Skip to content
Apex
Aether Cloud / Developer tools / Container registry
Aether Cloud · Developer tools

Container registry.

Private image registry with vulnerability scanning, signing and replication.

⌨ Developer tools
Overview

A private registry for your container images and artifacts — scanned for vulnerabilities, signed for provenance and replicated to the regions you deploy in.

Where it sits
Deployment
Managed → air-gapped
Governance
IAM · encryption · audit
How it works

Three steps to running.

01
Push images

A private registry for OCI images and artifacts.

02
Scan & sign

Continuous CVE scanning and signing for provenance.

03
Replicate

Geo-replicate for fast pulls near every cluster.

What you get

Container registry, in full.

Vulnerability scanning

Continuous CVE scanning with severity and fix guidance.

Image signing

Sign and verify provenance to block tampered images.

Replication

Geo-replicate for fast pulls near every cluster.

Retention rules

Garbage-collect old tags on policy to control cost.

API-first

Provision it in a few lines.

Every service is reachable from the same SDK, CLI and infrastructure-as-code — one identity, one bill, one audit trail across the whole catalog.

# Provision container registry on Aether Cloud
aether developer-tools create \
  --service container-registry \
  --name app \
  --region us-1 \
  --deploy managed   # or vpc | on-prem | air-gapped
Specs

At a glance.

Format
OCI images + artifacts
Scanning
Continuous CVE
Signing
Provenance, verified
Replication
Geo, multi-region
Retention
Policy-based GC
Use cases

Built for real work.

01

Image distribution

02

Supply-chain security

03

Multi-region deploys

Why one platform

On one model, not stitched together.

The usual stack runs container registry in one product, the model in another and the data in a third — and the seams between them are the cost. Aether Cloud runs it on the same platform that serves the model, governs your identity and deploys into your boundary, with the rest of the catalog one hop away.

One platform

No stitching a vector DB to one place, a warehouse to another and a model to a third — container registry sits next to the rest of the catalog, one identity, one bill.

The model is here

The provider that runs Aether runs your container registry — so the data and the model never leave the same governed boundary to talk to each other.

Built on demand

Need a capability that isn’t here yet? The model writes and deploys it into the same boundary — the catalog is a starting point, not a ceiling.

FAQ

Good to know.

How does this compare to ECR or Docker Hub?

A private registry with scanning, signing and replication — part of the supply-chain story across the platform.

Does it scan for CVEs?

Yes — continuous scanning with severity and fix guidance.

Can it block tampered images?

Yes — signing and verification stop unsigned or altered images.

Deploy anywhere

Your boundary, your choice.

Managed
Your VPC
On-prem
Air-gapped / sovereign

Run Container registry on Aether Cloud.

Private image registry with vulnerability scanning, signing and replication. Deployable managed, in your VPC, on-prem or fully air-gapped — talk to us about the configuration your workloads and your boundary require.