An OCI registry is suitable for Rootform Dialect and Policy Pack artifacts only
when it preserves the rootform-oci-core-v1
profile. Generic OCI support is not a Rootform qualification. A qualification
applies to the tested registry and authentication path, not to every deployment
or feature of that product.
Do not infer qualification for GitLab Container Registry, Azure Container Registry, Harbor, Artifactory, Nexus, or another OCI product from protocol similarity. A new path needs the same Rootform profile checks before it can carry a locked selection.
Rootform needs manifest resolution by version tag during publication and
review, manifest and blob reads by exact digest during locked acquisition,
and preservation of custom artifactType, config, and layer media types. When
publishing, the registry must accept blob uploads and manifest creation, then
return the exact manifest bytes for repull. Authentication must work through
Docker-compatible credentials when anonymous access is unavailable. Rootform
does not need registry catalog or tag listing.
rootform publish reports the repository, tag, digests, and sizes. Review that
identity, then record it with rootform add dialects REFERENCE or
rootform add policy-packs REFERENCE, which writes the complete pin to
rootform.lock. rootform init then requests the recorded repository and
manifest digest directly. It does not search tags or choose a newer version. See
Locks and vendored content for exact selection and
the OCI mirror procedure for moving the
same descriptor graph without changing its digests.
Rootform reads Docker config.json from DOCKER_CONFIG or the standard Docker
location. Host-specific helpers, a global credential store, or matching
auths supply credentials according to the Docker configuration. A configured
helper must be installed on PATH; a helper failure does not silently fall
back to another identity. Set SSL_CERT_FILE to a bounded PEM bundle when a
private certificate authority is required. Invalid trust data fails before
Rootform uses an artifact.
Use Container image when
credentials must enter a container. --offline on init or vendor forbids
registry acquisition, regardless of credential availability.