Kubernetes and Cloud Native Associate (KCNA)Cloud Native DeliveryMedium
A team is developing a new microservice and wants to store its Docker image in a registry. They've decided to use a registry that is hosted by their cloud provider and integrated with their existing identity and access management (IAM) solution. Which type of container registry are they most likely using?
- AA cloud-provider managed private registry
- BA local Docker daemon registry
- CA self-hosted open-source registry like Harbor
- DA public, unauthenticated registry
Show answer & explanationAnswer & explanation
Correct answer: A. A cloud-provider managed private registry
Cloud-provider managed private registries (like AWS ECR, Google Container Registry/Artifact Registry, or Azure Container Registry) offer seamless integration with the cloud provider's IAM, security features, and often have better performance and reliability than self-hosted or local options.
Why the other options are wrong
- B. A local Docker daemon registry is typically for development, not shared team use.
- C. Self-hosted registries require more operational overhead and separate IAM integration.
- D. Public registries lack security and integration for private images.
Cloud-Provider Managed Registry
A private container registry service offered and managed by a cloud provider (e.g., AWS ECR, GCR, ACR), deeply integrated with their platform's security, IAM, and networking services.
- Offers high availability and scalability without self-hosting overhead.
- Integrates with cloud IAM for granular access control.
- Often includes built-in vulnerability scanning and image signing.
- Optimized for use within the respective cloud ecosystem.
Memory trick: Cloud registries are the 'easy button' for secure image storage.