Prevent tags from being overwritten

Estimated reading time: 1 minute

By default, users with access to push to a repository, can push the same tag multiple times to the same repository. As an example, a user pushes an image to library/wordpress:latest, and later another user can push the image with exactly the same name but different functionality. This might make it difficult to trace back the image to the build that generated it.

To prevent this from happening, you can configure a repository to be immutable. Once you push a tag, DTR won’t allow anyone else to push another tag with the same name.

Make tags immutable

To make tags immutable, in the DTR web UI, navigate to the repository settings page, and change Immutability to On.

From now on, users will get an error message when trying to push a tag that already exists:

docker push
unknown: tag=latest cannot be overwritten because is an immutable repository

Where to go next

registry, immutable