6/24/2026 at 4:27:17 PM
My favorite use of this is peer-to-peer transfer of Docker images. The Docker CLI only allows you to use registries authenticated with HTTPS but there's an exception where it allows HTTP transfers over localhost.So, if you use SSH tunneling to forward a port from localhost to a remote, then Docker unwittingly pushes to a remote. This is super useful "off the grid" with robotics/embedded applications where you don't want to bother with a registry and a good Internet connection.
Example, docker pussh: https://github.com/psviderski/unregistry
by tangotaylor
6/24/2026 at 6:11:18 PM
That's not quite true, you just need to add the `insecure-registries`[1] option with a list of either IP (or ip ranges) or hostnames that you want to allow without TLS.```/etc/docker/daemon.json
{
"insecure-registries": ["10.100.0.0/24", "registry.yourmom.example.com:5000"]
}
```[1] https://docs.docker.com/reference/cli/dockerd/#insecure-regi...
by mmh0000
6/24/2026 at 7:29:45 PM
Yes this is true. I should caveat that we distributed the tool among a team and we didn't want to ask them to all edit their daemon.json with an ever-expanding list of IP addresses.by tangotaylor
6/24/2026 at 5:50:04 PM
This is really useful as you don't have to add an entry under insecure-registries for local registries that don't have valid certificates.by QGQBGdeZREunxLe
6/24/2026 at 5:53:03 PM
You might as well handover the images to hackers.by bitlad
6/24/2026 at 4:57:52 PM
iirc there's a setting to allow docker to trust and use http registriesi set it up a few years ago for my homelab
by Kampfschnitzel
6/24/2026 at 6:30:00 PM
Which makes me think that I have never heard of signed images/artefactsby afiori