It seems that the "set container registry" cannot be configured with a VRF or source-interface to be used.
This means that if you run a private registry on the MGMT-network VyOS will never be able to reach your custom registry.
Current configuration:
set container registry example.com insecure set container registry example.com mirror address '192.0.2.1' set container registry example.com mirror port '8080'
Would need something like:
set container registry example.com vrf VRF_MGMT
or something like:
set container registry example.com source-interface eth0
The purpose is to "force" which egress interface (and by that VRF) would be used to access the registry.