Kubernetes and Cloud Native Associate (KCNA)Cloud Native DeliveryMedium

A team is developing a new microservice and wants to store its Docker image in a registry. They've decided to use a registry that is hosted by their cloud provider and integrated with their existing identity and access management (IAM) solution. Which type of container registry are they most likely using?

  1. AA cloud-provider managed private registry
  2. BA local Docker daemon registry
  3. CA self-hosted open-source registry like Harbor
  4. DA public, unauthenticated registry
Show answer & explanation

Correct answer: A. A cloud-provider managed private registry

Cloud-provider managed private registries (like AWS ECR, Google Container Registry/Artifact Registry, or Azure Container Registry) offer seamless integration with the cloud provider's IAM, security features, and often have better performance and reliability than self-hosted or local options.

Why the other options are wrong

  • B. A local Docker daemon registry is typically for development, not shared team use.
  • C. Self-hosted registries require more operational overhead and separate IAM integration.
  • D. Public registries lack security and integration for private images.

Cloud-Provider Managed Registry

A private container registry service offered and managed by a cloud provider (e.g., AWS ECR, GCR, ACR), deeply integrated with their platform's security, IAM, and networking services.

  • Offers high availability and scalability without self-hosting overhead.
  • Integrates with cloud IAM for granular access control.
  • Often includes built-in vulnerability scanning and image signing.
  • Optimized for use within the respective cloud ecosystem.

Memory trick: Cloud registries are the 'easy button' for secure image storage.

More Cloud Native Delivery questions