diff --git a/runpodctl/reference/runpodctl-registry.mdx b/runpodctl/reference/runpodctl-registry.mdx index 44145537..89ee3585 100644 --- a/runpodctl/reference/runpodctl-registry.mdx +++ b/runpodctl/reference/runpodctl-registry.mdx @@ -39,12 +39,46 @@ runpodctl registry get ### Create a registry authentication -Create credentials for a private container registry: +Create credentials for a private container registry. Supply the password in one of three ways: + +- Pass it directly with the `--password` flag. +- Pipe or redirect it into `--password-stdin`. +- Omit both flags to enter it at an interactive prompt. + +Pass the password directly with `--password`: ```bash runpodctl registry create --name "docker-hub" --username "myuser" --password "mypassword" ``` +Omit the password flag to have the command prompt for the password without echoing it: + +```bash +runpodctl registry create --name "docker-hub" --username "myuser" +``` + +Pipe a token held in an environment variable into `--password-stdin`: + +```bash +printenv REGISTRY_TOKEN | runpodctl registry create --name "docker-hub" --username "myuser" --password-stdin +``` + +Redirect a token from a file into `--password-stdin`: + +```bash +runpodctl registry create --name "docker-hub" --username "myuser" --password-stdin < token.txt +``` + +For Google Artifact Registry or gcr.io, set `--username` to the literal `_json_key` and feed the multi-line service-account JSON key file through `--password-stdin`. The command supports multi-line passwords and strips only a single trailing newline added by the pipe or redirection. + +```bash +runpodctl registry create --name "gcr" --username "_json_key" --password-stdin < service-account.json +``` + + +Prefer `--password-stdin` or the interactive prompt over `--password`. A value passed to `--password` is visible in the process table and your shell history. + + #### Create flags @@ -55,8 +89,12 @@ Name for this registry authentication. Registry username. - -Registry password or access token. + +Registry password or access token. Cannot be used with `--password-stdin`. If neither `--password` nor `--password-stdin` is given, the command prompts for the password when run in an interactive terminal, or exits with an error otherwise. + + + +Read the registry password from standard input (pipe, heredoc, or file redirection). Supports multi-line values. Cannot be used with `--password`. ### Delete a registry authentication