Quick Start¶
This walks through the first few things you'll do after installing Portalcrane: logging in, exploring the dashboard, and using the registry from the Docker CLI.
1. Log in¶
Retrieve the auto-generated admin password from the container logs:
Open http://<host>:8000 in a browser and sign in with:
- Username:
admin - Password: the value printed in the logs
You land on the Dashboard, which shows image count, registry disk usage, and user counts at a glance.
2. Use the Docker CLI against Portalcrane¶
Portalcrane's registry proxy speaks the standard Docker Registry HTTP API, so any Docker-compatible client works against it directly:
docker login requires a Personal Access Token
scoped for Docker as the password — your account's real password (even the
built-in admin's) is rejected by the registry proxy. Generate one from the
account menu → Personal Access Tokens first.
Anonymous access
Set REGISTRY_PROXY_AUTH_ENABLED=false to allow unauthenticated
pull/push against the proxy — useful for fully trusted internal
networks. See Environment Variables.
For a full step-by-step example — login, pull, tag, push, pull back, run,
and logout, using the tiny traefik/whoami image, plus a side-by-side look
at what changes with authentication disabled — see the
Docker CLI Walkthrough.
3. Pull your first image via the Staging Pipeline¶
Rather than pushing images blindly from the CLI, use the Staging page to pull an image from Docker Hub, have it scanned by Trivy, and only then push it into your registry:
- Go to Staging in the sidebar.
- Search for an image (e.g.
nginx) and pick a tag. - Click Pull — Portalcrane downloads it as an OCI layout via
skopeo(no Docker daemon required on the server). - Once the CVE scan completes, review the vulnerability report.
- Click Push, choose a destination name/tag and (optionally) a folder, and the image lands in your registry.
See Staging Pipeline for the full walkthrough, including how to push to an external registry directly from a staged image.
4. Create your first non-admin user¶
Go to Settings → Accounts and create a user with just pull access, or grant folder-scoped push access instead of a blanket admin role. See Users, Groups & Permissions for the full model — permissions are always granted through groups, never directly to a user.
5. Add an external registry (optional)¶
If you want to mirror images from — or sync images to — another registry (Docker Hub, GHCR, Quay, a self-hosted instance), add it under Settings → Registries. See External Registries & Transfers.
What's next¶
- Folder-Based Access Control — scope permissions
to image namespaces like
production/*. - Vulnerability Scanning — tune which CVE severities block a staging push.
- Environment Variables — full reference for every configurable option.