Pricing
You pay for storage. That is all.
Pulls, pushes, scanning, signing and the pull-through cache are included on every plan.
Public
For open-source projects and public images.
€0
- Unlimited public repositories
- Unlimited pulls
- Scanning on push
- Cosign signing
- Community support
Team
most popularPrivate images, billed on deduplicated bytes.
€8/GB/mo
first 20 GB free · typical team stores 60–200 GB
- Unlimited private repositories
- Unlimited pulls
- Pull-through cache
- Retention rules with dry run
- SSO and audit log
- Support within one business day
Enterprise
Residency, private deployment and admission policy at scale.
Custom
- EU or US residency
- Single-tenant deployment option
- Cluster-side caching appliance
- Custom scan feeds
- 99.99% SLA
- Named support engineer
Storage is measured on unique blobs after deduplication. If ten repositories share a base layer, you are charged for it once.
Pricing questions
Because a registry whose pulls are metered gets worked around — teams build caches, mirror to another registry, and the whole thing becomes a source of outages. Charging for storage aligns better with what it costs us.
Cached upstream blobs count at half rate, and expire on the TTL you set. Most teams find the cache pays for itself in upstream rate-limit avoidance alone.
Twenty gigabytes of deduplicated storage, which is more than it sounds — that is roughly 40 typical service images with shared bases.