint lists, egress options, private DNS, and validation, use Imported VPC requirements for BYOC PrivateLink. Omnistrate configures these resources for an Omnistrate-managed VPC.

Amazon ECR uses ECR API for authorization, ECR DKR for manifests, and AWS-managed S3 storage for image and chart layers.

Artifact connectivity alone does not provide DNS-management connectivity. If external-dns or cert-manager DNS-01 manages DNS records without internet access, also provide the com.amazonaws.route53 interface endpoint and its private DNS configuration.

For non-ECR registries, use approved outbound egress or private routing and DNS to the registry and its layer-download hosts. ECR endpoints do not provide access to Docker Hub, GitHub Container Registry, or other registries.

Use Private SaaS Product Images

The generated AWS onboarding stack already grants ECR read permissions to the worker-node role used by Omnistrate-created node groups. No additional node-role policy is needed for an application-image repository in the deployment cell's AWS account, unless account or repository policies restrict access.

For a cross-account application image, the repository must also allow the pulling account or role. This is separate from the automatic private ECR Helm chart credential flow.

For username/password registries, use the existing Compose registry credentials or the Docker Registry Pull Secret example under Kubernetes Manifest Amenities.

Use Terraform and OpenTofu Artifacts

Use Terraform source configuration for Git and local artifacts. The control-plane worker fetches Git root source; a repository reachable only from the customer's VPC requires the local-artifact upload alternative.

Uploaded source requires S3 connectivity to Omnistrate deployment-artifact storage; see network requirements. Providers and remote modules must be reachable from the executor's network.