Page MenuHomeVyOS Platform

Add VRF or source-interface capability to set container registry feature
Open, LowPublic

Description

It seems that the "set container registry" cannot be configured with a VRF or source-interface to be used.

This means that if you run a private registry on the MGMT-network VyOS will never be able to reach your custom registry.

Current configuration:

set container registry example.com insecure
set container registry example.com mirror address '192.0.2.1'
set container registry example.com mirror port '8080'

Would need something like:

set container registry example.com vrf VRF_MGMT

or something like:

set container registry example.com source-interface eth0

The purpose is to "force" which egress interface (and by that VRF) would be used to access the registry.

Details

Version
2026.3
Is it a breaking change?
Unspecified (possibly destroys the router)
Issue type
Feature (new functionality)

Event Timeline

A workaround to using a custom private registry is to manually preload the images.

Note that you must use "sudo podman load -i <FILENAME>" and not "podman load -i <FILENAME>" for this to work.

Example:

sudo podman load -i /config/technitium_dns-server_2026-06-18.tar.gz

The above have been created by on another box doing "docker save" and compress the tar uzing "gzip -9".

Verify then by "podman images" that it will be empty while "sudo podman images" will display:

vyos@vyos:~$ sudo podman images
REPOSITORY                       TAG         IMAGE ID      CREATED      SIZE
docker.io/technitium/dns-server  latest      ba2762a21fbd  5 weeks ago  275 MB

Then add the container in the config example:

mkdir -p /config/container/dns-server/config
mkdir -p /config/container/dns-server/logs
set container name dns-server allow-host-networks
set container name dns-server capability 'net-bind-service'
set container name dns-server environment DNS_SERVER_WEB_SERVICE_LOCAL_ADDRESSES value '192.0.2.1'
set container name dns-server image 'docker.io/technitium/dns-server:latest'
set container name dns-server memory '4096'
set container name dns-server restart 'on-failure'
set container name dns-server volume config destination '/etc/dns'
set container name dns-server volume config source '/config/container/dns-server/config'
set container name dns-server volume logs destination '/var/log/technitium/dns'
set container name dns-server volume logs source '/config/container/dns-server/logs'

Once doing a commit and save (and exit from confmode) you can verify that the container is up and running by:

vyos@vyos:~$ sudo podman container ls
CONTAINER ID  IMAGE                                   COMMAND     CREATED         STATUS         PORTS       NAMES
a6f08f5aeb4e  docker.io/technitium/dns-server:latest  /etc/dns    32 minutes ago  Up 32 minutes              dns-server

Note that in above example Im using VRF's so the container will use one interface (192.0.2.1 being in VRF_MGMT) for mgmt and another interface (being in VRF_PROD) for the actual service (being a DNS-server in this case).

For this to work in VyOS you need to add this to the config:

set vrf bind-to-all